ConsentKit DPDP

For NBFCs, lending apps, fintech and cooperative banks

DPDP compliance for NBFCs and fintech

Lending needs data, and RBI rules already tell you how to handle much of it. The DPDP Act adds a layer on top: specific consent for each purpose, limits on reuse, rights for borrowers and a 72-hour breach clock. ConsentKit fits the DPDP layer alongside your existing RBI and KYC processes.

KYC retention
Still as RBI and PMLA require
Cross-selling
Needs its own consent
Breach report
Within 72 hours
app.swiftcredit.inLoan application

SwiftCredit asks for your consent

We need some data to assess and service your loan. The rest is your choice.

Withdraw consent anytime
Consent logRecording

    Where the DPDP Act touches a loan

    Some data you keep because RBI or PMLA says so. Some needs the borrower’s consent. Pick a stage to see which is which.

    What changes for lenders on 13 May 2027

    RBI compliance does not equal DPDP compliance. These duties sit on top of what you already do.

    Consent per purpose, not per agreementSections 5 and 6

    Loan servicing, bureau checks, cross-selling and partner sharing are separate purposes. One signature for all of them won’t hold up.

    Itemised notices in your app and journeys, with a consent record per purpose.

    Collect only what the loan needsSection 6(1)

    Consent is limited to data necessary for the specified purpose. Broad app permissions are hard to justify.

    A purpose register that maps each data point to its use.

    DSAs, agencies and partners are coveredSection 8

    DSAs, collection agencies, co-lenders and tech vendors process borrower data for you. You remain responsible.

    A partner register, processor contracts and consent checks before sharing.

    Borrowers can ask for their dataSections 11 to 14

    Borrowers can request access, correction and erasure where law allows, and file grievances.

    A rights portal that respects RBI retention while handling DPDP requests.

    Security and breach reportingSection 8(5) and Rules 6 and 7

    Access logs kept for at least a year, and breaches reported to the Board and to borrowers, alongside CERT-In and RBI reporting.

    A breach workflow that produces the DPDP report next to your other filings.

    Large lenders may be Significant Data FiduciariesSection 10 and Rule 13

    If notified, you need a DPO in India, annual audits and impact assessments.

    Audit trail and evidence exports for your DPO and auditors.

    When the law requires you to keep data

    The DPDP Act does not override other laws. Where RBI, PMLA, IRDAI or tax rules require you to collect or keep records, that duty stands, and a customer’s erasure request does not remove it. What changes is that you must be clear about which data you keep for which law, and stop using it for anything else.

    Kept because a law requires itKYC records, transaction records, records needed for audits, tax and regulator inspections.
    Needs consent or must goCross-selling, sharing with marketing partners, old leads and rejected applications.

    This is general guidance, not legal advice. Confirm how it applies to you with your counsel.

    A plan that fits alongside RBI compliance

    Most lenders already have KYC and grievance processes. Build the DPDP layer on top rather than from scratch.

    1. Purpose and data inventory

      Map every data point to a purpose and a basis: RBI or PMLA, contract, or consent.

    2. Rework journeys

      Split consents in app and web journeys and reduce app permissions.

    3. Partners and DSAs

      Update DSA, collection agency and co-lending contracts and add consent checks.

    4. Rights and breach readiness

      Connect rights requests to your grievance desk and rehearse breach reporting.

    For every kind of lender

    Templates for your lending model.

    NBFCs

    Branch and digital journeys, DSAs and collections.

    Digital lending apps

    App permissions and lending service providers.

    Microfinance

    Group lending and field officers.

    Cooperative banks

    Branch-heavy, legacy core banking systems.

    Payments and wallets

    Transaction data and merchant sharing.

    Wealth and broking

    Investor KYC and advisory data.

    Questions lenders are asking

    For the full picture, read our DPDP Act guide or compliance checklist.

    Do RBI rules override the DPDP Act?

    No, they sit side by side. Where RBI or PMLA requires you to keep data, you keep it. The DPDP Act adds consent, purpose limits, rights and breach duties on top.

    Can a borrower ask us to delete their KYC?

    You can refuse to erase data you must keep by law, but you should explain that, stop any other use of it and delete it when the legal period ends.

    Can we cross-sell insurance to borrowers?

    Only with separate consent for that purpose. It cannot be a condition of the loan.

    Are our DSAs covered?

    Yes. When DSAs act for you, they are your processors and you remain responsible. Bind them by contract and audit them.

    Do we need a Data Protection Officer?

    Only if you are notified as a Significant Data Fiduciary. Every lender must publish a contact for data questions and grievances.

    Add the DPDP layer before May 2027

    The readiness check takes about ten minutes and gives you a gap report built for lenders.