The NBFC Privacy Policy Study: 49 Lenders Scored Against the DPDP Act
ConsentOS reviewed the public privacy policies of 49 RBI-regulated lenders in August 2026. 8 state a retention schedule per data category. 12 acknowledge the RBI/DPDP dual mandate. 19 name a grievance officer. 4 do all three. The full methodology and counts are published here.
On This Page
What We Did
In August 2026, ConsentOS retrieved and archived the public privacy policy of 50 RBI-regulated lenders: all 17 NBFCs in the RBI’s Upper Layer list, the 18 largest Middle Layer NBFCs by assets under management, and 15 fintech lenders that hold their own NBFC licence. 49 policies were retrievable. One policy page delivered no text to the browser on the retrieval date and is reported as unreachable rather than scored.
Each policy was scored against three counting rules. The rules were fixed before collection began, and every yes was recorded with a verbatim quote from the archived document.
- Retention schedule per data category. A yes requires at least two named data categories, each with its own retention period or trigger. A single global statement, such as retaining data as long as required by law, scores no.
- The dual mandate acknowledged. A yes requires the policy to name a sectoral retention requirement (RBI directions, PMLA, or KYC norms) and to reference an erasure right or erasure limitation in the same document. Naming one side scores no.
- A named grievance officer. A yes requires an individual’s name with a contact route. A designation with a mailbox and no name scores no.
The Numbers
| Test | All lenders (49) | NBFCs (34) | Fintech lenders (15) |
|---|---|---|---|
| Retention schedule per data category | 8 | 6 | 2 |
| RBI/DPDP dual mandate acknowledged | 12 | 4 | 8 |
| Grievance officer named | 19 | 8 | 11 |
| DPDP Act named anywhere in the policy | 10 | 4 | 6 |
| All three tests passed | 4 | 2 | 2 |
Four institutions passed all three tests: Shriram Finance, Manappuram Finance, KreditBee, and Fibe.
What the Numbers Say
41 of 49 lenders publish no per-category retention schedule. These are institutions that hold KYC records under a five-year PMLA mandate, loan files under RBI directions, and marketing data under consent. Their public position on how long each category is kept is, in 41 cases, a single sentence or nothing. Section 8(7) of the DPDP Act sets erasure as the default once purpose is served, an obligation that becomes enforceable on 13 May 2027; a policy that cannot say which records outlast that default has no public answer to the first question a data principal, or a regulator, will ask.
The conflict is acknowledged by a quarter of the sample. 12 policies name a sectoral retention mandate and an erasure right in the same document. The other 37 present one side only: either the erasure right without the statutory carve-out, or the retention obligation without the DPDP right. The sectoral half is binding law today; the DPDP half becomes enforceable on 13 May 2027. The RBI-DPDP retention conflict binds the same records in opposite directions, and a policy that shows one half is describing a compliance position that does not exist.
The fintech lenders are ahead of the giants. 8 of 15 fintech policies acknowledge the dual mandate against 4 of 34 NBFC policies, and the fintech cohort also leads on named grievance officers. The pattern has a plain explanation: the RBI’s digital lending framework forced app-based lenders to rewrite their policies recently, and the rewrites absorbed DPDP language. The larger balance sheets are running older documents.
A named grievance officer is still the exception. 30 of 49 policies route grievances to a designation or a mailbox with no human name. Under the DPDP Rules, once they take effect on 13 May 2027, the grievance mechanism is the mandatory first stop before a data principal can escalate to the Data Protection Board; the DPBI complaint process begins where the policy’s grievance section ends.
One more count worth recording: 10 of 49 policies name the Digital Personal Data Protection Act at all, nine months before enforcement begins on 13 May 2027.
What This Means for a Regulated Lender
The gap this study measures is not a drafting gap. A privacy policy that cannot state per-category retention usually cannot state it because the underlying classification does not exist: nobody has mapped which records sit under the PMLA five-year mandate, which sit under RBI directions, and which sit on consent alone. The policy is downstream of the data inventory, and the inventory is where the 41 failures start.
The resolution is the same framework regardless of institution size: classify every data category by its retention basis, honour erasure where no mandate applies, refuse in writing with the specific legal basis where one does, and keep the denial register that proves it. That is the Legal Obligation Override, set out in full in the RBI-DPDP retention conflict guide.
Where your own policy stands against these three tests is a ten-minute check. The free DPDP Gap Assessment scores your organisation against the DPDP Act’s obligation areas and returns the gaps in a written report. For NBFCs and fintech lenders that need the classification, the override, and the denial register as running infrastructure, that is the Compliance Vault.
Methodology Notes
- Sample frame: all 17 RBI Upper Layer NBFCs (FY2026-27 list), the 18 largest Middle Layer NBFCs by AUM per public rankings, and 15 fintech lenders verified as holding their own NBFC licence. Two well-known digital lending brands were excluded because their own sites identify them as lending service providers operating on partner licences.
- Unit of observation: the public privacy policy linked from each entity’s primary website, retrieved on 21 August 2026. One document per entity, archived before scoring.
- Counting rules were fixed before collection and scored verbatim; ambiguity scored no.
- Findings, not failures: one entity’s policy page rendered without any policy text on the retrieval date and is reported as unreachable. Another entity’s footer link resolved to a policy hub; the group policy it listed first was scored.
- Positive naming only. Aggregate numbers are reported for the sample; only the four institutions that passed all three tests are named.
- The full entity list, per-rule counts, and archived documents are available on request: hello@consentos.in.
Frequently asked questions
How many NBFC privacy policies state a retention schedule per data category?
8 of the 49 policies reviewed in the ConsentOS study (August 2026) attach a distinct retention period or trigger to at least two named data categories. The other 41 either state a single global retention line, such as retaining data as long as required by law, or state no retention terms at all.
How many Indian lenders acknowledge the RBI/DPDP retention conflict in their privacy policy?
12 of 49. The study scored a policy as acknowledging the dual mandate only if it named a sectoral retention requirement (RBI, PMLA, or KYC directions) and referenced an erasure right or erasure limitation in the same document. Fintech lenders outperformed the large NBFCs: 8 of 15 fintech policies met the test against 4 of 34 NBFC policies.
How many privacy policies name a grievance officer?
19 of 49 policies name a specific individual with a contact route. The remaining 30 list a designation or a mailbox without a personal name, which does not satisfy the disclosure standard the study scored against.
What was the methodology of the ConsentOS NBFC privacy policy study?
50 entities were sampled: all 17 RBI Upper Layer NBFCs, the 18 largest Middle Layer NBFCs by assets under management, and 15 RBI-regulated fintech lenders selected by scale. Each entity's public privacy policy was retrieved and archived on 21 August 2026 and scored against three counting rules fixed before collection. One policy page delivered no text and is reported as unreachable. The archive is available on request.
Know where you stand on DPDP compliance
Run the free DPDP Gap Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.
Enforcement milestones, rule notifications, and deadline analysis.
One email when it matters, no more.
Resources
Continue Reading
Related DPDP Act 2023 guidance from the ConsentOS knowledge base.
RBI-DPDP Retention Conflict: KYC Erasure Rules for Indian Fintechs
The RBI and PMLA mandate five-year KYC retention. The DPDP Act requires erasure on request. For Indian fintechs and NBFCs, these obligations are in direct conflict. This article explains the Legal Obligation Override framework that supports resolution of both simultaneously.
11 min read
Industry GuidesNBFC DPDP Compliance: RBI KYC Retention and PMLA Overrides in India
How NBFCs reconcile DPDP Act 2023 with RBI KYC retention, PMLA record-keeping, CIBIL consent and FIU-IND reporting. Legal Obligation Override explained.
11 min read
Industry GuidesFintech DPDP Compliance: RBI Data Localisation and Payment Rules
How a fintech complies with the DPDP Act 2023: data inventory across payment flows, purpose-specific consent, security safeguards, and breach readiness, alongside RBI data localisation mandates.
10 min read
Industry GuidesKYC Record Retention Period in India: RBI, PMLA, and DPDP Rules
KYC records are retained five years after the relationship ends under the RBI KYC Direction and PMLA Rules. The retention matrix and where DPDP erasure fits.
10 min read