The Reserve Bank of India has issued a sweeping directive that prevents banks and other regulated entities from disabling borrowers' smartphones, tablets or laptops as a means of recovering loan arrears, unless the loan was taken specifically to purchase the device. The policy, slated to take effect on January 1, 2027, signals a decisive shift toward stronger borrower protection while still preserving a narrow enforcement tool for gadget‑financing agreements.
Industry observers had anticipated that the central bank might adopt a more permissive stance on technology‑enabled recovery, given the rapid growth of digital lending. Instead, the RBI chose a restrictive path, drawing a clear line between personal‑device loans and traditional credit products such as personal, home or auto loans.
The Development
Under the new framework, lenders are barred from employing any software or hardware mechanism that would render a borrower’s mobile device inoperable for loans unrelated to the device itself. The ban covers all regulated entities, including banks, non‑bank financial companies and fintech firms that fall under RBI supervision.
When a loan is expressly used to finance a gadget, the RBI permits a limited set of restrictions, but only after a graduated timeline. Borrowers must first receive notice of default, and only after the loan is 30 days past due may lenders begin to curtail non‑essential functions. Full restriction, as pre‑agreed in the loan contract, can be applied only after the account is 60 days overdue.
Even in the case of financed devices, essential services such as incoming calls, SMS, emergency SOS features and government alerts must remain functional. The RBI also mandates that any third‑party vendor offering device‑locking solutions obtain certification from the original equipment manufacturer (OEM) or the operating‑system platform before deployment.
In addition to technology controls, the revised directions tighten the oversight of recovery agents. Lenders must limit the personal data shared with agents to the minimum required for collection activities, and they must establish clear grievance‑redress mechanisms for borrowers who believe their devices have been wrongly restricted.
The Numbers
Effective date: January 1, 2027.
Device‑locking may commence only after a loan is 30 days past due.
Full suite of restrictions allowed only after 60 days past due.
Compensation for wrongful restriction: ₹250 per hour until service is restored.
OEM or OS platform certification required for any locking technology.
Essential functions (incoming calls, SMS, SOS, public alerts) must stay active at all times.
Reading Between The Lines
The RBI’s move appears to prioritize consumer rights in an era where digital credit is expanding rapidly. By disallowing blanket device‑locking, the regulator reduces the risk that borrowers could be cut off from critical communication channels, which could exacerbate financial distress or even pose safety concerns.
For lenders, the policy introduces a new layer of operational complexity. Companies that previously relied on remote device immobilization as a quick enforcement tool now must invest in alternative recovery strategies, such as enhanced credit monitoring, legal action or partnership with collection agencies that comply with the new data‑sharing limits.
Financial institutions that specialize in gadget financing may find a modest advantage, as the RBI still allows them to enforce restrictions on the financed device. However, the requirement for OEM certification could raise compliance costs and limit the pool of eligible technology partners.
Analysts also note that the graduated restriction timeline aligns with broader global trends toward proportional enforcement. By delaying full restrictions until a borrower is significantly delinquent, the RBI gives borrowers a clearer window to rectify defaults before facing the most severe penalty.
The Risks
One concern is that lenders might attempt to circumvent the ban by re‑characterizing existing loans as gadget‑financing agreements, thereby preserving the ability to lock devices. The RBI’s emphasis on explicit disclosure in loan contracts seeks to mitigate this risk, but enforcement will depend on robust audit mechanisms.
Another potential challenge lies in the certification process. Smaller fintech firms may struggle to secure OEM approval, which could create a competitive disadvantage against larger banks that have existing relationships with device manufacturers.
Finally, the compensation clause—₹250 per hour for each hour a device remains improperly disabled—could expose lenders to sizable liability if systemic errors occur. This risk may prompt institutions to adopt more conservative recovery practices, potentially slowing the overall pace of loan collections.
What To Watch
Stakeholders will be closely monitoring how quickly regulated entities adapt their technology stacks to meet the OEM certification requirement. Early adopters that demonstrate seamless compliance could gain a reputational edge.
Regulators are expected to issue periodic compliance reports, and any subsequent amendments to the framework will likely focus on refining the data‑sharing provisions and clarifying the definition of “essential functionalities.” Market participants should also watch for litigation trends, as borrowers may test the compensation provisions in court.
This article is based on reporting published by Inc42.






