🚀 Trusted by 10,000+ businesses across India — Start Right, Grow FastLearn more →

RBI

Data Privacy and Cybersecurity Compliance for Digital Lenders

SShubhajit Sharma22 September 20269 min read
Data Privacy and Cybersecurity Compliance for Digital Lenders

Digital lending businesses collect a large amount of borrower information within minutes.

A lender may collect identity information, financial records, bank details, credit information, device information, and other personal data during customer onboarding, underwriting, loan servicing, and recovery.

That creates a significant compliance responsibility. For Indian digital lenders, data protection is no longer only an IT or privacy-policy issue. Data Privacy and Cybersecurity Compliance for Digital Lenders now covers RBI regulation, cybersecurity controls, outsourcing arrangements, consent management and the Digital Personal Data Protection framework.

The RBI Digital Lending Directions, 2025 introduced specific requirements around borrower data, consent, storage, third-party sharing and the oversight of Lending Service Providers. Alongside this, the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 bring a wider data protection framework into the picture.

RBI Digital Lending Directions, 2025 and borrower data

The RBI issued the Digital Lending Directions, 2025 on May 8, 2025. The Directions consolidated the earlier regulatory framework for digital lending and brought several requirements relating to borrower data and technology under one framework. One of the most important changes for lenders is the focus on the way data is collected.

A lending app should not have access to a borrower's phone simply because the technical permission is available. The RBI framework restricts access to resources such as contact lists, call logs, files, and media. Access to facilities such as the camera, microphone or location is expected to be limited to situations where it is necessary for onboarding or KYC, with explicit borrower consent.

This has an important implication for digital lenders. When reviewing an app, the question should not only be whether a particular permission is technically enabled. The lender should ask why the permission is needed and whether the lending process can operate without it.

That is also where the consent mechanism becomes important. A borrower should know what information is being collected and why. The lender should be able to demonstrate when consent was obtained and what the borrower consented to.

The data collection problem starts with the app

Consider a simple digital loan application. The borrower installs the app, completes KYC, uploads documents, provides bank details, and submits the loan application. Several systems may then process this information. The NBFC's loan management system may receive it. A KYC provider may verify documents. An underwriting platform may analyse the application. An LSP may manage parts of the customer journey.

At every stage, another data flow is created. This is why lenders should map the complete borrower journey instead of reviewing the privacy policy in isolation.

For each stage, the lender should know:

  • What information is collected?

  • Why is it required?

  • Who receives it?

  • Where is it stored?

  • How long is it retained?

  • Who can access it?

  • What happens when the information is no longer required?

Without this mapping, it is difficult to identify unnecessary data collection or understand where borrower information is actually moving.

Where is the borrower's data stored?

Data storage is another area where digital lenders need to pay close attention. The RBI Digital Lending Directions require data related to digital lending to be stored on servers located in India. The framework also requires appropriate policies covering data storage, retention and destruction, along with procedures for handling security breaches. This can become complicated when a lender uses cloud infrastructure or works with international technology vendors.

The question is not simply where the main database is located. A proper review should also look at backups, disaster recovery systems, replicated databases and other environments where borrower information may be copied.

Third-party access is a major compliance area

Most digital lenders do not operate the entire lending journey themselves. There may be an LSP handling the digital interface, a KYC provider verifying documents, a technology company providing underwriting infrastructure and another vendor supporting collections. Each relationship needs to be examined from a data protection perspective.

The RBI framework requires prior and explicit borrower consent for sharing personal information with third parties, except where sharing is required by law or regulation. Relevant third parties that collect information through the digital lending app also need to be identified in the privacy policy.

Outsourcing a function does not mean outsourcing the regulatory responsibility. If an LSP mishandles borrower information, the NBFC cannot simply point to the vendor agreement and treat the matter as the vendor's problem. The regulated entity needs appropriate due diligence, contractual protections, monitoring and oversight of its partners.

This makes vendor due diligence an important part of digital lending compliance.

Data Privacy and Cybersecurity Compliance for Digital Lenders

Cybersecurity must be integrated into the overall compliance framework. Data privacy determines what information a lender should collect and how it should handle that information. Cybersecurity determines how that information is protected in practice.

For a digital lender, basic security controls should cover the complete technology environment. Borrower data should be protected while it is being transmitted and while it is stored. Access should be restricted according to job responsibilities. Sensitive information such as PAN, Aadhaar and bank account details should not be unnecessarily exposed to employees or support teams.

If sensitive borrower information is accessed, the lender should be able to determine who accessed it, when it happened and what system was involved.

Other areas that deserve regular review include application security, vulnerability testing, privileged access, API security, incident response and vendor security. The RBI Directions require regulated entities and their partners involved in digital lending to follow applicable cybersecurity standards and RBI requirements.

What happens when there is a data breach?

A breach response plan should not begin after an incident occurs. Digital lenders operate under multiple reporting requirements. CERT-In requires covered cyber incidents to be reported within six hours of noticing or being brought to notice of the incident. The DPDP framework introduces its own breach notification requirements, including reporting to the Data Protection Board and affected individuals as applicable.

