DPDP Act Compliance Checklist for NBFCs Using AI Calling
DPDP Act compliance for an NBFC using AI calling means treating every borrower as a Data Principal and your NBFC as a Data Fiduciary — collecting phone numbers and call data only with clear consent and notice, using them strictly for the stated purpose, honouring rights to erasure, and reporting breaches to the Data Protection Board.
This is an explainer, not legal advice. For obligations specific to your NBFC, consult a qualified advisor and the official text.
The Digital Personal Data Protection Act, 2023 (DPDP Act) was enacted by Parliament on 11 August 2023, and the Digital Personal Data Protection Rules, 2025 (DPDP Rules) were notified on 14 November 2025, marking full operationalisation of the framework (PIB, 2025). For a Non-Banking Financial Company (NBFC) running outbound AI voice calls for reminders, collections and onboarding, every one of those calls processes personal data — so the Act applies directly.
This is a practical, borrower-first checklist. It maps each DPDP concept to what your AI calling stack actually needs to do.
Who Is Who Under the DPDP Act?
The Act defines two roles that matter for every AI call your NBFC places (MeitY).
- Data Principal — the individual the data relates to. For an NBFC, that is your borrower, co-borrower or guarantor.
- Data Fiduciary — the entity that decides the purpose and means of processing. That is your NBFC. If you use a voice AI vendor, they typically act as a data processor working on your instructions.
Why does this distinction matter for AI calling? Because the Data Fiduciary carries the legal obligations — you cannot outsource accountability to a technology vendor. The NBFC remains answerable for consent, security and breach reporting.
What Are the Seven Principles You Must Design For?
The Act is built on seven principles (PIB salient features, 2023): consented, lawful and transparent use; purpose limitation; data minimisation; data accuracy; storage limitation; reasonable security safeguards; and accountability. Purpose limitation is the one AI-calling teams underestimate — a number collected for loan servicing cannot be quietly reused to cross-sell a new product.
The NBFC AI Calling Compliance Checklist
Use this table as your working checklist. Each row ties a DPDP requirement to a concrete control in your AI calling workflow.
DPDP requirement | What your AI calling setup must do |
|---|---|
Notice + consent | Give a clear notice stating what data is collected and why, then obtain consent before processing (unless a legitimate use applies) |
Purpose limitation | Use borrower numbers only for the stated purpose — servicing, reminders, collections — not for unrelated marketing |
Data minimisation | Capture only the fields the call actually needs; avoid recording surplus personal data |
Right to withdraw | Make consent as easy to withdraw as to give; stop calls when consent is withdrawn |
Storage limitation | Erase call recordings and personal data once the purpose is met and no legal retention applies |
Security safeguards | Encrypt recordings and transcripts; restrict access; log who hears what |
Breach reporting | Notify the Data Protection Board and every affected Data Principal in the prescribed manner |
Grievance officer | Publish contact details of a designated officer to handle borrower queries |
How Should NBFCs Handle Consent and Notice for Calls?
The Act permits processing of personal data for a lawful purpose after obtaining consent, and requires a notice before seeking consent describing the data collected and the purpose (PIB, 2023). Consent can be withdrawn at any time. The DPDP Rules add that Data Fiduciaries must issue standalone, clear and simple consent notices in plain language.
The Act also recognises legitimate uses where consent may not be separately required — such as data an individual has voluntarily provided for a specified purpose. Where a borrower gave their number for loan servicing, servicing calls may fall within that specified purpose — but refer to the official text for how this applies to your exact use case.
Consent Managers — entities that help individuals manage permissions — must be Indian companies under the DPDP Rules. Building consent capture into onboarding is far cheaper than retrofitting it. Our guide on voice AI use cases for NBFC collections in India shows where consent checkpoints fit naturally.
What Rights Must You Be Ready to Honour?
Every borrower, as a Data Principal, has the right to access information about their data, seek correction and erasure, obtain grievance redressal, and nominate another person to exercise these rights. Under the DPDP Rules, Data Fiduciaries must respond to such requests within a maximum of 90 days (PIB, 2025). Your AI calling platform should let you locate and delete a specific borrower's recordings on request — not just at the account level.
