Data Protection in the Financial Sector

By Ananya Sarkar and Pratishtha Sharma

Personal data is critical to financial services industry, right from loan applications and insurance policies to payment transactions. Financial institutions routinely process personal information, including financial records, personal identity details, transaction details, biometrics, health data etc., making them particularly exposed to privacy and data protection risks. The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 establish a comprehensive framework governing the collection, use, storage, retention and sharing of personal data, making compliance a key regulatory responsibility for the sector.

Type of Personal Data processed by Financial Institutions

Financial institutions collect personal data throughout the customer lifecycle, not just at onboarding. Information is continuously gathered through transactions, claims, service requests and digital interactions. For banks, NBFCs, insurers, intermediaries and payment service providers, this typically includes:

  • Identity and KYC information such as name, address, date of birth, photograph and biometric data.
  • Financial and transaction data including account details, credit history, repayment records and transaction activity.
  • Health and lifestyle information particularly in the insurance sector, such as medical records and data collected through wearable devices or telematics.
  • Behavioural and relationship data including nominee details, customer communications and usage patterns across digital platforms.

Much of this information qualifies as digital personal data under the DPDP Act. The Act requires organisations to collect only the personal data necessary for a specific, clearly stated purpose. For many financial institutions, meeting these data minimisation requirements may require changes to existing data collection practices.

Role of Financial Institutions under the DPDP Act

Financial institutions may act as either a Data Fiduciary or a Data Processor depending on the purpose of collection. A bank acts as a Data Fiduciary when processing customer data for KYC, account management, or transaction monitoring, but may act as a Data Processor when handling personal data on behalf of another organisation in arrangements such as co-branded credit cards or fintech partnerships.

Similarly, insurers are generally Data Fiduciaries in relation to policyholder data, while entities such as Third-Party Administrators that process claims on their behalf typically function as Data Processors. Other service providers, including cloud providers, outsourcing vendors and payment processors, may also act as Data Processors. However, outsourcing does not transfer legal responsibility. Under the DPDP Act, compliance obligations remain with the Data Fiduciary, making it essential for financial institutions to address data security, retention and breach management requirements in their vendor contracts.

Data Protection Challenges in the Financial Sector

A key challenge for financial institutions is their growing dependence on third-party service providers. As critical functions are outsourced, customer data may be exposed through vendors or partners, making third-party risk both a cybersecurity and compliance concern. Other significant risks include:

  • Cybersecurity threats: Financial institutions remain prime targets for cyberattacks due to the volume and sensitivity of the data they hold. Data breaches in the financial sector can cause significant financial, operational and reputational harm.
  • Data localisation and cross-border transfers: While the DPDP Act generally permits cross-border data transfers, sector-specific regulations may restrict where certain categories of financial data can be stored or processed.
  • Fraud and identity theft: Exposure of financial and identity information can lead to unauthorised transactions, fraud and identity theft.
  • Use of AI and automated decision-making: The growing use of AI for credit assessment, underwriting, fraud detection and customer profiling raises concerns around transparency, fairness and responsible data use.
  • Data retention: Information collected for regulatory purposes is often retained for long periods, creating additional challenges in managing and tracking data.

Sector-Specific Data Protection Requirements

Financial institutions are required to comply with data governance and cybersecurity requirements prescribed by sectoral regulators such as:

  1. Reserve Bank of India: Banks, NBFCs and payment system participants must comply with RBI’s information security and cybersecurity requirements, including the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, 2023, the Master Direction on Digital Payment Security Controls, 2021 and the RBI (Digital Lending) Directions, 2025. These frameworks require regulated entities to implement appropriate security controls, strengthen governance, manage third-party risks and safeguard customer data.
  2. Securities and Exchange Board of India: SEBI-regulated entities, including stock exchanges, depositories, market intermediaries and mutual funds are required to comply with the Cybersecurity and Cyber Resilience Framework, 2024. The framework prescribes governance, cybersecurity, incident reporting and cyber resilience measures to protect investor data and the integrity of the securities market.

Obligations Under the DPDP Act and Rules

The DPDP Act and Rules inter alia impose several obligations on financial institutions, requiring them to strengthen their data governance and compliance frameworks:

  1. Notice and consent: Institutions must provide clear notice about the personal data they collect and its intended use. Consent must be free, specific, informed and unconditional, unless processing falls within a recognised legitimate use.
  2. Security safeguards: Reasonable security measures must be implemented to protect personal data and complement existing cybersecurity requirements issued by sectoral regulators.
  3. Breach reporting: Data Fiduciaries must notify the Data Protection Board and affected individuals of personal data breaches without undue delay and comply with applicable breach reporting requirements, including prescribed reporting timelines.
  4. Data Principal rights: Customers have the right to access, correct and seek erasure of their personal data. Institutions must establish an effective grievance redressal mechanism.
  5. Data retention and erasure: Personal data must be deleted once its purpose has been fulfilled, unless retention is required under applicable laws or regulatory requirements.
  6. Significant Data Fiduciaries: Institutions notified as Significant Data Fiduciaries may be subject to additional requirements, including the appointment of a Data Protection Officer, Data Protection Impact Assessments and independent data audits.

Conclusion

For financial institutions, data protection is no longer just a compliance obligation, it is a core governance priority. The DPDP Act and Rules require organisations to adopt a structured approach to the collection, use, sharing and retention of personal data while maintaining accountability across their vendor ecosystems. As the DPDP framework moves towards full implementation, institutions that embed privacy into their operations will be better positioned to manage risk, strengthen customer trust and build long-term resilience.

To learn more about navigating DPDP compliance, managing privacy risks and implementing effective data protection frameworks in the financial sector, explore our Data Privacy Services page.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from Privacy Desk

Subscribe now to keep reading and get access to the full archive.

Continue reading