Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
October 14, 2025
No Result
View All Result
Concur News

Home » Draft DPDP Rules: Banks Prepare to Tackle Operational Challenges

Draft DPDP Rules: Banks Prepare to Tackle Operational Challenges

May 26, 2025
in India, LAW, News, Regulation
Reading Time: 3 mins read
draft rules
Share on LinkedinShare on Whatsapp

The draft Digital Personal Data Protection (DPDP) rules require banks to get clear, explicit consent from customers before using their data for anything beyond the original purpose. While many banks already follow this principle, experts say these formal rules leave no room for regulatory shortcuts or loopholes.

Experts also say it’s still too early to fully understand how these rules will affect business. However, once finalized, banks will need to create proper data processing agreements with third-party companies. This will help ensure they meet the rules.

Banks often cross-sell products from their subsidiaries or partner companies to their customers. Although banks generally get consent before sharing customer data for cross-selling — as part of good governance — there have been exceptions. In some cases, this practice has not always been properly followed.

Consent Foundation

“Banks and NBFCs were not sharing data without the explicit consent of customers with their subsidiaries. Formal regulations make the requirement very explicit and leave no room for regulatory arbitrage. We do not foresee any business impact as such on account of the regulations. In fact, we see this as a great opportunity to build trust within the financial services ecosystem,” said Vivek Iyer, Partner, Financial Services Risk Advisory, Grant Thornton Bharat LLP.

Experts believe the draft rules are a positive move for customers because they improve data protection and bring India’s practices in line with global standards.

But corporate advisor Srinath Sridharan points out another concern. He questions whether banks are fully prepared for the operational challenges these rules bring. Banks will now need explicit consent before using customer data for anything beyond its original purpose. Except for a few large banks that have already started working on DPDP readiness, most of the sector still has a long way to go.

“One would assume that with the draft rules open for comments, the RBI might get the sector to ideate on this, through the Indian Banks’ Association (IBA) to help them prepare for DPDP implementation. This will require investment from banks — financial, technological, process change and training. A playbook of minimum acceptable operational norm could be expected from the regulator soon,” he added.

Currently, banks and insurance companies are reviewing the draft rules, which are open for public comment. They haven’t yet finalized their views or decided on their next steps.

“We are studying the draft rules and will finalise our views in some time. However, for us, since mobilisation of customers is done by bank staff who are qualified for selling insurance, they get the forms filled by the customer with their consent duly signed,” said a senior private sector insurance executive.

At the same time, a senior private sector banker warned that because many businesses rely on cross-leveraging group customers, requiring explicit consent could result in some business leakage.

According to Tisha Bhambry, Director Analyst at Gartner, the DPDP rules will require banks to set up strong consent management systems. These systems must allow customers to easily give consent, manage it, and withdraw it whenever they choose.

Besides that, banks must also have clear agreements with third-party partners to stay compliant. While these changes strengthen data protection and align with international standards, they also bring both challenges and opportunities for banks to build more customer trust through better privacy practices.

Read : Draft Digital Personal Data Protection Rules, 2025

Tags: Data privacyData ProtectionDPDP ActDPDPAPrivacy

Related Posts

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns
India

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns

September 8, 2025
Affordability Meets Privacy Risks in ChatGPT Go
India

Affordability Meets Privacy Risks in ChatGPT Go

September 3, 2025
Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw
Global

Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw

September 1, 2025
Raghuveer
Interview

Interview with Dr. Raghuveer Kaur, DPO at Cateina Technologies, on DPDPA, GRC, and Building Scalable Privacy Frameworks

August 29, 2025

RECOMMENDED NEWS

FTC and DOJ

FTC and DOJ push for data protection in Google antitrust case

5 months ago
Gujarat Police’s Sentinel Lab to Offer Cybersecurity Audits to Businesses

Gujarat Police’s Sentinel Lab to Offer Cybersecurity Audits to Businesses

2 months ago
New Aadhaar App to Revolutionize Digital Identity Verification

New Aadhaar App to Revolutionize Digital Identity Verification

6 months ago
BigID Launches AI-Powered Privacy Executive Console to Help Privacy Leaders Stay Ahead

BigID Launches AI-Powered Privacy Executive Console to Help Privacy Leaders Stay Ahead

6 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR google Hack Hacked Industry Interview Law Meity penalty Personal data Press Release Privacy privacy rights RBI SPAM Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager