How the DPDP Act Applies to Debt Collection and Skip Tracing
Is skip tracing a loan defaulter exempt from DPDP Act consent rules? Yes, under Section 17(1)(f): but only with conditions, and RBI’s recovery rules still apply.

Skip tracing a loan defaulter is exempt from the DPDP Act’s consent and data-principal-rights machinery under Section 17(1)(f) of the Digital Personal Data Protection Act, 2023, once a real default exists and the processing stays scoped to the defaulter’s financial information, assets, and liabilities. That exemption does not touch security-safeguard obligations or RBI’s recovery-agent conduct rules, which apply in full regardless of whether the DPDP exemption is in play. The exemption carries real conditions: a genuine default has to exist, the data stays scoped to financial information, assets, and liabilities, and other regulatory regimes keep applying on top of it.
What Skip Tracing Is
Locating defaulted borrowers when contact information is missing or outdated
Skip tracing is the practice of locating a borrower, sometimes called “a skip,” who has defaulted or stopped responding and whose current contact details are unknown, outdated, or deliberately concealed. Lenders and collection agencies use it to re-establish contact for recovery, typically drawing on public records, credit-bureau data, and other databases.
For the fuller collections lifecycle, including where skip tracing sits inside SMA/NPA staging and the RBI/SARFAESI/DRT recovery process, see KYCKART’s companion piece, The Debt Collection Process: A Step-by-Step Guide for BFSI Teams. For the DPDP Act’s broader structure and phased rollout, see What Is the DPDP Act?
The Exemption Itself: Section 17(1)(f)
Statutory carve-out for ascertaining financial information, assets, and liabilities
Section 17 of the DPDP Actis titled “Exemptions” and sits in Chapter IV, “Special Provisions.” Its opening clause disapplies most of the Act’s obligations for a specific list of processing purposes: “The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 shall not apply where:” followed by sub-clauses (a) through (g). Sub-clause (f) is the one that covers loan-defaulter processing:
“...ascertaining the financial information and assets and liabilities of any person who has defaulted in payment due on account of a loan or advance taken from a financial institution, subject to such processing being in accordance with the provisions regarding disclosure of information or data in any other law for the time being in force.”
: Section 17(1)(f), Digital Personal Data Protection Act, 2023
Two terms in that clause are defined by cross-reference rather than inside the DPDP Act itself: “default” and “financial institution” both borrow their meaning from Section 3(12) and 3(14) of the Insolvency and Bankruptcy Code, 2016. Under the IBC, default means non-payment of a debt once any part or instalment has become due and isn’t repaid, and “financial institution” covers scheduled banks, institutions defined under Section 45-I of the RBI Act, 1934, public financial institutions under Section 2(72) of the Companies Act, 2013, and any institution the Central Government separately notifies. The Act’s own illustration under this clause is a simple one: a borrower defaults on a monthly instalment on its due date, and the bank may then process her financial information, assets, and liabilities to pursue recovery.
Because the DPDP Act borrows the IBC’s default definition rather than a Reserve Bank asset-classification concept like NPA (typically triggered after 90 days past due), the statutory trigger for this exemption reads as reachable earlier than an account’s formal NPA classification, potentially on a single missed instalment that’s due and unpaid. That reading is this piece’s own interpretation of how the two definitions interact rather than a position stated by any source consulted here, and it should be treated as such rather than as settled guidance.
The clause also carries its own condition: qualifying processing must be “in accordance with the provisions regarding disclosure of information or data in any other law for the time being in force.” The statute doesn’t name which other laws it means, so that condition is best described generically, as the Act itself does, rather than assumed to point at any specific named statute.
