DPDP Compliance for NBFCs - What Rule 6 Actually Requires (And What's Due by May 2027)
BySaloni Seth
TL;DR: The Digital Personal Data Protection Rules, 2025 were notified by MeitY on 13 November 2025. Rules 3, 5-16, 22 and 23, including Rule 6 on reasonable security safeguards, come into force 18 months later, on 13 May 2027. For NBFCs, this means every system holding KYC documents, Aadhaar, PAN, bank statements and loan files needs an answer to three questions: what personal data is inside these documents, who can access it, and is sensitive data masked. Most NBFCs can answer "where is it stored." Very few can currently answer all three.
What is DPDP compliance for an NBFC, in practical terms?
DPDP compliance is not primarily a storage question. It is a data governance question layered on top of storage.
An NBFC's KYC records, Aadhaar copies, PAN details, bank statements, income proofs and loan agreements sit across DMS platforms, shared drives, branch systems and legacy archives. DPDP compliance asks the institution to be able to answer, for that entire document estate:
- What personal data is actually inside these documents?
- What is the specific purpose for processing it?
- Who has access, and is that access logged and reviewed?
- Is sensitive data, Aadhaar in particular, masked, encrypted or tokenised?
- Is consent for each use traceable back to a record?
- Can any document be retrieved quickly if a regulator, auditor or customer asks?
If the honest answer to more than one of these is "we're not sure," the gap is not a technology gap; it's a document governance gap.
What does DPDP Rule 3 specifically require?
Rule 3 requires an itemised description of the personal data being processed and the purpose of processing. In practice, this means an NBFC needs a working inventory of personal data categories (Aadhaar, PAN, income data, bank statement data, contact details, etc.) mapped to the specific lending processes that use them: onboarding, underwriting, servicing, collections, audit.
Most document repositories were not built with this inventory in mind. Documents were filed by loan file or by branch, not by the personal data categories inside them. That's the first gap Rule 3 exposes.
What does DPDP Rule 6 (reasonable security safeguards) require?
Rule 6 requires appropriate measures to control access to computer resources, together with logs, monitoring and review of access to personal data. It also specifically names encryption, obfuscation, masking and virtual tokens among the accepted reasonable security safeguards.
For an NBFC, this translates into concrete operational questions:
- Is there role-based access control across every system holding customer documents, or only some?
- Is access to Aadhaar and PAN data logged, and is that log actually reviewed?
- Is Aadhaar masked wherever it appears, including in historical, legacy repositories, not just new intake?
- Are these safeguards consistent across branches, or does each branch effectively run its own access model?
Rule 6 is the provision most directly relevant to document infrastructure, because it is the one that turns "we store documents securely" into a testable, auditable claim.
What is the actual deadline for DPDP compliance in India?
The DPDP Rules, 2025 were notified by the Government of India (MeitY) on 13 November 2025. The Rules themselves state that Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication.
Eighteen months from 13 November 2025 places that group of provisions, including Rule 6, into force on 13 May 2027.
That is the operative date to work backward from. Eighteen months sounds distant. For an NBFC with document infrastructure spread across branches, legacy archives and multiple systems, it is a realistic but not generous runway to complete a personal data inventory, close access-control gaps, and roll out masking across both new and historical documents.
(Source: Digital Personal Data Protection Rules, 2025, MeitY. Worth a quick re-verification against the official MeitY DPDP Rules page if you're reading this more than a few months after publication, since implementation guidance can be refined.)
Is unmasked Aadhaar sitting somewhere in your legacy archive a real risk?
Yes, and it's one of the more common gaps found in NBFC document estates. Aadhaar numbers are frequently present, unmasked, in:
- Scanned KYC packets from years of onboarding
- Bank statement PDFs where Aadhaar was referenced for identity linking
- Loan agreement scans stored in shared drives or branch systems
- Old email attachments that were never formally filed
Rule 6 names masking explicitly as a safeguard. An inventory that only covers new documents and leaves legacy repositories unmasked is not a complete answer to Rule 6. It is a partial one, and the gap is exactly where an auditor or a data-breach investigation would look first.
Is document storage the same thing as document governance?
No, and this is the distinction most NBFCs are still working through.
Storage answers "where is the file." Governance answers "what's inside it, who can see it, is it protected, and can I prove that." An NBFC can have excellent storage: fast, redundant, well-organised, and still have weak governance, because governance depends on metadata, access control, masking and audit trails layered on top of storage, not on storage capacity itself.
This is also why RBI's Master Direction on KYC requires Regulated Entities to preserve account information so it can be retrieved easily and quickly whenever required, and why RBI's IT Governance, Risk, Controls and Assurance Directions apply IT governance, risk and business-continuity expectations directly to NBFCs. DPDP and RBI's existing expectations are converging on the same practical requirement: documents need to be governed, not just stored.
A quick self-check
Answer honestly. This is diagnostic, not a sales pitch:
- Can you produce an itemised list of what personal data categories exist in your document estate, mapped to purpose?
- Is access to documents containing Aadhaar or PAN logged and reviewed everywhere, not just in your primary DMS?
- Is Aadhaar masked in your legacy archives, not just in new intake?
- Could you retrieve a specific customer's full document history within minutes if asked?
- Do you have a single, current view of consent for how each document category can be used?
If more than one answer is "no" or "not sure," document governance, not storage capacity, is the priority.
What this means operationally?
The consequence of these gaps is rarely a single dramatic failure. It's a slow accumulation of exposure: growing document volumes, more branches generating unmasked scans, more auditors asking for retrieval proof, and a compliance team whose workload grows in direct proportion to loan book growth rather than staying flat. That's compliance operations that don't scale, and it compounds every quarter you wait.
Where HabileLabs fits?
HabileLabs works with regulated lenders through a staged document lifecycle: from digitisation, through storage and retrieval, into governance and intelligence. Rule 6 alignment sits squarely in the governance stage: access control, audit trails, and masking applied consistently across both live and legacy repositories, designed to support DPDP and RBI's existing audit-readiness expectations.
This isn't a claim that any technology "guarantees" compliance. No vendor can make that claim honestly. It's about building the document infrastructure that makes your own compliance posture provable when it's tested.
As a reference point: HabileLabs has worked with 20+ NBFCs to ensure end-to-end document management lifecycle.
Next step: A Document Infrastructure Assessment is a practical way to see exactly where your document estate stands against Rule 3 and Rule 6 today: what's governed, what's exposed, and what the realistic path to 13 May 2027 looks like for your specific systems.
Additional Details
Continue the series:
-
Part 2: Document Management System for NBFCs: Shared Drives vs Legacy DMS vs Cloud-Native DMS
-
Part 3: Document Intelligence for NBFCs: 2026 Trends and Practical Hacks

