RBI Governor tells fintechs to treat consumer data as a fiduciary duty

RBI Governor Sanjay Malhotra has urged fintechs to prioritise consumer consent, cybersecurity and operational resilience, while engaging regulators early as payment volumes, lending books and user bases scale.

— Source publishedFri, 11 Sept, 2026, 01:16 IST·First seen Fri, 11 Sept, 2026, 01:31 IST·Source ET Small Business

What happened

Reserve Bank of India · RBI Governor Sanjay Malhotra urged fintechs to treat consumer data as a fiduciary responsibility, stressing consent, cybersecurity,

Key facts

  • $2.4 billion fintech funding last year
  • 30 fintech unicorns

Why this matters

Retailers and financial platforms should prioritize partners and acquisition targets with regulator-ready data governance, resilient infrastructure and scalable consent management.

What to watch

  • RBI circulars or supervisory actions specifying consent-management, data-minimization, outsourcing or cyber-resilience requirements for fintechs and regulated partners.
  • Enforcement actions, license restrictions or public security incidents involving payment aggregators, digital lenders, account aggregators or major consumer fintechs.
  • Banks requiring merchants and fintech partners to submit enhanced due-diligence, audit evidence or incident-response commitments.
  • Increases in checkout abandonment, opt-out rates, fraud losses or credit approval declines after consent-flow changes.
  • Payment outages during peak retail events that expose inadequate business-continuity arrangements.
  • Consolidation, funding stress or pricing increases among smaller payment, lending and fraud-tech providers.
  • Audit every customer-data handoff across stores, apps, websites, loyalty programs, payment gateways, lending partners and marketplace sellers.
  • Separate marketing consent from consent for credit underwriting, payments, fraud prevention and data sharing; retain granular, revocable consent records.
  • Require fintech and payment partners to provide cybersecurity certifications, breach-notification SLAs, business-continuity plans, data-location disclosures and subcontractor inventories.
  • Build fallback checkout and reconciliation processes for payment-provider outages, including offline store procedures and alternate acquiring or UPI routing.
  • Reassess economics of embedded credit and loyalty-linked financial offers under lower data availability, higher compliance costs and potentially stricter customer disclosures.
  • Consolidate overlapping fintech vendors where accountability for customer data, fraud losses and service outages is unclear.