Each Monday, CRG holds an
Open House to review the latest developments in the regulatory world. Our
Experts offer their views for Policy Guidance.
Sector discussed this week: Fintech
The Reserve Bank of India
(RBI) Governor, Mr Sanjay Malhotra, in his address at the Global Fintech Fest,
said fintech companies should treat customer data as a fiduciary responsibility (with legal and ethical
obligation) rather than a business asset as he stressed on the need for responsible
data handling in the financial sector. Fintechs hold data – that can be
considered more valuable than the capital itself.
“This data must be treated
the way a trustee treats assets held for a beneficiary, collected with a clear
purpose and used strictly within the consent provided, and protected as though
it was one's own," as per Mr Malhotra. He further mentioned “
"Where a firm treats
consumer data as a monetizable asset first, and a responsibility second, trust
erodes”. Prudential regulations may not be necessitated at the early-stage
innovation, but as volumes grow, any disruption could have significant impact
on the financial system.
He cautioned against a
mindset of structuring a business around the gaps between regulatory categories
of scaling first and seeking clarity on forgiveness later.
From
CRG some of the perspectives that emerged are as follows:
FinTech and Data privacy: Even as the RBI
Governor states that fintech companies should treat
customer data as a fiduciary responsibility, one panellist stated that every other day one receives calls on insurance policy,
car insurance, medical insurance and so on. These data getting leaked out in
the market points to the fact that the companies use this as an asset rather
than a fiduciary duty.
Introduction of second SRO
by RBI for the FinTech sector: RBI
has recognised Unified FinTech Forum (UFF) as the second self-regulatory
organisation (SRO) in the FinTech sector
after FACE (Fintech Association for Consumer Empowerment). Even as
RBI
has refused to let go of its regulatory hold over the FinTech sector, probably
the bringing in of more than one self-regulatory organisation is necessary.
This may be what the FinTech sector needs in terms of a regulatory overview,
and letting the SROs decide on developing a regulatory framework for the sector
– opined one CRG member.
Establishment of PRB and
its challenges: On the Payment Regulatory Board (PRB), set up by the
RBI, following recommendations from the Watal Committee, one member pointed out
that the
committee had recommended PRB would be an independent body. The RBI has pushed
back against it. It was the first regulatory entity which was there with the
RBI on the payment sector, apart from DPSS (Department of Payment and
Settlement Systems). The PRB though, can do a lot more in terms of being a
quasi-independent, not independent because it's under the RBI. One meeting has been held so far. By
that time the second meeting happens this year, it is expected that the
concerned members will have got some idea of what they want to do.
DPDP Act vs RBI guidelines
on “Fiduciary duty” issue: A query was raised on why
the RBI is recommending looking at Fintechs treating data from a fiduciary
standpoint when you have the DPDP Act in play. The member opined that the problem
with FinTech is they create a database of information and they share it and
sell it. Now that is not permitted under the DPDP framework. So where is the
question of RBI coming in and saying is fiduciary? In any case, under DPDP & its rules they are data
fiduciaries and the data they use are not business assets of the companies.
One member replied
suggesting that RBI is maybe talking about it as a point of compliance with the
DPDP in terms of the fiduciary capability. The DPDP is still not fully rolled
out. Since it will happen by 2027, RBI is probably making a point without
explicitly referencing the DPDP that you must be acting with a higher
responsibility towards the data. So, it does not seem to be a separate track
from DPDP.
On similar lines, another
panellist mentioned the RBI was coming of the opinion that payment
aggregators may be utilising data as their own personal asset to sell off or to
share it through APIs etc to third parties. So, until DPDP takes full force, it
is maybe trying to enforce temporary caution and accountability. On the data
sharing agreements that are entered between two different people, he mentioned
there is insufficient clarity on rules with regards to what kind of data
sharing agreements can they enter into when they are transferring data through
APIs and other software development kits.
In his opinion, when
it comes to banking and financial data, we can expect a little bit more sense
of responsibility from these financial organisations with regards to the data
they have. If one looks at social media, they also share the same data with
third parties. But the data that they share is different than the commercial sensitive
data that exists with banking and financial organizations.
The panellist emphasized further that if
they come forward with some sort of regulation pertaining to a financial
organization, sharing data with third parties, one needs to be mindful of these
practices. You should act as a fiduciary but remember that handling sensitive
data presents a distinct set of challenges. Industry initiatives—such as
unified fintech forums—could serve as a practical channel for developing and
adopting these specialized data-handling standards.
Cross-Border Data Transfers & EU-GDPR
Conflicts: A query was raised by a CRG member in context of the upcoming EU–India
Free Trade Agreement - wondering how exactly is this relationship between the
data principle and data fiduciary with respect to payment aggregators being
managed in the European GDPR? The concern related to cross-border regulatory
hurdles that we might encounter in this respect.
Reply from one member harped on the fact that
the entities which are dealing with Europe in any way must be GDPR compliant.
There is need to study the comparisons of the
fiduciary structure between EUGDPR and the DPDP Act before further conclusions
could be made.
Another member
replied that if you are an entity that's based in India dealing with entities
in Europe, you need to have laws that are compliant at the same level. So,
regarding data transfers, you can't transfer to a country which has less
restrictions or less regulations with regards to data.
The third panellists
agreed on the fact that the countries to whom data is transferred should have
the same or similar protections as what GDPR offers. As per him, since the
Indian DPDP framework is not based entirely on GDPR, it has its own nuances.