{"id":163,"date":"2026-04-28T11:39:49","date_gmt":"2026-04-28T11:39:49","guid":{"rendered":"https:\/\/blog.osto.one\/?p=163"},"modified":"2026-05-05T10:12:50","modified_gmt":"2026-05-05T10:12:50","slug":"dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/","title":{"rendered":"DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027)"},"content":{"rendered":"<p style=\"font-size:17px;line-height:1.75;color:#333;\">India&#8217;s data protection law isn&#8217;t coming. It&#8217;s here.<\/p>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">The Digital Personal Data Protection Act was passed in 2023. The Data Protection Board is operational. Full enforcement, including penalty powers, is anticipated around May 2027. For a fintech processing financial data on millions of Indian users \u2014 most platforms haven&#8217;t started.<\/p>\n<p> It&#8217;s a practical map: what DPDPA actually requires, what&#8217;s genuinely new versus what overlaps with obligations you already have, and how to build toward compliance without treating it as a separate project.<\/p>\n<h2 style=\"font-size:22px;font-weight:600;color:#111;margin:40px 0 14px;padding-bottom:10px;border-bottom:2px solid #EEF1FB;\">Why fintechs specifically are in focus<\/h2>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">DPDPA classifies data into two tiers. General personal data gets baseline protections. Sensitive personal data, which explicitly includes financial data, gets stricter treatment.<\/p>\n<p><!-- SENSITIVE DATA CALLOUT --><\/p>\n<div style=\"background:#FFF8F8;border-left:5px solid #D94040;padding:20px 24px;margin:24px 0;border-radius:2px;\">\n<p style=\"font-size:14px;font-weight:700;color:#D94040;margin:0 0 10px;text-transform:uppercase;letter-spacing:0.08em;\">If your platform handles any of the following, you&#8217;re processing sensitive personal data:<\/p>\n<div style=\"display:flex;flex-wrap:wrap;gap:8px;\">\n    <span style=\"background:#D94040;color:white;font-size:13px;padding:4px 12px;border-radius:2px;\">Bank account details<\/span><br \/>\n    <span style=\"background:#D94040;color:white;font-size:13px;padding:4px 12px;border-radius:2px;\">Credit card numbers<\/span><br \/>\n    <span style=\"background:#D94040;color:white;font-size:13px;padding:4px 12px;border-radius:2px;\">Income \/ salary information<\/span><br \/>\n    <span style=\"background:#D94040;color:white;font-size:13px;padding:4px 12px;border-radius:2px;\">Transaction histories<\/span><br \/>\n    <span style=\"background:#D94040;color:white;font-size:13px;padding:4px 12px;border-radius:2px;\">Loan or credit records<\/span><br \/>\n    <span style=\"background:#D94040;color:white;font-size:13px;padding:4px 12px;border-radius:2px;\">Financial condition data<\/span>\n  <\/div>\n<p style=\"font-size:14px;color:#555;margin:12px 0 0;line-height:1.6;\">That&#8217;s most of what a fintech does. Your entire core dataset is sensitive personal data. Higher security standards, more rigorous consent requirements, larger potential penalties.<\/p>\n<\/div>\n<h2 style=\"font-size:22px;font-weight:600;color:#111;margin:40px 0 14px;padding-bottom:10px;border-bottom:2px solid #EEF1FB;\">The five obligations that require infrastructure, not just policy<\/h2>\n<p><!-- FIVE OBLIGATIONS --><\/p>\n<div style=\"margin:20px 0 36px;display:flex;flex-direction:column;gap:8px;\">\n<div style=\"border:1px solid #EEF1FB;padding:18px 20px;border-radius:2px;\">\n<div style=\"display:flex;align-items:center;gap:10px;margin-bottom:8px;\">\n      <span style=\"background:#1C267A;color:white;font-size:12px;font-weight:700;width:24px;height:24px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">1<\/span><\/p>\n<div style=\"font-size:15px;font-weight:600;color:#111;\">Security safeguards<\/div>\n<\/p><\/div>\n<p style=\"font-size:14px;color:#555;margin:0;line-height:1.65;\">The act requires &#8216;reasonable security safeguards to prevent personal data breach.&#8217; For a fintech handling financial data, reasonable means: active application protection, endpoint security on devices accessing customer data, continuous monitoring, strong access controls, and documented incident response. If you&#8217;re already doing this for RBI compliance, DPDPA&#8217;s security requirement is largely covered.