RBI NBFC Rules Just Banned Dark Patterns and Fake Consent
By Privy
Sep 30, 2026

RBI NBFC Rules Just Banned Dark Patterns and Fake Consent

On June 15, 2026, the RBI issued a circular that does something most financial regulation doesn't: it names and illustrates eleven specific dark patterns, in detail, and bans every one of them for NBFCs. Pre-ticked consent boxes, countdown timers on loan offers, insurance quietly added to a loan application by default, confusing double-negative checkboxes- all of it is now explicitly prohibited, not just discouraged.

The circular is the RBI NBFC (Non-Banking Financial Companies – Responsible Business Conduct) Second Amendment Directions, 2026, and it comes into effect on January 1, 2027. It applies to NBFCs, HFCs, ARCs, and most CICs, and it rewrites how consent, third-party product sales, and DSA/DMA (agent) conduct have to work.

rbi nbfc

Registration Link:

https://zoom.us/webinar/register/6017907535146/WN_OajAOm56SFq-Nd4UpC4nqQ

What Actually Counts as a Dark Pattern Now

Annex III of the circular lists eleven dark patterns by name, each with real illustrations drawn from lending and financial services specifically, not generic e-commerce examples. A few worth knowing in detail:

rbi nbfc

Every NBFC's own digital journeys and every DSA/DMA-operated interface now have to pass user testing and periodic internal audits against this exact list.

Explicit Consent Has a Legal Definition Now

Para 6(4A) defines explicit consent as a specific, informed, unambiguous indication of choice, captured through a recorded statement or a clear affirmative action. That sounds close to how DPDP already defines consent, and that overlap is not an accident. What changes in practice:

  • The default choice for consent must be "No" or "I do not agree." A pre-set "Yes" is no longer legally valid consent, regardless of what a database field says.
  • When a form covers more than one product or service, each one has to be listed separately, and the customer has to be able to choose only the ones they actually want. One blanket consent checkbox covering credit, insurance, and marketing in a single tick no longer holds up.
  • The consent flow has to force the customer through the terms and conditions before consent can be given. Consent captured without that step isn't valid, even with a timestamp attached.
  • Consent and related records have to be preserved for one year after the product relationship ends, not deleted at account closure.
  • A new product introduced later in the relationship needs its own fresh notice and consent, not an assumption that the original blanket agreement still covers it. That means consent has to be tracked at the level of each customer, product by product, over time, not as a single flag on an account record. Most legacy CRM and loan origination systems were never built to hold that, which is where the actual rework tends to land, not in the consent screen itself but in what sits behind it.

No More Compulsory Bundling

Para 101V bans conditioning a loan or core product on buying something else, most commonly credit insurance sold as a default add-on. If a third-party product is genuinely required as a risk mitigant, the customer still has to be free to buy it from any provider, not only the NBFC's preferred partner. Voluntary bundles offered at the customer's own choice, or genuinely complimentary add-ons, are fine. Anything conditional is not.

Mis-Selling Now Has a Definition, and Bundled Consent Isn't a Defence

This is the part worth sitting with longest. Para 6(9A) defines mis-selling to include selling a product that isn't suitable for the customer's profile, even when the customer gave explicit but bundled consent. A signature or an OTP confirming the sale no longer protects an NBFC if the product itself was wrong for that customer's income, financial literacy, or risk tolerance. Para 101P requires a documented suitability and appropriateness assessment before certain products are sold, based on the customer's actual profile, not just their willingness to sign.

That assessment runs on profiling, credit history, income, and financial literacy signals, which is itself personal data processing under DPDP. The cleanest way to satisfy both regulators at once is disclosing that profiling at the lead generation stage itself, before the suitability logic ever runs, rather than treating it as a separate notice bolted on right before the sale.

DSAs and DMAs Are Now the NBFC's Direct Responsibility

The circular pulls Direct Selling Agents, Direct Marketing Agents, and their sub-agents (loan service providers included) directly into the compliance perimeter. NBFCs now have to keep this documented in the same record of processing activities DPDP already expects, not a separate agent register:

  • Maintain a public, up-to-date list of every DSA/DMA they engage, updated within seven days of any change.
  • Run due diligence before and during the engagement, not just at onboarding.
  • Ensure no employee or agent receives an incentive, direct or indirect, tied to selling a third-party product, which is the mechanism most mis-selling actually runs through.
  • Make sure agents identify themselves clearly as agents, not as NBFC employees, in every customer interaction.

Where Legacy Consent Systems Actually Break

The failure mode most NBFCs will hit isn't the consent screen itself; it's what happens after. Consent gathered at a physical branch, through a DSA-assisted app, or on a web portal typically lands in separate, siloed CRM and loan origination databases with no shared source of truth. When a customer opts out through one channel, say a WhatsApp message or a call to customer care, that change has no reliable path to propagate to every other system still acting on the old consent: outbound dialers, marketing platforms, and third-party insurers who received the original data.

That gap is exactly what regulators will be testing for. A consent record that's correct in one database and stale in three others isn't a technical footnote; it's the same violation Para 6(4A) is written to prevent, just discovered a channel too late, and it becomes a privacy incident in its own right once a regulator asks for proof the propagation actually happened.

Where This Meets DPDP

RBI's explicit consent definition and DPDP's consent requirements aren't the same law, but they're now asking for the same kind of evidence: not a database flag that says consent given = True, but a time-stamped, auditable record proving a customer actually saw the terms and made an affirmative choice. DPDP's own consent artefact requirements already demand exactly this kind of immutable, versioned record.

Third-party risk management has the same overlap. RBI's DSA/DMA due diligence requirements and DPDP's processor governance obligations are asking about the same agent relationships from two different angles, conduct risk on one side, data processing risk on the other. An NBFC building consent and vendor infrastructure for this RBI circular and its DPDP obligations separately is building the same evidence trail twice, once for each regulator, on different timelines, when one dual-mapped approach to RBI and DPDP covers both.

What NBFCs Need to Do Before January 1, 2027

Getting NBFC compliance right on this circular means treating it as infrastructure, not a UI patch, the same discipline DPDP's own May 2027 deadline already demands, and the same one covered in more depth in Privy's guide to RBI compliance for banks and NBFCs:

  • Audit every digital and DSA-operated interface against the eleven dark patterns in Annex III, not just the NBFC's own app and website.
  • Rebuild consent flows to default to "No," force T&C navigation, and capture consent per product rather than as one blanket checkbox.
  • Separate credit or core product journeys from third-party product add-ons at the point of sale, so nothing is bundled by default.
  • Put a documented suitability assessment in place before selling products beyond the simplest, universally-suitable ones.
  • Publish and maintain the DSA/DMA list, and review incentive structures for anything that rewards agents for selling third-party products.
  • Confirm consent records can be preserved and retrieved for a full year past contract closure, in a format that would hold up as evidence, not just a log line.

None of this has to come at the cost of conversion. A consent flow that unbundles products into short, itemised screens rather than one long form tends to hold onboarding completion rates steadier than a blanket "agree to all" checkbox that gets abandoned when a customer actually reads it. The NBFCs treating this as a design problem, not just a legal one, are the ones least likely to see drop-off increase once the old single-tick consent screen disappears.

Where Privy Fits

Privy by IDfy's Consent Governance Platform generates immutable, versioned consent artefacts by design, the same standard of evidence both DPDP and this RBI circular now require, rather than a database flag that can't be defended under audit. The platform's Third-Party Risk Management module extends that same accountability to vendor and agent relationships, covering the due diligence and contract-level obligations RBI now expects of DSA/DMA oversight, and for enterprises specifically evaluating vendor risk tooling as part of this rollout, Privy's breakdown of the top TPRM software options for 2026 is a useful independent starting point. And because Privy operates on a PII-blind architecture, mapping consent and vendor obligations against both DPDP and sector-specific RBI, SEBI, or IRDAI requirements doesn't mean standing up a second, separate compliance system; it runs on the same platform IDfy built after winning MeitY NeGD's DPDP Innovation Challenge, alongside purpose-built incident management software for the consent-drift scenario above.

rbi nbfc

Conclusion

This circular is less about a new consent checkbox and more about a new evidentiary standard: RBI, like DPDP, now wants proof that a customer actually saw what they were agreeing to, not just a record that says they clicked something. NBFCs that treat this as a UI patch before January 2027 will be back here again for the next circular. The ones that treat it as infrastructure will not.

See how Privy by IDfy maps RBI's explicit consent and DSA governance requirements onto the same platform as DPDP compliance, book a demo, or write to shivani@idfy.com for a walkthrough.

FAQ's

What are dark patterns? 

Dark patterns are deceptive user interface or user experience designs that mislead or trick a person into an action they didn't intend, such as a pre-ticked checkbox, a fake urgency timer, or a confusing double-negative option. RBI's June 2026 circular lists eleven specific dark patterns that NBFCs and their agents are now banned from using.

When does RBI's dark patterns circular take effect? 

The Reserve Bank of India (Non-Banking Financial Companies – Responsible Business Conduct) Second Amendment Directions, 2026 take effect on January 1, 2027.

Does this circular apply to all NBFCs? 

It applies to NBFCs, HFCs, ARCs, and most CICs, with specific exclusions for Core Investment Companies, NBFC-Account Aggregators, Non-Operative Financial Holding Companies, and NBFCs without a customer interface.

Is a signature or OTP enough to prove valid consent under this circular? 

No. A signature or OTP confirms an action took place, but it doesn't establish that consent was informed, unambiguous, and given by affirmative choice, as Para 6(4A) requires. It also doesn't defend against a mis-selling claim if the product was unsuitable for that customer.

How is this different from DPDP's consent requirements? 

The two aren't the same law, but they ask for similar evidence: a specific, informed, and auditable record of consent rather than an assumed or implied agreement. An NBFC preparing for this RBI circular is largely building the same consent infrastructure DPDP already requires.

Are DSAs and LSPs directly liable under this circular? 

The regulatory obligation sits with the NBFC, which now has to run due diligence, maintain a public DSA/DMA list, and ensure no incentive structure encourages mis-selling, effectively extending the NBFC's own compliance perimeter to cover its agent network.

Search Here

Reach out to us

Explore More

The DPDP Build Trap: Why AI-Ready Compliance Needs a Bought Platform
DPDP Rules

Aug 31, 2026

The DPDP Build Trap: Why AI-Ready Compliance Needs a Bought Platform

DPDP for Board: A Leadership Framework
DPDP Rules

Aug 11, 2026

DPDP for Board: A Leadership Framework

What IDfy and MIT’s Research Reveals About Enterprise Privacy & DPDP Rules
DPDP Rules

Feb 23, 2026

What IDfy and MIT’s Research Reveals About Enterprise Privacy & DPDP Rules

Share