Apply Now
RBI Governor Urges Fintechs to Treat Customer Data As Fiduciary Responsibility, and not as Commercial Asset

RBI Governor Urges Fintechs to Treat Customer Data As Fiduciary Responsibility, and not as Commercial Asset

Category : RBI

Each Monday, CRG holds an Open House to review the latest developments in the regulatory world. Our Experts offer their views for Policy Guidance.

Sector discussed this week: Fintech

The Reserve Bank of India (RBI) Governor, Mr Sanjay Malhotra, in his address at the Global Fintech Fest, said fintech companies should treat customer data as a fiduciary responsibility (with legal and ethical obligation) rather than a business asset as he stressed on the need for responsible data handling in the financial sector. Fintechs hold data – that can be considered more valuable than the capital itself.

“This data must be treated the way a trustee treats assets held for a beneficiary, collected with a clear purpose and used strictly within the consent provided, and protected as though it was one's own," as per Mr Malhotra. He further mentioned “

"Where a firm treats consumer data as a monetizable asset first, and a responsibility second, trust erodes”. Prudential regulations may not be necessitated at the early-stage innovation, but as volumes grow, any disruption could have significant impact on the financial system.

He cautioned against a mindset of structuring a business around the gaps between regulatory categories of scaling first and seeking clarity on forgiveness later.

From CRG some of the perspectives that emerged are as follows:

FinTech and Data privacy: Even as the RBI Governor states that fintech companies should treat customer data as a fiduciary responsibility, one panellist stated that every other day one receives calls on insurance policy, car insurance, medical insurance and so on. These data getting leaked out in the market points to the fact that the companies use this as an asset rather than a fiduciary duty.

Introduction of second SRO by RBI for the FinTech sector: RBI has recognised Unified FinTech Forum (UFF) as the second self-regulatory organisation (SRO) in the FinTech sector after FACE (Fintech Association for Consumer Empowerment). Even as RBI has refused to let go of its regulatory hold over the FinTech sector, probably the bringing in of more than one self-regulatory organisation is necessary. This may be what the FinTech sector needs in terms of a regulatory overview, and letting the SROs decide on developing a regulatory framework for the sector – opined one CRG member. 

Establishment of PRB and its challenges: On the Payment Regulatory Board (PRB), set up by the RBI, following recommendations from the Watal Committee, one member pointed out that the committee had recommended PRB would be an independent body. The RBI has pushed back against it. It was the first regulatory entity which was there with the RBI on the payment sector, apart from DPSS (Department of Payment and Settlement Systems). The PRB though, can do a lot more in terms of being a quasi-independent, not independent because it's under the RBI. One meeting has been held so far. By that time the second meeting happens this year, it is expected that the concerned members will have got some idea of what they want to do.

DPDP Act vs RBI guidelines on “Fiduciary duty” issue: A query was raised on why the RBI is recommending looking at Fintechs treating data from a fiduciary standpoint when you have the DPDP Act in play. The member opined that the problem with FinTech is they create a database of information and they share it and sell it. Now that is not permitted under the DPDP framework. So where is the question of RBI coming in and saying is fiduciary? In any case, under DPDP & its rules they are data fiduciaries and the data they use are not business assets of the companies.

One member replied suggesting that RBI is maybe talking about it as a point of compliance with the DPDP in terms of the fiduciary capability. The DPDP is still not fully rolled out. Since it will happen by 2027, RBI is probably making a point without explicitly referencing the DPDP that you must be acting with a higher responsibility towards the data. So, it does not seem to be a separate track from DPDP.

On similar lines, another panellist mentioned the RBI was coming of the opinion that payment aggregators may be utilising data as their own personal asset to sell off or to share it through APIs etc to third parties. So, until DPDP takes full force, it is maybe trying to enforce temporary caution and accountability. On the data sharing agreements that are entered between two different people, he mentioned there is insufficient clarity on rules with regards to what kind of data sharing agreements can they enter into when they are transferring data through APIs and other software development kits.

In his opinion, when it comes to banking and financial data, we can expect a little bit more sense of responsibility from these financial organisations with regards to the data they have. If one looks at social media, they also share the same data with third parties. But the data that they share is different than the commercial sensitive data that exists with banking and financial organizations.  

The panellist emphasized further that if they come forward with some sort of regulation pertaining to a financial organization, sharing data with third parties, one needs to be mindful of these practices. You should act as a fiduciary but remember that handling sensitive data presents a distinct set of challenges. Industry initiatives—such as unified fintech forums—could serve as a practical channel for developing and adopting these specialized data-handling standards. 

Cross-Border Data Transfers & EU-GDPR Conflicts: A query was raised by a CRG member in context of the upcoming EU–India Free Trade Agreement - wondering how exactly is this relationship between the data principle and data fiduciary with respect to payment aggregators being managed in the European GDPR? The concern related to cross-border regulatory hurdles that we might encounter in this respect. 


Reply from one member harped on the fact that the entities which are dealing with Europe in any way must be GDPR compliant. There is need to study the comparisons of the fiduciary structure between EUGDPR and the DPDP Act before further conclusions could be made. 


Another member replied that if you are an entity that's based in India dealing with entities in Europe, you need to have laws that are compliant at the same level. So, regarding data transfers, you can't transfer to a country which has less restrictions or less regulations with regards to data. 


The third panellists agreed on the fact that the countries to whom data is transferred should have the same or similar protections as what GDPR offers. As per him, since the Indian DPDP framework is not based entirely on GDPR, it has its own nuances. 

Accessibility Options