{"id":1007,"date":"2026-08-24T18:49:36","date_gmt":"2026-08-24T18:49:36","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1007"},"modified":"2026-08-24T18:49:36","modified_gmt":"2026-08-24T18:49:36","slug":"rbi-digital-lending-security-requirements","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/rbi-digital-lending-security-requirements\/","title":{"rendered":"RBI Digital Lending Security Requirements"},"content":{"rendered":"\n<!-- Osto blog body for WordPress. Page title intentionally excluded. -->\n<style>\n.osto-dl{--b:#1c267a;--b2:#4d5bd0;--ink:#15172d;--muted:#62677a;--line:#e5e7f0;--pale:#f5f6ff;--teal:#08bfa9;max-width:840px;margin:0 auto;color:var(--ink);font-family:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;font-size:17px;line-height:1.75}.osto-dl *{box-sizing:border-box}.osto-dl h2{font-size:clamp(26px,3vw,32px);font-weight:700;line-height:1.2;margin:44px 0 16px;letter-spacing:-.5px}.osto-dl h3{font-size:clamp(20px,2.5vw,24px);font-weight:700;line-height:1.3;margin:32px 0 12px}.osto-dl p{margin:0 0 24px}.osto-dl a{color:var(--b);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.3)}.osto-dl ul,.osto-dl ol{padding-left:24px;margin:0 0 24px}.osto-dl li{margin-bottom:8px}.osto-dl .tldr,.osto-dl .note{background:var(--pale);border:1px solid #dfe3ff;border-radius:18px;padding:28px;margin:30px 0}.osto-dl .tldr h2{margin:0 0 10px}.osto-dl .toc{border-top:1px solid var(--line);border-bottom:1px solid var(--line);padding:24px 0;margin:38px 0}.osto-dl .toc h3{font-size:15px;text-transform:uppercase;letter-spacing:.12em;margin:0 0 12px}.osto-dl .key{border-left:4px solid var(--b);padding:4px 0 4px 20px;margin:28px 0}.osto-dl .key strong{display:block;color:var(--b);font-size:13px;text-transform:uppercase;letter-spacing:.08em}.osto-dl .fig{margin:30px 0;border:1px solid var(--line);border-radius:16px;overflow:hidden;background:#fff;box-shadow:0 10px 34px rgba(28,38,122,.1)}.osto-dl .fig-head{padding:20px 22px 5px}.osto-dl .fig-head strong{display:block;color:var(--b);font-size:14px;text-transform:uppercase;letter-spacing:.08em}.osto-dl .fig-head span{display:block;color:var(--muted);font-size:14px;margin-top:3px}\n.osto-dl .chain{display:flex;align-items:stretch;gap:8px;padding:20px}.osto-dl .node{flex:1;text-align:center;border-radius:14px;padding:17px 12px;background:#eef0ff}.osto-dl .node:nth-of-type(3){background:#f4f6fb}.osto-dl .node:nth-of-type(5){background:#e9f8f5}.osto-dl .node b{display:block;color:var(--b);font-size:14px}.osto-dl .node small{display:block;color:var(--muted);font-size:12px;line-height:1.45;margin-top:4px}.osto-dl .arr{align-self:center;color:#aeb5d9;font-size:20px;font-weight:800}\n.osto-dl .rules{display:grid;grid-template-columns:repeat(12,1fr);gap:1px;background:var(--line);padding:1px}.osto-dl .rule{grid-column:span 3;background:#fff;padding:18px 16px;min-height:120px}.osto-dl .rule:nth-child(n+5){grid-column:span 4}.osto-dl .rule i{display:grid;place-items:center;width:29px;height:29px;border-radius:8px;background:#eef0ff;color:var(--b);font-size:12px;font-style:normal;font-weight:800;margin-bottom:9px}.osto-dl .rule b{display:block;font-size:14px;color:var(--b)}.osto-dl .rule small{display:block;font-size:12.5px;line-height:1.45;color:var(--muted);margin-top:5px}\n.osto-dl .permission{display:grid;grid-template-columns:1fr 1fr;gap:0}.osto-dl .perm{padding:22px}.osto-dl .perm:first-child{background:#eaf9f5}.osto-dl .perm:last-child{background:#fff0f0}.osto-dl .perm h4{margin:0 0 11px;font-size:16px}.osto-dl .perm ul{margin:0;padding-left:20px;font-size:13px;line-height:1.55}.osto-dl .perm li{margin-bottom:6px}\n.osto-dl .flow{display:flex;align-items:stretch;gap:7px;padding:20px}.osto-dl .step{flex:1;padding:16px 10px;border-radius:13px;text-align:center;background:#eef0ff}.osto-dl .step:nth-of-type(3){background:#f4f6fb}.osto-dl .step:nth-of-type(5){background:#e9f8f5}.osto-dl .step:nth-of-type(7){background:#fff3e8}.osto-dl .step b{display:block;font-size:13px;color:var(--b)}.osto-dl .step small{display:block;font-size:11.5px;line-height:1.4;color:var(--muted);margin-top:4px}\n.osto-dl .table-wrap{overflow-x:auto;margin:25px 0 34px;border:1px solid var(--line);border-radius:16px;box-shadow:0 10px 34px rgba(28,38,122,.08)}.osto-dl table{width:100%;border-collapse:collapse;font-size:14.5px;line-height:1.5}.osto-dl th{background:var(--b);color:#fff;text-align:left;padding:14px}.osto-dl td{vertical-align:top;padding:14px;border-top:1px solid var(--line)}.osto-dl tr:nth-child(even) td{background:#fafbff}.osto-dl .steps{counter-reset:s;list-style:none;padding:0}.osto-dl .steps li{counter-increment:s;position:relative;padding:19px 0 19px 52px;border-top:1px solid var(--line)}.osto-dl .steps li:before{content:counter(s);position:absolute;left:0;top:17px;width:33px;height:33px;border-radius:50%;display:grid;place-items:center;background:var(--b);color:#fff;font-weight:800;font-size:13px}\n.osto-dl .cta{background:linear-gradient(135deg,#0e1444,var(--b) 60%,#303da8);color:#fff;border-radius:20px;padding:36px;margin:52px 0;box-shadow:0 18px 50px rgba(14,20,68,.24)}.osto-dl .cta h2{color:#fff;margin:0 0 12px}.osto-dl .cta a{display:inline-block;background:#fff;color:var(--b);border:0;border-radius:999px;padding:11px 19px;font-weight:700;margin-top:6px}.osto-dl .faq{border-top:1px solid var(--line);margin-top:8px;padding-top:8px}.osto-dl .faq details{border-bottom:1px solid var(--line);padding:6px 0}.osto-dl .faq summary{cursor:pointer;list-style:none;padding:16px 4px;font-weight:600;font-size:17px;display:flex;justify-content:space-between;align-items:center;gap:16px}.osto-dl .faq summary::-webkit-details-marker{display:none}.osto-dl .faq summary:after{content:'+';color:var(--b2);font-size:22px;font-weight:400}.osto-dl .faq details[open] summary:after{content:'\u2013'}.osto-dl .faq details p{padding:0 4px 18px;color:var(--muted);margin:0}.osto-dl .sources{font-size:14px;color:var(--muted)}\n@media(max-width:760px){.osto-dl .rule,.osto-dl .rule:nth-child(n+5){grid-column:span 6}.osto-dl .rule:last-child{grid-column:span 12}}@media(max-width:640px){.osto-dl .tldr,.osto-dl .note,.osto-dl .cta{padding:22px}.osto-dl .chain,.osto-dl .flow{flex-direction:column}.osto-dl .arr{transform:rotate(90deg);align-self:center}.osto-dl .node,.osto-dl .step{width:100%}.osto-dl .rule,.osto-dl .rule:nth-child(n+5),.osto-dl .rule:last-child{grid-column:span 12}.osto-dl .permission{grid-template-columns:1fr}}\n.osto-dl .svg-visual{display:block;width:100%;height:auto;margin:0}\n@media(max-width:700px){.osto-dl .svg-visual{overflow:visible}.osto-dl .fig{overflow-x:auto}.osto-dl .fig .svg-visual{min-width:680px}}\n<\/style>\n<article class=\"osto-dl\">\n<p>RBI digital lending security requirements govern how regulated entities, Lending Service Providers and Digital Lending Apps collect borrower data, request device permissions, store information, share it with third parties and prove that the complete lending journey is secure.<\/p>\n<section class=\"tldr\"><h2>TL;DR<\/h2><p>Under the RBI (Digital Lending) Directions, 2025, borrower data collected through a DLA must be need-based, backed by prior and explicit consent and supported by an audit trail. DLAs must not access files, media, contacts, call logs or telephony functions. Camera, microphone, location or another facility necessary for onboarding or KYC may be accessed once, with explicit consent.<\/p><p>Borrowers must be able to control consent, disclosure, retention and deletion. LSPs may retain only basic minimal personal data needed for their contracted service. Data must be stored on servers in India; data processed abroad must be deleted there and returned to India within 24 hours. The regulated entity remains responsible for ongoing customer-data privacy and security.