NEWS ANALYSIS4 min read

The Consent Paradox Under DPDPA 2023: Evaluating Financial Exposure for BFSI Enterprises

An analysis of the DPDP Act 2023 consent mechanics against the 2017 Puttaswamy privacy judgment, detailing how BFSI CFOs must manage contingent liabilities and audit-ready consent trails under the new Rules 2025.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

The Daily Pioneer published an analysis evaluating the role of consent in the Digital Personal Data Protection Act, 2023. The report anchors its discussion in the 2017 Supreme Court judgment of KS Puttaswamy v. Union of India, which established that privacy is an inherent constitutional right rather than a privilege granted by the State. The publication explores the paradox of consent in the digital world, questioning whether reliance on user consent genuinely serves as the cornerstone of modern Indian privacy law when digital ecosystems are highly complex.

Does The DPDP Act Apply Here

Under Section 3, the DPDP Act applies to the processing of digital personal data within India, and to processing outside India connected to offering goods or services to Data Principals in India. For a Chief Financial Officer in the BFSI sector, this encompasses virtually all digitized customer KYC, credit profiles, and transaction histories. The Act exempts personal data processed by an individual for personal or domestic purposes, but this exemption provides no cover for enterprise financial processing or corporate operations.

Legal Implications Under DPDP

The interplay between constitutional privacy rights and statutory obligations rests heavily on Section 4 of the Act. Consent is the primary basis for processing, except where Section 7 legitimate uses apply. To operationalize this, the DPDP Rules, 2025 mandate strict mechanics for itemised notices and verifiable parental consent. Furthermore, while companies may route data globally, cross-border transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories via a negative list. Failure to maintain these operational trails exposes the enterprise to severe contingent liabilities, with penalty ceilings reaching up to Rs 250 crore.

Could This Happen To You

The paradox of consent presents a direct operational risk for banks, NBFCs, and insurers. These entities are highly likely to face Significant Data Fiduciary, or SDF, obligations based on risk and volume, requiring rigorous evidence of compliance. If a privacy incident occurs, the DPBI and sector regulators like the RBI or IRDAI will immediately demand proof of valid consent. Under the Rules 2025, a breach requires intimation to affected Data Principals without delay, plus a detailed report to the Data Protection Board within 72 hours. Without a consolidated vendor tech stack that provides an audit-ready trail, the ensuing audit fees, cyber insurance premium hikes, and EBITDA impacts will force uncomfortable board-level conversations.

What Companies Should Do In The Next 30 Days

1. Chief Financial Officer: Quantify the total cost of ownership of current fragmented compliance tools versus vendor consolidation for consent and breach workflows, factoring in potential Rs 250 crore penalty exposures.

2. Chief Compliance Officer: Map legacy KYC data collection points to ensure initial notices align with the itemised notice requirements mandated by the DPDP Rules 2025.

3. General Counsel: Review processor contracts and cyber insurance policies to verify coverage aligns with the strict 72-hour breach reporting windows.

What To Watch

With exactly 283 days remaining until the 13 May 2027 hard compliance deadline, enterprises must transition from theoretical risk assessments to operational readiness. Expect intense scrutiny from the DPBI on how financial institutions capture, store, and revoke consent across legacy systems. A failure to build robust, automated compliance workflows will quickly translate into measurable financial loss. Enterprise leaders can evaluate their current regulatory exposure and readiness securely at freescan.complydp.com.

Sources

Frequently asked questions

Does the DPDP Act apply to legacy financial data and KYC records?

Yes. The DPDP Act applies to the processing of digital personal data within India, regardless of when it was collected, provided it is in digital form or digitized subsequently. Financial institutions must ensure legacy data meets current consent and notice standards under the DPDP Rules 2025.

What is the maximum penalty for failing to obtain valid consent under the DPDP Act?

Failing to fulfill the obligations of a Data Fiduciary, including proper consent management, can attract penalties of up to Rs 250 crore per breach. Enterprise financial leaders must provision for this contingent liability if compliance workflows are not verifiable and audit-ready.

Are there exceptions to obtaining consent for processing personal data?

Yes. While consent is the primary basis for processing, except where Section 7 legitimate uses apply, companies do not need explicit consent for specific scenarios outlined in the Act. These legitimate uses include compliance with court judgments, medical emergencies, and fulfilling state services.

What are the breach notification requirements for financial institutions under the DPDP Rules 2025?

In the event of a personal data breach, enterprises must send an intimation to affected Data Principals without delay. Additionally, they are required to submit a detailed report to the Data Protection Board within 72 hours.

When is the final deadline for DPDP Act compliance?

The hard compliance deadline is set for 13 May 2027. Companies have exactly 283 days remaining to operationalize their consent mechanisms, itemised notices, and processor oversight workflows.