DPDPA for Fintech and NBFCs: Speed Is Not a Consent Strategy
DPDPA for Fintech and NBFCs: Speed Is Not a Consent Strategy
Fast onboarding. Slow consequences.
The scene
The app asked for contacts, location, SMS and storage in one screen. Approval rates were excellent. The credit model used SMS parsing no customer had been told about. When the first customer asked what data the app held, nobody could export it in under a week.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
If the user allows the permission, we have consent.
An OS permission is not a notice; it does not state purpose.
Pair every permission with a purpose the customer can read and refuse.
Alternative data is our edge.
Data collected for one purpose cannot quietly feed another.
Declare the scoring purpose up front, or do not use the data.
The LSP handles collections.
Lending service providers act on your behalf; their conduct is your exposure.
Treat every LSP as a processor under contract and audit.
Account aggregators as a model
India's account aggregator framework already runs on granular, revocable, purpose-bound consent. It is the closest existing picture of what DPDPA consent should feel like.
The full Fintech & NBFC briefing 3 deep dives
Deep dive 01 →
Permission is not consent. It is only access.
‘Allow’ opens the door. It does not tell the customer what you will do inside.
Deep dive 02 →
The model knows things the customer was never told.
A secret input is not a competitive advantage. It is a finding.
Deep dive 03 →
The consent model already exists. Copy it.
India built the right consent once. Now build it everywhere.
Monday morning
01 List every app permission and the purpose it serves.
02 Remove any permission whose purpose you cannot write in one line.
03 Audit the top three lending service providers for data handling.
Questions, answered plainly
Is an Android or iOS permission valid consent under DPDPA? +
An operating-system permission grants technical access; it does not by itself provide the notice of purpose and the specific consent Section 5 and Section 6 require. Apps should pair permissions with a clear notice and choice.
Are lending service providers Data Processors under DPDPA? +
Where they process borrower data on behalf of a regulated lender, they generally act as Data Processors, and the lender as Data Fiduciary remains responsible under Section 8(1).
Sector · Healthcare & Pharma The Act has no 'sensitive' category. Your patients do. Read →
Sector · EdTech A child's data is not a cookie. Stop treating it like one. Read →
Sector · E-commerce & D2C Your funnel runs on consent. The Act just redefined consent. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).
