{"id":388597,"date":"2026-06-26T13:00:02","date_gmt":"2026-06-26T07:30:02","guid":{"rendered":"https:\/\/www.scconline.com\/blog\/?p=388597"},"modified":"2026-06-26T12:40:23","modified_gmt":"2026-06-26T07:10:23","slug":"account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector","status":"publish","type":"post","link":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/","title":{"rendered":"Fragmented Consent and Fractured Rights: Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules in Light of the Booming Fintech Sector"},"content":{"rendered":"<div style=\"text-align: justify; line-height: 150%;\">\n<p style=\"margin-bottom: 3%; font-style: italic; text-align: center;\">The current framework presents a regulatory paradox in which two regulations with looming ambiguities pose an operational threat to the Fintech sector as a whole.<\/p>\n<p style=\"margin-bottom: 3%; font-style: italic;\">This article is one of the winning entries (Ranked 1st) of Lexathon organised by NLU, Odisha, a technology law conclave on AI, data protection, and innovation which took place in April, 2026.<\/span><\/p>\n<p style=\"font-weight: bold;\"><span style=\"font-variant: small-caps;\">I<\/span>ntroduction<\/p>\n<p style=\"margin-left: 36pt;\"><span style=\"font-style: italic;\">&#8220;Contextual integrity is the appropriate benchmark of privacy.&#8221;<\/span><a id=\"fnref1\" href=\"#fn1\" title=\"1. Helen Nissenbaum, &#8220;Privacy as Contextual Integrity&#8221; (2004) 79 Washington Law Review 119.\"><sup>1<\/sup><\/a><\/p>\n<p style=\"margin-bottom: 3%; text-align: right;\"><span style=\"font-style: italic;\">&#8212;<\/span> Helen Nissenbaum<\/p>\n<p style=\"margin-bottom: 3%;\">2016 witnessed the legislative revolution in India&#8217;s fintech landscape, with Reserve Bank of India (RBI) conceptualising the Reserve Bank of India (Non-Banking Financial Companies &#8211; Account Aggregator) Directions, 2025<\/span><a id=\"fnref2\" href=\"#fn2\" title=\"2. Reserve Bank of India (Non-Banking Financial Companies - Account Aggregator) Directions, 2025.\"><sup>2<\/sup><\/a> (AA), which fervently proved to be a forerunner in global data protection regimes; built upon a strong foundation of data empowerment as opposed to data protection, this framework sought to disrupt the pre-existing notion of traditional power dynamics within the financial sector by placing individuals at the focal point of consent-based data sharing as opposed to them acting as passive data subjects.<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">This regulatory measure ensures the functionality of non-banking financial companies (NBFCs) as &#8220;blind conduits&#8221; that facilitate encrypted data flow between financial information providers (banks, mutual funds and insurers) with financial information users (wealth management systems, fintech platforms) operating solely on user-based consent. This semi-automated approach embeds consent and data minimisation within the technical system, making compliance structural rather than discretionary.<\/span><a id=\"fnref3\" href=\"#fn3\" title=\"3. Martin Moore &amp; Damian Tambini (Ed.), Regulating Big Tech: Policy Responses to Digital Dominance (OUP 2022) 234\u00e2\u201d\u20ac251.\"><sup>3<\/sup><\/a> By December 2025, a cumulative sum of 252.88 million users were onboarded onto the AA ecosystem.<\/span><a id=\"fnref4\" href=\"#fn4\" title=\"4. Sahamati Foundation, Account Aggregator Ecosystem Dashboard: Monthly Statistics, available at &lt;https:\/\/sahamati.org.in\/aa-dashboard\/&gt;.\"><sup>4<\/sup><\/a> Furthermore, India&#8217;s Data Empowerment and Protection Architecture (DEPA), which indexed the AA framework, garnered international fame with G20 endorsing the framework, particularly the AA framework, as an emerging primacy model for data governance in developing economies.<\/span><a id=\"fnref5\" href=\"#fn5\" title=\"5. G20 Digital Economy Working Group, Quad Principles for Development and Deployment of Digital Public Infrastructure (Bali Summit Declaration Annexure, November 2024).\"><sup>5<\/sup><\/a><\/span><\/p>\n<p style=\"margin-bottom: 3%;\">In retrospect, yet another crucial regulation, <span style=\"font-style: italic;\">namely<\/span>, the <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">Digital Personal Data Protection Act, 2023<\/a> (DPDP Act), &#8220;seeks to lay the foundation for developing a strong privacy regime in the country&#8221;<\/span><a id=\"fnref6\" href=\"#fn6\" title=\"6. Soumya Banerjee, &#8216;\"Digital Personal Data Protection Act&#8221;&mdash;A Strudel Served Raw!' (2024) 2024 Int'l J L Ethics Tech 85.\"><sup>6<\/sup><\/a>. Two years later, the Indian Government put forth the <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9002981468\" target=\"_blank\">Digital Personal Data Protection Rules, 2025<\/a> (DPDP Rules) in January for public consultation, and as per the Ministry of Electronics and Information Technology (MeiTY) circular, it is expected that by November 2026<\/span><a id=\"fnref7\" href=\"#fn7\" title=\"7. Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Notified on 13-11-2025, R. 4(1).\"><sup>7<\/sup><\/a> the provisions pertaining to Consent Managers (CMs) will be operational as prescribed under Rule 4, which enforces that entities registered within the Data Protection Board (DPB) must enable individuals to categorically &#8220;give, manage review and withdraw consent&#8221; for personal data processing in the digital sphere.<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">This creates a discord between AAs managing consent with respect to financial data in accordance with RBI guidelines, and CMs managing all personal data under the purview of the DPB, hereby aggravating the inconsistency. Such implications have severe repercussions for fintech firms operating at the confluence of these frameworks, and these regulatory inconsistencies are reflected in higher compliance costs and cast a shadow over any business strategy such a firm might wish to undertake. Several questions arise in the process.<\/p>\n<p style=\"margin-bottom: 3%;\">Most existing AAs separately register as CMs and subject themselves to multiple regulatory oversight mechanisms simultaneously? When consent-related violations do occur, does the RBI or the DPB exercise jurisdiction?<\/p>\n<p style=\"margin-bottom: 3%;\">These questions are not hypothetical; they pose a real-time issue that requires an immediate solution. While both frameworks aim to empower individuals and promote user consent to be at the helm of data governance, the existing discord undermines the very idea they seek to enforce. This analysis aims to alleviate these issues by adopting an approach that harmonises regulations without disregarding the legislation&#8217;s objectives.<\/p>\n<p style=\"font-weight: bold;\">Problem statement<\/p>\n<p style=\"margin-bottom: 3%;\">The current framework presents a regulatory paradox in which two regulations with looming ambiguities pose an operational threat to the Fintech sector as a whole. Such frameworks without sufficient amendments will enable inefficiency and encroach upon the sanctity of the data protection regime as opposed to Article <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001574870\" target=\"_blank\">14<\/a> of the <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002726967\" target=\"_blank\">Constitution<\/a> that aims to establish clarity and non-arbitrariness<\/span><a id=\"fnref8\" href=\"#fn8\" title=\"8. As held in E.P. Royappa v. State of T.N., (1974) 4 SCC 3 : 1974 SCC (L&amp;S) 165.\"><sup>8<\/sup><\/a> within State action in line with maintaining a harmonised approach that avoids jurisdictional overlap and regulatory arbitrariness while delineating a clear boundary between RBI and DPB in the light of a freshly consolidated consent management system to be integrated within Fintech bodies in particular.<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">On the one hand, the aforementioned regulatory bodies may choose to enforce their standards independently &#8212; RBI via Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001519133\" target=\"_blank\">45-JA<\/a><\/span>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002792123\" target=\"_blank\">Reserve Bank of India Act, 1934<\/a> (RBI Act)<\/span> and the DPB via Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593475\" target=\"_blank\">33<\/a><\/span>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">DPDP Act<\/a>. However, a lack of intelligible differentia in terms of a State action in either Act owing to the overlap and a lack of coherence demands a coordinated approach that prevents confusion and arbitrary actions.<\/p>\n<p style=\"font-weight: bold;\"><span style=\"font-variant: small-caps;\">C<\/span>ritical analysis<\/p>\n<p style=\"margin-bottom: 3%;\">Although Account Aggregators operate under RBI oversight, their functions align with those outlined in the DPDP Rules under Rule 4. This rule mandates that any data fiduciary permitting users to grant, review, revoke, or modify permissions for data sharing must register as a CM, since the aggregators undertake such actions themselves, particularly with financial records.<\/span><a id=\"fnref9\" href=\"#fn9\" title=\"9. Kishwar, Sanya Darakhshan, Sahani, Jaskaran Singhand Tyagi, Saumya, &#8220;Navigating India's Draft DPDP Rules 2025: Implementation Challenges in Protecting Children's Personal Data&#8221; (2025) 8(2) Journal of Data Protection &amp; Privacy 144.\"><sup>9<\/sup><\/a> It is therefore unclear whether additional approval from the DPB is necessary, leaving room for ambiguity and potentially leading to significant overlaps in oversight unless further clarification is provided. This may lead to higher compliance costs and differing capital requirements for fintech companies. Without clear guidance on coordination among authorities, organisations risk performing the same tasks under separate regulations, leaving the ambiguity unresolved.<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">Another issue involves technical clarity. Within the AA framework, Reserve Bank Information Technology<\/span> (ReBIT)<\/span><a id=\"fnref10\" href=\"#fn10\" title=\"10. Reserve Bank Information Technology Pvt. Ltd. (ReBIT), Cyber Security Framework for NBFCs (ReBIT, 2017).\"><sup>10<\/sup><\/a><\/span> establishes exact technical requirements<\/span><span style=\"Segoe UI&quot;;\"><\/span>, such as Application Programming Interface (API) designs, formats for consent records, and methods for securing data. Such rules apply consistently throughout banking institutions. On the other hand, the DPDP Regulations instruct CMs to support &#8220;interoperable platforms&#8221;, yet offer no detail on system-level requirements or confirm whether existing AA norms meet compliance needs. As a result, it remains unclear whether Fintech companies must adopt new architectures to handle personal information unrelated to finance, or whether such setup aligns with regulatory intent. Uncertainty of this kind affects how processes are managed.<\/span> <\/span><\/p>\n<p style=\"margin-bottom: 3%;\">Third, jurisdictional overlap. RBI regulates AAs for financial stability and inclusion under the <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002792123\" target=\"_blank\">RBI Act<\/a>. The DPB regulates CMs under the <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">DPDP Act<\/a> to protect personal data and enforce privacy rights. If an AA&#8217;s activities trigger obligations under both frameworks, it is unclear which regulator has primary authority. The result is potential parallel enforcement, duplicative penalties, and uncertainty for regulated entities.<\/p>\n<p style=\"background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\"><span style=\"font-variant: small-caps;\">C<\/span><span style=\"font-style: italic;\">onstitutional perspective<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">The dual framework raises constitutional concerns under three fundamental rights provisions.<\/span> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001574870\" target=\"_blank\">Article 14<\/a>&#8216;s equality guarantee prohibits arbitrary State action and requires legislative classifications to satisfy two tests: (1) intelligible differentia distinguishing persons or things classified from those left out, and (2) rational nexus between the differentia and the legislative object. In <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000051822\" target=\"_blank\"><span style=\"font-style: italic;\">Modern Dental College &amp; Research Centre<\/span> v. <span style=\"font-style: italic;\">State of M.P.<\/span><\/span><\/a><\/span><a id=\"fnref11\" href=\"#fn11\" title=\"11. (2016) 7 SCC 353.\"><sup>11<\/sup><\/a>, the Supreme Court held that regulatory burdens must be proportional to legislative objectives and cannot be excessive.<\/span> <\/span><\/p>\n<p style=\"margin-bottom: 3%;\">Article <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001574926\" target=\"_blank\">19(1)(<span style=\"font-style: italic;\">g<\/span>)<\/span><\/a> guarantees the right to practice any profession or carry on any trade or business, subject to reasonable restrictions under Article <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001574926\" target=\"_blank\">19(6)<\/a>. In <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000020540\" target=\"_blank\"><span style=\"font-style: italic;\">Papnasam Labour Union<\/span> v. <span style=\"font-style: italic;\">Madura Coats Ltd.<\/span><\/span><\/a><\/span><a id=\"fnref12\" href=\"#fn12\" title=\"12. Papnasam Labour Union v. Madura Coats Ltd., (1995) 1 SCC 501.\"><sup>12<\/sup><\/a> the court established that restrictions must not be arbitrary, excessive, or go beyond the requirements of public interest. Dual registration requirements, with hiking compliance costs and obligations constitute unreasonable restrictions which are highly disproportionate.<\/span><\/p>\n<p style=\"margin-bottom: 3%;\">Article <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001574949\" target=\"_blank\">21<\/a>&#8217;s<\/span> right to life and personal liberty, interpreted in <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002748027\" target=\"_blank\"><span style=\"font-style: italic;\">K.S. Puttaswamy (Privacy-9J.)<\/span> v<span style=\"font-style: italic;\">. Union of India<\/span><\/span><\/a><\/span><a id=\"fnref13\" href=\"#fn13\" title=\"13. (2017) 10 SCC 1.\"><sup>13<\/sup><\/a> to include informational privacy, requires any data governance regime to satisfy the test: (1) legitimate aim, (2) legality of measure, (3) proportionality, and (4) procedural guarantees. While both frameworks serve the legitimate aim of data protection, the question of procedural guarantees is left astray owing to the ongoing ambiguities present, leaving either regulation constitutionally non grata.<\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The Account Aggregator (AA) framework<\/p>\n<p style=\"margin-bottom: 3%;\">Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001519133\" target=\"_blank\">45-JA<\/a><\/span>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002792123\" target=\"_blank\">RBI Act, 1934<\/a> allows banks to probe into NBFCs &#8220;in the interest of depositors&#8221; to ensure transparency and protection, and further exercises authority on NBFCs by means of AA Directions, in accordance with Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001519134\" target=\"_blank\">45-K<\/a>, which categorises NBFCs as a distinct category which includes fintech companies that can be adjudicated upon which. The statutory definition as laid down in Chapter I-F(4)<\/span><a id=\"fnref14\" href=\"#fn14\" title=\"14. Reserve Bank of India, Master Direction &mdash; Non-Banking Financial Company &mdash; Account Aggregator (Reserve Bank) Directions 2016 (RBI\/DNBR\/2016-17\/26), Ch. I, Para F(4).\"><sup>14<\/sup><\/a> &#8220;business of an account aggregator&#8221; as providing services in order to retrieve or &#8220;collecting such financial information pertaining to its customer, as may be specified by the Reserve Bank from time to time&#8221; and to consolidate and present such information, provided that &#8220;the financial information pertaining to the customer shall not be the property of the Account Aggregator, and not be used in any other manner&#8221;.<\/span><\/p>\n<p>Further on under Chapter III-B Clause 17<\/span><a id=\"fnref15\" href=\"#fn15\" title=\"15. Reserve Bank of India, Master Direction &mdash; Non-Banking Financial Company &mdash; Account Aggregator (Reserve Bank) Directions 2016 (RBI\/DNBR\/2016-17\/26), Ch. III-B, Para 17.\"><sup>15<\/sup><\/a>, if a user must share his financial details they shall attach the following details to a consent artefact:<\/span><\/p>\n<p style=\"margin-left: 36pt; margin-bottom: 3%;\">&#8220;(1) identity of the customer and optional contact information; (2) the nature of the financial information requested; (3) purpose of collecting such information; (4) the identity of the recipients of the information, if any; (5) uniform resource locator (URL) or other address to which notification needs to be sent every time the consent artefact is used to access information; (6) consent creation date, expiry date, identity and signature\/digital signature of the NBFC-AA; and (7) any other attribute as may be prescribed by the Reserve Bank.&#8221;<\/p>\n<p style=\"margin-bottom: 3%;\">Again, Chapter III-A 14(7)<\/span><a id=\"fnref16\" href=\"#fn16\" title=\"16. Reserve Bank of India, Master Direction &mdash; Non-Banking Financial Company &mdash; Account Aggregator (Reserve Bank) Directions 2016 (RBI\/DNBR\/2016-17\/26), Ch. III-A, Para 14(7).\"><sup>16<\/sup><\/a> prohibits an AA from storing any financial information with respect to a customer and only allows for their transmission without reading such data but cannot retain the information and is &#8220;designed to be data blind&#8221;<\/span><a id=\"fnref17\" href=\"#fn17\" title=\"17. NITI Aayog, Data Empowerment and Protection Architecture (DEPA): Empowering Data to the People (2020).\"><sup>17<\/sup><\/a>, once consent on such platform expires the data flow stops subsequently. Furthermore, Chapter III-B 21<\/span><a id=\"fnref18\" href=\"#fn18\" title=\"18. Reserve Bank of India, Master Direction &mdash; Non-Banking Financial Company &mdash; Account Aggregator (Reserve Bank) Directions 2016 (RBI\/DNBR\/2016-17\/26), Ch. III-B, Para 21.\"><sup>18<\/sup><\/a> also explicates upon a consent artefact to be &#8220;logged, audited, verified&#8221; to keep a traceable means of information transfer.<\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">The Consent Manager framework<\/p>\n<p style=\"margin-bottom: 3%;\">The DPDP regime takes a nuanced approach to consent management, while Section<\/span><span style=\"Opan sans&quot;;\"><\/span> <\/span><span style=\"Opan sans&quot;;\"><a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593489\" target=\"_blank\">6<\/span><\/a><\/span> of the Act clarifies that consent must be &#8220;free, specific, unconditional and unambiguous&#8221;, Rule 4, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9002981468\" target=\"_blank\">DPDP Rules<\/a> operationalises that by enabling CMs as key players to help users provide, manage, review and withdraw their consent with respect to any personal data provided to the data fiduciary. In consonance, Part B of Schedule I imposes certain obligations, Item 9 says that CMs must &#8220;ensure that no conflict of interest arises on account of its Directors, key managerial personnel and senior management holding a Directorship, financial interest, employment or beneficial&#8221;<\/span><a id=\"fnref19\" href=\"#fn19\" title=\"19. Digital Personal Data Protection Rules, 2025, Sch. I Pt. B Item 9.\"><sup>19<\/sup><\/a> Upon a literal reading, the provision implies that any corporate structure operating as a fiduciary and a CM simultaneously must be prevented from using such user data for its own business purposes.<\/span> <\/span><\/p>\n<p style=\"margin-bottom: 3%;\">CMs primarily handle record management of such consent, rather than data transmission, unlike AAs. CMs operate as consent brokers, <span style=\"font-style: italic;\">i.e<\/span><span style=\"font-style: italic;\">.<\/span> maintaining records of consent given, denied or revoked by the user as the case may be; such records must be accessible to the data principals and kept for at least seven years from the date of consent withdrawal or expiry of consent<\/span>,<a id=\"fnref20\" href=\"#fn20\" title=\"20. Digital Personal Data Protection Rules, 2025, R 4.\"><sup>20<\/sup><\/a> whichever the case may be, enabling both individual and regulatory supervision. Most importantly, Item 9 under Part A of Schedule 1<\/span><a id=\"fnref21\" href=\"#fn21\" title=\"21. Digital Personal Data Protection Rules, 2025, Sch. I Pt. A Item 9.\"><sup>21<\/sup><\/a> clarifies that CM platforms shall be &#8220;interoperable&#8221; to allow data principals to access such consent management systems from several providers; however, there is no prescription as to how such interoperability should be achieved it establishes interoperability as a mechanism without creating a roadmap for its implementation.<\/span><\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Jurisdictional conflicts and overlaps<\/p>\n<p>The following regulatory overlaps transpire across these dimensions:<\/p>\n<p style=\"margin-left: 18pt; margin-bottom: 2%;\"><span style=\"font-style: italic;\">Firstly<\/span>, AAs operate exclusively on &#8220;financial information&#8221; under Chapter 1 F(9) of the Act, which includes tradable securities, insurance and bank deposits, and other enumerated categories pertaining to financial data. CMs include sensitive personal information in its purview, and by definition, any form of financial information comes under its scope as well. If CM interoperability is set to include such financial information, the absence of a coordinated standard between RBI and the DPB means that these frameworks are developing in parallel without any compatibility.<\/p>\n<p style=\"margin-left: 18pt; margin-bottom: 2%;\"><span style=\"font-style: italic;\">Secondly<\/span>, Clause 32 of Part III of the AA Directions further allocates ReBIT standards that fintech bodies must adhere to to ensure a &#8220;secured, duly authorised, smooth, and seamless&#8221; transfer of data. The DPDP Rules, on the other hand, do not have an equivalent or mandate for such CMs, creating yet another operational challenge: An entity cannot simultaneously comply with the given ReBIT standards for AA Rules while also being interoperable with other sectors without duplicating those systems.<\/p>\n<p style=\"margin-left: 18pt; margin-bottom: 3%;\"><span style=\"font-style: italic;\">Thirdly<\/span>, upon violation of user consent, both regulators have varying enforcement powers. Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593475\" target=\"_blank\">33(1)<\/a><\/span>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9001593555\" target=\"_blank\">DPDP Act<\/a><\/span> empowers the Board to impose a sum of up to Rs 250 crores on data fiduciaries and up to Rs 50 crores for CMs. In parallel, Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001519129\" target=\"_blank\">45-IA<\/a> read with Section <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0001519194\" target=\"_blank\">58-B<\/a>, RBI Act allows banks to charge a penalty of up to Rs 25 lakhs and, prospectively, cancel the licence of a defaulting NBFC, but there is no harmonisation between these frameworks. This creates unnecessary friction, and the current lacuna which either system aims to resolve is aggravated further.<\/p>\n<p style=\"font-weight: bold;\">International framework<\/p>\n<p style=\"margin-bottom: 3%;\">The European Union approaches the transfer of financial data under the Payment Services Directive 2 (PSD2)<\/span><a id=\"fnref22\" href=\"#fn22\" title=\"22. Directive (EU) 2015\/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market (PSD2) [2015] OJ L 337\/35.\"><sup>22<\/sup><\/a> and the General Data Protection Regulation<\/span><a id=\"fnref23\" href=\"#fn23\" title=\"23. Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation) [2016] OJ L 119\/1.\"><sup>23<\/sup><\/a> (GDPR) offer an advisory role. Under PSD2 Article 66<\/span><a id=\"fnref24\" href=\"#fn24\" title=\"24. Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation) [2016] OJ L 119\/1.\"><sup>24<\/sup><\/a>, the customer may provide consent in any form to a bank to access their payment accounts, with the consent being revocable at the customer&#8217;s disposal. Fintech entities can request access to such information &#8220;on an objective, non-discriminatory basis and proportionate basis&#8221; while GDPR Article 6(1)(<span style=\"font-style: italic;\">a<\/span>)<\/span><a id=\"fnref25\" href=\"#fn25\" title=\"25. General Data Protection Regulation, Art. 6(1)(a).\"><sup>25<\/sup><\/a> says that process of data processing shall be deemed as lawful only if the &#8220;data subject has given consent to the processing of his or her personal data&#8221;<\/span><a id=\"fnref26\" href=\"#fn26\" title=\"26. Fiona Maclean, Christian McDermott, Calum Docherty and Amy Smyth, &#8220;Consent under PSD2 and the GDPR: Squaring the Circle&#8221; Butterworths Journal of International Banking and Financial Law (March 2021), available at &lt;https:\/\/www.lw.com\/admin\/upload\/SiteAttachments\/Article%205%20-%20Smyth.1.pdf&gt;.\"><sup>26<\/sup><\/a>. To address this, the European Data Protection Board (EDPB)<\/span><a id=\"fnref27\" href=\"#fn27\" title=\"27. European Data Protection Board, Guidelines 06\/2020 on the Interplay of the Second Payment Services Directive and the GDPR (EDPB 2020).\"><sup>27<\/sup><\/a> clarified that &#8220;explicit consent&#8221; as mentioned under Article 94(2)<\/span><a id=\"fnref28\" href=\"#fn28\" title=\"28. Payment Services Directive 2, Art. 94(2). (EU).\"><sup>28<\/sup><\/a> and Article 67(2)(<span style=\"font-style: italic;\">a<\/span>)<\/span><a id=\"fnref29\" href=\"#fn29\" title=\"29. Payment Services Directive 2, Art. 67(2)(a). (EU).\"><sup>29<\/sup><\/a>, serves only contractual and transparency purposes. This form does not qualify as a valid legal ground under GDPR<\/span> <\/span><span style=\"Segoe UI&quot;;\">&#8212;<\/span><\/span> its permitted bases remain strictly defined. Instead, separate compliance must be met, typically via Article 6(1)(<span style=\"font-style: italic;\">b<\/span>)<\/span><a id=\"fnref30\" href=\"#fn30\" title=\"30. General Data Protection Regulation, Art. 6(1)(b).\"><sup>30<\/sup><\/a>, tied to contract execution. As a result, overlapping consent demands do not arise. Both frameworks operate together, each fulfilling distinct roles. Clarity prevents redundancy. Legal coherence remains intact.<\/span><a id=\"fnref31\" href=\"#fn31\" title=\"31. &Ouml;zg&uuml;r, Hasan, &#8220;Personal Data Processing by Third Party Providers in Online Payment Transactions under GDPR and PSD2 an in-depth Legal Analysis for GDPR and PSD2 Compliance&#8221; (2021).\"><sup>31<\/sup><\/a><\/span><\/p>\n<p style=\"margin-bottom: 3%;\">Under Singapore&#8217;s Personal Data Protection Act, 2012, consent serves as the main basis for handling personal information. Yet exceptions emerge where sector-specific rules apply, shaped to align with broader legal duties. While permission generally guides data use, sub-section 4(4)(<span style=\"font-style: italic;\">b<\/span>) clarifies that other laws may override this rule. When regulations demand financial firms to collect or share data<\/span> <span style=\"Segoe UI&quot;;\">&#8212;<\/span> say, for oversight or risk control<\/span> <span style=\"Segoe UI&quot;;\">&#8212;<\/span> the need for individual approval fades. Such cases permit processing without consent, provided statutory demands exist. Thus, compliance with external mandates can displace the usual consent requirement.<\/span><\/p>\n<p style=\"font-weight: bold;\"><span style=\"font-variant: small-caps;\">H<\/span>armonisation<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Sectoral exemptions under<span style=\"font-variant: small-caps;\"> DPDP<\/span><\/p>\n<p>A novel solution towards achieving harmonisation can be established foremost by creating a sectoral CM category. A new rule that clarifies a premise recognising AAs as already eligible for consent management and shall not require separate registration. A new rule which stipulates the following:<\/p>\n<p style=\"margin-bottom: 3%; margin-left: 36pt;\">&#8220;Notwithstanding the provisions under Rule 4 or any other provision within the rules, any entity which operates retrospectively under any relevant Act, Rule or legislation in force and thereunder is empowered to regulate, facilitate or operationalise any form of user consent-based data sharing, shall be deemed operative as a valid Consent Manager.<\/p>\n<p style=\"margin-bottom: 3%;\">Such an entity shall not require separate registration under Rule 4, provided that such entity operates strictly within the scope of its statutory mandates and complies with the obligations extended to Consent Managers under the given Act, Rule or legislation; however, the Data Protection Board reserves its right to probe into, examine, or initiate proceedings with respect to any act or omission that which, upon investigation satisfies the conditions of non-compliance with respect to the provisions of the said Act, Rule or legislation.&#8221;<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Unified consent artefacts<\/p>\n<p style=\"\">In light of the Fintech industry, both the DPB and RBI should establish a Joint Committee to develop a consent artefact system that extends to both AAs and CMs. These standards should build on the existing ReBIT framework, but the scope should be increased beyond financial data. The standards should be built on:<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">(<span style=\"font-style: italic;\">a<\/span>) A common consent scheme outlining elements of the data category, purpose, recipient, duration, and consent withdrawal mechanism. Such facets should be operational on a multisectoral basis.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">(<span style=\"font-style: italic;\">b<\/span>) Prescribing minimum encryption standards that need to be adhered to, while sectoral regulatory bodies can prescribe stringent mechanisms for the maintenance of sensitive data.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt; margin-bottom: 3%;\">(<span style=\"font-style: italic;\">c<\/span>) Consent management systems shall have an interoperable basis by means of which users can access their account aggregator consent forms through preferred interfaces.<\/p>\n<p style=\"margin-bottom: 3%;\">Integrating a central interoperable model will ensure that the AA ecosystem can maintain its standards regarding financial data while broader consent management protocols can be put in place as well.<\/p>\n<p style=\"font-style: italic; background-image: linear-gradient(to left, #FFFFFF, rgb(236, 198, 198));\">Institutional solution: RBI-DPB mechanism<\/p>\n<p>Legislative and systemic harmonisation alone will not be sufficient to sustain the aforementioned suggestions; therefore, RBI and DPB must coordinate as a whole to maintain this governance. A possible way to explore this is by executing a formal memorandum of understanding (MoU) that establishes the following facets:<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">(<span style=\"font-style: italic;\">a<\/span>) A quarterly review in a Board meeting presided over by Senior Board Members of RBI and the DPB to review emerging issues in light of Fintech bodies and their AA-CM intersection, creating robust policies that are aimed to prevent overlaps and ensure simpler compliance standards for their people.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt;\">(<span style=\"font-style: italic;\">b<\/span>) The protocols should explicitly mention the hierarchy of the management, <span style=\"font-style: italic;\">i.e.<\/span>, Sectoral Regulator (RBI) is to exercise authority over licensed entities (Fintech bodies operating with AAs), whereas the DPB enforces data protection horizontally. Therefore, upon any violation, for instance, breach of any financial data owing to improper consent management, either regulators can come into the picture and conduct joint investigations and impose a singular penalty based on the gravity of the breach within a specific limit, to ensure a singular penalty is charged.<\/p>\n<p style=\"margin-left: 36pt; text-indent: -18pt; margin-bottom: 3%;\">(<span style=\"font-style: italic;\">c<\/span>) Facilitating information transfer between the regulatory bodies to check audit reports, assess compliance, and ensure a thorough assessment. This mechanism allows the RBI to uphold financial data moderation while safeguarding the interests of fintech bodies, while the DPB can advise on a more considerate mechanism. This MoU should be recognised in the Gazettes through a notification to uphold its legal force and ensure the commitment of both bodies to a proper data governance regime.<\/p>\n<p style=\"font-weight: bold;\">Conclusion<\/p>\n<p style=\"margin-bottom: 3%;\">India&#8217;s data protection regime is currently at a critical juncture, with the fintech sector booming and reaching 47 billion dollars in 2025<\/span><a id=\"fnref32\" href=\"#fn32\" title=\"32. Press Trust of India, &#8220;FDI inflows to India surged by 73 per cent to $47 billion in 2025&#8221; The Economic Times (5-2-2025) available at &lt;https:\/\/m.economictimes.com\/news\/economy\/finance\/fdi-inflows-to-india-surged-by-73-per-cent-to-47-billion-in-2025-un\/articleshow\/127292155.cms&gt; last accessed 18-2-2026.\"><sup>32<\/sup><\/a>. It is expedient that we aim to resolve any regulatory ambiguity to maintain consistency and uphold such standards. Uncertainty surrounding legislation will undoubtedly have a chilling effect on the industry. The proposed three-pillar harmonisation framework, legislative exemptions, technical standardisation, and institutional coordination, offer a path forward, preserving regulatory rigour while eliminating operational conflicts. Implementation requires political will to prioritise goodwill over bureaucratic protection for such bodies. The constitutional imperative is clear: Article 14&#8217;s non-arbitrariness and Article 21&#8217;s privacy protection demand governance frameworks that are proportional and coordinated. India&#8217;s fintech future and the financial inclusion of millions depend on resolving this regulatory paradox with the urgency it warrants.<\/span><\/p>\n<\/div>\n<hr\/>\n<p style=\"margin-left: 18pt; text-indent: -18pt; font-family: ED Garamond;\"><strong><span style=\"color: #000080;\">*4th year BBA LLB (Hons.), Symbiosis Law School, Pune.<\/span><\/strong><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn1\" href=\"#fnref1\">1.<\/a> Helen Nissenbaum, &#8220;Privacy as Contextual Integrity&#8221; (2004) 79 Washington Law Review 119.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn2\" href=\"#fnref2\">2.<\/a> Reserve Bank of India (Non-Banking Financial Companies &#8211; Account Aggregator) Directions, 2025.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn3\" href=\"#fnref3\">3.<\/a> Martin Moore &amp; Damian Tambini (Ed.), <span style=\"font-style: italic;\">Re<\/span>gulating <span style=\"font-style: italic;\">Big Tech: Policy Responses to Digital Dominance<\/span> (OUP 2022) 234<\/span><span style=\"\">\u00e2\u201d\u20ac<\/span>251.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn4\" href=\"#fnref4\">4.<\/a> Sahamati Foundation, Account Aggregator Ecosystem Dashboard: Monthly Statistics, available at &lt;<a href=\"https:\/\/sahamati.org.in\/aa-dashboard\/\" target=\"_blank\">https:\/\/sahamati.org.in\/aa-dashboard\/<\/a>&gt;.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn5\" href=\"#fnref5\">5.<\/a> G20 Digital Economy Working Group, <span style=\"font-style: italic;\">Qu<\/span>ad Principles for Development and Deployment of Digital Public Infrastructure (Bali Summit Declaration Annexure, November 2024).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn6\" href=\"#fnref6\">6.<\/a> Soumya Banerjee, &#8216;&#8221;Digital Personal Data Protection Act&#8221;<\/span><span style=\"Segoe UI&quot;;\">&mdash;<\/span>A Strudel Served Raw!&#8217; (2024) 2024 Int&#8217;l J L Ethics Tech 85.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn7\" href=\"#fnref7\">7.<\/a> Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), Notified on 13-11-2025, R. 4(1).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn8\" href=\"#fnref8\">8.<\/a> As held in <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000009247\" target=\"_blank\"><span style=\"text-decoration: underline; text-underline-style: solid; text-underline-mode: continuous; text-underline-color: #0000ff; color: #0000ff;\"><span style=\"font-style: italic;\">E.P. Royappa<\/span> v. <span style=\"font-style: italic;\">State of T.N.<\/span><\/span><\/a>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000009247\" target=\"_blank\">(1974) 4 SCC 3<\/a> : 1974 SCC (L&amp;S) 165.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn9\" href=\"#fnref9\">9.<\/a> <span style=\"background-color: #ffffff; color: #333333;\">Kishwar, Sanya Darakhshan<\/span>, <span style=\"background-color: #ffffff; color: #333333;\">Sahani, Jaskaran Singh<\/span>and <span style=\"background-color: #ffffff; color: #333333;\">Tyagi, Saumya<\/span>, &#8220;Navigating India&#8217;s Draft DPDP Rules 2025: Implementation Challenges in Protecting Children&#8217;s Personal Data&#8221; (2025) 8(2) Journal of Data Protection &amp; Privacy 144.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn10\" href=\"#fnref10\">10.<\/a> Reserve Bank Information Technology Pvt. Ltd. (ReBIT), Cyber Security Framework for NBFCs (ReBIT, 2017).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn11\" href=\"#fnref11\">11.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000051822\" target=\"_blank\">(2016) 7 SCC 353<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn12\" href=\"#fnref12\">12.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000020540\" target=\"_blank\"><span style=\"text-decoration: underline; text-underline-style: solid; text-underline-mode: continuous; text-underline-color: #0000ff; color: #0000ff;\"><span style=\"font-style: italic;\">Papnasam Labour Union<\/span> v. <span style=\"font-style: italic;\">Madura Coats Ltd.<\/span><\/span><\/a>, <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0000020540\" target=\"_blank\">(1995) 1 SCC 501<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn13\" href=\"#fnref13\">13.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-0002748027\" target=\"_blank\">(2017) 10 SCC 1<\/a>.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn14\" href=\"#fnref14\">14.<\/a> Reserve Bank of India, Master Direction &mdash; Non-Banking Financial Company &mdash; Account Aggregator (Reserve Bank) Directions 2016 (RBI\/DNBR\/2016-17\/26), Ch. I, Para F(4).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn15\" href=\"#fnref15\">15.<\/a> Reserve Bank of India, Master Direction &mdash; Non-Banking Financial Company &mdash; Account Aggregator (Reserve Bank) Directions 2016 (RBI\/DNBR\/2016-17\/26), Ch. III-B, Para 17.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn16\" href=\"#fnref16\">16.<\/a> Reserve Bank of India, Master Direction &mdash; Non-Banking Financial Company &mdash; Account Aggregator (Reserve Bank) Directions 2016 (RBI\/DNBR\/2016-17\/26), Ch. III-A, Para 14(7).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn17\" href=\"#fnref17\">17.<\/a> NITI Aayog, Data Empowerment and Protection Architecture (DEPA): Empowering Data to the People (2020).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn18\" href=\"#fnref18\">18.<\/a> Reserve Bank of India, Master Direction &mdash; Non-Banking Financial Company &mdash; Account Aggregator (Reserve Bank) Directions 2016 (RBI\/DNBR\/2016-17\/26), Ch. III-B, Para 21.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn19\" href=\"#fnref19\">19.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9002981468\" target=\"_blank\">Digital Personal Data Protection Rules, 2025<\/a>, Sch. I Pt. B Item 9.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn20\" href=\"#fnref20\">20.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9002981468\" target=\"_blank\">Digital Personal Data Protection Rules, 2025<\/a>, R 4.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn21\" href=\"#fnref21\">21.