<\/p><\/section>\n<nav class=\"toc\" aria-label=\"On this page\"><h3>On this page<\/h3><ol><li><a href=\"#scope\">Who is responsible<\/a><\/li><li><a href=\"#requirements\">The RBI security requirements<\/a><\/li><li><a href=\"#permissions\">DLA permission rules<\/a><\/li><li><a href=\"#controls\">Technical controls to implement<\/a><\/li><li><a href=\"#roadmap\">Implementation roadmap<\/a><\/li><li><a href=\"#evidence\">Evidence to retain<\/a><\/li><li><a href=\"#osto\">How Osto helps<\/a><\/li><\/ol><\/nav>\n\n<h2 id=\"scope\">Who is responsible for digital lending security?<\/h2>\n<p>The regulated entity, or RE, may operate its own DLA or engage an LSP that operates one. That operating model changes who performs the work, but it does not remove the RE\u2019s regulatory responsibility. RBI requires the RE to ensure that its LSPs and both RE-owned and LSP-owned DLAs comply.<\/p>\n<div class=\"fig\" role=\"img\" aria-label=\"Responsibility chain for RBI digital lending security\"><div class=\"fig-head\"><strong>The accountability chain<\/strong><span>Execution may be distributed; accountability stays with the regulated entity.<\/span><\/div><svg class=\"svg-visual\" viewBox=\"0 0 900 220\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><defs><marker id=\"ac-arrow\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0 0L9 4.5 0 9Z\" fill=\"#7057ff\"\/><\/marker><\/defs><g font-family=\"Inter,Arial,sans-serif\"><g fill=\"#f7f5ff\" stroke=\"#d9d2ff\" stroke-width=\"2\"><rect x=\"20\" y=\"35\" width=\"245\" height=\"145\" rx=\"18\"\/><rect x=\"328\" y=\"35\" width=\"245\" height=\"145\" rx=\"18\"\/><rect x=\"635\" y=\"35\" width=\"245\" height=\"145\" rx=\"18\"\/><\/g><g stroke=\"#7057ff\" stroke-width=\"4\" marker-end=\"url(#ac-arrow)\"><path d=\"M278 108H313\"\/><path d=\"M586 108H620\"\/><\/g><g fill=\"#17152b\" text-anchor=\"middle\"><text x=\"142\" y=\"78\" font-size=\"20\" font-weight=\"700\">Regulated entity<\/text><text x=\"142\" y=\"110\" font-size=\"14\"><tspan x=\"142\">Owns compliance, oversight<\/tspan><tspan x=\"142\" dy=\"21\">and customer-data responsibility<\/tspan><\/text><text x=\"450\" y=\"78\" font-size=\"20\" font-weight=\"700\">Lending Service Provider<\/text><text x=\"450\" y=\"110\" font-size=\"14\"><tspan x=\"450\">Performs contracted lending<\/tspan><tspan x=\"450\" dy=\"21\">or support functions<\/tspan><\/text><text x=\"757\" y=\"78\" font-size=\"20\" font-weight=\"700\">Digital Lending App<\/text><text x=\"757\" y=\"110\" font-size=\"14\"><tspan x=\"757\">Collects consent and data<\/tspan><tspan x=\"757\" dy=\"21\">through the borrower interface<\/tspan><\/text><\/g><\/g><\/svg><\/div>\n<div class=\"key\"><strong>The rule to remember<\/strong>A secure app does not make an insecure operating model compliant. Contracts, permissions, data flows, third parties, storage, incident handling and continuous oversight all have to work together.<\/div>\n\n<h2 id=\"requirements\">Seven RBI digital lending security requirements<\/h2>\n<div class=\"fig\" role=\"img\" aria-label=\"Seven RBI digital lending security requirements\"><div class=\"fig-head\"><strong>The security requirement map<\/strong><span>What every RE should translate into controls and evidence.