DPDP Rules 2025: Key Changes, Obligations & Implementation Guide
Read here
RBI Digital Lending Directions and DPDP Act banner
Compliance

RBI Digital Lending Directions and DPDP Act: Data Rules for NBFCs and Loan Apps

By Charanjeet Singh, Co-Founder, IndiaConsent

RBI Digital Lending Directions and DPDP Act: Data Rules for NBFCs and Loan Apps

A digital lending app in India already operates under a specific RBI rule about what it can access on a borrower's phone, and will soon also operate under the DPDP Act's consent and erasure framework — the two aren't the same regime, and treating RBI compliance as if it covers DPDP too is the most common mistake we see NBFCs make. This post covers three concrete friction points for NBFCs and lending apps: what a digital lending app is actually allowed to collect from a borrower's device, what regulators are enforcing right now against apps that ignore that limit, and the genuine tension between AML/KYC record-retention mandates and a borrower's DPDP right to erasure.

One correction worth stating upfront: digital lending apps and NBFCs are regulated by the Reserve Bank of India, not SEBI (which oversees securities markets, brokers, and mutual funds) — the specific rules discussed below, on device permissions and lending conduct, come from RBI's Digital Lending framework.

Where RBI's Digital Lending Directions and DPDP overlap for NBFCs

AreaRBI (Digital Lending) Directions, 2025DPDP Act, 2023
Device/app permissionsPara 12 prohibits Digital Lending Apps (DLAs) from accessing mobile phone resources — files, media, contacts, call logs, or telephony functions — except one-time camera, microphone, or location access for onboarding/KYC, with explicit consent for that specific purposeSection 6 requires consent to be specific to the stated purpose and Section 8(1) requires processing to be limited to what's necessary for that purpose — a second, independent consent and purpose-limitation layer on top of RBI's device-access rule
Consent mechanicsRequires "explicit borrower consent" for data collection and before sharing personal data with third parties, per RBI's digital lending frameworkRequires a separate DPDP-compliant consent notice (Section 5) in the specified form, itemising the purpose — RBI's consent requirement and DPDP's are not automatically the same consent artifact
Data retentionRBI's KYC and AML rules require retaining identity and transaction records for a fixed statutory minimumSection 8(7) requires erasure once the purpose ends or consent is withdrawn — unless retention is necessary for compliance with any law in force, which is exactly what the RBI/PMLA retention mandate triggers

What a digital lending app can and can't collect

The Para 12 device-access restriction

RBI's original 2022 Digital Lending Guidelines drew a hard line after its own Working Group on Digital Lending found apps routinely harvesting contacts and media to enable coercive recovery tactics. The RBI (Digital Lending) Directions, 2025 repealed and replaced those 2022 guidelines with a "unified rule-based regime," and carried the restriction forward and clarified it: under Para 12, Digital Lending Apps are prohibited from accessing mobile phone resources such as files, media, contacts, call logs, or telephony functions, full stop. The only permitted access is one-time use of the camera, microphone, or location, and only for onboarding or KYC verification, with the borrower's explicit consent for that specific use.

Two consent regimes, not one

This is where NBFCs most often under-build. RBI's own consent requirement — that data collection and third-party sharing happen with the borrower's explicit consent — is a lending-conduct rule enforced by RBI. DPDP's consent requirement under Section 5 and Section 6 is a separate, independently enforceable data-protection rule with its own notice format, its own itemised-purpose standard, and its own regulator (the Data Protection Board of India, once the relevant provisions commence on 13 May 2027). An app can be fully compliant with RBI's Para 12 device restriction and still fail a DPDP consent audit if its DPDP-facing consent notice doesn't independently meet Section 5's requirements. Building one consent flow that happens to satisfy both, rather than assuming RBI compliance is a substitute for DPDP compliance, is the actual engineering task here.

Loan-app permission abuse: what's actually being enforced right now

The permission restriction above exists because ignoring it has a documented history of real harm, and regulators are still acting on it. On 30 March 2026, the Indian Cybercrime Coordination Centre (I4C), under the Ministry of Home Affairs, issued a takedown notice for six loan apps, directing Google to remove them from the Play Store within 36 hours. The notice alleged the apps had been harvesting Aadhaar details, financial records, contacts, and photographs, and using camera access beyond any legitimate onboarding need — paired with recovery tactics that involved contacting the borrower's relatives, friends, colleagues, and employers to apply pressure. The legal basis cited for the action was the Information Technology Act, 2000 and the Bharatiya Nyaya Sanhita, 2023 — worth noting precisely because it means this kind of enforcement is already happening on IT Act and criminal-law grounds, independent of the DPDP Act, whose own substantive provisions (including the security-safeguards and breach-notification duties that would also bite on conduct like this) don't commence until 13 May 2027. Once they do, this exact fact pattern — unauthorised harvesting of contacts and photos — becomes independently actionable as a DPDP breach as well, on top of whatever IT Act or criminal exposure already applies.

