scieee AI-readable full text Open interactive document viewer

RBI's Role as Data Regulator: Expanding or Limiting Banking Privacy

Patil, Shamrao Jagannath; Jadhav, Namdev D.

Abstract

Abstract: In the contemporary landscape of digitized banking and fintech innovation, customer data has become essential to financial services. The Reserve Bank of India (RBI), through its statutory powers, functions as a de facto data regulator for the banking sector, setting directives for the collection, processing, and sharing of personal financial information, including KYC (Know Your Customer) and credit data. This role requires the RBI to reconcile its regulatory objectives with the constitutional right to informational privacy, affirmed by the Supreme Court's Puttaswamy judgment.This report explores whether the RBI's regulatory approach is expanding the protection of banking privacy or inadvertently constraining it. The analysis examines the legal framework—from constitutional principles to the new Digital Personal Data Protection (DPDP) Act, 2023—and critiques key RBI policies, such as KYC norms, the Account Aggregator framework, and credit information sharing rules. The discussion evaluates where RBI's regulations enhance privacy (e.g., through confidentiality and consent-based systems) and where they limit it (e.g., through extensive data collection and broad sharing mandates). Ultimately, the study aims to determine if the RBI’s evolving role bolsters or erodes the privacy of bank customers.

Full text

Journal of Research and Development Peer Reviewed International, Open Access Journal. ISSN : 2230-9578 | Website: https://jrdrvb.org Volume-17, Issue-9(III) | Sept. - 2025 274 RBI’s Role as Data Regulator: Expanding or Limiting Banking Privacy Shamrao Jagannath Patil1, Dr. Namdev D. Jadhav2 1Ph. D. Research Scholar, Department of Law, Swami Ramanand Tirtha Marathwada University, Nanded, Maharashtra, India. 2Ph. D. Guide, Department of Law, Swami Ramanand Tirtha Marathwada University, Nanded, Maharashtra, India. Manuscript ID: JRD -2025(I)-170946 ISSN: 2230-9578 Volume 17 Issue 9(III)| Pp 274-279 Sept. 2025 Submitted: 12 Aug. 2025 Revised: 22 Aug. 2025 Accepted: 20 Sept. 2025 Published: 30 Sept. 2025 Abstract: In the contemporary landscape of digitized banking and fintech innovation, customer data has become essential to financial services. The Reserve Bank of India (RBI), through its statutory powers, functions as a de facto data regulator for the banking sector, setting directives for the collection, processing, and sharing of personal financial information, including KYC (Know Your Customer) and credit data. This role requires the RBI to reconcile its regulatory objectives with the constitutional right to informational privacy, affirmed by the Supreme Court's Puttaswamy judgment.This report explores whether the RBI's regulatory approach is expanding the protection of banking privacy or inadvertently constraining it. The analysis examines the legal framework—from constitutional principles to the new Digital Personal Data Protection (DPDP) Act, 2023—and critiques key RBI policies, such as KYC norms, the Account Aggregator framework, and credit information sharing rules. The discussion evaluates where RBI's regulations enhance privacy (e.g., through confidentiality and consent-based systems) and where they limit it (e.g., through extensive data collection and broad sharing mandates). Ultimately, the study aims to determine if the RBI’s evolving role bolsters or erodes the privacy of bank customers. Keywords: RBI (Reserve Bank of India), Data Privacy / Informational Privacy, Banking Sector, Data Regulator, Digital Personal Data Protection Act, 2023 (DPDP Act), KYC (Know Your Customer), Account Aggregator Framework Introduction: In an era of digitized banking and fintech innovation, customer data has become the lifeblood of financial services. Banks routinely collect, process, and share personal financial information for purposes ranging from account opening and loan underwriting to fraud prevention. In India, the Reserve Bank of India (RBI), empowered by various statutes, regulates these activities and thus functions as a de facto data regulator for the banking sector. RBI’s directives determine how banks gather KYC information, how credit data is shared with bureaus, and even how digital lending apps handle user data. At the same time, individuals’ right to privacy in their personal data has been constitutionally recognized as part of the right to life and liberty under Article 21. The Supreme Court’s decision in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) affirmed that Indians enjoy a fundamental right to privacy, including “informational privacy” or the right to control the dissemination of personal information. This transformed the legal landscape, compelling regulators like RBI to reconcile privacy rights with regulatory objectives. This report explores whether RBI’s regulatory approach is expanding the protection of banking privacy or inadvertently constraining it. We first outline the legal framework governing data privacy in Indian banking, from constitutional principles to sector-specific laws and RBI guidelines. Quick Response Code: Website: https://jrdrvb.org/ DOI: 10.5281/zenodo.16885235 Creative Commons (CC BY-NC-SA 4.0) This is an open access journal, and articles are distributed under the terms of the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International Public License, which allows others to remix, tweak, and build upon the work noncommercially, as long as appropriate credit is given and the new creations ae licensed under the idential terms. Address for correspondence: Bhavesh Tare, Assistant Professor in Department of Accountancy, Yeshwantrao Chaphekar College of Arts & Commerce, Palghar How to cite this article: S. J. Patil, N.D. Jadhav.(2025). RBI’s Role as Data Regulator: Expanding or Limiting Banking Privacy. Journal of Research & Development, 17(9(III)274-279 Original Article Journal of Research and Development Peer Reviewed International, Open Access Journal. ISSN : 2230-9578 | Website: https://jrdrvb.org Volume-17, Issue-9(III) | Sept. - 2025 275 We then analyze key RBI policies – KYC norms, the Account Aggregator framework, credit information sharing rules – and critique their impact on customer privacy. The discussion evaluates how RBI’s regulations enhance privacy (e.g. through confidentiality obligations and consent-based systems), and where they limit privacy (e.g. through extensive data collection and broad data-sharing mandates). We also assess RBI’s obligations under the new Digital Personal Data Protection Act, 2023, and how this comprehensive data law influences RBI’s role. Throughout, relevant judicial rulings and government policy initiatives are referenced to provide context. By focusing exclusively on Indian laws and regulations, this study aims to elucidate RBI’s evolving role as a data regulator in banking, and whether its actions ultimately bolster or erode the privacy of bank customers. Legal Framework for Data Privacy in Banking Constitutional BasisArticle 21 and the Right to Privacy: The foundation of data privacy in India lies in Article 21 of the Constitution, which guarantees the right to life and personal liberty. The Supreme Court, in a unanimous 9-judge bench decision, held that privacy is a fundamental right protected by Article 21. In the Puttaswamy judgment (2017), the Court specifically recognized an individual’s right to control personal data and demanded that any intrusion by the state or others must satisfy legality, necessity, and proportionality. This means that regulators like RBI must ensure that data collection or sharing mandates have a sound legal basis, serve a legitimate aim, and are narrowly tailored. Privacy is not absolute, but any curtailment must be justified. A concrete application of these principles came in Puttaswamy (Aadhaar) (2018), where the Supreme Court struck down a government rule requiring mandatory linking of Aadhaar (the national biometric ID) with bank accounts. The Court found this mandate disproportionate and unconstitutional, noting that forcing customers to link Aadhaar or face account deactivation violated privacy and property rights. This highlighted that even in banking, individual privacy cannot be overridden without adequate justification. Statutory Confidentiality Duties: Long before “data protection” entered common parlance, Indian banking laws imposed duties of confidentiality and secrecy on banks. For instance, the Public Financial Institutions (Obligation as to Fidelity and Secrecy) Act, 1983 requires public financial institutions (including nationalized banks) to uphold stringent standards of confidentiality with customer information. Similarly, the Credit Information Companies (Regulation) Act, 2005 (CIC Act), which governs credit bureaus, mandates in Section 29 that any credit data shared by banks with a Credit Information Company (CIC) “must be handled with strict confidentiality.” Banks and CICs are legally obligated to prevent misuse or unauthorized disclosure of such data, with penalties for non-compliance. These laws firmly establish a duty to safeguard customers’ financial information as a statutory norm. Permissible