Expert Guide
Everything banks, NBFCs, insurers and fintechs need to operationalise India's Digital Personal Data Protection Act — lawful bases, consent, penalties, breach rules, cross-border transfers and a step-by-step roadmap to the 2027 deadline.
Overview
What is the DPDP Act?
The Digital Personal Data Protection Act, 2023 (the DPDP Act) is India’s first comprehensive law governing how organisations collect, use, store and share the personal data of individuals. It is operationalised by the Digital Personal Data Protection Rules, 2025, notified in November 2025, and enforced by the newly created Data Protection Board of India. For financial institutions — which handle some of the most sensitive personal data in the economy — it changes how customer data can be processed at every stage of the lifecycle.
DPDP at a glance
- The Act applies to any organisation (a Data Fiduciary) that processes the digital personal data of individuals (Data Principals) in India — including offshore processing tied to offering goods or services in India.
- Processing is lawful only on one of two grounds: consent (Section 6) or a closed list of “legitimate uses” (Section 7).
- The DPDP Rules, 2025 commence in stages: Board provisions on notification, Consent Managers around November 2026, and the core obligations around mid-May 2027.
- Penalties are fixed rupee caps — up to ₹250 crore for a security-safeguards failure — not a percentage of turnover.
- For BFSI, DPDP is a floor plus an oversight layer that sits on top of existing RBI, SEBI and IRDAI rules — it does not replace them.
This guide is written for compliance, risk and product leaders in Indian BFSI. It walks through the Act’s structure, the 2025 Rules and their timeline, the penalty regime, how DPDP interacts with sectoral regulation, and a practical roadmap to readiness. Where dates or figures are still settling, we say so.
Key Roles
Who the DPDP Act applies to
The Act defines a small set of roles (mostly in Section 2). Getting these right is the foundation of a compliance programme, because obligations attach to the role you play in each data flow.
- Data Principal — s.2(j)
- The individual the personal data is about. Where the individual is a child, it includes the parents or lawful guardian; for a person with a disability, the lawful guardian.
- Data Fiduciary — s.2(i)
- Any person who, alone or with others, determines the purpose and means of processing personal data. In BFSI, you are almost always the Data Fiduciary and your customers are Data Principals.
- Data Processor — s.2(k)
- Any person who processes personal data on behalf of a Data Fiduciary — for example a KYC vendor or a cloud provider. A processor may be engaged only under a valid contract, and the Fiduciary stays liable.
- Significant Data Fiduciary (SDF) — s.10
- A Data Fiduciary (or class) that the Central Government notifies as significant, based on the volume and sensitivity of data and the risks it poses. SDFs carry extra duties (see below). Large banks and insurers are likely candidates, though designation is by government notification.
- Consent Manager — s.2(g)
- A person registered with the Board that gives Data Principals a single, interoperable, data-blind point to give, manage, review and withdraw consent.
The Act governs digital personal data — personal data in digital form, or non-digital data later digitised (Section 3). It reaches processing outside India where it is connected to offering goods or services to Data Principals in India, and excludes purely personal or domestic use.
Lawful Processing
The two lawful bases: consent and legitimate uses
Under Section 4, personal data may be processed only for a lawful purpose, and only where the Data Principal has given consent (Section 6) or the processing falls within a “legitimate use” (Section 7). Critically, there is no open-ended “legitimate-interest” basis as under GDPR — so ordinary commercial processing by a bank, NBFC, insurer or fintech generally needs consent.
What valid consent looks like (Section 6)
Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the stated purpose. It must be as easy to withdraw as to give; on withdrawal, the Fiduciary and its processors must stop processing within a reasonable time. Every consent request must be accompanied by an itemised notice (Section 5) describing the data collected, the purpose, how to exercise rights and how to complain to the Board — in clear language, available in English or a scheduled Indian language.
The “legitimate uses” (Section 7)
Section 7 permits processing without fresh consent for a closed list of grounds. The ones that matter most in BFSI are: data voluntarily provided by the individual for a service (7(a)), and compliance with a legal obligation or a court order — which covers KYC/AML, statutory record-keeping and credit-bureau reporting (7(b), 7(d), 7(e)). Others cover State functions, medical emergencies, epidemics, disasters and employment purposes. This carve-out is what lets a bank keep records the law requires without treating every statutory act as a consent event.
Individual Rights
Data Principal rights
The Act gives individuals a defined — and deliberately narrower than GDPR — set of rights (Sections 11–14). There is no right to data portability and no right to object.
| Right | Section | What it means for a Data Fiduciary |
|---|---|---|
| Access | s.11 | Provide a summary of the personal data processed, the processing activities, and the identities of other Fiduciaries/Processors it has been shared with. |
| Correction & erasure | s.12 | Correct, complete, update or erase personal data on request — unless a law requires it to be retained. |
| Grievance redressal | s.13 | Offer a grievance mechanism the individual must use before approaching the Board. |
| Nomination | s.14 | Let an individual nominate someone to exercise their rights in the event of death or incapacity. |
Data Principals also have duties (Section 15): not to impersonate, not to suppress material information, and not to file false or frivolous complaints — breach of which is itself penalised (up to ₹10,000).
