The RBI Just Wrote the DPDP Act's Missing Implementation Manual — and Comments Close August 17
RBI's draft data governance guidance makes banks tag consent onto every customer record at collection. It is DPDP Act compliance, specified as engineering.
#The RBI Just Wrote the DPDP Act's Missing Implementation Manual — and Comments Close August 17
India's banking regulator has done something the Data Protection Board of India has not: it has told institutions, in concrete engineering terms, what DPDP Act compliance actually looks like inside a database. The RBI's draft Guidance on Regulatory Expectations for Data Governance, released on July 15, 2026, is open for public comment until August 17 — nine days from today — and it deserves attention from far beyond the banks it formally binds.
The headline requirement is deceptively small. Every piece of customer data must be tagged at the moment it is collected with who owns it, why it was taken, how sensitive it is, how long it may be kept, and whether the customer consented — and those tags must travel with the data into every downstream system it touches. That single sentence is the difference between a privacy policy and an actual compliance capability, and no Indian regulator had put it in writing before.
#What the RBI data governance draft actually requires
The draft applies across eleven categories of regulated entities: commercial banks, small finance banks, payments banks, regional rural banks, cooperative banks, NBFCs across all layers, All India Financial Institutions such as EXIM Bank and NABARD, Asset Reconstruction Companies, and — critically for the privacy conversation — Credit Information Companies, meaning CIBIL, Experian, Equifax and CRIF High Mark.
Structurally, it demands three things most Indian institutions do not currently have:
A named accountability chain. Each regulated entity must stand up a dedicated Data Function headed by an officer at Chief General Manager rank or equivalent, per Business Today's reporting. Below that sit three designated roles: Data Owners (who define and classify data in a domain, approve sharing rules, and designate the authoritative source), Data Stewards (day-to-day implementation, documentation, cross-department coordination), and Data Custodians (access controls, security, retention and disposal, business continuity). Oversight runs up through a management-level Data Governance Executive Committee to a Board-level Data Governance Committee.
A Single Source of Truth. Every data element needs exactly one authoritative system of record, with the draft explicitly requiring that no parallel or competing SSOT exists for the same element. Implementation may be centralised, federated or hybrid — but traceability back to the authoritative source is non-negotiable.
Metadata and lineage that survive the journey. Attributes must be established "at the point of origination or capture, to enable downstream governance," and preserved through every transformation. The draft also anticipates something most data classification schemes miss: aggregation changes sensitivity. ThePrint reports that transaction patterns which begin to reveal, say, health information must be reclassified upward accordingly — a pharmacy spending pattern is health data even though no field in the schema says so.
The framework is built on seven stated principles — accountability, integrity, auditability, transparency, traceability, proportionality and standardisation — and draws openly on BCBS 239, the Basel Committee's risk data aggregation standard. That lineage matters: this is prudential regulation reaching into privacy territory, not the other way round.
#Why the consent tag is the hardest problem in DPDP compliance
Here is why this draft matters more than its banking-supervision framing suggests.
The DPDP Act's substantive obligations are not enforceable until May 13, 2027. When they arrive, a data fiduciary must be able to answer questions that sound simple and are brutally hard at scale: What purpose was this record collected for? Did the data principal consent to this use, or a different one? Has consent since been withdrawn? Is the specified purpose still being served, or must this record now be erased?
Section 8 of the DPDP Act places that burden squarely and unconditionally on the fiduciary — responsibility for compliance holds "irrespective of any agreement to the contrary". You can outsource the processing; you cannot outsource the liability. And Section 8(7) requires erasure once the specified purpose is served and no legal retention obligation applies — without the data principal having to ask. Rule 8 of the DPDP Rules 2025 goes further, requiring notice to the data principal at least 48 hours before scheduled erasure.
Now consider what that demands operationally. To erase on purpose-expiry, a system must know what the purpose was. To honour a consent withdrawal, it must know every downstream copy that consent authorised. To send a 48-hour pre-erasure notice, it must be able to compute an expiry date per record, not per table.
None of that is possible if consent lives in a separate consent-management application while the customer data lives in forty systems that have never heard of it. The RBI's tagging requirement — purpose, sensitivity, retention period and consent status attached at origination, flowing downstream — is precisely the plumbing that makes DPDP rights mechanically executable rather than aspirational. It is, functionally, the implementation manual MeitY did not write.
#Where DPDP liability actually lives: third-party sharing
The draft's third-party provisions are the sharpest DPDP intersection, and the most commercially painful.
Regulated entities remain fully accountable for data shared with external providers and with group entities — a point that lands hard on Indian subsidiaries of global banking groups and on the fintech-bank partnership model generally. Controls must govern access, usage, retention, deletion and monitoring; shared data must stay traceable to its designated SSOT; and the arrangement must carry contractual, technical and audit safeguards. Reporting on the draft indicates encryption, authentication, access controls and non-disclosure agreements as baseline expectations, with third-party systems subject to CERT-In empanelled audits.
