Skip to content
A grey concrete bank building
Article

India's Data Protection Board began its first enforcement actions in Q1 2026 as fintechs navigate a dual compliance burden with RBI's separate data rules.

DPDP Act 2026: What India's Privacy Law Means for Fintechs

India's DPDP Act is now in active enforcement, layering consent and retention obligations on top of RBI's payment-data localization mandate — with no size exemption for startups.

PV

Parivestra Research Desk

22 July 2026 · 2 min read

Share

India's Digital Personal Data Protection (DPDP) Act moved from passed-but-dormant legislation to an actively enforced law in 2026, and fintechs are feeling the compliance weight first.

Enforcement has already begun

The Data Protection Board initiated its first enforcement actions in Q1 2026, targeting app developers found processing personal data without valid consent or with inadequate retention policies. That's a meaningful marker — DPDP is no longer a future-tense compliance item on a roadmap; it's live.

A dual compliance burden, not a replacement

For fintechs specifically, the DPDP Act layers on top of existing RBI rules rather than replacing them. Payment System Operators must continue storing all payment-system data, including end-to-end transaction details, exclusively on servers located in India — RBI's payment-data localization mandate continues to override the DPDP Act's more permissive cross-border data transfer provisions. Sector regulators including IRDAI, SEBI, the Department of Telecommunications, and CERT-In also maintain their own localization mandates that remain in full force alongside DPDP. The net effect: fintechs face compliance obligations from RBI and the DPDP Act simultaneously, with no single unified standard.

The most concrete near-term milestone is the Consent Manager Framework, which becomes operational November 13, 2026. This introduces licensed intermediaries through which individuals can manage and revoke consent for how their data is used — a structural change fintechs handling KYC and transaction data will need to integrate with.

No exemption for smaller players

Critically, the DPDP Act applies broadly: any organization — startup, SME, MNC, NGO, or government body — that digitally processes personal data of Indian residents must comply, with no minimum turnover threshold, employee count exemption, or SME carve-out. Most operational obligations phase in over an 18-month runway, reaching full effect by mid-May 2027, but several intermediate deadlines land squarely within 2026.

Sources

Fintech Laws and Regulations 2026: India — ICLG, DPDP Act Compliance for BFSI, NBFCs & Fintech — MYITMANAGER, Fintech and Data Privacy in India: When RBI and the DPDP Act Pull in Opposite Directions — LawLex.Org.

Frequently asked questions

No. RBI's payment-data localization mandate continues to override the DPDP Act's more permissive cross-border transfer provisions for payment system operators, meaning fintechs must comply with both frameworks simultaneously.

No. The DPDP Act applies to any organization — startup, SME, MNC, NGO, or government body — that digitally processes personal data of Indian residents, with no minimum turnover threshold or employee count exemption.

Yes — the Data Protection Board initiated its first enforcement actions in Q1 2026 against app developers found processing data without valid consent or with inadequate data retention policies.