Data Sharing and Exceptions: Indian law recognizes that banks may share customer information in certain situations, but only under carefully defined exceptions. RBI’s guidelines (and general law) allow disclosures in cases such as: (a) Compliance with legal orders – e.g. a court order or law enforcement demand can compel banks to provide information; (b) Regulatory requirements – banks must furnish data to regulators like RBI or the Financial Intelligence Unit (FIU) for supervision and anti-money laundering (AML) purposes; (c) Public interest – matters of national security or public safety can warrant data sharing; and (d) Customer consent – the customer authorizes a disclosure. These exceptions reflect the understanding that privacy may yield when outweighed by other interests (such as fighting crime), but even then, legality and necessity must be satisfied. Judicial precedents prior to Puttaswamy, such as Gobind v. State of M.P. (1975), had also held that privacy intrusions must be proportional to the need. Thus, a legal framework exists where banks are guardians of personal data by default, and any sharing of data is circumscribed by law and purpose. Notably, banks are also subject to the Right to Information Act, 2005 for certain disclosures. In RBI v. Jayantilal N. Mistry (2015), the Supreme Court ruled that RBI and banks could not hide behind “trust and confidentiality” to refuse sharing inspection reports and defaulters’ data under RTI – transparency for public interest was given primacy over blanket secrecy. This underscores that RBI’s role requires balancing privacy with transparency and accountability in the banking system. Digital Personal Data Protection Act, 2023 (DPDP Act): In 2023, India enacted its first comprehensive data privacy law. The DPDP Act, once fully in force, will apply to all organizations (including banks and the RBI itself) in processing digital personal data. It defines roles of “data fiduciaries” (akin to data controllers) and “data principals” (individuals), and lays down principles of consent, purpose limitation, data minimization, storage limitation, security safeguards, and data subject rights. Crucially, the DPDP Act will override previous IT rules (like the 2011 SPDI Rules) and any conflicting provisions in other laws on personal data. However, the Act also envisions co-existence with sectoral regulations. Sector-specific laws or regulators (finance, telecom, etc.) can continue to impose stricter requirements, and entities must comply with both regimes unless there is an outright conflict. In practice, this means banks must follow the DPDP Act’s general requirements (e.g. obtaining valid consent, allowing individuals to access or erase their data, notifying breaches), in addition to RBI’s regulations. If RBI rules are stricter (for example, requiring local storage of certain data), those prevail as a higher standard; if they are laxer in some respect, banks may have to elevate to the DPDP standard. Policy Analysis: RBI Regulations and Privacy Implications KYC Norms: Necessary Due Diligence vs. Intrusive Data Collection: Know Your Customer (KYC) norms are perhaps the most visible aspect of RBI’s data regulation. KYC rules require banks and financial institutions to verify the Journal of Research and Development Peer Reviewed International, Open Access Journal. ISSN : 2230-9578 | Website: https://jrdrvb.org Volume-17, Issue-9(III) | Sept. - 2025 276 identity of customers at onboarding and periodically thereafter. These norms stem from the Prevention of Money Laundering Act, 2002 (PMLA) and global anti-money laundering (AML) standards, and RBI first issued comprehensive KYC guidelines in 2004-2005 (in line with FATF recommendations). Today, RBI’s Master Direction on KYC (2016, as amended) forms the backbone of customer due diligence in India. Under this framework, banks must collect a range of personal data: official identity documents (such as PAN, passport, voter ID, or Aadhaar with consent), proof of address, photographs, and financial information, and must verify these against independent sources. They also categorize customers by risk profile and apply enhanced monitoring for higher-risk accounts. Moreover, KYC records and transaction data must be preserved for at least 5 years after the account closes, as per PMLA recordkeeping rules. These requirements mean that banks hold detailed personal databases of their customers – raising obvious privacy concerns about scope, security, and potential misuse. Privacy Enhancing Features: RBI’s KYC regime is intended to achieve a “critical balance” between security and privacy. In