Sector guide
Financial services already sit under RBI, IRDAI and SEBI data rules, so the DPDP Act lands on an existing regime rather than an empty one. The work is mostly reconciliation: the Act adds consent, purpose limitation and data principal rights on top of retention and localisation obligations that were written for a different purpose and sometimes pull the other way.
Three tensions come up in every BFSI programme, and none of them resolve by choosing one regulator over the other.
BFSI data estates are old, and the risk concentrates in the parts nobody inventoried.
Start with the purpose register rather than with consent screens. Until each processing activity has a stated purpose and a recorded lawful basis, consent UX built on top of it will encode the wrong model and have to be rebuilt.
Then map the agent and aggregator channels. That is where personal data enters without passing your own front door, and it is the part of the estate most often missing from a first inventory.
Yes. Any entity determining the purpose and means of processing digital personal data of individuals in India is a Data Fiduciary, NBFCs included, regardless of existing RBI obligations.
They can make the request, but erasure does not override a statutory retention obligation such as KYC or transaction record-keeping. You must be able to show which records are retained, under which legal basis, and for how long.
Often not. A great deal of BFSI processing rests on legal obligation rather than consent. Recording the correct basis matters, because labelling a legal-obligation activity as consent-based creates a withdrawal right you cannot honour.
Jupinder Bedi — Jupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →