Banks and non-banking financial companies (NBFCs) are preparing to revisit their partnerships with fintech firms.
The evolving data governance and privacy requirements underscore the importance of compliance and reassure financial institutions of their critical role in safeguarding data and maintaining trust.
The move follows the Reserve Bank of India’s (RBI) draft guidance on regulatory expectations for data governance and related requirements under the Digital Personal Data Protection (DPDP) Act, 2023 & DPDP Rules, 2025. This will directly impact how fintech companies structure their partnerships with banks and NBFCs.
Banks, NBFCs & other stakeholders have started discussions with legal, consulting and regulatory technology firms to review existing arrangements, emphasising the need for compliance teams to update their review protocols to align with new RBI data rules.
Also Read: India’s Data Protection Law Decoded: An Explainer on the DPDP Act
RBI Data Governance Rules Drive Partnership Review
The RBI’s draft guidance calls on regulated entities to establish a data governance framework aligned with their risk management systems. Boards would oversee these frameworks and review related reports and metrics annually, or more frequently where necessary.
The draft also requires financial institutions to identify and control data risks arising from third-party arrangements. Feedback on the proposals closed on August 17.
Bankers said existing fintech contracts will need to be reassessed as governance and compliance requirements become more demanding. The Indian Banks’ Association and Finance Industry Development Council, the RBI-approved self-regulatory organisation for NBFCs, are expected to have a role in the transition.
A key challenge for traditional lenders is that data is often spread across separate systems, and reworking these systems to meet new governance standards could take significant time and resources, requiring strategic planning and phased implementation.
Also Read: RBI Tightens Digital Payment Security Norms, Signals Shift Beyond OTP-Authentication
DPDP Penalties Put Greater Focus on Contracts
Sugandh Saxena, chief executive officer of the Fintech Association for Consumer Empowerment (FACE), said partnerships between financial institutions and fintechs are already being revisited, with contracts being reworked to meet the new requirements.
Penalties under the DPDP Rules, 2025, ranging from about ₹50 crore to ₹250 crore, highlight the need for stronger internal controls and encourage stakeholders to strengthen their data responsibilities proactively.
Rohan Lakhaiyar of Grant Thornton Bharat said several partnerships are undergoing compliance checks. Sprinto co-founder Raghuveer Kancherla said companies are increasingly being pushed to build compliance into products from the outset rather than add it later.
Also Read: RBI Tightens AI Rules for Banks, Seeks End to ‘Black Box’ Systems with New Governance Framework
Fintech Funding Faces Another Test
Tracxn data shows Indian fintechs have raised $822.9 million in calendar 2026 so far, compared with $2.4 billion in 2025 and $2.2 billion in 2024.
The number of funding rounds stood at 379 in 2026 so far, compared with 296 in 2025 and 60 in 2024, according to the report. Investors are increasingly favouring safer businesses, while the West Asia crisis and changing artificial intelligence-led business models in developed markets could further affect fresh fintech funding.
For banks and fintechs, the next phase will be less about simply signing partnerships and more about proving that customer data, accountability and compliance are built into those relationships from the start.

Samarjit Kaur is a journalist and communications professional covering technology & emerging digital trends. With a focus on clarity and context, she reports on developments shaping industries and governance. When not reporting, she chooses to plug-in and relax on her playlists and plan her next bucket-list trips!
