RBI's Data Governance Framework for Banks and NBFCs (Indian Economy)
RBI's Data Governance Framework for Banks and NBFCs (Indian Economy)
Why In News:
The Reserve Bank of India (RBI) released draft norms on a Data Governance Framework (DGF) for regulated entities such as commercial banks and NBFCs (Non-Banking Financial Companies).
Source: The Hindu, Page 13, 16 July 2026, 'RBI issues data governance guidance framework for banks'.
Key Provisions of the Draft DGF
The Board of a bank or NBFC must oversee the framework and periodically review related reports and metrics.
Each regulated entity should set up a Board-level Data Governance Committee, or assign the task to an existing board committee, to oversee implementation.
The framework must comply with the Digital Personal Data Protection (DPDP) Act, 2023 and the DPDP Rules, 2025.
Related Regulatory Landmarks
The Digital Personal Data Protection (DPDP) Act, 2023 is India’s first comprehensive law on data protection. It provides a legal framework to handle digital personal data, aiming to protect individual privacy while allowing lawful data use.
Applicability: It covers digital personal data processed within India-whether originally digital or later digitized-and also applies to data processed outside India if related to offering goods or services in India.
It excludes data used for personal purposes or data made publicly available by the individual or under legal obligation.
Consent: Personal data can be processed only with the consent of the Data Principal for a lawful purpose, and such consent can be withdrawn at any time.
For children and persons with disabilities, consent must be given by a parent or legal guardian.
The Data Protection Board of India functions as the grievance redressal body under the DPDP Act.
The RBI had earlier mandated (2018) that payment system data be stored only in India, an early data-localisation measure for the financial sector.