The short answer: Financial services is the only sector with a DPDP exemption written around its own commercial problem: section 17(1)(f) permits processing to ascertain the financial information, assets and liabilities of a person who has defaulted on a loan or advance from a financial institution. Beyond that, BFSI's defining DPDP challenge is that sectoral retention mandates routinely override the erasure right.

DPDP for Banking & Financial Services

🏦 Sector: Banking, Financial Services & Insurance⚖️ Key provisions: s. 17(1)(f) defaulter exemption · s. 12 erasure subject to law · s. 8(5) safeguards · s. 10 SDF📅 In force: 13 May 2027
On this page
  1. The exemption drafted for lenders: section 17(1)(f)
  2. The central BFSI problem: erasure versus mandate
  3. Consent versus legitimate use: drawing the line
  4. Expect Significant Data Fiduciary designation
  5. Security is your highest exposure, not consent
  6. What to build, in order
  7. Where Consiva fits
  8. Frequently asked questions

The exemption drafted for lenders: section 17(1)(f)

Section 17(1) disapplies Chapter II (except sections 8(1) and 8(5)), Chapter III and section 16 in specified situations. Clause (f) covers processing:

for the purpose of ascertaining the financial information and assets and liabilities of any person who has defaulted in payment due on account of a loan or advance taken from a financial institution, subject to such processing being in accordance with the provisions regarding disclosure of information or data in any other law for the time being in force.

The Act's explanation ties "default" and "financial institution" to the meanings in sections 3(12) and 3(14) of the Insolvency and Bankruptcy Code, 2016. Its illustration is direct: an individual takes a loan from a bank and defaults on a monthly instalment; the bank may process her personal data to ascertain her financial information, assets and liabilities.

Read the boundaries carefully, because this exemption is narrower than recovery teams tend to assume:

A recovery function relying on this needs the purpose limitation encoded, not assumed. Processing a defaulter's data for cross-sell because the exemption was available for recovery is outside it.

The central BFSI problem: erasure versus mandate

Section 12 gives a Data Principal the right to erasure — unless retention is necessary for the specified purpose or for compliance with any law for the time being in force.

For a bank, NBFC, insurer or payment aggregator, that exception swallows a large part of the right. Indian financial regulation is dense with retention obligations.

SourceBroadly requires retention of
RBI Master Directions on KYCCustomer identification and due diligence records, transaction records
Prevention of Money-Laundering Act and rulesClient identity records, transaction records
RBI payment aggregator and gateway directionsTransaction and merchant records
Income-tax Act and rulesBooks of account and supporting documents
Companies Act, 2013Books of account and statutory registers
IRDAI regulationsPolicyholder, proposal and claims records
SEBI regulationsClient and transaction records for registered intermediaries
Credit information regulationCredit information reported to bureaux
[VERIFY] Periods vary by instrument and are amended periodically. Confirm from the source instrument, and take advice where a period is contested or where instruments conflict. This table shows where to look; it does not substitute for the instrument.

What this means operationally

The wrong responses are both common. Refusing the whole request because "we're regulated" is not compliant — data outside a mandate must still be erased. Deleting everything because the customer asked is worse, because it destroys records a regulator requires.

The correct response is purpose-scoped: erase what no mandate covers, retain what is mandated, restrict the retained data to the retention purpose only, and record the mandate you relied on. That last step matters — under section 33(2) the timeliness and effectiveness of your action is an express factor in penalty determination.

This requires a retention register: data category, purpose, retention rule, source instrument, and a review date for when the instrument changes. A policy paragraph will not survive an audit. → Retention & Erasure

BFSI processing splits into three buckets, and conflating them is the most common design error.

Mandated processing. KYC, AML screening, regulatory reporting, credit bureau submission. These rest on compliance with law, not consent. Asking for consent you don't need — and cannot honour a withdrawal of — creates a worse position than relying on the correct basis, because withdrawal then becomes a request you must refuse.

Service delivery processing. Operating the account, executing transactions, servicing the product. Substantially covered by data voluntarily provided for the specified purpose under section 7, within the bounds of that purpose.

Discretionary processing. Marketing, cross-sell, propensity modelling, analytics, partner sharing. This needs specific, unbundled consent under section 6, with withdrawal at comparable ease.

