RBI Governor Sanjay Malhotra has warned India’s fintech industry that customer data should be treated as a fiduciary responsibility, not merely as an asset companies can exploit for commercial growth.
Speaking at the Global Fintech Fest 2026, Malhotra said financial technology companies must collect and use information with clear customer consent and for a defined purpose. He placed trust at the centre of India’s rapidly expanding digital financial ecosystem.
The message matters because fintech companies can hold some of the most sensitive information a person generates.
A financial app may know a customer’s income, spending patterns, loans, investments, repayments and even where money is being transferred. How that information is collected, shared and analysed can directly affect privacy as well as access to financial services.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
RBI wants fintech growth without treating data as free fuel
Malhotra urged fintech companies to build business models around responsible data use rather than searching for regulatory gaps.
He pointed to India’s Account Aggregator framework as an example of how financial information can be shared without taking control away from the customer.
Under RBI rules, Account Aggregators can retrieve and transfer a person’s financial information only after explicit consent.
That consent must identify what information is being requested, why it is required and who will receive it. Customers must also be able to revoke permission.
Importantly, an Account Aggregator is not supposed to treat the information as its own property.
RBI directions state that customer financial information accessed through the system should not be used beyond the purpose authorised by the customer. Account Aggregators are also prohibited from requesting banking passwords, PINs or private authentication keys.
For ordinary users, that creates a simple principle: giving a financial company access to data for one purpose should not automatically become permission to use it for everything else.
What does “fiduciary responsibility” actually mean?
A fiduciary is someone entrusted with something valuable who is expected to act with a high degree of responsibility towards the person who placed that trust in them.
Applied to data, the idea is straightforward.
If a bank or fintech receives your financial information because you need a loan, it should not behave as though that information became unrestricted commercial property the moment you clicked “agree”.
The institution should know why it is collecting the information, protect it from misuse and limit its use to legitimate purposes.
This direction is not entirely new for the RBI.
Its existing Account Aggregator framework already relies heavily on consent and purpose limitation. RBI material also says customer information cannot be transferred through the framework without explicit permission and should be securely transmitted between authorised entities.
Earlier RBI work on digital lending has similarly identified notice, consent, purpose limitation, data minimisation, use limitation and retention limits as core principles of responsible data governance.
RBI has already begun tightening data governance expectations
Malhotra’s warning also comes just weeks after the RBI moved towards a broader framework for how regulated financial institutions manage data.
In July 2026, the central bank issued draft “Guidance on Regulatory Expectations for Data Governance” covering regulated entities.
The timing is significant.
Banks and fintech companies increasingly use artificial intelligence, alternative credit scoring and automated systems to assess customers. That can allow lenders to serve people who previously lacked a conventional credit history.
But the same systems can depend on enormous amounts of personal and financial data.
Malhotra therefore linked innovation with responsibility rather than presenting the two as competing goals.
He also urged fintech companies to strengthen cybersecurity, operational resilience and business continuity. In other words, protecting customer information is not only about obtaining permission to use it; companies must also be able to keep that information secure when systems fail or attackers strike.
Fintechs told not to build businesses around regulatory loopholes
The RBI Governor also cautioned firms against designing products primarily around gaps in regulation.
Instead, he encouraged companies developing new financial models to use the RBI’s regulatory sandbox, which allows innovative products to be tested under controlled conditions while regulators examine potential risks.
Malhotra simultaneously pushed the industry to expand access to finance for groups that remain underserved, including informal-sector workers, MSMEs, women entrepreneurs and rural customers.
That creates the larger policy challenge.
India wants fintech companies to use technology and data to bring millions more people into formal finance. But doing that sustainably requires customers to believe that handing over their financial information will not expose them to uncontrolled profiling, unnecessary sharing or weak security.
What this means for you: Before allowing any finance app to access bank or financial information, check what data it wants and why. Where consent controls are available, review and revoke permissions you no longer need rather than leaving permanent access open.
The420 Insight: The RBI’s message signals a shift from asking whether financial firms can collect data to asking whether they should use it in a particular way. As AI-driven lending and personalised finance expand, consent, purpose and accountability are likely to become as important to fintech regulation as capital and liquidity.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics