DPDPA compliance for NBFCs now means one breach starts two regulatory clocks — CERT-In’s 6-hour incident report and the Data Protection Board’s 72-hour notification — and most lenders have planned for only one.
TL;DR
- One incident, two clocks: CERT-In’s April 2022 directions require cyber-incident reporting within 6 hours; the DPDP Rules 2025 require a detailed report to the Data Protection Board (DPB) within 72 hours under Section 8(6) of the DPDPA 2023.
- The DPDPA abolished the “sensitive personal data” tier — KYC documents, bureau pulls and loan records are all just personal data, protected under one uniform standard (Sections 4–8).
- Rule 13 audits and DPIAs apply only to Significant Data Fiduciaries notified under Section 10 — not to every NBFC. Know which side of that line you sit on.
- Consent under Section 6 must be free, specific, informed, unconditional, unambiguous and given by clear affirmative action — bundled loan-form consent fails this test.
- Substantive obligations phase in, with key duties commencing 13 May 2027. The breach clocks, once live, do not wait for your remediation plan.
- Maximum penalty for failing security safeguards: ₹250 crore per instance (Schedule, DPDPA 2023).
What does DPDPA compliance for NBFCs actually require?
DPDPA compliance for NBFCs starts with a simple recognition: your entire lending stack runs on digital personal data. Aadhaar-based KYC, PAN, bank statements, bureau reports, salary slips, repayment histories — every one of these makes your NBFC a Data Fiduciary under Section 2(i) of the DPDPA 2023, with obligations under Sections 4 through 8: lawful processing grounds, valid notice and consent, purpose limitation, data accuracy, erasure when purpose is served, and reasonable security safeguards.
Unlike the SPDI Rules 2011, the DPDPA does not carve out a “sensitive personal data” category. There is no lighter tier for “ordinary” data and heavier tier for financial data — everything your loan origination system touches is governed by the same standard. For an NBFC compliance officer, that removes a familiar mental model: you can no longer triage protection by data class. You triage by purpose and lifecycle stage instead.
| Data category | Typical purpose | DPDPA handling requirement |
|---|---|---|
| KYC documents (Aadhaar, PAN, address proof) | Identity verification, RBI KYC Master Direction | Consent or legitimate-use ground (Sec 7); retain per RBI norms, then erase (Sec 8(7)) |
| Credit bureau data | Underwriting, risk scoring | Specific, informed consent (Sec 6); purpose-limited |
| Bank statements / income proof | Repayment capacity assessment | Notice under Sec 5; no reuse for cross-sell without fresh consent |
| Repayment & collections data | Servicing, recovery | Accuracy duty (Sec 8(3)); grievance channel (Sec 8(10)) |
| Co-lending / DSA-shared data | Sourcing, partnership lending | Fiduciary remains responsible for processors (Sec 8(1)) |
Why does one breach start two clocks for an NBFC?
Because two regulators claim the same incident. CERT-In’s directions of 28 April 2022 (under Section 70B of the IT Act) require covered entities to report specified cyber incidents — including data breaches and data leaks — within 6 hours of noticing them. Separately, Section 8(6) of the DPDPA read with the DPDP Rules 2025 requires a Data Fiduciary to intimate each affected Data Principal and the Data Protection Board without delay, followed by a detailed report to the DPB within 72 hours covering the breach’s nature, extent, timing, consequences and mitigation.
These are not alternatives. They are cumulative, they run in parallel from the same trigger event, and they demand different artefacts: CERT-In wants a technical incident report; the DPB wants an evidentiary account of what personal data was affected, whose, and what you did about it. An NBFC whose incident-response runbook was written for CERT-In alone will hit hour 7 with one obligation discharged and a much harder one still ticking.
The failure mode we see most often in gap analyses: the CISO owns the CERT-In clock, nobody owns the DPB clock, and the Data Principal notification — which must go out without delay, not at hour 72 — is discovered last. Assign both clocks before the incident, not during it.
Is your NBFC a Significant Data Fiduciary — and does Rule 13 apply?
This is where lenders most often over- or under-comply. Rule 13 of the DPDP Rules 2025 — annual data audits, Data Protection Impact Assessments, and algorithmic due-diligence — applies only to Significant Data Fiduciaries (SDFs), entities notified by the Central Government under Section 10 based on the volume and sensitivity of data processed, risk to Data Principals, and similar factors. It does not apply to every Data Fiduciary.
A large NBFC processing lakhs of borrower records may well be notified as an SDF and must then also appoint a Data Protection Officer based in India and an independent data auditor. A smaller lender that is not notified owes the full Section 8 stack — safeguards, breach notification, erasure, grievance redressal — but not the Rule 13 audit. Budgeting for an audit you don’t owe wastes money; skipping obligations you do owe risks the Schedule’s penalty slabs. We’ve unpacked the SDF criteria in detail in our Significant Data Fiduciary explainer.
How should NBFCs fix consent across the lending lifecycle?
Section 6 sets a high bar: consent must be free, specific, informed, unconditional, unambiguous, and signalled by clear affirmative action. Measure your current loan journey against each word. A single checkbox that bundles KYC verification, bureau pull, cross-sell marketing and data-sharing with “group companies and partners” fails specific and unconditional in one stroke. Making loan disbursal conditional on marketing consent fails free. Pre-ticked boxes fail affirmative action.
