NBFC door. DPDP + RBI + CERT-In + KYC + PMLA reconciled.

DPDP Compliance for NBFC in India. RBI-aligned. SDF-ready. CERT-In pre-filled.

Every NBFC in India runs under five overlapping regulators for personal data: RBI Master Direction on IT Governance, RBI Digital Lending Guidelines, KYC Direction 5-year retention, CERT-In 6-hour reporting, and the DPDP Act 2023 that now caps failures at ₹250 crore. dcomply gives you one workspace that reconciles all five, one consent artefact that satisfies RBI + DPDP, one retention schedule that handles both, one breach workflow that files DPB + CERT-In in parallel, and a Section 10 named DPO on retainer.

Want your compliance team certified first? Free DPDP course for NBFC staff Certified. 4 hours. Written for BFSI compliance heads.

One consent for RBI + DPDP Reconciled retention (5-yr + purpose) Advocate-DPO for SDF status
Live NBFC Compliance Snapshot
Acme Finance Ltd (NBFC-ND)
DPDP Readiness: 76/100 AMBER
───────────────────────────────
DPDP consent artefacts ....... 94%
KYC retention (RBI-aligned) . Compliant
CERT-In incident register ... 180d retained
SDF status (Section 10) ..... Likely SDF
DPO appointed ............... vDPO Premium
───────────────────────────────
Open DSRs: 3 (all in SLA) · CERT-In drill: 14 days ago
Powered by dcomply
Sound familiar?

If any of this sounds familiar, you're in the right place.

These are the exact sentences NBFC compliance heads say on the first call. If two or three are true, dcomply is the workspace you have been trying to build in Excel.

Your KYC data goes back to 2013 and nobody has thought about DPDP purpose limitation.

A borrower asked for a copy of their data and your legal team is drafting a first response.

Your digital lending app collects phone contacts and your privacy policy does not mention it.

Your DPO obligation under Section 10 is unclear and your board asked last week.

Your CERT-In 6-hour incident register is a shared inbox with three CC'd people.

For payment-processor or PPI-specific coverage see the Fintech door. For DPDP fundamentals see the DPDP door. For the RBI Digital Lending overlay see RBI compliance.

Your regulator stack

Every Indian NBFC lives under all of these.

DPDP is the foundation because every borrower generates personal data. RBI Digital Lending sits directly on top. KYC and PMLA are the operational baseline. CERT-In catches every cyber incident. SEBI applies if you securitise. dcomply ships modules for each layer.

SEBI (if securitisation)
Securitisation disclosures, related-party transactions, listing obligations for listed NBFCs.
CERT-In Directions 2022
6-hour incident report for ransomware, data breach, unauthorised access. 180-day log retention. Named CISO.
KYC Direction + PMLA
5-year post-relationship record retention, STR / CTR filings, SDD escalation, beneficial ownership.
RBI Digital Lending Guidelines
Consent for data collection, prohibition on sensitive data on app, KFS format, LSP disclosure, cool-off period.
DPDP Act 2023 + Rules 2025
The foundation. Every borrower interaction generates personal data. Consent, DSR, breach, retention, Section 10 SDF DPO.
₹250 Cr
Max DPDP penalty per violation
6 hours
CERT-In incident reporting window
5 years
RBI KYC retention post-relationship
SDF likely
Most mid-to-large NBFCs
Why NBFC compliance is a spreadsheet nightmare

One NBFC, five overlapping regulators

From loan origination to recovery, each stage generates a separate register. dcomply collapses them into one workspace.

KYC vs DPDP retention

RBI wants 5 years post-relationship. DPDP wants purpose-limited erasure. Reconciling the two is a legal-tech puzzle most NBFCs punt on.

Digital lending consent

Apps collect GPS, phone contacts, SMS history. RBI + DPDP + your privacy policy rarely agree. Fine print does not survive scrutiny.

Recovery agent liability

Agents are Data Processors. Without a DPA and agent register, the NBFC is directly liable for agent conduct under DPDP + FPC.

CERT-In + DPB dual notification

Ransomware = CERT-In in 6 hours + DPB notification + affected borrower notice. Three formats, three deadlines, one incident.

In your tenant on day one

Every NBFC module, pre-mapped to Indian law

Subscribe to dcomply Business and you get all of these. No three-month implementation.

DPDP
Borrower Consent Capture

RBI + DPDP unified consent at loan origination. Purpose-itemised, versioned, withdrawable, in 22 Indian languages.

DPDP
Borrower DSR Portal

Access, correction, erasure requests via public portal. SLA-tracked. Auto-reconciled against RBI 5-year retention.

DPDP
Breach Notification

DPB + CERT-In dual filing. 6-hour incident report pre-filled. Affected-borrower notice in local language.

DPDP
Retention Schedule

Two-phase retention: RBI 5-year hold, then purpose-limited erasure. Per-category rule engine.

RBI
Digital Lending Compliance

KFS format, LSP disclosure, cool-off period, prohibition on sensitive data storage on app.

RBI
RBI Master Direction Tracker

IT Governance, Cybersecurity, Fraud Risk, Outsourcing, one deadline register.

CERT-In
CERT-In Incident Register

6-hour incident reporting, 180-day log retention, named CISO, tabletop drill logger.

KYC/PMLA
KYC + PMLA Records

Beneficial owner register, STR/CTR co-ordination, PEP screening, quarterly return reminders.

SDF
SDF Determination

Live Section 10 SDF classifier. Sensitivity + volume + rights + sovereignty risk model.

DPIA
DPIA Library

Auto-triggered on new digital lending product, cross-border transfer, or high-volume data category.

DPO
Named vDPO

Section 10(2)(a) compliant named DPO on retainer. Advocate-DPO from ₹19,999/month.

