Listen to this post

Device Locking in Digital Lending: Welcoming the New Recovery Agent in Town

Summary: The Reserve Bank of India has proposed a formal framework for deployment of device-based restrictions in smartphone financing. This tool has been in operation for a while now and regulation is only just catching up. The Draft Amendments may have gotten the architecture right: controlled permission, not prohibition. However, does the proposal strike the right balance between borrower protection and lending viability?

The smartphone is now at the centre of India’s digital lending story. Fintech-focused NBFCs sanctioned over 10.9 crore personal loans worth INR 1.06 lakh crore in FY 2024-25,[1] with digital lenders disbursing INR 97,381 crore in small-ticket personal loans in H1 alone, largely to borrowers entering the formal credit system for the first time.[2] For a large segment of the Indian population, particularly first-time and thin-file customers, a smartphone is not just a consumption good, it is the gateway to credit, income, identity and financial inclusion.

It is, therefore, not surprising that device financing has evolved into a niche lending product, with lenders moving from traditional recovery tools to technology-based ones like device locking (“DL”), relying on the indispensable nature of smartphones in people’s lives to minimise delinquencies.

DL is widely used globally as a recovery tool[3], though no major jurisdiction has enacted a dedicated statutory framework governing DL. In India, implementation of this tool preceded regulatory action, with device restriction practices prompting regulatory intervention by the Reserve Bank of India (“RBI”). What was once an operational tool has now become a policy question.

The RBI’s draft amendment to the Non-Banking Financial Companies (Responsible Business Conduct) Directions, 2025 (“Draft Amendments”)[4], which was open for stakeholder comments in May, proposes to bring DL technology for device financing under a formal framework for the first time.

What is the Regulators Approach?

If lenders extending credit to buy a mobile device wish to deploy DL for recovery, the RBI, through the Draft Amendments, asks lenders to work within a framework[5], quick snapshot below:

ParameterProposed requirement
When can restriction begin?When a loan account is 90 days past due (DPD)  and post prior notices, giving the borrower an opportunity to cure the default
Notice Notice at 60 DPD (21 days to cure) + subsequent notice after expiry (seven more days to cure)
ApproachGraduated, not immediate blanket lock; no disruption to core functionality such as internet, communication, emergency services
Reversal on paymentWithin one hour of default being cured
PenaltyINR 250/ hour for (a) wrongful restriction—until restriction is lifted; and (b) delay in reversal after borrower cures default—until functionalities are restored
Data access prohibitionAbsolute; no accessing of personal data on device
Product scopeDevice-financed loans only
UninstallationDL to be removed on repayment

Read together, the message is clear. DL is permissible, but only at the margins, and with strong borrower protection guardrails.

Device Locking: Collateral or Recovery Mechanism?

Unlike traditional collateral, DL does not grant the lender a proprietary interest in the device or a right to realise value through sale. Instead, it restricts the borrower’s ability to use the device upon non-payment, creating an incentive to cure the default. This distinction is particularly significant if the financed smartphone is an essential economic asset. For many borrowers, especially gig workers, a smartphone is a tool used to access work, communicate with customers, receive payments and generate income. The lender’s leverage stems not from the ability to repossess or monetise the device, but from the borrower’s continued need to use it.

By anchoring the trigger at 90 DPD and embedding DL within the responsible business conduct framework, the RBI is positioning it as a pure recovery mechanism. The implication is that lenders lose the ability to treat DL as a form of security interest over the financed asset.

In traditional secured lending, security interest is enforced upon default, often early in the default cycle, through possession and sale. Clause 100P of the Draft Amendments recognises this by permitting lenders to take possession of secured assets upon satisfying certain procedural prerequisites. DL achieves a different form of possession – one that restricts access without physical repossession, at significantly lower costs and operational complexity, while avoiding the practical challenges of recovering rapidly depreciating mobile devices.

If taking possession of a device through technology is materially the same in effect, the question worth asking is whether a different regulatory treatment is genuinely warranted? The 90 DPD threshold sits at the far end of the delinquency curve. By that point, borrower engagement is typically low, repayment behaviour is entrenched, and the marginal effectiveness of any restriction may be limited.

This matters especially because smartphone financing in India is largely extended to customer segments with limited credit history, unstable income documentation, and no access to traditional collateral. Here, the device serves not only as the asset being financed but also as the main tool used to generate income. DL, therefore, serves a collateral-like function – maintaining some lender control over the financed asset and encouraging repayment.

Ultimately, DL may not fit neatly into either category. It provides lenders some degree of control over an asset critical to the borrower, thereby influencing repayment behaviour. The main policy question now is whether regulating it exclusively as a recovery tool could reduce its effectiveness as a credit-enhancement mechanism.

Does the Global Playbook Differ?