<\/a> <a href=\"https:\/\/www.scconline.com\/DocumentLink.aspx?q=JTXT-9002981468\" target=\"_blank\">Digital Personal Data Protection Rules, 2025<\/a>, Sch. I Pt. A Item 9.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn22\" href=\"#fnref22\">22.<\/a> Directive (EU) 2015\/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market (PSD2) [2015] OJ L 337\/35.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn23\" href=\"#fnref23\">23.<\/a> Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation) [2016] OJ L 119\/1.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn24\" href=\"#fnref24\">24.<\/a> Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation) [2016] OJ L 119\/1.<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn25\" href=\"#fnref25\">25.<\/a> General Data Protection Regulation, Art. 6(1)(<span style=\"font-style: italic;\">a<\/span>).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn26\" href=\"#fnref26\">26.<\/a> Fiona Maclean, Christian McDermott, Calum Docherty and Amy Smyth, &#8220;Consent under PSD2 and the GDPR: Squaring the Circle&#8221; Butterworths Journal of International Banking and Financial Law (March 2021), available at &lt;<a href=\"https:\/\/www.lw.com\/admin\/upload\/SiteAttachments\/Article%205%20-%20Smyth.1.pdf\" target=\"_blank\">https:\/\/www.lw.com\/admin\/upload\/SiteAttachments\/Article%205%20-%20Smyth.1.pdf<\/a>&gt;.<\/span><\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn27\" href=\"#fnref27\">27.<\/a> European Data Protection Board, Guidelines 06\/2020 on the Interplay of the Second Payment Services Directive and the GDPR (EDPB 2020).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn28\" href=\"#fnref28\">28.<\/a> Payment Services Directive 2, Art. 94(2). (EU).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn29\" href=\"#fnref29\">29.<\/a> Payment Services Directive 2, Art. 67(2)(<span style=\"font-style: italic;\">a<\/span>). (EU).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn30\" href=\"#fnref30\">30.<\/a> General Data Protection Regulation, Art. 6(1)(<span style=\"font-style: italic;\">b<\/span>).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn31\" href=\"#fnref31\">31.<\/a> &Ouml;zg&uuml;r, Hasan, &#8220;Personal Data Processing by Third Party Providers in Online Payment Transactions under GDPR and PSD2 an in-depth Legal Analysis for GDPR and PSD2 Compliance&#8221; (2021).<\/p>\n<p style=\"margin-left: 18pt; text-indent: -18pt;\"><a id=\"fn32\" href=\"#fnref32\">32.<\/a> Press Trust of India, &#8220;FDI inflows to India surged by 73 per cent to $47 billion in 2025&#8221; <span style=\"font-style: italic;\">The Economic Times<\/span> (5-2-2025) available at &lt;<a href=\"https:\/\/m.economictimes.com\/news\/economy\/finance\/fdi-inflows-to-india-surged-by-73-per-cent-to-47-billion-in-2025-un\/articleshow\/127292155.cms\" target=\"_blank\">https:\/\/m.economictimes.com\/news\/economy\/finance\/fdi-inflows-to-india-surged-by-73-per-cent-to-47-billion-in-2025-un\/articleshow\/127292155.cms<\/a>&gt;<\/span> last accessed 18-2-2026.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>by Sambhav Mukherjee*<\/p>\n","protected":false},"author":67011,"featured_media":388598,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[42503,1191],"tags":[108213,108210,108211,108215,108216,96177,92487,108212,108214,108217],"class_list":["post-388597","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-legal-analysis","category-op-ed","tag-account-aggregator-consent-paradox","tag-account-aggregator-framework-india","tag-consent-manager-dpdp-rules","tag-data-protection-and-financial-information","tag-depa-account-aggregator-ecosystem","tag-digital-personal-data-protection-rules-2025","tag-fintech-compliance-india","tag-fintech-data-governance-india","tag-rbi-dpdp-regulatory-overlap","tag-scc-technology-law-analysis"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.4 (Yoast SEO v27.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules | SCC Times<\/title>\n<meta name=\"description\" content=\"Analysis of regulatory overlap between Account Aggregators and Consent Managers under the DPDP framework and its impact on fintech.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fragmented Consent and Fractured Rights: Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules in Light of the Booming Fintech Sector\" \/>\n<meta property=\"og:description\" content=\"Analysis of regulatory overlap between Account Aggregators and Consent Managers under the DPDP framework and its impact on fintech.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/\" \/>\n<meta property=\"og:site_name\" content=\"SCC Times\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/scc.online\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-26T07:30:02+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/Account-Aggregator-and-Consent-Manager-paradox.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"886\" \/>\n\t<meta property=\"og:image:height\" content=\"590\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Editor\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Fragmented Consent and Fractured Rights: Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules in Light of the Booming Fintech Sector\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Editor\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/\"},\"author\":{\"name\":\"Editor\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#\\\/schema\\\/person\\\/84e42bab48238baf12c7e33b3d9761fe\"},\"headline\":\"Fragmented Consent and Fractured Rights: Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules in Light of the Booming Fintech Sector\",\"datePublished\":\"2026-06-26T07:30:02+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/\"},\"wordCount\":318,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Account-Aggregator-and-Consent-Manager-paradox.webp\",\"keywords\":[\"account aggregator consent paradox\",\"Account Aggregator framework India\",\"Consent Manager DPDP Rules\",\"data protection and financial information\",\"DEPA account aggregator ecosystem\",\"Digital Personal Data Protection Rules 2025\",\"FinTech Compliance India\",\"fintech data governance India\",\"RBI DPDP regulatory overlap\",\"SCC technology law analysis\"],\"articleSection\":[\"Op Eds\",\"OP. ED.\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/\",\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/\",\"name\":\"Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules | SCC Times\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Account-Aggregator-and-Consent-Manager-paradox.webp\",\"datePublished\":\"2026-06-26T07:30:02+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#\\\/schema\\\/person\\\/84e42bab48238baf12c7e33b3d9761fe\"},\"description\":\"Analysis of regulatory overlap between Account Aggregators and Consent Managers under the DPDP framework and its impact on fintech.