fact, RBI explicitly acknowledges that robust KYC norms serve dual goals: preventing financial crime on one hand, while maintaining the confidentiality of sensitive information on the other. In a December 2024 analysis, Economic Laws Practice noted that “the KYC norms issued by the RBI highlight the critical balance between ensuring financial security and safeguarding customer privacy”, being fundamental to a crime-free banking environment that also builds customer trust. Several policy safeguards support this balance. For example, RBI’s KYC Master Direction requires banks to protect KYC data as confidential and use it only for lawful AML/KYC purposes. Customer consent is built into certain processes: e.g., if Aadhaar is used for e-KYC, the customer must consent to UIDAI authentication. After the 2018 Aadhaar judgment, banks cannot force Aadhaar; they must offer other ID options, thereby upholding the individual’s choice and privacy. RBI also centralized KYC storage through CKYCR (Central KYC Registry) to reduce redundancy – meaning once a customer’s KYC is in the central registry, other banks can fetch it (with consent) instead of collecting documents repeatedly. This minimization of repeated data collection can reduce privacy risk. Furthermore, RBI has imposed penalties on banks for KYC violations, signaling that negligence in handling KYC data or processes is taken seriously. For instance, in 2024 RBI fined certain banks (RBL Bank, SBI and others) for failing to adhere to KYC and customer data guidelines. Enforcement actions like these underscore that customer data protection in KYC is an obligation, not an option. Account Aggregator Framework: Consent-Based Data Sharing RBI has also pioneered a novel data-sharing architecture in finance known as the Account Aggregator (AA) framework. Launched via Master Directions in 2016 (and operationalized by 2021), the AA system embodies the principles of the Data Empowerment and Protection Architecture (DEPA) – a policy idea to give individuals control over their personal data. Under the AA framework, specialized RBI-licensed entities (NBFC-AAs) act as “consent managers” that enable customers to share their financial information from one institution to another in a secure, digital, and consent-driven manner. As the government described at the AA launch, the network was introduced as “a financial data-sharing system that could facilitate investing and credit, giving consumers access and control over their financial records”. An Account Aggregator will only transfer data with the individual’s explicit direction and consent, and participation is entirely voluntary for consumers. The Account Aggregator (AA) model is a major privacy-enhancing innovation in India’s financial sector. It allows individuals to securely share their financial data—like bank statements or loan records—between institutions only with their explicit, informed consent. AAs don’t store or read data; they simply transmit encrypted information between Financial Information Providers and Users.This consent-based, auditable, and revocable system replaces risky practices like giving login credentials or physical documents. Regulated by the RBI, it ensures that data sharing stops immediately if consent is withdrawn. The AA framework thus gives customers full control over their financial information, aligning with the right to privacy recognized in Puttaswamy, and exemplifies how privacy and innovation can coexist in India’s digital finance ecosystem. While the Account Aggregator (AA) system strengthens privacy, some concerns remain. Users must fully understand the consent they give, but varying financial literacy may lead to over-sharing. Security risks also persist— despite strict RBI regulations and audits, data breaches are never impossible. As the AA ecosystem expands, effective oversight will be essential.Under the Digital Personal Data Protection (DPDP) Act, AAs could also function as “Consent Managers,” bringing them under the Data Protection Board’s supervision along with the RBI. Though participation is voluntary, banks or fintechs might indirectly pressure users to opt in, potentially undermining true consent. Overall, AAs mark a major step in privacy-focused, data-driven finance—but maintaining user trust will depend on strong regulation, awareness, and accountability. Credit Information Sharing: Transparency at the Cost of Privacy? The RBI regulates the sharing of customer credit data with Credit Information Companies (CICs) like CIBIL, Experian, Equifax, and CRIF Highmark under the CIC Act. Banks and NBFCs must regularly report borrowers’ loan and repayment