Duties
Data Fiduciary and SDF obligations
Section 8 sets the baseline obligations for every Data Fiduciary. You are responsible for compliance for all processing done by you or on your behalf by a processor, regardless of any contrary agreement.
| Obligation | Section | Requirement |
|---|---|---|
| Accuracy | s.8(3)-(4) | Ensure completeness, accuracy and consistency where data drives a decision about the individual or is disclosed to another Fiduciary. |
| Security safeguards | s.8(5) | Implement reasonable security safeguards to prevent a personal data breach. |
| Breach notification | s.8(6) | Notify the Board and each affected Data Principal of a breach, in the prescribed manner. |
| Retention limitation | s.8(7) | Erase data on withdrawal of consent or once the purpose is served — unless a law requires retention — and cause processors to erase too. |
| Grievance & contact | s.8(9)-(10) | Publish the contact of a DPO or responsible person and run an effective grievance-redressal mechanism. |
Extra duties for Significant Data Fiduciaries (Section 10)
If designated an SDF, an institution must additionally appoint an India-based Data Protection Officer answerable to its board, appoint an independent data auditor (internal audit does not qualify), and carry out a periodic Data Protection Impact Assessment and audit — at least once every 12 months under the Rules, along with due-diligence on algorithmic software. Given their scale and data sensitivity, large banks and insurers should plan on the assumption they may be designated.
DPDP Rules 2025
What the 2025 Rules require, and when
The DPDP Rules, 2025 were notified in November 2025 and commence in stages (Rule 1(2)). This staggered timeline is the single most important planning fact for BFSI.
| When | What takes effect |
|---|---|
| On notification (Nov 2025) | Definitions and the Data Protection Board provisions — the Board can be constituted and operate as a digital office. No substantive corporate obligation is yet enforceable. |
| +12 months (~Nov 2026) | Consent Manager registration regime (Rule 4). |
| +18 months (~13 May 2027) | The compliance core: notice (Rule 3), security safeguards (Rule 6), breach intimation (Rule 7), retention/erasure (Rule 8), children’s data (Rules 10–12), SDF duties (Rule 13), rights (Rule 14) and cross-border transfer (Rule 15). |
Reasonable security safeguards (Rule 6)
The Rules put substance behind Section 8(5). Measures include encryption, tokenisation or masking of personal data, access control, logging and monitoring to detect unauthorised access, backups for continuity, retention of logs for at least one year, and contractual security obligations flowed down to processors.
Breach notification (Rule 7)
A Data Fiduciary must intimate affected individuals and the Board without delay on becoming aware of a breach, and file a detailed report with the Board within 72 hours (extendable on written request). There is no minimum-severity threshold — every personal data breach is reportable, which is stricter than most incident regimes.
Children’s data and cross-border transfers
Processing the data of anyone under 18 requires verifiable parental consent, verified against reliable identity details or a government-authorised token (e.g. DigiLocker); tracking and targeted advertising to children are barred (Section 9, Rules 10–12). For cross-border flows, the Act uses a permissive “blacklist” model (Section 16, Rule 15): transfers abroad are allowed unless the Government restricts a specific country — though, importantly, this does not loosen the stricter localization rules that already bind financial data.
Enforcement
Penalties: the Schedule to the Act
Penalties are fixed monetary caps set out in the Schedule and imposed by the Data Protection Board after inquiry — there is no turnover-linked fine. The amounts below are ceilings; the Board sets the actual figure weighing the gravity and duration of the breach, the sensitivity of the data, whether it was repetitive, and — crucially — the mitigation the institution had in place.
| Failure | Provision | Maximum penalty |
|---|---|---|
| Failure to take reasonable security safeguards | s.8(5) | ₹250 crore |
| Failure to notify a personal data breach | s.8(6) | ₹200 crore |
| Breach of children's-data obligations | s.9 | ₹200 crore |
| Breach of SDF additional obligations | s.10 | ₹150 crore |
| Breach of a Data Principal's duties | s.15 | ₹10,000 |
| Breach of any other provision (residuary) | — | ₹50 crore |
Two nuances matter for BFSI. First, the ₹250 crore entry attaches to the failure to safeguard, not to the breach itself — an institution with demonstrably strong, tested controls that is still breached is in a far better position than a negligent one. Second, penalties stack: a single incident can combine a safeguards failure and a notification failure. Documented DPIAs, a tested incident-response plan and a prompt breach notice are the levers that pull the number down. On repeated findings, the Board can even advise the Government to block access to the Fiduciary’s platform (Section 37).
Sector Focus
DPDP for BFSI: how it fits with RBI, SEBI and IRDAI
DPDP does not displace financial-sector regulation — it layers on top of it. Under Section 38, the Act is “in addition to and not in derogation of” other laws, and prevails only to the extent of a genuine conflict. Because sectoral rules usually impose more (localization, longer retention, tighter breach clocks), they coexist with DPDP rather than conflicting with it.
