Product notes

The DPDP Act, Explained: What It Means for Your Financial Data

The Digital Personal Data Protection Act, 2023 is India’s first comprehensive law on how companies can collect, use, and store personal data. If you’ve handed a financial advisor your PAN, bank statements, or income details, this is the law that’s meant to govern what they can do with that information — and increasingly, what they have to ask you before doing it.

Where things actually stand

The Act itself was passed in 2023, but a law like this doesn’t take effect all at once — it needs detailed rules, and those rules define the real deadlines. Here’s the timeline as it stands:

  • November 2025 — the DPDP Rules were notified, and the Data Protection Board was established. This is the phase we’re in now.
  • November 2026 — the window for organizations to register as “Consent Managers” — the entities meant to help individuals manage consent across services — is expected to close.
  • May 2027 — full enforcement, at the end of an 18-month transition period. This is when notice requirements, consent rules, security obligations, data-principal rights, and breach notification all become fully enforceable, with penalties attached.

There’s also a proposal, made in January 2026, to shorten that transition window from 18 months to 12 for large-volume data processors — which would move some deadlines earlier if it’s formally notified. Worth checking back on if you’re tracking this closely.

What the Act actually asks of a company like a financial advisor

Stripped of legal language, the core ideas are fairly simple:

  • Consent has to be specific. Not one blanket agreement — a clear notice for each purpose data is collected for, in a language you can understand.
  • You can take it back. Consent isn’t a one-way door. Withdrawing it should be as easy as giving it.
  • You have rights over your own data — to access it, correct it, and in most cases, ask for it to be deleted.
  • Breaches have to be reported, both to the regulator and to the people affected.
  • There has to be someone to contact — a named grievance officer, not a generic support inbox.

Why this matters more for financial data specifically

A PAN number, a bank statement, an income figure — this is data that can’t be reissued if it leaks, the way a password can be reset. Financial advisors and fintech platforms sit on exactly this kind of data for entire households, which is part of why the consent and security obligations here are worth understanding, not just complying with on paper.

This is also why we built purpose-based consent and encrypted storage of sensitive fields into Fleek’s product from early on, rather than waiting for the May 2027 deadline to start.

← Back to Insights Get a Demo

Leave a Reply

Your email address will not be published. Required fields are marked *