DPDP Rules 2025: Key Changes, Obligations & Implementation Guide
Read here
RBI DPDP Act Compliance for Banks banner
Compliance

RBI DPDP Act Compliance for Banks: KYC Data, Co-Lending, and Board Accountability

By Charanjeet Singh, Co-Founder, IndiaConsent

RBI DPDP Act Compliance for Banks: KYC Data, Co-Lending, and Board Accountability

Banks answer to two data regulators at once: the RBI, which has governed KYC, co-lending, and IT security for years, and the Data Protection Board of India, whose powers under the Digital Personal Data Protection Act, 2023 ("DPDP Act") are already active. The two regimes overlap but don't map onto each other cleanly — RBI's KYC and co-lending directions were written before the DPDP Act existed, and neither one tells a bank's compliance team who owns what when both apply to the same customer data. This post works through the three places that overlap creates real work: KYC data flows, co-lending data sharing between banks and NBFCs, and board-level accountability once a bank is classified as a Significant Data Fiduciary (SDF).

One fact worth stating plainly before anything else: Section 10 of the DPDP Act — the section that creates SDF obligations — is not yet in force. It comes into effect on 13 May 2027, eighteen months after the Act's staggered commencement began on 13 November 2025. Everything below about SDF duties describes what becomes mandatory on that date, not what's enforceable today. Banks that wait until then to start will be building under deadline pressure; the sections below are written as a 2026 preparation guide.

Where RBI and DPDP overlap for banks

RBI's rules and the DPDP Act regulate overlapping data with different vocabulary and different regulators. RBI's Master Directions were built around prudential risk, fraud prevention, and financial-system stability; the DPDP Act was built around an individual's rights over their own personal data. A bank following RBI's KYC and IT-governance rules to the letter can still fall short of DPDP obligations, because DPDP asks a question RBI's rules never had to: does the customer whose data this is have visibility into, and control over, how it's used beyond the purpose RBI mandated?

RBI instrumentWhat it requires todayWhere DPDP adds a distinct obligation
Master Direction – Know Your Customer (KYC) Direction, 2016 (as amended)Customer due diligence, identity verification via Aadhaar/PAN/officially valid documents, sharing verified KYC data via the Central KYC Records Registry (CKYCR)DPDP requires a lawful basis for each use of that data beyond the KYC purpose itself, and gives the customer (Data Principal) rights to access and correct it once Sections 11–13 come into force in May 2027
RBI (Co-Lending Arrangements) Directions, 2025Prompt sharing of borrower classification data (e.g. Special Mention Account/NPA status) between the originating and partner lender, a single customer-facing point of contactDPDP treats the bank and the NBFC as two separate Data Fiduciaries for the same borrower's data — the Act has no "joint controller" concept to allocate responsibility between them (more below)
Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (effective 1 April 2024)Board of Directors, IT Strategy Committee, and Audit Committee oversight of IT and information-security riskDPDP's Section 8(5) "reasonable security safeguards" duty applies on top of this — a breach can trigger a DPDP penalty (up to ₹250 crore) independently of any RBI enforcement action

KYC data flows: what changes once DPDP is fully in force

The immediate question compliance teams ask is whether KYC collection needs separate DPDP consent on top of what RBI already mandates. The honest answer is that this is still an open interpretive question, and IndiaConsent would rather say so than guess. Section 7 of the DPDP Act lists nine "certain legitimate uses" that let a Data Fiduciary process personal data without going through the full consent mechanism in Section 6. Two are directly relevant to banks: Section 7(a) covers data "voluntarily provided" by the customer for a specified purpose (arguably covering the KYC documents a customer hands over to open an account), and Section 7(d) covers processing needed "for fulfilling any obligation under any law for the time being in force in India to disclose information to the State" (arguably covering onward reporting to CKYCR, FIU-IND, or RBI itself). Neither clause was written with banking KYC specifically in mind, and the Data Protection Board hasn't yet issued guidance settling how they apply to it — so a bank's safest position is to document its legal basis for each stage of the KYC data lifecycle (collection, verification, CKYCR upload, ongoing monitoring) rather than assume one blanket justification covers all of it.

What isn't in doubt: once Sections 11–13 (Data Principal rights) come into force in May 2027, a bank's KYC customers will be able to request access to and correction of the personal data held about them, subject to the exceptions the Act and Rules carve out. That's a new operational surface — a request-handling workflow — that RBI's KYC framework never required banks to build.

Co-lending data sharing: a gap DPDP doesn't fill

Co-lending is where the overlap gets genuinely unresolved. Under the RBI (Co-Lending Arrangements) Directions, 2025, a bank and an NBFC originate and service a loan jointly, and RBI requires them to share classification data — if either lender flags a borrower as a Special Mention Account or NPA, the other must reflect that promptly. That's a mandated, ongoing personal-data-sharing pipeline between two separately regulated entities, built around a single borrower's financial and repayment history.

The DPDP Act has no clean answer for who's responsible for that shared data. Unlike the GDPR, which uses Article 26 to make two organisations "joint controllers" with defined, allocable liability when they jointly decide the purpose and means of processing, the DPDP Act doesn't operationalise this. Section 2(i) of the Act gestures at a Data Fiduciary acting "alone or in conjunction with other persons," but that phrase isn't developed anywhere else in the Act — there's no joint-and-several liability mechanism, no requirement for a joint-controller agreement, nothing equivalent to GDPR's Article 26. In practice, each co-lender is independently a Data Fiduciary for the data it processes, and if something goes wrong — a breach, a customer complaint about an unauthorised use — allocating responsibility between the bank and the NBFC falls entirely on whatever the co-lending agreement between them says, not on the statute.

