By sector · Fintech

Fintech compliance in India
where the DPDP Act meets RBI.

A fintech answers to the DPDP Act and to whichever financial regulator licenses it or its partner. The two rarely contradict each other. The trouble is in the seams: what must be kept, what must be erased, whose consent counts, and how many clocks one incident starts.

DPDP s.8(7)PMLA s.12Digital Lending Directions 2025DAKSH six hours
01

Which laws apply to a fintech in India?

Every fintech is a Data Fiduciary under the DPDP Act. On top of that sits the regulator of whoever holds the licence: RBI for banks, NBFCs, payment aggregators and account aggregators; SEBI for brokers, advisers and wealth platforms; IRDAI for insurtech distribution; and anti-money-laundering law for anyone doing KYC.

Law or ruleWhat it governsWho it binds
DPDP Act 2023 and Rules 2025Notice, consent, purpose, erasure, breach reporting, rightsEvery fintech processing personal data of people in India
RBI Cybersecurity Directions, 2026Security governance, SOC, VAPT, six-hour reporting on DAKSHBanks, NBFCs, CICs and other RBI entities; partners by contract. See the RBI guide
RBI Digital Lending Directions, 2025App permissions, need-based collection, explicit consent, storage in IndiaRegulated lenders, and the lending service providers and apps they use
Payment Aggregator Directions, 2025Authorisation, security baseline, card data, payment data localisationPayment aggregators; gateways by recommendation
Storage of Payment System Data, 2018Payment system data held only in IndiaPayment system operators and aggregators
SEBI CSCRFCyber resilience, SOC, audits, six-hour reportingSEBI regulated entities. See the CSCRF guide
PMLA and RBI KYC directionsIdentity verification and record retentionReporting entities, including banks, NBFCs and payment system operators
CERT-In directions, 2022Six-hour incident reporting, 180-day logs in IndiaBody corporates and service providers generally. See the CERT-In guide
02

The obligation fintechs get wrong: retention versus erasure

Fintechs usually treat RBI retention and DPDP erasure as a conflict and resolve it by keeping everything. They do not conflict. Section 8(7) of the DPDP Act exempts retention necessary for compliance with law, but only for the data that law names, for as long as it names.

The anti-money-laundering rule is the anchor. Section 12 of the Prevention of Money-laundering Act requires reporting entities to keep records of transactions and of client identity for five years after the transaction or after the business relationship ends. RBI's KYC directions, consolidated in November 2025, build on it. That covers the KYC document, the video-KYC recording, the transaction history. It does not cover the marketing consent captured at signup, the referral graph, the device fingerprint used for growth analytics, or the half-completed application of someone who never became a customer.

So the work is a map, field by field: which law requires each field, from what trigger, for how long, and what happens at the end. A regulated entity that can produce that map passes an inspection. One that says "we are RBI-regulated, we keep everything" has told the examiner it cannot tell the two kinds of data apart. The DPDP retention and erasure guide covers the Rule 8 mechanics, including the one-year floor on logs.

04

One incident, several clocks

A cyber incident at a bank or NBFC must reach RBI on DAKSH within six hours of detection and CERT-In within six hours. If personal data is affected, the Data Protection Board and every affected person must be told without delay, with the Board's detailed report within 72 hours. SEBI entities add SEBI and the exchange.

The clocks run in parallel from different triggers, detection for RBI and awareness for the Board, so the incident runbook has to name who files each report. A fintech that is not itself regulated, but processes for a bank, will be contractually required to tell the bank fast enough for the bank to meet its six hours, which in practice means within one or two. The breach deadline calculator lays the deadlines out from a single timestamp.

05

Fintech control checklist

These are the controls an examiner, an auditor or a bank partner will test. Each should produce evidence you can hand over, not a policy paragraph.

ControlWhyEvidence to hold
Retention map per data field, with the law and period for eachDPDP s.8(7); PMLA s.12The map, and deletion logs for fields past their period
Separate consent per purpose: service, cross-sell, marketing, analyticsDPDP s.6(1)Consent record per purpose, tied to notice version
DPDP notice shown alongside every AA data requestDPDP s.5; AA frameworkNotice version recorded with each AA fetch
App permissions limited to what the Directions allowDigital Lending Directions 2025Manifest review per release; consent audit trail
Payment and lending data stored in IndiaRBI 2018 circular; DL DirectionsData residency evidence per store and backup
Incident runbook naming the owner of each reportRBI 2026 Directions; CERT-In; DPDP Rule 7Runbook, drill records, timestamps from last incident
Trackers held until consent on web and appDPDP s.6Two-pass scan showing nothing fires before a choice
Withdrawal reaches every processorDPDP s.6(6)Relay log per processor
06

Where to go next

Regulated entities should read the RBI cybersecurity guide or, for brokers, the SEBI CSCRF guide. For the law underneath all of it, read the DPDP Act and Rules 2025 guide. To see what your own website does before a visitor answers the banner, run the free two-pass cookie scan. The consent platform holds versioned notices in 22 languages, a hash-chained consent ledger, withdrawal relayed to each processor, and rights requests and breaches on their statutory clocks. The industries overview compares all eight sectors.

Questions

The things people ask us

Does the DPDP Act override RBI's KYC retention rules?

No. Section 8(7) requires erasure once the purpose is served unless retention is necessary for compliance with law. KYC records that the Prevention of Money-laundering Act and RBI's KYC directions require you to keep are covered by that exception. The marketing preferences and behavioural data stored beside them are not.

Is an Account Aggregator consent the same as DPDP consent?

No. The Account Aggregator framework has its own consent artefact under RBI's rules, which authorises a specific flow of financial information from one institution to another. It does not replace the notice section 5 of the DPDP Act requires from you, or the record of consent section 6(10) says you must be able to produce.

Can a lending app access a borrower's contacts?

No. RBI's Digital Lending Directions, 2025 bar digital lending apps from accessing file and media, contact lists, call logs and telephony functions. One-time access to the camera, microphone or location is allowed only for onboarding or KYC, with the borrower's explicit consent, and data collection must be need-based with an audit trail.

How many breach reports does a fintech file after one incident?

Often three or more. A bank or NBFC reports to RBI on DAKSH within six hours, CERT-In within six hours, and, for a personal data breach, the Data Protection Board and every affected person, with the Board's detailed report within 72 hours. A SEBI-regulated broker adds SEBI and the exchange.

Can a fintech store payment data outside India?

Not payment system data. RBI's 2018 circular requires it to be stored only in India, and the 2025 Payment Aggregator Directions apply that to aggregators. The Digital Lending Directions allow processing abroad only if the data is deleted there and brought back within 24 hours. The DPDP Act preserves these stricter rules.

Fintech consent

Keep what the law names. Erase the rest on schedule.

See what your site and app send before anyone consents, then see how the platform ties every consent to a purpose and notice version, and relays withdrawal to each processor.