DPDP Rules status: compliance window active. Read the update

Skip to content
Sector Rules · Finance

Finance & Fintech — RBI and SEBI Expectations

For fintechs, several RBI expectations already apply today. SEBI Regulation 16C already makes regulated firms answer for their AI tools. Wider SEBI AI guidelines are still only proposed.

Educational only · not legal adviceReviewed by Sandesh Kokate, Editor

What already applies (RBI)

  • Payment data localisation. The rule is not card-specific. RBI requires system providers to store payment-system data in a system located only in India. That covers the full end-to-end transaction details. It also covers everything collected, carried, or processed as part of the payment message or instruction. RBI's FAQs of 26 June 2019 list four categories of covered data:
    • Customer data.
    • Payment sensitive data.
    • Payment credentials.
    • Transaction data.

    UPI, wallet, and net-banking payment data is inside that scope, not outside it. The obligation reaches every payment system operator authorised under the PSS Act. It also reaches the entities they engage: intermediaries, third-party vendors, and payment gateways.

    Compliance responsibility sits with the authorised operator, not the vendor. Say cross-border transaction data has a foreign component and a domestic component. In that case, a copy of the domestic component may also be stored abroad if required. The FAQs also say you can process data outside India. There is no bar on that. But you must delete the data from the overseas systems and bring it back to India. The deadline is one business day, or 24 hours from payment processing, whichever comes first.

    If you run a payment system yourself, RBI's cyber-resilience Master Directions for non-bank payment system operators apply on top of this. Cyber rules for payment system operators

  • KYC data is dual-classified. KYC is the identity checks a regulated firm must run on customers. KYC data collected under RBI guidelines is "sensitive" under the SPDI Rules 2011. It is also "personal data" under DPDP. Both obligations apply at the same time.
Good practice, not required (no RBI rule cited)
  • Explainable credit decisions. If AI helps decide a loan, be ready to tell the customer why.
  • Model-drift checks. An AI model can change how it behaves over time. Watch for this and fix it.

SEBI — one binding rule, one proposal

SEBI already has one binding AI rule. Regulation 16C has applied since 10 Feb 2025: a regulated firm is responsible for any AI tool it uses. Separately, SEBI's June 2025 consultation paper proposes wider AI guidelines covering:

  • Disclosure.
  • Oversight.
  • Testing.
  • Fairness.
  • Investor protection.

Treat the consultation as a signal, not yet a binding obligation, until SEBI finalises it.

In plain English: if you're a fintech in India, RBI is the near-term regulator to plan for. SEBI matters if you use AI in the securities market. Regulation 16C already binds you. Wider rules are still being written.

Educational only — not legal advice

This page summarises sector expectations for orientation. For binding rulings on your product, consult qualified counsel and the primary source below.

Source
RBI — Storage of Payment System Data

RBI/2017-18/153, DPSS.CO.OD No. 2785/06.08.005/2017-2018, 6 April 2018. Issued by the Department of Payment and Settlement Systems under section 10(2) read with section 18 of the Payment and Settlement Systems Act, 2007, and signed by Nanda S. Dave, Chief General Manager. Being a DPSS instrument, it was not covered by the Department of Regulation consolidation of 28 November 2025. System providers were given six months to comply and to report compliance by 15 October 2018, with a Board-approved System Audit Report from a CERT-In empanelled auditor by 31 December 2018. PDF: https://rbidocs.rbi.org.in/rdocs/notification/PDFs/153PAYMENTEC233862ECC4424893C558DB75B3E2BC.PDF

Source
RBI — Frequently Asked Questions on Storage of Payment System Data

26 June 2019. DPSS instrument. The FAQs enumerate the payment data covered as customer data, payment sensitive data, payment credentials and transaction data. They recognise that there is no bar on processing payment transactions outside India, subject to deletion from the overseas systems and return of the data to India not later than one business day or 24 hours from payment processing, whichever is earlier; sharing payments data with an overseas regulator requires RBI approval. Where cross-border transaction data consists of a foreign component and a domestic component, a copy of the domestic component may also be stored abroad if required. Applicability reaches all payment system operators authorised by RBI under the PSS Act and the entities in the payments ecosystem they engage — including intermediaries, third-party vendors and payment gateways — with compliance responsibility resting on the authorised payment system operator rather than the vendor.

Source
SEBI — AI Guidelines consultationPrimary source not yet confirmed

Primary-source URL not yet confirmed against the regulator's own document listing — search to verify.

Quick self-check

Am I a Data Fiduciary?

Sector rules sit on top of DPDP, not instead of it. Run the self-check to confirm your baseline DPDP status first.

Run it now