
The government and the Reserve Bank of India (RBI) have announced a strengthened regulatory framework for the fintech sector. The revised guidelines, released on Monday, are squarely aimed at boosting consumer protection and fortifying cybersecurity measures across digital financial services.
Under the new framework, all fintech firms will be required to comply with enhanced data localisation norms. Customer data must now be stored exclusively on servers located within India. The move is intended to prevent unauthorised access and ensure that sensitive financial information remains under domestic jurisdiction.
The RBI has made annual third-party cybersecurity audits mandatory for all payment system operators and lending platforms. Firms will also have to report any data breach or cyber incident to the regulator within six hours of detection. Non-compliance will attract strict penalties, including potential suspension of operations.
These measures come in response to a sharp increase in cyber frauds targeting digital payment users. According to RBI data, complaints related to digital fraud have risen by nearly 30% in the last financial year. The central bank has made it clear that consumer trust is non-negotiable.
One of the key changes involves digital lending apps. All loan products must now display the annual percentage rate (APR) upfront. Hidden charges and opaque interest calculations will no longer be permitted. The regulator has also mandated that lenders provide a standardised key fact statement to every borrower before loan disbursal.
The new rules also tighten norms around recovery practices. Lending apps have been barred from accessing a borrower's phone contacts or photo gallery. These restrictions are designed to curb aggressive recovery tactics that have led to widespread complaints and even suicides in some cases.
The government has directed all fintech firms to set up a dedicated grievance redressal mechanism. Customers will now have the option to escalate unresolved complaints to the RBI's Integrated Ombudsman Scheme. The aim is to ensure that disputes are resolved within 30 days, failing which firms will face financial disincentives.
Industry bodies have largely welcomed the move. However, some smaller fintech startups have expressed concerns about the compliance burden. They argue that the cost of mandatory audits and data localisation could squeeze margins for newer players.
The RBI and the finance ministry will jointly monitor compliance. A quarterly review mechanism has been put in place to assess the effectiveness of the framework.
Going forward, the government is expected to release a draft bill that seeks to create a statutory authority for fintech regulation. The sector should brace for more oversight as India aims to balance innovation with consumer safety.