<\/span><\/div><svg class=\"svg-visual\" viewBox=\"0 0 900 440\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><g font-family=\"Inter,Arial,sans-serif\"><g fill=\"#f7f5ff\" stroke=\"#ddd7ff\" stroke-width=\"2\"><rect x=\"12\" y=\"18\" width=\"210\" height=\"178\" rx=\"18\"\/><rect x=\"234\" y=\"18\" width=\"210\" height=\"178\" rx=\"18\"\/><rect x=\"456\" y=\"18\" width=\"210\" height=\"178\" rx=\"18\"\/><rect x=\"678\" y=\"18\" width=\"210\" height=\"178\" rx=\"18\"\/><rect x=\"123\" y=\"220\" width=\"210\" height=\"178\" rx=\"18\"\/><rect x=\"345\" y=\"220\" width=\"210\" height=\"178\" rx=\"18\"\/><rect x=\"567\" y=\"220\" width=\"210\" height=\"178\" rx=\"18\"\/><\/g><g fill=\"#7057ff\"><circle cx=\"46\" cy=\"52\" r=\"21\"\/><circle cx=\"268\" cy=\"52\" r=\"21\"\/><circle cx=\"490\" cy=\"52\" r=\"21\"\/><circle cx=\"712\" cy=\"52\" r=\"21\"\/><circle cx=\"157\" cy=\"254\" r=\"21\"\/><circle cx=\"379\" cy=\"254\" r=\"21\"\/><circle cx=\"601\" cy=\"254\" r=\"21\"\/><\/g><g fill=\"#fff\" font-size=\"13\" font-weight=\"700\" text-anchor=\"middle\"><text x=\"46\" y=\"57\">01<\/text><text x=\"268\" y=\"57\">02<\/text><text x=\"490\" y=\"57\">03<\/text><text x=\"712\" y=\"57\">04<\/text><text x=\"157\" y=\"259\">05<\/text><text x=\"379\" y=\"259\">06<\/text><text x=\"601\" y=\"259\">07<\/text><\/g><g fill=\"#17152b\" font-size=\"17\" font-weight=\"700\"><text x=\"28\" y=\"96\">Data minimisation<\/text><text x=\"250\" y=\"96\">Explicit consent<\/text><text x=\"472\" y=\"96\">Permission limits<\/text><text x=\"694\" y=\"96\">Borrower control<\/text><text x=\"139\" y=\"298\">Controlled storage<\/text><text x=\"361\" y=\"298\">India localisation<\/text><text x=\"583\" y=\"298\">Cybersecurity<\/text><\/g><g fill=\"#55516e\" font-size=\"13\"><text x=\"28\" y=\"126\"><tspan x=\"28\">Only data needed for<\/tspan><tspan x=\"28\" dy=\"19\">the lending purpose<\/tspan><\/text><text x=\"250\" y=\"126\"><tspan x=\"250\">Prior, specific consent<\/tspan><tspan x=\"250\" dy=\"19\">with an audit trail<\/tspan><\/text><text x=\"472\" y=\"126\"><tspan x=\"472\">No contacts, call logs,<\/tspan><tspan x=\"472\" dy=\"19\">files or telephony access<\/tspan><\/text><text x=\"694\" y=\"126\"><tspan x=\"694\">Give, deny, restrict,<\/tspan><tspan x=\"694\" dy=\"19\">revoke and delete<\/tspan><\/text><text x=\"139\" y=\"328\"><tspan x=\"139\">Minimal storage with<\/tspan><tspan x=\"139\" dy=\"19\">defined destruction<\/tspan><\/text><text x=\"361\" y=\"328\"><tspan x=\"361\">Store in India; return<\/tspan><tspan x=\"361\" dy=\"19\">processed data promptly<\/tspan><\/text><text x=\"583\" y=\"328\"><tspan x=\"583\">Meet relevant RBI<\/tspan><tspan x=\"583\" dy=\"19\">technology requirements<\/tspan><\/text><\/g><\/g><\/svg><\/div>\n<h3>1. Need-based collection with an audit trail<\/h3><p>Every field, document, device signal and derived data point should have a defined purpose. The RE must ensure that collection through its DLA or an LSP\u2019s DLA is need-based and occurs only after prior and explicit borrower consent. Record the consent text, purpose, timestamp, DLA version and borrower action so the decision can be reconstructed later.<\/p>\n<h3>2. Granular borrower choice<\/h3><p>The borrower must be able to allow or deny use of specific data, restrict disclosure to third parties and control retention. The journey must also support revocation of previously granted consent and, where requested, deletion or forgetting of personal data by the RE or LSP. The purpose of consent should be disclosed at every relevant interface stage, rather than hidden in a single broad acceptance.<\/p>\n<h3>3. Restricted mobile permissions<\/h3><p>A DLA must not access phone resources such as files and media, the contact list, call logs or telephony functions. RBI allows one-time access to camera, microphone, location or another facility necessary for onboarding or KYC, but only with explicit consent. Product convenience is not enough; the access must be necessary for the permitted purpose.<\/p>\n<h3>4. Controlled third-party sharing<\/h3><p>Personal information requires explicit borrower consent before it is shared with a third party unless the disclosure is required by law or regulation. The privacy policy should identify third parties that may collect personal information through the DLA. Maintain an accurate data-flow map so product, compliance and security teams can see where information goes after the borrower taps \u201callow.