RBI urges fintechs to treat customer data as a fiduciary responsibility

RBI Governor Sanjay Malhotra called on fintechs to strengthen data governance and operational resilience while expanding financial inclusion. The central bank also recognised the Unified Fintech Forum as India’s second fintech self-regulatory organisation.

— Source publishedThu, 10 Sept, 2026, 20:37 IST·First seen Thu, 10 Sept, 2026, 20:53 IST·Source Business Standard · Companies

What happened

Reserve Bank of India · RBI Governor Sanjay Malhotra urged Indian fintechs to treat customer data as a fiduciary responsibility, strengthen resilience as they

Key facts

  • 57 crore PMJDY accounts
  • 280 billion digital transactions in FY26
  • 24 billion UPI transactions per month
  • Indian fintechs rank third globally in funding
  • Unified Fintech Forum recognised as the second fintech SRO
  • FACE was recognised as the first fintech SRO in 2024

Why this matters

Deal teams should prioritize fintech targets with proven data stewardship, resilient infrastructure, and readiness to operate under industry-led self-regulation.

What to watch

  • RBI circulars or supervisory actions translating fiduciary-data language into mandatory controls, penalties or audit requirements.
  • Unified Fintech Forum codes of conduct covering consent, data sharing, cyber resilience, grievance redressal or third-party risk.
  • Increase in RBI enforcement actions, data-breach disclosures, payment outages or restrictions on fintech-bank partnerships.
  • Large banks requiring enhanced retailer and fintech due diligence for co-lending, card issuance or payment-processing arrangements.
  • Merchant and consumer adoption shifts toward payment providers marketing privacy, reliability and transparent data practices.
  • Audit all consumer-data flows across payment, loyalty, credit, marketplace and customer-service systems; identify data shared with fintech, bank and analytics partners.
  • Require fintech partners to provide evidence of consent management, data retention limits, encryption, subcontractor controls, breach notification and operational-resilience testing.
  • Review customer disclosures and consent journeys for co-branded cards, BNPL, wallets and seller-finance products; separate essential service data from marketing and profiling permissions.
  • Build contingency plans for payment or lending-partner outages, including alternative rails, customer communications and manual service procedures.
  • Prioritise partners with established governance capabilities and self-regulatory alignment over lowest-cost providers.