RBI Customer Data Protection Advisory (Cyber Security & IT Risk Group)

RBI BFSI Advisory Active 1 Apr 2026

Applies to: Banks, NBFCs, fintechs, payment aggregators

RBI's sector-specific operationalisation of the DPDP Act for the financial ecosystem. It directs regulated entities to obtain board-level (or board-committee) approval for customer-data-security, privacy and third-party-risk policies, and to review data-security risks and incidents at board level on a quarterly or semi-annual basis. Where AI systems or chatbots handle customer data, entities must deploy API gateways, rate limiting, logging, threat detection and secure hosting, proportionate to the use case, with continuous monitoring via SIEM, API monitoring and anomaly detection. Data-erasure obligations point entities to NIST 800-88 (secure wiping, cryptographic erasure, physical destruction) in the absence of a domestic standard. Third-party data sharing is restricted to defined purposes, with anonymisation or pseudonymisation expected; a CRM generating unique complaint reference numbers with automated customer alerts is required.
Why it matters
RBI has moved first to translate DPDP principles into operational financial-sector controls — a year before DPDP's own substantive provisions bite. The tell is the explicit AI/chatbot control set: RBI is pre-positioning for the customer-facing GenAI deployments banks are racing to ship. The NIST 800-88 pointer is a quiet but real gap-filler — India has no domestic erasure standard, so RBI imported a US one, and your data-destruction SOPs should now cite it. Quarterly board review of data-security risk is the governance hook examiners will check first.