India’s banks to adopt customer-controlled delegated authority amid data protection reforms

Indian banks are developing a delegated-authority system to comply with the Digital Personal Data Protection Act, aiming to formalise trusted relationships and enhance operational security amid new legal requirements.

India’s banks are being pushed to draw a sharper line between trust and formal authority as the country’s new data protection regime takes hold. A familiar scene at a branch counter now carries legal risk: a spouse, child, accountant or office assistant arrives to collect a document, but the bank must decide whether that person is merely known to staff or properly empowered to receive financial information.

That tension matters because the Digital Personal Data Protection Act, 2023, and the rules notified by the Ministry of Electronics and Information Technology in November 2025 create a consent-based framework for handling digital personal data. According to PwC, those rules set out operational requirements for data fiduciaries, including breach reporting, cross-border transfers and the functioning of the Data Protection Board of India. The NIST Privacy Framework likewise notes that the rules operationalise the Act, with substantive compliance expected to shape how organisations handle personal information in practice.

For banks, the issue is especially acute because routine documents such as account statements, loan schedules and KYC records can reveal sensitive personal data. The original article argues that India’s relationship-based banking culture has long allowed relatives and trusted employees to act informally on behalf of customers, but that practice is harder to reconcile with a regime that expects explicit authority. That gap is not limited to individual households. It also affects proprietorships, partnerships, limited liability partnerships and companies, where representatives often collect paperwork without a formal digital mechanism that ties authorisation to the customer’s own instructions.

The article’s proposed answer is a delegated-authority system built into banks’ internet and mobile platforms. Under that model, customers could register authorised recipients through one-time password authentication, choose which documents may be collected, set expiry periods and revoke permissions instantly. Such a system would also create an audit trail, reducing disputes at the counter and giving staff a clearer basis for compliance. The broader point is that the DPDP regime is not meant to stop families or businesses from sharing routine banking tasks; it is meant to make that sharing explicit, verifiable and controlled by the customer.

With the rules in place and the compliance deadline approaching, banks have an opportunity to fix an operational blind spot before it turns into a recurring source of friction. India has already normalised digital payments, electronic mandates and online customer authentication. Extending that infrastructure to delegated authority would be a logical next step, turning informal trust into documented permission and making everyday banking both safer and more efficient.

Disclaimer: This article is intended to inform and educate, not to recommend or endorse any financial product, investment or strategy. Please consider your own financial circumstances and seek professional advice where appropriate before making financial decisions.