Readiness assessment
Fintech & Banking · Digital Lending

The DPDP Act for Digital Lending

For NBFCs, LSPs and loan apps, the Act reshapes consent, data collection and vendor liability across the lending workflow.

In short

The DPDP Act reshapes digital lending around clear, purpose-specific consent, strict data minimization, and borrower rights. Lenders must separate loan-underwriting consent from marketing, halt excessive device-data harvesting, and face penalties up to ₹250 crore for misuse or breaches.

Core impacts

What changes for this sub-sector.

Consent architecture

An RBI Key Fact Statement is not a DPDP notice. Consent must be granular, affirmative and easy to withdraw, for each specific purpose.

Data minimization

Lenders cannot harvest contacts, media files or call logs beyond strict, one-time KYC needs, in line with RBI limits.

Third-party and vendor oversight

Lending apps (LSPs) and outsourced recovery agents act as processors. If they mishandle data, liability lands on the lender.

Borrower rights

Borrowers can access and correct their profiles, and request erasure once mandatory RBI and tax retention periods have lapsed.

Breach and incident reporting

Run parallel reporting: notify the RBI or CERT-In and the Data Protection Board during a security event.

Go deeper

Niche guides for this area, each naming the specific regulation.

Check your lending flow.

The readiness check surfaces consent-splitting, device-data and vendor-liability gaps.

Take the readiness check