Banking

Can A Bank Disable Your Phone Over A Loan Default? RBI Has A New Answer

New recovery rules allow device locking only for financed gadgets, while tightening norms for recovery agents and protecting borrowers from unfair recovery practices

AI generated
RBI's New Loan Recovery Rules Photo: AI generated
info_icon
Summary

Summary of this article

  • Banks cannot disable phones for most loan default cases.

  • Device locking allowed only for lender-financed mobile devices.

  • New RBI rules tighten recovery agent conduct and borrower safeguards.

Borrowers who default on personal, home or vehicle loans will no longer face the risk of their mobile phones or laptops being disabled by banks to recover dues. The Reserve Bank of India (RBI) has barred lenders from using device-locking technology in most loan recovery cases, allowing it only when the device itself has been financed through a loan from the lender.

The revised directions on loan recovery and the engagement of recovery agents will take effect from January 1, 2027. Besides restricting the use of device-locking technology, the rules also lay down fresh standards for recovery agents, the handling of borrower information, and the use of technology during the recovery process.

Device Locking Limited To Financed Gadgets

The biggest change relates to mobile devices financed through loans. Banks can no longer disable phones, tablets or laptops for defaults on unrelated loans, such as personal, home or vehicle loans.

“A bank shall not deploy any technology-based mechanism... which restricts or disables any of the functionalities of a mobile device of a borrower... except to recover its loan dues arising out from financing of such a device,” the RBI's amended directions stated.

Even when the loan has been taken to purchase the device, banks cannot lock it immediately after a missed payment. Borrowers must first receive notice, and restrictions can begin only after the loan becomes overdue for the period prescribed under the directions.

“The bank shall adopt a gradual approach rather than disabling the device, ab initio,” the directions added.

The RBI has also protected essential functions on financed devices. Incoming calls, SMS and emergency SOS services cannot be disabled, while any restrictions should not prevent borrowers from carrying out work or employment-related activities.

Recovery Agents Face Tighter Rules

The revised directions also address the conduct of recovery agents following complaints from borrowers about harassment during loan recovery.

Banks can share borrower information with employees or recovery agencies only to the extent where it is absolutely necessary for recovery work. They must also maintain records of recovery-related calls and inform borrowers if conversations are being recorded.

The directions prohibit recovery agents from using abusive or threatening language, making excessive or anonymous calls, publishing borrowers’ personal information on social media or harassing borrowers, their relatives or colleagues.

“A bank’s employee/recovery agent shall not engage in any harsh methods towards collection/recovery,” the amended directions specify.

Recovery visits should generally take place only between 8 am and 7 pm unless the borrower has requested otherwise.

"For the first time, the regulator has drawn a clear and enforceable line between recovery and harassment," said Ananth Shroff, Co-founder and CEO of DPDzero, a debt collection and recovery platform.

"This means using agents with a Debt Recovery Agent (DRA) certificate, contacting borrowers only during permitted hours, recording every call, issuing prior notice before field visits, protecting personal data and maintaining clear audit trails. The real challenge is ensuring that these safeguards are followed consistently across millions of borrower interactions," adds Shroff.

Technology Must Meet New Conditions

Where banks use device-locking technology for financed gadgets, the system must be certified by the original equipment manufacturer or the operating system platform, wherever such certification is available.

The directions also prohibit banks and third-party service providers from accessing personal data stored on a borrower’s device, including contacts, messages, call logs, photographs and location history

Published At:
CLOSE