<\/p>\n<\/p><\/div>\n<div style=\"border:1px solid #EEF1FB;padding:18px 20px;border-radius:2px;\">\n<div style=\"display:flex;align-items:center;gap:10px;margin-bottom:8px;\">\n      <span style=\"background:#D94040;color:white;font-size:12px;font-weight:700;width:24px;height:24px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">2<\/span><\/p>\n<div style=\"font-size:15px;font-weight:600;color:#111;\">Breach notification <span style=\"font-size:12px;font-weight:400;color:#D94040;margin-left:6px;\">\u2014 where most fintechs will be underprepared<\/span><\/div>\n<\/p><\/div>\n<p style=\"font-size:14px;color:#555;margin:0;line-height:1.65;\">You must notify both the Data Protection Board and affected users of a personal data breach. Expected timeline: 72 hours for the board notification. The clock may start from when you reasonably should have known, not when you confirmed the breach. Without automated detection, real-time alerting, and a pre-built notification workflow, 72 hours is nearly impossible to meet.<\/p>\n<\/p><\/div>\n<div style=\"border:1px solid #EEF1FB;padding:18px 20px;border-radius:2px;\">\n<div style=\"display:flex;align-items:center;gap:10px;margin-bottom:8px;\">\n      <span style=\"background:#1C267A;color:white;font-size:12px;font-weight:700;width:24px;height:24px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">3<\/span><\/p>\n<div style=\"font-size:15px;font-weight:600;color:#111;\">Consent management<\/div>\n<\/p><\/div>\n<p style=\"font-size:14px;color:#555;margin:0;line-height:1.65;\">Personal data can only be processed with explicit consent or specific exemptions. The transaction exemption is broad \u2014 you can process the bank account number to execute the payment. What isn&#8217;t covered: using customer transaction data to train credit scoring models without disclosure, selling aggregated data to third parties for marketing, or using financial behaviour data for insurance underwriting without specific consent.<\/p>\n<\/p><\/div>\n<div style=\"border:1px solid #EEF1FB;padding:18px 20px;border-radius:2px;\">\n<div style=\"display:flex;align-items:center;gap:10px;margin-bottom:8px;\">\n      <span style=\"background:#1C267A;color:white;font-size:12px;font-weight:700;width:24px;height:24px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">4<\/span><\/p>\n<div style=\"font-size:15px;font-weight:600;color:#111;\">Data principal rights<\/div>\n<\/p><\/div>\n<p style=\"font-size:14px;color:#555;margin:0;line-height:1.65;\">Your users will have the right to access their data on request, correct inaccurate data, and have their data erased when it&#8217;s no longer necessary. Erasure rights interact with RBI record-keeping obligations \u2014 you likely have legally mandated retention periods for transaction records. DPDPA provides exemptions for legally required retention, but you still need a workflow that distinguishes between data you must keep and data you can delete.<\/p>\n<\/p><\/div>\n<div style=\"border:1px solid #EEF1FB;padding:18px 20px;border-radius:2px;\">\n<div style=\"display:flex;align-items:center;gap:10px;margin-bottom:8px;\">\n      <span style=\"background:#1C267A;color:white;font-size:12px;font-weight:700;width:24px;height:24px;border-radius:50%;display:flex;align-items:center;justify-content:center;flex-shrink:0;\">5<\/span><\/p>\n<div style=\"font-size:15px;font-weight:600;color:#111;\">Cross-border data transfers<\/div>\n<\/p><\/div>\n<p style=\"font-size:14px;color:#555;margin:0;line-height:1.65;\">Will be restricted to approved countries once implementing rules are published. If you use US-based fraud detection vendors, data enrichment services, or any infrastructure that your customer data flows through, map those data flows now, before the rules land.<\/p>\n<\/p><\/div>\n<\/div>\n<h2 style=\"font-size:22px;font-weight:600;color:#111;margin:40px 0 14px;padding-bottom:10px;border-bottom:2px solid #EEF1FB;\">The penalty structure is not symbolic<\/h2>\n<p><!