News Analysis • 4 mins
Finch Innovate Launches FinchSCAN: Assessing DPDP Act 2023 Compliance in SaaS Onboarding Tools
Finch Innovate has launched FinchSCAN, a SaaS platform for digital onboarding and AML screening. This analysis examines the legal implications for General Counsels evaluating third-party Data Processors under the DPDP Act 2023 and Rules 2025.
Last updated:
What happened
According to Elets BFSI, Finch Innovate has announced the global launch of FinchSCAN, a SaaS platform designed for digital onboarding and Anti-Money Laundering screening. The platform explicitly supports global data protection requirements, including India's Digital Personal Data Protection Act, 2023. FinchSCAN also integrates capabilities for the European Union General Data Protection Regulation and Gulf Personal Data Protection Law requirements. This release highlights a shift where enterprise vendors are directly embedding jurisdictional privacy capabilities into their identity verification workflows.
Does the DPDP Act apply here?
Under Section 3 of the DPDP Act, the law applies to the processing of digital personal data within the territory of India, and processing outside India if connected to offering goods or services to Data Principals in India. Digital onboarding and Anti-Money Laundering screening inherently require collecting and processing substantial volumes of personal data. When a Data Fiduciary uses a SaaS vendor like FinchSCAN, the Act applies directly to the Fiduciary, who remains fully accountable for the vendor's actions. General Counsels must recognise that engaging a third-party platform for onboarding triggers direct legal obligations regarding lawful processing and vendor oversight.
Legal implications under DPDP
Under Section 4, a person may process personal data only in accordance with the Act for a lawful purpose, where consent is the primary basis for processing, except where Section 7 legitimate uses apply. For General Counsels in the D2C and e-commerce sectors, onboarding tools cannot legally bundle consent for identity verification with marketing communications. Furthermore, the DPDP Rules, 2025 mandate itemised notices available in 22 regional languages under Rule 3. Cross-border transfers to offshore SaaS servers are generally permitted unless the Central Government restricts transfer to notified countries. Data Fiduciaries must ensure their Data Processor contracts include clear liability allocation and indemnities to secure defensibility during regulatory scrutiny. If the vendor experiences a security incident, the Rules, 2025 require the Fiduciary to intimate affected Data Principals without delay and submit a detailed report to the Data Protection Board within 72 hours.
Could this happen to you
When evaluating platforms that advertise built-in compliance, General Counsels must look beyond marketing claims to actual legal defensibility. If your e-commerce platform integrates an onboarding tool that fails to unbundle consent or lacks multi-language notice translation, your organisation bears the regulatory liability. The Data Protection Board of India will not penalise the processor directly for consent failures; they will penalise the Fiduciary up to 250 crore rupees for breaching processing obligations. During an audit, the regulator will demand clear evidence trails of executed processor contracts, limitation of liability frameworks, and records showing how you validated the vendor's compliance posture. Relying on a heavy legacy tool without clear consent unbundling for shipping versus marketing data exposes D2C brands to significant litigation risk.
What companies should do in the next 30 days
1. Legal teams must audit all existing SaaS agreements for identity verification to ensure they contain explicit DPDP Data Processor clauses and specific indemnities.
2. General Counsels should map the data flows of current onboarding tools to confirm no cross-border transfers occur to countries on the Central Government negative list.
3. Chief Marketing Officers and CTOs must implement a consent unbundler mechanism that cleanly separates shipping data from marketing data during the checkout and onboarding process.
4. Compliance teams must verify that any newly procured SaaS platform provides itemised notices in the 22 languages specified by the Rules, 2025.
What to watch
Legal leaders must track how the Data Protection Board sets precedents regarding Data Fiduciary liability for third-party SaaS failures. Enterprises should monitor outside counsel spend related to negotiating compliant processor contracts as the enforcement phase begins. Exactly 269 days remain until the 13 May 2027 hard deadline for DPDP Act compliance. Organisations unsure of their processor contracting gaps or consent unbundling readiness can assess their defensibility using the free scan tool at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to third-party AML and onboarding software?
Yes. Under Section 3, the Act applies to the processing of digital personal data. When a Data Fiduciary uses third-party onboarding software, the Fiduciary remains fully liable for ensuring the processing complies with the DPDP Act and Rules, 2025.
Can we rely on SaaS vendors that claim built-in DPDP compliance?
While vendor capabilities help streamline operations, legal defensibility rests entirely with the Data Fiduciary. General Counsels must execute detailed processor contracts with clear liability allocation and indemnities to manage litigation risk.
What are the consent rules for e-commerce onboarding?
Under Section 4, consent is the primary basis for processing, except where Section 7 legitimate uses apply. E-commerce platforms must unbundle consent, explicitly separating data required for onboarding and shipping from data used for marketing.
How do the DPDP Rules 2025 impact privacy notices during onboarding?
The Rules mandate that Fiduciaries provide itemised privacy notices. Crucially for D2C brands, these notices must be made available in 22 regional languages under Rule 3 to ensure valid consent from Data Principals across India.
What happens if a SaaS processor suffers a data breach?
The Data Fiduciary must notify the affected Data Principals without delay. Additionally, the Rules, 2025 require the Fiduciary to submit a detailed incident report to the Data Protection Board within 72 hours.
ComplyDP