AMLEGALS — Strategic Lawyering

Alternative Data Credit Scoring and DPDPA Purpose Limitation

Alternative Data Credit Scoring and DPDPA Purpose Limitation

A secret input is not a competitive advantage. It is a finding.

The scene

The credit model's best feature was the time of day customers charged their phones. It predicted default beautifully. The data came from an SDK installed for crash reporting. The privacy notice mentioned crash reporting.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

We collected it, so we can use it.

Purpose is set at collection; a new use needs a new basis.

Declare the scoring purpose in the notice, before collection.

It's anonymised inside the model.

If it is linked to an applicant's decision, it is personal data in use.

Treat model inputs as personal data and govern them as such.

Explaining a decision

DPDPA gives Data Principals the right to a summary of personal data processed and the processing activities. A lender that cannot say what fed a decision cannot answer that request.

Monday morning

01 List every input to the credit model and its source.

02 Match each source to the purpose declared at collection.

03 Retire inputs with no matching purpose.

Questions, answered plainly

Can fintechs use SMS data for credit scoring under DPDPA? +

Only if the purpose was clearly notified and the customer gave specific consent for it, and subject to RBI rules on app data access. Data collected for another purpose cannot be repurposed without a new basis.

Do customers have a right to know what data a lender used? +

Section 11 gives Data Principals the right to obtain a summary of personal data being processed and the processing activities undertaken.

Sector · Fintech & NBFC Your onboarding takes ninety seconds. Your liability lasts years. Read →

Fintech & NBFC · Deep dive Permission is not consent. It is only access. Read →

Fintech & NBFC · Deep dive The consent model already exists. Copy it. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).