Crucially, the draft requires those third-party controls to account for data classification, sensitivity and customer consent where personal data is involved. That is a DPDP Section 8(2) obligation — a fiduciary engaging a processor must do so under a valid contract — expressed as a supervisory expectation with an examination trail behind it.
For anyone running a data-sharing business in Indian financial services, the practical consequence is that "the customer agreed to our terms and conditions" stops being an answer. Blanket consent for unspecified downstream sharing does not survive either framework.
#Why a banking regulator got here before the privacy regulator
This is now a recognisable pattern, and it is the most important structural fact about Indian data protection in 2026.
The Data Protection Board of India was constituted on November 13, 2025, and MeitY ran the selection process for its chairperson and members through mid-2026. But the Board is an adjudicatory body. It hears complaints and imposes penalties; it does not write technical standards or tell an industry how to architect its systems. And the obligations it will eventually adjudicate do not bite until May 2027.
So the substantive privacy engineering in India is being done by whoever already holds a lever. In the past three weeks alone: NPCI ordered mobile number masking across UPI by September 4. TRAI acted against 1.83 lakh telecom resources over unsolicited commercial communications in Q1 FY 2026-27, screening 22.99 billion calls against subscriber consent preferences. And now the RBI has specified consent metadata as a supervisory requirement.
None of these instruments cite the DPDP Act as their enabling authority. All three enforce DPDP principles — data minimisation, purpose limitation, consent integrity — on timelines that run ahead of May 2027, against institutions that cannot afford to argue with their sectoral regulator.
The RBI's own timing tells you this is not incidental. These norms land ahead of the Expected Credit Loss framework effective April 1, 2027, which requires banks to model provisioning off historical data whose quality and lineage they must be able to defend. The regulator needs trustworthy data for prudential reasons and privacy-compliant data for statutory reasons, and it has correctly concluded that both problems have the same solution: know what every record is, where it came from, and what you are permitted to do with it.
#What this means if you are not an RBI-regulated entity
Most Indian businesses reading this are not banks. The draft still matters to you for three reasons.
It is a template, and it is free. The RBI has published a defensible, internationally-benchmarked answer to "what does data governance for DPDP compliance actually consist of." The role structure, the classification-and-tagging discipline, the SSOT requirement, the lineage expectations — none of it is bank-specific. A healthcare platform, an edtech company or a D2C retailer facing the same May 2027 deadline can lift the architecture wholesale and scale it down. The draft's own proportionality principle explicitly contemplates calibration to "size, complexity, and business model."
Your bank is about to push it downhill. If you are a fintech, a lending service provider, a BPO, an analytics vendor or any partner in a regulated entity's data supply chain, your contracts are going to be rewritten. Expect consent-status pass-through requirements, lineage attestations, deletion SLAs and audit rights you do not currently grant. Budget for that now, not in the renewal cycle.
It previews the Significant Data Fiduciary regime. The government has not yet published its list of Significant Data Fiduciaries under Section 10, but financial services, health, telecom and large consumer platforms are the obvious candidates. SDFs face heavier obligations — Data Protection Impact Assessments, independent audits, an appointed Data Protection Officer based in India. The governance scaffolding the RBI is describing is very close to what an SDF will need to evidence. If you expect to be designated, this draft is a preview of your examination.
#What to do in the next nine days
The consultation closes August 17, 2026. Two concrete actions:
If you are a regulated entity, file comments. The proportionality language is the lever worth pulling on. Smaller NBFCs and cooperative banks will struggle with a CGM-rank data function head and a full three-role governance structure; the time to argue for tiering is during consultation, not after the final guidance issues. Cost of metadata retrofits on legacy core banking systems is the other argument that will only land now.
Regardless of who regulates you, run the gap check. Three questions answer most of it: Can you produce, for any single customer record, the purpose it was collected for and the consent that authorised it? Can you enumerate every downstream system that holds a copy? Can you delete it everywhere within a defined window? Institutions that answer no to any of these have roughly nine months before the November 13, 2026 consent-manager milestone and twenty-one before full DPDP enforcement — and retrofitting lineage into a mature data estate is a multi-quarter programme, not a policy update.
The penalties frame the stakes plainly: up to ₹250 crore for failure to implement reasonable security safeguards, and up to ₹200 crore for failure to notify a breach. A single incident can attract both.
The pattern to take away is not that banking regulation is encroaching on privacy. It is that DPDP compliance was never going to be a legal exercise. Notice text and consent checkboxes are the visible five per cent; the other ninety-five is metadata, lineage, classification and deletion machinery that takes quarters to build. The RBI has now said so out loud, with a Board-level accountability chain attached. Every other Indian regulator is watching how this consultation lands.
Start with the plumbing. Our consent manager is built to attach purpose, scope and consent state to records at the point of collection and keep them traceable downstream — the exact capability the RBI draft describes and the DPDP Act's erasure and withdrawal rights depend on. For section-by-section obligation mapping, retention matrices and breach-notification templates, see our resources.
Sources: Business Standard · ThePrint · Business Today · Cyril Amarchand Mangaldas — FIG Paper No. 61 · Nasscom Public Policy · DPDP Act 2023, Section 8 · DPDP Rules 2025, Rule 8