details to these bureaus, creating a comprehensive credit profile and score. This system improves transparency and access to credit but also involves continuous sharing of sensitive personal data, raising privacy concerns despite RBI’s oversight and data protection guidelines.The RBI has implemented strong privacy safeguards for credit data under the CIC Act. Section 29 ensures strict confidentiality, with penalties for unauthorized disclosure. Journal of Research and Development Peer Reviewed International, Open Access Journal. ISSN : 2230-9578 | Website: https://jrdrvb.org Volume-17, Issue-9(III) | Sept. - 2025 277 RBI’s Master Directions mandate data accuracy, security, and regular audits by CICs and lenders. Since 2023, customers must be notified in real time whenever their credit data is accessed or updated. They also get one free credit report annually and can dispute errors, which must be resolved within 30 days, with compensation for delays. These measures enhance transparency, accountability, and individual control, reflecting RBI’s commitment to privacy-bydesign and data protection in financial systems. Despite strong safeguards, credit information sharing still raises privacy concerns. Individuals’ financial data—loans, repayments, and credit cards—is continuously reported to all Credit Information Companies (CICs), often without explicit consent. Errors in reporting can harm credit scores, affecting both privacy and consumer rights. Experts have highlighted gaps in data accuracy and warned against secondary use of credit data by CIC affiliates for marketing or profiling. Additionally, long data retention periods— often 7–10 years or more—mean past defaults may remain visible indefinitely, raising questions about fairness and proportionality. As fintech expands, the DPDP Act is expected to push for clearer limits on data use and retention, reinforcing privacy and accountability in credit reporting. Data Localization and Sharing with Third Parties In 2018, the RBI issued a landmark directive requiring all payment system data—including credit/debit card, UPI, and wallet transactions—to be stored exclusively on servers in India. This ensured “unfettered supervisory access” for regulators and improved data security. Global networks like Visa, MasterCard, and American Express were compelled to comply, with RBI even restricting new customer onboarding until localization was completed. While primarily a sovereignty and security measure, data localization also strengthens privacy protections, as sensitive financial data remains under Indian legal oversight. The rule mandates that even if transaction data is processed abroad, copies must be deleted from foreign systems and repatriated within 24 hours. The Digital Lending Guidelines (2022) extended this principle—requiring all customer data collected by digital lending apps to be stored domestically, ensuring transparency, accountability, and ease of regulatory audit. Together, these measures reflect RBI’s broader effort to create a secure, privacy-conscious digital financial ecosystem, balancing innovation with national and consumer interests. The RBI takes a conservative stance on third-party data sharing, prohibiting banks and lenders from sharing customer information without explicit consent or legal mandate. The Digital Lending Guidelines forbid access to borrowers’ personal device data (contacts, photos) without consent and limit collection to what is necessary. Automated decisions like algorithmic credit scoring also require consent to prevent opaque profiling. Following privacy breaches by some digital lenders, RBI now mandates clear privacy notices, disclosure of data sharing, and appointment of grievance officers. These rules embed fair information practices in finance, positioning RBI as a strong sectoral data regulator ahead of the DPDP Act. Critical Discussion: Does RBI’s Regulatory Approach Enhance or Erode Privacy? We now turn to a holistic appraisal of RBI’s role: Has the RBI emerged as an expander of banking privacy or a limiter of it? The analysis suggests a nuanced answer – RBI’s interventions have both protected and, at times, encroached upon customer privacy, reflecting the constant balancing act between privacy and other imperatives. On the side of enhancing privacy, RBI has indeed acted proactively in many areas: Confidentiality and Security Mandates: RBI’s regulations underscore a strong commitment to confidentiality – from statutory secrecy obligations to detailed cybersecurity guidelines requiring banks to encrypt personal data and tightly control access. These reduce the risk of unauthorized