The DPDP Rules are phasing in through 2026 and 2027. Organisational compliance is mandatory by 13 May 2027.

What this means for you

Home / Sectors / BFSI and lending

Banking, lending and insurance

Lending and insurance businesses already carry regulatory obligations, which usually means some controls exist. The gap is rarely that nothing is documented. It is that what is documented was built for a different regulator, with a different purpose, and nobody has mapped it across.

The Act applies to every organisation that holds personal data. What reasonable looks like changes a great deal by sector, and this is what it changes to here.

The position

What makes this sector different

NBFCs, lending platforms, insurance intermediaries, brokers and cooperative banks hold more categories of personal data than almost any other kind of small business. Identity documents, income proof, bank statements, credit decisions, collection notes and call recordings all sit in different systems, often with different vendors.

The customers here also carry the most risk if something leaks. A marketing list is embarrassing. A folder of identity documents and bank statements is a different order of problem, and it is usually the folder nobody remembered existed.

Discovery

Where personal data usually sits

Drawn from engagements and from the questions that come up most often on first calls in this sector.

Banking, lending and insurance
SystemWhat it holdsWhat usually needs attention
Loan origination systemApplications, identity and income documents, credit decisions, co-applicant detailsRejected applications held forever with the documents attached
CollectionsContact history, call recordings, field agent notes, references and guarantorsReferences were never told their details were taken, and recordings have no notice
Agent networkCustomer data handled by people outside your payrollAgents work from personal phones, with no contract covering data
Credit bureau and KYC vendorsData sent to and received from third partiesNo written data terms, and no record of what was sent when
Customer supportChat transcripts, email history, complaint records, call recordingsRecordings kept indefinitely with no stated retention
MarketingLead lists, pre-approved offer lists, cross-sell segmentsLists bought or imported with no recorded origin
Specific risks

What we look at first here

Identity documents in the wrong place. Scans of identity and address proof end up in shared drives, email threads and WhatsApp during a rush, and stay there.

Agents operating outside your controls. If someone collects customer data on your behalf, you remain answerable for what happens to it, including on their personal device.

References and guarantors. These people never applied for anything. They were named by someone else, and most lenders have never told them their details are held.

Rejected applications. The richest and least useful data in the business. There is usually no rule that ever deletes it.

The engagement

Which steps carry the most weight

The full sequence is on the engagement page. In this sector, these three usually do the heavy lifting.

Priority

Discovery and mapping

The agent and vendor layer is where the surprises are. We map the whole chain, including people who are not your employees.

Priority

Gasp Assessment

Your existing regulatory documentation gets tested against what the data protection position actually requires, so you reuse what works rather than starting again.

Priority

Compliance Support

Notices at application and at collection, retention rules that finally delete rejected applications, and data terms for your agent and vendor agreements.

Existing regulatory compliance is an advantage here, not a complication. Much of what you already do for your sector regulator can be mapped across rather than rebuilt, and part of our job is to tell you which parts those are so you are not paying twice.

Other sectors

Not quite your business?

Every engagement is scoped to what you actually run, so none of these pages will match you exactly.

Start here

Thirty minutes, and you will know where you stand.

Tell us what your business runs on. We will tell you which gaps matter most, whether or not you engage us.