8 months ago

India's Data Protection Law Challenges Digital Lenders

India's Data Protection Law Challenges Digital Lenders
India data protection law collides with digital lenders’ monitoring models · livemint.com

India has a new law called the DPDP Act that says apps must make it easy for users to withdraw their consent to share personal data.

Digital lenders, who give out loans, use a lot of personal data to decide who gets a loan and to keep an eye on borrowers.

Now, they are asking for special permission to keep using this data even if a borrower says they don't want to share it anymore.

The lenders say they need this data to manage risk and make sure borrowers pay back their loans.

But some lawyers say the lenders already have other legal reasons to use this data and don't need special permission.

The lenders also use this data to send marketing messages and make better loan offers.

The law says users must be able to withdraw consent easily, but the lenders want to treat some data use as mandatory.

There are also rules about how lenders can access data from borrowers' phones and bank accounts.

Some lenders are trying to find new ways to monitor borrowers' bank balances without breaking the rules.

Key facts

Act
Digital Personal Data Protection (DPDP) Act
Industry Body
Fintech Association for Consumer Empowerment (FACE)
Regulatory Bodies
Reserve Bank of India (RBI), Ministry of Electronics and Information Technology (MeitY)
Key Clause
Section 17 of the DPDP Act
Data Access
Bank transaction alerts, statement data, device-intelligence signals
Account Aggregators
RBI-regulated system for consent-based financial data sharing
Consent Requirements
Free, specific, informed, unconditional, unambiguous, and withdrawable

Quotes

Policy expert consulting for fintech firms

A policy expert consulting for fintech firms

“The industry is seeking relief to let the lenders continue accessing and using specified borrower data for the entire duration of a live loan, even if the borrower tries to withdraw consent mid-tenure.”
livemint.com
“RBI… has told digital lenders they can’t look into the photographs on your phone… and you can’t contact other people on the contact list… because those were egregious behaviours… so the RBI blocked it.”
livemint.com

Sugandh Saxena

Chief executive officer of FACE

“When lenders start sourcing a customer, device-intelligence signals also come into play such as metadata and behavioral biometrics that feed into models to gauge whether the applicant looks legitimate.”
livemint.com
“But…the industry will have to really distinguish between what is a mandatory regulated use case requirement… versus something…where they have option to withdraw the consent.”
livemint.com

Naqeeb Ahmed Kazia

Partner at CMS IndusLaw

“If there’s a law which sort of requires retention of data for a longer period, then that law will supersede (user consent).”
livemint.com
“As per the digital lending guidelines, a lender cannot continuously access phone memory or the phone storage data.”
livemint.com

Vamsi Madhav

CEO of Finvu AA

“A third use case that has emerged is lenders proactively ask consumers for their consent to monitor their balance, not transactions, but just the balance.”
livemint.com
“Lenders increasingly request post-loan data to monitor the deposit account once they make a loan.”
livemint.com

Krishna Prasad

Founder of OneMoney

“That is now being replaced by a fully-digital process, where the users journey during the loan application transfers to OneMoney… and once the user provides consent, it becomes a consent artefact. OneMoney will then present this signed consent artefact to the bank in an encrypted format.”
livemint.com

Tejinder Pal Singh

Chief executive of CAMSFinserv, an RBI-licensed Account Aggregator

“India now has about 17 operational AAs, covering data from roughly 240 crore accounts. The system processes about two crore consents a month, resulting in roughly 40 crore monthly data deliveries.”
livemint.com

Sources

Related news