The regulatory intersection: DPDPA and RBI
Fintech operates under two compliance regimes that apply simultaneously:
| Area | DPDPA requirement | RBI requirement |
|---|---|---|
| Consent for data collection | Section 6: free, specific, informed, unconditional, unambiguous | Digital Lending Guidelines: explicit consent before accessing data |
| Data access scope | Section 5: itemised notice of each purpose | Digital Lending Guidelines: no access to contacts, photos, media files |
| Retention | Section 8(7): erase when purpose is fulfilled | RBI directions on data retention for regulatory purposes |
| Cross-border transfers | Section 16: restricted countries | RBI data localisation: payments data must be stored in India |
| Breach notification | Section 8(6), Rule 7: Board and Data Principals | RBI incident reporting requirements |
Where RBI requirements are stricter (for example, data localisation for payments data), both must be met. Where DPDPA requirements are stricter (for example, purpose-level consent), both must be met. There is no override.
Reconciling three consent regimes
A fintech platform may need to manage three consent frameworks simultaneously:
- DPDPA Section 6 consent: for each processing purpose, with withdrawal as easy as giving.
- RBI Account Aggregator consent artefact: for accessing financial data through the AA framework.
- DPDPA Rule 4 Consent Manager: a registered intermediary for managing consent across Data Fiduciaries.
The consent management architecture must handle all three without creating a fragmented user experience. The notice under Section 5 must cover every purpose, including those served by the AA consent artefact.
Alternative data and credit scoring
Some fintech lenders use alternative data for credit scoring: social media activity, device data, app usage patterns, transaction frequency. Under DPDPA:
- Each data source is a processing purpose that requires either consent (Section 6) or a legitimate use (Section 7).
- The Section 5 notice must itemise each alternative data source and explain how it is used.
- If any data comes from children (users under eighteen), Section 9 applies: no tracking, no behavioural monitoring, verifiable parental consent.
- Device data access (contacts, location, SMS) is already restricted by RBI Digital Lending Guidelines. DPDPA adds the consent and notice requirements.
Significant Data Fiduciary notification for large fintech
Section 10(1) allows the Central Government to notify Data Fiduciaries as Significant Data Fiduciaries considering the volume and sensitivity of data processed. Large fintech companies and NBFCs with millions of users are likely candidates.
If notified, the additional duties apply: DPO based in India, independent data auditor, annual DPIA and audit, and Board reporting under Rule 13.
How AMLEGALS advises fintech on DPDPA
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder & Managing Partner. The team includes Rohit Lalwani, Associate Partner, who works on DPDPA compliance.
The team maps the intersection of DPDPA and RBI requirements, designs the consent architecture for multiple regimes, assesses alternative data practices against the Act, and prepares for potential SDF notification.

