Introduction
India’s Fintech sector operates in one of the most heavily regulated environments in the world. Between the Reserve Bank of India (RBI), the Securities and Exchange Board of India (SEBI), and various payments authorities, fintech companies are accustomed to strict compliance. However, the introduction of the Digital Personal Data Protection (DPDP) Act, 2023, adds a new, complex layer of regulation that occasionally appears to conflict with existing financial mandates.
Navigating the intersection of financial regulation and data privacy requires a nuanced understanding of where the DPDP Act yields to sectoral laws and where it imposes new obligations. This article explores the primary compliance friction points for Fintech.
The Clash of Data Retention vs. Data Erasure
The most significant conflict lies in data lifecycle management. The DPDP Act Champions the Right to Erasure and the principle of storage limitation—once the purpose of processing is fulfilled, personal data should be deleted.
Conversely, financial regulators mandate long-term data retention. The Prevention of Money Laundering Act (PMLA) and RBI guidelines often require financial institutions to retain customer KYC (Know Your Customer) records and transaction data for 5 to 10 years after the business relationship ends, primarily for anti-fraud and audit purposes.
The Resolution: Section 8(4) of the DPDP Act provides a clear exception. A Data Fiduciary must erase personal data unless such retention is necessary for compliance with any law for the time being in force. Therefore, if a user demands the deletion of their data, a fintech app must delete their marketing profile and behavioral data, but is legally obligated to retain their KYC and transaction logs to satisfy the RBI.
Data Localization: RBI vs. DPDP
The DPDP Act surprised many by adopting a relatively relaxed stance on cross-border data transfers, moving away from strict localization to a "negative list" approach (transfers are allowed everywhere except restricted countries).
However, Fintech companies cannot take advantage of this relaxed rule for their core payment data. The RBI’s April 2018 directive on the Storage of Payment System Data strictly mandates that all data relating to payment systems must be stored in systems located only in India.
The Resolution: The DPDP Act explicitly states that if any other law provides for a higher degree of protection or restriction on the transfer of personal data outside India, that law shall prevail. For payment data, the RBI’s strict localization rules override the DPDP Act’s liberal transfer policy.
Alternative Scoring and Consent
Many innovative fintechs use alternative data (like SMS logs, social media behavior, or GPS data) for credit scoring. Under the DPDP Act, collecting this data requires explicit, informed, and specific consent.
Fintechs must clearly articulate in their Privacy Notices that accessing a user's SMS inbox is specifically for assessing creditworthiness. Crucially, under the DPDP Act, users have the right to withdraw this consent. If a user withdraws consent for SMS access halfway through a loan tenure, the fintech must have operational protocols in place to manage the risk without violating the user's privacy rights.
Conclusion
For Fintech companies, DPDP compliance is an exercise in dual-track governance. They must build data architectures capable of respecting the DPDP Act's emphasis on user consent and transparency while simultaneously satisfying the RBI's unyielding demands for auditability, retention, and localization. Success in this sector requires legal and engineering teams to work in lockstep to map every data point against both regulatory frameworks.