Globally, large ecosystem players and fintech-led lenders have treated device restriction less as a last-resort enforcement tool and more as a behavioural nudge, introducing restrictions early and calibrating carefully: small frictions first, stronger ones later.[6]

In the United States, the Federal Communication Commission’s handset-locking rules address carrier network locks during a financing period, not lender-initiated recovery restrictions.[7] Consumer lending protections under the Fair Debt Collection Practices Act apply broadly but say nothing specific about device-based restrictions.[8] The practice exists; the regulatory category does not.

DL has scaled most aggressively in Africa. In Kenya, M-KOPA has disbursed over $1.6 billion to 4.8 million customers through a pay-as-you-go model built entirely around device lock.[9] Watu Simu has financed nearly two million devices since 2022 using internet-enabled locking software.[10] Crucially, locks engage early, sometimes from day one of a missed payment, and are graduated: payment functionality stays active so borrowers can still clear dues.[11] Again, no regulation squarely governs this space.

The pattern here is consistent: practice has run ahead of regulation, with obvious pitfalls including delayed unlocks, opaque triggers, and criminal syndicates offering illegal device-unlocking services. India’s Draft Amendments, in that context, are novel and welcome. It is, therefore, critical that we get this right.

Borrower Protection vs. Lending Viability: Is there a Balance?

The Draft Amendments are anchored in borrower protection, a legitimate concern, since an unregulated device lock can easily tip into coercive recovery or digital exclusion. The counterpoint, however, is equally important: over-correction carries its own risks.

If the framework treats all aspects of device access as equally sacrosanct, it limits room for meaningful restriction. And if restrictions are only permitted once a borrower is deeply delinquent, any behavioural impact may be limited.

The challenge is not choosing between borrower protection and lender rights but identifying a middle ground that preserves a borrower’s ability to function, work and repay, while leaving lenders with sufficient tools to manage credit risks. A framework that protects borrowers but renders the lending model commercially unviable may ultimately reduce access to credit for the very segments regulations seek to safeguard.

From this lens, the debate shifts from abstract notions of “internet access” to specific functionalities that must remain protected. Certain services such as banking, payments, authentication, emergency communications are integral to a borrower’s ability to participate in the economy and service their obligations. These form the core layer meriting the strongest protection. Beyond that lies a layer of discretionary use that can be adjusted temporarily and proportionately without disabling the borrower’s ability to cure the default.

The real policy question is not whether restrictions should be permitted, but whether a blanket 90 DPD prohibition is the optimal balance. If a carefully calibrated restriction can be deployed earlier without impairing the borrower’s ability to function or repay, does that necessarily produce a worse outcome than waiting until deep delinquency?

Conclusion

The Draft Amendments draw an important boundary: device-based recovery cannot translate to digital exclusion. That is a necessary safeguard in a country where smartphone ownership translates to economic participation. The harder question is where to draw the line within that boundary. If restrictions are too broad, they risk harming borrowers. If too delayed or narrow, they become ineffective. DL may work only if it strikes a careful balance, creating just enough inconvenience to encourage repayment, without taking away the ability to do so.


[1] Salesforce, 5 Hidden Risks Slowing Down Digital Lenders in India (May 2026), citing fintech NBFC data for FY 2024–25,  available here

[2] Grant Thornton Bharat & FACE, Risk Barometer Survey 2024, citing FACE industry data for FY 2023, available here.

[3] GSMA Mobile for Development, Smartphone Device Financing: A Catalyst for Mobile Money Growth (April 2025) (documenting PAYGO device-lock deployment across Kenya, South Africa, and Sri Lanka), available here; Datacultr, How Telcos and Fintechs in Kenya Are Enabling Smartphone Access with Device Locking Technology (December 2025), available here.

[4] Draft – Reserve Bank of India (Non-Banking Financial Companies – Responsible Business Conduct) Directions, 2025, available here.

[5] Para J.3.4, 100Q to 100S, Draft Amendments.

[6] Device Locking: Why the End User Matters in Digital Lending, available here, October 27, 2025, available here.

[7] FCC, Cell Phone Unlocking (Consumer Information Page), available here; Federal Register, Promoting Consumer Choice and Wireless Competition Through Handset Unlocking Requirements and Policies, August 8, 2024, available here.

[8] Consumer Financial Protection Bureau, About the CFPB, available here; The American Consumer Institute, FCC Makes the Right Call with Handset Unlocking Rule (February 2026), available here.

[9] TechCabal, M-KOPA Crosses $1.6 Billion in Loans as PAYGO Market Expands (November 2025), available here.

[10] The Standard (Kenya), New Financing Model Takes on Kenya’s Smartphone Affordability Crisis (September 2025), available here.

[11] GSMA Mobile for Development, Smartphone Device Financing: A Catalyst for Mobile Money Growth (April 2025), available here.