The Delhi HC's notice to RBI over non-enforcement of digital lending guidelines reveals a structural gap between rule-making and rule-enforcement in India's financial regulatory architecture. Critically examine.
The Delhi High Court's notice to the RBI and the Centre on a PIL alleging that NBFC-run digital lending apps (DLAs) still harvest contact lists and call logs despite the RBI (Digital Lending) Directions, 2025 [1][2] reopens a familiar question: India's financial regulation is rich in norms but thin in verified compliance. The gap is real, though not total.
Evidence of a rule-making–enforcement gap
- Persisting violations: the 2025 Directions expressly bar DLAs from accessing file/media, contact lists, call logs and telephony functions, yet the petition alleges continued access [1][2] — a norm on paper, not on devices.
- Coercive consent: non-negotiable privacy policies as a condition of service defeat the "free and informed" consent standard of the DPDP Act, 2023 [3], and informational self-determination under Article 21 (Puttaswamy, 2017) [4].
- Supervisory capacity: regulation extends to Regulated Entities, their LSPs and DLAs [1][5], but ex-post, complaint-driven supervision cannot police app-level permissions at scale.
- Fragmented accountability: the DPDP Act's Data Protection Board (MeitY) and RBI's sector rules create overlapping mandates without a single enforcement owner [3][5].
The counter-view: enforcement is not absent
- The 2025 Directions consolidated scattered norms and added data localisation with 24-hour repatriation of overseas-processed data [2].
- RBI's DLA Directory (operational 1 July 2025) lets borrowers verify an app's link to a Regulated Entity [5].
- MeitY has blocked 87 illegal loan apps under Section 69A, IT Act [5] — coordinated, not merely declaratory, action.
- Reporting through the CIMS portal builds the compliance database enforcement requires [2].
The gap, therefore, is one of supervisory technology and last-mile verification, not of regulatory intent. Moving from disclosure-based to audit-based supervision — periodic technical audits of app permissions, penalties on the Regulated Entity for its LSP's conduct, and early constitution of the Data Protection Board — would align practice with norm. Judicial insistence on a counter-affidavit detailing "action taken" is thus a healthy accountability nudge, converting Article 21's privacy guarantee into an enforceable regulatory duty.
Sources
- 1Reserve Bank of India (Digital Lending) Directions, 2025 — RBI Notification, 8 May 2025prohibited access to file/media, contact list, call logs, telephony functions (Para 12); coverage of REs, LSPs and DLAs
- 2RBI (Digital Lending) Directions, 2025 — data storage and reporting provisionsPara 13 data localisation and 24-hour deletion from overseas servers; CIMS reporting
- 3The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYconsent standard and Data Protection Board of India
- 4Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) — Supreme Court of Indiaright to privacy under Article 21, including informational control
- 5Government and RBI have taken several measures to Strengthen Digital Lending Ecosystem — PIBDLA Directory operational from 01.07.2025; 87 illegal loan apps blocked under Section 69A, IT Act