AMLEGALS — Strategic Lawyering

Account Aggregators and DPDPA: India's Working Model of Granular Consent

Account Aggregators and DPDPA: India's Working Model of Granular Consent

India built the right consent once. Now build it everywhere.

The scene

The same customer used two products from the same company. In one, she shared bank statements through an account aggregator: purpose, period and expiry shown on one screen, revocable in two taps. In the other, she ticked a box beside eleven pages of terms. Same company. Same legal team.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Account aggregator consent is only for AA flows.

It is the clearest working example of what DPDPA consent should look like.

Use the AA consent artefact as the design pattern for all consent.

Granular consent kills conversion.

Unclear consent kills defensibility; conversion built on it is borrowed.

Measure conversion on consent the customer understood.

What to borrow

A stated purpose. A stated period. A stated frequency of access. An expiry. A one-step revocation. A log of all of it. That is most of Section 6 in six lines.

Monday morning

01 Put your main consent screen beside an AA consent screen.

02 Mark every element the AA screen has that yours lacks.

03 Ship one of them this sprint.

Questions, answered plainly

How does the account aggregator framework relate to DPDPA? +

Account aggregators operate under RBI regulation using consent artefacts that specify purpose, duration and revocation. The model closely reflects DPDPA's requirements for specific, informed and withdrawable consent.

Are account aggregators consent managers under DPDPA? +

They are distinct concepts. Consent managers are registered with the Data Protection Board under DPDPA. The Rules set their registration conditions.

Sector · Fintech & NBFC Your onboarding takes ninety seconds. Your liability lasts years. Read →

Fintech & NBFC · Deep dive Permission is not consent. It is only access. Read →

Fintech & NBFC · Deep dive The model knows things the customer was never told. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).