Banks, NBFCs to Reset Fintech Partnerships as RBI Data Rules Raise Compliance Bar

Banks and NBFCs are reviewing fintech partnerships as RBI data governance norms and DPDP rules tighten data, privacy and third-party risk requirements.

By Samarjit Kaur

on August 28, 2026

Banks and non-banking financial companies (NBFCs) are preparing to revisit their partnerships with fintech firms.

The evolving data governance and privacy requirements underscore the importance of compliance and reassure financial institutions of their critical role in safeguarding data and maintaining trust.

The move follows the Reserve Bank of India’s (RBI) draft guidance on regulatory expectations for data governance and related requirements under the Digital Personal Data Protection (DPDP) Act, 2023 & DPDP Rules, 2025. This will directly impact how fintech companies structure their partnerships with banks and NBFCs.

Banks, NBFCs & other stakeholders have started discussions with legal, consulting and regulatory technology firms to review existing arrangements, emphasising the need for compliance teams to update their review protocols to align with new RBI data rules.

Also Read: India’s Data Protection Law Decoded: An Explainer on the DPDP Act

RBI Data Governance Rules Drive Partnership Review

The RBI’s draft guidance calls on regulated entities to establish a data governance framework aligned with their risk management systems. Boards would oversee these frameworks and review related reports and metrics annually, or more frequently where necessary.

The draft also requires financial institutions to identify and control data risks arising from third-party arrangements. Feedback on the proposals closed on August 17.

Bankers said existing fintech contracts will need to be reassessed as governance and compliance requirements become more demanding. The Indian Banks’ Association and Finance Industry Development Council, the RBI-approved self-regulatory organisation for NBFCs, are expected to have a role in the transition.

A key challenge for traditional lenders is that data is often spread across separate systems, and reworking these systems to meet new governance standards could take significant time and resources, requiring strategic planning and phased implementation.

Also Read: RBI Tightens Digital Payment Security Norms, Signals Shift Beyond OTP-Authentication

DPDP Penalties Put Greater Focus on Contracts

Sugandh Saxena, chief executive officer of the Fintech Association for Consumer Empowerment (FACE), said partnerships between financial institutions and fintechs are already being revisited, with contracts being reworked to meet the new requirements.

Penalties under the DPDP Rules, 2025, ranging from about ₹50 crore to ₹250 crore, highlight the need for stronger internal controls and encourage stakeholders to strengthen their data responsibilities proactively.

Rohan Lakhaiyar of Grant Thornton Bharat said several partnerships are undergoing compliance checks. Sprinto co-founder Raghuveer Kancherla said companies are increasingly being pushed to build compliance into products from the outset rather than add it later.

Also Read: RBI Tightens AI Rules for Banks, Seeks End to ‘Black Box’ Systems with New Governance Framework

Fintech Funding Faces Another Test

Tracxn data shows Indian fintechs have raised $822.9 million in calendar 2026 so far, compared with $2.4 billion in 2025 and $2.2 billion in 2024.

The number of funding rounds stood at 379 in 2026 so far, compared with 296 in 2025 and 60 in 2024, according to the report. Investors are increasingly favouring safer businesses, while the West Asia crisis and changing artificial intelligence-led business models in developed markets could further affect fresh fintech funding.

For banks and fintechs, the next phase will be less about simply signing partnerships and more about proving that customer data, accountability and compliance are built into those relationships from the start.

News Image