India's DPDP Act Forces Fintechs to Overhaul KYC Stacks Within 18 Months
India's Digital Personal Data Protection Act 2023 runs alongside RBI's KYC Master Directions rather than replacing them, creating a separate layer of compliance obligations for fintech companies. The law introduces stricter consent requirements, meaning pre-checked or bundled consent forms are no longer sufficient, and any data use beyond regulatory KYC — such as marketing or credit scoring — requires its own explicit, revocable consent. Purpose limitation is now enforceable, preventing identity data from being quietly repurposed, while retention rules require actual deletion once the legal basis for holding data has ended. Fintechs must also build real workflows to handle data access, correction, and deletion requests within 30 days, and must update vendor contracts to explicitly name DPDP obligations. Non-compliance can attract penalties running into hundreds of crores from the Data Protection Board, with teams having roughly 18 months to make the necessary changes.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in