Key Points
- RBI Governor warns fintechs against treating user data as monetisable business asset
- Malhotra criticises strategy of scaling first and seeking regulatory forgiveness later
- Account aggregator framework cited as model for consent-based data sharing
Reserve Bank of India Governor Sanjay Malhotra has urged fintech companies to treat customer data as a “fiduciary responsibility” rather than a business asset, warning that exploiting regulatory gaps to scale operations is not an acceptable strategy.
Speaking at the Global Fintech Fest in Mumbai on Thursday, Malhotra said fintechs hold something far more valuable than capital: the financial and non-financial data of ordinary citizens. Fiduciary responsibility, a legal and ethical obligation to act in the best interests of another party, places the duty of care on the entity holding the data rather than on the individual who provided it.
“I would urge all of you to treat data as a fiduciary responsibility, not as a business asset. Every fintech in this room holds something which is much more valuable than capital, and that is the data, financial as well as non-financial, of very real people like you and me,” Malhotra said.
The RBI Governor compared the duty to that of a trustee managing assets for a beneficiary. Data must be collected with a clear purpose, used strictly within the consent provided and protected as though it were one’s own, he said.
Malhotra warned that treating data primarily as a monetisable asset erodes consumer trust, which is then difficult to rebuild. Several fintech players, banks and Non-Banking Financial Company (NBFC) have faced scrutiny for aggressive data collection practices and the use of customer information to push not only the new financial products but also blatantly misusing and passing it to Direct Selling Agent (DSA).
Regulatory guidance
The RBI Governor also cautioned fintechs against building business models that depend on exploiting gaps in the regulatory framework. The strategy of scaling first and seeking clarity or forgiveness later was not acceptable, he said.
Malhotra pointed to the account aggregator framework as a model for responsible data handling. Account aggregators are RBI-regulated entities that enable consent-based sharing of financial data between institutions without themselves being able to access or store the underlying information. The framework was designed to ensure that no single entity, including the aggregator itself, can see or exploit the data being shared.
“The account aggregator framework was built precisely to formalise this principle, consent-based, purpose-limited data sharing, so that no single entity, including the aggregator itself, can see or exploit the underlying data,” he said.
While fintechs currently operate outside the central bank’s direct regulatory purview to avoid placing compliance burdens on early-stage innovation, Malhotra urged them to exercise responsibility in their operations. The regulatory exemption was not intended as a permanent shield from accountability, he suggested.
The RBI Governor introduced a new framing for fintech responsibility that goes beyond traditional systemic risk concerns. As a firm’s payment volumes, lending book or user base grows to a point where its disruption could meaningfully affect the financial system, that firm acquires obligations beyond its balance sheet or shareholders, he said.
“I would describe this as the obligation to be not just ‘too big to fail’ but ‘too significant to be careless’,” Malhotra said.
The views signal a shift in regulatory posture towards fintechs that have grown rapidly in recent years. India’s fintech sector has expanded significantly, with companies operating across payments, lending, insurance and wealth management. Many operate in areas adjacent to traditional banking but without equivalent regulatory oversight.
The account aggregator ecosystem now includes over 1.4 billion accounts linked across banks, mutual funds, insurance and pension funds, making it one of the largest consent-based data sharing networks globally. The framework’s emphasis on purpose limitation and user consent has been cited internationally as a model for data governance in financial services.
Your Questions, Answered
What did RBI Governor say about fintech data practices?
Sanjay Malhotra urged fintechs to treat customer data as a fiduciary responsibility rather than a business asset, warning that using data primarily for monetisation erodes consumer trust.
What is the account aggregator framework?
Account aggregators are RBI-regulated entities that enable consent-based sharing of financial data between institutions without themselves accessing or storing the underlying information, ensuring purpose-limited data use.
Why did RBI Governor warn fintechs about regulatory gaps?
Malhotra cautioned that building businesses whose scale depends on exploiting regulatory gaps is not acceptable, and the strategy of scaling first and seeking forgiveness later is not the right approach.
What does too significant to be careless mean?
Malhotra used this phrase to describe fintechs whose payment volumes or user base have grown large enough that their disruption could affect the financial system, creating obligations beyond their balance sheet.

