
Most conversations about digital lending rules focus on interest rates and recovery conduct, and rightly so, but a quieter, equally significant shift has been happening alongside it. Since 2023, two separate legal frameworks now govern what a lending app can do with your personal data, and they overlap in ways most borrowers, and honestly a fair number of lenders, have not fully absorbed yet. One specific right buried in this framework is worth knowing about before you ever apply for a loan, what happens to your data if your application gets rejected.
Here is how India’s digital lending data rules actually work in 2026, and what specific protections exist around your information that go well beyond the usual interest rate and recovery conversation.
Two Separate Laws Now Govern Your Data
RBI’s own Digital Lending Directions set specific, sector-focused rules for lending apps, restricting what data they can collect and how. Running alongside this, the Digital Personal Data Protection Act, 2023, along with its 2025 Rules, applies a broader, statutory layer of protection across every digital platform handling personal data in India, lending apps included. This overlap matters practically, since a data practice that once might have only violated an RBI circular can now also constitute a statutory consent violation under the DPDP Act, carrying its own separate, considerably larger penalty structure.
What Data an App Can Actually Collect
Under both frameworks together, a lending app is restricted to need-based data collection with your prior, explicit consent, and this consent must be recorded with an audit trail. Camera, microphone, and location access can only be requested on a one-time basis specifically for KYC verification, such as a video KYC session, and lending platforms are explicitly barred from accessing your contacts, call logs, or photo gallery. Google Play has actively been removing apps found violating this specific restriction. Your consent itself must be granular, meaning you can agree to some data uses and not others, rather than an all-or-nothing checkbox, and it must include a genuine right to revoke that consent and request deletion at any point.
The Right to Be Forgotten After a Rejected Loan Application
This is a protection worth knowing about specifically because almost nobody does. If your loan application is rejected, the lender is required to delete all borrower data collected during that application process within 30 days. In practice, this means a rejected application should not leave a permanent data trail sitting on a lender’s servers indefinitely, available to be repurposed for future marketing or resold to other platforms. If you have been rejected by a lender and are concerned about what happened to the information you shared, you are entitled to ask the platform to confirm this deletion has occurred, and a lender’s failure to do so is a genuine compliance violation you can raise through the grievance channels covered below. Our guide to why personal loan applications get rejected is worth reading alongside this if you have recently been declined and want to understand both why it happened and what should now happen to your data.
Where Your Data Must Be Stored
Digital lending platforms, along with related entities like NBFC peer-to-peer platforms and account aggregators, are required to store your data within India, a requirement drawn from both the RBI’s KYC Master Direction and Section 9 of the DPDP Act. This data localisation rule exists specifically to keep Indian borrower data under Indian regulatory jurisdiction, rather than allowing it to sit on servers subject to a different country’s laws and access requests.
What Happens If Your Data Is Breached
If a lending platform suffers a data breach involving your personal information, it is required to report this to India’s Data Protection Board within 72 hours of becoming aware of it. This is a considerably stricter and more specific timeline than most borrowers would assume exists, and it exists precisely because delayed breach disclosure has historically left affected individuals unaware of exposure for weeks or months at a time.
Your Grievance Redressal Officer Must Be a Real Employee
Every RBI-regulated digital lender is now required to appoint a nodal Grievance Redressal Officer, and as of 2026, this individual must be an actual employee of the bank or NBFC itself, not a third-party call centre agent reading from a script. Your Key Fact Statement must include this officer’s direct email and phone number. Complaints submitted to this officer must be acknowledged within 24 hours and resolved within 30 days. If you remain unsatisfied with the outcome, you can escalate to the RBI’s Integrated Ombudsman Scheme for digital lending specifically, the same escalation route covered in our guide to RBI borrower rights on personal loans. Our guide to safe, regulated digital loan apps covers how to verify that the app you are dealing with is actually subject to these obligations in the first place, since an unregistered operator sits outside this entire framework.
How Lender and LSP Liability Actually Works
Many digital lending apps are not themselves the lender, they operate as a Lending Service Provider acting on behalf of a bank or NBFC, the Regulated Entity actually extending the credit. If an LSP mishandles borrower data or engages in unfair recovery practices, the Regulated Entity it represents remains directly liable for that conduct, facing fines of up to ₹1 crore or even licence revocation under Section 47A of the Reserve Bank of India Act. This liability structure exists specifically so that a bank or NBFC cannot outsource its compliance obligations to a technology partner and disclaim responsibility when something goes wrong on the app-facing side of the relationship.
Penalties That Make This Framework Genuinely Enforceable
The DPDP Act carries penalties considerably steeper than most RBI circular violations historically did, with fines reaching up to ₹250 crore per breach for significant violations, entirely separate from and in addition to whatever penalty RBI itself might impose on the same lender for the same underlying failure. Larger digital lending platforms are additionally required to appoint a dedicated Data Protection Officer and undergo annual compliance audits, formalising data governance as a board-level responsibility rather than a technical afterthought. Enforcement across the full DPDP framework is expected to fully close out by May 2027, meaning the compliance runway for lenders is genuinely tightening this year and next.
What This Actually Means for You as a Borrower
Practically, this framework gives you specific, actionable levers if a lending app oversteps. You can ask, and are entitled to a real answer, why an app needs a specific permission before granting it, and you can decline access to your contacts or gallery outright, since these are excluded from legitimate use regardless of what the app’s own onboarding flow implies. If you are rejected, you can follow up on data deletion rather than assuming it happens automatically. And if something does go wrong, whether a data misuse issue or a recovery conduct problem, you now have a clearer, faster path through a named Grievance Redressal Officer rather than a generic support inbox that may or may not respond.
Frequently Asked Questions
Does a lending app have to delete my data if my loan is rejected?
Yes. Under current digital lending rules, a lender is required to delete all borrower data collected during a rejected application within 30 days. This is specifically meant to prevent your information from being retained indefinitely or repurposed after a rejection.
Can a lending app access my contacts or photo gallery?
No. Digital lending apps are explicitly barred from accessing your contacts, call logs, or photo gallery under current RBI and DPDP rules. They can only request one-time camera, microphone, or location access specifically for KYC verification purposes.
What is the deadline for a lending platform to report a data breach?
A digital lending platform must report a data breach involving your personal information to India’s Data Protection Board within 72 hours of becoming aware of it, a considerably stricter timeline than many borrowers assume exists.
Who is responsible if a lending app mishandles my data, the app or the bank behind it?
The Regulated Entity, the bank or NBFC actually extending the credit, remains directly liable even when a Lending Service Provider operates the customer-facing app on its behalf. This entity can face fines up to ₹1 crore or licence revocation for the LSP’s mishandling of borrower data.
Must my lending app’s grievance officer be a real bank employee?
Yes, as of 2026. The nodal Grievance Redressal Officer for a digital lending app must be an actual employee of the regulated bank or NBFC, not a third-party call centre agent, and their direct contact details must be disclosed in your Key Fact Statement.