AML/KYC retention vs DPDP erasure rights: the actual conflict

This is the tension NBFC compliance teams ask about most, and it has a real answer, with one number worth flagging as genuinely unsettled.

DPDP's erasure right and the law-mandated-retention exception

Section 8(7) of the DPDP Act requires a Data Fiduciary to erase personal data once the Data Principal withdraws consent or once it's reasonable to assume the specified purpose is no longer being served — "unless retention is necessary for compliance with any law for the time being in force." Section 12 gives the Data Principal (the borrower) the corresponding right to request that erasure, with the same law-mandated-retention exception preserved (Section 12(5) on the current text). In plain terms: a borrower can ask an NBFC to delete their data, and the NBFC can lawfully refuse for exactly as long as a specific other law — here, the RBI/PMLA framework — requires the record to be kept, provided it can name that law and the applicable period.

How long records actually have to be kept — and where our research hit a genuine conflict

This is the number an NBFC needs to cite when refusing an erasure request, and it's worth being direct about an inconsistency we found rather than picking one figure and hoping it's right. Two independent readings of the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005 (Rules 6 and 10) that we pulled this session state a ten-year retention period from the date of cessation of the transaction or client relationship. Separately, secondary commentary citing RBI's own Master Direction on KYC, 2016 (paragraph 46) describes a five-year retention requirement after the business relationship ends. We were not able to independently pull a clean, current, machine-readable copy of the governing PMLA Rules PDF this session to resolve which figure currently governs, or whether the two instruments simply impose different periods for different record categories (transaction records vs. identity/KYC documents) that both apply. Before an NBFC builds an erasure-refusal policy citing a specific number, its legal or compliance function should confirm the currently applicable period directly against both the PMLA Rules and the RBI KYC Master Direction — and where they diverge, the safer posture is to retain for the longer of the two.

What this means for an erasure-request workflow

Whichever specific figure applies, the operational shape is the same: an NBFC cannot run a blanket "delete everything on request" workflow. Data has to be classified field-by-field — KYC identity documents and transaction records fall under the statutory retention floor and get refused (with the refusal citing the specific law and period, not a generic "we can't do that"); everything else genuinely outside a regulatory mandate — marketing preferences, app-usage analytics, behavioural data collected beyond the KYC/lending purpose — has no such shield and should be erased on request once the underlying purpose has ended.

Compliance timeline for NBFCs

  • Now (2026): RBI's Digital Lending Directions, 2025 Para 12 device-access restriction, and RBI/PMLA retention mandates, are already in force and already being enforced (as the March 2026 I4C takedown shows).
  • 13 May 2027: DPDP Act Sections 3–10 (processing conditions, consent, Significant Data Fiduciary duties) and Sections 11–17 (Data Principal rights including Section 12 erasure) come into force, alongside the corresponding DPDP Rules. From this date, the same permission-abuse conduct RBI and IT Act enforcement already target becomes independently actionable as a DPDP breach, with penalties running up to ₹250 crore under Section 8(5) for inadequate security safeguards.

Frequently Asked Questions

Which regulator governs digital lending apps and NBFCs in India — RBI or SEBI?

The Reserve Bank of India — SEBI regulates securities markets, brokers, and mutual funds, while digital lending apps and NBFCs fall under RBI's Digital Lending Directions and NBFC regulatory framework.

Can a digital lending app access a borrower's contacts or photos?

No — Para 12 of the RBI (Digital Lending) Directions, 2025 prohibits Digital Lending Apps from accessing mobile phone resources such as files, media, contacts, call logs, or telephony functions, permitting only one-time camera, microphone, or location access for onboarding or KYC verification with the borrower's explicit consent.

Can a borrower force an NBFC to delete their KYC data under the DPDP Act?

Not while a statutory retention period is running — Section 8(7) and Section 12 of the DPDP Act both exempt a Data Fiduciary from erasure obligations where retention is necessary for compliance with another law, such as the RBI/PMLA KYC and transaction-record retention mandates.

Is complying with RBI's Digital Lending Directions enough to satisfy the DPDP Act?

No — RBI's consent and device-access rules are a separate, independently enforceable regime from DPDP's own consent (Sections 5–6) and data-processing (Section 8) requirements, and an app must satisfy both rather than assuming one covers the other.

When did the current RBI restrictions on loan-app data collection become enforceable?

The original device-access restriction dates to RBI's 2022 Digital Lending Guidelines; the RBI (Digital Lending) Directions, 2025 repealed and replaced those guidelines with a consolidated framework that carried the restriction forward under Para 12.


Related Articles & Internal Resources


Primary Sources Cited