and Overlap Under DPDP Rules Creates
India's data protection framework has taken a curious turn. With the release of the final DPDP Rules in , the country now operates two parallel consent intermediaries—Consent Managers under the , and Non-Banking Financial Company-Account Aggregators under the —both built on the same architectural principle of , yet answerable to different regulators, different compliance standards, and different cost structures. The result, as legal analysts warn, is a textbook case of that could undermine the very purpose of both regimes.
At the heart of the problem lies . The illustration depicts a scenario where a (P) facilitates the transfer of a bank statement directly from a financial information provider (B2) to a requesting (B1), with the (X) giving consent. The function described is identical to that of an : retrieving, consolidating, and securely transferring financial information between institutions on the basis of customer consent. Yet the operates under the DPDP framework, while the remains tethered to the .
The Overlap Problem
The source material frames the dilemma succinctly: "One Function, Two Rulebooks." A
can take the exact seat of an
for financial data without assuming the additional obligations that the RBI imposes on Account Aggregators. The DPDP Rules attach no extra layer of regulatory rigour to a
handling bank statements—no
restriction, no conservative
calculation, no
, no
.
"What happens when there are two guards guarding two entrances but into the same vault?"
the analysis asks.
"The qualifications for both guards are different, one had to prove himself for years to earn the post; the other was waved in on far lighter terms."
The divergence is stark. Under the RBI framework, an must be a barred from any business other than account aggregation. A under the DPDP Rules faces no such limitation—it cannot be a or for the same , but it can operate across multiple sectors simultaneously. The capital requirement of ₹2 crore sounds identical, but the RBI measures "" (net worth minus intangible assets and investments in group companies), while the DPDP Rules use simple "Net Worth" under the . The former is far more conservative and difficult to satisfy.
Moreover, an must undergo a 12-month trial period before obtaining a final , and thereafter maintain a of total outside liabilities not exceeding seven times for three consecutive years before declaring dividends. A merely registers with the —which, as of now, exists only on paper, with chairperson and members yet to be appointed—and awaits technical standards that remain unpublished.
in Practice
The immediate consequence is a clear arbitrage opportunity. Entities that cannot clear the RBI's conservative entry bar may simply register as Consent Managers and route financial information through the DPDP channel, performing the identical function under a lighter rulebook at a fraction of the compliance cost. As the source notes,
"Considering the contemporary world that everyone wants a service with the lowest cost and the most efficiency, two scenarios may arise: first, an organization would avail Consent Managers as it allows
on all types of data, making Account Aggregators redundant; second, entities that cannot clear RBI's conservative entry bar may simply register as Consent Managers."
This is not a hypothetical concern. India has witnessed similar regulatory loopholes before—most notably under the , where manufacturers exploited the overlapping jurisdiction of and to bypass stricter drug regulations. The pattern repeats itself: two regulators, two rulebooks, one function, and a .
Legal Safeguards or Paper Tigers?
The DPDP Act contains a ——which states that the Act is in addition to, and not , any other law, and in case of conflict, the DPDP Act prevails to the extent of the conflict. On paper, this tilts the balance toward Consent Managers. But several practical barriers stand in the way.
First, the bank at the centre of Illustration 2 remains a regulated entity of the RBI. Its authority to part with financial information continues to be governed by the NBFC-AA Master Directions, banking secrecy obligations, and RBI's data-sharing norms. An illustration in a Schedule cannot compel a bank to open its systems to an intermediary the RBI has never licensed. As the source observes,
"The real danger is not that Consent Managers will make Account Aggregators redundant tomorrow. It is that the Rules, as drafted, create arbitrage on paper."
Second, the has held that sectoral regulators must exercise jurisdiction first before the general regulator steps in. Applied here, the RBI—not the —would have the first word on how financial information moves. The NBFC-AA ecosystem already runs on mandatory APIs across more than 600 regulated entities; a cannot compel a single financial information provider onto its rails without the RBI's blessing.
Third, the machinery gap is enormous. registration opens only on , and the required by the DPDP Rules are yet to be published. The framework, by contrast, is operational, battle-tested, and backed by a mature regulatory apparatus.
Implications for Fintech and Data Principals
For the legal community, the overlap raises serious questions about and compliance costs. Fintechs seeking to offer services must now evaluate two distinct regulatory paths—one under the RBI with high entry barriers and ongoing leverage restrictions, the other under the DPDP Board with lighter requirements but uncertain technical standards and potential jurisdictional challenges. The confusion is compounded for data principals, who may not understand which intermediary they are dealing with or which regulator offers them stronger protection.
The analysis concludes that the DPDP Rules, as drafted, invite
"
, compliance costs for fintechs and confusion for the very
both entities claim to empower."
Without harmonisation—either through the RBI relaxing its AA norms or the DPDP Board imposing equivalent safeguards—the two regimes will remain in tension, each undermining the other's credibility.
Conclusion
The - overlap under the DPDP Rules, 2025, is a cautionary tale of regulatory design. What was intended as a parallel, sector-agnostic consent mechanism has inadvertently created a lighter-touch alternative to the RBI's carefully constructed financial data-sharing framework. While practical barriers may delay immediate arbitrage, the Rules provide a roadmap for it. The and the RBI must act swiftly to align standards, close loopholes, and ensure that one function does not end up with two rulebooks—especially when the safety of financial information is at stake.