top of page

DPDP Act, Trade Secrets and Algorithmic Confidentiality in Indian FinTech

16 minutes ago
8 min read

Introduction : Financial technology businesses increasingly derive their competitive advantage from information. A digital lender may use a proprietary credit-scoring model, a payments platform may develop fraud-detection systems around transactional patterns, and an account-based service may rely on sophisticated customer segmentation. Alongside these technologies sits personal data belonging to borrowers, account holders and users. The same technological ecosystem can therefore contain two legally different interests - the individual’s interest in controlling personal data and the enterprise’s interest in keeping valuable commercial information confidential.


What happens when compliance with data protection obligations requires a business to explain how it processes personal data, identify the entities with which data has been shared, respond to requests for correction or erasure, or submit information to a regulator, while the same systems contain algorithms, datasets, technical methods or business strategies that the company regards as confidential?


What the DPDP Act actually requires from a FinTech business


The DPDP Act regulates digital personal data rather than commercial information in general. A Data Fiduciary is the person determining the purpose and means of processing personal data, while a Data Processor processes such data on behalf of the fiduciary. For a FinTech business, this distinction may operate at several levels. A lending platform can be a Data Fiduciary for information collected directly from borrowers, while an outsourced technology provider may act as a Data Processor.


The Act’s transparency obligations begin with notice. Section 5 requires information about the personal data proposed to be processed and the purpose for which it will be processed, while the final Rules require the notice to contain an itemised description of personal data and a specific description of the purpose of processing. This places a meaningful limit on vague descriptions of data practices.


Data principals also receive a right to obtain a summary of personal data being processed and information about the processing activities undertaken. Importantly for FinTech ecosystems, section 11 can require disclosure of the identities of other Data Fiduciaries and Data Processors with whom the personal data has been shared, together with a description of the personal data shared. The provision is significant because financial platforms frequently operate through interconnected arrangements involving lenders, technology providers, credit information entities and other service providers.


However, this does not amount to a statutory right to inspect the underlying algorithm. The Act requires information concerning personal data and its processing, not disclosure of source code, model weights, proprietary rules or the complete architecture of a credit-scoring system. Treating the right of access as an automatic right to proprietary technology would therefore extend the provision beyond its text.


The same distinction applies to the right of correction and erasure under section 12. A borrower may have a right to seek correction or erasure of personal data in the circumstances specified by the Act, but this does not necessarily create a right to delete the proprietary software through which that data was processed. The legal problem instead becomes one of separating the personal-data component from the commercial system that processes it.


Why FinTech makes the distinction especially important


FinTech intensifies this problem because personal data and proprietary technology are often economically intertwined. The information used to assess a borrower may include income, transaction history, repayment behaviour and other personal information. But the method used to convert that information into a lending decision may be proprietary.


The regulatory environment already reflects this distinction. RBI’s Digital Lending framework requires need-based data collection, prior and explicit consent, clear privacy policies and restrictions on the storage of borrower information by Lending Service Providers and Digital Lending Apps. RBI’s framework has also recognised the need for regulated entities to document the rationale for algorithmic features aiding lending decisions. That requirement is designed to facilitate accountability without necessarily requiring the public disclosure of the algorithm itself.


This produces a layered transparency model. A FinTech enterprise may need to demonstrate that a decision-making system is lawful, documented and capable of regulatory scrutiny while still having legitimate reasons to prevent competitors from obtaining the underlying model. Transparency about the operation of a financial service is therefore not synonymous with transparency of every component through which that service operates.


The distinction is also important because financial institutions routinely use third-party technology. RBI’s IT outsourcing framework places responsibility on regulated entities for customer-data confidentiality and integrity even where data is processed by service providers. In practice, a contractual structure may consequently contain several overlapping confidentiality obligations while the DPDP framework imposes an independent regulatory layer over the personal data itself.


Trade secrets occupy a different legal category


India does not have a standalone comprehensive statute governing trade secrets. Protection instead arises principally through contracts, confidentiality obligations and common law principles. Indian courts have consequently approached trade-secret claims by examining whether particular information genuinely possesses the quality of confidence and whether circumstances justify preventing its disclosure.


American Express Bank Ltd v. Priya Puri involved a financial institution seeking protection for customer and wealth-management information. The Delhi High Court distinguished ordinary knowledge and experience acquired during employment from confidential information capable of protection. The case illustrates that information connected with a financial business can attract protection, but the claimant must establish why the information is genuinely confidential rather than simply asserting that everything obtained during employment is secret.


The Delhi High Court’s later decision in Navigators Logistics Ltd v. Kashif Qureshi similarly emphasised the need for specificity in trade-secret claims. The court considered whether customer information and business data actually possessed the necessary confidential character rather than assuming that all commercially useful information was protectable. This is particularly relevant to FinTech because large volumes of customer information may consist of information that is personal, commercially valuable, regulated, or some combination of all three.


The problem becomes more complicated with algorithms. International trade-secret principles recognise software algorithms as potentially protectable confidential information where they possess commercial value because of secrecy and are subject to reasonable measures to maintain that secrecy. But the proprietary algorithm and the personal data fed into it remain legally distinct. Protecting the algorithm cannot provide a blanket justification for withholding personal-data information to which a data principal has an independent statutory right.


Where the real collision may occur


The strongest tension is therefore not between a right to personal data and a direct right to inspect source code. It lies in the boundaries of meaningful explanation.


