LSN News › India

Politics · India Bureau

Banks, NBFCs to renegotiate fintech partnership terms amid data rules

Stricter data governance norms from the Reserve Bank of India and the Digital Personal Data Protection Act are forcing Indian financial institutions to overhaul their fintech collaboration agreements and reassess third-party data handling risks.

LSN India · 26 August 2026

Banks, NBFCs to renegotiate fintech partnership terms amid data rules

Banks and non-banking financial companies across India are undertaking a comprehensive review of their fintech partnerships as regulatory frameworks tighten around data management and consumer protection. The push stems from two major regulatory developments: the RBI's draft guidelines on data governance for the financial sector and the recently enacted Digital Personal Data Protection (DPDP) Act, both of which impose stricter accountability measures on how financial data is collected, stored, and shared.

Financial institutions are now scrutinizing existing contracts with fintech partners to ensure compliance with the new standards. The revisions focus particularly on clarifying data ownership, defining permissible uses of customer information, and establishing clear liability frameworks for data breaches or misuse. Banks and NBFCs are also conducting detailed risk assessments of third-party service providers, including payment processors, lending platforms, and analytics firms.

The regulatory shift reflects growing concerns about data security and consumer privacy in India's rapidly expanding digital finance ecosystem. The RBI's data governance framework seeks to establish uniform standards across the banking sector, while the DPDP Act grants individuals greater control over their personal information. Together, these measures are expected to reshape the fintech landscape by imposing higher compliance costs and operational standards on partnerships.

Fintech firms and traditional financial institutions are now engaged in renegotiations to align their agreements with the new requirements. Industry observers expect the process to take several months as institutions work to balance innovation with enhanced regulatory compliance. The outcome may result in fewer but more carefully structured partnerships, with greater emphasis on data security infrastructure and consumer consent mechanisms.