DPDP Act 2025: Is Your Financial Data Safe?
India's new Digital Personal Data Protection Act 2023 and Rules 2025 force banks, lenders, and CAs to handle your personal and financial data carefully. If they don't, they face huge penalties — and you get new rights over your own data.
Your CA knows more about your finances than your spouse — and now the law holds them accountable for protecting it.
Your personal financial data breach could cost companies this much under new law
Key Takeaways
Review the privacy policy of every fintech app, lending platform, and bank portal you use — check if it mentions DPDP compliance and lists a grievance or Data Protection Officer contact.
Withdraw consent for data sharing you no longer need — most loan apps and financial platforms allow you to revoke permissions for marketing or third-party data sharing in settings or by writing to their DPO.
Ask your CA or tax advisor how your ITR documents, bank statements, and financial records are stored — request confirmation that their systems are password-protected, encrypted, and not shared without your consent.
India's new Digital Personal Data Protection Act 2023 and Rules 2025 force banks, lenders, and CAs to handle your personal and financial data carefully. If they don't, they face huge penalties — and you get new rights over your own data.
Here's what happened: India's DPDP Act 2023, with Rules enforced from 2025, creates binding data protection obligations for any entity processing Indian citizens' digital personal data, including financial institutions and tax professionals.. Penalties for non-compliance can reach up to ₹250 crore per incident, pushing banks, NBFCs, fintech platforms, and chartered accountants to urgently update how they collect, store, and use your data.. Indian citizens now have enforceable rights as 'data principals' — including the right to access, correct, and erase personal data held by lenders, apps, and advisors, and to file complaints with the Data Protection Board..
What you should do: Review the privacy policy of every fintech app, lending platform, and bank portal you use — check if it mentions DPDP compliance and lists a grievance or Data Protection Officer contact.. Withdraw consent for data sharing you no longer need — most loan apps and financial platforms allow you to revoke permissions for marketing or third-party data sharing in settings or by writing to their DPO.. Ask your CA or tax advisor how your ITR documents, bank statements, and financial records are stored — request confirmation that their systems are password-protected, encrypted, and not shared without your consent..
Under the DPDP Act, you can request a company to erase your personal data once your loan or service relationship ends — most lenders won't tell you this, but it is your legal right.
Draft a Free RBI Complaint
Loan Kavach walks you through the RBI CMS process. No lawyer, no fee. Escalate to the RB-IOS Ombudsman if unresolved in 30 days.
Get Loan Kavach — Free →References
- [1]“Digital Personal Data Protection Advisory Manual for Chartered Accountants” taxguruin · 10 Aug 2026
This article is reported by GoCredit's Editorial Team based on the source above. GoCredit synthesises, contextualises, and adds India-borrower-relevant analysis. We are not the original publisher.