RBI Digital Lending Guidelines 2026: What Changed and How to Stay Compliant

June 12, 2026 · 8 min read · Regulatory Guide

The RBI issued updated digital lending norms in 2026 with stricter disclosure requirements and new restrictions on data usage. Here is what fintech companies and their lawyers need to know.

The Reserve Bank of India has been progressively tightening its oversight of digital lending since the original Guidelines on Digital Lending were issued on September 2, 2022. Those initial guidelines - born from the recommendations of the Working Group on Digital Lending - established the framework that every lending app, NBFC, and bank with digital lending operations must follow.

In 2026, the RBI issued a comprehensive update to these guidelines that reflects lessons learned over three years of implementation, the rapid growth of the digital lending ecosystem, and the new data protection obligations imposed by the DPDP Act. For fintech companies and the lawyers who advise them, understanding these changes is critical to continued regulatory compliance.

The Evolution: From 2022 to 2026

The 2022 guidelines established foundational principles: all loan disbursals and repayments must flow directly between the borrower's bank account and the regulated entity's bank account (no pass-through of funds via third-party apps); a Key Fact Statement must be provided to borrowers before loan execution; and Lending Service Providers (LSPs) must be disclosed to borrowers.

Subsequent circulars in 2023 and 2024 addressed specific issues - the First Loss Default Guarantee (FLDG) framework, digital lending through co-lending arrangements, and penal charges standardisation.

The 2026 update consolidates these piecemeal changes into a unified framework while introducing several new requirements.

Key 2026 Changes

1. Enhanced KYC for Digital-Only Lending

The most significant operational change is the introduction of enhanced KYC requirements for loans originated entirely through digital channels without any physical interaction.

Previously, video KYC (V-KYC) was accepted as equivalent to in-person verification for digital loans up to INR 10 lakh. The 2026 guidelines introduce tiered KYC requirements:

Loans up to INR 50,000: Simplified digital KYC using Aadhaar-based OTP authentication remains sufficient.

Loans from INR 50,001 to INR 5 lakh: V-KYC mandatory, plus verification of at least one additional identity document (PAN, Voter ID, or Passport) through DigiLocker or equivalent government-authenticated channel.

Loans above INR 5 lakh: Full in-person KYC or V-KYC with enhanced due diligence including income verification through Account Aggregator framework or verified bank statements, employment or business verification, and address verification through physical dispatch of a verification letter.

Practical Impact: Fintech lenders offering instant personal loans above INR 50,000 now need to build more robust KYC flows. The "instant approval in 2 minutes" model is no longer viable for larger loan amounts. Product teams must redesign user journeys to accommodate the additional verification steps while minimising drop-off rates.

2. Stricter Fee Disclosure Norms

The 2022 guidelines required a Key Fact Statement (KFS) disclosing the Annual Percentage Rate (APR), loan amount, tenure, and total cost. The 2026 update significantly expands disclosure requirements:

All fees must be disclosed individually - processing fee, documentation fee, insurance premium, credit score access fee, platform fee, and any other charge by whatever name.

The APR calculation must now include all fees charged by any entity in the lending chain (including LSP fees), not just the lender's own charges.

A standardised comparison table must be provided showing: the interest rate alone, the total cost including all fees, and the effective annual cost expressed as a single percentage.

Late payment charges must be disclosed upfront in absolute terms (not just as a percentage), with illustrative examples for different delay periods.

Prepayment and foreclosure charges must be clearly stated with examples of the actual amount payable at different stages of the loan tenure.

The KFS must be provided in the borrower's preferred language (from among the 22 scheduled languages), not just English and Hindi.

Practical Impact: Fintech companies must redesign their loan offer screens. The practice of showing only the interest rate while burying fees in terms and conditions is no longer compliant. Technology teams need to build dynamic KFS generators that calculate total costs inclusive of all charges across the lending chain.

3. Restrictions on Accessing Borrower Phone Data

This is the change that will most significantly affect digital lending apps:

No lending app may access the borrower's phone contacts, call logs, SMS messages, photos, media files, or any data beyond what is strictly necessary for the lending transaction.

The only permissible device data access is: camera (for KYC document capture and selfie verification), location (one-time, at the time of application, for address verification), and storage (read-only, limited to uploading specific documents selected by the borrower).

Apps must not request blanket storage permissions. Document upload must use the system file picker, allowing the borrower to select specific files rather than granting the app access to browse all stored files.

Background location access is completely prohibited. Location may only be accessed when the app is in the foreground and the borrower has actively initiated a location-dependent action.

