RISKFORTIS
Enforcement092d 01h 44m

Sector

DPDP compliance for lending & NBFCs

Your borrower data sits under the DPDP Act and Rules, the CERT-In directions, RBI's digital lending and IT governance mandates, TRAI's rules on how you may contact customers, and your SRO's code — at the same time, on the same records.

Most of that data is held by someone else: a KYC processor, an LSP, a collections agency, a bureau. DPDP does not care whose systems failed.

The regulatory stack

MEITY

DPDP Act 2023 & Rules 2025

Notice, consent, rights, retention, transfers, and breach intimation under Rule 7.

CERT-IN

Directions of 2022

Cyber incident report within 6h of noticing, plus log retention for 180 days.

RBI

Digital Lending Guidelines

No borrower data stored by the LSP, explicit consent for collection, disclosure of the lender behind the app.

RBI

Master Direction, IT Governance

Board-level IT governance, outsourcing controls, incident management and audit trails.

TRAI

TCCCPR

DLT-registered headers and templates — which is what decides whether you can notify borrowers at all.

SRO-FT / DLAI

SRO codes of conduct

Member conduct on data use, recovery practices and grievance handling.

Where your data actually sits

Six systems holding borrower data that you don't operate.

Each of these is a Data Processor under the Act. Each one needs a contract, a security position and a breach notification path back to you inside your own clock.

01

KYC and video-KYC vendors

Aadhaar XML, PAN images, selfies and V-CIP recordings, held in the vendor's storage for as long as their own retention setting says.

02

Lending Service Providers

Sourcing apps and partner platforms that RBI says must not store borrower data — and which frequently cache it in logs and analytics anyway.

03

Collections and tele-calling agencies

Delinquency lists on agent phones, WhatsApp groups and personal spreadsheets. The highest-risk personal data you hold, in the least controlled place.

04

Bureau, AA and alt-data pulls

Bureau reports, Account Aggregator statements and bank-statement analysers, each retained in an underwriting file nobody purges.

05

Communication and DLT stack

SMS aggregators, WhatsApp BSPs and IVR recordings, holding phone numbers, EMI amounts and overdue status in message logs.

06

Co-lending and DA/DL partners

Shared borrower files under co-lending and direct assignment, where two Data Fiduciaries each think the other is answerable.

Breach patterns

Five ways lending books actually leak.

  1. Pattern 01 · Modelled in Fortis Drill #01

    Public KYC document store at a processor

    A misconfigured bucket at a KYC vendor exposes Aadhaar and PAN images, indexed by a search engine, found by a journalist before it is found by you.

    Triggers first: CERT-In · 6h — then Rule 7(1) intimation and borrower notification.

  2. Pattern 02

    Collections list leaves with an agent

    A delinquency sheet is forwarded to a personal number or a WhatsApp group, then used after the agent leaves the agency.

    Triggers first: Rule 7(1) intimation — plus SRO conduct and RBI outsourcing exposure.

  3. Pattern 03

    LSP app caches borrower data it should not hold

    A sourcing partner's crash logs and analytics SDK retain PAN, phone and loan amount, surfacing during an unrelated vendor incident.

    Triggers first: RBI Digital Lending Guidelines — then Rule 7 as a processor breach.

  4. Pattern 04

    Insider export from the LOS or CRM

    A credit ops user pulls a full borrower extract before resigning. No alert fires because bulk export is a normal privilege for that role.

    Triggers first: Rule 6 safeguards and logging — then Rule 7, then a forensic investigation.

  5. Pattern 05

    Misdirected bulk communication

    An overdue-EMI campaign is sent against a stale mapping, disclosing loan status to the wrong numbers at scale.

    Triggers first: Rule 7 borrower notification — plus TCCCPR and grievance volume within hours.

Pattern 01 is the scenario your team runs in Fortis Drill #01 — ninety minutes, five seats, two clocks.

What we do for lenders

Five of our eight lines, scoped for a loan book.

01FIXED SCOPE · FIXED FEE

DPDP Gap Assessment

Three weeks. Every processor in the loan lifecycle mapped, from sourcing to collections, with the RBI overlay called out separately.

Details
02FIXED SCOPE · FIXED FEE

DPDP Compliance Implementation

Eight weeks. Loan-journey notices, consent capture at sourcing, borrower rights workflow, retention reconciled against RBI record-keeping.

Details
03

DPDP Breach Readiness

Rule 7 and CERT-In plans with named owners, DLT-registered borrower notification templates, and a processor escalation path that beats your own clock.

Details
04

DPIA & Transfer Assessments

For alternative-data underwriting, bureau and AA flows, and offshore analytics on borrower cohorts.

Details
05

Fraud Investigation & Forensics

Certified fraud examiners for insider data theft, agent misuse and sourcing fraud — when the incident turns out to be internal.

Details

Objections

Certification covers their management system, not your obligation. Under DPDP you remain the Data Fiduciary for data they process, and the Board will ask for your contract, your security expectations and evidence that you checked. A certificate is one input to that, not a substitute.

Your borrower data is in six places you don't operate. Start by finding all six.

Talk to DPDP experts

Free consultation · 45 min · in-house privacy counsel and certified fraud examiners.