27 Aug 2026


This is a link enhanced version of the article that first appeared in Business Standard.
Article Overview:
The article examines how the RBI’s draft data governance guidance and the DPDP Act are prompting banks and NBFCs to reassess their partnerships with fintech companies. With increased board-level oversight, third-party data risk controls and penalties of up to Rs.250 crore, financial institutions are reviewing contracts and working with legal, consulting and regtech firms to strengthen compliance and data governance. It also highlights the need for stronger internal controls, clearer contractual allocation between data fiduciaries and data processors, and appropriate risk-based obligations for fintech partners.
Our Partner, Jishnu Sanyal, shared his perspective. Here’s what he had to say:
“The penalty architecture reinforces the need for stronger internal controls and clearer contractual allocation between data fiduciaries and data processors, although the data fiduciary remains primarily responsible for compliance under the DPDP Act.”
“The RBI’s outsourcing norms require REs to flow down appropriate risk-based obligations to fintech partners, calibrated to the functions outsourced and the risks involved.”
Under the rules of the Bar Council of India, Trilegal is prohibited from soliciting work or advertising in any form or manner. By accessing this website, www.trilegal.com, you acknowledge that:
We prioritize your privacy. Before proceeding, we encourage you to read our privacy policy, which outlines the below, and terms of use to understand how we handle your data:
For more information, please read our terms of use and our privacy policy.