7 October 2026 · DPDP Act · Banks & NBFCs

DPDP Act for Banks and NBFCs: Aligning Privacy with RBI Expectations

By CA Ratan Singh Tanwar · Chartered Accountant, Bhilwara

Banks and NBFCs hold some of the most sensitive personal data in the economy: KYC documents, PAN and Aadhaar details, account statements, loan files, income proofs and transaction histories. The Digital Personal Data Protection Act, 2023 (DPDP Act) now adds a privacy layer on top of the RBI framework these institutions already follow.

The good news is that a well-run regulated entity already has many of the building blocks. The challenge is connecting them to DPDP obligations and being able to prove it.

Where DPDP meets existing RBI requirements

  • Retention: RBI KYC norms require records to be preserved for at least five years after the business relationship ends. DPDP permits retention where another law requires it, but data kept beyond that period without a reason becomes a liability.
  • IT governance: RBI’s directions on IT governance, risk, controls and assurance already demand access control, logging and information security policies. These directly support DPDP’s “reasonable security safeguards” obligation.
  • Incident reporting: Cyber incidents may already need reporting to RBI and to CERT-In within 6 hours. A personal data breach also requires intimation to the Data Protection Board and to affected customers.

Gaps we commonly see

  • No consolidated inventory of where customer personal data sits across core banking, LOS, CRM, email and branch-level files.
  • Marketing, cross-selling and analytics using KYC data without a clear purpose or consent trail.
  • Recovery agents, DSAs, call centres and fintech partners receiving customer data without strong contractual and technical controls.
  • Customer requests for correction or erasure handled ad hoc, with no tracked turnaround.

A practical roadmap

  • Map personal data by product, process and system.
  • Record the lawful basis for each purpose: consent, legal obligation or other legitimate use.
  • Refresh customer notices in clear language, including regional languages where relevant.
  • Review every third party that processes customer data and update agreements.
  • Integrate DPDP breach intimation into the existing incident response plan.
  • Include DPDP controls in the IS audit and internal audit scope.
Key takeaway: For banks and NBFCs, DPDP is not a separate project. It should be built into IS audit, RBI compliance and vendor risk management, so that one set of controls produces evidence for every regulator.
Need a DPDP readiness review?
Gap assessment, data mapping and IS audit support from CA Ratan Singh Tanwar, Bhilwara.
Request a Consultation →

← Back to all articles · 25 DPDP FAQs