Quick Answer
Fintech companies operating in India must navigate at least three distinct RBI regulatory frameworks: the Regulatory Sandbox for product testing, Payment Aggregator licensing for merchant payment processing, and the Digital Lending Guidelines 2022 (updated through 2025) for loan origination and disbursement. Separate rules govern payment data localisation and, from 2025, the Digital Personal Data Protection Act.
Fintech regulation in India is not a single statute it is a layered architecture. The Reserve Bank of India administers authorisation frameworks, conduct guidelines, and data storage directives across lending, payments, and digital infrastructure. The Digital Personal Data Protection Act 2023 adds a consent and processing layer on top. Together, these frameworks define what a fintech company can build, how it can operate, and what it must disclose.
This post maps the frameworks that matter most for fintech founders and compliance heads: the RBI Regulatory Sandbox, Payment Aggregator and Payment Gateway licensing, the Digital Lending Guidelines as they stand in 2025, payment data localisation requirements, and the DPDP Act’s fintech overlay. Each section states the current requirement, the specific regulatory reference, and the compliance obligation that follows.
For the broader statutory context on banking and financial services law in India, refer to our Banking and Finance Law guide.
RBI Regulatory Sandbox: How Fintechs Test Products Legally
The RBI Regulatory Sandbox is not a licence. This distinction matters. Acceptance into a Sandbox cohort allows a fintech to test a product with real customers under a defined regulatory relaxation; it does not authorise the entity to offer that product commercially at scale.
The Sandbox operates through cohorts, each organised around a theme. Past cohorts have covered retail payments, cross-border payments, MSME lending, and prevention of financial fraud. The RBI issues a call for applications per cohort, evaluates eligibility, and grants selected applicants a test period typically six to nine months during which specific regulatory requirements are relaxed in a controlled environment.
Eligibility requirements include:
- The applicant must be a company incorporated in India.
- The product must address a genuine financial services problem and not be commercially available in the same form.
- The product must be testable within a defined customer and transaction limit.
- Existing authorised entities (banks, registered NBFCs, payment aggregators) can apply alongside new entrants.
Sandbox status has real boundaries. An entity testing a lending product in the Sandbox cannot disburse loans beyond the cohort’s approved customer limit. An entity testing a payment solution cannot process merchant settlements at commercial volumes. When the test period ends, the entity must either exit the Sandbox (with findings documented) or seek the applicable commercial authorisation NBFC registration, PA licence, or equivalent before continuing operations.
The Sandbox is best used strategically: to generate the regulatory comfort and documented evidence base that an RBI authorisation application, or a board-level compliance decision, will subsequently require.
Payment Aggregator and Payment Gateway (PA-PG) Licensing
The RBI’s Master Directions on Payment Aggregators and Payment Gateways (March 2020, updated 2021) drew a regulatory line between two categories that previously operated without differentiated treatment.
Payment Aggregators (PAs) handle merchant funds they collect payments from customers and settle them to merchants. This makes them intermediaries in the money flow. The RBI treats PA activity as a regulated financial service requiring authorisation.
Payment Gateways (PGs) provide the technical infrastructure for payment processing, routing, authentication, encryption but do not touch merchant funds. PGs do not require RBI authorisation, but the entities operating them must comply with RBI’s technology and security standards.
What Requires a PA Licence
Any entity that:
- Receives payments on behalf of merchants from customers, and
- Settles those payments to merchants from a pooled float or escrow requires RBI authorisation as a Payment Aggregator.
The test is functional, not definitional. An entity that calls itself a “payments platform” or a “checkout solution” but controls the flow of merchant funds will be treated as a PA. Operating PA services without RBI authorisation is a violation of the Payment and Settlement Systems Act 2007.
Existing non-bank PAs that were operating before the March 2020 Directions were required to apply for authorisation by a specified deadline. New entrants must obtain in-principle approval before commencing PA activity.
Net Worth and Escrow Requirements
The RBI has set minimum net worth thresholds for non-bank Payment Aggregators:
Requirement | Amount |
Net worth at time of application | ₹15 crore |
Net worth to be achieved within prescribed ongoing timeline | ₹25 crore |
Escrow account | Maintained with a scheduled commercial bank |
Merchant settlement timeline | T+1 (funds settled to merchant the business day after transaction) |
The escrow account requirement is non-negotiable. All merchant funds collected by a PA must be held in a designated escrow account with a scheduled commercial bank, not in the PA’s own operating account. This structural separation protects merchant funds from the PA’s own credit risk and insolvency exposure.
