Delhi HC Seeks RBI Response on Data Practices of Digital Lending Apps: The Push for Fintech Accountability The rapid rise of digital lending in India has transformed access to quick, short - term credit. However, this convenience has increasingly come at the cost of personal privacy. In a major legal development, the Delhi High Court sought a response from the Re serve Bank of India (RBI) regarding the intrusive data practices and privacy violations allegedly committed by several digital lending applications (DLAs). This judicial intervention marks a critical turning point for fintech regulation in India, forcing regulators and platforms alike to address the balance between financial inclusion and consumer protection. The Judicial Notice: What Prompted the Delhi High Court’s Action? The decision by the Delhi High Court to issue a formal notice to the RBI, the Uni on Government, and major app platforms stems from a Public Interest Litigation (PIL). The petition raised urgent concerns over how digital lending platforms handle borrower data, alleging that many apps continue to bypass regulatory boundaries despite exis ting guidelines. A Division Bench comprising Chief Justice Devendra Kumar Upadhyaya and Justice Tejas Karia directed the RBI to file a counter - affidavit detailing its active supervisory actions, enforcement mechanisms, and penalties imposed on non - complia nt entities. The court’s stance emphasizes that issuing policy frameworks is not enough — active policing and enforcement are required to protect vulnerable borrowers from predatory data practices. Regulatory Standards vs. Ground Reality To address recurr ing issues in the digital credit sector, the central bank previously issued the RBI (Digital Lending) Directions . These guidelines established strict rules to safeguard borrower data and mandate transparency: Restricted Data Access: Apps are strictly pro hibited from scraping hardware resources such as contact books, call logs, media galleries, and social media data. One - Time Permission Limits: Access to hardware features like the camera, microphone, or location is restricted to a single use for identity verification and Know Your Customer (KYC) onboarding. Data Minimization: Lenders can only collect data that has a clear, reasonable connection to credit assessment and underwriting. Direct Disbursement: Funds must flow directly between the regulated lender (Bank/NBFC) and the borrower, bypassing third - party pool accounts. Despite these clear boundaries, the PIL presented before the High Court highlighted several widespread violations across popular plat forms. ┌───────────────────────────────────────────────────────────┐ │ RBI REGULATORY COMPLIANCE CHECK │ ├────────────────────────────┬──────────────────────────────┤ │ Mandated Safeguard │ Alleged Ground Reality │ ├────────────────────────────┼──────────────────────────────┤ │ Contact Access Banned │ Intrusive Scrape for Recovery│ │ One - Time Camera/Mic Access │ Persistent Background Tracking│ │ Explicit Consent Required │ "Take - it - or - Leave - it" Policies│ │ Dom estic Data Storage │ Unauthorized Third - Party Transfer│ └────────────────────────────┴──────────────────────────────┘ Key Allegations Highlighted in the Petition The petition specifically pointed out three major areas where digital lending apps report edly fail to adhere to privacy mandates: 1. Involuntary and Coercive Consent Many lending apps deploy "take - it - or - leave - it" consent models. Borrowers who attempt to opt out of non - essential data collection are frequently denied access to credit entirely. This practice violates the principle of voluntary, informed consent as outline d under India’s Digital Personal Data Protection (DPDP) Act 2. Excessive Hardware Access Despite explicit RBI bans, several apps allegedly continue to ping contacts and access media files under the guise of security or risk assessment. This data is ofte n used during debt collection cycles, leading to harassment of borrowers' friends and family members. 3. The "Enforcement Gap" A core contention in the petition is the perceived delay between reporting a violation and taking action. Despite complaints fi led directly with regulators, many non - compliant apps remain available on major app marketplaces like the Google Play Store and Apple App Store. What This Means for the Future of Fintech in India As the Delhi High Court awaits the RBI’s formal counter - af fidavit, this case is set to shape the future of digital finance regulation in several key ways: 1. Stricter App Store Gatekeeping: Regulators may mandate tighter coordination with tech platforms to instantly pull down apps that violate data guidelines. 2. Ma ndatory Audits: Non - Banking Financial Companies (NBFCs) partnering with digital lending apps may face compulsory third - party privacy audits. 3. Suspension of Licenses: If systematic violations are proven, the RBI may move from issuing warnings to revoking th e operating licenses of non - compliant lenders. The ongoing proceedings at the Delhi High Court serve as a reminder that consumer data privacy cannot be sacrificed for speed and convenience in digital credit. Best Practices for Digital Lending Borrowers While regulatory frameworks continue to evolve, consumers taking out loans through mobile apps should adopt basic privacy precautions: Audit App Permissions: Check your device settings and revoke access to your contacts, call logs, and gallery for any fi nancial app. Verify Regulated Lenders: Ensure the app clearly discloses its partner Bank or RBI - registered NBFC before accepting loan terms. Review the Key Fact Statement (KFS): Read the KFS carefully to understand the total Annual Percentage Rate (APR), hidden fees, and data retention policies. Report Intrusive Behavior: File a formal complaint on the RBI’s Sachet portal if an app attempts to scrape your personal data or harass secondary contacts. https://zenyalegal.com/expertise/data - protection - privacy