RBI's Data Governance Push Meets DPDP: Why NBFCs Must Rethink Fintech Partnerships Now

Two separate regulatory tracks are converging on the exact same data flows between NBFCs and their technology partners. Neither one waits for the other to finish.

On 15 July 2026, RBI released a draft "Guidance on Regulatory Expectations for Data Governance" for public comment, proposing that banks and NBFCs — across every Scale-Based Regulation layer — take board-level accountability for data even when a fintech partner is the one actually handling it. Separately, the Digital Personal Data Protection (DPDP) Rules, 2025, notified in November 2025, make many of those same fintech partners independently liable as Data Fiduciaries in their own right, with penalties reaching ₹250 crore per breach.

Neither framework is finished arriving — the RBI guidance is still a draft, and DPDP's core obligations phase in through May 2027 — but NBFCs that wait for both to fully settle before acting on their fintech contracts will be doing so under supervisory and public scrutiny that has already started.

Two Regulatory Tracks, Converging

These are two distinct pieces of regulation, moving on two different timelines, arriving at the same conclusion from different directions.

RBI
Draft Guidance on Data Governance
  • Released 15 July 2026; comment period closed 17 August 2026.

  • Still a draft — not yet a binding Direction.

  • Covers the full data lifecycle: creation, collection, storage, processing, sharing, disposal.

  • Requires a board-approved Data Governance Framework, proportionate to institution size.

  • Makes the regulated entity responsible for data governance even when a third party handles it.

  • Explicitly requires alignment with the DPDP Act and Rules.

DPDP
Digital Personal Data Protection Act & Rules
  • Act passed 2023; Rules notified 13 November 2025.

  • A statute — obligations are legally binding, phased by date, not by draft status.

  • Applies to any entity processing personal data as a Data Fiduciary, fintechs included.

  • Independent of RBI — enforced by the Data Protection Board, not RBI supervision.

  • Penalties can reach ₹250 crore per breach, separate from any RBI action.

  • Turns existing data-minimisation expectations into statutory consent obligations.

Note: Read separately, each is manageable on its own timeline. Read together, they close the gap that let "the fintech partner handles the data" function as an answer to a compliance question. Under RBI's draft, it no longer fully does. Under DPDP, it never legally did.

Where This Actually Bites: Fintech Partnerships

RBI's draft guidance does not bring fintechs directly under RBI's regulatory perimeter simply because they supply technology to a bank or NBFC. What it does is make the regulated entity — the NBFC — explicitly accountable for governing data shared with third parties: knowing what's shared, for what defined purpose, with what access controls, and with what deletion and retention rules. In practice, that accountability doesn't stay on the NBFC's side of the contract. It gets pushed downstream, through vendor selection criteria, contractual terms, technical audits, and reporting requirements imposed on the fintech partner.

At the same time, DPDP doesn't wait for that to happen contractually — a fintech processing personal data on an NBFC's behalf can already be a Data Fiduciary in its own right, with its own independent exposure. And this isn't entirely new territory layered onto nothing: RBI's existing Digital Lending Directions already restrict lending apps from accessing a borrower's phone contacts, gallery, or location data without necessity. DPDP now makes that same over-collection a statutory consent violation, not just a breach of an RBI circular — meaning a single bad practice can now trigger two separate regulators, two separate penalty regimes, for the same underlying act.

Why this matters for co-lending and LSP models specifically

Co-lending and Lending Service Provider arrangements depend on data moving cleanly between an NBFC and its partner — underwriting inputs, KYC records, repayment data. Under a converging RBI-plus-DPDP regime, "clean" now has to mean traceable, consented, purpose-limited, and auditable on both sides of that relationship, not just fast.

What Actually Changes in Practice

Five things worth doing before either framework fully settles, not after.

  • Map every data flow to every fintech partner.

Most NBFCs can name their partners; fewer can currently produce a complete list of exactly what data moves to each one, and why.

  • Re-paper partner contracts for defined purpose and deletion terms.

"Access to customer data as needed" is the kind of clause both frameworks are explicitly moving away from.

  • Build technical visibility, not just contractual promises.

Access logs and audit trails that can actually answer "who touched this record and why" during a supervisory review.

  • Confirm your partner's own DPDP posture.

Their exposure as a Data Fiduciary is not automatically your exposure, but it becomes your operational risk the moment they're handling your customers' data.

  • Treat consent architecture as infrastructure, not a checkbox.

The Account Aggregator framework's scoped, revocable, logged consent model is the closest existing template for what both RBI and DPDP are pointing toward.

Timeline to Watch

  • 13 Nov 2025

DPDP Rules, 2025 notified; Data Protection Board provisions take effect on notification.

  • 15 Jul 2026

RBI releases draft "Guidance on Regulatory Expectations for Data Governance" for public comment.

  • 17 Aug 2026

RBI's public comment window on the draft guidance closes.

  • ~13 Nov 2026

Consent Manager registration under DPDP Rules expected to open.

  • ~13 May 2027

Core DPDP obligations on Data Fiduciaries expected to take full effect.

Note: Dates marked "expected" reflect the phased timeline set out in the DPDP Rules as currently published; RBI has not yet indicated when its draft guidance will be finalised. Treat both as directional, and confirm against the regulators' own publications before making a compliance deadline commitment internally.

Where AOPAY Fits

The practical answer to "rethink your fintech partnerships" is infrastructure that makes data flows visible and governable by default, not a policy document describing intentions:

  • Account Aggregator-based data sharing — scoped, consented, revocable and logged, the model both frameworks are converging toward.

  • KYC and KYB verification built into onboarding, with a clear record of what was collected and why.

  • Connected banking infrastructure with audit-trail visibility into data as it moves between systems.

  • NBFC software and co-lending infrastructure built for RBI-compliant, auditable multi-party data handling.

FAQs

The Bottom Line

Neither framework is finished arriving, and that's exactly the problem with waiting. RBI's draft will change before it's final; DPDP's obligations will keep phasing in regardless of whether an NBFC's fintech contracts are ready. The NBFCs least exposed when both fully land will be the ones that already know what data moves to which partner, why, and under what controls — not the ones who found out during a supervisory review.

Talk to AOPAYExplore Account Aggregator Licensing