Application Process
The PA authorisation application is filed with the RBI’s Department of Payment and Settlement Systems. The application must include:
- Certificate of incorporation and shareholding structure
- Audited financials confirming net worth at the prescribed threshold
- Business plan covering merchant onboarding, KYC framework, and grievance redressal
- Board-approved information security policy aligned with RBI’s cybersecurity framework
- Details of escrow bank arrangements
The RBI issues an in-principle approval, during which the applicant must satisfy any outstanding conditions. Final authorisation follows on confirmation of compliance. The timeline from application to final authorisation has typically ranged from 12 to 24 months, depending on documentation completeness and RBI query cycles.
Altacit Global advises PA applicants on documentation structuring, escrow account arrangements, and RBI correspondence across the authorisation cycle.
Digital Lending Guidelines 2025: Key Fintech Obligations
The RBI’s Digital Lending Guidelines, issued in September 2022 and effective from November 2022, restructured the operational relationship between regulated lenders (banks, NBFCs) and the Lending Service Providers (LSPs) and Digital Lending Apps (DLAs) that front-end their loan products.
As the guidelines have been implemented and refined through 2025, five obligations carry the highest compliance weight for fintech companies:
- Direct disbursal to borrower’s bank account
Loan disbursements must go directly to the borrower’s bank account. Disbursement to a third-party account including a Lending Service Provider’s pooled account is prohibited. The funds flow from lender to borrower, not through a pass-through pool operated by the LSP or DLA. - Key Facts Statement (KFS) before loan execution
The lender or its DLA must provide a Key Facts Statement to the borrower before the loan agreement is executed. The KFS must disclose the Annual Percentage Rate (APR) , a standardised rate that includes all fees, charges, and interest expressed as an annualised figure. No additional charge that is not disclosed in the KFS can be levied post-disbursement. - Cooling-off period for loan cancellation
Borrowers have a defined cooling-off period after loan disbursement during which they may cancel the loan without penalty. The specific period varies by loan tenor, as prescribed by the RBI. A cancellation within this window requires the borrower to return the principal; no prepayment penalty or cancellation charge applies. - Grievance Redressal Officer
Every regulated entity offering digital lending products must designate a Grievance Redressal Officer (GRO). The GRO’s contact details must be disclosed on the lender’s website and in the loan documents. Borrower complaints must be resolved within the RBI’s prescribed timeframe. - FLDG structures restricted beyond RBI-prescribed limits
First Loss Default Guarantees (FLDG) arrangements under which an LSP or fintech entity covers a portion of loan losses on behalf of the regulated lender are permitted, but only within the limits prescribed by the RBI’s September 2023 circular on Default Loss Guarantee structures. FLDG cover cannot exceed 5% of the loan portfolio covered. Structures that exceed this cap, or that operate as synthetic risk transfers without meeting the prescribed conditions, are not compliant.
Altacit Global’s regulatory team assists fintech companies and NBFCs in reviewing LSP agreements, KFS templates, and FLDG structures against the current Digital Lending Guidelines. Our NBFC guide covers the NBFC registration requirements for entities seeking to lend directly rather than through an LSP arrangement.
Data Localisation for Payment Data (RBI Storage Directive)
The RBI’s circular on Storage of Payment System Data (April 2018) applies to all payment system operators banks, non-banks, PAs, PGs, card networks, and other entities in the payments chain.
The rule is unambiguous: all data related to payment systems operated in India must be stored exclusively in India.
“Payment system data” includes the full end-to-end transaction data: payer and payee information, payment credentials, transaction amount, and timestamp. The RBI interprets this broadly. A foreign-headquartered payment entity processing Indian transactions cannot maintain a mirror database in a data centre outside India as its primary store.
The cross-border processing exception is narrow. If transaction data is transmitted abroad for processing for example, for foreign card network authorisation it must be deleted from the foreign system within 24 hours of the transaction. The data can flow out for processing; it cannot remain outside India beyond that window.
Implications for fintech companies:
- Cloud infrastructure must be India-hosted for payment data. AWS Mumbai, Google Cloud Mumbai, and Azure India Central are commonly used compliant configurations.
- Cross-border group data sharing must be structured so that raw payment transaction data does not persist in a foreign entity’s systems beyond the 24-hour deletion window.
- Third-party service providers, analytics vendors, fraud detection platforms, customer data platforms that process payment transaction data on behalf of a fintech must be assessed for India-hosting compliance before onboarding.
The RBI has conducted compliance audits and imposed penalties for data localisation violations. Fines have been levied against card networks and payment service providers including entities of significant scale confirming that the RBI treats data localisation as an active enforcement priority, not a policy aspiration.
