DPDP Compliance for Banks and NBFCs

Every KYC record, video verification, credit bureau check, and transaction is personal data under the DPDP Act, 2023. Trusted by Axis Bank, 5+ leading banks, and 8+ NBFCs.

Why The DPDP Act Matters For Banking Now

Banks and NBFCs act as Data Fiduciaries under the DPDP Act, while third-party vendors process data on their behalf. Effective data governance begins with identifying customer data, systems, and processors.

Phased Compliance Timeline

Phased Compliance Timeline

DPDP Rules, 2025 follow a staggered rollout, with key obligations effective from 13 May 2027.
Consent Manager Readiness

Consent Manager Readiness

Registration opens on 13 November 2026, making consent governance an immediate priority.
DPDP and RBI Alignment

DPDP and RBI Alignment

Banks and NBFCs must meet both DPDP requirements and RBI expectations on governance, outsourcing, cyber resilience, and localisation.
Cross-Border Data Governance

Cross-Border Data Governance

Personal data must be mapped against RBI localisation requirements and DPDP cross-border transfer rules.
Third-Party Accountability

Third-Party Accountability

BPOs, cloud providers, credit bureaus, and video KYC partners remain within the compliance scope.
Governance Before Compliance

Governance Before Compliance

DPDP readiness starts with visibility into personal data, processors, and data flows.

Types Of Personal Data Processed

aadhaar
Aadhaar (masked)
pan
PAN
passport
Passport
voterID
Voter ID
address
Address Proof
Key Compliance & Data Governance Challenges

Key Compliance & Data Governance Challenges

  • tick

    Personal data is fragmented across core banking, LOS/LMS, CRM, collections, credit bureaus, and verification systems.

  • tick

    Consent is captured differently across branches, mobile apps, net banking, call centres, and digital lending journeys.

  • tick

    Customer data moves across cloud providers, BPOs, video KYC partners, and credit bureaus, expanding third-party risk.

  • tick

    RBI data localisation requirements and the DPDP Act's cross-border transfer rules must be managed together.

  • tick

    Customer data spread across multiple products makes Data Principal rights requests difficult to fulfil.

  • tick

    Continuous visibility into data flows, consent, and third-party processing is essential for audit readiness.

Built to Solve Every DPDP Challenge

Banking/NBFC Challenge

KYC and biometric data scattered across core banking, LOS/LMS, and BPO vendor systems

Privy by IDfy Capability

Personal Data Discovery & Governance (Data Compass) maps personal data across structured and unstructured systems

Banking/NBFC Challenge

Consent captured inconsistently across branch forms, mobile app, and net banking

Privy by IDfy Capability

Consent Lifecycle Management unifies capture, versioning, and withdrawal across every channel

Banking/NBFC Challenge

RBI data-localisation rules for payment data running alongside the DPDP Act's separate cross-border regime

Privy by IDfy Capability

Personal Data Discovery & Governance tracks where each data element sits and which regime applies to it

Banking/NBFC Challenge

Heavy dependence on BPOs, collection agencies, cloud core banking, and credit bureaus

Privy by IDfy Capability

Continuous Compliance & Risk Management monitors third-party processors against data-processing agreement terms

Banking/NBFC Challenge

Data Principal rights requests hard to fulfil when a customer's record spans multiple systems

Privy by IDfy Capability

Data Principal Rights Management routes and fulfils access, correction, and erasure requests across connected systems

Banking/NBFC Challenge

Breach response needs to identify affected data and notify within tight statutory windows once Rule 7 is in force

Privy by IDfy Capability

Continuous Compliance & Risk Management provides an auditable, time-stamped incident response workflow

Banking/NBFC Challenge

Anticipated Significant Data Fiduciary obligations (DPIA, India-based DPO, algorithmic due diligence for credit models)

Privy by IDfy Capability

Continuous Compliance & Risk Management runs the DPIA cycle and builds the evidence trail regulators expect

Banking/NBFC Challenge

Net banking portal and marketing site use tracking cookies without DPDP-aligned consent

Privy by IDfy Capability

Cookie Manager brings banner logic and preference storage in line with consent requirements

Banking/NBFC Challenge

Credit-scoring and fraud models need training data without directly exposing customer PII

Privy by IDfy Capability

Personal Data Discovery & Governance supports classification that enables masking and de-identification ahead of model training