-- PENALTY TABLE --><\/p>\n<div style=\"overflow-x:auto;margin:20px 0 28px;\">\n<table style=\"width:100%;border-collapse:collapse;font-size:14px;font-family:inherit;\">\n<thead>\n<tr>\n<th style=\"background:#1C267A;color:white;padding:12px 16px;text-align:left;font-weight:600;font-size:13px;width:55%;\">Violation<\/th>\n<th style=\"background:#D94040;color:white;padding:12px 16px;text-align:left;font-weight:600;font-size:13px;width:45%;\">Max Penalty<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #EEF1FB;color:#333;background:white;\">Failure to implement security safeguards resulting in a data breach<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #EEF1FB;font-weight:700;color:#D94040;background:#FFF8F8;\">\u20b9250 crore<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;border-bottom:1px solid #EEF1FB;color:#333;background:white;\">Failure to notify the Data Protection Board<\/td>\n<td style=\"padding:12px 16px;border-bottom:1px solid #EEF1FB;font-weight:700;color:#D94040;background:#FFF8F8;\">\u20b9200 crore<\/td>\n<\/tr>\n<tr>\n<td style=\"padding:12px 16px;color:#333;background:white;\">Failure to notify affected users<\/td>\n<td style=\"padding:12px 16px;font-weight:700;color:#D94040;background:#FFF8F8;\">\u20b9200 crore<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2 style=\"font-size:22px;font-weight:600;color:#111;margin:40px 0 14px;padding-bottom:10px;border-bottom:2px solid #EEF1FB;\">What DPDPA adds on top of RBI obligations<\/h2>\n<p><!-- COMPARISON --><\/p>\n<div style=\"display:flex;gap:12px;margin:20px 0 32px;flex-wrap:wrap;\">\n<div style=\"flex:1;min-width:220px;background:#EEF1FB;border-top:4px solid #1C267A;padding:20px 22px;border-radius:2px;\">\n<div style=\"font-size:11px;font-weight:700;letter-spacing:0.15em;text-transform:uppercase;color:#1C267A;margin-bottom:10px;\">RBI covers<\/div>\n<p style=\"font-size:14px;color:#333;margin:0;line-height:1.65;\">Protecting your systems and reporting incidents to the regulator. Security infrastructure, incident response, VAPT.<\/p>\n<\/p><\/div>\n<div style=\"flex:1;min-width:220px;background:#FFF8F8;border-top:4px solid #D94040;padding:20px 22px;border-radius:2px;\">\n<div style=\"font-size:11px;font-weight:700;letter-spacing:0.15em;text-transform:uppercase;color:#D94040;margin-bottom:10px;\">DPDPA adds<\/div>\n<p style=\"font-size:14px;color:#333;margin:0;line-height:1.65;\">Obligations to notify users whose data was compromised, and consent and data subject rights infrastructure \u2014 entirely new for Indian fintechs.<\/p>\n<\/p><\/div>\n<\/div>\n<p style=\"font-size:17px;line-height:1.75;color:#333;\">The security infrastructure overlap is significant. One comprehensive programme satisfies both. The consent and data rights infrastructure is genuinely new work. If you don&#8217;t have it, RBI compliance doesn&#8217;t help you here.<\/p>\n<h2 style=\"font-size:22px;font-weight:600;color:#111;margin:40px 0 14px;padding-bottom:10px;border-bottom:2px solid #EEF1FB;\">The 13-month roadmap<\/h2>\n<p><!-- ROADMAP --><\/p>\n<div style=\"margin:20px 0 32px;display:flex;flex-direction:column;gap:2px;\">\n<div style=\"display:flex;align-items:flex-start;gap:16px;padding:16px 18px;background:#FAFBFF;border:1px solid #EEF1FB;\">\n<div style=\"min-width:80px;flex-shrink:0;\">\n<div style=\"font-size:11px;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#1C267A;\">Months 1\u20133<\/div>\n<\/p><\/div>\n<div>\n<div style=\"font-size:15px;font-weight:600;color:#111;margin-bottom:4px;\">Data mapping<\/div>\n<div style=\"font-size:14px;color:#555;line-height:1.6;\">What personal and sensitive personal data do you collect? Where is it stored? Which vendors process it? Which countries does it flow to? You cannot comply without knowing your data flows.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div style=\"display:flex;align-items:flex-start;gap:16px;padding:16px 18px;background:#FAFBFF;border:1px solid #EEF1FB;\">\n<div style=\"min-width:80px;flex-shrink:0;\">\n<div style=\"font-size:11px;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#1C267A;\">Months 3\u20136<\/div>\n<\/p><\/div>\n<div>\n<div style=\"font-size:15px;font-weight:600;color:#111;margin-bottom:4px;\">Consent audit and redesign<\/div>\n<div style=\"font-size:14px;color:#555;line-height:1.6;\">Review every consent touchpoint in your product against DPDPA requirements. Identify secondary data uses that need specific consent. Redesign the flows that don&#8217;t meet the standard.