Industry · NBFCs
DPDPA Compliance for NBFCs in India
NBFCs sit on some of India's densest personal data: Aadhaar-based KYC, bank statements, credit bureau pulls and repayment histories, much of it collected through DSAs and lending service providers. The DPDP Act 2023 and its 2025 Rules give you until 13 May 2027 to fix consent, retention and breach response. RBI obligations continue alongside — DPDPA adds to them, not replaces.
Last reviewed: 30 July 2026
What DPDPA compliance risks do NBFCs face?
Unlike employers, NBFCs have no employment-style legitimate use to fall back on: lending, cross-sell and collections all run on Section 6 consent — itemised, plain-language, withdrawable. The exposure is concentrated in three places. Rejected-applicant files kept forever with no live purpose. DSAs, LSPs, co-lenders and recovery agents processing borrower data under thin contracts, where liability stays with you. And KYC records retained under PMLA rules while DPDPA demands erasure once the purpose ends — a retention-mapping problem, not a genuine legal conflict.
What should NBFCs prepare first for DPDPA compliance?
- Map the borrower data lifecycle — application, KYC, disbursal, collections, closure — and the lawful ground for each step.
- Itemise Section 6 consent notices; stop bundling lending, cross-sell and marketing into one tick.
- Tighten DSA / LSP / recovery-agent contracts with incident-escalation timelines (hours, not “promptly”).
- Build a dual-clock breach SOP: CERT-In 6 hours + Data Principal intimation without delay + DPB report within 72 hours.
- Reconcile KYC / PMLA retention with DPDPA purpose limitation and erasure rights.
Frequently asked questions
We already follow RBI's IT and digital lending directions. Doesn't that cover us?
No. RBI's Master Directions govern you as a regulated entity; DPDPA governs you as a Data Fiduciary, and the two run in parallel. RBI dictates what you must retain and how you must secure it; DPDPA dictates the lawful ground you collected it on, the notice you gave, and the borrower's rights to access, correction, erasure and grievance redressal. RBI compliance is evidence of good security hygiene — it is not a defence before the Data Protection Board. Both apply from 13 May 2027.
Can we process loan applicant data under a "legitimate use" instead of taking consent?
Generally no. Section 7 legitimate uses are a closed list, and none of them covers commercial lending, credit assessment, cross-selling or collections the way Section 7(i) covers employment for employers. That leaves Section 6 consent as your ground: a specific, itemised, plain-language notice in English or any Eighth Schedule language, with withdrawal as easy as giving. Note also that DPDPA has no "sensitive personal data" category — your bank statements and credit reports are personal data, treated under the same single standard as a phone number.
A breach hits our LOS at 9 AM. What are the actual deadlines?
Two clocks start together, and they are cumulative, not alternatives. CERT-In requires reporting of covered cyber incidents within 6 hours of detection. Separately, under DPDPA you must intimate affected borrowers without delay (Rule 7(1)), give the Board an initial description without delay (Rule 7(2)(a)), and give detailed particulars within 72 hours (Rule 7(2)(b)). As an RBI-regulated entity, your incident-reporting obligation to the Regulator runs alongside as well. Missing them is expensive twice over: failure to maintain reasonable security safeguards attracts up to ₹250 crore under Section 8(5), and failure to notify attracts up to ₹200 crore under Section 8(6) — assessed separately, so one incident can trigger both.
Are we a Significant Data Fiduciary? Do we need annual audits and DPIAs?
Only if the Central Government notifies you as one — SDF status is conferred by notification, based on factors like volume and sensitivity of data processed and risk to electoral democracy, sovereignty and public order. It is not automatic on AUM or borrower count. The additional Rule 13 obligations — annual DPIA and independent data audit, algorithmic due diligence, appointing an India-based DPO — bind SDFs only. Every other NBFC still owes the baseline duties: valid consent, purpose limitation, erasure, security safeguards, breach notification, and a working grievance channel.
See where your borrower data actually sits
A 30-minute call with our team: we walk your loan journey end to end — application, KYC, disbursal, collections, closure — and show you which processing has a lawful ground under Section 6, where retention has outlived its purpose, and whether your DSA and LSP contracts would survive scrutiny. You leave with a written gap list, whether or not you work with us.
Book a demo call
Free Gap Analysis
No pitch deck. Bring your consent notice and one DSA agreement.
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.