The fix is architectural, not cosmetic. Consent must be captured per purpose, recorded immutably, and be as easy to withdraw as it was to give (Section 6(4)) — with withdrawal actually propagating to your LOS, LMS, collections vendors and DSAs. For a stack-by-stack walkthrough, see our earlier piece on DPDP consent across the NBFC and wealth stack.
What architecture survives a DPB inquiry — not just an audit checklist?
When the 72-hour clock is running, policy PDFs don’t help; evidence does. The question the Board will effectively ask is: show us what data was exposed, whose it was, what consent governed it, and what safeguards existed. Three architectural properties answer that question:
- A sealed PII vault. KYC and loan data live in one governed enclave — tokenised outward — so a peripheral breach may expose only tokens, not the vaulted KYC/loan identifiers, and the blast radius is knowable within hours, not weeks.
- Cryptographically immutable consent records. Every grant, modification and withdrawal is tamper-evident, so the consent state at the moment of breach is provable, not reconstructed.
- An evidentiary-grade audit trail. Access, purpose, and processing events are logged in a form you can hand to the DPB — and to CERT-In — without a forensic scramble.
This is the design philosophy behind Privigo’s financial-services solution: compliance as architecture, so the dual-clock response is a query, not a crisis.
Who owns what before 13 May 2027?
Substantive DPDPA obligations commence in phases, with the heavy operational duties landing on 13 May 2027. That is not far for an NBFC with legacy LOS/LMS systems and a DSA network. Use this ownership grid — and if your board wants the wider SMB timeline context, our 2027 readiness guide covers it.
| Area | Owner | Status |
|---|---|---|
| Personal-data inventory across LOS/LMS/collections | Compliance Officer / CS | ☐ |
| Dual-clock breach runbook (CERT-In 6h + DPB 72h) | CISO + Compliance | ☐ |
| Section 6 consent capture & withdrawal flows | Product + Legal | ☐ |
| SDF assessment (Sec 10) & Rule 13 applicability | Company Secretary | ☐ |
| Processor & DSA contracts (Sec 8(1)) | Legal | ☐ |
| Retention & erasure schedule vs RBI KYC norms | Compliance Officer | ☐ |
| Grievance redressal channel (Sec 8(10)) | Customer Service Head | ☐ |
Closing
Three concrete next steps for this quarter:
- Run a dual-clock tabletop exercise — simulate one breach, staff both the CERT-In 6-hour and DPB 72-hour tracks, and record where evidence-gathering stalls.
- Complete your SDF self-assessment against Section 10 factors so your Rule 13 budget (audit, DPIA, DPO) is right-sized before FY27 planning closes.
- Map every consent touchpoint in the loan journey against the six Section 6 tests and fix bundled or conditional consent first — it’s the most visible failure in any inquiry.
Book a 30-minute call with Privigo — we’ll walk your team through the dual-clock runbook and a free gap analysis for your lending stack.
Frequently Asked Questions
Do NBFCs have to report a data breach twice under Indian law?
Yes. Under Section 8(6) of the DPDPA 2023 read with the DPDP Rules 2025, an NBFC must notify affected Data Principals and the Data Protection Board (with a detailed report within 72 hours), while CERT-In’s 2022 directions separately require reporting cyber incidents within 6 hours. One incident, two clocks.
Are DPDPA audits mandatory for every NBFC?
No. Rule 13 of the DPDP Rules 2025 makes annual data audits and Data Protection Impact Assessments mandatory only for Significant Data Fiduciaries notified under Section 10 of the DPDPA. Other NBFCs still owe Section 8 obligations, but not the Rule 13 audit.
Is KYC data ‘sensitive personal data’ under the DPDPA?
No. The DPDPA 2023 does not retain the old SPDI ‘sensitive personal data’ category from the 2011 IT Rules — all digital personal data, including KYC and loan records, is governed by one uniform standard under Sections 4–8, so NBFCs cannot rely on tiered protection logic.
What is the maximum DPDPA penalty an NBFC can face for a breach?
Yes, penalties are severe: the Schedule to the DPDPA 2023 caps penalties at ₹250 crore per instance for failure to take reasonable security safeguards under Section 8(5) — the highest slab in the Act, and the one breach cases fall under.
Sources
- Digital Personal Data Protection Act, 2023 — MeitY: https://www.meity.gov.in/writereaddata/files/Digital%20Personal%20Data%20Protection%20Act%202023.pdf
- Digital Personal Data Protection Rules, 2025 — Gazette notification, MeitY: https://www.meity.gov.in/data-protection-framework
- CERT-In Directions dated 28.04.2022 under Section 70B(6), IT Act 2000: https://www.cert-in.org.in/Directions70B.jsp
- PIB — Notification of the DPDP Rules, 2025: https://pib.gov.in/PressReleasePage.aspx?PRID=2075278
This article is general information on DPDPA compliance for NBFCs and is not legal advice; consult qualified counsel for decisions specific to your organisation.

