The right to informational privacy under Article 21 is increasingly threatened by data-intensive fintech models. Analyse the adequacy of India's legal and regulatory framework to address this challenge.
Q. The right to informational privacy under Article 21 is increasingly threatened by data-intensive fintech models. Analyse the adequacy of India's legal and regulatory framework to address this challenge. (15 marks, 250-350 words)
Informational privacy — the individual's control over personal data — was held integral to Article 21 by the nine-judge bench in K.S. Puttaswamy (2017) [1]. Digital lending apps (DLAs), which monetise device-level data, test whether India's framework protects this right in practice, not merely on paper.
How fintech models threaten informational privacy - Excessive data harvesting: DLAs seek access to contact lists, call logs, media files and telephony functions bearing no nexus to KYC or credit assessment [2]. - Coercive consent: broad, non-negotiable privacy policies imposed as a condition of service render consent involuntary, defeating the "free, specific, informed" standard [3]. - Power asymmetry: low-income, first-time borrowers cannot negotiate terms; harvested contacts have historically been weaponised for recovery harassment [2].
Strengths of the existing framework - Constitutional: Puttaswamy subjects data collection to legality, necessity and proportionality [1]. - Statutory: the DPDP Act, 2023 codifies purpose limitation, data minimisation and consent, with MeitY as nodal ministry [4]. - Sectoral: the RBI (Digital Lending) Directions, 2025 mandate need-based collection, storage of borrower data in India, disclosure of third parties with data access, and cover Regulated Entities and their Lending Service Providers [2][3]. - Institutional: RBI's public DLA Directory (operational from 1 July 2025) lets borrowers verify an app's link to a regulated lender; MeitY has blocked scores of illegal loan apps under Section 69A, IT Act [3].
Persisting inadequacies - Enforcement deficit: the Delhi High Court, hearing a PIL, sought RBI's counter-affidavit on action actually taken to enforce the 2025 Directions — rule-making has outpaced rule-enforcement [2]. - Institutional lag: the Data Protection Board is yet to become a fully functioning grievance forum [4]. - Coverage gap: the Directory and Directions bind only regulated entities; unregistered apps operate outside them [3]. - Fragmented oversight between RBI and MeitY dilutes accountability.
India's framework is normatively sound but operationally thin. Strengthening supervisory audits of lending apps, expediting the Data Protection Board, and building consent literacy would convert the proportionality mandate of Puttaswamy into lived protection — making digital credit inclusive without making borrowers surveilled.
(~330 words)
Sources: 1. K.S. Puttaswamy (Retd.) v. Union of India, Supreme Court of India, 24 August 2017 — right to informational privacy under Article 21; proportionality standard 2. PIB, "Government and RBI have taken several measures to Strengthen Digital Lending Ecosystem" — RBI (Digital Lending) Directions, 2025; prohibited data access; data storage in India; enforcement concerns 3. PIB, "Government and RBI Strengthen Measures Against Fraudulent Loan Apps" — DLA Directory from 1 July 2025; coverage of REs and LSPs; blocking of illegal loan apps under Section 69A 4. The Digital Personal Data Protection Act, 2023, MeitY — consent, purpose limitation, data minimisation; Data Protection Board