What the Exemption Removes, and What Still Applies
The boundary between disapplied rights and surviving security duties
Section 17(1)’s disapplication clause is narrower than it first appears. It removes qualifying processing from Chapter II’s consent and notice framework (Sections 5 and 6), from all of Chapter III’s data-principal rights (access, correction and erasure, grievance redressal, nomination), and from Section 16’s cross-border transfer restrictions. It does not remove Section 8(1) or Section 8(5), both of which keep applying regardless of the exemption.
| Disapplied for qualifying skip tracing | Still applies regardless of exemption |
|---|---|
| Consent and notice requirements (Sections 5-6) | Section 8(1): a fiduciary’s overall responsibility for Act compliance, “irrespective of any agreement to the contrary” |
| Data-principal rights: access, correction/erasure, grievance redressal, nomination (Chapter III) | Section 8(5): the duty to implement reasonable security safeguards against a breach |
| Cross-border data-transfer restrictions (Section 16) | Rule 6’s minimum security safeguards (encryption, masking, tokenisation, access controls, monitoring, and at least one year of access logs) |
| None | RBI’s recovery-agent conduct rules, a wholly separate regulatory layer (covered below) |
That distinction matters most for one specific obligation that sits in an unresolved spot. Section 8(6), the duty to notify the Data Protection Board and affected data principals of a personal data breach, is part of Section 8 but is not one of the two sub-sections (8(1), 8(5)) the disapplication clause names as surviving. Read literally, that would mean breach notification itself is disapplied for qualifying Section 17(1)(f) processing. No source addresses that specific interplay directly, so it’s presented here as a genuinely open interpretive question rather than a settled answer, and any confident claim one way or the other about whether Section 8(6) survives this exemption should be treated with caution until RBI, the Data Protection Board, or a court addresses it.
The Rule-level obligations that flow from Section 8(5) apply independently of that open question, since Section 8(5) itself is unaffected by the exemption. Rule 7 of the DPDP Rules, 2025 sets a two-stage breach-notification structure: the Data Protection Board must be told of a breach without delay, with initial details of its nature, extent, timing, and likely impact, followed by a fuller report within 72 hours of the fiduciary becoming aware (or a longer period the Board allows). Sources differ on whether the parallel notification to affected data principals runs on that same 72-hour clock or on its own “without delay” standard, so that specific detail is best treated as unsettled rather than stated as a fixed deadline. Separately, Rule 8 requires personal data, traffic data, and processing logs to be retained for a minimum of one year from the date of processing, after which the data must be erased, unless another law or a Central Government notification requires a longer period.
DPDP Roles in a Skip-Tracing Chain
Fiduciaries, processors, vendors, and the public-data carve-out
The Act’s terms are defined generally under Section 2: a Data Fiduciary determines the purpose and means of processing; a Data Processor processes personal data on a fiduciary’s instructions rather than deciding independently why or how; a Data Principal is the individual the data relates to. For the fuller fiduciary-obligations treatment, see KYCKART’s companion piece, What Is a Data Fiduciary Under India’s DPDP Act?
| Role | Who fills it in skip tracing | Why |
|---|---|---|
| Data Fiduciary | The lending bank or NBFC | It determines the purpose (recovering a defaulted loan) and the means of processing the defaulter’s personal data |
| Data Processor | The collection agency, typically | It acts on the lender’s instructions rather than independently deciding why or how data is processed: the classification is contract-dependent, and an agency that starts making its own decisions risks being treated as a fiduciary for that processing instead |
| Data Processor | A skip-tracing technology or API vendor | It processes personal data on a lender’s behalf, and Section 8(2) requires that engagement to happen only under a valid contract |
| Data Principal | The defaulting individual | The individual to whom the personal data relates, here the person whose financial information, assets, and liabilities are being processed |
Two things follow from that table worth stating plainly. First, a collection agency is best understood as typically a Data Processor rather than a Data Fiduciary, contract-specific rather than fixed by role title, which is the better-supported reading across the sources checked here. Second, Section 8(1) means a lender can’t contract its way out of responsibilityfor what a collection agency or vendor does with the data it’s given, “irrespective of any agreement to the contrary.”
A separate, narrower carve-out: publicly available data
The Act also doesn’t apply at all to personal data made publicly available by the data principal themselves, or by anyone under a legal obligation in India to make it public, under Section 3(c)(ii). This is a different, narrower mechanism from Section 17(1)(f): it removes certain publicly sourced data from the Act’s scope entirely, rather than exempting defaulter-financial-data processing from specific chapters. It may cover some address-tracing work that draws on genuinely public records, but doesn’t extend to data pulled from private or commercial databases.
The Layer That Doesn't Go Away: RBI's Recovery-Agent Conduct Rules
Two decades of fair-practice norms, 2025 Outsourcing Directions, and 2026-2027 tightening
Everything above is about DPDP-specific obligations. It’s a separate question from how a lender or its agent is allowed to act while pursuing recovery, and RBI has regulated that conduct independently for two decades, through a Fair Practices Code circular dated 5 May 2003, extended most directly by RBI/2022-23/108, “Outsourcing of Financial Services : Responsibilities of regulated entities employing Recovery Agents,” dated 12 August 2022. That circular applies to scheduled commercial banks, NBFCs, and other regulated entities (excluding microfinance loans, governed separately), and it bars intimidation or harassment of any kind, verbal or physical, including acts meant to publicly humiliate a debtor or intrude on the privacy of family members, referees, or friends. It also prohibits inappropriate messages by mobile or social media, threatening or anonymous calls, persistent calling, false or misleading representations, and calls before 8:00 a.m. or after 7:00 p.m.
That regime has since been folded into a broader instrument. The Reserve Bank of India (Commercial Banks : Responsible Business Conduct) Directions, 2025, issued 28 November 2025, consolidate a range of earlier customer-service and fair-conduct instructions, including recovery-related conduct rules, into one instrument for commercial banks (excluding Small Finance Banks, Payments Banks, and Local Area Banks); parallel Directions extend the equivalent framework to NBFCs and All-India Financial Institutions. A companion pair, the Commercial Banks : Managing Risks in Outsourcing Directions and its NBFC equivalent, also dated 28 November 2025, separately require risk-based due diligence on service providers, restrict a vendor’s access to customer information to a “need to know” basis, and prohibit commingling of customer data across a vendor’s other clients.
A further round of RBI rule-making on recovery conduct specifically is still in motion as of September 2026, and its final form and effective date aren’t settled across the sources available. Several 2026-dated legal and compliance-advisory sources describe a proposed uniform recovery framework across banks and NBFCs: mandatory IIBF certification for individual recovery agents with a one-year compliance runway, a rule limiting recovery-agent contact to the borrower or guarantor specifically (extending beyond the 2022 circular’s existing family/referee/friend protections), an 08:00-19:00 contact-hours window, and, most relevant to the DPDP angle, a restriction on banks accessing personal data stored on a borrower’s device, including contacts, messages, photographs, or location information, which at least one source describes as explicitly aligned with the DPDP Act. Sources disagree on the effective date: one describes a 1 July 2026 date for the NBFC-side uniform recovery norms, while a more recent source describes a finalised Fourth Amendment Directions, 2026, notified 6 August 2026 and effective 1 January 2027, amending the NBFC-side 2025 Directions. Whether these are the same regulatory action described at two different stages, or two related but distinct instruments, isn’t clear from how the two sources describe them. What’s consistent is that RBI has been actively tightening recovery-agent conduct rules through 2026, with a new effective date landing somewhere between mid-2026 and January 2027 depending on the specific instrument.
Global Comparison: India, the EU, and the US
Contrasting statutory exemptions against legitimate interests and permissible purposes
The table below compares how India’s DPDP Act, the EU’s GDPR, and the US’s FCRA/FDCPA regime each treat skip tracing, on four dimensions: legal basis, consent requirement, the data subject’s right to object, and maximum penalties.
