Click the Play button to listen to article

What happens when there are two guards guarding two entrances but into the same vault? The qualifications for both guards are different, one had to prove himself for years to earn the post; the other was waved in on far lighter terms. While the stricter guard is more trusted, the visitor, who sees none of this, simply picks the nearer door. This choice in itself turns out to be problematic.

The final DPDP rules were released back in November, 2025. India will now run on two consent intermediaries built on the same architecture but answering to different regulators: RBI's Non-Banking Financial Company -Account Aggregators for financial information and Consent Managers for all personal data.

The DPDP rules provide for a situation in which a Consent Manager can take a substantial role in place of an Account Aggregator. This situation as a whole is more problematic as the regimes overlap; harmony might not be established once the rules are read closely.

Where does this crisis start, because the DPDP Act 2023 has no express data-portability right; however, reading the illustrations to Part B of Schedule 1 of the DPDP Rules points towards a sort of Data moving between different fiduciaries that can be said to mirror Data Portability. Consent Managers allow a consent-mediated data flow while staying data blind, which is exactly what an Account Aggregator does.

Let's map the overlap between a Consent Manager and an Account Aggregator:

Parameter

NBFC-AA (RBI)

Consent Manager (DPDP Act & Rules, 2025)

Regulator

Reserve Bank of India

Data Protection Board of India, constituted 13 Nov 2025, but Chairperson and Members yet to be appointed.

Scope

Financial information only

Any personal data, any sector

Financial threshold

₹2 crore Net Owned Funds

₹2 crore Net Worth

Licence Type

Certificate of Registration (RBI)

Registration with the DPB under Rule 4.

Data Storage

Explicitly prohibited

Routed data must remain unreadable to the CM (data-blind); consent records retained for at least 7 years

Interoperability

ReBIT API standards (mandatory)

Interoperable platform mandatory; technical standards yet to be published by the Board

Sector Coverage

Cross-sector finance

All sectors

Illustration 2 of Part B, Schedule 1 mentions four actors, wherein X = Data Principal; B2 = the bank holding the statement; B1 = the requesting fiduciary; P = the Consent Manager. The flow mentioned is that P manages consent and transfers data directly from B2 to B1.

The illustration places a plain Consent Manager in the exact seat of an Account Aggregator for a bank statement.

This means that the rule attaches no extra obligations that are to be fulfilled by an Account Aggregator on a Consent Manager. According to the RBI, the business of an account aggregator is defined as retrieving, collecting, consolidating, organising and presenting financial information; but the main functionality of an AA is to facilitate secure digital transfer of financial information between institutions with the consent of customers, exactly the work done by a Consent Manager.

Let's see how the road to financial information has always been tough for AAs but a shortcut exists for a CM:

Single Purpose Entity

The NBFC-AA Directions bar an Account Aggregator from any business other than account aggregation. The DPDP Rules, however, have no such limit fastened to the Consent Managers, only that a Consent Manager cannot be a fiduciary or a processor for the same principal it serves. Therefore, one intermediary for all purposes can only be built around a Consent Manager, because the directions defeat AA in a non-financial scope.

RBI created a boundary to contain any risk and regulate the conduct of Account Aggregators; the DPDP has borrowed the data-blind obligation but left out creating any boundary on Data Portability of Consent Managers.

Net Owned Funds vs Net Funds

Both Regimes oblige 2 Crore as requirement but weigh different standards, for Consent Managers, Net Funds or Net worth by S. 2(57), Companies Act, 2013, in simple words this means only the Balance sheet position, add up everything the company owns on paper, Share Capital + Reserves + Premiums – Losses = Net Worth.

Net Owned Funds by RBI Act, S. 45-IA means Net Worth further deducted by intangible assets like goodwill and money the company has parked in its own group companies, subsidiaries etc.

Therefore, registration for an Account Aggregator is far more conservative and tough to match than of simple net worth, for entities that end up doing the same jobs.

2L- License & Leverage

After completing all above requirements and completing a trial period of 12 months wherein a company has to fulfil more obligations, does RBI issues a Final Certificate of Registration and the company obtains a license to perform the business of account aggregation.

Obtaining the license is just a start as Account Aggregators then should maintain a leverage where total outside liabilities do not exceed 7 times the Net Owned Funds, this should be done for continuous 3 years to declare dividends.

Both entities share so many fundamental qualities and most importantly the function, but the obligations to be established are very different. The main problem surfaces itself:

Considering the contemporary world that everyone wants a service with the lowest cost and the most efficiency, 2 scenarios may arise: first, an organization would avail Consent Managers as it allows Data Portability on all types of data, making Account Aggregators redundant; second, entities that cannot clear RBI's conservative entry bar may simply register as Consent Managers and route financial information through the DPDP channel, performing the identical function under a lighter rulebook at a fraction of the cost. That is arbitrary regulation.

A claim of redundancy must, however, be analysed also through the lens of S. 38 of the DPDP Act, which says that the Act is in addition to and not in derogation of any other law, and in case of conflict the DPDP Act prevails to the extent of the conflict. On paper, this tilts towards the Consent Manager.

First, the bank at the centre of Illustration 2 remains a regulated entity of the RBI. Its authority to part with financial information continues to be governed by the NBFC-AA Master Directions, banking secrecy obligations and RBI's data-sharing norms. An illustration in a Schedule cannot compel a bank to open its systems to an intermediary the RBI has never licensed.

Second, the Supreme Court has held that the sectoral regulator must exercise jurisdiction first before the general regulator steps in. Applied in this scenario, the RBI, and not the Data Protection Board, would have the first word on how financial information moves.

Third, the machinery gap. The Board exists only on paper, Consent Manager registration opens on 14 November 2026, and its interoperability standards are unpublished. The AA ecosystem already runs on mandatory ReBIT APIs across 600-plus regulated entities; a Consent Manager cannot compel a single Financial Information Provider onto its rails.

The real danger, therefore, is not that Consent Managers will make Account Aggregators redundant tomorrow. It is that the Rules, as drafted, create arbitrage on paper, making two intermediaries, one function, two very different price tags. This invites Forum Shopping, compliance costs for fintechs and confusion for the very Data Principal both entities claim to empower.

It's not like India has not faced this pattern before, the FSS (Health Supplements, Nutraceuticals) Regulations, 2016, had infact harmonised supplements, which could be classified as a food under FSSAI with lighter regulations or a drug under CDSCO's stricter one, the manufacturers used this option to exploit and bypass stricter regulations.

Views are personal.

Tags: