Summary
RBI Governor Sanjay Malhotra told fintech representatives at the Global Fintech Fest 2026 to treat consumer data as a "fiduciary responsibility," not a business asset and warned against the strategy of "scaling first and seeking clarity or forgiveness later." He pointed to the Account Aggregator framework as the model for consent-based, purpose-limited data sharing.
WHY IN NEWS FOR UPSC & STATE PCS
The statement marks a visible shift in RBI's regulatory posture - from the sandbox-era light touch that helped fintechs scale, toward explicit warnings about data exploitation and regulatory arbitrage now that non-bank fintechs and digital lenders have grown systemically significant. SEBI Chairman Tuhin Kanta Pandey was present alongside Malhotra at the event.
Standard News
The Same Regulator That Enabled Fintech's Speed Just Asked It to Slow Down Here's the
contradiction sitting underneath Sanjay Malhotra's speech: the RBI's own regulatory sandbox is part of what let India's fintech sector scale as fast as it has. On Thursday, the RBI Governor stood in front of that same sector and told it, in effect, that scale itself is now the liability - because a fintech holding financial and non-financial data on millions of people isn't just running a business anymore, it's running something closer to a public utility with private incentives.
Who's Actually
Affected by This Reframing This isn't really a message for large, already-compliant institutions. It's aimed squarely at the mid-sized and growth-stage digital lenders and payment platforms that built their competitive edge on aggressive data use - alternative credit scoring from non-financial data, aggressive cross-selling, product recommendations built on behavioural data most users never explicitly consented to in a meaningful way.
For a fintech whose valuation story depends partly on "we know our users better than banks do," Malhotra's fiduciary framing isn't a compliance footnote - it's a direct challenge to the business model.
The Actual Mechanism: From Asset to Trust
Malhotra's specific phrase - treat data "the way a trustee treats assets held for a beneficiary"
- describes a real legal shift in obligation, not just a tone change. A business asset can be monetised within the bounds of consent language buried in a terms-of-service document. A fiduciary duty requires the data holder to act in the user's interest even where that interest isn't explicitly stated - a materially higher bar. The Account Aggregator framework is RBI's working proof-of-concept for this: it structurally prevents even the aggregator itself from reading the data it moves, making the "trust" enforceable through architecture, not just policy language.
Is Regulation Actually Catching Up or Still Behind?
The honest answer is: partially. The Account Aggregator model shows RBI can build consent-based infrastructure that scales. But Malhotra's own warning - against "scaling first, seeking forgiveness later"
- is itself an admission that a meaningful share of the fintech sector is still operating in that gap, outside AA-style architecture, on data practices closer to the "asset" model he's now discouraging. The Digital Personal Data Protection Act, 2023 provides the statutory backbone, but its rules and enforcement mechanics for financial data specifically are still catching up to how fast lending and payment platforms have scaled their user bases. So the honest read isn't "RBI has solved fintech data governance." It's that RBI has built one working model (AA) and is now using moral and regulatory pressure to push the rest of the sector toward it, because rule-writing alone hasn't kept pace with how quickly some fintechs became systemically significant. For an aspirant, that gap - between having a good framework and having universal compliance with it - is the actual governance story, not the speech itself.
Quick Facts
Key numbers & takeaways — revise these first
-
Speaker: RBI Governor Sanjay Malhotra, at the Global Fintech Fest 2026, Mumbai.
-
Core message: treat consumer data as a fiduciary responsibility, not a monetisable business asset.
-
Warning issued: against fintechs "scaling first and seeking clarity or forgiveness later." Regulatory model cited: the Account Aggregator (AA) framework - consent-based, purpose-limited data sharing.
-
Related law: Digital Personal Data Protection Act, 2023.
-
Also present: SEBI Chairman Tuhin Kanta Pandey.
Connect the dots for your UPSC preparation.
Standard news covers the event. Log in to read our comprehensive analysis and uncover the hidden constitutional, structural, and ethical dimensions of this topic:
The specific structural comparison between the Account Aggregator model's consent architecture and how a typical non-AA fintech currently handles user data.
The full critical analysis of where India's data-governance framework is ahead of global peers and where it still lags fintech's systemic footprint.
The case study connecting the Puttaswamy privacy judgment's constitutional basis to how the DPDP Act and AA framework operationalise it for financial data.
The complete way-forward on what a binding, RBI-enforced timeline for AA-model adoption across all significant fintechs could look like.
Included in this analysis
Join thousands of aspirants analyzing the news deeply.
Log In to Read Full ArticleDon't have an account? Sign up for free