Back to All Blogs

Consent-Based Data Sharing: A Complete Guide for NBFCs

Shivam Jadon's avatar
Shivam Jadon
Risk & Compliance

Introduction

Consent is not merely a legal checkbox in India’s evolving financial data framework; it is the architectural foundation of the Account Aggregator ecosystem and the central requirement of the DPDP Act 2023. For NBFCs, building consent-based data practices is both a regulatory necessity and a competitive differentiator.

This guide covers what consent-based data sharing means in practice for NBFCs: how to design consent flows that are compliant and conversion-optimized, what data governance obligations consent management triggers, and how to operationalize consent across the loan lifecycle. To understand the broader system, here’s what an account aggregator is in India.

What Consent-Based Data Sharing Means for NBFCs

In the AA context, consent-based data sharing ensures every data access follows specific, informed, voluntary, and revocable consent. Borrowers know what data lenders access, why they access it, and for how long. They can also revoke consent at any time.

This marks a fundamental shift from historical NBFC practices, where lenders often collected data implicitly. They stored bank statements indefinitely and sometimes shared them without explicit disclosure.

The DPDP Act 2023 formalizes consent in law for processing personal and financial data. Entities must process data only for the agreed purpose and duration, and allow withdrawal anytime.

To understand how this operates in practice, refer to the account aggregator consent flow.

Role of NBFCs in the AA Ecosystem/

NBFCs primarily act as Financial Information Users (FIUs) in the AA ecosystem. They request financial data from Financial Information Providers (FIPs) through the Account Aggregator to assess borrowers and make lending decisions.

To understand how NBFCs function within this system, refer to FIP vs FIU roles in the account aggregator ecosystem.

Designing a Compliant Consent Flow for NBFC Lending

A compliant consent flow for NBFC lending must meet several design requirements simultaneously:

Purpose specificity: The consent screen must state the exact purpose, “to assess your income and obligations for a personal loan of Rs. X,” not a vague “for financial assessment.”

Data minimization: Request only the data types and date ranges genuinely needed. A 12-month savings account transaction history is sufficient for most personal loan underwriting. Requesting five years of data across all account types for a small-ticket loan is not proportionate.

Consent separation: Lenders must obtain separate consent for each purpose, such as underwriting and monitoring. They cannot use bundled “I agree” consents for multiple purposes under DPDP or RBI rules.

Revocation mechanism: Lenders must clearly show borrowers how to revoke consent. They can provide an AA app link or a direct revocation option in their interface.

Plain language: Consent screens must be understandable to a person without legal or financial training. Legal jargon in consent screens is a compliance risk.

These requirements align with NBFC regulatory obligations and lending rules and also with the Reserve Bank of India Digital Lending Guidelines.

Consent in the Loan Lifecycle

Consent applies across the entire loan lifecycle:

  • Origination consent: For underwriting and evaluation
  • Monitoring consent: For ongoing borrower assessment
  • Renewal consent: When consent expires
  • Cross-sell consent: For additional product offers
  • Post-delinquency consent: For restructuring analysis

NBFCs must treat each stage independently, ensuring proper consent capture and management.

Data Usage in Lending

AA-based consent enables structured financial data usage in lending. NBFCs use this data for credit decisions and borrower evaluation. This is exactly what loan underwriting is with account aggregator data.

The insights derived include income verification, obligation mapping, cash flow analysis, and behavioral signals, all of which improve decision accuracy and reduce reliance on self-declared or PDF-based inputs.

Compliance and Regulatory Requirements

Consent-based data sharing introduces strict data privacy and regulatory obligations. NBFCs must ensure purpose limitation, data minimization, storage controls, and deletion workflows.

For a deeper understanding, refer to the DPDP Act and the account aggregator.

NBFCs must also:

  • Maintain data inventory
  • Implement access controls
  • Enable user rights (access, correction, erasure)
  • Ensure breach reporting compliance

Data Governance Obligations Triggered by Consent

Each consent event triggers a set of data governance obligations for the NBFC:

Data inventory update: Record the data collected, its purpose, consent expiry, and deletion schedule in the NBFC’s data inventory.

Storage controls: Teams must store AA data with strict access controls. They should restrict access only to employees with a legitimate business need.

Retention counter: The retention period specified in the consent artefact starts from data collection. Implement an automated counter that triggers deletion at expiry.

Rights fulfillment readiness: The borrower may, under the DPDP Act, request access to, correction of, or erasure of their data. The NBFC must be able to fulfill these requests within the Act’s prescribed timelines.

Breach reporting: If a security incident involves AA data, NBFCs must notify the Data Protection Board. Additionally, they must comply with existing RBI incident reporting requirements.

Key Takeaways

  • Consent is not a box to tick; it is the legal and operational foundation of every AA-based data interaction. Each consent must be purpose-specific, time-bound, and revocable.
  • Separate consents are required for each purpose: underwriting, monitoring, cross-sell, and restructuring cannot share a single bundled consent.
  • Consent in the loan lifecycle extends beyond origination; monitoring consents, renewal consents, and cross-sell consents each require distinct design and management.
  • Every consent event triggers data governance obligations: inventory update, storage controls, retention counter, and rights fulfillment readiness.
  • NBFC compliance with both the AA framework and the DPDP Act requires consent management to be an operationalized process, not an ad hoc practice.

Frequently Asked Questions

Q1: Can an NBFC use a single consent for both loan assessment and credit monitoring?

Only if both purposes are clearly disclosed in the same consent screen, and the borrower gives separate affirmative consent for each purpose. Many AA implementations require separate consent events for different purposes to meet both RBI and DPDP requirements.

Q2: What happens when a borrower revokes consent mid-loan?

Revocation stops future data pulls. The NBFC retains data already collected for the duration specified in the original consent artefact. The loan relationship continues; consent revocation does not affect the loan contract. The NBFC simply cannot request new data pulls.

Q3: Do NBFCs need to inform borrowers about the DPDP Act in the consent flow?

The consent flow should be compliant with DPDP requirements, specific, informed, and voluntary but does not need to explicitly name the Act. The privacy notice (required under DPDP) should describe the institution’s data processing practices in accordance with the Act.

Q4: What format should consent records be retained in?

The AA consent artefact is a cryptographically signed JSON object that serves as the consent record. Retain the artefact in its original form; do not convert to other formats. Store it alongside metadata: the date collected, associated loan application ID, and the date it was deleted.

Q5: Can consent be obtained via WhatsApp for NBFC customers in rural areas?

WhatsApp-based consent falls outside the AA consent framework. Borrowers need a smartphone and internet for digital AA consent. For rural users, officers can assist on shared devices but must document the process carefully.

Conclusion

Consent-based data sharing is a business practice, not just a technical feature. NBFCs that build strong consent management capabilities will stay ahead in tightening data governance environments.

The investment in getting consent right pays dividends in multiple directions: regulatory alignment, borrower trust, data quality, and operational efficiency. A closer look at account aggregator ROI for lenders highlights the full business impact.

For NBFCs evaluating AA adoption, the consent framework is not the hardest part; it is the most important part.

Home » Data sharing consent

Shivam Jadon's avatar

Shivam Jadon

Discover more from FinEye

Subscribe now to keep reading and get access to the full archive.

Continue reading