Readiness assessment
Fintech & Banking · Digital Lending · Loan apps

The DPDP Act for Loan Apps & LSPs

Loan apps and Lending Service Providers operate under the RBI Digital Lending Directions 2025, where the regulated lender, not the app, stays liable.

In short

The RBI (Digital Lending) Directions, 2025 govern loan apps and LSPs, with the DPDP Act layered on. The regulated lender stays fully liable for the app data conduct. Data must be need-based, taken with prior explicit consent and an audit trail, and apps are barred from grabbing contacts, media or call logs. Penalties reach ₹250 crore under the Act, on top of RBI action.

Core impacts

What changes for this niche, and the specific rule it turns on.

The lender stays liable

Under the RBI Directions, an outsourcing contract cannot dilute the regulated lender responsibility for the app acts and omissions.

No device harvesting

Apps must not access files, media, contacts, call logs or telephony; camera, mic and location are one-time, onboarding or KYC only, with explicit consent.

Consent at every stage

Borrowers must be able to give, refuse, restrict, revoke and erase; the purpose of consent must be shown at each step of the interface.

India-only storage

The RBI Directions require India-only storage; any overseas processing must be deleted abroad and brought back within 24 hours, stricter than the DPDP default.

LSP data minimization

An LSP may store only basic operational data such as name, address and contact; no raw exports or unapproved sub-processors.

Common questions

Short, cite-able answers, mirrored in FAQPage schema.

Who is liable when a loan app mishandles data, the app or the lender?
The regulated lender. RBI is explicit that an outsourcing agreement cannot absolve the lender of responsibility for the app conduct.
Can a loan app access my contacts or call logs?
No. The RBI Directions prohibit access to contacts, call logs, files, media and telephony; only one-time camera, mic or location for onboarding or KYC, with explicit consent.
Where must digital-lending data be stored?
On servers in India. If processed abroad, it must be deleted from overseas servers and brought back within 24 hours.
How does the DPDP Act change digital lending?
It adds consent, security, breach, retention and rights duties on top of the RBI Directions; the RBI consent rules apply now, the broader DPDP duties from 13 May 2027.

Check your lending app.

The readiness check flags device-permission, consent, storage and LSP-liability gaps.

Take the readiness check