Practical Impact: Many lending apps currently use phone data (SMS bank transaction messages, contact lists) for credit scoring and fraud detection. This practice is now explicitly prohibited. Lenders must pivot to consent-based data sources - Account Aggregator data, bureau scores, and borrower-provided documents. Apps that currently request broad permissions must release updates removing those permissions within the compliance timeline.

4. Mandatory Cooling-Off Period Expansion

The 2022 guidelines introduced a concept of a "look-up period" during which borrowers could exit the loan without penalty. The 2026 guidelines formalise and expand this:

For loans with tenure of 7 days or more: A mandatory 48-hour cooling-off period from the time of loan disbursal, during which the borrower can return the entire disbursed amount and exit the loan with zero charges (no interest, no processing fee, no penalty).

For loans with tenure of 30 days or more: A 72-hour cooling-off period.

The cooling-off period must be prominently communicated to the borrower at the time of disbursal through an SMS and an in-app notification, with clear instructions on how to exercise the exit option.

Practical Impact: Lenders must build loan reversal workflows that are as frictionless as the disbursement workflow. If it takes 2 minutes to get a loan, it should take no more than 5 minutes to reverse it during the cooling-off period. Customer support teams must be trained to process cooling-off exits without attempting to retain the borrower.

5. FLDG (First Loss Default Guarantee) Compliance

The 2023 FLDG circular capped the guarantee amount at 5% of the loan portfolio originated through the LSP. The 2026 update adds operational requirements:

FLDG arrangements must be backed by fixed deposits or bank guarantees - not merely contractual commitments.

The regulated entity must verify the FLDG cover monthly and report any shortfall to the RBI within 15 days.

LSPs providing FLDG must maintain a minimum net worth of INR 2 crore (increased from no specified minimum previously).

FLDG invocation and settlement must occur within 120 days of a loan being classified as NPA, rather than being accumulated and settled periodically.

Practical Impact: Smaller fintech companies operating as LSPs with FLDG arrangements face a capitalisation requirement they may not meet. The fixed deposit or bank guarantee requirement increases the cost of FLDG arrangements significantly. Lawyers advising LSPs should review existing FLDG agreements for compliance with the new operational requirements.

6. LSP (Lending Service Provider) Obligations

LSPs now face enhanced regulatory expectations:

Annual compliance certification to the regulated entity confirming adherence to all RBI digital lending guidelines.

Mandatory appointment of a Nodal Compliance Officer responsible for digital lending guideline compliance.

Customer-facing LSPs must display a standardised "RBI Regulated Lending" disclaimer on all borrower-facing communications, clearly identifying the actual regulated lender.

LSP agreements must include audit rights for the regulated entity and for the RBI.

LSPs must maintain records of all borrower interactions (digital and telephonic) for a minimum of 8 years from loan closure.

7. Grievance Redressal Timelines

The 2026 update imposes strict timelines:

Level 1 (LSP/Lender's grievance cell): Must acknowledge within 24 hours, resolve within 15 days.

Level 2 (Lender's Nodal Officer): Must resolve within 15 days of escalation.

Level 3 (RBI Ombudsman): If unresolved within 30 days total, the borrower can approach the RBI Integrated Ombudsman.

Non-compliance with these timelines will be treated as a regulatory violation, not merely a service deficiency.

Compliance Steps for Fintech Companies

For lawyers advising digital lending businesses, here is a practical compliance roadmap:

1. Audit current data practices against the new phone access restrictions. Identify any data collection that exceeds the permitted scope and plan technical changes to remove it.

2. Review KFS templates and update them to include all newly required disclosures. Build dynamic KFS generation if you have not already.

3. Implement the cooling-off period workflow. Test it thoroughly - the RBI will likely conduct mystery shopping exercises.

4. Review FLDG arrangements for compliance with the backing requirement (FD or bank guarantee) and the net worth threshold.

5. Update LSP agreements to include the new audit rights, compliance certification requirements, and record-keeping obligations.

6. Redesign the KYC workflow for different loan tiers. Build the additional verification steps into the user journey.

7. Implement the grievance redressal timeline tracking system. Automated escalation at 12 days (Level 1), 12 days (Level 2), and alert at 27 days (approaching 30-day total limit).

8. Update the privacy policy and consent flows to align with both the DPDP Act and the RBI's data restrictions. These two frameworks overlap but are not identical - compliance with one does not guarantee compliance with the other.

The compliance deadline for existing operations is 180 days from the circular's effective date. New products launched after the circular must be compliant from day one. For fintech companies operating at scale, 180 days is tight - particularly for the technology changes required by the phone data access restrictions and the enhanced KYC flows.

Lawyers who develop expertise in this intersection of financial regulation and technology implementation will find strong demand from the fintech ecosystem, which continues to grow rapidly despite the tightening regulatory environment.