A single loan passes through an originator, a co-lender, a lending-service provider, a collections agent and four credit bureaus, and each of them holds the borrower’s record. The DPDP Act addresses its rights to “the Data Fiduciary” — singular. No instrument in the lending stack says which copy answers an erasure request, or how a correction accepted by one party reaches the others. For app-first lenders the intake problem is largely solved by the login itself; the hard part is fulfilment across a graph of copies that nobody mapped.
FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 10 PROBLEMS SWEPT · 4 SHOWN HERE · HOW THIS WAS BUILT
Each of these is marked confirmed: two independent sources, at least one the instrument or a practitioner record. Sources are linked so your counsel can read them.
DPDP s.12 and s.8(7) require erasure once the purpose is served unless retention is required by law; PMLA s.12 and the RBI KYC Master Direction require five years. The Third Schedule’s fixed erasure clocks apply to e-commerce, gaming and social media — not to fintech — so a lender self-derives retention per data category and defends it. The refusal is lawful, but only record by record, in writing, with the specific statutory basis. Practitioners note there is “no explicit DPDP retention schedule for credit data.”
SOURCES · DPDP Rules 2025 (notified 13 Nov 2025) — retention and pre-erasure notice provisions (text) · Vinod Kothari Consultants, implications for financial-sector entities (practitioner) · RSRR on digital lending under DPDP (practitioner)
Confirmed · sweep of 2 Sep 2026The default is clear at entity level: the regulated entity is the fiduciary, the lending-service provider its processor. The real problem is narrower and worse. An LSP that runs its own analytics, its own cross-lender matching or its own decisioning is a fiduciary for that slice even while a processor for the loan slice — one data flow, two fiduciaries for different elements. The RBI Digital Lending Directions make the regulated entity accountable for the LSP’s conduct but do not allocate data rights.
SOURCES · RBI (Digital Lending) Directions, 2025 (instrument, 8 May 2025) · IndusLaw sector FAQs (practitioner) · RSRR (practitioner) · Vinod Kothari (practitioner)
Confirmed · a per-element allocation problem, not blanket ambiguityThe RBI Co-Lending Directions, 2025 mandate a single customer-interface entity for servicing and allocate nothing for data rights. Each co-lender reports the same loan to the credit bureaus independently. A correction accepted by one lender leaves stale copies at the other and at every bureau — and nobody has published a working propagation protocol.
SOURCES · Vinod Kothari on the Co-Lending Directions, 2025 (practitioner) · Legal500, data privacy in digital lending (practitioner)
Confirmed · the absence of any allocation is itself the findingUnder DPDP s.6 the consent must come from the data principal — the reference, not the borrower. The universal origination practice of collecting two or three reference contacts and calling them at default rests on boilerplate that fails specificity, disclosure and rights-notification requirements, and the lender is liable for its collection agents’ conduct. The reference never had a relationship with the lender at all: no notice, no consent, no legitimate-use hook.
SOURCES · DPDP Act s.6, s.8 (statute) · “Privacy Meets Recovery” — debt collection under DPDP (practitioner) · RBI Fair Practices / recovery-conduct rules (instrument, context)
Confirmed · structural in reference-based lendingThe register started from AI-drafted hypotheses and kept only what the instruments supported. These are the lending-specific claims that changed on the way.
Section 5(2) is a grandfathering-by-notice mechanism: lawfully collected pre-Act data continues under a retrospective notice, with no fresh consent required. Deletion is compelled only where no valid original consent existed — which is exactly the device-data troves (contacts, gallery, SMS) the RBI lending rules already prohibit. The distinction matters for what you build.
The mainstream position is settled at entity level: regulated entity as fiduciary, LSP as processor. The problem is that an LSP is a fiduciary for its own-purpose slices. Treating this as blanket ambiguity leads to a contract clause; treating it as a per-element allocation leads to a data map.
An authenticated session verifies identity at intake in-product — the one scale advantage fintechs hold over platforms whose users never log in. What no login solves is fulfilment across the originator, co-lender, LSP, bureau and collections copies.
The fixed three-year inactivity clocks are for e-commerce, gaming and social media above their user thresholds. A lender has no safe-harbour clock and must derive retention per data category from PMLA, the KYC Direction and its own purpose analysis.
The Board had no members as of 1 August 2026 and the penalty provisions commence in mid-May 2027. Every severity statement on this page is exposure-based, not enforcement-history-based — and the register says so. The penalty schedule is stated plainly here, once.
RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM
Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.
Every access, correction and erasure request carries a response deadline computed when it is filed and an escalation ladder when it slips. An erasure cannot be marked complete unless its execution path is configured, and the destruction is recorded, not asserted. The written refusal for a PMLA-held record lands in the same audit chain, dated and attributable.
Live: DSR orchestration · SLA tracking · grievance workflowsWhen a correction completes, each processor recorded against that person’s consent is notified, and a delivery record is kept per processor — pending, delivered or failed — as evidence of who was told and when. It does not rewrite the processor’s copy for them; it makes the propagation, and its gaps, visible instead of assumed.
Live: correction propagation to processors, with per-processor delivery evidenceThe platform models you as the fiduciary and holds your processors and their data-processing agreements as a scored register — effective dates, expiry, status. Per-element fiduciary-versus-processor allocation across a co-lending chain is not something any tool the register found does, and ours does not either. The register to hold your allocation in exists; the allocation is yours to write.
Live: processor registry · DPA tracking on the scorecardConsent is captured per processing purpose, never all-or-nothing, and withdrawn as easily as it was given. Every consent, erasure, refusal and notice publication is a linked record bound to the one before it, periodically stamped by an independent timestamp authority. Anyone can check the chain.
Live: purpose-by-purpose consent · tamper-evident audit trail · verifiable receipts