Section 17(1) disapplies Chapter II (except sections 8(1) and 8(5)), Chapter III and section 16 in specified situations. Clause (f) covers processing:
for the purpose of ascertaining the financial information and assets and liabilities of any person who has defaulted in payment due on account of a loan or advance taken from a financial institution, subject to such processing being in accordance with the provisions regarding disclosure of information or data in any other law for the time being in force.
The Act's explanation ties "default" and "financial institution" to the meanings in sections 3(12) and 3(14) of the Insolvency and Bankruptcy Code, 2016. Its illustration is direct: an individual takes a loan from a bank and defaults on a monthly instalment; the bank may process her personal data to ascertain her financial information, assets and liabilities.
Read the boundaries carefully, because this exemption is narrower than recovery teams tend to assume:
A recovery function relying on this needs the purpose limitation encoded, not assumed. Processing a defaulter's data for cross-sell because the exemption was available for recovery is outside it.
Section 12 gives a Data Principal the right to erasure — unless retention is necessary for the specified purpose or for compliance with any law for the time being in force.
For a bank, NBFC, insurer or payment aggregator, that exception swallows a large part of the right. Indian financial regulation is dense with retention obligations.
| Source | Broadly requires retention of |
|---|---|
| RBI Master Directions on KYC | Customer identification and due diligence records, transaction records |
| Prevention of Money-Laundering Act and rules | Client identity records, transaction records |
| RBI payment aggregator and gateway directions | Transaction and merchant records |
| Income-tax Act and rules | Books of account and supporting documents |
| Companies Act, 2013 | Books of account and statutory registers |
| IRDAI regulations | Policyholder, proposal and claims records |
| SEBI regulations | Client and transaction records for registered intermediaries |
| Credit information regulation | Credit information reported to bureaux |
The wrong responses are both common. Refusing the whole request because "we're regulated" is not compliant — data outside a mandate must still be erased. Deleting everything because the customer asked is worse, because it destroys records a regulator requires.
The correct response is purpose-scoped: erase what no mandate covers, retain what is mandated, restrict the retained data to the retention purpose only, and record the mandate you relied on. That last step matters — under section 33(2) the timeliness and effectiveness of your action is an express factor in penalty determination.
This requires a retention register: data category, purpose, retention rule, source instrument, and a review date for when the instrument changes. A policy paragraph will not survive an audit. → Retention & Erasure
BFSI processing splits into three buckets, and conflating them is the most common design error.
Mandated processing. KYC, AML screening, regulatory reporting, credit bureau submission. These rest on compliance with law, not consent. Asking for consent you don't need — and cannot honour a withdrawal of — creates a worse position than relying on the correct basis, because withdrawal then becomes a request you must refuse.
Service delivery processing. Operating the account, executing transactions, servicing the product. Substantially covered by data voluntarily provided for the specified purpose under section 7, within the bounds of that purpose.
Discretionary processing. Marketing, cross-sell, propensity modelling, analytics, partner sharing. This needs specific, unbundled consent under section 6, with withdrawal at comparable ease.
The line to hold: you cannot make a regulated product conditional on consent to discretionary processing. Consent must be unconditional and free, and a loan application that requires marketing consent to proceed fails both tests.
Section 10 allows the Central Government to notify a Data Fiduciary or class as a Significant Data Fiduciary based on factors including the volume and sensitivity of personal data processed, risk to Data Principals' rights, and potential effects on the security of the State and public order.
No threshold triggers this automatically — designation follows notification. But large banks, insurers and payment aggregators are plainly within the contemplated population, and the additional obligations take time to stand up:
The DPO's accountability line to the board is worth noting: it is an internal governance relationship, which is why a wholly outsourced arrangement requires careful structuring rather than a service contract. Institutions should plan on the assumption of designation rather than waiting for it.
The Schedule's largest penalty — up to ₹250 crore — attaches to breach of the section 8(5) obligation to take reasonable security safeguards to prevent a personal data breach. Failure to notify a breach under section 8(6) sits at up to ₹200 crore.
For BFSI this compounds an existing obligation set. DPDP breach intimation and CERT-In's incident direction are separate regimes with different triggers, timelines and recipients, and RBI incident reporting is a third. An incident response process built for one will not satisfy the others, and all of them attach to you rather than to your technology vendor.
Consiva holds the retention register with its source instruments, flags erasure conflicts at the point of request, records the basis per purpose, and produces the closure artefact. Determining which mandate applies, and resolving a conflict between instruments, is legal work — that determination is yours, and where a period is contested it belongs with counsel.
Consiva's retention register, erasure-conflict flagging and the SDF module (DPO workflow, DPIA templates, annual audit readiness) sit on the Enterprise plan, with on-premise deployment available. Determining which mandate applies, and resolving conflicts between instruments, is legal work that stays with you and your counsel. → Pricing
Yes. They are Data Fiduciaries for customer personal data and carry the full Chapter II obligations, subject to specific exemptions including section 17(1)(f) for processing a defaulter's financial information.
Where retention is necessary for compliance with any law, yes — and RBI, PMLA, tax and company law mandates frequently apply. Data outside any mandate must still be erased, and the refusal must be explained and documented.
It permits processing to ascertain the financial information, assets and liabilities of a person who has defaulted on a loan or advance from a financial institution, subject to disclosure provisions in other law. "Default" and "financial institution" take their IBC meanings.
KYC is mandated by law, so compliance with law rather than consent is the appropriate basis. Seeking consent for mandated processing creates a withdrawal you cannot honour.
Designation requires notification under section 10 and no threshold triggers it automatically, but the factors listed clearly contemplate large financial institutions. Given the lead time for a DPO, independent audits and periodic DPIAs, planning on the assumption is prudent.
No. Three separate regimes with different triggers, timelines and recipients. An incident process must satisfy all applicable ones from a single detection event.
Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 8, 10, 12, 17(1)(f) with its explanation and illustration, 33(2) and the Schedule. Sectoral retention periods must be confirmed from the applicable instrument. Reference material about the law, not legal advice — see /disclaimer.
Consiva.ai covers every obligation above with pre-configured workflows, templates, and automated jobs — purpose-built for India's data protection law.
Start Free — No Credit Card →