Your NBFC touches customer info more than you think — here's why that matters.
Think about the last time your NBFC sent a repayment reminder on WhatsApp. Or when your call centre called a customer to verify their Aadhaar. Or when a support agent opened a loan file. Each of these moments uses a customer's personal information. Under the new DPDP law, every single one of these moments counts. If something goes wrong, your business is responsible.
Say your NBFC sends a repayment reminder via WhatsApp. That message uses the customer's phone number and loan details. Your call centre calls to verify a PAN card — that is another data moment. A support ticket is opened with the customer's Aadhaar copy — that is another one. Each step involves your team or an outside vendor touching personal information. The DPDP law says you must track all these moments. You must also make sure your vendors handle this information safely.
List every way your team contacts customers — SMS, call, WhatsApp, email.
Check if your call centre or vendor has a data safety agreement signed.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“Every customer communication trail is also a data-use trail.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.