Now onboarding a founding cohort of NBFCs — pilot FI volume on us for the first month.
Ambrezo
Blog·11 July 2026·9 min read

DPDP Act compliance for field verification: what lenders and FI agencies must do

AM
Akhil Mishra
Founder, Ambrezo · Chartered Accountant

The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's first comprehensive personal-data law, and field investigation sits squarely inside it: an FI case file contains an applicant's name, address, phone number, photographs of their home and workplace, GPS coordinates and neighbours' statements. Every one of those is personal data being processed by a lender and its verification agencies.

This post maps the DPDP Act's obligations onto a field-verification programme: who is the fiduciary, what consent must look like, how long evidence can be kept, and what changes lenders should be demanding from their FI agencies. It is a practical operations guide, not legal advice — involve counsel for your specific implementation.

Who is the data fiduciary in a field investigation — the lender or the agency?

The lender is the data fiduciary, because the lender decides the purpose (verify this applicant before disbursal) and the means (order an RV and BV through empanelled agencies). The verification agency — and any marketplace or platform in between — processes that data on the lender's behalf, which makes them data processors under Section 2(k) of the Act.

What does valid consent look like for a field visit?

Valid consent under the DPDP Act must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the specified purpose — and the fiduciary must be able to prove it was obtained. For FI programmes the operational question is evidence: when the Data Protection Board or an auditor asks how this applicant consented to a home visit and photography, what record do you produce?

How long can FI photographs and reports be retained?

Only as long as the purpose requires or another law requires retention — after that, the DPDP Act expects erasure. FI evidence has a genuine business purpose during underwriting, and loan-file records have their own statutory retention under RBI and other regulations once a loan is booked. The gap most programmes miss is everything else: evidence for rejected applications, duplicate captures, and photographs sitting in field officers' phone galleries and WhatsApp threads.

What security safeguards does the Act expect for field-collected data?

The Act requires reasonable security safeguards to prevent personal-data breaches, and it attaches its largest penalty — up to ₹250 crore per instance — to failing this duty. For field verification, the highest-risk surface is the last mile: data captured on phones, in transit, by contractors.

When do the DPDP obligations actually bite?

The Act was passed in August 2023, and the DPDP Rules — which operationalise consent notices, breach reporting and retention specifics — were notified in November 2025 with a phased implementation timeline giving organisations a transition window for the substantive obligations. The direction is settled; only the deadlines were ever in question. Lenders retooling their FI programmes now are building against requirements that are already law, and agency contracts signed today should assume full enforcement within the transition window.

Frequently asked questions

Does the DPDP Act apply to verification agencies directly?

Yes — verification agencies are data processors under the Act and must process personal data only under a valid contract with the lender (the data fiduciary). The heaviest duties and the liability sit with the lender, which is why lenders now audit agency data-handling, not just report quality.

Is a consent clause in the loan application enough for a field visit?

It is weak evidence on its own. The Act requires consent to be specific, informed and demonstrable for the stated purpose — a per-case, logged attestation that names physical verification and photography is a much stronger artifact than a general clause on page 30 of an application form.

Can field officers use WhatsApp to send verification photos?

It is a practice to eliminate. Photos sent over personal messaging create uncontrolled copies on personal devices and servers, defeating both the security-safeguard and erasure obligations. Evidence should be captured and transmitted inside a controlled application with encryption and access control.

What are the penalties for getting this wrong?

The DPDP Act's schedule provides penalties up to ₹250 crore per instance for failing to maintain reasonable security safeguards, and up to ₹200 crore for breach-notification failures, with other breaches attracting lower slabs. The Data Protection Board weighs the breach's nature, gravity and duration when setting the amount.

Run field investigations as a system of record

Auto-routed cases, geo-stamped evidence, hash-chained audit trails and DPDP-first data handling — live at ambrezo.com.