The Lawxy Times

Author Image
Lawxy Times Reporter

RBI Guidance Narrows Call‑Centre Data Use Under DPDPA

On 13 May 2027 the Reserve Bank of India issued IT Governance Directions clarifying the processing of call‑centre data under the Digital Personal Data Protection Act, 2023. The Directions restrict the “voluntarily provided” exception to the specific enquiry purpose and require separate consent for any secondary use. Banks, NBFCs and other RBI‑regulated entities must redesign call‑centre workflows to comply. The guidance also imposes board‑level oversight and data‑flow segregation requirements.

Full News Breakdown

The dispute arose when a bank captured a caller’s mobile number and name at the start of an inbound toll‑free call and used the data for marketing without obtaining explicit consent. The regulator examined whether such capture fell within Section 7(a) of the DPDPA or required consent under Section 6.

  • Date: 13 May 2027

  • Statutes Cited: Digital Personal Data Protection Act, 2023

  • Key Provisions: Section 4, Section 5, Section 6, Section 7(a) of the Act; RBI Directions on board oversight and data governance

  • Primary Legal Issue: Whether capturing caller’s number/name at call initiation requires consent or is permissible under the “voluntarily provided” exception

  • Petitioner Arguments: The bank contended that the caller voluntarily supplied the number by dialing the toll‑free line, so processing was covered by Section 7(a) and no consent was needed.

  • Respondent Arguments: The RBI argued that the bank’s use of the data for marketing exceeded the specific enquiry purpose and therefore fell outside the exception, triggering the consent regime of Section 6.

  • Reasoning: The Directions reasoned that the “voluntarily provided” exception is limited to processing strictly necessary for the immediate service purpose and that any broader processing must satisfy the consent requirements of the Act.

  • Ratio Decidendi: Section 7(a) applies only to processing necessary for the caller’s stated enquiry; secondary purposes are not covered.

  • Operative Order: Banks must implement pre‑call disclosures, separate service and marketing data streams, obtain explicit consent for secondary uses, and maintain board‑level data‑governance records.

  • Practical Outcome: Institutions must revise call‑centre scripts, consent logs, retention policies and data‑flow maps before the 13 May 2027 effective date.

How Does This Affect You?

Before the Directions, it was unclear whether the mere capture of caller ID at call start fell within the “voluntarily provided” carve‑out or triggered the consent regime. The RBI now clarifies that the carve‑out applies only to processing necessary for the specific enquiry and that any secondary purpose demands consent under Section 6. Consequently, banks can rely on the exception for call handling but must treat any marketing, analytics or sharing as consent‑based activities, creating a clear compliance boundary. The clarification also narrows the scope for data‑analytics units that previously relied on implied consent for call‑centre recordings. Firms must now document the purpose limitation in their data‑mapping exercises to demonstrate compliance during audits.

For Lawyers & Advocates

  • Revise call‑centre scripts to include a pre‑call notice that discloses recording and purpose, thereby satisfying the Act’s notice requirement for all inbound calls.

  • Amend data‑processing agreements with third‑party telephony vendors to embed limitation clauses reflecting Section 7(a) and to require consent logs for any data shared beyond the service purpose.

  • Update retention schedules in the bank’s data‑governance policy so that call recordings are kept only for the period needed for service, audit or regulatory compliance, in line with the purpose‑limitation rule.

  • Prepare board‑level compliance reports that map service‑versus‑marketing data flows, demonstrating adherence to the RBI Directions on senior‑management accountability.

  • Deploy the Directions as precedent in disputes where regulators allege unlawful marketing use of call‑centre data, arguing that the exception does not extend to secondary purposes.

For Law Students

This decision shows how courts and regulators balance statutory purpose‑limitation with practical business needs.
The core doctrine is the narrow interpretation of the “voluntarily provided” exception under Section 7(a) versus the consent requirement of Section 6.
The decision is particularly relevant for the study of:

  • Purpose limitation under the DPDPA

  • Consent mechanisms and notice under Sections 5‑6

  • Data fiduciary obligations under Section 4

  • Board oversight under RBI IT Governance Directions

  • Comparative analysis of privacy exceptions in Indian law
    The judgment should be read alongside Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) and Shreya Singhal v. Union of India (2015), which together illustrate how the courts distinguish between implied consent in voluntary disclosures and explicit consent for secondary processing.

For Businesses

  • Boards of banks and NBFCs must review and approve updated call‑centre data‑governance frameworks, or risk enforcement notices under the RBI Directions.

  • Call‑centre operations must embed a pre‑call disclosure script and maintain consent logs; failure to do so may attract penalties of up to 4 % of global turnover from the Data Protection Board.

  • Third‑party vendors providing telephony services must sign contracts that restrict data use to service purposes; otherwise the principal entity could be held liable for unauthorized processing.

  • Marketing teams cannot automatically import call‑centre captured numbers into campaign databases without a separate consent capture, or they will breach Section 6 and face fines.

Key Takeaways

  • The law now limits the “voluntarily provided” exception to processing strictly necessary for the caller’s immediate enquiry.

  • Call‑centre agents must deliver a pre‑call notice and obtain explicit consent before any use beyond service, prompting revision of scripts and consent logs.

  • Regulators can now sanction banks for any secondary processing that lacks consent, and the Data Protection Board can levy penalties for such breaches.

  • Watch the enforcement of Sections 6(9) and 27(1)(d) scheduled for 13 November 2026, which will tighten consent‑logging and cross‑border transfer rules.

  • In‑house counsel should finalize updated call‑centre policies and board approvals before the 13 May 2027 effective date to avoid regulatory action.

Source: Your Name Is On Bank's Screen Before You Say Hello: What DPDPA Says About Call-Centre Data

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested

Secure by design. Built for enterprise.

More About Security

Lawxy AI is designed with encrypted infrastructure, access controls, audit visibility, and enterprise-grade security standards.

SOC 2 Type I, II

GDPR

ISO 27001

VAPT Tested