Your onboarding takes ninety seconds.Your liability lasts years.

Digital lending already restricts what an app may access. DPDPA adds a question behind every data point: for which purpose?

In one line: An operating-system permission grants technical access; it does not by itself provide the notice of purpose and the specific consent Section 5 and Section 6 require. Apps should pair permissions with a clear notice and choice.

The estate · Fintech & NBFCHover to inspect

Fast onboarding. Slow consequences.

The scene

The app asked for contacts, location, SMS and storage in one screen. Approval rates were excellent. The credit model used SMS parsing no customer had been told about. When the first customer asked what data the app held, nobody could export it in under a week.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
If the user allows the permission, we have consent. An OS permission is not a notice; it does not state purpose. Pair every permission with a purpose the customer can read and refuse.
Alternative data is our edge. Data collected for one purpose cannot quietly feed another. Declare the scoring purpose up front, or do not use the data.
The LSP handles collections. Lending service providers act on your behalf; their conduct is your exposure. Treat every LSP as a processor under contract and audit.

Account aggregators as a model

India's account aggregator framework already runs on granular, revocable, purpose-bound consent. It is the closest existing picture of what DPDPA consent should feel like.

The full Fintech & NBFC briefing

3 deep dives
Deep dive 01→

Permission is not consent. It is only access.

‘Allow’ opens the door. It does not tell the customer what you will do inside.

Deep dive 02→

The model knows things the customer was never told.

A secret input is not a competitive advantage. It is a finding.

Deep dive 03→

The consent model already exists. Copy it.

India built the right consent once. Now build it everywhere.

Monday morning

  1. 01List every app permission and the purpose it serves.
  2. 02Remove any permission whose purpose you cannot write in one line.
  3. 03Audit the top three lending service providers for data handling.

Questions, answered plainly

Is an Android or iOS permission valid consent under DPDPA?

An operating-system permission grants technical access; it does not by itself provide the notice of purpose and the specific consent Section 5 and Section 6 require. Apps should pair permissions with a clear notice and choice.

Are lending service providers Data Processors under DPDPA?

Where they process borrower data on behalf of a regulated lender, they generally act as Data Processors, and the lender as Data Fiduciary remains responsible under Section 8(1).

Sector · Healthcare & PharmaThe Act has no 'sensitive' category. Your patients do.Read → Sector · EdTechA child's data is not a cookie. Stop treating it like one.Read → Sector · E-commerce & D2CYour funnel runs on consent. The Act just redefined consent.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner