You already collect consent. The Act asks a different question.
16 September 2026
Financial services already run KYC and RBI consent regimes. Where the DPDP Act overlaps with them, and where it asks for something those regimes never did.
Financial services is the sector most likely to believe it is already compliant, because it has been collecting consent under KYC rules, RBI circulars and the account aggregator framework for years. Those regimes ask whether consent was obtained. The DPDP Act asks whether it was valid, and then whether it can still be withdrawn.
Where the existing regimes carry over
The account aggregator framework is the closest thing India already has to DPDP-shaped consent: purpose-scoped, time-bound, revocable, machine-readable. Firms already inside it have the conceptual model and often the plumbing. That is a genuine head start, and it is confined to the data flowing through the AA rails.
Where it does not
Everything outside AA. Marketing databases, app analytics, call recordings, support transcripts and partner referrals are personal data collected under consent that was usually bundled into onboarding.
Bundled consent at onboarding. A single tick covering account operation, credit checks, marketing and partner offers is one consent doing four jobs. Sec. 6(1) requires it to be specific, and Sec. 6(4) requires withdrawal to be as easy as giving — which is not possible for a purpose that was never separated.
Legal retention as a blanket answer. Some financial records must be retained under other law, and the Act accommodates that. It does not extend the accommodation to the marketing profile built alongside them.
The evidence standard
Under Sec. 8, a Data Fiduciary is accountable for demonstrating compliance. For a regulated firm the practical bar is higher than the statutory one: the record has to satisfy an auditor who will ask which notice version a customer saw, in which language, on which date, and what happened in every downstream system when they withdrew.
What unbundling the onboarding tick actually costs
Sec. 6(1) limits consent to the personal data necessary for the specified purpose, and Sec. 6(2) makes the part of a consent that infringes the Act invalid to that extent. The onboarding tick above is not void in the round, but the part of it reaching beyond what each of those purposes needs does not hold.
Separating four purposes on the account-opening screen is a design change. Separating them in core banking, loan origination, the CRM and the campaign tool, so that withdrawal from one does not stop the other three, is the project — and Sec. 6(6) requires the Fiduciary, within a reasonable time, to cease processing and to cause its processors to cease.
Retention against erasure, and the bank in the Act's own illustration
Sec. 8(7) requires erasure on withdrawal or once the purpose is no longer served, whichever is earlier, and requires the Fiduciary to cause its processors to erase, unless retention is necessary for compliance with law. The Act's own illustration is a bank: required by law to keep client identity records for ten years beyond the closure of an account, it may keep them for that period. This is the sector whose retention argument the Act expressly accepts.
It accepts it for those records. The marketing profile, app event stream, call recordings and support transcripts beside them are different purposes with different answers, and Sec. 8(8) deems a purpose no longer served once the Data Principal has neither approached the Fiduciary for it nor exercised her rights for the prescribed period.
Rule 8(3) adds a floor, not a ceiling, and it attaches to any processing rather than to a class of it. The personal data, the associated traffic data and the logs of processing a Fiduciary undertakes, or that a processor undertakes on its behalf, are kept for at least one year from the date of that processing, so they stay available for the purposes in the Seventh Schedule, unless another law requires them for longer. It runs alongside the erasure duty, and the two are reconciled per purpose or not at all.
Reasonable security safeguards in an already-regulated estate
Rule 6 turns Sec. 8(5) into a minimum list — among other things encryption, masking or virtual tokens, access control, logging and monitoring of access, backups, one year's retention of logs and personal data unless another law requires otherwise, and security obligations in a processor contract wherever applicable. The full list is in the compliance checklist. Most of it already exists in a bank's control framework; two items are worth checking rather than assuming: that the logs kept for a year are the ones that evidence access to personal data, and that the contractual flow-down reaches processors procured by business lines as well as by technology.
Sec. 8(5) also carries the largest figure in the Schedule to the Act, up to ₹250 crore. It is a ceiling the Board may impose after an inquiry and a hearing, weighing the factors in Sec. 33(2), not a fixed fine.
Two breach clocks, against an incident process that already exists
Rule 7 runs two notifications. Each affected Data Principal is told without delay, in plain language, through her user account or a registered mode of communication: what happened, the consequences relevant to her, what is being done, what she can do, and whom to contact. The Board is told without delay, and then, within 72 hours of the Fiduciary becoming aware — longer only if the Board allows it on a written request — receives a detailed report covering the facts, mitigation, findings on who caused it, remedial measures, and the intimations given to affected Data Principals.
A bank already runs incident reporting. The mismatch is rarely the timeline and usually the list: an existing process reports an incident, while Rule 7 requires an intimation to each person. Establishing who was affected is the step both clocks wait on.
Rights and grievance, and the ninety-day outer limit
Sec. 11 gives access to a summary of the personal data held and the processing done on it, and to the identities of the other Data Fiduciaries and processors it was shared with, with a description of what was shared — so the processor chain has to be answerable per customer, not per system. Sec. 12 to Sec. 14 add correction, completion, updating and erasure, grievance redressal, and nomination.
Rule 14 requires the means of making a request to be published prominently, and Rule 14(3) caps the grievance response at a reasonable period not exceeding ninety days — an outer limit, not a service standard. Sec. 13 has to be exhausted before she can approach the Board, so the grievance queue is where a complaint ends or escalates. Rule 9 adds a published contact — the Data Protection Officer's, or that of a person who can answer questions about the processing — mentioned in every response to a communication exercising rights.
If you are notified as a Significant Data Fiduciary
Sec. 10(1) lets the Central Government notify a Data Fiduciary as Significant on factors including the volume and sensitivity of the personal data processed and the risk to the rights of Data Principals. A large institution ranks high on both by construction.
If notified, Sec. 10(2) requires a Data Protection Officer based in India, responsible to the board of directors and the point of contact for grievance redressal, and an independent data auditor. Rule 13 then requires, every twelve months from notification, a Data Protection Impact Assessment and an audit, with a report of significant observations furnished to the Board; due diligence that technical measures, algorithmic software included, are not likely to pose a risk to Data Principals' rights; and that personal data specified by the Central Government on a committee's recommendation, with its traffic data, is not transferred outside India.
Model that last condition early. It attaches to whatever the Central Government specifies, so check what, if anything, has been specified; an estate with processing offshore cannot answer it at short notice. Sec. 16 sits beside it: the Central Government may restrict transfers to a notified country or territory, and a higher degree of protection under any other law in India is unaffected.
Employee data, which is mostly not a consent problem
Sec. 7(i) makes employment a legitimate use, covering processing for the purposes of employment and to safeguard the employer from loss or liability. In a bank that reaches payroll, attendance, access provisioning and the controls that protect the bank itself from loss, and consent is the wrong instrument for any of it. The safeguards in Sec. 8(5) and breach intimation under Sec. 8(6) apply to the HR estate as to any other, and Sec. 8(1) keeps the Fiduciary responsible for processing done on its behalf irrespective of any agreement to the contrary. The detail is on employers and HR.