โ† Home
Home โ€บ Banking
Banking

RBI proposes stricter data rules for banks and NBFCs

๐Ÿ“… 2026-07-19 ๐Ÿ“‚ Banking Original source โ†—
RBI proposes stricter data rules for banks and NBFCs
Representative image ยท Pexels (free license)
Key points

The Reserve Bank of India (RBI) has proposed a fresh set of data governance rules for banks and non-banking financial companies (NBFCs), tightening the leash on how customer information is stored, processed and shared.

The draft framework, released on Thursday, is aimed at ensuring that financial entities maintain a robust data architecture to prevent breaches and misuse. The central bank has invited public comments on the proposal until August 15, 2026.

What the draft mandates

Under the proposed rules, every bank and NBFC will have to appoint a Chief Data Officer (CDO) who will be responsible for overseeing the institution's data management practices. The CDO must report directly to the board or a board-level committee.

The board itself will need to approve a comprehensive data policy that covers classification, storage, retention, archiving and destruction of data. The policy must also define access control mechanisms and spell out the procedure for handling data breaches.

Entities will be required to maintain a data inventory that classifies information into categories such as customer personal data, transaction data, and operational data. Each category will have specific handling protocols.

Local storage and audit requirements

A key provision in the draft is the mandatory localisation of customer data. All personal and transaction data of Indian residents must be stored on servers physically located within the country. Offshoring or replication abroad will not be permitted without explicit RBI approval.

Banks and NBFCs will also have to conduct annual system audits by an independent auditor empanelled by the central bank. The audit report must be submitted to the RBI within three months of the end of the financial year.

Non-compliance could attract penalties, including restrictions on launching new digital products or services, the draft says.

Impact on the financial sector

The proposed rules come at a time when digital lending and online banking have surged across India. The RBI has been increasingly concerned about data leaks and the use of customer information by third-party vendors without explicit consent.

Industry insiders say the new regime will increase compliance costs for smaller NBFCs and fintechs that rely on cloud services hosted abroad. Larger banks, many of which already comply with similar norms under the IT Act, are expected to have an easier transition.

The central bank has not specified a timeline for implementation after the consultation period ends.

All regulated entities must now review their existing data governance frameworks and identify gaps. The RBI's final guidelines are expected to be released by October 2026, giving the industry roughly a year to fully comply.

Verify this story
Reported by News Arena India. This article was written with AI assistance from publicly available reporting โ€” always cross-check important details with the original coverage.
This content is AI-assisted and published for information only. TIVRA News links every story to its original source above โ€” please verify dates, figures and statements there. See our Disclaimer and Editorial Policy.