RBI data governance draft redraws bank-fintech ties

RBI data governance draft
RBI's data governance draft could reshape bank-fintech contracts as lenders face greater responsibility for third-party data risks.

RBI data governance draft: For years, banks and NBFCs supplied the licence, balance sheet and customers while fintech companies supplied technology, analytics and digital distribution. The division of labour helped fuel India’s digital lending boom. It also scattered customer data across lenders, apps, cloud providers, KYC vendors and analytics firms.

The Reserve Bank of India now wants regulated entities to know where that data sits, how it moves and who is accountable for it. Its draft Guidance on Regulatory Expectations for Data Governance, issued on July 15, puts data governance within the institution’s risk architecture and extends scrutiny to third-party arrangements. The consultation closed on August 17.

READ | DPDP Act: Can India enforce its data protection law?

The consequences will extend well beyond banks and NBFCs. Much of modern finance runs through technology partners. If lenders remain answerable for the data moving through these arrangements, fintech contracts, systems and business models will have to reflect that responsibility.

Data governance moves to the boardroom

The RBI draft asks regulated entities to establish a Data Governance Framework aligned with their risk-management framework. It envisages board oversight, a board-level committee responsible for data governance and an executive committee to implement the framework. It also assigns specific responsibilities to data owners, stewards and custodians.

The technical requirements are equally important. Institutions are expected to understand the origin and movement of data, maintain metadata and lineage, classify information according to risk and sensitivity, manage data quality and apply controls throughout the data lifecycle. Third-party data sharing falls within the same structure.

This is a substantial change for institutions built over decades on fragmented technology systems. Customer information that once remained largely within a lender’s own systems can now pass through a lending service provider, digital lending app, cloud platform, KYC vendor and analytics company before a transaction is completed. The speed of that movement makes accountability harder, not less necessary.

The RBI’s proposal seeks to make that trail visible. A regulated entity should be able to identify what data it holds, its source, where it has been processed, who can access it and how long it should be retained. For banks and NBFCs with ageing or fragmented systems, meeting that standard could require sizeable investment in data architecture and controls.

READ | Data protection law risks fortifying Big Tech

Outsourcing carries accountability with it

The principle itself is not new. The RBI’s 2023 directions on outsourcing of information technology services state that outsourcing does not diminish the obligations of a regulated entity, its board or senior management. The regulated entity remains ultimately responsible for the outsourced activity. Its contracts must also provide for oversight, access, audit and business continuity. RBI directions on outsourcing of IT services

Data protection law pushes in the same direction. Under the Digital Personal Data Protection Act, a Data Fiduciary is responsible for compliance in respect of personal-data processing undertaken by it or on its behalf by a Data Processor. The law also requires a valid contract when a processor handles personal data on behalf of a fiduciary.

This matters for the bank-fintech relationship. A lender can outsource customer acquisition, verification, loan processing, analytics or the customer interface. It cannot assume that contractual outsourcing removes its regulatory exposure when customer data is mishandled.

Fintech companies that fall outside the RBI’s regulated perimeter are not directly brought under the draft guidance merely because they supply technology to a bank or NBFC. In practice, however, lenders are likely to transmit much of the regulatory burden through vendor selection, contracts, audits and technology standards. Fintechs may also have obligations in their own right under the DPDP framework, depending on the role they play in processing personal data.

DPDP raises the cost of weak controls

The government notified the Digital Personal Data Protection Rules in November 2025. Implementation is phased over an 18-month transition period, giving organisations time to modify systems and processes. DPDP Rules and implementation framework

The financial stakes are considerable. The DPDP Act’s penalty schedule provides for penalties of up to ₹250 crore for failure to take reasonable security safeguards against a personal-data breach and up to ₹200 crore for failure to notify the Data Protection Board or affected individuals of a breach. Other violations can attract penalties of up to ₹50 crore. These are maximum amounts; the penalty is to be determined according to factors including the nature, gravity and duration of the breach.

The transition period matters. These provisions should not be read as though the entire DPDP enforcement regime is already fully operative. The government has provided phased commencement, while organisations prepare for the substantive compliance requirements.

For a large bank or NBFC, a statutory penalty may still be only part of the cost of a serious breach. Customer information sits close to the heart of the financial relationship. Once account, identity or transaction data are compromised, the institution faces remediation costs, regulatory scrutiny and damage to customer confidence.

READ | Data protection: Govts step up regulation of data use by social media firms

RBI data governance draft: Fintech economics will change

The most immediate effect is likely to be contractual. Banks and NBFCs will want more exact definitions of data access, permitted use, security controls, audit rights, retention and deletion. They will demand stronger evidence that technology partners can meet these obligations before onboarding them or renewing contracts.

That changes the basis on which fintech companies compete. User experience, customer acquisition costs and lending speed will still matter. So will the ability to demonstrate where data came from, what happened to it and whether access to it was authorised.

Compliance will cost money. Larger fintech companies can hire specialised teams, upgrade security infrastructure and build governance systems across products. Smaller firms will find that harder. The RBI draft itself recognises proportionality for regulated entities, requiring frameworks appropriate to their size, complexity and business model. Yet lenders dealing with outside vendors may still prefer common standards that simplify their own compliance.

That could produce an unintended consequence. Rules designed to reduce operational and data risk may favour larger technology vendors capable of meeting bank-grade compliance requirements. Smaller fintechs could face higher barriers to working with regulated lenders. Regulators and lenders will need to distinguish genuine risk controls from compliance requirements that merely raise entry costs.

India’s first fintech wave showed that technology could lower the cost and increase the reach of financial services. The regulatory question has moved on. The institutions that benefit from the speed and scale of digital finance are now being asked to account for the data on which that speed and scale depend.

READ | Data Protection Act: Big Tech on government’s cross-hairs over compliance deadline