News Analysis • 4 min read
Finch Innovate's Global SaaS Launch: Managing Vendor Risk Under DPDP 2023
Finch Innovate has launched a global SaaS platform for AML and identity verification. Learn how General Counsels at fintechs must secure Data Processor Agreements, update itemised notices, and manage cross-border transfer risks under the DPDP Act 2023 and Rules 2025.
Last updated:
What Happened
According to a report by Elets BFSI, Finch Innovate has announced the global launch of FinchSCAN. This Software-as-a-Service platform is designed specifically for digital onboarding, identity verification, and Anti-Money Laundering screening. By automating background checks and financial profiling, the tool targets rapid customer acquisition cycles commonly found in fintech and banking environments.
Does The DPDP Act Apply Here
Identity verification and AML screening inherently involve the collection and processing of digital personal data. Section 3 of the Digital Personal Data Protection Act, 2023 clearly dictates that the Act applies to processing digital personal data within India. Furthermore, its extraterritorial scope covers processing outside India if it connects to offering services to Data Principals within the territory of India.
The Act does not apply to corporate IP or fully anonymised datasets, but any onboarding process capturing personal identifiers falls strictly under its purview. For a General Counsel evaluating a third-party SaaS tool, this means customer KYC data sent to the platform is fully regulated, requiring immediate legal attention to safeguard the enterprise and establish clear liability allocation.
Legal Implications Under DPDP
Under Section 4 of the Act, consent is the primary basis for processing, except where Section 7 legitimate uses apply. General Counsels must ensure that when deploying platforms like FinchSCAN, the fintech provides an itemised notice as mandated by the DPDP Rules, 2025. This notice must explicitly inform Data Principals about the collection of their government identifiers and financial profiles for onboarding purposes, creating a clear audit trail.
Because the platform operates globally, cross-border data transfer rules apply. Transfers are generally permitted unless the Central Government restricts transfer to notified countries or territories. Fintechs acting as Data Fiduciaries must execute strict Data Processor Agreements outlining liability allocation, indemnity, and limitation of liability before sharing customer data. You must verify where the SaaS provider hosts its infrastructure and enforce strict data retention cycles to ensure data is deleted once the AML screening is complete.
Could This Happen To You
Fintech product teams often integrate SaaS onboarding APIs in rapid sprint cycles, sometimes outpacing comprehensive legal review. If a third-party processor like a cloud-based KYC tool suffers a breach, the fintech remains directly accountable to the Data Protection Board of India. There is no safe harbour under the DPDP Act for blaming the vendor. Under the DPDP Rules, 2025, fiduciaries must intimate affected Data Principals without delay and submit a detailed report to the DPBI within 72 hours.
When an incident occurs, the DPBI will demand verifiable evidence of consent logs, risk assessments, and contractual safeguards. A failure to present a defensible position can expose the business to a penalty ceiling of Rs 250 crore. Managing this risk requires balancing product velocity with regulator defensibility, ensuring indemnities cover vendor-induced breaches without exhausting outside counsel spend or slowing down account-aggregator APIs.
What Companies Should Do In The Next 30 Days
1. General Counsels must mandate a privileged review of all existing processor agreements, verifying that indemnity clauses adequately shield the fiduciary from third-party failures.
2. Compliance heads should update consumer-facing consent flows to include itemised notices for KYC and AML processing, satisfying the notified rules.
3. Legal and engineering teams must jointly map the geographic hosting of all vendor cloud infrastructure to ensure compliance with the negative list for cross-border transfers.
4. Establish a tested protocol for vendor breach escalation that guarantees the fiduciary can meet the 72-hour DPBI notification window.
What To Watch
Legal teams should monitor regulator engagement regarding overlapping obligations between RBI digital lending guidelines and DPDP requirements. The interpretation of data processor liability during DPBI adjudications will heavily influence future software procurement and contract negotiations. Exactly 268 days remain until the DPDP hard compliance deadline of 13 May 2027.
To assess your organisation's exposure and check how your vendor contracts measure up against the Act, complete a self-assessment at freescan.complydp.com.
Sources
Frequently asked questions
Does the DPDP Act apply to third-party SaaS tools used for AML screening?
Yes. Any SaaS platform processing digital personal data for identity verification falls under the Act. Under Section 3, the Act applies to processing digital personal data within India or outside India if connected to offering services to Data Principals in India.
What is the maximum penalty for a data breach under the DPDP Act?
A failure to implement reasonable security safeguards can result in financial penalties reaching up to Rs 250 crore. Fintechs acting as Data Fiduciaries hold strict liability even if the breach occurs at the third-party processor level.
How do cross-border data transfer rules affect global SaaS platforms?
Transfers of digital personal data are generally permitted unless the Central Government restricts transfer to a notified negative list of countries. General Counsels must verify the geographic hosting of all vendor cloud infrastructure to maintain compliance.
What are the breach notification requirements under the DPDP Rules 2025?
The DPDP Rules, 2025 mandate that Data Fiduciaries intimate affected Data Principals without delay. Additionally, they must submit a detailed breach report to the Data Protection Board of India within 72 hours of becoming aware of the incident.
When is the final deadline to comply with the DPDP Act 2023?
The hard compliance deadline is set for 13 May 2027. Businesses must establish comprehensive consent architectures, update processor agreements, and deploy itemised notices well before this date to avoid regulatory action.
ComplyDP