RBI's Customer Data Advisory and DPDPA: What Banks and Fintechs Must Reconcile
The RBI's 2025 Customer Data Protection Advisory and the DPDPA 2023 are two parallel frameworks that BFSI organisations must reconcile — and where they conflict, the stricter requirement applies.

BFSI organisations in India are currently navigating two overlapping data protection frameworks: the RBI's Customer Data Protection Advisory and the DPDPA, supported by the finalised DPDP Rules 2025. Both frameworks address customer data protection, and compliance obligations apply simultaneously, often to the same data processing activities.
Organisations cannot choose one framework over the other. They must satisfy both sets of requirements. Understanding where the frameworks align and where they diverge can help organisations develop a more coherent compliance approach.
Where RBI and DPDPA Requirements Overlap
At a practical level, the RBI Advisory and DPDPA share common principles regarding customer data protection. Both frameworks expect organisations to obtain appropriate consent or lawful bases before processing personal data. Both provide customers with rights to access their data and request corrections. Both impose limits on how long personal data can be retained. Both require security measures proportionate to the sensitivity of the data. And both require notification to affected individuals and regulators in the event of a personal data breach.
Organisations that have established policies around these five areas are already positioned to satisfy significant portions of both frameworks. The overlap between the two regulatory regimes is substantial.
Key Differences Between RBI and DPDPA Requirements
Divergences arise because the RBI writes specifically for the banking sector, while the DPDPA is a general-purpose data protection law covering the entire economy.
Financial transaction data. The RBI has granular requirements for how financial transaction data is secured and stored, expectations that go beyond the DPDPA's general security obligations.
Data localisation. The RBI maintains its own requirements around keeping payment data within India. These requirements operate alongside, and in some cases cut across, the DPDPA's rules on cross-border data transfers.
Third-party arrangements. Co-lending partnerships, fintech tie-ups and outsourced analytics are subject to RBI expectations about how customer data moves through these relationships. These obligations remain in force even where the DPDPA also addresses Data Processor and Data Fiduciary relationships.
The differences do not necessarily create contradictions. The RBI tends to be more specific because it addresses banking realities directly, while the DPDPA provides the wider legal framework within which sectoral obligations operate. Insurers and investment platforms face the same layered structure with their own regulators. IRDAI sets retention and disclosure expectations for policyholder data, and SEBI does the same for investor records, so the reconciliation exercise described here for RBI applies just as directly to organisations governed by those regulators.
Applying the Stricter Requirement
Where the RBI and DPDPA impose different requirements on the same activity, organisations should apply the stricter standard.
Consider KYC records. The RBI requires these to be retained for a minimum period after a customer relationship ends. The DPDPA, on its own, might allow earlier deletion. In this case, the RBI rule governs.
For the operational playbook on handling this exact conflict when a customer files an erasure request, see Right to Erasure vs Right to Retention.
The records must be retained for the required period regardless of what the DPDPA would otherwise permit. Conversely, where the DPDPA sets a higher bar for consent on marketing communications than anything the RBI has specified, the DPDPA standard becomes the operating rule.
This approach removes ambiguity when applied consistently across all data processing activities. The stakes for getting this wrong are not abstract. The DPDPA allows the Data Protection Board to levy penalties of up to ₹250 crore per contravention, and RBI carries its own separate enforcement powers under banking law. A single processing activity that falls short of either framework can trigger action from either regulator independently.
Build a Unified Compliance Framework
Treating RBI compliance and DPDPA compliance as separate tracks, managed by separate teams with separate reporting lines, often leads to contradictory internal guidance, duplicated audit work and confusion among frontline staff.
A more effective approach is to build a single, integrated data governance structure. Organisations should map every data processing activity against both frameworks, identify where both apply, determine which standard is stricter where they overlap, implement that stricter standard as the operational policy, and maintain a single audit trail capable of satisfying both the RBI and the Data Protection Board if reviewed by either authority.
This approach turns two parallel obligations into one operating model, with two regulators reviewing different aspects of the same underlying controls.
Align DPO and Compliance Responsibilities
Under the DPDPA, banks classified as Significant Data Fiduciaries must appoint a Data Protection Officer. Most banks already have a Chief Privacy Officer or Data Governance lead responsible for RBI-related data obligations.
These roles should not operate independently. A DPO issuing guidance without visibility into the RBI-facing privacy lead's work may create the exact contradictory instructions that a unified compliance framework is meant to avoid. Organisations should integrate the roles or, at minimum, integrate the decision-making process. One data question should receive one answer, not competing responses depending on which function provided it.
Using Integrated Data Governance to Strengthen Customer Trust
A dual-framework environment could be viewed as an administrative burden. However, BFSI organisations that build an integrated governance layer are not just avoiding penalties. They are constructing the most rigorous customer data protection standard currently existing in any Indian industry.
Customers are growing increasingly aware of how their financial data is used. Organisations that demonstrate strong, integrated data protection practices can build trust advantages that differentiate them from competitors.
BFSI organisations looking to bring their consent, customer data and privacy workflows into a more structured framework can use a consent management platform as part of their broader DPDPA and regulatory compliance strategy. OneConsent helps organisations manage consent records, preferences and related compliance evidence through a centralised consent layer, supporting a more consistent approach across customer touchpoints.
Want to see how OneConsent can support your BFSI data protection workflow? Request a demo to explore the platform and see how it can fit into your existing compliance processes.
Frequently Asked Questions
Have more questions?
Search our full DPDP knowledge base for more answers.