For a bank's compliance team, the practical takeaway is that the co-lending agreement itself has to do work the DPDP Act won't: it should specify which party is the Data Fiduciary for which processing activity, how a data-breach notification obligation under Section 8(6) gets triggered and by whom, and how a Data Principal's access/correction request gets routed when the data lives in both parties' systems.

Board-level accountability: two boards, two separate duties

"Board" shows up twice in this framework, and conflating the two is an easy mistake with real compliance consequences.

The bank's own Board of Directors — under Section 10(2)(a)

Once a bank is classified as a Significant Data Fiduciary (not yet the case for any entity, but "almost certain" for banks given the Section 10(1) criteria — see below), Section 10(2)(a)(iii) of the DPDP Act requires the appointed Data Protection Officer to be "an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary." This DPO must also be based in India and serve as the organisation's point of contact for grievance redressal under the Act. This is an internal corporate-governance requirement — it puts data protection accountability at board level inside the bank, the same way RBI's IT Governance Master Direction already puts cybersecurity oversight at board level through the IT Strategy Committee and Audit Committee.

The Data Protection Board of India — under Rule 13(2)

Separately, Rule 13(2) of the DPDP Rules, 2025 requires a Significant Data Fiduciary to have its annual Data Protection Impact Assessment (DPIA) and data audit carried out, and to "furnish to the Board a report containing significant observations" from that assessment. Here, "the Board" — capitalised, as a defined term throughout the Act and Rules — means the Data Protection Board of India, the external regulator, not the bank's own board of directors. This is an external reporting obligation on top of the internal one, and the two shouldn't be described interchangeably: a DPO reporting internally to the Board of Directors satisfies Section 10(2)(a); furnishing the DPIA/audit report to the Data Protection Board of India is a separate duty under Rule 13(2).

Is a bank actually going to be classified as an SDF?

No bank has been formally notified as a Significant Data Fiduciary yet — the Central Government makes that designation under Section 10(1), based on factors including the volume and sensitivity of personal data processed, risk to Data Principals, and potential impact on the security of the State and public order. No notification has been issued as of this writing. That said, banks process exactly the profile of data the criteria describe — Aadhaar and PAN numbers, income and spending data, loan repayment history — at a scale few other sectors match, which is why compliance teams across the sector are treating SDF designation as a near-certainty to prepare for rather than a possibility to wait out.

What a DPDP breach costs a bank

The DPDP Act's Schedule sets penalty ceilings by provision, decided by the Data Protection Board of India on a case-by-case basis (these are ceilings, not fixed fines):

Provision breachedWhat it coversMaximum penalty
Section 8(5)Failure to take reasonable security safeguards, resulting in a personal data breach₹250 crore
Section 8(6)Failure to notify the Data Protection Board and affected Data Principals of a breach₹200 crore
Section 9Breach of additional obligations relating to children's data₹200 crore
Section 10Breach of a Significant Data Fiduciary's additional obligations (once in force)₹150 crore
Any other provisionGeneral catch-all₹50 crore

For a bank running a co-lending book or a large KYC dataset, the ₹250 crore ceiling under Section 8(5) is the one to plan around first — it applies to any Data Fiduciary regardless of SDF status, and it's already the section commencing alongside the rest of Chapter II obligations on 13 May 2027.

Compliance timeline: what's already law and what's coming

  • 13 November 2025 — DPDP Rules, 2025 notified (Gazette notification G.S.R. 846(E)); the Act's own staggered commencement began the same day (G.S.R. 843(E)), bringing into force the definitions, the Data Protection Board's establishment and powers (Sections 18–26), and related procedural sections.
  • 13 November 2026 — Section 6(9) and Section 27(1)(d) of the Act, and Rule 4 (Consent Manager registration), come into force.
  • 13 May 2027 — The core of the Act comes into force: Sections 3–10 (processing conditions, consent, children's data, and Significant Data Fiduciary obligations), Sections 11–17 (Data Principal rights and duties), and the corresponding Rules (3, 5–16, 22, 23) — including Rule 13's DPIA, audit, and board-reporting requirements.

That gives banks roughly until May 2027 to have consent architecture, DPO reporting lines, DPIA processes, and co-lending data-sharing agreements ready — not a deadline to build against starting in April 2027.

Frequently Asked Questions

Are Indian banks currently classified as Significant Data Fiduciaries under the DPDP Act?

Not yet — no entity has been formally notified as a Significant Data Fiduciary as of this writing, though banks are widely expected to be designated given the volume and sensitivity of the personal data they process.

When do Significant Data Fiduciary obligations actually become mandatory?

Section 10 of the DPDP Act and Rule 13 of the DPDP Rules, 2025 both come into force on 13 May 2027, eighteen months after the Rules were notified on 13 November 2025.

Does a bank's Data Protection Officer report to the Data Protection Board of India or to the bank's own board?

Both, but for different things — Section 10(2)(a)(iii) makes the DPO responsible to the bank's own Board of Directors or governing body, while Rule 13(2) separately requires the annual DPIA/audit report to be furnished to the Data Protection Board of India, the external regulator.

Who is liable if personal data is mishandled in a co-lending arrangement between a bank and an NBFC?

The DPDP Act doesn't have a "joint controller" concept like the GDPR does, so each co-lender is independently a Data Fiduciary for the data it processes — liability allocation depends on what the co-lending agreement between the two parties says, not on the statute.

What is the maximum penalty a bank could face for a data breach caused by inadequate security safeguards?

Up to ₹250 crore under Section 8(5) of the DPDP Act, read with the Act's Schedule, decided case-by-case by the Data Protection Board of India.


Related Articles & Internal Resources


Primary Sources Cited