DPDPAcademyKnow the law. Prove it.
Home/Implementation/Banking & financial services
§ 17(1)(f) · § 38(1)

The Act Has A Provision Just For Lenders.

Financial services is the only sector with an exemption drafted around its own business problem - and the Act illustrates both that exemption and its retention rule with a bank.

Implementation guide

Covers: banks, NBFCs, fintech, lending apps, insurance, wealth platforms.

Why this sector is treated differently

Regulated financial institutions arrive at the DPDP Act already carrying more data obligations than almost anyone else: RBI directions on storage and localisation, KYC record-keeping, SEBI and IRDAI requirements, prevention of money laundering rules. The first question is always whether the new statute displaces any of it. Section 38(1) answers plainly - the Act is in addition to and not in derogation of any other law for the time being in force. Nothing is displaced. Where an RBI direction is stricter, it governs; where the Act adds a duty, the duty is added.

What makes this sector distinctive is that the Act then legislates directly for one of its problems. Section 17(1)(f) disapplies Chapter II (except sections 8(1) and 8(5)), Chapter III and section 16 where processing is for ascertaining the financial information, assets and liabilities of a person who has defaulted on payment due on a loan or advance taken from a financial institution - with default and financial institution taking their meanings from the Insolvency and Bankruptcy Code. The illustration is a bank and a borrower who misses an instalment.

That exemption is substantial. Chapter III is the entire rights chapter, so a defaulting borrower's access, correction and erasure rights do not run against recovery-related processing. Section 16 is cross-border transfer restriction. What survives is section 8(1) - the Data Fiduciary remains responsible for compliance - and section 8(5), reasonable security safeguards. The exemption removes process obligations; it does not remove accountability or the duty to keep the data secure.

The Act also uses a bank to illustrate its retention rule. Under section 8(7) illustration (II), X closes her savings account, Y is required by law to maintain client identity records for ten years beyond closure, and because retention is necessary for compliance with law, Y retains the data for that period.

Banking & financial services§ 17(1)(f) · § 38(1)The personal data you holdOnboard a customer§ 38(1)3 systems touch it§ 8(7)Service the account§ 38(1)3 systems touch it§ 8(7)Pursue a defaulter§ 17(1)(f)3 systems touch it§ 8(5)Process acrossborders§ 163 systems touch it§ 8(7)10 yearsclient identity records, by law§ 17(1)(f)disapplied for defaulter processing₹250 croremax penalty, safeguards failure
One body of personal data, 4 activities, 4 different answers to when it has to go. That is why the table below has a row per activity rather than per data type.Download as PNG
10 yearsclient identity records, by law§ 8(7)
§ 17(1)(f)disapplied for defaulter processing§ 17(1)(f)
₹250 croremax penalty, safeguards failureSchedule

What you actually process

One row per activity, not per data type. Lawful basis and erasure attach to a purpose, so the same phone number can sit in three rows below with three different answers.

Processing activities, their lawful basis and when the data must be erased
ActivityLawful basisWhen it must go
Onboard a customerIdentity documents, Address proof, PAN, Photograph, Biometrics where used§ 38(1)The Act is in addition to and not in derogation of other law. Identification obligations come from those statutes, so consent is the wrong frame for most of onboarding.§ 8(7)Retention required by law survives the erasure duty. The Act's own illustration is ten years of client identity records beyond account closure, because a law requires it.
Service the accountTransactions, Balances, Communications, Device and channel data§ 38(1)Most account servicing is required or authorised by other law. Where it is not, section 6 consent applies.§ 8(7)Erase what no law requires you to keep once the purpose is served. The carve-out covers retention that is necessary for compliance, not retention that is merely customary.
Pursue a defaulterLoan account, Assets and liabilities, Third-party financial information§ 17(1)(f)Chapter II except sections 8(1) and 8(5), Chapter III and section 16 do not apply where processing is for ascertaining the financial information, assets and liabilities of a person who has defaulted on a loan from a financial institution. Default and financial institution take their Insolvency and Bankruptcy Code meanings.§ 8(5)The exemption removes process duties, not the duty to secure the data. Set a period against the recovery purpose.
Process across bordersCustomer records, Transactions, Support interactions§ 16The Central Government may restrict transfer to notified territories. Rule 12 adds localisation of specified personal data for Significant Data Fiduciaries, and RBI directions continue to apply under section 38(1).§ 8(7)Erasure must reach offshore copies, or it has not happened.

The data flow, and where it breaks

Each lane follows one activity through the actors and systems that touch the data. The failure mode sits on the hop where it happens, rather than in a list somewhere else on the page.

Onboard a customer

Open the account and meet identification obligations

  1. ApplicationCollects the documents§ 5Fails when: Notice presented as a consent form for processing another law already requires
  2. KYC vendorVerifies identity§ 8(2)Fails when: Vendor engaged commercially with no processing contract
  3. Core bankingCreates the customer record§ 38(1)Fails when: The Act treated as replacing sectoral obligations rather than adding to them

Service the account

Operate the account and meet ongoing reporting duties

  1. ChannelsCollect transaction and device dataFails when: Digital channel telemetry grouped with regulated transaction data under one vague basis
  2. Core bankingRecords the transaction§ 38(1)Fails when: Sectoral retention and the Act's erasure duty never reconciled in one register
  3. ReportingFiles regulatory returns§ 7Fails when: Regulatory reporting described to customers as something they consented to

Pursue a defaulter

Ascertain the financial position of a borrower who has defaulted

  1. CollectionsIdentifies the default§ 17(1)(f)Fails when: The exemption applied to the customer's whole relationship rather than to recovery
  2. InvestigationAscertains assets and liabilities§ 17(1)(f)Fails when: Default and financial institution read loosely rather than as the Insolvency and Bankruptcy Code defines them
  3. Recovery agentsAct on the information§ 8(2)Fails when: Agents outside the exemption's scope handling data as if inside it

Process across borders

Use group systems or offshore providers

  1. Group platformProcesses outside India§ 16Fails when: Section 16, rule 12 localisation and RBI directions treated as one rule rather than three
  2. Offshore supportAccesses records to resolve tickets§ 8(2)Fails when: Access granted broadly because the contract is intra-group
  3. AnalyticsAggregates for group reportingFails when: Payment data leaving India despite a direction that requires it to stay

The provisions that apply

§ 17(1)(f)

The defaulter exemption

Chapter II (except sections 8(1) and 8(5)), Chapter III and section 16 do not apply where processing is for ascertaining the financial information and assets and liabilities of a person who has defaulted on payment due on a loan or advance taken from a financial institution. "Default" and "financial institution" carry their Insolvency and Bankruptcy Code meanings, so the scope is defined by another statute and should be read against it.

§ 38(1)

RBI and SEBI directions are untouched

The Act is in addition to and not in derogation of any other law in force. Storage and localisation directions, KYC record-keeping, PMLA obligations and sectoral audit requirements all continue on their own terms. The compliance question is never "which one wins" but "what does each require", and the stricter requirement sets the operating standard.

§ 8(7)

Ten years, illustrated with a bank

Illustration (II) to section 8(7): a customer closes her savings account; the bank is required by law to maintain client identity records for ten years beyond closure; retention is therefore necessary for compliance with law and the bank retains the data. This is the Act confirming that statutory record-keeping defeats the erasure duty - for the records the law names, for the period it names.

§ 10

Significant Data Fiduciary is likely

Designation under section 10 has regard to the volume and sensitivity of personal data processed, the risk to the rights of Data Principals, the potential impact on the sovereignty and integrity of India, the risk to electoral democracy, security of the State and public order. Large financial institutions sit within that profile, bringing a DPO in India, independent audit, DPIAs and the additional measures in rule 12.

What to do about it

  1. Do not treat section 17(1)(f) as a general exemption

    It is bounded by purpose - ascertaining financial information, assets and liabilities of a defaulter. Ordinary account servicing, marketing and analytics for the same customer are outside it. Scope the exemption to the recovery workflow and keep the rest of the estate under the full regime.

  2. Build one retention register across both regimes

    Every record type needs the law that requires retention, the period, and what happens after. Section 8(7) erases what no law requires you to keep, and the answer to that question is already implicit in your RBI and PMLA obligations - it just needs writing down in a form that survives an audit.

  3. Check localisation against section 16 and the Rules

    Section 16 lets the Central Government restrict transfer to notified territories, and rule 12 imposes localisation of specified personal data on Significant Data Fiduciaries. Existing RBI payment data directions continue regardless under section 38(1). Confirm which of the three applies to each data flow, because they have different scopes.

  4. Give consent a smaller job

    Much of a bank's processing is required or authorised by other law, or falls within section 7 legitimate uses. Grounding it in consent creates a withdrawal right you cannot honour against a statutory obligation. Map the basis honestly, and reserve consent for processing the customer can genuinely decline.

Sequence the work

The same controls as above, in the order they are worth doing. Each names the evidence you would put in front of an auditor, because a control you cannot evidence is a control you cannot prove you had.

Phase 01

Build the foundation

Get the lawful basis and the roles right. Everything else assumes these are settled.

  • Onboard a customerGround each element in the law that actually requires it, and reserve consent for the processing a customer can decline without being refused the account.Evidence: A basis map per data element citing the statute, and processing contracts with every verification vendor.
Phase 02

Operationalise it

Turn the basis into systems that run without anyone remembering to run them.

  • Service the accountOne retention register covering both regimes, naming per record type the law that requires retention, the period, and what happens after.Evidence: The register itself, reviewed on a stated cadence, with the statute cited per row.
  • Pursue a defaulterScope the exemption to the recovery workflow and keep the rest of that customer's data under the full regime. Section 8(1) responsibility and section 8(5) safeguards survive regardless.Evidence: A written scope for the exemption, and access controls that stop recovery data reaching general servicing.
Phase 03

Keep it honest

Prove it still works, and answer the people whose data it is.

  • Process across bordersConfirm which of the three applies to each flow, because they have different scopes and the strictest governs.Evidence: A data flow inventory with the governing rule named per flow.

Section and Schedule references above point at the statute itself. Read them in context in the full text of the Act, or against the MeitY publication. This is an educational summary, not legal advice for your organisation.

Banking & financial services

Banking & financial services: common questions

Does the DPDP Act override RBI data localisation directions?

No. Section 38(1) provides that the Act is in addition to and not in derogation of any other law in force. RBI directions continue to apply on their own terms. Section 16 is a separate power for the Central Government to restrict transfers to notified territories, and rule 12 adds localisation duties for Significant Data Fiduciaries. All three can apply to the same institution.

Do borrowers lose their rights once they default?

For a defined purpose, largely yes. Section 17(1)(f) disapplies Chapter III - the rights chapter - where processing is for ascertaining the financial information, assets and liabilities of a defaulter, with default taking its Insolvency and Bankruptcy Code meaning. The exemption is tied to that purpose. Rights continue to run against the institution's other processing of the same person's data.

Can we still delete nothing, given our retention obligations?

No. Section 8(7) carves out retention necessary for compliance with law, not retention that is merely convenient or customary. The Act's own bank illustration is precise about this: ten years, because a law requires ten years. Data your statutory obligations do not name still falls under the erasure duty when the purpose is served.

Know this well enough to prove it

The certification is a free, graded 15-question exam covering the Act end to end, not just this sector. Pass mark is 70%.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against Banking & financial services implementation guide. Educational information, not legal advice.

Review standards and attribution →