Banking/NBFC Challenge

No single, current view of privacy posture across consent, data, and vendor risk

Privy by IDfy Capability

InspectAI gives a unified view across all modules, continuously scanning for gaps

Recommended Implementation Journey

Now
November 2026
May 2027
2027 Onwards
Stage 1
Stage title icon

Build the Foundation

  • Checkmark iconDiscover and classify personal data across core banking, LOS/LMS, and CRM.
  • Checkmark iconAudit consent collection across every customer channel.
  • Checkmark iconInventory third-party vendors handling customer data.
  • Checkmark iconIdentify contracts requiring updated data-processing terms.
Stage alert icon
Consent Manager registration opens — 13 November 2026
Stage 2
Stage title icon

Operationalise Compliance

  • Checkmark iconAlign consent infrastructure with DPDP notice and consent requirements.
  • Checkmark iconImplement Data Principal rights workflows.
  • Checkmark iconEstablish breach notification processes.
  • Checkmark iconUpdate vendor agreements identified during the audit.
Stage alert icon
Core DPDP obligations become effective — 13 May 2027
Stage 3
Stage title icon

Continuous Governance

  • Checkmark iconConduct DPIAs if notified as a Significant Data Fiduciary
  • Checkmark iconAppoint an India-based Data Protection Officer.
  • Checkmark iconEngage an independent data auditor.
  • Checkmark iconContinuously monitor compliance, consent, and third-party risks.
Stage alert icon
Move from project-based compliance to continuous privacy governance.

Key Takeaways

Banks and NBFCs are Data Fiduciaries under the DPDP Act for customer KYC, transaction, and credit data.

DPDP Rules 2025 were notified on 13 November 2025, with Consent Manager registration from 13 November 2026 and major obligations effective from 13 May 2027.

Non-compliance can attract penalties of up to ₹250 crore per contravention, depending on the nature of the violation.

RBI requirements on data localisation, outsourcing, and governance apply alongside DPDP, requiring institutions to manage both regulatory frameworks together.

A unified privacy management platform enables faster regulatory responses through centralised data mapping, consent records, automated rights management, and continuous third-party risk monitoring.

Early DPDP readiness helps banks build audit-ready evidence, reduce manual compliance effort, and stay prepared for evolving regulatory requirements.

Why Privy by IDfy for Banks & NBFCs

Leading banks and financial institutions trust Privy by IDfy to operationalise DPDP compliance across complex data ecosystems. Our platform enables continuous data governance, centralized consent management, and audit-ready compliance at enterprise scale.

DPDP ready

FAQs

A bank is almost always a Data Fiduciary for the personal data it collects directly from customers KYC documents, transaction records, and credit data because it determines the purpose and means of processing. Vendors it engages to process that data on its behalf, such as a BPO running collections calls, act as Data Processors under contract to the bank.

The Act applies to personal data processing generally, not just data collected after a specific date. Existing customer records collected before the Act's provisions came into force still need to meet the Act's consent, purpose-limitation, and security requirements going forward.

The two operate alongside each other rather than one replacing the other. RBI's 2018 circular requires payment system data to be stored in India specifically. The DPDP Act governs cross-border transfer more broadly and currently permits transfer to any country the government hasn't specifically restricted by notification — no such restriction list has been published as of mid-2026. A bank needs both rules mapped against its actual data flows, not just the more permissive one.

A Consent Manager under the DPDP Act is a registered intermediary through which a Data Principal can manage consent across multiple platforms. It's structurally similar to RBI's existing Account Aggregator framework, which already lets customers consent to share financial data across institutions, but the Consent Manager framework is broader in scope and sits under the Data Protection Board rather than the RBI. Registration for Consent Managers opens 13 November 2026.

The DPDP Act allows the government to notify certain Data Fiduciaries as Significant Data Fiduciaries based on the volume and sensitivity of data they process, among other factors. Institutions processing data at the scale of a large bank or NBFC are widely expected to qualify, but as of this writing the government has not published the specific list or criteria for that notification; treat this as a strong likelihood to prepare for, not a confirmed classification.

Penalties can run up to ₹250 crore per contravention, depending on the nature and severity of the violation, as stated in the Act's Schedule. The exact figure depends on which specific obligation was breached.

DPDP consent needs to be specific to the purpose for which data is collected and processed. A single KYC consent captured at account opening is unlikely to cover distinct purposes like credit scoring, marketing communication, or data sharing with a collections vendor; each purpose generally needs its own clearly itemised consent.