Consider a lending model that uses several variables to generate a credit assessment. A borrower may seek information concerning what personal data is being processed and how it is being used. The FinTech company may respond by explaining the categories of data and purpose of processing without revealing the mathematical architecture or proprietary features of the model. That approach can satisfy transparency while preserving the core secret.


The difficult situation arises where the company argues that even identifying certain categories of processing would expose a commercially sensitive methodology. Here, the DPDP framework’s emphasis on clear notice makes complete reliance on trade-secret status difficult. A company cannot convert every internal processing practice into a trade secret merely by labelling it confidential.


The reverse concern is equally important. Data protection should not become an indirect mechanism through which competitors acquire valuable technology. Disclosure to a data principal, regulator or service provider should therefore be controlled according to purpose, necessity and confidentiality safeguards. The objective should be to disclose enough information to make the statutory right meaningful without unnecessarily transferring the underlying competitive advantage.


The protection within the DPDP framework


The DPDP Act itself recognises that legitimate processing can intersect with trade-secret protection. Section 7 permits certain legitimate uses, including processing for employment-related purposes connected with preventing corporate espionage and maintaining confidentiality of trade secrets and intellectual property. This does not establish a general trade-secret exemption from the Act. It does, however, demonstrate that the draftsmen did not conceive privacy compliance and commercial secrecy as wholly incompatible interests.


The Act also contains exemptions in section 17, including specified situations where processing is necessary for enforcing a legal right or claim. This can become important where a FinTech business processes personal data in the context of defending or enforcing confidentiality and intellectual-property rights. The eventual operation of these provisions will require careful interpretation because an exemption connected to a legitimate legal purpose cannot automatically justify unlimited processing.


The final Rules add another dimension for Significant Data Fiduciaries. Rule 13 requires such entities to undertake periodic data protection impact assessments and audits and to exercise due diligence concerning algorithmic software so that it does not create risks to the rights of Data Principals. This could have considerable consequences for large financial platforms using algorithmic systems. Yet again, the provision requires responsible governance of algorithmic software, not publication of proprietary algorithms.


What a workable boundary should look like


A sustainable approach for Indian FinTech will depend on treating personal data, processing information and proprietary technology as three related but distinct categories.


First, information necessary for a Data Principal to understand the collection and use of personal data should be disclosed in a meaningful form. A notice that technically lists data categories but leaves the user unable to understand why the information is collected would undermine the purpose of transparency.


Second, proprietary technology should not be exposed merely because it is involved in processing personal data. Source code, proprietary model architecture, confidential scoring methodologies and commercially sensitive technical documentation should remain capable of protection where they independently satisfy the requirements of confidentiality.


Third, regulatory access should be accompanied by appropriate safeguards. RBI already expects regulated entities to preserve confidentiality while enabling regulatory supervision and access to relevant information. This model offers a useful conceptual distinction: information can be available for legitimate oversight without thereby becoming generally available to the market.


The contractual layer will remain equally important. FinTech businesses should separate personal-data obligations from confidentiality obligations in agreements with employees, vendors and technology providers. The existence of a DPDP obligation should not be treated as destroying confidentiality automatically, just as a confidentiality clause should not be treated as overriding a statutory data right.


Conclusion


The relationship between the DPDP framework and trade-secret protection in Indian FinTech is therefore not a simple contest between transparency and secrecy. The two regimes regulate different legal interests. Data protection asks whether an individual’s personal information is processed lawfully and accountably. Trade-secret law asks whether commercially valuable confidential information has been improperly acquired, used or disclosed.


The more difficult question is how those interests interact when they exist inside the same technological system. The answer is unlikely to be found in either absolute disclosure or absolute secrecy. It will depend upon identifying precisely what information a Data Principal is entitled to know, what technology remains commercially confidential, and what information regulators legitimately need to examine.


As the substantive DPDP provisions move towards operation, the coming enforcement phase will therefore be important not because it will simply reveal whether FinTech businesses must become more transparent, but because it will determine how Indian law draws the line between transparency about the processing of personal data and disclosure of the intellectual capital that makes a financial technology business competitive.


Author: Amrita Pradhan in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at  Khurana & Khurana, Advocates and IP Attorney


References


  1. Ministry of Electronics and Information Technology, Government of India, Digital Personal Data Protection Rules, 2025, GSR 846(E), 13 November 2025.

  2. Ministry of Electronics and Information Technology, Digital Personal Data Protection Act, 2023: Commencement Notification, GSR 843(E), 13 November 2025.

  3. Reserve Bank of India, Guidelines on Digital Lending, RBI/2022-23/111, DOR.CRE.REC.66/21.07.001/2022-23, 2 September 2022, Annex I https://rbi.org.in/Scripts/NotificationUser.aspx?Id=12382

  4. Reserve Bank of India, Master Direction on Outsourcing of Information Technology Services, RBI/2023-24/102, DoS.CO.CSITEG/SEC.1/31.01.015/2023-24, 10 April 2023 https://rbidocs.rbi.org.in/rdocs/notification/PDFs/102MDITSERVICES56B33FD530B1433187D75CB7C06C8F70.PDF

  5. World Intellectual Property Organization, Overview of National and Regional Trade Secret Systems: India (2024) https://www.wipo.int/documents/d/trade-secrets/docs-overview-country-sheets-india-final.pdf

  6. American Express Bank Ltd v. Priya Puri 2006 SCC OnLine Del 638 (Delhi High Court, 24 May 2006).

  7. Navigators Logistics Ltd v. Kashif Qureshi 2024:DHC:8965-DB (Delhi High Court, 20 November 2024).

Comments


bottom of page