The Delhi HC's notice to RBI over non-enforcement of digital lending guidelines reveals a structural gap between rule-making and rule-enforcement in India's financial regulatory architecture. Critically examine.

Q. The Delhi HC's notice to RBI over non-enforcement of digital lending guidelines reveals a structural gap between rule-making and rule-enforcement in India's financial regulatory architecture. Critically examine. (15 marks, 250-350 words)

The Delhi High Court's notice to the RBI and the Centre on a PIL alleging that NBFC-run digital lending apps (DLAs) still harvest contact lists and call logs despite the RBI (Digital Lending) Directions, 2025 [1][2] reopens a familiar question: India's financial regulation is rich in norms but thin in verified compliance. The gap is real, though not total.

Evidence of a rule-making–enforcement gap - Persisting violations: the 2025 Directions expressly bar DLAs from accessing file/media, contact lists, call logs and telephony functions, yet the petition alleges continued access [1][2] — a norm on paper, not on devices. - Coercive consent: non-negotiable privacy policies as a condition of service defeat the "free and informed" consent standard of the DPDP Act, 2023 [3], and informational self-determination under Article 21 (Puttaswamy, 2017) [4]. - Supervisory capacity: regulation extends to Regulated Entities, their LSPs and DLAs [1][5], but ex-post, complaint-driven supervision cannot police app-level permissions at scale. - Fragmented accountability: the DPDP Act's Data Protection Board (MeitY) and RBI's sector rules create overlapping mandates without a single enforcement owner [3][5].

The counter-view: enforcement is not absent - The 2025 Directions consolidated scattered norms and added data localisation with 24-hour repatriation of overseas-processed data [2]. - RBI's DLA Directory (operational 1 July 2025) lets borrowers verify an app's link to a Regulated Entity [5]. - MeitY has blocked 87 illegal loan apps under Section 69A, IT Act [5] — coordinated, not merely declaratory, action. - Reporting through the CIMS portal builds the compliance database enforcement requires [2].

The gap, therefore, is one of supervisory technology and last-mile verification, not of regulatory intent. Moving from disclosure-based to audit-based supervision — periodic technical audits of app permissions, penalties on the Regulated Entity for its LSP's conduct, and early constitution of the Data Protection Board — would align practice with norm. Judicial insistence on a counter-affidavit detailing "action taken" is thus a healthy accountability nudge, converting Article 21's privacy guarantee into an enforceable regulatory duty.

(~330 words)

Sources: 1. Reserve Bank of India (Digital Lending) Directions, 2025 — RBI Notification, 8 May 2025 — prohibited access to file/media, contact list, call logs, telephony functions (Para 12); coverage of REs, LSPs and DLAs 2. RBI (Digital Lending) Directions, 2025 — data storage and reporting provisions — Para 13 data localisation and 24-hour deletion from overseas servers; CIMS reporting 3. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitY — consent standard and Data Protection Board of India 4. Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) — Supreme Court of India — right to privacy under Article 21, including informational control 5. Government and RBI have taken several measures to Strengthen Digital Lending Ecosystem — PIB — DLA Directory operational from 01.07.2025; 87 illegal loan apps blocked under Section 69A, IT Act