01
KYC and video-KYC vendors
Aadhaar XML, PAN images, selfies and V-CIP recordings, held in the vendor's storage for as long as their own retention setting says.
Sector
Your borrower data sits under the DPDP Act and Rules, the CERT-In directions, RBI's digital lending and IT governance mandates, TRAI's rules on how you may contact customers, and your SRO's code — at the same time, on the same records.
Most of that data is held by someone else: a KYC processor, an LSP, a collections agency, a bureau. DPDP does not care whose systems failed.
The regulatory stack
MEITY
Notice, consent, rights, retention, transfers, and breach intimation under Rule 7.
CERT-IN
Cyber incident report within 6h of noticing, plus log retention for 180 days.
RBI
No borrower data stored by the LSP, explicit consent for collection, disclosure of the lender behind the app.
RBI
Board-level IT governance, outsourcing controls, incident management and audit trails.
TRAI
DLT-registered headers and templates — which is what decides whether you can notify borrowers at all.
SRO-FT / DLAI
Member conduct on data use, recovery practices and grievance handling.
Where your data actually sits
Each of these is a Data Processor under the Act. Each one needs a contract, a security position and a breach notification path back to you inside your own clock.
01
Aadhaar XML, PAN images, selfies and V-CIP recordings, held in the vendor's storage for as long as their own retention setting says.
02
Sourcing apps and partner platforms that RBI says must not store borrower data — and which frequently cache it in logs and analytics anyway.
03
Delinquency lists on agent phones, WhatsApp groups and personal spreadsheets. The highest-risk personal data you hold, in the least controlled place.
04
Bureau reports, Account Aggregator statements and bank-statement analysers, each retained in an underwriting file nobody purges.
05
SMS aggregators, WhatsApp BSPs and IVR recordings, holding phone numbers, EMI amounts and overdue status in message logs.
06
Shared borrower files under co-lending and direct assignment, where two Data Fiduciaries each think the other is answerable.
Breach patterns
Pattern 01 · Modelled in Fortis Drill #01
A misconfigured bucket at a KYC vendor exposes Aadhaar and PAN images, indexed by a search engine, found by a journalist before it is found by you.
Triggers first: CERT-In · 6h — then Rule 7(1) intimation and borrower notification.
Pattern 02
A delinquency sheet is forwarded to a personal number or a WhatsApp group, then used after the agent leaves the agency.
Triggers first: Rule 7(1) intimation — plus SRO conduct and RBI outsourcing exposure.
Pattern 03
A sourcing partner's crash logs and analytics SDK retain PAN, phone and loan amount, surfacing during an unrelated vendor incident.
Triggers first: RBI Digital Lending Guidelines — then Rule 7 as a processor breach.
Pattern 04
A credit ops user pulls a full borrower extract before resigning. No alert fires because bulk export is a normal privilege for that role.
Triggers first: Rule 6 safeguards and logging — then Rule 7, then a forensic investigation.
Pattern 05
An overdue-EMI campaign is sent against a stale mapping, disclosing loan status to the wrong numbers at scale.
Triggers first: Rule 7 borrower notification — plus TCCCPR and grievance volume within hours.
Pattern 01 is the scenario your team runs in Fortis Drill #01 — ninety minutes, five seats, two clocks.
What we do for lenders
Three weeks. Every processor in the loan lifecycle mapped, from sourcing to collections, with the RBI overlay called out separately.
DetailsEight weeks. Loan-journey notices, consent capture at sourcing, borrower rights workflow, retention reconciled against RBI record-keeping.
DetailsRule 7 and CERT-In plans with named owners, DLT-registered borrower notification templates, and a processor escalation path that beats your own clock.
DetailsFor alternative-data underwriting, bureau and AA flows, and offshore analytics on borrower cohorts.
DetailsCertified fraud examiners for insider data theft, agent misuse and sourcing fraud — when the incident turns out to be internal.
DetailsObjections
Certification covers their management system, not your obligation. Under DPDP you remain the Data Fiduciary for data they process, and the Board will ask for your contract, your security expectations and evidence that you checked. A certificate is one input to that, not a substitute.
Your borrower data is in six places you don't operate. Start by finding all six.
Free consultation · 45 min · in-house privacy counsel and certified fraud examiners.