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div style=\"display:flex;align-items:flex-start;gap:16px;padding:16px 18px;background:#FAFBFF;border:1px solid #EEF1FB;\">\n<div style=\"min-width:80px;flex-shrink:0;\">\n<div style=\"font-size:11px;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#1C267A;\">Months 4\u20138<\/div>\n<\/p><\/div>\n<div>\n<div style=\"font-size:15px;font-weight:600;color:#111;margin-bottom:4px;\">Security infrastructure<\/div>\n<div style=\"font-size:14px;color:#555;line-height:1.6;\">Commission a VAPT scoped to your personal data processing systems. Implement or verify WAF coverage, endpoint protection, and continuous monitoring. Build the breach detection capability that makes 72-hour notification achievable.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div style=\"display:flex;align-items:flex-start;gap:16px;padding:16px 18px;background:#FAFBFF;border:1px solid #EEF1FB;\">\n<div style=\"min-width:80px;flex-shrink:0;\">\n<div style=\"font-size:11px;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#1C267A;\">Months 8\u201311<\/div>\n<\/p><\/div>\n<div>\n<div style=\"font-size:15px;font-weight:600;color:#111;margin-bottom:4px;\">Breach notification workflow<\/div>\n<div style=\"font-size:14px;color:#555;line-height:1.6;\">Who gets alerted? Who files the DPB notification? What does user notification look like in practice? Run a tabletop exercise. Work through every step.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div style=\"display:flex;align-items:flex-start;gap:16px;padding:16px 18px;background:#FAFBFF;border:1px solid #EEF1FB;\">\n<div style=\"min-width:80px;flex-shrink:0;\">\n<div style=\"font-size:11px;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#1C267A;\">Months 11\u201313<\/div>\n<\/p><\/div>\n<div>\n<div style=\"font-size:15px;font-weight:600;color:#111;margin-bottom:4px;\">Data rights infrastructure<\/div>\n<div style=\"font-size:14px;color:#555;line-height:1.6;\">Build the ability to export a user&#8217;s full data record, update it on request, and delete it subject to legal holds. These are product engineering tasks, not documentation tasks.<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p><!-- PULL QUOTE --><\/p>\n<blockquote style=\"margin:36px 0;padding:24px 28px;background:#EEF1FB;border-left:5px solid #1C267A;border-radius:2px;\">\n<p style=\"font-size:18px;font-style:italic;font-weight:500;color:#1C267A;margin:0;line-height:1.7;\">The May 2027 deadline feels distant until it doesn&#8217;t. Companies that start now can build toward compliance steadily. Companies that start in late 2026 will be running a sprint, and sprints in regulated environments miss things.<\/p>\n<\/blockquote>\n<p><!-- SUBTLE OSTO PLUG --><\/p>\n<p style=\"font-size:15px;line-height:1.75;color:#777;border-top:1px solid #EEF1FB;padding-top:24px;margin-top:40px;font-style:italic;\">The security infrastructure layer of DPDPA \u2014 WAF, endpoint protection, continuous monitoring, VAPT, incident response \u2014 is what <a href=\"https:\/\/osto.one\" style=\"color:#1C267A;text-decoration:none;font-weight:500;\">Osto<\/a> deploys and runs for Indian fintech teams, so months 4\u20138 of this roadmap don&#8217;t have to be the hard part.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>India&#8217;s data protection law isn&#8217;t coming. It&#8217;s here. The Digital Personal Data Protection Act was passed in 2023. The Data\u2026<\/p>\n","protected":false},"author":5,"featured_media":240,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12,40],"tags":[],"class_list":["post-163","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-fintech"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.6 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027) - Osto<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027) - Osto\" \/>\n<meta property=\"og:description\" content=\"India&#8217;s data protection law isn&#8217;t coming. It&#8217;s here. The Digital Personal Data Protection Act was passed in 2023. The Data\u2026\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/\" \/>\n<meta property=\"og:site_name\" content=\"Osto\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-28T11:39:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-05T10:12:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_16_00-AM.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1536\" \/>\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Ansh Satwani\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ansh Satwani\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/\"},\"author\":{\"name\":\"Ansh Satwani\",\"@id\":\"https:\/\/www.osto.one\/resources\/#\/schema\/person\/4e82cd35cf60206ad1232e7d2d255144\"},\"headline\":\"DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027)\",\"datePublished\":\"2026-04-28T11:39:49+00:00\",\"dateModified\":\"2026-05-05T10:12:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/\"},\"wordCount\":846,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.osto.one\/resources\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_16_00-AM.png\",\"articleSection\":[\"Blog\",\"Fintech\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/\",\"url\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/\",\"name\":\"DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027) - Osto\",\"isPartOf\":{\"@id\":\"https:\/\/www.osto.one\/resources\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_16_00-AM.png\",\"datePublished\":\"2026-04-28T11:39:49+00:00\",\"dateModified\":\"2026-05-05T10:12:50+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#primaryimage\",\"url\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_16_00-AM.png\",\"contentUrl\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_16_00-AM.png\",\"width\":1536,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.osto.one\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.osto.one\/resources\/#website\",\"url\":\"https:\/\/www.osto.one\/resources\/\",\"name\":\"Osto\",\"description\":\"Osto secures apps, networks, and endpoints with an integrated platform built for modern teams.\",\"publisher\":{\"@id\":\"https:\/\/www.osto.one\/resources\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.osto.one\/resources\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.osto.one\/resources\/#organization\",\"name\":\"Osto\",\"url\":\"https:\/\/www.osto.one\/resources\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.osto.one\/resources\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/01\/cropped-osto-blue-21-edited.png\",\"contentUrl\":\"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/01\/cropped-osto-blue-21-edited.png\",\"width\":1144,\"height\":428,\"caption\":\"Osto\"},\"image\":{\"@id\":\"https:\/\/www.osto.one\/resources\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.osto.one\/resources\/#\/schema\/person\/4e82cd35cf60206ad1232e7d2d255144\",\"name\":\"Ansh Satwani\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.osto.one\/resources\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/febb3eb0d31b99257e1d641255c28ad967bb930f531f6f2997f0bea21fd977c9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/febb3eb0d31b99257e1d641255c28ad967bb930f531f6f2997f0bea21fd977c9?s=96&d=mm&r=g\",\"caption\":\"Ansh Satwani\"},\"url\":\"https:\/\/www.osto.one\/resources\/author\/ansh\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027) - Osto","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/","og_locale":"en_US","og_type":"article","og_title":"DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027) - Osto","og_description":"India&#8217;s data protection law isn&#8217;t coming. It&#8217;s here. The Digital Personal Data Protection Act was passed in 2023. The Data\u2026","og_url":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/","og_site_name":"Osto","article_published_time":"2026-04-28T11:39:49+00:00","article_modified_time":"2026-05-05T10:12:50+00:00","og_image":[{"width":1536,"height":1024,"url":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_16_00-AM.png","type":"image\/png"}],"author":"Ansh Satwani","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ansh Satwani","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#article","isPartOf":{"@id":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/"},"author":{"name":"Ansh Satwani","@id":"https:\/\/www.osto.one\/resources\/#\/schema\/person\/4e82cd35cf60206ad1232e7d2d255144"},"headline":"DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027)","datePublished":"2026-04-28T11:39:49+00:00","dateModified":"2026-05-05T10:12:50+00:00","mainEntityOfPage":{"@id":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/"},"wordCount":846,"commentCount":0,"publisher":{"@id":"https:\/\/www.osto.one\/resources\/#organization"},"image":{"@id":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#primaryimage"},"thumbnailUrl":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_16_00-AM.png","articleSection":["Blog","Fintech"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/","url":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/","name":"DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027) - Osto","isPartOf":{"@id":"https:\/\/www.osto.one\/resources\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#primaryimage"},"image":{"@id":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#primaryimage"},"thumbnailUrl":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_16_00-AM.png","datePublished":"2026-04-28T11:39:49+00:00","dateModified":"2026-05-05T10:12:50+00:00","breadcrumb":{"@id":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#primaryimage","url":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_16_00-AM.png","contentUrl":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/04\/ChatGPT-Image-May-1-2026-11_16_00-AM.png","width":1536,"height":1024},{"@type":"BreadcrumbList","@id":"https:\/\/www.osto.one\/resources\/blog\/dpdpa-for-fintechs-what-the-rs-250-crore-penalty-means-for-your-platform-and-what-to-do-before-may-2027\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.osto.one\/resources\/"},{"@type":"ListItem","position":2,"name":"DPDPA for Fintechs: What the Rs 250 Crore Penalty Means for Your Platform (And What to Do Before May 2027)"}]},{"@type":"WebSite","@id":"https:\/\/www.osto.one\/resources\/#website","url":"https:\/\/www.osto.one\/resources\/","name":"Osto","description":"Osto secures apps, networks, and endpoints with an integrated platform built for modern teams.","publisher":{"@id":"https:\/\/www.osto.one\/resources\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.osto.one\/resources\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.osto.one\/resources\/#organization","name":"Osto","url":"https:\/\/www.osto.one\/resources\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.osto.one\/resources\/#\/schema\/logo\/image\/","url":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/01\/cropped-osto-blue-21-edited.png","contentUrl":"https:\/\/www.osto.one\/resources\/wp-content\/uploads\/2026\/01\/cropped-osto-blue-21-edited.png","width":1144,"height":428,"caption":"Osto"},"image":{"@id":"https:\/\/www.osto.one\/resources\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.osto.one\/resources\/#\/schema\/person\/4e82cd35cf60206ad1232e7d2d255144","name":"Ansh Satwani","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.osto.one\/resources\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/febb3eb0d31b99257e1d641255c28ad967bb930f531f6f2997f0bea21fd977c9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/febb3eb0d31b99257e1d641255c28ad967bb930f531f6f2997f0bea21fd977c9?s=96&d=mm&r=g","caption":"Ansh Satwani"},"url":"https:\/\/www.osto.one\/resources\/author\/ansh\/"}]}},"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=163"}],"version-history":[{"count":2,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/163\/revisions"}],"predecessor-version":[{"id":165,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/163\/revisions\/165"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/240"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=163"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}