RBI Governor urges fintechs to treat consumer data as a fiduciary duty

RBI Governor Sanjay Malhotra said fintechs must prioritise consumer-data protection, cybersecurity, resilience and accountability as their payment volumes, lending books and user bases expand.

— Source publishedFri, 11 Sept, 2026, 00:16 IST·First seen Fri, 11 Sept, 2026, 00:25 IST·Source ET Small Business

What happened

Reserve Bank of India · RBI Governor Sanjay Malhotra urged fintechs to treat consumer data as a fiduciary responsibility, warning that larger firms must

Key facts

  • $2.4 billion fintech funding last year
  • 30 fintech unicorns
  • India ranks third globally by fintech funding

Why this matters

Any fintech partnership or acquisition should be diligenced for data-governance maturity, cybersecurity controls and regulatory-accountability readiness.

What to watch

  • RBI circulars, supervisory guidance or enforcement actions on fintech data governance, outsourcing, cyber resilience or digital-lending practices.
  • New requirements for consent architecture, data localization, reporting of cyber incidents or third-party risk assessments.
  • Payment gateway, wallet or BNPL partner notices of revised merchant pricing, onboarding documentation or security requirements.
  • Major fintech outages, customer-data breaches or fraud events that accelerate retailer due diligence.
  • Evidence that banks restrict partnerships with lightly governed fintechs or require merchants to migrate transaction flows.
  • Map all customer-data flows involving payment gateways, BNPL, wallets, loyalty platforms, marketplace sellers and cloud vendors.
  • Require fintech partners to provide evidence of consent controls, data-retention policies, incident-response SLAs, penetration testing and business-continuity plans.
  • Review contracts for breach liability, customer-notification obligations, audit rights, subcontractor disclosure and service-availability commitments.
  • Prioritize first-party loyalty-data collection with clear opt-in language and reduce dependence on partner-held transaction data.
  • Prepare a contingency plan for payment-provider outages, including alternate acquirers, offline payment procedures and customer-service scripts.