Loan apps and Lending Service Providers operate under the RBI Digital Lending Directions 2025, where the regulated lender, not the app, stays liable.
In short
The RBI (Digital Lending) Directions, 2025 govern loan apps and LSPs, with the DPDP Act layered on. The regulated lender stays fully liable for the app data conduct. Under the RBI Digital Lending Directions, 2025, data collection must be need-based, taken with the borrower’s prior consent and an audit trail, and apps are barred from accessing contacts, media or call logs. Those are RBI requirements; the DPDP basis for each lending purpose (Section 6 consent, or a Section 7 legitimate use) must be assessed separately. DPDP penalties can reach ₹250 crore, on top of RBI action.
What changes for this niche, and the specific rule it turns on.
Under the RBI Directions, an outsourcing contract cannot dilute the regulated lender responsibility for the app acts and omissions.
Apps must not access files, media, contacts, call logs or telephony; camera, mic and location are one-time, onboarding or KYC only, with the borrower’s explicit consent (an RBI Digital Lending requirement, distinct from the DPDP basis).
Borrowers must be able to give, refuse, restrict, revoke and erase; the purpose of consent must be shown at each step of the interface.
The RBI Directions require India-only storage; any overseas processing must be deleted abroad and brought back within 24 hours, stricter than the DPDP default.
An LSP may store only basic operational data such as name, address and contact; no raw exports or unapproved sub-processors.
Short, cite-able answers, mirrored in FAQPage schema.
Kill device-permission access and fix staged consent first.
The readiness check flags device-permission, consent, storage and LSP-liability gaps.
Take the readiness check →Consultant-led and partner-backed.