DPDPA for Bank Partners: DSAs, Collection Agents and Business Correspondents
DPDPA for Bank Partners: DSAs, Collection Agents and Business Correspondents
The bank signs the licence. The agent holds the phone. The customer holds you responsible.
The scene
A collection agent had the borrower's address, phone, loan balance and three emergency contacts on a spreadsheet emailed from the branch. The borrower's brother-in-law received the call. He had never been asked if he minded being in the file.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Agents are separate legal entities.
Where they process for you, they are Data Processors and Section 8(1) keeps you responsible.
Contract every agent as a processor, with audit rights.
Emergency contacts consented through the borrower.
A third person's data needs its own basis; the borrower cannot consent for them.
Limit what you collect about third parties, and how you use it.
Co-lending and shared customers
Where two lenders share a borrower, map who decides purpose for each activity. Both may be fiduciaries for different parts. Put it in writing before the first complaint.
Monday morning
01 List every partner category that receives customer data.
02 Check which have processing clauses aligned to DPDPA.
03 Stop spreadsheets leaving branches by email.
Questions, answered plainly
Are collection agents Data Processors under DPDPA? +
When they process borrower data on behalf of a bank or NBFC, they generally act as Data Processors. The lender, as Data Fiduciary, remains responsible for compliance under Section 8(1).
Can a lender call a borrower's references or relatives? +
Processing a third person's personal data needs a lawful basis of its own. Lenders should limit collection and use of reference contacts and follow applicable RBI conduct rules.
Sector · Banking & BFSI Banks keep everything. The law now asks why. Read →
Banking & BFSI · Deep dive One incident. Three clocks start at once. Read →
Banking & BFSI · Deep dive The law says keep. The Act asks: keep what, exactly? Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).