RBI's Draft Data Governance Guidance: What Banks and NBFCs Must Build
RBI's draft data governance guidance mandates a board-level committee, data tagging, and quarterly reporting for banks and NBFCs. Comments due August 17, 2026.
On This Page
- What the Draft Guidance Is
- Who Must Comply
- The Core Mandate: A Board-Level Data Governance Committee
- Data Tagging: Metadata and Lineage Requirements
- Quarterly Reporting and Annual Review
- Where the Draft Meets the DPDP Act 2023
- Draft Status: What “Not in Force” Means
- What Banks and NBFCs Should Do Now
On July 15, 2026, the Reserve Bank of India released the draft Guidance on Regulatory Expectations for Data Governance. Comments are due by August 17, 2026. The document is short on ceremony and long on structure: it tells every regulated entity to put data governance in front of its board, tag its data with metadata, trace its lineage, and measure its quality on a reporting cadence.
For banks and NBFCs the significant line is not any single control. It is that the draft writes the DPDP Act 2023 directly into RBI’s supervisory expectations. Data protection compliance and prudential supervision have been separate conversations. This draft merges them.
What the Draft Guidance Is
The draft sets out regulatory expectations across six areas: data governance structure, roles and responsibilities, data architecture, metadata and lineage, data quality, and third-party arrangements involving data sharing.
It is guidance, not directions. The consultation closes on August 17, 2026, and the final instrument will follow. Treat the draft as the blueprint RBI has already committed to in outline, with the details open for comment.
The full draft text is published on the RBI website as Guidance on Regulatory Expectations for Data Governance.
Who Must Comply
The draft applies to eleven categories of regulated entities:
- Commercial banks
- Small finance banks
- Payments banks
- Local area banks
- Regional rural banks
- Urban co-operative banks
- Rural co-operative banks
- All India Financial Institutions
- Non-banking financial companies, across all layers
- Asset reconstruction companies
- Credit information companies
There is no size carve-out in the coverage list. A base-layer NBFC and a systemically important bank are addressed by the same document.
The Core Mandate: A Board-Level Data Governance Committee
The draft puts accountability at the top of the organisation.
“An RE should establish a Board level Data Governance Committee (DGC) or assign the responsibility to an existing Committee of the Board.” (Paragraph 9)
The committee owns data governance policy and oversees implementation. For most NBFCs this is a new obligation category: data governance stops being an IT function and becomes a board agenda item with a paper trail.
Data Tagging: Metadata and Lineage Requirements
The draft requires data to carry metadata from capture onward. The minimum attributes named include the source application, the purpose, the data owner, the classification, and retention and usage requirements. When data is transformed or derived, the metadata must be updated to record the relationship between source and derived data, the purpose of the transformation, and any change in classification or accessibility.
Lineage is defined as documented traceability of data from its origin through aggregation, transformation, and usage to its final destination. Third-party sharing is inside the perimeter:
”… data shared with third-parties remains traceable to the designated SSOT, and metadata and lineage capture the extent of such sharing.” (Paragraph 63)
The SSOT is the entity’s designated single source of truth for each data element. Read that against your current state. If your customer records live in spreadsheets and CRM exports, none of this metadata exists. Building it starts with a personal data inventory, because you cannot tag data you have not mapped.
Quarterly Reporting and Annual Review
The draft sets a measurement cadence.
“The data quality metrics report and persistent data quality issues should be placed before the DGC at quarterly or more frequent intervals.” (Paragraph 59)
The governance framework itself must be reviewed annually or more frequently. Quarterly metrics before a board committee means the committee needs something to review. Defined metrics. A pipeline that produces them on schedule. And a record of what was decided when they arrived.
Where the Draft Meets the DPDP Act 2023
This is the section that makes the draft more than an internal-controls document. Paragraph 6 requires a governance framework that “complies with the Digital Personal Data Protection (DPDP) Act, 2023, the DPDP Rules, 2025, and all other applicable laws and rules”. Paragraph 18 repeats the requirement at the data level:
“An RE should ensure that customer-related data is handled in compliance with DPDP Act, 2023, and DPDP Rules, 2025.” (Paragraph 18)
The draft also names consent management for customer data within its scope. The consequence is direct: when RBI supervisors examine data governance, DPDP compliance is part of what they examine. A bank or NBFC that treats the DPDP Act as a standalone legal project, separate from its RBI obligations, will build the same infrastructure twice and defend it twice.
This compounds the dual-compliance position BFSI already occupies. The Responsible Business Conduct Directions have governed consent conduct for banks since July 1, 2026. The Second Amendment Directions for NBFCs take effect on January 1, 2027. The retention conflict between RBI mandates and DPDP erasure rights remains unresolved by either regulator. The draft guidance now adds the governance layer above all of it.
Draft Status: What “Not in Force” Means
The guidance is not enforceable today. Comments close on August 17, 2026, and finalisation follows. Nothing in the draft changes the DPDP enforcement timeline: the DPDP Rules took effect in November 2025, Consent Manager registration closes in November 2026, and penalty enforcement is expected from May 2027.
The preparation logic still runs one way. The DPDP obligations the draft references exist independently of it. A board committee does not materialise in a quarter. Neither does a tagged data estate. Entities that wait for the final guidance will be building governance structure at the same time their supervisors begin asking for it.
What Banks and NBFCs Should Do Now
Four actions fit inside the consultation window.
- File comments by August 17, 2026. The tagging and lineage requirements carry real implementation cost. If the draft’s expectations are impractical for your data estate, the comment window is the mechanism to say so.
- Map the data estate. Every subsequent obligation assumes you know what personal data you hold, where it came from, and why. Start with the data inventory.
- Put data governance on a board agenda. Whether a new committee or an existing one, the designation decision and its mandate belong in board minutes now.
- Consolidate the DPDP and RBI workstreams. The draft makes them one examination surface. Data Fiduciary obligations, consent records, and retention documentation should live in one system of record, not in parallel legal and IT projects.
ConsentOS operates this layer for BFSI: consent capture with signed Electronic Consent Artifacts, a Data Inventory portal, and a conflict-of-law documentation register that records where RBI retention mandates and DPDP erasure obligations collide. Run the Gap Assessment to see where your organisation stands, or review what DPDP compliance requires for NBFCs.
Know where you stand on DPDP compliance
Run the free Compliance Vault Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.
Enforcement milestones, rule notifications, and deadline analysis.
One email when it matters, no more.
Resources
Continue Reading
Related DPDP Act 2023 guidance from the ConsentOS knowledge base.
RBI Consent Rules for BFSI: Advisory 3/2026 and the July 1 Business Conduct Directions
The RBI Business Conduct Directions on consent took effect July 1, 2026. What banks and NBFCs must already have in place, alongside Advisory 3/2026.
9 min read
Industry GuidesRBI-DPDP Retention Conflict: KYC Erasure Rules for Indian Fintechs
The RBI and PMLA mandate five-year KYC retention. The DPDP Act requires erasure on request. For Indian fintechs and NBFCs, these obligations are in direct conflict. This article explains the Legal Obligation Override framework that resolves both simultaneously.
9 min read
Industry GuidesNBFC DPDP Compliance: RBI KYC Retention and PMLA Overrides in India
How NBFCs reconcile DPDP Act 2023 with RBI KYC retention, PMLA record-keeping, CIBIL consent and FIU-IND reporting. Legal Obligation Override explained.
11 min read
Industry GuidesDPDP Compliance for Banks: RBI KYC Retention vs Erasure Rights
RBI requires 5-year KYC retention. The DPDP Act grants erasure rights. Section 8(7) decides which wins. How banks resolve the conflict field by field.
10 min read