Your onboarding takes ninety seconds.Your liability lasts years.
Digital lending already restricts what an app may access. DPDPA adds a question behind every data point: for which purpose?
In one line: An operating-system permission grants technical access; it does not by itself provide the notice of purpose and the specific consent Section 5 and Section 6 require. Apps should pair permissions with a clear notice and choice.
Fast onboarding. Slow consequences.
The scene
The app asked for contacts, location, SMS and storage in one screen. Approval rates were excellent. The credit model used SMS parsing no customer had been told about. When the first customer asked what data the app held, nobody could export it in under a week.
Where the thinking breaks
Account aggregators as a model
India's account aggregator framework already runs on granular, revocable, purpose-bound consent. It is the closest existing picture of what DPDPA consent should feel like.
The full Fintech & NBFC briefing
3 deep divesPermission is not consent. It is only access.
‘Allow’ opens the door. It does not tell the customer what you will do inside.
The model knows things the customer was never told.
A secret input is not a competitive advantage. It is a finding.
The consent model already exists. Copy it.
India built the right consent once. Now build it everywhere.
Monday morning
- 01List every app permission and the purpose it serves.
- 02Remove any permission whose purpose you cannot write in one line.
- 03Audit the top three lending service providers for data handling.
Questions, answered plainly
Is an Android or iOS permission valid consent under DPDPA?
An operating-system permission grants technical access; it does not by itself provide the notice of purpose and the specific consent Section 5 and Section 6 require. Apps should pair permissions with a clear notice and choice.
Are lending service providers Data Processors under DPDPA?
Where they process borrower data on behalf of a regulated lender, they generally act as Data Processors, and the lender as Data Fiduciary remains responsible under Section 8(1).
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner