Back to Knowledge Hub
Regulatory Compliance September 2026 9 min read Fintech Regulatory Counsel

RBI Digital Lending Guidelines: Borrower Rights, FLDG, KFS & Data Sovereignty

The proliferation of digital lending applications and fintech platforms has revolutionized retail and MSME credit accessibility. To eliminate predatory lending practices, usurious interest rates, unconsented data harvesting, and aggressive recovery tactics, the Reserve Bank of India (RBI) established a comprehensive Digital Lending Regulatory Architecture.

Whether you are a retail borrower taking an instant personal loan or a financial institution operating in the fintech ecosystem, understanding these regulatory guidelines is essential. This guide outlines the key rights, technical guardrails, and compliance standards governing digital loans.

1. The Regulated Entity (RE) vs. Lending Service Provider (LSP) Architecture

Under the RBI framework, non-bank fintech apps are classified as Lending Service Providers (LSPs). Crucially, LSPs cannot independently disburse credit or hold borrower funds; they act strictly as technology intermediaries for Regulated Entities (REs)—licensed commercial banks and NBFCs.

Mandatory Direct Fund Flow Rule:
Disbursement: RE Bank Account → Directly to Borrower Bank Account (Zero intermediary pass-through)
Repayment: Borrower Bank Account → Directly to RE Bank Account

Any digital lending platform that routes borrower repayments through third-party pool accounts or unregulated escrow wallets violates RBI directives.

2. The Mandatory Key Fact Statement (KFS)

Before a borrower signs or accepts any digital loan agreement, the lender must provide a standardized Key Fact Statement (KFS). The KFS must explicitly disclose:

  • Annual Percentage Rate (APR): The single, all-inclusive effective annual cost of the loan (combining base interest, processing fees, documentation fees, insurance, and verification charges).
  • Cooling-off / Look-up Period: A statutory window (minimum 1 to 3 days) during which the borrower can cancel the loan by repaying the principal and proportionate APR with zero pre-closure penalty.
  • Grievance Redressal Officer (GRO): Exact contact details, name, phone number, and physical nodal office for complaint escalations.

3. Data Privacy & Mobile Permission Restrictions

The RBI framework enforces strict digital privacy standards to prevent predatory surveillance:

Strictly Prohibited Permissions

Lending apps are strictly forbidden from accessing mobile contact lists, photo galleries, media files, call logs, and continuous background location tracking.

Permitted One-Time Access

One-time camera and microphone access is allowed strictly for Video KYC (V-CIP) onboarding. Location access is permitted solely for one-time geographic KYC verification.

4. First Loss Default Guarantee (FLDG) Framework

In fintech partnerships where an LSP guarantees credit defaults to its partner bank, the RBI caps the Default Loss Guarantee (DLG / FLDG) at a strict maximum of 5% of the total loan portfolio. Furthermore, DLG must be backed by cash deposits, fixed deposits with scheduled banks, or bank guarantees.

5. Ethical Debt Collection Guidelines

Regulated entities and their recovery agents must adhere to strict operational codes of conduct:

  • No calls before 8:00 AM or after 7:00 PM.
  • No harassment, public shaming, or contacting relatives/employers not listed as formal guarantors.
  • Mandatory advance notice prior to assigning any recovery agent to a customer's account.

Summary

India's digital lending regulations protect borrower dignity and financial transparency. Borrowers should always verify that their lending provider issues an official KFS and operates in formal partnership with an RBI-regulated bank or NBFC.

Private In-Browser Credit Technology

CreditCore Ten executes 100% client-side WASM banking forensics, ensuring zero server-side data retention and local browser processing.