DPDP Compliance for NBFC in India. RBI-aligned. SDF-ready. CERT-In pre-filled.
Every NBFC in India runs under five overlapping regulators for personal data: RBI Master Direction on IT Governance, RBI Digital Lending Guidelines, KYC Direction 5-year retention, CERT-In 6-hour reporting, and the DPDP Act 2023 that now caps failures at ₹250 crore. dcomply gives you one workspace that reconciles all five, one consent artefact that satisfies RBI + DPDP, one retention schedule that handles both, one breach workflow that files DPB + CERT-In in parallel, and a Section 10 named DPO on retainer.
Want your compliance team certified first? Free DPDP course for NBFC staff Certified. 4 hours. Written for BFSI compliance heads.
If any of this sounds familiar, you're in the right place.
These are the exact sentences NBFC compliance heads say on the first call. If two or three are true, dcomply is the workspace you have been trying to build in Excel.
Your KYC data goes back to 2013 and nobody has thought about DPDP purpose limitation.
A borrower asked for a copy of their data and your legal team is drafting a first response.
Your digital lending app collects phone contacts and your privacy policy does not mention it.
Your DPO obligation under Section 10 is unclear and your board asked last week.
Your CERT-In 6-hour incident register is a shared inbox with three CC'd people.
For payment-processor or PPI-specific coverage see the Fintech door. For DPDP fundamentals see the DPDP door. For the RBI Digital Lending overlay see RBI compliance.
Every Indian NBFC lives under all of these.
DPDP is the foundation because every borrower generates personal data. RBI Digital Lending sits directly on top. KYC and PMLA are the operational baseline. CERT-In catches every cyber incident. SEBI applies if you securitise. dcomply ships modules for each layer.
One NBFC, five overlapping regulators
From loan origination to recovery, each stage generates a separate register. dcomply collapses them into one workspace.
KYC vs DPDP retention
RBI wants 5 years post-relationship. DPDP wants purpose-limited erasure. Reconciling the two is a legal-tech puzzle most NBFCs punt on.
Digital lending consent
Apps collect GPS, phone contacts, SMS history. RBI + DPDP + your privacy policy rarely agree. Fine print does not survive scrutiny.
Recovery agent liability
Agents are Data Processors. Without a DPA and agent register, the NBFC is directly liable for agent conduct under DPDP + FPC.
CERT-In + DPB dual notification
Ransomware = CERT-In in 6 hours + DPB notification + affected borrower notice. Three formats, three deadlines, one incident.
Every NBFC module, pre-mapped to Indian law
Subscribe to dcomply Business and you get all of these. No three-month implementation.
Borrower Consent Capture
RBI + DPDP unified consent at loan origination. Purpose-itemised, versioned, withdrawable, in 22 Indian languages.
Borrower DSR Portal
Access, correction, erasure requests via public portal. SLA-tracked. Auto-reconciled against RBI 5-year retention.
Breach Notification
DPB + CERT-In dual filing. 6-hour incident report pre-filled. Affected-borrower notice in local language.
Retention Schedule
Two-phase retention: RBI 5-year hold, then purpose-limited erasure. Per-category rule engine.
Digital Lending Compliance
KFS format, LSP disclosure, cool-off period, prohibition on sensitive data storage on app.
RBI Master Direction Tracker
IT Governance, Cybersecurity, Fraud Risk, Outsourcing, one deadline register.
CERT-In Incident Register
6-hour incident reporting, 180-day log retention, named CISO, tabletop drill logger.
KYC + PMLA Records
Beneficial owner register, STR/CTR co-ordination, PEP screening, quarterly return reminders.
SDF Determination
Live Section 10 SDF classifier. Sensitivity + volume + rights + sovereignty risk model.
DPIA Library
Auto-triggered on new digital lending product, cross-border transfer, or high-volume data category.
Named vDPO
Section 10(2)(a) compliant named DPO on retainer. Advocate-DPO from ₹19,999/month.
Evidence Locker
One vault: consent artefacts, breach reports, DSR responses, DPO board reports, RBI inspection prep.
What dcomply replaces
| Regulator / Framework | Why it applies | dcomply module |
|---|---|---|
| DPDP Act 2023 | Every borrower generates personal & financial data | Data Privacy pack (11 modules) |
| DPDP Rules 2025 | Consent format, breach format, DPO obligations | Rules 2025 mapping built-in |
| RBI Digital Lending | Any digital lending app / LSP arrangement | Digital Lending compliance module |
| RBI KYC Direction | All NBFC customer onboarding | KYC records & retention |
| PMLA | AML obligations under 2002 Act | Financial Risk module (STR/CTR) |
| CERT-In 2022 | All ICT infrastructure incidents | CERT-In incident register |
| DPDP Sec. 10 (SDF) | Most large NBFCs classified SDF | SDF determination + DPO + DPIA |
| SEBI LODR | Listed NBFCs only | SEBI LODR tracker (add-on) |
SDF NBFCs need a DPO. We are one.
Most NBFCs will be classified Significant Data Fiduciaries under Section 10 given the volume of sensitive financial data. A DPO is mandatory.
dcomply vDPO Premium provides a named advocate-DPO on retainer from ₹19,999/mo with weekly review calls, 4-hour breach response, DPB liaison and a quarterly board report. Section 10(2)(a) fully satisfied.
See DPO cost breakdownDedicated advocate-DPO on retainer.
- Named advocate as your DPO (Section 10 satisfied)
- Weekly compliance review call
- Breach response in 4 hours (DPB + CERT-In)
- DPB liaison for regulator queries
- Quarterly board report + RBI inspection prep
- Annual staff DPDP training
Questions NBFC compliance heads actually ask.
"RBI inspection was clean."
"We had a live RBI inspection three months into using dcomply. The evidence locker gave us every consent artefact, retention schedule and breach drill log in one export. The inspection team accepted the format. That was the moment I stopped worrying."
Start free. Add the DPO when you need one.
Pay-per-module from ₹1,499. Corporate Compliance pack from ₹11,999. vDPO Premium from ₹19,999.