What Are the Penalties an NBFC Should Plan Around?
Penalties are imposed by the Data Protection Board of India after an inquiry, and the Schedule to the Act specifies significant amounts. Two are especially relevant for a data-heavy NBFC.
Default | Penalty (up to) |
|---|---|
Failure to take reasonable security safeguards to prevent a data breach | ₹250 crore |
Non-fulfilment of obligations relating to children's data | ₹200 crore |
Breach of a Data Principal's duties (e.g. false or frivolous complaint) | ₹10,000 |
These figures come from the Schedule to the Act (PRS Legislative Research summary). A ₹250 crore exposure for a security lapse reframes the business case for encrypting every call recording. The DPDP Rules provide an 18-month phased compliance timeline, so NBFCs have a defined window to align systems — not an excuse to delay.
How AI Helps NBFCs Stay DPDP-Ready
YuVoice, YuVerse's voice AI platform, is built for regulated BFSI outreach. It can read a standardised, template-controlled notice at the start of a call, capture and timestamp consent, and automatically suppress numbers where consent is withdrawn. Recordings and transcripts are stored with access controls, and calls stay tied to a single stated purpose — supporting purpose limitation and data minimisation. Because every interaction is logged, responding to a borrower's access or erasure request becomes a search, not a scramble. That auditability is exactly what a Data Fiduciary needs to demonstrate accountability. See our checklist for ensuring voice AI compliance with RBI guidelines for the wider regulatory picture.
FAQ
Does the DPDP Act apply to AI voice calls made by NBFCs? Yes. AI calls process personal data — phone numbers, borrower details, voice recordings. The NBFC is the Data Fiduciary and must meet consent, notice, security and breach-reporting obligations for that processing.
Are the DPDP Rules in force yet? The DPDP Rules, 2025 were notified on 14 November 2025, operationalising the Act. They provide an 18-month phased compliance timeline for organisations to align their systems.
Can an NBFC reuse borrower numbers collected for a loan to cross-sell products? The Act's purpose-limitation principle requires that data be used only for the purpose specified when consent was obtained. Reusing servicing data for unrelated marketing generally needs fresh consent — refer to the official text for your scenario.
What happens if a borrower withdraws consent mid-way? Consent can be withdrawn at any time. Once withdrawn, the NBFC must stop the relevant processing and erase personal data where retention is no longer necessary for a legal purpose.
Who enforces the DPDP Act and what are the penalties? The Data Protection Board of India inquires into breaches and imposes financial penalties. The Schedule specifies amounts up to ₹250 crore for failing to take reasonable security safeguards against a data breach.
Does using a third-party voice AI vendor transfer the compliance burden? No. The Data Fiduciary — the NBFC — remains accountable. A vendor acting as a data processor works on your instructions, so contractual safeguards and oversight are essential.
Conclusion
The DPDP Act does not ban AI calling — it demands that NBFCs run it responsibly, with consent, purpose discipline and strong security. Treat this checklist as a design brief: bake notice and consent into onboarding, minimise what you capture, secure every recording, and be ready to honour erasure within 90 days. Do that, and AI calling becomes a compliance asset rather than a liability. For a broader view, see how AI ensures fair practice compliance in collections calling.
Build DPDP-ready AI calling into your NBFC's collections and servicing. Talk to the YuVerse team
References
- Government notifies DPDP Rules to empower citizens and protect privacy (PIB, 14 Nov 2025) — https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014®=3&lang=2
- Digital Personal Data Protection Act, 2023 (MeitY) — https://www.meity.gov.in/content/digital-personal-data-protection-act-2023
- Salient Features of the Digital Personal Data Protection Bill, 2023 (PIB, 9 Aug 2023) — https://www.pib.gov.in/PressReleaseIframePage.aspx?PRID=1947264
- The Digital Personal Data Protection Bill, 2023 — Penalties summary (PRS Legislative Research) — https://prsindia.org/billtrack/digital-personal-data-protection-bill-2023