Audit
Evidence Locker

One vault: consent artefacts, breach reports, DSR responses, DPO board reports, RBI inspection prep.

Coverage by regulator

What dcomply replaces

Regulator / FrameworkWhy it appliesdcomply module
DPDP Act 2023Every borrower generates personal & financial data Data Privacy pack (11 modules)
DPDP Rules 2025Consent format, breach format, DPO obligations Rules 2025 mapping built-in
RBI Digital LendingAny digital lending app / LSP arrangement Digital Lending compliance module
RBI KYC DirectionAll NBFC customer onboarding KYC records & retention
PMLAAML obligations under 2002 Act Financial Risk module (STR/CTR)
CERT-In 2022All ICT infrastructure incidents CERT-In incident register
DPDP Sec. 10 (SDF)Most large NBFCs classified SDF SDF determination + DPO + DPIA
SEBI LODRListed NBFCs only SEBI LODR tracker (add-on)
vDPO Add-on

SDF NBFCs need a DPO. We are one.

Most NBFCs will be classified Significant Data Fiduciaries under Section 10 given the volume of sensitive financial data. A DPO is mandatory.

dcomply vDPO Premium provides a named advocate-DPO on retainer from ₹19,999/mo with weekly review calls, 4-hour breach response, DPB liaison and a quarterly board report. Section 10(2)(a) fully satisfied.

See DPO cost breakdown
vDPO Premium for NBFCs₹19,999/mo

Dedicated advocate-DPO on retainer.

  • Named advocate as your DPO (Section 10 satisfied)
  • Weekly compliance review call
  • Breach response in 4 hours (DPB + CERT-In)
  • DPB liaison for regulator queries
  • Quarterly board report + RBI inspection prep
  • Annual staff DPDP training
NBFC DPDP FAQs

Questions NBFC compliance heads actually ask.

NBFCs are Data Fiduciaries under the DPDP Act 2023 because they determine the purpose and means of processing borrower personal data. KYC, financial history, income, credit bureau pulls, GPS at loan origination, phone contacts on digital lending apps, and repayment behaviour. Every one of these creates DPDP obligations on consent, purpose limitation, retention, DSR fulfilment and breach notification.

The Central Government will notify SDFs based on Section 10(1) factors. Given the volume of sensitive financial data and the systemic role of NBFCs, most mid-to-large NBFCs and all HFCs are expected to be classified as SDFs. That triggers mandatory DPO, DPIA and independent audit obligations.

RBI Master Direction on KYC requires records to be maintained for at least five years after the business relationship ends. DPDP Section 8(7) requires erasure when the purpose is no longer served. The reconciliation: hold KYC records for the RBI-mandated period as a lawful obligation under Section 7 (legitimate use), then erase per DPDP. dcomply's Retention module encodes this as a two-phase policy per data class.

The RBI Digital Lending Guidelines (September 2022, updated 2023) require explicit consent for data collection, purpose limitation, prohibition on sensitive data storage on the app, deletion on request, and disclosure of data collection to the borrower. All of these map directly to DPDP obligations. dcomply provides one consent artefact that satisfies both regulators.

CERT-In Direction 20(3)/2022 requires 6-hour incident reporting for ransomware, data breach, unauthorised access, and 20+ other incident types. NBFCs face this alongside DPDP breach notification. dcomply pre-fills both formats and preserves logs for the 180-day CERT-In retention.

Recovery agents are Data Processors under DPDP Section 8(2) if they process data on the NBFC's instructions, or joint Data Fiduciaries if they determine their own purposes. Either way, contractual DPAs are mandatory, and the NBFC remains accountable for agent conduct. dcomply ships recovery-agent DPA templates.

Highest exposure: Section 8(5) security safeguards failure (₹250 crore) for ransomware on borrower data, Section 8(6) breach notification failure (₹200 crore), and Section 10 SDF obligations failure (₹150 crore) for missing DPO or audit. NBFCs also carry RBI monetary penalties in parallel.

Yes, if classified as SDF. dcomply's vDPO Premium provides a named advocate-DPO on retainer from ₹19,999/month, which is Section 10(2)(a) compliant. Most large NBFCs pair this with an internal compliance officer.

DPDP Section 11 gives borrowers a right to access, correct and erase their personal data. dcomply provides a public DSR portal at yournbfc.dcomply.in where borrowers can submit requests. Each request is SLA-tracked. Erasure requests are reconciled against RBI 5-year retention automatically.

RBI Circular DPSS.CO.OD.No.2785/06.08.005/2017-18 requires payment system data to be stored only in India. DPDP Section 16 adds a cross-border regime that may whitelist select destinations. dcomply's Cross-Border Transfer module maps every third-party (cloud, credit bureau, analytics) to the applicable regime.

dcomply runs as a parallel compliance workspace and does not require Loan Origination or Loan Management System integration. Borrower data stays in your LOS/LMS. Compliance evidence, workflows and audit trails live in dcomply. Native connectors for leading LOS platforms are on the roadmap.

PMLA obligations sit alongside DPDP, not inside it. dcomply covers KYC-related record-keeping and consent artefacts but the STR / CTR filings themselves stay with your AML system. Our Financial Risk module tracks PMLA deadlines and RBI STR reporting for coordination.
Real lenders, real compliance programmes

"RBI inspection was clean."

"We had a live RBI inspection three months into using dcomply. The evidence locker gave us every consent artefact, retention schedule and breach drill log in one export. The inspection team accepted the format. That was the moment I stopped worrying."
Head of Compliance, a mid-market NBFC-ND-SI in Mumbai.

Start free. Add the DPO when you need one.

Pay-per-module from ₹1,499. Corporate Compliance pack from ₹11,999. vDPO Premium from ₹19,999.