DPDP Act Overlay for Fintech Companies
The Digital Personal Data Protection Act 2023 (DPDP Act) came into force in 2023, with implementation rules and the Data Protection Board operationalisation progressing through 2024-2025. For fintech companies, the DPDP Act adds a distinct layer of obligation that operates alongside not instead of the RBI’s data storage rules.
The distinction between the two frameworks is functional: RBI governs where payment data sits; the DPDP Act governs how personal data is used.
Under the DPDP Act, a fintech company processing personal data of Indian residents is a “Data Fiduciary.” Core obligations include:
Obligation | DPDP Act Requirement |
Consent | Explicit, informed consent before processing personal data for each specified purpose |
Purpose limitation | Data collected for loan underwriting cannot be repurposed for marketing without fresh consent |
Data minimisation | Only data necessary for the stated purpose can be collected |
Data Principal rights | Users have the right to access, correct, and erase their data; grievance redressal required |
Cross-border transfer | Transfer of personal data outside India permitted only to countries notified by the Central Government |
Breach notification | Mandatory notification to the Data Protection Board and affected Data Principals on a personal data breach |
For fintech companies, the DPDP Act compliance build-out runs in parallel with RBI compliance. A fintech that has structured its payment data architecture for RBI localisation compliance must separately audit its data processing activities, consent flows, purpose mapping, vendor contracts against the DPDP Act.
Altacit Global has published a detailed DPDP compliance guide for technology businesses covering the Data Fiduciary framework, consent architecture, and Data Protection Officer requirements in full.
Work With Altacit Global on Your Fintech Compliance Strategy
Fintech regulation in India is active and evolving. The RBI has issued significant updates to digital lending rules, payment aggregator requirements, and data localisation enforcement expectations over the past three years. The DPDP Act adds a further layer that most fintech compliance frameworks have not yet fully integrated.
Altacit Global advises fintech founders, compliance heads, and boards across lending, payments, and wealthtech on regulatory authorisation, structural compliance, and ongoing obligations including LSP agreement review, KFS and FLDG structure assessment, PA licence applications, and DPDP Act readiness.
We work from offices in Bangalore and Hyderabad. Contact us at info@altacit.com to discuss a compliance review, authorisation application, or regulatory strategy assessment for your fintech business.
Frequently Asked Questions: Fintech Regulation India
Q1: Does every fintech app need RBI authorisation?
Not every fintech app requires direct RBI authorisation, but most fintech business models involve a regulated activity that requires either direct authorisation or a compliant partnership with an authorised entity. An app that originates loans must either hold an NBFC registration or operate as an LSP for an authorised lender under the Digital Lending Guidelines. An app that processes payments and settles funds to merchants requires a PA licence. An app that provides investment advice may require SEBI registration. The relevant test is the underlying activity not the technology layer.
Q2: What is FLDG and why does RBI restrict it?
FLDG (First Loss Default Guarantee) is an arrangement where a fintech LSP guarantees to absorb a portion of the credit losses on loans it has originated on behalf of a regulated lender. The fintech, in effect, takes on credit risk that belongs to the balance sheet of the licensed lender. The RBI restricts FLDG beyond a 5% portfolio cap set in its September 2023 Default Loss Guarantee circular because uncapped FLDG structures allow unlicensed entities to carry bank-equivalent credit risk without the capital adequacy, provisioning, or regulatory oversight that banks and NBFCs must maintain. Structures that exceed the cap are treated as synthetic lending arrangements by the entity providing the guarantee.
Q3: Can a foreign fintech company operate in India directly?
A foreign fintech company cannot hold Indian financial service licences directly in most regulated categories. An NBFC, Payment Aggregator, or investment adviser licence must be held by an entity incorporated in India. A foreign fintech seeking to operate in India must establish an Indian subsidiary, which then applies for the applicable authorisation. Foreign direct investment in Indian fintech entities is generally permitted under the automatic route up to 100% for payment aggregators and NBFCs, subject to RBI and FEMA conditions. Operating a regulated fintech activity in India through a foreign entity without an Indian incorporated vehicle is non-compliant.
Q4: How long does it take to get RBI Payment Aggregator authorisation?
The timeline from application submission to final RBI authorisation for a Payment Aggregator licence has ranged from 12 to 24 months. The variance is driven primarily by documentation completeness at filing, the number of clarification rounds the RBI initiates, and whether the applicant’s net worth, KYC framework, and escrow arrangements are in place before application. In-principle approval is granted first; final authorisation follows after the applicant confirms compliance with all conditions attached to the in-principle grant. Applicants that file with incomplete documentation, or whose net worth only marginally meets the ₹15 crore threshold, tend to experience longer cycles.



