Bank Account

India’s digital lending ecosystem includes genuinely legitimate, RBI-regulated online lenders (banks and NBFCs, or fintech Lending Service Providers partnering with them) and a persistent class of illegal, unregistered lending apps that use coercive recovery, data weaponisation, and predatory rates. Under RBI’s Digital Lending Directions (issued 8 May 2025), all Digital Lending Apps must be registered with CIMS by June 2025 and listed on their regulated entity’s official website — creating a verifiable whitelist. Legitimate digital loans must: provide a Key Facts Statement (with APR disclosed, not just flat rates) before borrower acceptance; offer a minimum one-day cooling-off period for penalty-free exit; disburse directly to the borrower’s bank account; restrict app data permissions to KYC-only (no contact list/call log access); and store all data in India. Red flags for predatory/illegal apps: no named RBI-regulated lender, excessive device permissions, disbursement to a wallet, instant approval with zero KYC, and interest expressed as daily/weekly rates without APR. We cover the practical risks of legitimate digital lending too: impulsive borrowing due to speed, multiple simultaneous loans increasing aggregate debt burden, and the debt-management problem at portfolio level that individual-loan convenience can create. For victims of illegal lending: cybercrime.gov.in for harassment, sachet.rbi.org.in for illegal lending activity, and state police under the IT Act/BNS for data misuse.

Book an Appointment Form