Become a member

Get the best offers and updates relating to Liberty Case News.

― Advertisement ―

spot_img

DPDP E-Commerce Customer Data: What Online Retailers Must Know

The DPDP Act transforms how Indian online retailers handle DPDP e-commerce customer data — here is what every founder and marketplace seller must do now.
HomeLaw for YouDPDP Fintech RBI Compliance India: What You Must Know

DPDP Fintech RBI Compliance India: What You Must Know

In short: DPDP fintech RBI compliance India is now a dual mandate. The Digital Personal Data Protection Act, 2023 and the DPDP Rules notified in November 2025 sit alongside RBI’s sectoral framework. Fintechs must navigate explicit consent rules, legitimate-use carve-outs for KYC, and a phased compliance timeline running to May 2027.

Key points

  • The DPDP Act was enacted in August 2023, but the operative DPDP Rules were only notified by MeitY on 13 November 2025 and published in the Gazette on 14 November 2025.
  • Implementation is phased across three stages: the Data Protection Board was instituted in November 2025, Consent Manager registration begins by November 2026, and full compliance duties — including notice, security, breach notification, and Data Principal rights — kick in by 13 May 2027.
  • Until May 2027, the IT Act, 2000 and the SPDI Rules, 2011 continue to govern data protection in parallel with the DPDP framework.
  • Section 6 of the DPDP Act requires consent to be free, specific, informed, unambiguous, and unconditional — and prohibits bundled consent for unrelated purposes.
  • RBI-mandated KYC data collection falls under a “legitimate use” carve-out and does not require fresh consent; however, any secondary use of that data — marketing, profiling, cross-selling — requires separate, explicit, and revocable consent.
  • Fintech platforms face a dual compliance mandate: the DPDP Act does not replace RBI’s sectoral rules; both apply simultaneously.

What is the DPDP Act and why does it matter for fintechs?

The Digital Personal Data Protection Act, 2023 (DPDP Act or DPDPA) was enacted by Parliament in August 2023. For most of its life it sat largely dormant — its practical application only became clear after draft Rules were published for consultation in January 2025.

The DPDP Rules, 2025, notified on 13 November 2025, are the operative instrument that gives the Act full effect. They build a structured, practical system to protect personal data in a rapidly expanding digital economy — and fintech is squarely in scope.

If your business collects, stores, or processes any personal data of individuals in India — loan applications, credit scores, bank account details, UPI transaction history — you are a Data Fiduciary under the Act, with binding obligations.

What does the phased implementation timeline mean for your compliance planning?

Many founders assume the DPDP Act is already fully in force. It is not. Understanding the three stages is essential for prioritising your compliance roadmap.

StageDateWhat happens
Stage 113 November 2025Data Protection Board of India constituted
Stage 213 November 2026 (12 months)Consent Manager registration process implemented
Stage 313 May 2027 (18 months)Full compliance duties apply: notice, security, breach notification, Significant Data Fiduciary obligations, Data Principal rights

Critically, until Stage 3 takes full effect, the IT Act, 2000 and the Sensitive Personal Data or Information (SPDI) Rules, 2011 continue to govern data protection obligations in parallel. You cannot ignore them in the interim.

How does the DPDP Act’s consent framework change the way fintechs collect data?

Section 6 of the DPDP Act sets a high bar. Consent must be free, specific, informed, unambiguous, and unconditional — and it must be given through a clear affirmative action. Passive tick-boxes or pre-filled forms will not meet this standard.

Equally important: consent must be limited to personal data that is necessary for the specified purpose. This strikes directly at a common fintech practice — bundling consent for multiple, unrelated uses into a single terms-and-conditions acceptance. The Act signals that bundled consent of this kind is not permissible.

In practical terms, if you want to use a customer’s data for loan underwriting, that is one consent. If you also want to use it for insurance cross-selling or third-party marketing, that is a separate consent — specific, separately obtained, and independently revocable.

What about data you collect because RBI requires it?

This is where fintech compliance gets more nuanced. The DPDP Act does not operate on consent alone. Section 7 enumerates categories of “legitimate uses” — situations where personal data may be processed without consent.

RBI-mandated KYC collection is one such legitimate use. When you collect the minimum data required by the KYC framework, the legal basis is your regulatory obligation, not the customer’s consent. You do not need to obtain a fresh, DPDP-style consent notice for that specific collection.

However — and this is the critical line — the moment you step outside that regulatory purpose, the exemption ends. Using KYC data for marketing, profiling, or cross-selling requires explicit, specific, separately obtained consent that the customer can revoke at any time.

What is the “dual compliance mandate” and why does it matter for RBI-regulated entities?

Fintechs operating under an RBI licence — NBFCs, payment aggregators, account aggregators, digital lenders — face a dual compliance mandate. The DPDP Act does not replace RBI’s data-related directions, guidelines, and master circulars. Both frameworks apply simultaneously.

This means compliance teams must map every data flow against two sets of requirements. Where the two frameworks overlap, you must satisfy the stricter standard. Where they conflict, legal advice is essential — the resolution will depend on the specific provision and the nature of the processing activity.

For a broader overview of how Indian data and consumer protection laws interact across sectors, the Law for You guides at The Courtroom offer plain-language starting points across a range of regulatory areas.

What should your compliance team prioritise right now?

Before November 2026

Begin mapping your data flows and identifying which processing activities rest on consent versus legitimate use. Assess whether your current consent mechanisms meet the “free, specific, informed, unambiguous, unconditional” standard under Section 6.

Before May 2027

Build or procure systems for notice delivery, consent management, data breach notification, and responding to Data Principal rights requests. If your scale or data sensitivity may qualify you as a Significant Data Fiduciary, seek legal advice on the additional obligations that status will carry.

Do not wait until May 2027 to start. Retrofitting consent architecture and internal processes across a live fintech product is time-consuming and expensive. The organisations that begin now will find Stage 3 manageable; those that wait will not.

Frequently asked questions

Is the DPDP Act already fully in force for fintech companies in India?

Not yet in full. The DPDP Rules were notified on 13 November 2025 and the Data Protection Board was constituted on the same date. However, the core operational obligations — including notice requirements, breach notifications, security protocols, and Data Principal rights — only become mandatory at Stage 3, which is 13 May 2027. Until then, the IT Act, 2000 and the SPDI Rules, 2011 continue to apply alongside the emerging DPDP framework.

Does a fintech need fresh DPDP consent every time it collects KYC data as required by RBI?

No — not for the minimum data required by the RBI KYC mandate. That collection is treated as a “legitimate use” under Section 7 of the DPDP Act because the legal basis is a regulatory obligation, not the customer’s consent. However, any use of that KYC data beyond its regulatory purpose — for example, for marketing, profiling, or cross-selling — requires separate, explicit, and revocable consent under Section 6.

Can a fintech app bundle all data-use consents into a single terms-and-conditions acceptance?

The DPDP Act strongly signals that this approach is not permissible. Section 6 requires consent to be specific — limited to the personal data necessary for a stated purpose. Bundling consent for multiple, unrelated uses into a single acceptance is inconsistent with this requirement. Fintechs should design separate, purpose-specific consent flows for each distinct category of data use.

Primary sources

Written by Editorial Team, The Courtroom · Last verified 2026-07-14

This article is for general information only and is not legal advice. Laws change; verify against the primary sources cited and consult a qualified advocate for your situation.