Why the convergence of data-protection law, AI accountability, and consent architecture is the defining governance challenge for Indian financial institutions in 2025-26, and why the window to act is narrower than most boards currently appreciate.
The Regulatory Intersection Nobody Can Afford to Ignore
India’s financial sector is approaching a structural inflection point where regulation and technology increasingly shape each other.
The Digital Personal Data Protection (DPDP) Act signals that trust must be engineered into digital systems, while AI is rapidly moving into production across fraud detection, credit underwriting, and digital onboarding.
As these forces converge, financial institutions must move beyond policy-driven privacy and experimental AI to build systems where data use is provable, and decisions are explainable, a fundamentally different engineering mandate than most institutions operate under today.
REGULATORY CONTEXT: India vs the World
How does India’s DPDP framework compare against GDPR & EU AI Act globally?
DPDP’s ₹250 crore per-category penalty can be more severe for large financial institutions than GDPR’s revenue-based cap. With no lower-tier administrative fines, a single violation could become one of the largest regulatory penalties in Indian banking history.
The DPDP Transition: Compliance Becomes Architecture
The DPDP Act is expected to give institutions about 18 months to reach operational readiness, a compressed timeline for financial institutions with complex, legacy data ecosystems and multiple vendor dependencies. Unlike earlier privacy frameworks focused on policies and disclosures, DPDP requires operational proof of consent across all data environments, from apps and CRM systems to analytics and partner integrations. It also introduces the concept of the Data Fiduciary, making accountability a board-level responsibility and embedding compliance directly into technology and operational governance.
For BFSI institutions, the reputational cost of a DPDP failure may ultimately exceed the financial penalty, in a sector where trust is the primary product.
Why BFSI Faces the Most Complex Transition
Few industries handle data at the scale and sensitivity of financial services. Each digital interaction generates a stream of identity, transaction, and behavioural data flowing across multiple systems and partners. This creates a distributed data environment where DPDP compliance requires operational redesign, not just policy updates, including clear consent interfaces, real-time withdrawal propagation, auditable grievance records, and detailed data access logs demonstrating lawful use of personal data.
The Consent Stack: A Reference Architecture for DPDP-Ready Institutions
DPDP readiness requires more than policy updates. Institutions require a Consent Stack Architecture that can serve as a layered technology framework that operationalises consent governance across the various systems, APIs, and data pipelines. Unlike the basic consent tools, what it does is that it enforces consent capture, control, and auditability throughout the entire data ecosystem.
AI Is Expanding Faster Than the Governance Frameworks
While the DPDP tightens expectations around the lawful use of data, AI adoption across BFSI is increasing as well. Global AI investment in financial services is projected to cross $190 billion this decade. This will be driven by automated risk assessment, fraud detection, and personalised services. Indian banks, insurers, and fintechs are already deploying AI across underwriting, fraud monitoring, customer service, and collections. However, every model introduces new data flows and dependencies. Under the DPDP, these must be fully traceable and purpose-bound to make consent lineage and data governance critical to avoid the retroactive compliance risk.
REGULATORY SIGNAL: The EU AI Act’s Relevance to the Indian BFSI ecosystem
Under the European Union’s AI Act, things like credit scoring, insurance risk assessment, and fraud detection systems are classified as High-Risk AI. This means that it requires a mandatory conformity assessment, data governance documentation, and human oversight. India, till now, does not have an equivalent AI regulation, but the RBI’s evolving guidance on model risk management and the MeitY AI Advisory increasingly reference EU frameworks as crucial benchmarks. Institutions that build to EU AI Act standards today will face less retrofitting when Indian AI regulation arrives, likely within this regulatory cycle.
Responsible AI as Operational Infrastructure
Responsible AI in the BFSI ecosystem is shifting away from ethical aspiration to operational infrastructure. Institutions deploying AI in onboarding, fraud detection, and credit decisions must also ensure data lineage, model validation, version governance, drift monitoring, and human oversight not as constraints, but as foundations for resilient and audit-ready AI.
V-KYC: A Microcosm of the DPDP-AI Convergence
Video-KYC illustrates how AI and DPDP converge in practice. Technologies like face matching, liveness detection, and automated document extraction have accelerated onboarding. But regulators are increasingly asking whether the institutions can prove the process was conducted correctly or not. That requires recorded interactions, explicit consent capture, operator logs, and tamper-evident audit trails. When designed well, digital onboarding strengthens both privacy and financial inclusion.
The Infrastructure Gap and Who Is Filling It
DPDP readiness cannot be achieved by retrofitting legacy GRC platforms. It requires purpose-built infrastructure that can operationalise consent governance, enforce data lineage, and maintain audit-ready trails across distributed systems. A new layer of technology is emerging where data consent, AI oversight, and financial operations are coming together.
Preparing for the Next Phase of AI Regulation
As AI adoption grows, regulatory scrutiny will intensify. With the EU AI Act and emerging Indian policy signals, explainability, fairness, and governance will become the centre of AI regulation. A 2023 McKinsey study found that European banks that treated GDPR as an architectural transformation and not documentation achieved 40% faster AI deployment and lower breach costs. When the right systems are in place to manage consent and track how data is used, AI teams can work with more clarity and confidence within set boundaries. India’s DPDP framework offers a similar opportunity.
Institutions that treat this moment as a one-time compliance exercise may find themselves repeatedly retrofitting controls as technology and regulation evolve in tandem. Those that treat it as an architectural shift will be far better positioned to scale AI confidently and to demonstrate to regulators, boards, and customers that they have earned the right to operate at scale.
Read More: Cross-Border Payments: The Next Fintech Battleground
The Two Questions That Will Define the Next Decade
Did we have the lawful right to use this data? Can we clearly explain the decision our system produced?
When those answers are embedded within architecture, governance processes, and operational controls, compliance ceases to be defensive. It becomes strategic.
In a sector where trust has always been the currency of growth, that strategic confidence may ultimately determine which institutions lead the next phase of AI-driven finance in India and which ones spend the next decade explaining why they weren’t ready.
Views expressed by: Amit Das, Founder and CEO, Think360.ai










