Back to Blog
BFSI · Consent Management

Without Consent Management, DPDP Compliance Is Impossible: The Brutal Truth for BFSI

Published 19 Aug 2026 9 min read
Illustration of a mobile consent screen with toggles for account opening, credit assessment and marketing, next to a bank building marked DPDP compliant.

India's banks and NBFCs have spent decades building compliance frameworks. KYC processes, AML systems, fraud monitoring, credit risk models — layers upon layers of regulatory infrastructure, all built in response to RBI, SEBI, IRDAI and PMLA mandates.

None of it covers what the Digital Personal Data Protection Act, 2023 actually demands.

The DPDP Act does not care how robust your KYC system is. It asks a different question entirely: did the customer explicitly consent to each specific use of their personal data? Can you prove it? Can you honour a withdrawal request within hours?

For most BFSI institutions, the honest answer to all three questions is no.

That is not a technology gap. It is a structural one. And with the DPDP Rules 2025 now notified and a compliance deadline of May 13, 2027 in place, the window to fix it is closing.

Why BFSI is the highest-risk sector under DPDP

Every sector in India must comply with the DPDP Act. But BFSI organisations process more categories of personal data than almost any other sector — transaction records, credit histories, income details, biometric KYC data, health information for insurance, behavioural data from digital lending apps.

Each category carries distinct consent, security and processing obligations under the Act.

The scale of data processing in Indian financial services is significant. Between January and October 2023 alone, the sector faced over 1.3 million cyberattacks — roughly 4,400 per day. Phishing incidents grew substantially in H1 2024. The DPDP Act directly addresses these realities through mandatory security safeguards, breach notification obligations, and purpose-limited data use.

The financial stakes are real. The Data Protection Board of India can impose penalties up to ₹250 crore for non-compliance. That ceiling applies per violation. An institution with millions of customers and thousands of data processing activities across onboarding, credit assessment, marketing, collections and third-party sharing has significant exposure.

The core problem: consent is not what most institutions think it is

Walk through any bank's onboarding process today. Somewhere in the stack of forms and digital checkboxes, there is a consent clause. It is typically buried in the terms and conditions. It is pre-ticked, or it covers everything in one sweep. It says something like: "I consent to the use of my data for all purposes related to banking services."

Under the DPDP Act, that consent is invalid.

The Act requires explicit consent that is free, specific, informed, unconditional and unambiguous, conveyed through a clear affirmative action. Each purpose must be separately identified. A customer must be able to consent to loan processing without automatically consenting to marketing. A customer must be able to consent to credit bureau sharing without automatically consenting to data sharing with group companies.

Blanket consent forms are now obsolete. The DPDP Act replaces them with a consent architecture that most institutions have never built.

There is more. The Act grants every customer the right to withdraw consent at any time. When a customer withdraws, the institution must stop processing data for that purpose — unless a separate legal basis applies. The institution must honour that withdrawal quickly, and maintain an auditable record showing it was honoured.

For an NBFC running marketing campaigns, cross-sell programmes and analytics systems across millions of customer records, that withdrawal obligation is not a minor operational adjustment. It requires a consent management system that tracks consent status per customer, per purpose, in real time.

The conflict nobody prepared for: DPDP vs RBI

Here is where BFSI compliance gets genuinely complex.

The DPDP Act grants customers the right to erasure — to request that their data be deleted. RBI's Master Direction on KYC requires institutions to retain customer identification records for a minimum of five years after the business relationship ends. PMLA mandates independent transaction record retention for five years. These obligations run simultaneously and do not exempt each other.

This retention conflict is the most structurally significant compliance problem that NBFCs and banks face under DPDP. An institution cannot simply delete a customer's KYC record because they withdrew consent — RBI prohibits it. But the institution also cannot ignore the withdrawal — DPDP requires a response.

The resolution lies in Section 8(7) of the DPDP Act, which permits continued retention where a legal obligation requires it. But implementing this correctly means the institution must:

  • Document the legal basis for retention field by field
  • Delete all data not covered by a regulatory mandate — marketing preferences, app usage analytics, browsing behaviour
  • Notify the customer of the specific legal basis for continued retention
  • Maintain an auditable record of every such decision

Banks should prepare for SDF designation rather than hope for exemption. Most scheduled commercial banks, major NBFCs and large insurance companies will likely qualify as Significant Data Fiduciaries based on data volume and sensitivity criteria under Section 10 of the Act. SDF designation triggers additional obligations: a Data Protection Officer, independent audits, Data Protection Impact Assessments, and periodic compliance reviews.

What the RBI is already signalling

The DPDP Act's enforcement may be managed by the Data Protection Board. But the RBI has not waited for that board to set expectations for the BFSI sector.

RBI's IT Governance Master Direction (2023) makes DPDP compliance mandatory for all financial institutions under its purview. The NBFC Responsible Business Conduct Directions, issued in November 2025, carry consent and dark-pattern amendments effective July 1, 2026. From that date, an NBFC must:

  • Capture explicit, per-product consent through affirmative action
  • Maintain an auditable trail that the customer can view and withdraw
  • Abandon bundled or pre-ticked consent entirely

That is not the May 2027 DPDP deadline. That is July 2026 — already in effect.

For BFSI institutions that assumed the DPDP compliance timeline gave them breathing room, the RBI's parallel consent requirements have already closed that window for core lending products.

The five consent failures that will drive enforcement

When the Data Protection Board begins enforcement actions — and regulators globally have shown a consistent pattern of targeting financial services first — these are the failure modes that will appear in every finding.

