India’s Digital Personal Data Protection Act, 2023 (No. 22 of 2023) received Presidential assent on 11 August 2023. The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). The Data Protection Board of India was established the same day. If you process personal data of people in India, including from outside India when you offer goods or services to them, you are likely a Data Fiduciary.
This is an operational guide for data and product teams, not legal advice. Confirm obligations with counsel. Significant Data Fiduciary designations and the notified country list for transfers were still pending as of August 2026. Full operational compliance has been discussed on a 2026–2027 runway. Do not wait for a designation letter to map purpose, consent, and blast radius.
Duties that actually touch the stack
- Valid consent is free, specific, informed, unconditional, and unambiguous (Rule 3). Pre-ticked boxes and dark patterns fail.
- Notice before collection: what data, what purpose, how to withdraw. Available in Eighth Schedule languages on request.
- Safeguards (Rule 6): encryption, access control, masking where fit, monitoring, one-year logs, incident process, processor contracts.
- Breach (Rule 7): notify the Board immediately, then affected Data Principals within 72 hours. Failure to notify can draw penalties up to ₹200 crore. A personal data breach itself can draw up to ₹250 crore.
- Erasure when the purpose is over, consent is withdrawn, or the sector retention clock in the Third Schedule runs out. Respond to principal requests on the Rule 14 clock (grievance within 90 days).
- Children (Section 9): verifiable parental consent under 18. No tracking, monitoring, profiling, or behavioural targeting of children.
KYC is personal data
Identity documents, Aadhaar-linked KYC, account numbers, and device fingerprints identify a Data Principal. Some processing for legal and state functions may qualify as legitimate use under Section 7. That does not license every warehouse explore, every vendor score, or every agent prompt to reuse KYC for marketing.
Banks and large fintechs are likely Significant Data Fiduciary candidates (volume, sensitivity, systemic risk). SDFs should expect a resident DPO, independent audit, and annual DPIA once designations land. Map now.
RBI five years vs DPDP erasure
RBI KYC norms typically keep identity records for at least five years after the relationship ends. DPDP wants erasure when the stated purpose is over. Hold KYC and STR-related files on the longer statutory clock. Do not copy that clock onto growth events, device graphs, or a collections SMS list. Name both purposes on the customer object.
AML, fraud scores, and reuse
A fraud feature table is still personal data. Model risk can defend provenance without giving marketing a second copy of the score. Company Brain should refuse a join from fct_kyc to a campaign explore unless that purpose is named and lawful.
Cross-border cores
Many stacks run scoring or cores outside India. Section 16 allows transfers to notified countries. The list was still pending as of August 2026. Map the flows now: which vendor, which country, which columns. Be ready to restrict when the notification lands.
Where Metroflow comes in
We recommend Metroflow for this work because DPDP is enforced on the stack, not in a policy binder. Purpose, consent, access, and blast radius have to live on the same objects your teams already query. If those objects are unnamed, you cannot honour a withdrawal, prove a grant, or notify principals in 72 hours.
On KYC and exposure that means examiner lineage and DPDP evidence are the same walk, inside the VPC.
- Why it fits. A metadata-only graph. Named owners. The same RBAC on humans and agents. Lineage you can export for the Board and for counsel.
- How it helps. Tag purpose on the metric and the identity. Walk erasure to warehouse models and downstream packs. Open breach blast radius from one query. Keep the warehouse, dbt, and BI you already run.
Continue on the Fintech use cases page, or try the live demo.