RBI chief tells fintechs to treat customer data as a fiduciary responsibility

RBI Governor Sanjay Malhotra urged fintechs to use consumer data only with clear purpose and consent, warning against exploiting regulatory gaps in ways that erode trust or financial-system stability.

— Source publishedFri, 11 Sept, 2026, 07:49 IST·First seen Fri, 11 Sept, 2026, 07:58 IST·Source Indian Express · Business

What happened

Reserve Bank of India · RBI Governor Sanjay Malhotra urged Indian fintechs to treat consumer data as a fiduciary responsibility, use it only with consent and

Why this matters

M&A teams should treat data-consent practices, regulatory-gap exposure, and governance controls as core diligence items for fintech and retail-finance targets.

What to watch

  • RBI circulars, enforcement actions or thematic inspections addressing consent, digital lending, account aggregators, outsourcing or data localization.
  • New RBI expectations for lending service providers, digital customer acquisition, algorithmic underwriting and recovery-agent data access.
  • Rise in consumer complaints related to unsolicited credit offers, misuse of transaction data, unauthorized data sharing or difficult consent withdrawal.
  • Fintech partner requests for revised data-processing agreements, consent artifacts or restrictions on retailer access to underwriting outcomes.
  • Declines in marketing opt-in, pre-approved credit conversion or embedded-finance approval rates after consent-flow changes.
  • Acceleration of Account Aggregator adoption, which could standardize consented financial-data sharing while reducing reliance on informal data collection.
  • Audit every customer-data flow across apps, stores, loyalty programs, checkout finance, wallets and third-party fintech integrations; map purpose, consent, retention and downstream sharing.
  • Separate mandatory service consent from optional marketing, personalization and cross-sell permissions, with simple withdrawal and consent-history access.
  • Require fintech, NBFC, payment and data-analytics partners to provide auditable consent logs, breach notification commitments, data-deletion SLAs and restrictions on secondary use.
  • Reduce dependence on opaque alternative-data underwriting for retail credit; test first-party transaction, repayment and loyalty signals that can be explained to customers.
  • Prepare for lower opt-in rates by redesigning loyalty and personalization value exchanges around visible benefits such as rewards, faster refunds, fraud protection and better financing terms.
  • Establish a board-level data-fiduciary governance cadence linking privacy metrics to customer complaints, fraud, credit losses, conversion and regulator interactions.