\u201d<\/p>\n<h3>5. Minimal LSP storage and defined deletion<\/h3><p>An LSP should not retain borrower personal information beyond basic minimal data needed to deliver the contracted service, such as name, address and contact details where required. Storage policies must define data types, retention periods, use restrictions, destruction procedures and security-breach handling, and these policies must be prominently disclosed on the relevant websites and DLA.<\/p>\n<h3>6. Biometric restrictions and data localisation<\/h3><p>The RE must ensure that it and its LSP do not collect or store biometric data unless permitted under applicable statutory guidelines. Digital lending data should be stored only on servers located in India. If processing occurs outside India, the data must be deleted from those foreign servers and brought back to India within 24 hours of processing.<\/p>\n<h3>7. Current cybersecurity standards<\/h3><p>The 2025 directions do not treat \u201ccybersecurity\u201d as a one-line app-security test. The RE must ensure that it and its LSP comply with technology and cybersecurity requirements stipulated by RBI and other relevant agencies. The exact control set therefore depends on the RE\u2019s category and other applicable directions, including the 2026 entity-specific cybersecurity framework.<\/p>\n\n<h2 id=\"permissions\">What can a Digital Lending App access?<\/h2>\n<div class=\"fig\" role=\"img\" aria-label=\"Allowed and prohibited Digital Lending App permissions\"><div class=\"fig-head\"><strong>DLA permissions at a glance<\/strong><span>One-time permitted access is narrow, purpose-bound and consent-based.<\/span><\/div><svg class=\"svg-visual\" viewBox=\"0 0 900 350\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><g font-family=\"Inter,Arial,sans-serif\"><rect x=\"18\" y=\"20\" width=\"420\" height=\"300\" rx=\"20\" fill=\"#effbf5\" stroke=\"#bcebd4\" stroke-width=\"2\"\/><rect x=\"462\" y=\"20\" width=\"420\" height=\"300\" rx=\"20\" fill=\"#fff3f4\" stroke=\"#ffcbd0\" stroke-width=\"2\"\/><circle cx=\"58\" cy=\"62\" r=\"22\" fill=\"#179b63\"\/><path d=\"M47 62l8 8 15-17\" fill=\"none\" stroke=\"#fff\" stroke-width=\"4\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/><circle cx=\"502\" cy=\"62\" r=\"22\" fill=\"#d83c4c\"\/><path d=\"M494 54l16 16m0-16l-16 16\" stroke=\"#fff\" stroke-width=\"4\" stroke-linecap=\"round\"\/><text x=\"92\" y=\"69\" fill=\"#116c47\" font-size=\"21\" font-weight=\"700\">May be accessed once<\/text><text x=\"536\" y=\"69\" fill=\"#a62b38\" font-size=\"21\" font-weight=\"700\">Must not be accessed<\/text><g fill=\"#25463a\" font-size=\"15\"><text x=\"48\" y=\"116\">\u2022 Camera for onboarding or KYC<\/text><text x=\"48\" y=\"154\">\u2022 Microphone where necessary<\/text><text x=\"48\" y=\"192\">\u2022 Location where necessary<\/text><text x=\"48\" y=\"230\">\u2022 Strictly necessary KYC facility<\/text><text x=\"48\" y=\"268\">\u2022 Explicit consent for every access<\/text><\/g><g fill=\"#60343a\" font-size=\"15\"><text x=\"492\" y=\"116\">\u2022 Files and media<\/text><text x=\"492\" y=\"154\">\u2022 Contact list<\/text><text x=\"492\" y=\"192\">\u2022 Call logs<\/text><text x=\"492\" y=\"230\">\u2022 Telephony functions<\/text><text x=\"492\" y=\"268\">\u2022 Any unrelated excessive permission<\/text><\/g><\/g><\/svg><\/div>\n<p>Enforce this rule technically, not only through policy. Review Android and iOS manifests, permission prompts, SDK behaviour and runtime calls. A third-party analytics, fraud or marketing SDK can create a compliance issue even if the DLA\u2019s own code never requests the prohibited resource.<\/p>\n\n<h2 id=\"controls\">Technical security controls behind RBI compliance<\/h2>\n<div class=\"table-wrap\"><table><thead><tr><th>Control area<\/th><th>What to implement<\/th><th>What proves it<\/th><\/tr><\/thead><tbody><tr><td>Consent<\/td><td>Granular purpose-level consent, withdrawal and deletion workflows<\/td><td>Versioned consent text, timestamps, user action and fulfilment logs<\/td><\/tr><tr><td>Application security<\/td><td>Secure SDLC, SAST, dependency review, API testing, mobile VAPT and release gates<\/td><td>Test scope, findings, remediation tickets, retest and release approval<\/td><\/tr><tr><td>Identity and access<\/td><td>MFA, least privilege, privileged access monitoring and periodic reviews<\/td><td>Access approvals, configuration snapshots, logs and signed reviews<\/td><\/tr><tr><td>Data protection<\/td><td>Encryption in transit and at rest, key management, DLP and secure deletion<\/td><td>Configuration, key rotation, DLP alerts and destruction records<\/td><\/tr><tr><td>Infrastructure<\/td><td>Cloud posture management, hardening, patching, segmentation, WAF and API protection<\/td><td>Asset inventory, posture reports, patch evidence and alert records<\/td><\/tr><tr><td>Third parties<\/td><td>SDK inventory, vendor due diligence, contract controls and continuous monitoring<\/td><td>Assessments, data-flow map, contracts, exceptions and review records<\/td><\/tr><tr><td>Incidents<\/td><td>Detection, triage, containment, forensics, notification and recovery<\/td><td>Incident timeline, decisions, reports, lessons and corrective action<\/td><\/tr><tr><td>Localisation<\/td><td>India-hosted storage and controlled foreign processing<\/td><td>Architecture, region settings, data-transfer and deletion logs<\/td><\/tr><\/tbody><\/table><\/div>\n<p>Testing must cover more than the user interface. Mobile, web, API, cloud and network surfaces have different weaknesses; Osto\u2019s <a href=\"https:\/\/www.osto.one\/resources\/blog\/types-of-vapt\/\">guide to the types of VAPT<\/a> explains how to scope them. Maintain an <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sbom\/\">SBOM<\/a> for visibility into software components and an up-to-date <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">risk assessment<\/a> connecting technical weaknesses to borrower and business impact.<\/p>\n\n<h2 id=\"roadmap\">RBI digital lending security compliance checklist<\/h2>\n<ol class=\"steps\"><li><strong>Map the operating model.<\/strong> Identify the RE, every LSP, every DLA, each lender relationship, third-party SDK and data processor.<\/li><li><strong>Build the data inventory.<\/strong> Record every field and device signal, purpose, consent basis, recipient, storage location, retention and deletion method.<\/li><li><strong>Remove prohibited permissions.<\/strong> Inspect app manifests, runtime requests and embedded SDKs for files, media, contacts, call logs and telephony access.<\/li><li><strong>Redesign consent where needed.<\/strong> Make it prior, explicit, granular, purpose-specific and auditable; add restriction, revocation and deletion workflows.<\/li><li><strong>Validate storage and localisation.<\/strong> Reduce LSP-held data to the contracted minimum and verify India storage plus the 24-hour foreign-processing return rule.<\/li><li><strong>Secure the complete stack.<\/strong> Protect mobile, web, APIs, cloud, endpoints, identities, source code, data and administrative consoles.<\/li><li><strong>Test and remediate.<\/strong> Run secure code analysis, dependency scanning, configuration reviews and independent VAPT; verify closure.<\/li><li><strong>Prepare CIMS certification evidence.<\/strong> Ensure DLA details, links, grievance information, data practices and regulatory compliance are supportable before certification.<\/li><li><strong>Monitor continuously.