1. Bundled consent at onboarding

A single consent covering KYC, marketing, credit bureau sharing, third-party data transfer and analytics is not specific consent. It is a legal liability dressed as a checkbox. Third-party vendor consent must be expressly covered with disclosures on what categories of data will be shared and for what purpose.

2. No consent withdrawal mechanism

Most BFSI institutions have a process for customers to close accounts. Very few have a process for customers to withdraw consent for specific data processing activities while the relationship continues. The Act requires both to exist independently.

3. Missing audit trail

Every consent given, modified or withdrawn must be time-stamped and auditable. Real-time audit trails for traceability and accountability are mandatory. Institutions that rely on paper forms or PDF-based consent records cannot produce these trails on demand.

4. Third-party data sharing without consent coverage

NBFCs typically share customer data with lending service partners, collection agencies, credit bureaus and analytics vendors. Each of these data-sharing arrangements requires consent that expressly names the third-party category and the purpose. Existing vendor contracts built around blanket data-sharing clauses do not satisfy this requirement.

5. No language compliance

The DPDP Act requires consent notices to be available in multiple Indian languages. A consent notice available only in English does not satisfy the informed-consent requirement for customers whose primary language is not English. This is a gap that most institutions have not even begun to address.

Why manual consent management cannot work at BFSI scale

A mid-sized NBFC onboards thousands of customers monthly. Each customer interaction — onboarding, loan application, top-up, insurance cross-sell, collections communication — may involve a distinct data-processing purpose with its own consent requirement.

Manual consent management at this scale is not just operationally difficult. It is structurally impossible.

An institution processing hundreds of thousands of active customer relationships cannot track consent status per customer, per purpose, in real time using spreadsheets or PDF archives. It cannot honour withdrawal requests within reasonable timeframes without automated routing. It cannot produce consent audit trails for regulatory inspection without a system that captures and stores consent events as they occur.

Consent management platform deployment is the first operational priority for BFSI compliance under DPDP — not data mapping, not policy drafting, not vendor assessments. Those matter. But without a consent management system, every other compliance activity rests on a foundation that cannot hold.

What a DPDP-ready consent architecture looks like for BFSI

A consent management system built for BFSI DPDP compliance must do five things:

Purpose-level consent capture. Every data processing purpose — KYC, credit assessment, marketing, third-party sharing, analytics — must be captured as a separate consent event with a timestamp, the notice served, and the customer's response.

Real-time withdrawal processing. When a customer withdraws consent for a specific purpose, the system must immediately flag all downstream processing that relies on that consent, route the withdrawal to relevant systems, and generate an audit record.

Legal override management. Where an RBI or PMLA retention obligation overrides the erasure right, the system must document the specific legal basis and retain that documentation alongside the customer record — not as a blanket policy but as a per-record decision.

Multilingual notice delivery. Consent notices must be delivered and recorded in the customer's preferred language. The system must maintain a copy of the exact notice delivered to each customer at the time of consent.

Third-party consent propagation. When customer data is shared with a lending service partner, collection agency or analytics vendor, the consent coverage for that sharing must be verifiable. Data Processor Agreements must be executed with every vendor, and the consent basis for each data-sharing arrangement must be documented.

The timeline every BFSI compliance team needs to know

  • November 2025: DPDP Rules 2025 officially notified, starting the compliance clock.
  • July 1, 2026: RBI's NBFC Responsible Business Conduct Directions on consent take effect. Per-product explicit consent and auditable withdrawal mechanisms are mandatory from this date.
  • May 13, 2027: DPDP Act compliance deadline for all regulated entities.

For institutions that have not yet begun consent architecture work, the July 2026 RBI deadline is the more immediate pressure point. It arrives before the DPDP deadline and applies specifically to NBFCs with lending products.

Key takeaways for BFSI compliance and technology teams

  • Blanket consent at onboarding is no longer valid under DPDP. Purpose-specific, affirmative consent is required for each data processing activity.
  • The right to erasure does not override RBI and PMLA retention mandates — but the institution must document the legal basis field by field and delete all data not covered by a regulatory obligation.
  • Most large banks, NBFCs and insurers will likely qualify as Significant Data Fiduciaries, triggering DPO appointment, DPIAs and independent audits.
  • RBI's NBFC consent directions are effective July 1, 2026 — ahead of the May 2027 DPDP deadline. Lending institutions cannot rely on the DPDP timeline alone.
  • Manual consent management cannot function at BFSI scale. A purpose-level consent platform with real-time withdrawal processing and audit-trail generation is the foundational requirement.

FAQ

Does DPDP apply to banks and NBFCs already complying with RBI KYC norms?

Yes. RBI KYC compliance and DPDP compliance are separate obligations — one does not exempt the other.

What is the penalty for DPDP non-compliance in BFSI?

The Data Protection Board can impose penalties up to ₹250 crore per violation under the DPDP Act.

When does RBI's new consent requirement for NBFCs take effect?

July 1, 2026 — ahead of the May 13, 2027 DPDP deadline.

Can a customer force a bank to delete their KYC data under DPDP?

No. RBI and PMLA retention mandates override the erasure right for regulatory data, but the bank must document the legal basis and delete non-mandatory data.

What is a Significant Data Fiduciary under DPDP?

An entity designated by the government based on data volume and sensitivity, subject to additional obligations including a DPO, DPIAs and independent audits — most large BFSI institutions are expected to qualify.

This article is for informational purposes and does not constitute legal or compliance advice. Regulated entities should refer directly to the DPDP Act, 2023 and RBI's Master Direction on KYC for authoritative guidance.

See how ConsentCure builds purpose-level consent architecture for BFSI.

Book a Demo