Consent is not merely a legal checkbox in India’s evolving financial data framework; it is the architectural foundation of the Account Aggregator ecosystem and the central requirement of the DPDP Act 2023. For NBFCs, building consent-based data practices is both a regulatory necessity and a competitive differentiator.
This guide covers what consent-based data sharing means in practice for NBFCs: how to design consent flows that are compliant and conversion-optimized, what data governance obligations consent management triggers, and how to operationalize consent across the loan lifecycle. To understand the broader system, here’s what an account aggregator is in India.
In the AA context, consent-based data sharing ensures every data access follows specific, informed, voluntary, and revocable consent. Borrowers know what data lenders access, why they access it, and for how long. They can also revoke consent at any time.
This marks a fundamental shift from historical NBFC practices, where lenders often collected data implicitly. They stored bank statements indefinitely and sometimes shared them without explicit disclosure.
The DPDP Act 2023 formalizes consent in law for processing personal and financial data. Entities must process data only for the agreed purpose and duration, and allow withdrawal anytime.
To understand how this operates in practice, refer to the account aggregator consent flow.
NBFCs primarily act as Financial Information Users (FIUs) in the AA ecosystem. They request financial data from Financial Information Providers (FIPs) through the Account Aggregator to assess borrowers and make lending decisions.
To understand how NBFCs function within this system, refer to FIP vs FIU roles in the account aggregator ecosystem.
A compliant consent flow for NBFC lending must meet several design requirements simultaneously:
Purpose specificity: The consent screen must state the exact purpose, “to assess your income and obligations for a personal loan of Rs. X,” not a vague “for financial assessment.”
Data minimization: Request only the data types and date ranges genuinely needed. A 12-month savings account transaction history is sufficient for most personal loan underwriting. Requesting five years of data across all account types for a small-ticket loan is not proportionate.
Consent separation: Lenders must obtain separate consent for each purpose, such as underwriting and monitoring. They cannot use bundled “I agree” consents for multiple purposes under DPDP or RBI rules.
Revocation mechanism: Lenders must clearly show borrowers how to revoke consent. They can provide an AA app link or a direct revocation option in their interface.
Plain language: Consent screens must be understandable to a person without legal or financial training. Legal jargon in consent screens is a compliance risk.
These requirements align with NBFC regulatory obligations and lending rules and also with the Reserve Bank of India Digital Lending Guidelines.
Consent applies across the entire loan lifecycle:
NBFCs must treat each stage independently, ensuring proper consent capture and management.
AA-based consent enables structured financial data usage in lending. NBFCs use this data for credit decisions and borrower evaluation. This is exactly what loan underwriting is with account aggregator data.
The insights derived include income verification, obligation mapping, cash flow analysis, and behavioral signals, all of which improve decision accuracy and reduce reliance on self-declared or PDF-based inputs.
Consent-based data sharing introduces strict data privacy and regulatory obligations. NBFCs must ensure purpose limitation, data minimization, storage controls, and deletion workflows.
For a deeper understanding, refer to the DPDP Act and the account aggregator.
NBFCs must also:
Each consent event triggers a set of data governance obligations for the NBFC:
Data inventory update: Record the data collected, its purpose, consent expiry, and deletion schedule in the NBFC’s data inventory.
Storage controls: Teams must store AA data with strict access controls. They should restrict access only to employees with a legitimate business need.
Retention counter: The retention period specified in the consent artefact starts from data collection. Implement an automated counter that triggers deletion at expiry.
Rights fulfillment readiness: The borrower may, under the DPDP Act, request access to, correction of, or erasure of their data. The NBFC must be able to fulfill these requests within the Act’s prescribed timelines.
Breach reporting: If a security incident involves AA data, NBFCs must notify the Data Protection Board. Additionally, they must comply with existing RBI incident reporting requirements.
Only if both purposes are clearly disclosed in the same consent screen, and the borrower gives separate affirmative consent for each purpose. Many AA implementations require separate consent events for different purposes to meet both RBI and DPDP requirements.
Revocation stops future data pulls. The NBFC retains data already collected for the duration specified in the original consent artefact. The loan relationship continues; consent revocation does not affect the loan contract. The NBFC simply cannot request new data pulls.
The consent flow should be compliant with DPDP requirements, specific, informed, and voluntary but does not need to explicitly name the Act. The privacy notice (required under DPDP) should describe the institution’s data processing practices in accordance with the Act.
The AA consent artefact is a cryptographically signed JSON object that serves as the consent record. Retain the artefact in its original form; do not convert to other formats. Store it alongside metadata: the date collected, associated loan application ID, and the date it was deleted.
WhatsApp-based consent falls outside the AA consent framework. Borrowers need a smartphone and internet for digital AA consent. For rural users, officers can assist on shared devices but must document the process carefully.
Consent-based data sharing is a business practice, not just a technical feature. NBFCs that build strong consent management capabilities will stay ahead in tightening data governance environments.
The investment in getting consent right pays dividends in multiple directions: regulatory alignment, borrower trust, data quality, and operational efficiency. A closer look at account aggregator ROI for lenders highlights the full business impact.
For NBFCs evaluating AA adoption, the consent framework is not the hardest part; it is the most important part.