·The Hindu·15 marks·250–350 wordsPolityEconomy

The Delhi HC's notice to RBI over non-enforcement of digital lending guidelines reveals a structural gap between rule-making and rule-enforcement in India's financial regulatory architecture. Critically examine.

In this answer
  1. Evidence of a rule-making–enforcement gap
  2. The counter-view: enforcement is not absent

The Delhi High Court's notice to the RBI and the Centre on a PIL alleging that NBFC-run digital lending apps (DLAs) still harvest contact lists and call logs despite the RBI (Digital Lending) Directions, 2025 [1][2] reopens a familiar question: India's financial regulation is rich in norms but thin in verified compliance. The gap is real, though not total.

Evidence of a rule-making–enforcement gap

  • Persisting violations: the 2025 Directions expressly bar DLAs from accessing file/media, contact lists, call logs and telephony functions, yet the petition alleges continued access [1][2] — a norm on paper, not on devices.
  • Coercive consent: non-negotiable privacy policies as a condition of service defeat the "free and informed" consent standard of the DPDP Act, 2023 [3], and informational self-determination under Article 21 (Puttaswamy, 2017) [4].
  • Supervisory capacity: regulation extends to Regulated Entities, their LSPs and DLAs [1][5], but ex-post, complaint-driven supervision cannot police app-level permissions at scale.
  • Fragmented accountability: the DPDP Act's Data Protection Board (MeitY) and RBI's sector rules create overlapping mandates without a single enforcement owner [3][5].

The counter-view: enforcement is not absent

  • The 2025 Directions consolidated scattered norms and added data localisation with 24-hour repatriation of overseas-processed data [2].
  • RBI's DLA Directory (operational 1 July 2025) lets borrowers verify an app's link to a Regulated Entity [5].
  • MeitY has blocked 87 illegal loan apps under Section 69A, IT Act [5] — coordinated, not merely declaratory, action.
  • Reporting through the CIMS portal builds the compliance database enforcement requires [2].

The gap, therefore, is one of supervisory technology and last-mile verification, not of regulatory intent. Moving from disclosure-based to audit-based supervision — periodic technical audits of app permissions, penalties on the Regulated Entity for its LSP's conduct, and early constitution of the Data Protection Board — would align practice with norm. Judicial insistence on a counter-affidavit detailing "action taken" is thus a healthy accountability nudge, converting Article 21's privacy guarantee into an enforceable regulatory duty.

Sources

  1. 1Reserve Bank of India (Digital Lending) Directions, 2025 — RBI Notification, 8 May 2025prohibited access to file/media, contact list, call logs, telephony functions (Para 12); coverage of REs, LSPs and DLAs
  2. 2RBI (Digital Lending) Directions, 2025 — data storage and reporting provisionsPara 13 data localisation and 24-hour deletion from overseas servers; CIMS reporting
  3. 3The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYconsent standard and Data Protection Board of India
  4. 4Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) — Supreme Court of Indiaright to privacy under Article 21, including informational control
  5. 5Government and RBI have taken several measures to Strengthen Digital Lending Ecosystem — PIBDLA Directory operational from 01.07.2025; 87 illegal loan apps blocked under Section 69A, IT Act
Practice
3 questions on this article
Check the answer for each question, or reveal all at once.
Practice MCQs →

More from this note

More on Polity