DPDP compliance for banks, NBFCs and fintech
Financial services hold some of the most sensitive personal data in India and already answer to RBI, SEBI and PMLA requirements. The DPDP Act adds a consent-and-rights layer on top. ConsentLo lets compliance, risk and product teams run both without spreadsheets.
What DPDP changes for you
- Consent for cross-selling, credit bureau checks and marketing has to be separate from consent for the core account.
- KYC and transaction records must be kept for years under other laws, so erasure requests need a documented legal-hold answer.
- Lending apps and payment partners act as processors, and consent withdrawal has to reach them too.
- Breaches must be reported to the Data Protection Board within 72 hours, in addition to CERT-In and RBI reporting.
How ConsentLo helps
Purpose-level consent
Separate, un-ticked choices for each purpose, tied to the exact notice version and sealed as evidence.
Retention with legal holds
Erasure requests check statutory retention first and record why data was kept, so answers stand up in an audit.
Processor cascade
Withdrawals and erasures are pushed to lending, payment and marketing partners, with proof of delivery.
Breach desk with parallel clocks
One incident record drives the Board intimation, the 72-hour report and notices to affected customers.
Frequently asked questions
Does the DPDP Act override RBI data rules?
The DPDP Act applies in addition to other laws. Where another law gives a higher degree of protection or restricts transfers outside India more strictly, such as RBI's payment data storage rules, that stricter rule continues to apply.
Can a bank refuse an erasure request?
Yes, where another law requires the data to be retained, for example KYC records under anti-money-laundering law. The bank should record the legal basis for retention and tell the customer.
Related DPDP guides
DPDP compliance checklist: 12 steps to get ready
A practical DPDP Act compliance checklist: data mapping, notices, consent, rights, grievances, processors, breach response, children, retention, security and evidence.
Read the guide
Data breach notification under DPDP: the 72-hour rule
How to report a personal data breach under India's DPDP Act and Rules: who to tell, what to include, the 72-hour Board report and how to prepare your team.
Read the guide
Cross-border data transfer under the DPDP Act
Can personal data leave India under the DPDP Act? How the negative-list model works, sectoral localisation rules such as RBI's, and what the DPDP Rules 2025 add.
Read the guide