Home / Sectors / BFSI and lending
Lending and insurance businesses already carry regulatory obligations, which usually means some controls exist. The gap is rarely that nothing is documented. It is that what is documented was built for a different regulator, with a different purpose, and nobody has mapped it across.
The Act applies to every organisation that holds personal data. What reasonable looks like changes a great deal by sector, and this is what it changes to here.
What makes this sector different
NBFCs, lending platforms, insurance intermediaries, brokers and cooperative banks hold more categories of personal data than almost any other kind of small business. Identity documents, income proof, bank statements, credit decisions, collection notes and call recordings all sit in different systems, often with different vendors.
The customers here also carry the most risk if something leaks. A marketing list is embarrassing. A folder of identity documents and bank statements is a different order of problem, and it is usually the folder nobody remembered existed.
Where personal data usually sits
Drawn from engagements and from the questions that come up most often on first calls in this sector.
| System | What it holds | What usually needs attention |
|---|---|---|
| Loan origination system | Applications, identity and income documents, credit decisions, co-applicant details | Rejected applications held forever with the documents attached |
| Collections | Contact history, call recordings, field agent notes, references and guarantors | References were never told their details were taken, and recordings have no notice |
| Agent network | Customer data handled by people outside your payroll | Agents work from personal phones, with no contract covering data |
| Credit bureau and KYC vendors | Data sent to and received from third parties | No written data terms, and no record of what was sent when |
| Customer support | Chat transcripts, email history, complaint records, call recordings | Recordings kept indefinitely with no stated retention |
| Marketing | Lead lists, pre-approved offer lists, cross-sell segments | Lists bought or imported with no recorded origin |
What we look at first here
Identity documents in the wrong place. Scans of identity and address proof end up in shared drives, email threads and WhatsApp during a rush, and stay there.
Agents operating outside your controls. If someone collects customer data on your behalf, you remain answerable for what happens to it, including on their personal device.
References and guarantors. These people never applied for anything. They were named by someone else, and most lenders have never told them their details are held.
Rejected applications. The richest and least useful data in the business. There is usually no rule that ever deletes it.
Which steps carry the most weight
The full sequence is on the engagement page. In this sector, these three usually do the heavy lifting.
Discovery and mapping
The agent and vendor layer is where the surprises are. We map the whole chain, including people who are not your employees.
Gasp Assessment
Your existing regulatory documentation gets tested against what the data protection position actually requires, so you reuse what works rather than starting again.
Compliance Support
Notices at application and at collection, retention rules that finally delete rejected applications, and data terms for your agent and vendor agreements.
Existing regulatory compliance is an advantage here, not a complication. Much of what you already do for your sector regulator can be mapped across rather than rebuilt, and part of our job is to tell you which parts those are so you are not paying twice.
Not quite your business?
Every engagement is scoped to what you actually run, so none of these pages will match you exactly.
Thirty minutes, and you will know where you stand.
Tell us what your business runs on. We will tell you which gaps matter most, whether or not you engage us.