Loan apps and Lending Service Providers operate under the RBI Digital Lending Directions 2025, where the regulated lender, not the app, stays liable.
In short
The RBI (Digital Lending) Directions, 2025 govern loan apps and LSPs, with the DPDP Act layered on. The regulated lender stays fully liable for the app data conduct. Data must be need-based, taken with prior explicit consent and an audit trail, and apps are barred from grabbing contacts, media or call logs. Penalties reach ₹250 crore under the Act, on top of RBI action.
What changes for this niche, and the specific rule it turns on.
Under the RBI Directions, an outsourcing contract cannot dilute the regulated lender responsibility for the app acts and omissions.
Apps must not access files, media, contacts, call logs or telephony; camera, mic and location are one-time, onboarding or KYC only, with explicit consent.
Borrowers must be able to give, refuse, restrict, revoke and erase; the purpose of consent must be shown at each step of the interface.
The RBI Directions require India-only storage; any overseas processing must be deleted abroad and brought back within 24 hours, stricter than the DPDP default.
An LSP may store only basic operational data such as name, address and contact; no raw exports or unapproved sub-processors.
Short, cite-able answers, mirrored in FAQPage schema.
Kill device-permission access and fix staged consent first.
The readiness check flags device-permission, consent, storage and LSP-liability gaps.
Take the readiness check →