RBI Drafts New Data Governance Rules for Banks, NBFCs

BANKINGFINANCE
Whalesbook Logo
AuthorAnanya Iyer|Published at:
RBI Drafts New Data Governance Rules for Banks, NBFCs

The Reserve Bank of India has introduced a draft Data Governance Framework to improve data security and management across banks and NBFCs. This move aims to handle the expected surge in banking data, which is projected to reach 10 Exabytes by 2030. The framework emphasizes local data storage in line with the DPDP Act and mandates clear internal roles for data oversight.

The Reserve Bank of India has released a new draft Data Governance Framework aimed at strengthening how commercial banks, small finance banks, and non-banking financial companies handle information. As these institutions increase their use of digital platforms, the RBI is prioritizing better data protection, accuracy, and traceability to lower operational risks. This initiative is designed to ensure that the financial system remains secure as it shifts further toward technology-driven services.

Preparing for Exponential Data Growth

The Indian banking and financial sector currently holds between 1.5 and 2.5 Exabytes of data. With the industry pushing for broader financial inclusion and digital adoption, this volume is expected to grow significantly. Projections indicate that the sector's data footprint could increase by up to five times, potentially hitting 8 to 10 Exabytes by 2030. To manage this influx, financial institutions will likely need to make substantial investments in upgrading their digital architecture and data storage systems.

Focus on Local Storage and Infrastructure

The financial sector is currently a major user of India's commercial data center capacity, consuming nearly 30% of the country’s 1.8 Gigawatt capacity. Demand is expected to rise sharply, potentially quadrupling in the coming years. A key aspect of the new draft framework is its alignment with the Digital Personal Data Protection Act of 2023. By enforcing data localization, the RBI requires that sensitive information, including payment records and personal customer profiles, be processed and stored strictly within India. This mandate will influence the capital spending plans of many financial institutions as they scale their infrastructure to comply with these sovereignty requirements.

Clarifying Roles and Internal Oversight

To ensure consistent implementation, the proposed framework introduces a two-tier governance structure. Financial institutions will be expected to establish a board-level data governance committee supported by an executive-level team tasked with daily management. The framework creates specific roles: data owners responsible for defining usage and quality, data stewards handling day-to-day operations, and data custodians overseeing technical security controls. By clearly defining these responsibilities, the RBI aims to improve the overall quality of data, which in turn should help banks make more accurate risk assessments. Investors and stakeholders should monitor how quickly these institutions update their internal compliance systems and the subsequent impact on their operational spending budgets as they align with these new, more rigorous standards.

Disclaimer: This article is published for informational purposes only. This is not a buy sell recommendation.