Fintech compliance in India
where the DPDP Act meets RBI.
A fintech answers to the DPDP Act and to whichever financial regulator licenses it or its partner. The two rarely contradict each other. The trouble is in the seams: what must be kept, what must be erased, whose consent counts, and how many clocks one incident starts.
Which laws apply to a fintech in India?
Every fintech is a Data Fiduciary under the DPDP Act. On top of that sits the regulator of whoever holds the licence: RBI for banks, NBFCs, payment aggregators and account aggregators; SEBI for brokers, advisers and wealth platforms; IRDAI for insurtech distribution; and anti-money-laundering law for anyone doing KYC.
| Law or rule | What it governs | Who it binds |
|---|---|---|
| DPDP Act 2023 and Rules 2025 | Notice, consent, purpose, erasure, breach reporting, rights | Every fintech processing personal data of people in India |
| RBI Cybersecurity Directions, 2026 | Security governance, SOC, VAPT, six-hour reporting on DAKSH | Banks, NBFCs, CICs and other RBI entities; partners by contract. See the RBI guide |
| RBI Digital Lending Directions, 2025 | App permissions, need-based collection, explicit consent, storage in India | Regulated lenders, and the lending service providers and apps they use |
| Payment Aggregator Directions, 2025 | Authorisation, security baseline, card data, payment data localisation | Payment aggregators; gateways by recommendation |
| Storage of Payment System Data, 2018 | Payment system data held only in India | Payment system operators and aggregators |
| SEBI CSCRF | Cyber resilience, SOC, audits, six-hour reporting | SEBI regulated entities. See the CSCRF guide |
| PMLA and RBI KYC directions | Identity verification and record retention | Reporting entities, including banks, NBFCs and payment system operators |
| CERT-In directions, 2022 | Six-hour incident reporting, 180-day logs in India | Body corporates and service providers generally. See the CERT-In guide |
The obligation fintechs get wrong: retention versus erasure
Fintechs usually treat RBI retention and DPDP erasure as a conflict and resolve it by keeping everything. They do not conflict. Section 8(7) of the DPDP Act exempts retention necessary for compliance with law, but only for the data that law names, for as long as it names.
The anti-money-laundering rule is the anchor. Section 12 of the Prevention of Money-laundering Act requires reporting entities to keep records of transactions and of client identity for five years after the transaction or after the business relationship ends. RBI's KYC directions, consolidated in November 2025, build on it. That covers the KYC document, the video-KYC recording, the transaction history. It does not cover the marketing consent captured at signup, the referral graph, the device fingerprint used for growth analytics, or the half-completed application of someone who never became a customer.
So the work is a map, field by field: which law requires each field, from what trigger, for how long, and what happens at the end. A regulated entity that can produce that map passes an inspection. One that says "we are RBI-regulated, we keep everything" has told the examiner it cannot tell the two kinds of data apart. The DPDP retention and erasure guide covers the Rule 8 mechanics, including the one-year floor on logs.
Whose consent counts: DPDP, Account Aggregator or the app store?
Three consent layers run through a typical fintech, and only one of them is DPDP consent. An Account Aggregator consent artefact authorises one flow of financial data. An app's permission prompt authorises access to a device resource. Neither is the section 5 notice and section 6 consent you must be able to prove.
The Account Aggregator framework is RBI's own consent architecture, with its own artefact, purpose codes and expiry. It is well designed, and it answers a narrower question: may this institution fetch that account's data for this purpose. Your DPDP notice still has to tell the person what you will do with the data once it arrives, and your record still has to show which notice version they saw.
Lending adds a third layer. The Digital Lending Directions, 2025 bar apps from contacts, call logs, files and telephony functions, allow one-time camera, microphone or location access only for onboarding or KYC with explicit consent, and require collection to be need-based with an audit trail and a way to revoke consent and ask for deletion. Data may be processed abroad only if it is deleted there and returned to India within 24 hours. The same onboarding consent also will not carry a later cross-sell campaign: purpose limitation under section 6(1) is the provision most often breached by re-using it.
One incident, several clocks
A cyber incident at a bank or NBFC must reach RBI on DAKSH within six hours of detection and CERT-In within six hours. If personal data is affected, the Data Protection Board and every affected person must be told without delay, with the Board's detailed report within 72 hours. SEBI entities add SEBI and the exchange.
The clocks run in parallel from different triggers, detection for RBI and awareness for the Board, so the incident runbook has to name who files each report. A fintech that is not itself regulated, but processes for a bank, will be contractually required to tell the bank fast enough for the bank to meet its six hours, which in practice means within one or two. The breach deadline calculator lays the deadlines out from a single timestamp.
Fintech control checklist
These are the controls an examiner, an auditor or a bank partner will test. Each should produce evidence you can hand over, not a policy paragraph.
| Control | Why | Evidence to hold |
|---|---|---|
| Retention map per data field, with the law and period for each | DPDP s.8(7); PMLA s.12 | The map, and deletion logs for fields past their period |
| Separate consent per purpose: service, cross-sell, marketing, analytics | DPDP s.6(1) | Consent record per purpose, tied to notice version |
| DPDP notice shown alongside every AA data request | DPDP s.5; AA framework | Notice version recorded with each AA fetch |
| App permissions limited to what the Directions allow | Digital Lending Directions 2025 | Manifest review per release; consent audit trail |
| Payment and lending data stored in India | RBI 2018 circular; DL Directions | Data residency evidence per store and backup |
| Incident runbook naming the owner of each report | RBI 2026 Directions; CERT-In; DPDP Rule 7 | Runbook, drill records, timestamps from last incident |
| Trackers held until consent on web and app | DPDP s.6 | Two-pass scan showing nothing fires before a choice |
| Withdrawal reaches every processor | DPDP s.6(6) | Relay log per processor |
Where to go next
Regulated entities should read the RBI cybersecurity guide or, for brokers, the SEBI CSCRF guide. For the law underneath all of it, read the DPDP Act and Rules 2025 guide. To see what your own website does before a visitor answers the banner, run the free two-pass cookie scan. The consent platform holds versioned notices in 22 languages, a hash-chained consent ledger, withdrawal relayed to each processor, and rights requests and breaches on their statutory clocks. The industries overview compares all eight sectors.
The things people ask us
Does the DPDP Act override RBI's KYC retention rules?
No. Section 8(7) requires erasure once the purpose is served unless retention is necessary for compliance with law. KYC records that the Prevention of Money-laundering Act and RBI's KYC directions require you to keep are covered by that exception. The marketing preferences and behavioural data stored beside them are not.
Is an Account Aggregator consent the same as DPDP consent?
No. The Account Aggregator framework has its own consent artefact under RBI's rules, which authorises a specific flow of financial information from one institution to another. It does not replace the notice section 5 of the DPDP Act requires from you, or the record of consent section 6(10) says you must be able to produce.
Can a lending app access a borrower's contacts?
No. RBI's Digital Lending Directions, 2025 bar digital lending apps from accessing file and media, contact lists, call logs and telephony functions. One-time access to the camera, microphone or location is allowed only for onboarding or KYC, with the borrower's explicit consent, and data collection must be need-based with an audit trail.
How many breach reports does a fintech file after one incident?
Often three or more. A bank or NBFC reports to RBI on DAKSH within six hours, CERT-In within six hours, and, for a personal data breach, the Data Protection Board and every affected person, with the Board's detailed report within 72 hours. A SEBI-regulated broker adds SEBI and the exchange.
Can a fintech store payment data outside India?
Not payment system data. RBI's 2018 circular requires it to be stored only in India, and the 2025 Payment Aggregator Directions apply that to aggregators. The Digital Lending Directions allow processing abroad only if the data is deleted there and brought back within 24 hours. The DPDP Act preserves these stricter rules.
Keep what the law names. Erase the rest on schedule.
See what your site and app send before anyone consents, then see how the platform ties every consent to a purpose and notice version, and relays withdrawal to each processor.