The model knows thingsthe customer was never told.
Alternative data is an edge only while it is a declared one.
In one line: Only if the purpose was clearly notified and the customer gave specific consent for it, and subject to RBI rules on app data access. Data collected for another purpose cannot be repurposed without a new basis.
A secret input is not a competitive advantage. It is a finding.
The scene
The credit model's best feature was the time of day customers charged their phones. It predicted default beautifully. The data came from an SDK installed for crash reporting. The privacy notice mentioned crash reporting.
Where the thinking breaks
Explaining a decision
DPDPA gives Data Principals the right to a summary of personal data processed and the processing activities. A lender that cannot say what fed a decision cannot answer that request.
Monday morning
- 01List every input to the credit model and its source.
- 02Match each source to the purpose declared at collection.
- 03Retire inputs with no matching purpose.
Questions, answered plainly
Can fintechs use SMS data for credit scoring under DPDPA?
Only if the purpose was clearly notified and the customer gave specific consent for it, and subject to RBI rules on app data access. Data collected for another purpose cannot be repurposed without a new basis.
Do customers have a right to know what data a lender used?
Section 11 gives Data Principals the right to obtain a summary of personal data being processed and the processing activities undertaken.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner