RBI urges fintechs to treat customer data as a fiduciary responsibility

RBI Governor Sanjay Malhotra called on fintechs to strengthen data governance, cybersecurity and operational resilience, while directing innovation toward financial inclusion. The central bank also recognised the United Fintech Forum as a fintech self-regulatory organisation.

— Source publishedThu, 10 Sept, 2026, 20:06 IST·First seen Thu, 10 Sept, 2026, 20:24 IST·Source Business Today · Latest

What happened

Reserve Bank of India · RBI Governor Sanjay Malhotra urged fintechs to treat customer data as a fiduciary responsibility, strengthen cybersecurity and

Key facts

  • India's fintech ecosystem ranks third globally
  • 30 fintech unicorns
  • United Fintech Forum recognised as the second fintech self-regulatory organisation

Why this matters

Prioritize fintech partners and targets with demonstrable data controls, cyber resilience and regulatory maturity, as these capabilities are becoming essential to scalable embedded-finance propositions.

What to watch

  • RBI circulars or supervisory guidance translating fiduciary language into mandatory governance, audit, reporting or resilience requirements.
  • United Fintech Forum codes of conduct, membership standards, dispute-resolution rules or enforcement actions.
  • A major fintech data breach, payments outage or fraud event that accelerates retailer due diligence and regulatory scrutiny.
  • Merchant contract repricing or service-level changes tied to cybersecurity, data governance and disaster-recovery commitments.
  • Evidence of banks and large payment platforms tightening API-access, data-sharing and third-party-risk requirements for retail partners.
  • Audit all customer-data flows across checkout, loyalty, CRM, marketplace, delivery, lending and fraud vendors; identify where customer consent, data retention and breach-accountability are unclear.
  • Add cybersecurity, operational-resilience, subcontractor-risk and incident-notification clauses to fintech and payment-provider contracts.
  • Prioritize partners with strong RBI alignment, mature governance certifications, tested disaster recovery and clear data-localization practices.
  • Redesign checkout and embedded-finance consent journeys to separate necessary transaction data from optional marketing, profiling and credit-use permissions.
  • Build fallback payment-routing and manual-order-continuity plans for outages affecting gateways, UPI, fraud tools, BNPL and identity-verification services.