New Delhi: Banks, non-banking financial companies (NBFCs) and credit bureaus will have to tag every piece of customer data at the point of collection, recording who owns it, why it was taken, how sensitive it is, how long it may be kept and whether the customer consented. Those tags will have to travel with the data into every system it moves to, under a draft guidance released Wednesday by the Reserve Bank of India (RBI).

The central bank has invited comments from regulated entities and the public on the draft ‘Guidance on Regulatory Expectations for Data Governance’. The comments can be submitted until 17 August.The draft policy arrives 10 months before the deadline for stakeholders to comply with privacy norms proposed by the Digital Personal Data Protection (DPDP) Rules. The DPDP Rules were notified in November 2025 with an 18-month runway, taking the compliance date to May 2027. Under the DPDP Act, 2023, failure to maintain security safeguards for personal data attracts a penalty of up to Rs 250 crore.

Through the draft, the RBI does not restate that law. It sets out the systems lenders will need to comply with it.

Also Read: Meta & WhatsApp step back, tell SC they’ll comply with take-it-or-leave-it NCLAT privacy order