exposure of customer information, thus upholding privacy in practice. Consent and Control: Frameworks like the Account Aggregator are a testament to RBI’s efforts to empower customers with control over their data. By institutionalizing consent-based sharing and data portability, RBI has set a precedent that individual choice is central in financial data exchanges. Similarly, in digital lending, RBI’s insistence on explicit, granular consent for each type of personal data collected is a privacy-positive move. These measures align with the fundamental right to informational privacy affirmed in Puttaswamy, operationalizing it in the financial sector. Transparency to Customers: The mandate for credit bureaus and lenders to notify individuals whenever their credit report is accessed is an important privacy safeguard. It ensures that people are not kept in the dark about who is using their data. Coupled with annual free credit reports and an Ombudsman scheme for grievances, it strengthens individuals’ ability to monitor and control financial information about themselves. This empowerment reduces asymmetry and potential abuse. Data Protection Alignment: With the DPDP Act, RBI has shown signs of cooperation. It participated in consultations, and there are indications that RBI will issue revised guidelines to harmonize with DPDP (for instance, updating KYC rules to clarify data retention vs deletion in line with DPDP). The fact that both RBI and DPDP frameworks emphasize consent, reasonable purpose, security etc., means RBI’s approach is conceptually in line with modern privacy norms. In areas like tokenization of card data – RBI mandated that merchants cannot store card numbers, implementing a token system for transactions – the RBI actually went beyond existing law to protect consumers from card data breaches. This shows regulatory initiative to enhance privacy and security even absent a direct legal requirement. Journal of Research and Development Peer Reviewed International, Open Access Journal. ISSN : 2230-9578 | Website: https://jrdrvb.org Volume-17, Issue-9(III) | Sept. - 2025 278 There are ways in which RBI’s role has limited or compromised privacy, usually in pursuit of other objectives: Mandatory Data Collection and Sharing: RBI regulations require extensive personal data collection—such as full KYC and biometric e-KYC—and compulsory sharing of data, like credit information to bureaus or reports to government agencies under AML rules. Customers cannot refuse KYC or opt out of credit reporting, making this coercive processing justified by law for security and risk management. While necessary, these rules limit individual privacy. The proportionality of measures is debated—for example, whether small accounts or loans need the same KYC rigor as large ones. RBI’s “simplified KYC” eases requirements for small accounts but still demands basic personal information. This reflects a global regulatory trade-off: reducing privacy to strengthen transparency, security, and systemic integrity. Broad Surveillance Powers: Under RBI’s AML/CFT rules, banks monitor transactions and report suspicious activity to the FIU without notifying customers, to avoid alerting potential offenders. While lawful and aimed at security, this erodes privacy by allowing undisclosed scrutiny of financial activities. Such surveillance reflects RBI’s role in prioritizing security over individual privacy, a practice likely covered by consent exemptions under the DPDP Act. Localization vs Global Best Practices: RBI’s strict data localization boosts sovereignty and oversight but is critiqued as burdensome and not necessarily enhancing privacy. Critics say local storage doesn’t guarantee security and limits global interoperability. While the DPDP Act allows cross-border flows with safeguards, RBI prefers strict localization, prioritizing caution—especially given past misuse by foreign payment firms—though it may limit informational privacy and service choice. Judicial and Government Oversight: The judiciary (e.g., Puttaswamy) has mandated privacy as a core regulatory principle, pushing RBI to embed legality, necessity, and proportionality in its rules. Government initiatives like DEPA show privacy-friendly innovation, but mandates like Aadhaar rules highlight tensions. With the DPDP Act, RBI will work alongside the Data Protection Board, facing dual compliance for financial data. RBI may need to update its Master Directions (KYC, cybersecurity, outsourcing) to align with DPDP requirements such as breach notifications and data erasure requests. This could create overlaps and gaps, requiring clarity on roles between RBI and the Data Protection Board. RBI’s data regulation reflects cautious progressivism—advancing privacy and security while allowing broad data use for public good. This balance, shaped by its mandate for stability and integrity, faces a test in implementation. Success means protecting data without misuse while enabling financial inclusion; failure means eroding trust and privacy. Judicial guidance and the DPDP Act will likely push RBI further toward privacy-by-design. Conclusion RBI’s role as a data regulator balances enhancing privacy with necessary limits for security, fraud prevention, and credit development. It has strengthened safeguards through consent frameworks, transparency, and stricter guidelines (e.g., digital lending, credit reporting, Account Aggregators), aligning with constitutional privacy principles post-Puttaswamy. Yet, RBI mandates extensive KYC, monitoring, and compulsory data sharing, which constrain privacy as a trade-off for systemic goals. Under the DPDP Act, RBI must further align its rules with data protection standards on consent, retention, and security. Moving forward, RBI’s challenge will be to refine this balance— embedding privacy-by-design while enabling innovation—so that banking growth and customer trust advance together. References 1. Reserve Bank of India, Master Direction – Know Your Customer (KYC) Direction, 2016 (as updated in 2023), which consolidates RBI’s KYC guidelines and emphasizes both AML compliance and customer data confidentiality. 2. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 (Supreme Court of India) – the landmark judgment that declared the right to privacy (including informational privacy) to be a fundamental right under Article 21. 3. Justice K.S. Puttaswamy v. Union of India (Aadhaar), (2019) 1 SCC 1 – Supreme Court judgment striking down mandatory Aadhaar linking with bank accounts as unconstitutional for violating privacy and proportionality. 4. Credit Information Companies (Regulation) Act, 2005 – Section 29 imposes strict confidentiality on credit data shared with bureaus; RBI Master Directions on CICs and related RBI circulars (2023) enhancing consumer consent and grievance rights in credit reporting. 5. Public Financial Institutions (Obligation as to Fidelity and Secrecy) Act, 1983 – Section 3 mandates bank secrecy and underpins banks’ duty to protect customer privacy. 6. Payment and Settlement Systems Act, 2007 – Section 22 protects payment data secrecy; RBI circular on Storage of Payment System Data (2018) requiring data localization of payment information. 7. RBI, Account Aggregator (Reserve Bank) Directions, 2016 (updated 2021) – regulatory framework establishing NBFC-AAs to enable consent-based financial data sharing, giving individuals control over their financial data. 8. Press Information Bureau (Government of India), “94 Financial Institutions onboarded on Account Aggregator platform…” (Dec. 12, 2022) – highlights RBI’s introduction of the AA network as a secure, consent-driven datasharing system. Journal of Research and Development Peer Reviewed International, Open Access Journal. ISSN : 2230-9578 | Website: https://jrdrvb.org Volume-17, Issue-9(III) | Sept. - 2025 279 9. RBI, Digital Lending Guidelines (Sept. 2022) – guidelines imposing data privacy and security requirements on digital lenders, including consent for data access, data localization, and prohibition of excessive data harvesting. 10. Ankita Kaw, “The impact of India’s DPDPA on existing laws and regulations,” IAPP Privacy Tracker (Oct. 2024) – analysis of how the DPDP Act intersects with RBI regulations, noting differences in data localization and consent frameworks requiring alignment. 11. Shivalik Chandan et al., “India: Examining the Digital Personal Data Protection Act…,” Global Investigations Review (July 2025) – overview of the DPDP Act’s scope and sectoral interplay, acknowledging Puttaswamy’s informational privacy concept and RBI’s mandates on data storage and tokenization in the financial sector. 12. Economic Laws Practice, “Analysis of RBI Norms on KYC, Data Privacy, and Confidentiality Obligations in Banking” (Dec. 2024) – a comprehensive review of the evolution of KYC and privacy in Indian banking, citing legal provisions and RBI actions that maintain a balance between financial security and customer privacy. 13. Shyam Ponappa, “View: Privacy rules around credit information companies need tightening,” The Economic Times (Oct. 2023) – opinion by a former RBI ED suggesting improvements in CIC data handling, including stricter privacy safeguards in credit reporting (e.g. limiting data sharing with affiliates).