News Analysis4 min read

DPDP Act 2023 Analysis: Balancing Consent and Legitimate Uses in BFSI Processing

An analysis of the tension between individual consent and legitimate uses under the DPDP Act 2023, exploring how Chief Compliance Officers in the BFSI sector must build regulator-ready audit trails to defend their processing activities.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

What Happened

The Daily Pioneer recently published an analytical piece by Rajlaxmi Singh examining the balance between consent and exceptions under the Digital Personal Data Protection Act, 2023. The article argues that while the 2017 Supreme Court judgment in KS Puttaswamy v. Union of India established privacy as an intrinsic dimension of human dignity, exceptions within the DPDPA risk making consent largely ceremonial. Singh highlights an unresolved tension between individual autonomy and administrative practicality. The author also acknowledges the baseline requirements the Act establishes for transparency and purpose limitation, framing the legislation as a milestone requiring ongoing refinement.

Does The DPDP Act Apply Here

This debate strikes at the core of applicability for every Data Fiduciary in the financial sector. Under Section 3, the Act applies to the processing of digital personal data within India, and processing outside India connected to offering goods or services to Data Principals in India. It does not apply to non-digital data unless subsequently digitised. For banks, NBFCs, and insurers managing legacy KYC systems, this means almost all customer profiling, policy underwriting, and transaction data falls squarely under the Act and the accompanying DPDP Rules, 2025.

Legal Implications Under DPDP

Section 4 of the DPDPA establishes that consent is the primary basis for processing, except where Section 7 legitimate uses apply. Singh critiques how broad legitimate uses might bypass individual autonomy. However, the DPDP Rules, 2025 dictate exact operational boundaries even when relying on these exemptions. Financial institutions cannot simply declare administrative practicality to bypass data principal rights. If relying on consent, the Rules require itemised notices and verifiable mechanisms. If leaning on legitimate uses for fraud prevention or regulatory compliance with RBI mandates, fiduciaries still bear the burden of purpose limitation, data minimisation, and maintaining a clear Record of Processing Activities.

Could This Happen To You

A Chief Compliance Officer reading this critique should immediately recognize the regulatory exposure in their own data pipelines. If the Data Protection Board of India queries your legal basis for processing loan application data, pointing vaguely to legitimate uses without a mapped RoPA will trigger scrutiny and potential penalties up to 250 crore rupees. The Board will demand your consent artefacts or your documented justification under Section 7. Furthermore, if a breach occurs within those pipelines, the DPDP Rules, 2025 require intimation to affected Data Principals without delay and a detailed report to the Board within 72 hours. A credible compliance platform must automatically link every data field to its legal basis, providing an audit trail that proves consent or a lawful exemption.

What Companies Should Do In The Next 30 Days

1. Map all existing data processing activities to establish whether they rely on consent or a specific legitimate use, ensuring this RoPA is owned by the Chief Compliance Officer.

2. Evaluate your current consent mechanisms against the itemised notice requirements detailed in the DPDP Rules, 2025, producing a gap analysis report signed by legal counsel.

3. Establish a regulator-ready audit trail system that records the exact time and context of data collection to serve as your primary evidence pack during an audit.

4. Review breach response workflows to ensure your organization can notify the Board within the mandatory 72 hours, testing this via a simulated incident run by the risk management team.

What To Watch

The tension between individual privacy and administrative practicality will inevitably be tested through enforcement actions and judicial interpretation over the coming years. 283 days remain until the DPDP hard compliance deadline of 13 May 2027. Before then, the regulatory body is expected to release further operational guidelines clarifying how legitimate uses overlap with existing financial regulations. Assess your organization's readiness and map your gaps with a free scan at freescan.complydp.com to ensure you have the evidence required for regulator defense.

Sources

Frequently asked questions

Is consent required for all data processing under the DPDP Act 2023?

No. Under Section 4 of the DPDPA, consent is the primary basis for processing, except where Section 7 legitimate uses apply. Legitimate uses include situations like state functions, medical emergencies, or employment purposes.

How does the DPDP Act impact legacy financial data and KYC records?

The Act applies to digital personal data processed within India, including non-digital data that is subsequently digitised. Banks and insurers must map legacy KYC records in their RoPA and identify whether processing relies on valid consent or a specific legitimate use.

What happens if a financial institution misclassifies its legal basis for processing?

Misclassifying the basis of processing invalidates the data collection and violates the Act's purpose limitation requirements. The Data Protection Board can demand audit trails and impose penalties up to 250 crore rupees for non-compliance with fiduciary obligations.

What are the data breach reporting timelines under the DPDP Rules 2025?

The DPDP Rules, 2025 require organizations to provide intimation to affected Data Principals without delay. Additionally, a detailed breach report must be submitted to the Data Protection Board within 72 hours of discovering the incident.

How can a Chief Compliance Officer prepare for DPBI audits?

Compliance leaders must establish a Record of Processing Activities that maps every data flow to its legal basis. They should implement platforms that automate consent tracking and generate regulator-ready evidence packs to demonstrate adherence to itemised notice and purpose limitation rules.