The line to hold: you cannot make a regulated product conditional on consent to discretionary processing. Consent must be unconditional and free, and a loan application that requires marketing consent to proceed fails both tests.

Expect Significant Data Fiduciary designation

Section 10 allows the Central Government to notify a Data Fiduciary or class as a Significant Data Fiduciary based on factors including the volume and sensitivity of personal data processed, risk to Data Principals' rights, and potential effects on the security of the State and public order.

No threshold triggers this automatically — designation follows notification. But large banks, insurers and payment aggregators are plainly within the contemplated population, and the additional obligations take time to stand up:

The DPO's accountability line to the board is worth noting: it is an internal governance relationship, which is why a wholly outsourced arrangement requires careful structuring rather than a service contract. Institutions should plan on the assumption of designation rather than waiting for it.

Security is your highest exposure, not consent

The Schedule's largest penalty — up to ₹250 crore — attaches to breach of the section 8(5) obligation to take reasonable security safeguards to prevent a personal data breach. Failure to notify a breach under section 8(6) sits at up to ₹200 crore.

For BFSI this compounds an existing obligation set. DPDP breach intimation and CERT-In's incident direction are separate regimes with different triggers, timelines and recipients, and RBI incident reporting is a third. An incident response process built for one will not satisfy the others, and all of them attach to you rather than to your technology vendor.

What to build, in order

  1. Retention register — category, purpose, rule, source instrument, review date. Everything else depends on it.
  2. Basis map per purpose — mandated, service delivery, or discretionary. Stop asking for consent you do not need.
  3. Unbundle discretionary consent from product onboarding, and fix withdrawal parity.
  4. Rights workflow with conflict detection — surfacing the mandate that blocks an erasure, and documenting the refusal with its basis.
  5. Purpose-bound recovery processing if relying on section 17(1)(f).
  6. Unified incident process mapping DPDP, CERT-In and RBI reporting from one detection event.
  7. SDF readiness — DPO structure, auditor, DPIA cadence, on the assumption of designation.

Where Consiva fits

Consiva holds the retention register with its source instruments, flags erasure conflicts at the point of request, records the basis per purpose, and produces the closure artefact. Determining which mandate applies, and resolving a conflict between instruments, is legal work — that determination is yours, and where a period is contested it belongs with counsel.

Consiva's retention register, erasure-conflict flagging and the SDF module (DPO workflow, DPIA templates, annual audit readiness) sit on the Enterprise plan, with on-premise deployment available. Determining which mandate applies, and resolving conflicts between instruments, is legal work that stays with you and your counsel. → Pricing

Frequently asked questions

Does the DPDP Act apply to banks and NBFCs?

Yes. They are Data Fiduciaries for customer personal data and carry the full Chapter II obligations, subject to specific exemptions including section 17(1)(f) for processing a defaulter's financial information.

Can a bank refuse to delete customer data on request?

Where retention is necessary for compliance with any law, yes — and RBI, PMLA, tax and company law mandates frequently apply. Data outside any mandate must still be erased, and the refusal must be explained and documented.

What is the section 17(1)(f) exemption?

It permits processing to ascertain the financial information, assets and liabilities of a person who has defaulted on a loan or advance from a financial institution, subject to disclosure provisions in other law. "Default" and "financial institution" take their IBC meanings.

Do we need consent for KYC processing?

KYC is mandated by law, so compliance with law rather than consent is the appropriate basis. Seeking consent for mandated processing creates a withdrawal you cannot honour.

Will banks be designated Significant Data Fiduciaries?

Designation requires notification under section 10 and no threshold triggers it automatically, but the factors listed clearly contemplate large financial institutions. Given the lead time for a DPO, independent audits and periodic DPIAs, planning on the assumption is prudent.

Is DPDP breach reporting the same as RBI or CERT-In reporting?

No. Three separate regimes with different triggers, timelines and recipients. An incident process must satisfy all applicable ones from a single detection event.

Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Act, 2023, ss. 8, 10, 12, 17(1)(f) with its explanation and illustration, 33(2) and the Schedule. Sectoral retention periods must be confirmed from the applicable instrument. Reference material about the law, not legal advice — see /disclaimer.

DPDP compliance built for Banking & Financial Services

Consiva.ai covers every obligation above with pre-configured workflows, templates, and automated jobs — purpose-built for India's data protection law.

Start Free — No Credit Card →