NBFCs
Liability Check
NBFCs dealing with sensitive customer financial data, credit scores, and loan applications are highly susceptible to DPDP violations, facing penalties up to ₹250 Crore.
Why NBFCs is at Risk
NBFCs inherently process vast amounts of personal data, from **loan applications** and **credit histories** to **repayment records** and **Aadhaar for KYC**. This volume and sensitivity often qualifies them as **Significant Data Fiduciaries** under DPDP, requiring stricter obligations like Data Protection Impact Assessments (DPIAs) and a Data Protection Officer (DPO). The intersection with existing RBI guidelines adds another layer of complexity, making data sharing with collection agents, credit bureaus, and fintech partners particularly risky. Unchecked data flows could lead to massive fines.
Common Violations
- 1.Retaining detailed customer financial histories or KYC documents (like Aadhaar copies) longer than necessary for legal or business purposes without a clear retention policy.
- 2.Sharing customer default data or contact details with third-party recovery agents or marketing partners without explicit, granular consent or a lawful basis.
- 3.Using customer loan application data for cross-selling other financial products (e.g., insurance, wealth management) without obtaining specific, separate consent for each purpose.
The Immediate Fix
Immediately conduct a comprehensive data mapping exercise to identify all customer, employee, and partner data flows within your NBFC. Review all existing consent forms and third-party vendor agreements (e.g., collection agencies, credit bureaus) to ensure DPDP-compliant data sharing and processing clauses are in place.
Get DPDP Updates for NBFCs
We'll send you compliance alerts and deadline reminders specific to your area. No spam — unsubscribe anytime.
Projected Compliance Deadline: Immediate
What Should You Do Next?