<\/strong> Reassess after releases, SDK changes, new data uses, LSP changes, incidents and regulatory updates.<\/li><\/ol>\n<div class=\"fig\" role=\"img\" aria-label=\"Secure digital lending data lifecycle\"><div class=\"fig-head\"><strong>The secure data lifecycle<\/strong><span>Control the borrower\u2019s data from first request to verified deletion.<\/span><\/div><svg class=\"svg-visual\" viewBox=\"0 0 900 220\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><defs><marker id=\"lc-arrow\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0 0L9 4.5 0 9Z\" fill=\"#7057ff\"\/><\/marker><\/defs><g font-family=\"Inter,Arial,sans-serif\"><g fill=\"#f7f5ff\" stroke=\"#d9d2ff\" stroke-width=\"2\"><rect x=\"15\" y=\"40\" width=\"190\" height=\"130\" rx=\"18\"\/><rect x=\"242\" y=\"40\" width=\"190\" height=\"130\" rx=\"18\"\/><rect x=\"469\" y=\"40\" width=\"190\" height=\"130\" rx=\"18\"\/><rect x=\"696\" y=\"40\" width=\"190\" height=\"130\" rx=\"18\"\/><\/g><g stroke=\"#7057ff\" stroke-width=\"4\" marker-end=\"url(#lc-arrow)\"><path d=\"M211 105h22\"\/><path d=\"M438 105h22\"\/><path d=\"M665 105h22\"\/><\/g><g text-anchor=\"middle\"><g fill=\"#17152b\" font-size=\"20\" font-weight=\"700\"><text x=\"110\" y=\"91\">Request<\/text><text x=\"337\" y=\"91\">Consent<\/text><text x=\"564\" y=\"91\">Protect<\/text><text x=\"791\" y=\"91\">Delete<\/text><\/g><g fill=\"#55516e\" font-size=\"14\"><text x=\"110\" y=\"124\">State a specific purpose<\/text><text x=\"337\" y=\"124\">Capture explicit choice<\/text><text x=\"564\" y=\"124\">Limit, encrypt and monitor<\/text><text x=\"791\" y=\"124\">Prove retention ended<\/text><\/g><\/g><\/g><\/svg><\/div>\n\n<h2 id=\"evidence\">Evidence the RE should retain<\/h2>\n<p>The CCO or board-designated official certifies DLA information submitted through RBI\u2019s CIMS portal, including compliance of DLA data collection and storage. Certification should be backed by retrievable evidence, not a last-minute email confirmation from the LSP.<\/p>\n<div class=\"table-wrap\"><table><thead><tr><th>Requirement<\/th><th>Evidence examples<\/th><\/tr><\/thead><tbody><tr><td>Consent<\/td><td>Consent ledger, purpose, text version, timestamp, borrower choice, withdrawal and deletion completion<\/td><\/tr><tr><td>Permissions<\/td><td>Manifest review, screenshots, runtime test, SDK assessment and release approval<\/td><\/tr><tr><td>Data minimisation<\/td><td>Field-level inventory, necessity justification and approved data-flow diagram<\/td><\/tr><tr><td>LSP storage<\/td><td>Contract scope, data schema, retention configuration and deletion reports<\/td><\/tr><tr><td>India storage<\/td><td>Cloud-region settings, architecture, storage logs and foreign-processing deletion proof<\/td><\/tr><tr><td>Security testing<\/td><td>SAST\/SCA results, VAPT report, cloud review, remediation and independent retest<\/td><\/tr><tr><td>Privacy disclosure<\/td><td>Published policy version, third-party list, change approval and archived copies<\/td><\/tr><tr><td>CIMS reporting<\/td><td>DLA inventory, certification pack, approval, submission and update history<\/td><\/tr><\/tbody><\/table><\/div>\n<h3>Common failures to avoid<\/h3><ul><li>Using one bundled consent for every purpose.<\/li><li>Keeping a prohibited permission because an SDK requests it by default.<\/li><li>Assuming an LSP\u2019s contract transfers responsibility away from the RE.<\/li><li>Storing full borrower records at the LSP when only minimal data is necessary.<\/li><li>Listing an India cloud region while backups, logs or analytics data remain abroad.<\/li><li>Publishing a privacy policy that does not match the DLA\u2019s actual data flows.<\/li><li>Running annual VAPT without testing after a major release or architecture change.<\/li><li>Certifying DLA compliance on CIMS without a traceable evidence pack.