Banks, NBFCs, payment and lending companies

DPDP compliance for banks, NBFCs and fintech

Financial services hold some of the most sensitive personal data in India and already answer to RBI, SEBI and PMLA requirements. The DPDP Act adds a consent-and-rights layer on top. ConsentLo lets compliance, risk and product teams run both without spreadsheets.

What DPDP changes for you

  • Consent for cross-selling, credit bureau checks and marketing has to be separate from consent for the core account.
  • KYC and transaction records must be kept for years under other laws, so erasure requests need a documented legal-hold answer.
  • Lending apps and payment partners act as processors, and consent withdrawal has to reach them too.
  • Breaches must be reported to the Data Protection Board within 72 hours, in addition to CERT-In and RBI reporting.

How ConsentLo helps

Purpose-level consent

Separate, un-ticked choices for each purpose, tied to the exact notice version and sealed as evidence.

Retention with legal holds

Erasure requests check statutory retention first and record why data was kept, so answers stand up in an audit.

Processor cascade

Withdrawals and erasures are pushed to lending, payment and marketing partners, with proof of delivery.

Breach desk with parallel clocks

One incident record drives the Board intimation, the 72-hour report and notices to affected customers.

Frequently asked questions

Does the DPDP Act override RBI data rules?

The DPDP Act applies in addition to other laws. Where another law gives a higher degree of protection or restricts transfers outside India more strictly, such as RBI's payment data storage rules, that stricter rule continues to apply.

Can a bank refuse an erasure request?

Yes, where another law requires the data to be retained, for example KYC records under anti-money-laundering law. The bank should record the legal basis for retention and tell the customer.

Related DPDP guides