New

DPDP Rules 2025 compliance checklist is live —

Read now
← All articles BFSI

DPDP for BFSI: what banks and insurers must get right

VaultDef Team7 Sept 20263 min read

No sector feels the DPDP Act more acutely than BFSI. Banks, insurers, NBFCs and fintechs hold enormous volumes of sensitive personal and financial data, operate under multiple regulators at once, and face customers and auditors with little patience for mistakes. The Act does not replace existing obligations — it stacks on top of them.

Why BFSI is the hardest case

  • Volume and sensitivity. Financial data is both voluminous and high-harm. A breach here is not embarrassing; it is dangerous to the individual.
  • Overlapping regulators. You are already answering to the RBI, IRDAI or SEBI depending on your business. The DPDP Act adds a data-protection lens that must coexist with those regimes, not contradict them.
  • Long retention, wide sharing. Financial records are retained for years and shared across a web of processors — credit bureaus, KYC providers, collection agencies, analytics vendors.

Consent at scale

BFSI collects consent constantly — at onboarding, for cross-sell, for credit checks, for sharing with bureaus. The DPDP Act's requirement that consent be specific and purpose-bound collides with the industry habit of broad, bundled consent. The work is to:

  • Break consent into discrete purposes rather than one sweeping agreement.
  • Produce a retrievable receipt for each — because in a dispute, "the customer agreed" is worthless without the record of what they agreed to and when.
  • Make withdrawal real and provable, with downstream effects you can demonstrate.

Retention and the tension with financial rules

The DPDP Act leans toward data minimisation and erasure when the purpose ends. Financial regulation often requires retention for defined periods. These are not actually in conflict — but reconciling them requires a retention schedule mapped to a lawful basis, so you can show precisely why each dataset is kept, for how long, and under which obligation. "We keep everything forever" is defensible under neither regime.

In BFSI, the question is rarely "can we delete this?" It is "can we prove why we still hold it?"

Third-party and processor risk

Financial data flows through a long chain of processors. Under the Act, responsibility for that data does not end at your boundary. That means:

  • A current inventory of every processor and what data they touch.
  • Contracts that bind them to equivalent protections.
  • Assurance that they actually meet them — not a one-time questionnaire, but ongoing evidence.

Evidence for auditors — and three of them at once

BFSI is audited constantly. The efficient path is to build compliance so that the same evidence serves multiple regulators. A well-kept record of classification, consent, access and incident response answers RBI, IRDAI/SEBI and DPDP questions from one source of truth. Maintaining separate, contradictory evidence trails for each regulator is how teams drown.

Where to focus first

  1. Map the sensitive data across core banking, policy admin, CRM, warehouses and the processor chain.
  2. Rebuild consent as discrete, receipted, withdrawable purposes.
  3. Codify retention against lawful bases so every kept dataset is justified.
  4. Instrument access to sensitive data with an append-only log.
  5. Stand up rights and breach workflows that can meet statutory clocks at scale.

BFSI cannot bolt privacy on as an afterthought — the volumes and the stakes are too high. But the sector also has an advantage: it already understands controls, audit and evidence. The DPDP Act is, in many ways, asking BFSI to do what it already does for money, now for personal data.