| Dimension | India (DPDP Act) | EU (GDPR) | US (FCRA / FDCPA) |
|---|---|---|---|
| Legal basis for skip tracing | Statutory exemption once a real default exists, Section 17(1)(f) | Legitimate interests, Article 6(1)(f): controller must satisfy a documented three-part test (genuine purpose, necessity, and a balancing test against the data subject’s interests) | Permissible purpose under FCRA §1681b(a)(3) for credit reports; FDCPA §1692b separately governs how a collector may acquire location information from third parties |
| Consent required? | No, for qualifying processing | No: legitimate interests (Article 6(1)(f)) is the basis relied on instead, subject to the balancing test | No consent framework: the permissible-purpose test governs instead |
| Data subject's right to object or stop processing | None, for qualifying Section 17(1)(f) processing: Chapter III rights are disapplied | Yes, a live, enforceable right to object under Article 21: controller must stop unless it shows “compelling legitimate grounds” | No general right to stop a collector with a valid permissible purpose from locating them: FDCPA gives dispute and communication-cessation rights instead |
| Maximum penalty tier | Up to ₹250 crore for a Section 8(5) security-safeguard breach | Up to €20 million, or 4% of total worldwide annual turnover of preceding financial year, whichever is higher | Actual damages, or statutory damages of $100-$1,000 per violation, plus punitive damages and attorneys’ fees for willful FCRA noncompliance |
Under FDCPA §1692b specifically, a debt collector contacting a third party for location information must identify themselves and state they’re confirming or correcting location information, but can’t say the consumer owes a debt, contact the same third party more than once absent a specific reason, communicate by postcard, or use language or symbols indicating the sender is a debt collector; once the collector learns the consumer has an attorney on the debt, it generally can’t contact anyone but that attorney. Under FCRA’s civil-liability provision, “willful” noncompliance covers reckless disregard of a requirement, not just intentional violations, per the U.S. Supreme Court.
What This Means for Lenders and Collection Agencies
Why checking DPDP consent without checking RBI conduct leaves 50% of risk unaddressed
Read together, the exemption and RBI’s conduct rules cover two entirely different questions, and treating them as one compliance checkbox is where the risk sits. Section 17(1)(f) answers whether a lender needs consent and must honor data-principal rights before processing a defaulter’s financial data. Once a real default exists and the processing stays within scope, it does not. RBI’s rules answer a different question entirely: how that data can be used operationally, regardless of whether DPDP consent applies. A lender or its collection agency can be fully covered by the Section 17(1)(f) exemption on the data-processing side and still be in breach of RBI’s rules for contacting a guarantor’s employer, calling outside permitted hours, or, under the newer 2026 rules described above, accessing data on a borrower’s device beyond what’s needed. A compliance program built only around the DPDP exemption, without a parallel check against RBI’s conduct rules, is checking half the requirement.
The comparison table above also points to a specific practical difference for any BFSI institution operating across India and other markets. Because Chapter III’s data-principal rights are disapplied for qualifying Section 17(1)(f) processing while GDPR’s Article 21 right to object stays live throughout, a defaulter in the EU retains a channel to challenge or halt skip-tracing processing that a defaulter in India, under the same DPDP-exempt processing, does not have. That’s a meaningful compliance-design difference for any lender running the same recovery playbook across both jurisdictions. The India side of that playbook can rely on the statutory exemption directly, while the EU side needs to be built to withstand an actual Article 21 objection, meaning the lender has to be able to show “compelling legitimate grounds” if a data subject pushes back.
Frequently Asked Questions
Key regulatory nuances on skip tracing, DPDP contracts, and recovery conduct
This piece is KYCKART’s informational interpretation of publicly available regulatory sources on the DPDP Act, its Rules, and related RBI recovery-agent and outsourcing conduct rules. It is not legal or compliance advice. Several points discussed here are genuinely unresolved in the sources available, including whether Section 8(6)’s breach-notification duty survives the Section 17(1)(f) exemption and the exact effective date of RBI’s newest recovery-conduct rules. Organisations should verify specific obligations against the primary statutory and regulatory text and consult qualified counsel before acting on any interpretation here.
KYCKART Collections Intelligence
Strengthen Collections Compliance with Real-Time Intelligence
Orchestrate borrower skip tracing, contact-data verification, and recovery-agent compliance within RBI and DPDP statutory guardrails.
Explore Collections Intelligencearrow_forward