RBI Governor tells fintechs to treat customer data as a fiduciary responsibility

RBI Governor Sanjay Malhotra urged fintechs to strengthen cyber resilience, use consent-led Account Aggregator architecture and avoid exploiting regulatory gaps or putting growth ahead of compliance.

— Source publishedThu, 10 Sept, 2026, 22:07 IST·First seen Thu, 10 Sept, 2026, 22:16 IST·Source The Hindu BusinessLine

What happened

Reserve Bank of India · RBI Governor Sanjay Malhotra urged fintechs to treat customer data as a fiduciary responsibility, strengthen resilience and

Why this matters

Prioritize targets and partners with mature Account Aggregator integration, auditable data controls and strong cyber capabilities to reduce regulatory and reputational risk.

What to watch

  • RBI circulars or supervisory guidance specifying Account Aggregator, consent, cyber-resilience or data-localization requirements.
  • Enforcement actions, business restrictions or remediation orders involving digital lenders, payment firms or account aggregators.
  • A major fintech data breach, unauthorized data-sharing complaint wave or cyber outage affecting customer balances or credit access.
  • Growth in Account Aggregator consent volumes, participating financial information providers and lender underwriting use cases.
  • Investor funding terms that increasingly require regulatory audits, security certifications or board-level risk controls.
  • Accelerate consent-management, data-retention, breach-response and third-party vendor-control programs.
  • Shift customer-data architecture toward Account Aggregator-compatible, purpose-limited data flows with auditable consent logs.
  • Review lending, insurance and wealth cross-sell journeys for dark patterns, excessive permissions and unclear data-sharing disclosures.
  • Prioritize bank and NBFC partnerships that can provide stronger governance, compliance oversight and incident-management capabilities.
  • Prepare for increased RBI scrutiny by documenting board accountability for cyber resilience, model governance and customer grievance handling.