Evaluate the key provisions of the RBI (Digital Lending) Directions, 2025 with respect to consumer protection and data sovereignty. What enforcement mechanisms are available to the RBI?
Issued on 8 May 2025, the RBI (Digital Lending) Directions consolidate the 2022 guidelines into a single framework binding Regulated Entities (REs), Lending Service Providers and Digital Lending Apps (DLAs) [1]. Judged on outcomes, they are strong in design but uneven in enforcement.
Merits — consumer protection
- Transparency: mandatory disclosure of the Annual Percentage Rate and a Key Fact Statement before sanction, with a look-up/cooling-off period for exit without penalty [1].
- Accountability: the RE remains liable for the conduct of its LSPs, including recovery practices and grievance redressal [1].
- Verifiability: the DLA Directory, operational from 1 July 2025, lets borrowers verify an app's claimed link to an RE [4].
- Default Loss Guarantee norms cap risk-transfer arrangements, curbing reckless lending by unregulated partners [1].
Merits — data sovereignty
- Data minimisation: collection restricted to need-based data; access to contact lists, call logs, files/media and telephony functions is prohibited [1][2].
- Localisation: borrower data must be stored in India, with data processed abroad repatriated within 24 hours and deleted overseas [1].
- Privacy policies must publicly name all third parties receiving personal data, aligning with the DPDP Act, 2023 [2].
Limitations
- The Directory covers only REs' apps; illegal apps operate outside the regulatory perimeter — MeitY has blocked 87 such apps under Section 69A, IT Act [3].
- Consent remains coercive in practice: the Delhi High Court, hearing a PIL in January 2026, asked RBI to detail enforcement action, signalling a rule-making versus rule-enforcement gap [5].
- Overlapping jurisdiction with the Data Protection Board risks fragmented redress.
Enforcement toolkit: off-site surveillance and on-site inspection; monetary penalties and cancellation of NBFC registration under Section 45-IA, RBI Act, 1934; business restrictions; the RBI Integrated Ombudsman for consumer complaints; public cautions [2]; and referral to MeitY for blocking rogue apps [3].
The Directions are a credible consumer-protection charter; the deficit lies in supervisory bandwidth. Strengthening the Data Protection Board, publishing enforcement dashboards and app-store gatekeeping can convert paper rights into real protection — securing informational privacy under Article 21 alongside credit inclusion.
Sources
- 1Reserve Bank of India (Digital Lending) Directions, 2025 — RBI/2025-26/36, dated May 8, 2025scope, APR/KFS and cooling-off, RE liability for LSPs, DLG, data minimisation, prohibited phone permissions, localisation and 24-hour repatriation
- 2Government and RBI have taken several measures to Strengthen Digital Lending Ecosystem — PIBthird-party disclosure and DPDP Act alignment; RBI public cautions against unauthorised platforms
- 3Government and RBI Strengthen Measures Against Fraudulent Loan Apps — PIB87 illegal loan apps blocked by MeitY under Section 69A, IT Act, 2000
- 4Government and RBI Strengthen Digital Lending Ecosystem Through New Regulatory Framework, Digital Lending App Directory and Enhanced Customer Safeguards — PIBDLA Directory operational from July 1, 2025
- 5"Delhi HC seeks RBI's stand on PIL plea over data protection" — *The Hindu*, January 8, 2026 — Delhi HC notice to RBI on enforcement of the 2025 Directions and coercive consent