<\/li><\/ul>\n\n<section class=\"cta\" id=\"osto\"><h2>Secure the DLA, the stack and the evidence.<\/h2><p><strong>Osto is a one-stop platform for cybersecurity and compliance.<\/strong> Its 21+ native modules\u2014including WAF, EDR, CSPM, IAM, DLP and SAST\u2014help regulated entities and digital lenders protect applications, APIs, cloud, endpoints, identities, code and data while keeping the related compliance evidence visible.<\/p><p>Bring application testing, cloud posture, access control, data protection, remediation and regulatory evidence into one operating view. That unified approach is why Osto is becoming the default for cybersecurity and compliance.<\/p><a href=\"https:\/\/www.osto.one\/contact-us\/\">Book a demo \u2192<\/a><\/section>\n\n<h2>Frequently asked questions<\/h2><section class=\"faq\"><details><summary>What are RBI digital lending security requirements?<\/summary><p>They are the technology and data obligations governing consent, device permissions, third-party sharing, storage, localisation, privacy, cybersecurity and DLA reporting under the RBI Digital Lending Directions, 2025 and other applicable cybersecurity instructions.<\/p><\/details><details><summary>Can a digital lending app access contacts or call logs?<\/summary><p>No. RBI requires DLAs of the RE and LSP to desist from accessing files and media, contact lists, call logs and telephony functions.<\/p><\/details><details><summary>Can a DLA access camera, microphone or location?<\/summary><p>Only once where the facility is necessary for onboarding or KYC, and only with the borrower\u2019s explicit consent.<\/p><\/details><details><summary>Where must digital lending data be stored?<\/summary><p>Data must be stored only on servers located in India. If it is processed outside India, it must be deleted from the foreign server and brought back to India within 24 hours of processing.<\/p><\/details><details><summary>Can an LSP store borrower personal data?<\/summary><p>Only basic minimal personal data required to perform its operations or service within the RE-LSP agreement. The RE remains responsible for ongoing privacy and security of customer personal information.<\/p><\/details><details><summary>Who is responsible if an LSP-operated DLA is non-compliant?<\/summary><p>The regulated entity remains responsible for ensuring that the LSP and its DLA comply. Outsourcing the activity does not outsource the RE\u2019s regulatory accountability.<\/p><\/details><\/section>\n<div class=\"note sources\"><strong>Primary sources:<\/strong> RBI\u2019s <a href=\"https:\/\/www.rbi.org.in\/scripts\/NotificationUser.aspx?Id=12848&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">Digital Lending Directions, 2025<\/a> and the applicable entity-specific RBI cybersecurity, technology risk, resilience and assurance directions. Confirm applicability for the RE and current date. This article is not legal advice.<\/div>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>RBI digital lending security requirements govern how regulated entities, Lending Service Providers and Digital Lending Apps collect borrower data, request\u2026<\/p>\n","protected":false},"author":8,"featured_media":1008,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[457,459,458],"class_list":["post-1007","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-digital-lending-app-security-requirements","tag-rbi-compliance-for-digital-lenders","tag-rbi-digital-lending-security-requirements"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1007"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1007\/revisions"}],"predecessor-version":[{"id":1009,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1007\/revisions\/1009"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1008"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}