NBFCs deal with a lot of personal data. Loan forms. KYC scans. Bank statements. Credit checks. Video KYC recordings. Call logs from collections teams. No other business touches this much personal data per customer. This is exactly why NBFC compliance teams need to pay close attention to this new law.
The new data law is called the DPDP Act. The rules under this act came out on 13 November 2025. The clock is already running, and it’s now a core part of NBFC compliance work for every firm in this sector.
This is not a “later” problem. It’s a live project with real dates and real fines. Let’s look at what your NBFC compliance team needs to know and do.
Why NBFCs Need to Pay Extra Attention
Under this law, your NBFC is called a Data Fiduciary. This simply means you collect and use people’s personal data. But most NBFCs will likely be marked as something bigger: a Significant Data Fiduciary (SDF). This happens because you handle large amounts of sensitive money data. Digital lending, video KYC, and co-lending all push you into this category, making NBFC compliance even more demanding.
Being an SDF means extra work for your NBFC compliance team:
- You need a Data Protection Officer (DPO). This person reports directly to the Board.
- You need an outside audit every year.
- You need a proper review before launching any new loan product or tool.
- If you use AI to help decide who gets a loan, you need clear records for that too.
So if your NBFC uses a credit scoring tool, that tool now falls under this law. If you use customer data to sell more products, you need real proof of consent. This is now a basic part of NBFC compliance, not a side task for your legal team.
This law does not replace RBI’s rules. It sits on top. Every NBFC that handles customer data digitally must follow both RBI rules and this new law and that overlap is where most NBFC compliance gaps show up.
The Three Key Dates
This law is rolling out in three steps. Each step adds new duties, and each one changes what NBFC compliance actually requires.
Step 1 — 13 November 2025 (already started) The basic definitions of the law are now active. The Data Protection Board of India is now formed. Your NBFC compliance duties technically began here. But fines have not started yet.
Step 2 — 13/14 November 2026 (soft period ends) This is the date to prepare for right now. After this date, the Board can check complaints and give fines. This is also when a new tool called “Consent Manager” opens for sign-up. Right now, the Board mostly gives warnings and guidance. After this date, real checks and real action begin and that means real risk for weak NBFC compliance.
One big focus area during this time will be old data. You need to show that data you collected before this law existed still has valid consent behind it. If you can’t show consent for old loan files or old KYC records, your NBFC compliance stands on shaky ground.
Step 3 — 13 May 2027 (full rules apply) From this date, every part of the law applies. This covers consent, data storage limits, data transfers, and breach rules. Many experts call this the real, final deadline for NBFC compliance. Start your work now. Focus on mapping your data, building consent tools, and fixing vendor contracts.
Don’t wait until May 2027 to start. By then, the hard work should already be done. November 2026 is when real NBFC compliance checks begin.
The Fines: Show These Numbers to Your Board
Here are the exact numbers. These get attention fast, and they explain why NBFC compliance budgets need to grow this year.
What Goes WrongMaximum FineWeak security that leads to a data breachUp to ₹250 croreNot reporting a breach to the Board and customersUp to ₹200 croreNot meeting extra SDF dutiesSeparate fineNot respecting people’s data rightsCase by case
Two things matter a lot here.
Fines can add up. One breach can trigger two fines at once. One for weak security. One for not reporting it properly. These count as two separate mistakes, not one. So one bad vendor deal or one unlocked database could cost your NBFC compliance budget twice over.
There’s no “small breach” exception. You must tell the Board and every affected customer about a breach. No matter how small. A leak affecting 10 people needs the same report as one affecting 10 million people. This is stricter than most other countries. So even a small mistake like losing a file with 40 customer PAN numbers is a full legal event under NBFC compliance, not a minor slip.
The 72-Hour Rule: What It Really Means
This part confuses a lot of people. It sounds easy. It isn’t, and it’s one of the trickiest parts of NBFC compliance to get right.
When a breach happens, you must send two notices. First, tell every affected customer, right away, in simple language. Tell them what happened, what it means for them, and what they should do next. Second, tell the Data Protection Board in two steps. First, a quick alert as soon as you know. Then, a full report within 72 hours.
Here’s the part most people get wrong: the 72-hour clock does not start when the breach happens. It starts when you find out about it. If it takes your team five days to notice a breach, you don’t get 72 hours to report it. You’re already five days behind. This means strong NBFC compliance depends on fast detection, not just a good notice template.
There’s also a faster rule to watch. A separate rule called CERT-In needs a report within just 6 hours for some cyber incidents. That’s much faster than the 72-hour rule. So your NBFC compliance plan needs to work for both timelines, not just one.
One last tip: don’t try to hide a breach or manage the story quietly. Hiding it is treated worse than the breach itself under NBFC compliance rules. Keep your message the same everywhere. Don’t delete any records. Show real fixes instead of empty promises.
Where This Law Meets RBI Rules
RBI already has strict rules. This new law adds to them, not replaces them. Video KYC is a good example of where NBFC compliance now means meeting two sets of rules at once.
Under RBI rules, a video KYC call must feel real and live, like a face-to-face meeting. The customer must be in India during the call. All recordings and data from that call must be stored inside India. No outside server can hold this data, anywhere.
This new law adds one more layer: clear consent for using that data. If you use an outside company for video KYC, you need a setup to pull that data onto your own India-based servers right after each call.
The smart move for NBFC compliance is to not build a whole new team for this. Add this work into your current RBI compliance team. Build one shared plan for breaches. One shared audit. One shared Board report.
What Being an SDF Will Cost
Most banks and NBFCs will likely be marked as Significant Data Fiduciaries. Plan for two new costs now as part of your NBFC compliance budget: outside data auditors, and reviews before launching new products. In simple terms, you’ll need:
- A DPO who reports straight to the Board.
- Regular outside data checks, separate from your usual RBI audits.
- A review before you launch any new loan product or data-sharing deal.
- Written records for any AI tool used in loan decisions.
The Consent Manager Deadline
At the same time, India is building a new tool called Consent Manager. This lets customers control and cancel their data permission across many apps and platforms at once. This is now part of the wider NBFC compliance landscape too.
Between June and August 2026, the government plans to switch this system on. Your systems will need to work with this new tool.
If your NBFC already works with Account Aggregators, this won’t feel completely new. But decide now how deep you want to go, since this is fast becoming a standard piece of NBFC compliance.
A Simple 6-Point Checklist
- Map your data first. You can’t report a breach or prove consent without this. This is the foundation of any NBFC compliance programme.
- Fix old consent records before November 2026. This is likely the first thing checked.
- Turn vendor deals into proper contracts. Sign clear data agreements with credit bureaus, lending partners, and collection agencies. Start now.
- Test how fast you catch a breach not just how you respond to one.
- Name your DPO now. This role is now central to NBFC compliance.
- Plan a real budget and timeline. Most firms need 10 to 16 weeks to go from a first check to being fully ready.
This law is not just a job for your legal team. It touches your KYC process, your vendor deals, your tech systems, and your Board reports, all at once and all of it now falls under one bigger umbrella: NBFC compliance.
November 2026 matters most right now. That’s when real checks begin. May 2027 is the final deadline. But strong NBFC compliance needs to be built before that, not after.
NBFCs that start today mapping their data, fixing vendor deals, and testing their breach response will spend 2027 proving their NBFC compliance was ready all along.
Need help getting your NBFC DPDP-ready? Connect with NBFC Advisory we help NBFCs map their data, fix vendor contracts, and build breach-ready systems before the deadlines hit.