The RBI Account Aggregator Framework and the DPDP Act, Explained
An Account Aggregator is an RBI-licensed intermediary that moves your financial data between institutions only with your explicit, purpose-bound, time-limited consent. It cannot read or store the data it carries, every transfer issues a consent receipt, and consent is revocable at any time — which is why an AA-based eligibility check leaves no hard enquiry on your credit file.
The Account Aggregator framework was built to solve a specific problem: before it, proving your financial position to a lender meant emailing PDF statements or handing over net-banking credentials to a screen-scraper. Both are worse than what replaced them.
What an Account Aggregator is — and is not
An Account Aggregator is an RBI-licensed NBFC operating under a specific licence class. Its defining constraint is that it is "data-blind": it is prohibited from storing, reading, analysing or monetising the financial information that passes through it. It is a consent-controlled pipe, not a repository.
- It moves data from Financial Information Providers (your banks, insurers, mutual funds) to Financial Information Users (a lender, or a platform like Naxelona).
- The payload is encrypted end-to-end. The AA holds no decryption key and cannot inspect what it forwards.
- It cannot initiate a transfer. Every movement requires a fresh, specific consent artefact granted by you.
- It never touches money. An AA cannot move funds, authorise a payment, or act on your accounts in any way.
What a consent artefact actually specifies
Consent under this framework is not a checkbox. It is a structured, digitally signed object with defined fields, and you see every one of them before approving. The specificity is what makes revocation and audit possible.
| Field | What it controls | Example |
|---|---|---|
| Purpose | The declared reason for access, from a fixed RBI-defined list | Personal finance management / loan underwriting |
| Data range | The historical window requested | Transactions from the last 6 months |
| Frequency | One-time fetch, or recurring pulls | Single fetch |
| Consent validity | The date access automatically expires | 30 days from grant |
| Data life | How long the recipient may retain what it received | Delete within 1 day of processing |
| Accounts | Precisely which linked accounts are in scope | One savings account only |
How the DPDP Act 2023 sits on top
The Digital Personal Data Protection Act 2023 is India’s general data protection law. Where the AA framework governs how financial data moves, DPDP governs what any organisation may do with your personal data once it holds it. The two reinforce each other.
- Purpose limitation: data collected for one declared purpose cannot be quietly repurposed for another.
- Data minimisation: only what is necessary for the stated purpose may be collected.
- Right to correction and erasure: you can require a Data Fiduciary to fix or delete your data.
- Right to withdraw consent: withdrawal must be as easy as granting it was.
- Breach notification: affected individuals and the Data Protection Board must be informed.
- Grievance redressal: every Data Fiduciary must publish a reachable complaints channel with defined timelines.
The term "Data Fiduciary" is deliberate. It frames the organisation holding your data as owing you a duty of care, rather than as an owner of an asset it happens to have collected.
Why an AA check does not affect your credit score
This is the most common misconception, and the distinction is genuinely simple: an AA fetch and a bureau enquiry are different events against different systems.
The two events, separated
- An AA fetch retrieves bank transaction data from your bank, with your consent. It never touches CIBIL, Experian, Equifax or CRIF.
- A soft enquiry checks your bureau file for a pre-qualification. It is visible to you but not to other lenders, and does not affect the score.
- A hard enquiry is logged when you formally apply for credit. It is visible to other lenders and can shave a few points, particularly when several cluster together.
Eligibility checks built on AA data plus a soft enquiry leave the score untouched. Only a formal application triggers the hard enquiry — which is why comparing widely before applying costs you nothing.
Auditing and revoking access
- Open the AA app where you granted the consent — the artefact lives with the aggregator, not with the recipient.
- Review active consents. Each shows purpose, scope, validity and the requesting institution.
- Revoke any you no longer want. Revocation stops future fetches immediately.
- Note the limit: revocation halts future access but does not retroactively delete data already transferred. For that, exercise your DPDP erasure right directly with the recipient.
Frequently asked questions
Is the Account Aggregator framework safe?
It is materially safer than the alternatives it replaced. Aggregators are RBI-licensed, data passes through encrypted end-to-end with the AA unable to read it, every transfer requires a specific consent artefact, and consent is revocable. Critically, it never requires you to share net-banking credentials.
Can an Account Aggregator see my bank balance?
No. The AA is required to be data-blind — it forwards encrypted data without the ability to decrypt or store it. Only the Financial Information User you consented to, such as the lender assessing your application, can read the contents.
Does using an Account Aggregator affect my CIBIL score?
No. An AA fetch retrieves bank transaction data and does not touch the credit bureaus at all. Your score is only affected by a hard enquiry, which is logged when you formally apply for credit — not when you check eligibility.
How do I revoke Account Aggregator consent?
Open the AA app where the consent was granted, find the active consent and revoke it. This stops all future data fetches immediately. It does not delete data already shared — for that, make an erasure request to the recipient under the DPDP Act.
What is a consent receipt?
A timestamped, digitally signed record of exactly what you agreed to: the purpose, the data range, the validity period, the retention period and the accounts in scope. It is your evidence of the terms if you later need to dispute how data was used.
What is a Data Fiduciary under the DPDP Act?
Any entity that determines the purpose and means of processing your personal data. The term carries a duty of care: fiduciaries must limit collection to the stated purpose, secure what they hold, honour correction and erasure requests, and maintain a grievance channel.
Related
This guide is general information, not personalised financial advice. Rates, limits and tax rules change; verify current terms with the provider before acting. How Naxelona makes money and ranks products.