DPDP Act compliance for field verification: what lenders and FI agencies must do
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive personal-data law, and field investigation sits squarely inside it: an FI case file contains an applicant's name, address, phone number, photographs of their home and workplace, GPS coordinates and neighbours' statements. Every one of those is personal data being processed by a lender and its verification agencies.
This post maps the DPDP Act's obligations onto a field-verification programme: who is the fiduciary, what consent must look like, how long evidence can be kept, and what changes lenders should be demanding from their FI agencies. It is a practical operations guide, not legal advice — involve counsel for your specific implementation.
Who is the data fiduciary in a field investigation — the lender or the agency?
The lender is the data fiduciary, because the lender decides the purpose (verify this applicant before disbursal) and the means (order an RV and BV through empanelled agencies). The verification agency — and any marketplace or platform in between — processes that data on the lender's behalf, which makes them data processors under Section 2(k) of the Act.
- The fiduciary carries the compliance duties: valid consent or another lawful ground, notice, accuracy, security safeguards, erasure, and answering data-principal requests.
- Processors act only under a valid contract with the fiduciary — the Act requires the fiduciary to engage processors contractually, so empanelment agreements need explicit data-processing clauses.
- Liability does not outsource: if an agency's field officer leaks applicant photographs from a personal phone, the lender answers to the Data Protection Board for the safeguard failure.
- Practical consequence: lenders should be auditing how agencies store evidence, who can access it, and on what devices it is captured — not just how fast reports arrive.
What does valid consent look like for a field visit?
Valid consent under the DPDP Act must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the specified purpose — and the fiduciary must be able to prove it was obtained. For FI programmes the operational question is evidence: when the Data Protection Board or an auditor asks how this applicant consented to a home visit and photography, what record do you produce?
- Capture consent per case, not per relationship: a purpose-bound attestation recorded at FI creation (who attested, when, through which channel) is far stronger evidence than a general clause signed at application.
- Give real notice: the applicant should know a physical visit and photographs are part of verification. Notice must be available in English or any of the languages in the Eighth Schedule of the Constitution.
- Store the consent artifact with the case: consent recorded in a system nobody can query is consent you cannot demonstrate.
- Honour withdrawal: if an applicant withdraws consent mid-process, the Act expects processing to stop with effect from the withdrawal — your workflow needs a way to halt a case.
How long can FI photographs and reports be retained?
Only as long as the purpose requires or another law requires retention — after that, the DPDP Act expects erasure. FI evidence has a genuine business purpose during underwriting, and loan-file records have their own statutory retention under RBI and other regulations once a loan is booked. The gap most programmes miss is everything else: evidence for rejected applications, duplicate captures, and photographs sitting in field officers' phone galleries and WhatsApp threads.
- Define a retention window per data class: delivered reports attached to booked loans follow loan-file retention; evidence for rejected or abandoned applications should have a much shorter clock.
- Automate the purge: a retention policy without a deletion mechanism is a document, not a control. Storage should delete evidence past its window without a human remembering to.
- Kill the side channels: evidence captured through personal WhatsApp is a retention and security violation waiting to be found. Capture should happen inside a controlled app that does not leave copies on the device.
- Remember processors: erasure obligations extend to data your agencies hold. Contracts should require deletion downstream when the fiduciary's window closes.
What security safeguards does the Act expect for field-collected data?
The Act requires reasonable security safeguards to prevent personal-data breaches, and it attaches its largest penalty — up to ₹250 crore per instance — to failing this duty. For field verification, the highest-risk surface is the last mile: data captured on phones, in transit, by contractors.
- Encrypted capture and transport: evidence should move from the officer's device to controlled storage over encrypted channels, not through consumer messaging apps.
- Access control by role and party: an agency should see its own cases only; a lender should see its own applicants only; a field officer should see assigned work only.
- Tamper-evidence and audit trails: an immutable log of who touched a case, when, and what changed is both a security control and your defence exhibit.
- Breach readiness: personal-data breaches must be reported to the Data Protection Board and affected individuals — which presupposes you can detect a breach and reconstruct its scope from logs.
When do the DPDP obligations actually bite?
The Act was passed in August 2023, and the DPDP Rules — which operationalise consent notices, breach reporting and retention specifics — were notified in November 2025 with a phased implementation timeline giving organisations a transition window for the substantive obligations. The direction is settled; only the deadlines were ever in question. Lenders retooling their FI programmes now are building against requirements that are already law, and agency contracts signed today should assume full enforcement within the transition window.
Frequently asked questions
Does the DPDP Act apply to verification agencies directly?
Yes — verification agencies are data processors under the Act and must process personal data only under a valid contract with the lender (the data fiduciary). The heaviest duties and the liability sit with the lender, which is why lenders now audit agency data-handling, not just report quality.
Is a consent clause in the loan application enough for a field visit?
It is weak evidence on its own. The Act requires consent to be specific, informed and demonstrable for the stated purpose — a per-case, logged attestation that names physical verification and photography is a much stronger artifact than a general clause on page 30 of an application form.
Can field officers use WhatsApp to send verification photos?
It is a practice to eliminate. Photos sent over personal messaging create uncontrolled copies on personal devices and servers, defeating both the security-safeguard and erasure obligations. Evidence should be captured and transmitted inside a controlled application with encryption and access control.
What are the penalties for getting this wrong?
The DPDP Act's schedule provides penalties up to ₹250 crore per instance for failing to maintain reasonable security safeguards, and up to ₹200 crore for breach-notification failures, with other breaches attracting lower slabs. The Data Protection Board weighs the breach's nature, gravity and duration when setting the amount.
Auto-routed cases, geo-stamped evidence, hash-chained audit trails and DPDP-first data handling — live at ambrezo.com.