23 Aug 2026


This is a link-enhanced version of an article that first appeared in Business Standard.
Article Overview:
The article examines how India’s evolving data-protection and regulatory framework is narrowing the regulatory-arbitrage advantage traditionally enjoyed by fintech companies. It discusses the impact of the DPDP Act, DPDP Rules, 2025 and RBI’s data-governance expectations on fintechs, banks and NBFCs, including the increasing importance of data governance, regulatory preparedness and risk-based obligations. The article also considers the implications for fintech funding, valuations and emerging opportunities across regtech, cyberrisk and governance.
Our Partner, Jishnu Sanyal, shared his perspective. Here’s what he had to say:
“Although banks, NBFCs and payment systems continue to operate within a more stringent regulatory framework overall, the compliance gap in data governance between regulated entities (REs) and fintechs has narrowed.”
“In parallel, the RBI’s outsourcing norms require REs to flow down appropriate risk-based obligations to fintech partners, calibrated to the functions outsourced and the risks involved.”
Download PDFUnder the rules of the Bar Council of India, Trilegal is prohibited from soliciting work or advertising in any form or manner. By accessing this website, www.trilegal.com, you acknowledge that:
We prioritize your privacy. Before proceeding, we encourage you to read our privacy policy, which outlines the below, and terms of use to understand how we handle your data:
For more information, please read our terms of use and our privacy policy.