Table of Contents
Introduction
With the implementation timeline of the Digital Personal Data Protection Act (DPDPA) now clear, stretching from November 2025 to May 2027, Financial Institutions are moving past awareness and intent into real execution. And that’s where the discomfort is setting in. Behind steering committees, compliance trackers, and project plans, difficult questions are surfacing often without clear answers. Practical issues are being discussed between compliance, technology, legal, risk, and business teams trying to figure out what practical DPDPA readiness really entails across layered financial ecosystems.
DPDPA implementation is expected to progress in phases, with different obligations becoming operational over time. The following sections highlight key challenges institutions are addressing across these phases.
The Fiduciary - Processor Grey Zone
BFSI institutions operate through multiple partners such as collection agencies, TPAs, fintech platforms, cloud vendors, and analytics providers. Under the DPDP Act, the institution remains the Data Fiduciary and retains primary accountability for compliance, even though data processing is distributed across partners.
If a vendor mishandles personal data, regulatory scrutiny and liability will primarily attach to the bank, insurer, or NBFC, including in cases where the incident occurs within the vendor’s environment. Accordingly, institutions are required to implement robust contractual controls, due diligence, audits, and ongoing monitoring over vendors. While vendors may also face consequences, fiduciary accountability cannot be outsourced.
Contracts should be revised to include clearer data protection obligations, audit rights, breach reporting timelines, and liability clauses. These provisions help assign responsibility, but they do not prevent data incidents. Data fiduciaries are therefore required to monitor vendor practices, security controls, and data handling on a continuous basis.
Historical Customer Data and Legacy Consent
Join Our Newsletter
Get exclusive insights on banking, fintech, regulatory updates and industry trends delivered to your inbox.
Consent Across Multiple Products and Journeys
Customers usually interact with institutions through multiple products such as deposits, loans, cards, and investments, across digital, assisted, and partner-led channels. While consent frameworks can be clearly defined at a policy level, applying them consistently across interconnected products and data flows requires careful design.
Institutions are evaluating when existing consent applies, when fresh consent is required for cross-selling or analytics, and for how long consent remains valid. Tracking these permissions without disrupting customer journeys remains a key challenge.
To address this, many institutions are undertaking data discovery and consent mapping exercises to link customer journeys, systems, and processing purposes, and are redesigning consent flows to balance compliance with customer experience.
Personal Data in Unstructured and Distributed Systems
Customer data does not sit only in core databases. It is also spread across emails, call recordings, scanned documents, chat histories, and shared drives, often built up over many years with limited structure or oversight. When customers request access to or deletion of their data, responding fully becomes difficult. Addressing this requires reviewing how unstructured data is stored, retained, and accessed over time.
Breach Notification Timelines and Practical Challenges
DPDPA requires organizations to notify the regulator within 72 hours of becoming aware of a data breach. In practice, incidents often take time to assess, and complete details are not always available within that period.
Early notification can mean sharing partial information, while delays risk regulatory and customer trust issues. Coordination becomes more complex when incidents involve multiple parties, such as shared platforms, service providers, or intermediaries.
Cross-Border Data Transfer Considerations
Many BFSI institutions rely on global cloud providers and international vendors as part of their core operations. At the same time, clarity on cross-border data transfer restrictions under DPDPA is still evolving. In response, some institutions are choosing to localize data in advance, while others are continuing existing arrangements until formal guidance is issued. Many are taking a middle path by building the ability to localize or reroute data quickly if required.
Key Takeaways for BFSI Institutions
While DPDPA provides a structured framework, implementation will not follow a straight path. Many aspects require judgement, sequencing, and practical interpretation as organizations move forward.
Institutions that are progressing well are not waiting for complete regulatory clarity. They are taking risk-informed decisions, documenting their approach, and strengthening core capabilities such as data visibility, consent management, security controls, and governance structures.
Equally important, these organizations are focusing on building internal awareness and accountability around data protection. Checklists and controls are only as effective as the extent to which data protection principles are understood across the organization.
DPDPA should therefore be viewed not only as a compliance requirement, but as a shift in how BFSI institutions manage and take responsibility for customer data over time.