All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

IT Act and RBI Digital Payment and Lending Regulation Explained

A digital payment sits on two legal foundations: the IT Act makes the electronic transaction and signature valid and criminalises the fraud, while RBI's regulatory regime governs the rails, the data and the allocation of loss. Digital lending adds a further RBI framework over the same IT Act and data-protection base. Topics 85 and 89 touched the pieces; this note, as asked, maps the interface.

1. The Interface

Transaction, rails, data, fraud and lending

Figure 1: Transaction, rails, data, fraud and lending

  • E-contract and e-record. The IT Act validates the foundation: s.10A for the electronic contract, ss.4 to 7A for the electronic record and its retention and audit, the legal base the payment rides on (Topics 45, 131)
  • Payment regulation. RBI governs the rails: the Payment and Settlement Systems Act 2007, the payment-aggregator and payment-gateway directions, and the prepaid-instrument master directions for wallets, with capital, escrow and KYC disciplines (Topic 89)
  • Data and localisation. RBI's 2018 payment-data localisation directive and card tokenisation limit what is stored and where, while s.43A and the DPDP Act govern the personal data more broadly (Topics 87, 116)
  • Fraud and liability. ss.66C and 66D with BNS cheating prosecute the fraud, while RBI's limited-liability circulars allocate the loss, zero customer liability on prompt reporting, the civil and criminal tracks running together (Topics 85, 86)
  • Digital lending. RBI's 2022 digital-lending framework disciplines lending apps, direct disbursal and recovery, with the IT Act and DPDP Act governing the data, consent and the app's intermediary and security duties.

2. How the Regimes Fit

  • Validity against regulation. The IT Act answers whether the transaction and signature are legally valid; RBI answers whether the entity and the rails are authorised and compliant, two separate questions on one payment.
  • The loss allocation. Where an unauthorised transaction occurs, the criminal track runs ss.66C, 66D and cheating against the fraudster, the civil track runs RBI's limited-liability framework between customer and bank, and the freeze runs through the 1930 machinery (Topics 85, 86)
  • Data in three layers. Payment data sits under RBI localisation and tokenisation, s.43A security, and the DPDP Act consent and breach regime, a layered discipline the entity must satisfy at once (Topic 95)
  • Digital lending's extra edge. A lending app is at once an IT Act intermediary with due-diligence and security duties, a DPDP fiduciary for borrower data, and an RBI-regulated participant under the 2022 framework, three regimes on one application.

⚠ Exam trap

Divide the questions cleanly: the IT Act validates the electronic transaction and prosecutes the fraud (ss.66C, 66D), RBI regulates the rails under the PSS Act and its directions, and RBI's limited-liability circulars allocate the loss while the DPDP Act and s.43A govern the data. For digital lending, name the 2022 RBI framework layered over the IT Act and DPDP data duties, and keep the criminal, civil and regulatory tracks of a payment fraud distinct rather than merging them.

3. Frequently Asked Questions

How do the IT Act and RBI regulation govern digital payments?

The IT Act validates the electronic contract and record the payment rides on under Sections 10A and 4 to 7A and prosecutes payment fraud under Sections 66C and 66D with BNS cheating. RBI governs the payment rails under the Payment and Settlement Systems Act 2007 and its aggregator, gateway and prepaid-instrument directions, requires payment-data localisation and card tokenisation, and allocates the loss from unauthorised transactions through its limited-liability framework. Personal and payment data additionally fall under Section 43A and the DPDP Act, and digital-lending apps answer to RBI's 2022 framework layered over these duties.

4. Related Topics

  • Topic 89: E-Commerce Law. Payment fraud and gateway liability.
  • Topic 87: Privacy and Data Protection. The data layer over payments.