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Account-Aggregator-and-Consent-Manager-paradox.webp\",\"contentUrl\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Account-Aggregator-and-Consent-Manager-paradox.webp\",\"width\":886,\"height\":590,\"caption\":\"Account Aggregator and Consent Manager paradox\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/2026\\\/06\\\/26\\\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Fragmented Consent and Fractured Rights: Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules in Light of the Booming Fintech Sector\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/\",\"name\":\"SCC Times\",\"description\":\"Bringing you the Best Analytical Legal News\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/#\\\/schema\\\/person\\\/84e42bab48238baf12c7e33b3d9761fe\",\"name\":\"Editor\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g\",\"caption\":\"Editor\"},\"url\":\"https:\\\/\\\/www.scconline.com\\\/blog\\\/post\\\/author\\\/editor_4\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules | SCC Times","description":"Analysis of regulatory overlap between Account Aggregators and Consent Managers under the DPDP framework and its impact on fintech.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/","og_locale":"en_US","og_type":"article","og_title":"Fragmented Consent and Fractured Rights: Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules in Light of the Booming Fintech Sector","og_description":"Analysis of regulatory overlap between Account Aggregators and Consent Managers under the DPDP framework and its impact on fintech.","og_url":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/","og_site_name":"SCC Times","article_publisher":"https:\/\/www.facebook.com\/scc.online\/","article_published_time":"2026-06-26T07:30:02+00:00","og_image":[{"width":886,"height":590,"url":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/Account-Aggregator-and-Consent-Manager-paradox.jpg","type":"image\/jpeg"}],"author":"Editor","twitter_card":"summary_large_image","twitter_title":"Fragmented Consent and Fractured Rights: Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules in Light of the Booming Fintech Sector","twitter_misc":{"Written by":"Editor","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/#article","isPartOf":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/"},"author":{"name":"Editor","@id":"https:\/\/www.scconline.com\/blog\/#\/schema\/person\/84e42bab48238baf12c7e33b3d9761fe"},"headline":"Fragmented Consent and Fractured Rights: Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules in Light of the Booming Fintech Sector","datePublished":"2026-06-26T07:30:02+00:00","mainEntityOfPage":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/"},"wordCount":318,"commentCount":0,"image":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/#primaryimage"},"thumbnailUrl":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/Account-Aggregator-and-Consent-Manager-paradox.webp","keywords":["account aggregator consent paradox","Account Aggregator framework India","Consent Manager DPDP Rules","data protection and financial information","DEPA account aggregator ecosystem","Digital Personal Data Protection Rules 2025","FinTech Compliance India","fintech data governance India","RBI DPDP regulatory overlap","SCC technology law analysis"],"articleSection":["Op Eds","OP. ED."],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/","url":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/","name":"Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules | SCC Times","isPartOf":{"@id":"https:\/\/www.scconline.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/#primaryimage"},"image":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/#primaryimage"},"thumbnailUrl":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/Account-Aggregator-and-Consent-Manager-paradox.webp","datePublished":"2026-06-26T07:30:02+00:00","author":{"@id":"https:\/\/www.scconline.com\/blog\/#\/schema\/person\/84e42bab48238baf12c7e33b3d9761fe"},"description":"Analysis of regulatory overlap between Account Aggregators and Consent Managers under the DPDP framework and its impact on fintech.","breadcrumb":{"@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/#primaryimage","url":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/Account-Aggregator-and-Consent-Manager-paradox.webp","contentUrl":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/Account-Aggregator-and-Consent-Manager-paradox.webp","width":886,"height":590,"caption":"Account Aggregator and Consent Manager paradox"},{"@type":"BreadcrumbList","@id":"https:\/\/www.scconline.com\/blog\/post\/2026\/06\/26\/account-aggregator-consent-manager-paradox-dpdp-rules-fintech-sector\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.scconline.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Fragmented Consent and Fractured Rights: Resolving the Account Aggregator-Consent Management Paradox under DPDP Rules in Light of the Booming Fintech Sector"}]},{"@type":"WebSite","@id":"https:\/\/www.scconline.com\/blog\/#website","url":"https:\/\/www.scconline.com\/blog\/","name":"SCC Times","description":"Bringing you the Best Analytical Legal News","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.scconline.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.scconline.com\/blog\/#\/schema\/person\/84e42bab48238baf12c7e33b3d9761fe","name":"Editor","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/34e366be721c41333586de05faa13743195f5b142dcd7a015c6fabd2389521d0?s=96&d=mm&r=g","caption":"Editor"},"url":"https:\/\/www.scconline.com\/blog\/post\/author\/editor_4\/"}]}},"jetpack_featured_media_url":"https:\/\/www.scconline.com\/blog\/wp-content\/uploads\/2026\/06\/Account-Aggregator-and-Consent-Manager-paradox.webp","jetpack_sharing_enabled":true,"jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts\/388597","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/users\/67011"}],"replies":[{"embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/comments?post=388597"}],"version-history":[{"count":2,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts\/388597\/revisions"}],"predecessor-version":[{"id":388601,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/posts\/388597\/revisions\/388601"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/media\/388598"}],"wp:attachment":[{"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/media?parent=388597"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/categories?post=388597"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.scconline.com\/blog\/wp-json\/wp\/v2\/tags?post=388597"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}