Independent Research and Policy Advocacy

Comments to the Draft Guidance on Regulatory Expectations for Data Governance

Save Post

Abstract

On 15 July 2026, the Reserve Bank of India (RBI) released the “Draft Guidance on Regulatory Expectations for Data Governance(hereafter “the Guidance“). This Guidance establishes expectations for data governance across banks, NBFCs, cooperative banks, financial institutions, asset reconstruction companies and credit information companies. It requires a Board-approved Data Governance Framework (DGF) aligned with risk management, supported by Board oversight, Executive Committee and assigned Data Owners, Stewards and Custodians. Data must be governed throughout its lifecycle, from origination, processing to retention and deletion.

Summary of Recommendations

  1. Despite multiple frameworks, customer harms from data misuse may remain unaddressed. Typically, the data protection frameworks and authorities oversee the issue of redressing and compensating customers for privacy-led financial harms. However, the Digital Personal Data Protection Act, 2023 and the attendant Data Protection Board, do not allow for compensating customers on account of data-driven financial losses. Under such circumstances, the RBIIntegrated Ombudsman Scheme, 2026 promises to be a viable channel. However, it may be prohibitively onerous for an aggrieved customer to establish data-driven harms such as discriminatory loan pricing. These outcomes often become intricately linked to the lender’s “commercial judgment”, which (rightly) remains out of the scope of the Integrated Ombudsman.As such, it is currently unclear how and if at all, customers can be compensated for data-related harms that result in financial losses such as in discriminatory loan pricing, losses due to financial breach etc. The Guidance could consider defining “harm”, consistently across this and the model risk management framework, categorically empower and equip the Ombudsman to accept complaints of harm, assess them through appropriate technological tools and share the burden of proof more symmetrically between the Ombudsman and the complainant.
  2. Proportionate regulations may be complemented with minimum standards. It is very welcome that the Guidance is anchored in a strong notion of proportionality. It recommends that the safeguards be proportionate to the size, complexity, IT infrastructure of the organisation and the criticality of the data. However, advances in artificial intelligence (AI) have rendered cyber-offensive strategies cheap and easily accessible. These attacks often pry on the weakest link in the value chain. An employee email, for instance or shared drives that do not necessarily strike as critical may become easy targets for AI-led cyber-attacks. The Guidance could, therefore, consider laying out minimum, baseline safeguards for all organisations, assets and data types, and any safeguards beyond the baseline should be in tandem with the risk carried by the organisation or the asset or the data type. Where smaller organisations struggle for monetary or tech resources to meet the baseline safeguards, development funds and meaningful capacity building exercises could be considered to help them bridge the gap. A readily exploitable vulnerability anywhere has the potential to cascade into a grave system-wide threat.
  3. Harmonizing related and adjacent frameworks to build an integrated data risk management framework. We appreciate that the Guidance is one of the many instruments in the suite of frameworks designed to address data-related risks. It is essential that the different frameworks operate in harmony, do not pose conflicts or require duplication of efforts. For instance, incidents’ are likely to be interconnected, exhibiting dual properties of cyber and data incidents. In those circumstances, it is important for Regulated Entities (REs) to understand the integrated protocol to enable thorough investigation, timely communication to regulators and customers, and customer remediation.

Read the full response here

Authors :

Tags :

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts :