Your DSA's phoneis inside your perimeter.
Banks built walls around the core. The data left through the partners.
In one line: When they process borrower data on behalf of a bank or NBFC, they generally act as Data Processors. The lender, as Data Fiduciary, remains responsible for compliance under Section 8(1).
The bank signs the licence. The agent holds the phone. The customer holds you responsible.
The scene
A collection agent had the borrower's address, phone, loan balance and three emergency contacts on a spreadsheet emailed from the branch. The borrower's brother-in-law received the call. He had never been asked if he minded being in the file.
Where the thinking breaks
Co-lending and shared customers
Where two lenders share a borrower, map who decides purpose for each activity. Both may be fiduciaries for different parts. Put it in writing before the first complaint.
Monday morning
- 01List every partner category that receives customer data.
- 02Check which have processing clauses aligned to DPDPA.
- 03Stop spreadsheets leaving branches by email.
Questions, answered plainly
Are collection agents Data Processors under DPDPA?
When they process borrower data on behalf of a bank or NBFC, they generally act as Data Processors. The lender, as Data Fiduciary, remains responsible for compliance under Section 8(1).
Can a lender call a borrower's references or relatives?
Processing a third person's personal data needs a lawful basis of its own. Lenders should limit collection and use of reference contacts and follow applicable RBI conduct rules.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner