Back to Interaction with Other Laws

RBI Regulations (Banking/FinTech)

How RBI data localisation, IT governance, and payment system requirements interact with the DPDPA for banking and FinTech entities.

7 min read

RBI Data Localisation Directive

The RBI's 2018 circular requires all payment system data to be stored exclusively in India. This data localisation requirement is stricter than the DPDPA's permissive cross-border framework and operates independently. Payment system operators, banks, and FinTech companies must comply with both frameworks, applying the stricter RBI standard for payment data while following the DPDPA for other categories of personal data. See the financial services sector guide for detailed compliance considerations.

Master Direction on IT Governance

RBI's Master Direction on Information Technology Governance, Risk, Controls, Assurance and Audit prescribes specific standards for data security, access controls, encryption, and incident reporting for regulated entities. It is much more granular than DPDP Rule 6 - mandating CISO appointment, prescribed VAPT (Vulnerability Assessment and Penetration Testing) frequency, and specific Board-level oversight. These requirements overlap with the DPDPA's security safeguards under Rule 6. Compliance with DPDPA Rule 6 alone is insufficient for RBI-regulated entities - banks and NBFCs must layer the RBI Master Direction's controls on top of Rule 6 to satisfy both frameworks.

KYC Data Processing

Financial institutions process extensive KYC (Know Your Customer) data under RBI regulations, PMLA (Prevention of Money Laundering Act), and SEBI requirements. This processing may rely on the DPDPA's legitimate use provisions (Section 7) for compliance with legal obligations. However, any use of KYC data beyond regulatory compliance - such as marketing or analytics - would require consent under the DPDPA's framework.

Dual Compliance Framework

Financial entities must maintain dual compliance by: (a) ensuring payment data localisation per RBI requirements - noting that RBI permits storage abroad for the 'foreign leg' of an international transaction, so the localisation requirement is not a total ban; (b) implementing security safeguards meeting both RBI and DPDPA standards; (c) establishing breach notification processes covering both RBI incident reporting and DPDPA's R.7; (d) where data is processed abroad, maintaining 'near real-time' mirroring of the data back to India per RBI's specific requirement; (e) producing an annual System Audit Report (SAR) by a CERT-In empanelled auditor specifically for data localisation compliance; (f) separating consent-based processing from regulatory-mandated processing; and (g) conducting DPIAs where required as SDFs.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.