A wave of predatory lending apps — aggressive recovery tactics, hidden charges, opaque data collection — pushed RBI to draw a hard structural line: fintech apps can originate and market loans, but the money itself has to move directly between the regulated lender and the borrower, with nothing routed through the app's own account.
RBI's digital lending guidelines require that all loan disbursals and repayments must be executed directly between the borrower's bank account and the account of the Regulated Entity (RE) — the bank or NBFC actually extending the loan. Funds are not permitted to be routed through any pooled or pass-through account of the Lending Service Provider (LSP) — the fintech app or platform facilitating the loan.
Lenders must provide borrowers a standardised Key Fact Statement before loan execution, disclosing the all-inclusive cost of the loan (Annual Percentage Rate, capturing interest plus all other charges) in a clear, comparable format — addressing the historical practice of digital lending apps advertising a low headline interest rate while burying substantial processing fees, penal charges, and other costs elsewhere in the loan terms.
Borrowers are given a cooling-off / look-up period during which they can exit the digital loan by paying the principal and proportionate APR, without additional penalty — giving borrowers a genuine window to reconsider a loan taken in haste (a common pattern with instant-approval digital lending apps) without being locked into unfavourable terms immediately.
Digital lending apps are restricted from collecting borrower data beyond what is necessary for the specific loan product, must obtain explicit borrower consent for each specific data access (rather than blanket permissions bundled at app installation), and must not access certain categories of device data (contact lists, media files, call logs) unless genuinely necessary and separately consented to — this directly targets the well-documented pattern of predatory apps mining borrowers' phone contacts for coercive recovery tactics.
Lenders and their agents are required to follow a defined code of conduct for loan recovery — restrictions on contact timing, prohibition of intimidation or harassment, and accountability of the regulated entity for the conduct of any recovery agents engaged on its behalf, even where a third-party agency is used.
These guidelines operate by placing compliance responsibility squarely on the Regulated Entity (the licensed bank/NBFC), not on the LSP/fintech app directly — since the LSP itself is often not an RBI-regulated entity in its own right. This means the RE bears responsibility for ensuring its lending-partner apps comply, which has pushed banks and NBFCs to tighten their due diligence and ongoing oversight of the fintech platforms they partner with, since regulatory action for non-compliance lands on the RE.
Use the current official instrument, portal or regulator publication before acting. This panel separates the category authority from page-specific references.
The prior page did not embed a page-specific external source. The category authority above is the minimum verification starting point; a specific instrument should be added during the next substantive editorial review.