A Practical Guide to DPDP Compliance for Digital Lenders

The DPDP Act and RBI's digital lending rules now regulate how digital lenders handle borrower data. This guide walks you through what changes at each stage of the lending journey and what you need to do about it.

Cover of the guide: A Practical Guide to DPDP Compliance for Digital Lenders

What's inside

Data fiduciary or data processor?

What role you, the LSP, your KYC vendor and your co-lender play under the DPDP Act.

Consent collection

What a valid notice must contain, and how to design one that is compliant without increasing drop offs in your customer journey.

Borrower rights

The six things a borrower can ask you to do with their data, and what your systems have to do in response.

Deletion vs retention

What to do when DPDP says erase and RBI says keep.

LSPs, co-lenders and vendors

How to move data between each of these without a consent gap.

Breach response

The 72-hour clock, what to send to whom, and the logs that prove you complied.

Questions the guide answers

Do I need to collect consent for KYC if RBI mandates it anyway?

Yes, a purpose being mandatory doesn't remove the consent requirement under DPDP or RBI's own rules. Only the consequence of refusal changes, if the borrower declines, you can end the journey there and not provide them the service.

RBI wants me to retain data but the borrower is asking me to delete it. What do I do?

You can retain it. Section 8(7) of the DPDP Act allows retention where another law requires it. However, you have to tell the borrower why you are retaining it, use it for nothing else and delete when the retention period ends.

Do I need a registered Consent Manager? Is there one yet?

No, and no. Zero registered consent managers exist today and the registration window only opens on 13 Nov 2026. You do not need a Consent Manager, the borrower chooses the Consent Manager, not you.

Is my fintech / LSP a data fiduciary or a data processor?

It is almost always a data fiduciary. If you decide what data is collected and how it's used, you're a fiduciary, independently accountable alongside the RE. A KYC vendor acting only on your instructions is a processor.

Can my LSP collect consent on behalf of the RE, and is that legal under DPDP?

Yes. While RBI's Credit Facilities Directions require explicit consent before data transfer to a third party, the DPDP doesn't specify which party must collect it. In practice, this can be done by the first Data Fiduciary by collecting consent for its own processing, transfer of data and the receiving RE's purposes.

What counts as a data breach, and when does the 72-hour clock start?

Any unauthorised processing or accidental disclosure/loss/alteration is a data breach including emailing a sanction letter to the wrong borrower or a lost field-agent phone. The 72-hour clock starts when you become aware of the breach.

Can I use the research exemption for borrower analytics and marketing?

No. The research and statistics exemption bars individual-level decisions, so using it to profile borrowers or target products isn't permitted.

A peek inside the handbook

How to build a consent notice

Handbook page showing how to build a consent notice

Breach response timeline

Handbook page showing the breach response timeline

Get the guide

Built for compliance, tech, and product teams at NBFCs, fintechs, and banks to know exactly what the DPDP Act and RBI's directions change at every step of the lending journey.

Download the guide (PDF)
arrow icon

No email required.

Written by the team behind Consentin

Consentin is a DPDP compliance platform for consent collection, rights management, retention and deletion, vendor risk and breach response. It is built by Leegality, and used by Union Bank of India, YES Bank, SBI Card, IIFL and Chola, among others.

Talk to us

Compliance Deadline:

0 weeks away