The DPDP framework requires notification to the Board without delay, followed by a detailed report within 72 hours.

For a lender, this creates a simple operational lesson. Do not build your incident response process around the 72-hour period. Your internal escalation should start much earlier. The security team needs to identify the incident. Compliance and legal teams need to assess the regulatory implications. Management needs to know what happened. The organisation then needs to determine the required notifications and corrective action.

This process should be tested periodically.

DPDP Act and Rules: Why lenders should start preparing now

The DPDP framework adds another layer to the data governance obligations of digital lenders. The Digital Personal Data Protection Rules, 2025 were notified in November 2025, with full substantive compliance scheduled from May 13, 2027.

For an established NBFC with years of borrower data, multiple vendors and several lending products, however, data clean-up can take considerable time.

A lender may have millions of borrower records collected over several years. The organisation needs to understand what information it holds, why it was collected, whether the necessary consent records exist and how long the information should be retained.

The same applies to vendor contracts. If dozens of technology and operational partners process borrower information, updating contracts, reviewing security controls and documenting responsibilities can take time.

RBI and DPDP requirements need to be mapped together

A common mistake is to treat data privacy and cybersecurity compliance for digital lenders as two completely separate projects under RBI and DPDP requirements. For example, RBI requirements focus specifically on digital lending and impose requirements around borrower consent, data collection, storage and LSP oversight. The DPDP framework creates broader obligations relating to personal data processing, security safeguards and data principal rights.

The practical approach is to create one data governance framework and map the applicable requirements against it. For example:

  • A consent flow should satisfy the relevant RBI requirements while also supporting the requirements of the DPDP framework.

  • A vendor agreement should address both RBI outsourcing expectations and data protection responsibilities.

  • An incident response plan should account for the different regulatory reporting requirements.

  • A data retention policy should consider both regulatory record-keeping needs and personal data deletion requirements.

This approach is easier to manage than creating separate compliance processes that operate independently.

Data Privacy and Cybersecurity Compliance Checklist for Digital Lenders

Before the next compliance review, an NBFC or digital lending business should:

  • Map every category of personal data collected through its lending application.

  • Review app permissions and remove access that is not required for the lending process.

  • Maintain a clear audit trail of borrower consent.

  • Provide borrowers with appropriate mechanisms to deny or withdraw consent.

  • Maintain visibility over where primary data and backups are stored.

  • Verify that data storage arrangements comply with applicable RBI requirements.

  • Identify all LSPs and vendors that can access borrower information.

  • Complete appropriate due diligence on third-party service providers.

  • Ensure vendor contracts cover data security, audit rights, breach reporting and data deletion requirements.

  • Maintain records that allow the organisation to identify access to sensitive borrower information.

  • Conduct periodic security assessments of the lending application and supporting systems.

  • Ensure the incident response plan addresses the applicable six-hour CERT-In reporting requirement.

  • Establish processes to respond to potential DPDP breaches within the applicable timelines.

  • Review and properly document legacy borrower data, including its purpose, retention period and consent records.

  • Keep RBI digital lending records and CIMS information accurate and up to date.

Common gaps found in digital lending operations

The biggest gaps are not always complicated technical vulnerabilities. Sometimes they are operational. A collection executive may retain borrower information on a personal device. An old vendor may still have access to customer records after the engagement ends. A cloud backup may not have been included in the original data-location assessment.

In another case, the privacy policy may mention a third party, but the internal team may not have documented exactly what data that third party receives. Legacy loan accounts can create another problem when the lender cannot easily produce the consent trail associated with older records.

These are the areas where technology, operations and compliance meet. That is why a data privacy review should involve more than the IT team.

What should digital lenders do now?

The first step should be a data-mapping exercise. Take one lending product and follow the borrower journey from application to loan closure. Document every system involved and every party receiving borrower information. Then review the findings against the RBI Digital Lending Directions, 2025, applicable cybersecurity requirements and the DPDP framework. From there, the lender can prioritise the gaps.

Some may require an application change. Others may require a new vendor contract, a change in access controls, better consent records or a review of legacy data. The objective is to make sure that the way the digital lending business actually handles borrower data matches the regulatory framework.

For NBFCs and digital lenders, data privacy and cybersecurity compliance are now closely connected to the overall regulatory framework. Lenders that start with their data flows, vendors, technology controls and records can identify gaps well before those gaps become a regulatory or operational problem.

The Way Forward

A common, expensive mistake is treating RBI compliance and DPDP readiness as two separate engineering sprints. They are two sides of the same coin.

Your product and engineering teams shouldn't build one consent flow for banking rules and a completely different toggle for privacy rules. A unified data governance framework is the only sustainable way to build fintech products today.

Start by picking your primary lending product. Trace a single borrower's data footprint from the first app install to the final loan closure. Find the gaps before the regulator does.