Retention vs erasure: the PMLA release valve
The most-asked BFSI question — “must we delete data a customer asks us to?” — resolves through Section 7. PMLA and the RBI KYC Master Direction require identity and transaction records to be kept for five years; that retention is a legitimate use (Section 7(b)), so the erasure right yields to the statutory hold. Wire your erasure workflow to check for a KYC/PMLA hold before honouring any deletion, then erase once no legal basis survives.
Localization and cross-border
DPDP’s permissive cross-border model is overridden in practice by stricter sectoral mandates: RBI’s 2018 payment-data localization, SEBI’s cloud framework and IRDAI’s records rules all require regulated data to stay in India. The practical BFSI posture is to localize regulated data in India (using onshore cloud regions), keep rights and audit infrastructure onshore, and treat any future SDF “no-transfer” category list as a live watch-item.
Consent, the Account Aggregator and Consent Managers
Purpose-binding is the core discipline: onboarding and KYC rest on service-provision and legal-obligation grounds, but marketing and cross-sell need separate opt-in consent. The Account Aggregator consent artefact is already specific, granular, revocable and logged, aligning closely with DPDP’s Consent Manager concept — though exactly how the AA and Consent Manager regimes reconcile remains an open regulatory question. Legacy blanket consents fail Section 6 and must be re-papered into granular opt-ins.
Breach response: overlapping clocks
BFSI faces multiple, non-substitutable breach clocks — reporting to one regulator does not discharge the others. CERT-In requires notice within 6 hours, the RBI cyber framework as little as 2–6 hours for customer-data events, and DPDP a detailed Board report within 72 hours. Build one incident-response runbook with parallel notification tracks; the RBI/CERT-In clocks are the binding operational constraint.
Comparison
DPDP vs GDPR: what's different
Global institutions cannot lift-and-shift a GDPR programme into India. The structural differences change how you design consent, rights and cross-border flows. (For a deeper treatment, see our DPDP vs GDPR analysis.)
| Dimension | DPDP (India) | GDPR (EU) |
|---|---|---|
| Lawful bases | Consent + a closed list of legitimate uses | Six bases, incl. open-ended legitimate interests |
| Data portability | Not provided | Right to portability (Art. 20) |
| Right to object | Not provided | Rights to object & restrict |
| Sensitive data | No separate special-category tier | Art. 9 special categories |
| Cross-border | Blacklist (allowed unless restricted) | Adequacy + SCCs/BCRs |
| Penalties | Fixed caps (max ₹250 crore) | Up to 4% of global turnover |
| Children | Under 18; verifiable parental consent | 13–16 (member-state set) |
Get Ready
A DPDP compliance roadmap for BFSI
Treat mid-May 2027 as the hard deadline for the substantive obligations and November 2026 as the Consent-Manager-integration milestone. Because enterprise programmes typically run 9–12 months, the practical work should start now.
- 1
Map your personal data
Inventory personal data across LOS, LMS, collections, CRM, the data warehouse and every vendor. For each flow, capture the purpose, the lawful basis, data categories, retention rule and storage location. This map is the substrate for notices, retention schedules, DPIAs and breach scoping.
- 2
Re-architect consent and notice
Replace blanket consent with purpose-specific, itemised notices and granular opt-ins. Separate marketing/cross-sell consent from onboarding, and rely on Section 7 for statutory processing so you are not re-consenting for KYC or bureau reporting.
- 3
Stand up governance (DPO, auditor, DPIA)
Appoint a grievance/DPO contact for every Fiduciary; if you are likely an SDF, add an India-based DPO, an independent data auditor and a 12-monthly DPIA and audit cadence.
- 4
Reconcile retention with PMLA
Codify retention schedules keyed to five years post-relationship/transaction, add automated legal-hold logic, and make erasure requests check holds before deletion.
- 5
Build a multi-track breach playbook
One runbook, parallel clocks: CERT-In (6 hours), RBI (2–6 hours for customer-data events) and DPDP (72-hour detailed Board report, no severity threshold), plus without-delay notice to affected individuals.
- 6
Operationalise rights and children's flows
Publish rights request channels, wire access/correction/erasure/nomination into your systems, and add verifiable-parental-consent and age-assurance to minor-account and guardian journeys.
FinHub’s DPDP Governance Platform and its live ConsentGuard consent engine are built to turn this roadmap into default behaviour — capturing purpose-bound consent, maintaining a live data map, powering rights requests and producing an audit-ready trail.
FAQ
DPDP Act: frequently asked questions
Straight answers to the questions BFSI compliance and product teams ask most about the DPDP Act and Rules 2025.
India's Digital Personal Data Protection Act, 2023 is the country's first comprehensive personal-data protection law. It is operationalised by the DPDP Rules, 2025 and enforced by the Data Protection Board of India (DPBI).
Turn this guide into a compliance plan
Our team can map DPDP obligations to your current data estate and stand up consent, rights and audit workflows before the 2027 deadline.