The permission screen is the most informative thing a borrower sees, and it appears before any money changes hands.
Under the Reserve Bank of India’s digital lending framework, data collection by digital lending apps is to be need-based, with explicit borrower consent, and access to phone contacts, call logs and media files is not permitted. Platform policy in several markets imposes similar restrictions independently. The direction of travel across the region has been the same: narrow what a lending app may see.
Why contacts were the flashpoint
Because access to a borrower’s contact list is not a credit-assessment tool. It is a collections tool.
The documented pattern that drove these rules involved contact lists harvested at installation and used later to pressure borrowers through the people in them. That is the practice the restrictions exist to stop, and it is why a contacts request from a lending app should end the installation rather than prompt a moment’s thought.
What legitimate requests look like
A lending app has real reasons to request some access. Camera and storage for document capture during onboarding is ordinary. SMS access is more debatable and has historically been justified for transaction-message analysis, which is exactly the kind of broad justification the framework’s data-minimisation requirement is aimed at.
The distinguishing questions are whether the request is tied to a specific function the user is performing at that moment, and whether declining it blocks the whole app or only the feature.
The patterns that have adapted
Two are worth flagging.
Bundling. Requesting a legitimate permission and a questionable one together at first launch, so declining either blocks onboarding entirely.
Justification drift. Broad permissions defended by reference to underwriting or fraud prevention — categories capacious enough to justify almost anything, and which do not become more specific when questioned.
What a borrower can do
Check permissions before installing, using the store listing rather than the app itself. Grant at the point of use rather than at install where the platform allows it. Treat any contacts or call-log request from a lending app as disqualifying. And review what an app retains after a loan closes, since data-deletion practice varies considerably and is set out in the privacy policy rather than in the app.
Nothing here is financial advice. Borrow only from lenders licensed in your own jurisdiction, and verify a licence with the regulator directly rather than relying on a claim inside an app.