Fintech App Permissions Under DPDPA: Why Permission Is Not Consent
Fintech App Permissions Under DPDPA: Why Permission Is Not Consent
‘Allow’ opens the door. It does not tell the customer what you will do inside.
The scene
The permission screen appeared before the customer had typed her name. Contacts, SMS, location, storage. She tapped Allow four times because the loan was urgent. Six months later she asked the app what it knew about her. The answer ran to eleven categories she had never heard of.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
The OS permission dialog is our consent.
It names a capability, not a purpose; DPDPA requires notice of purpose and specific consent.
Show your own notice before the OS dialog: what, why, and what happens if she says no.
Without permissions the app won't work.
Section 6 bars conditioning a service on consent to data it does not need.
Ask only for what the loan needs. Ask later for anything else.
What regulators already said
The RBI's digital lending framework already restricts lending apps from accessing contacts, media and call logs beyond one-time needs. DPDPA adds the general rule: necessity for the stated purpose.
Monday morning
01 List every permission your app requests.
02 Write the purpose for each in one line a customer would understand.
03 Remove any you cannot justify.
Questions, answered plainly
Is an app permission valid consent under DPDPA? +
No, not by itself. A permission grants technical access. DPDPA requires a notice of the purpose and consent that is free, specific, informed and unambiguous. Apps should show their own notice alongside permissions.
Can a lending app access a borrower's contact list? +
RBI's digital lending rules restrict access to contacts, media and call logs. DPDPA separately requires the data to be necessary for the stated purpose.
Sector · Fintech & NBFC Your onboarding takes ninety seconds. Your liability lasts years. Read →
Fintech & NBFC · Deep dive The model knows things the customer was never told. Read →
Fintech & NBFC · Deep dive The consent model already exists. Copy it. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).