For NBFCs, LSPs and loan apps, the Act reshapes consent, data collection and vendor liability across the lending workflow.
In short
The DPDP Act reshapes digital lending around clear, purpose-specific consent, strict data minimization, and borrower rights. Lenders must separate loan-underwriting consent from marketing, halt excessive device-data harvesting, and face penalties up to ₹250 crore for misuse or breaches.
What changes for this sub-sector.
An RBI Key Fact Statement is not a DPDP notice. Consent must be granular, affirmative and easy to withdraw, for each specific purpose.
Lenders cannot harvest contacts, media files or call logs beyond strict, one-time KYC needs, in line with RBI limits.
Lending apps (LSPs) and outsourced recovery agents act as processors. If they mishandle data, liability lands on the lender.
Borrowers can access and correct their profiles, and request erasure once mandatory RBI and tax retention periods have lapsed.
Run parallel reporting: notify the RBI or CERT-In and the Data Protection Board during a security event.
Niche guides for this area, each naming the specific regulation.
Fix consent and vendor contracts first, then work toward certification.
The readiness check surfaces consent-splitting, device-data and vendor-liability gaps.
Take the readiness check →