Banking2Day Check eligibility
NBFC & Fintech 10 Aug 2026 · 7 min read

You Tap "Approve" on a Fintech App — Here's What You Actually Just Consented To

Every time you link your bank account to a loan app or budgeting tool, you're using India's Account Aggregator system. Here's what that consent screen really means, and why the fine print matters.

B2D
Banking2Day Editorial Team
Research & explainers on Indian banking and personal finance
NBFC & Fintech

The screen you clicked "Allow" on, without really reading

If you've ever applied for an instant personal loan, tried a budgeting app, or linked your bank account to a wealth management platform in the last couple of years, you've almost certainly seen a screen that lists your bank accounts and asks you to pick which ones to "share." Most people scroll past it, tick the boxes, and hit approve because the app needs it to move forward. That screen is not a random permission request — it's the consent layer of India's Account Aggregator (AA) framework, a system built by the RBI that lets your financial data move between institutions with your explicit, revocable permission.

It sounds technical, but it affects something very personal: who gets to see your bank statements, your loan history, your insurance policies, and increasingly, your tax and pension data — and for how long.

What an Account Aggregator actually does

An Account Aggregator is a licensed NBFC — think Anumati, OneMoney, CAMS Finserv, or Perfios — that acts as a secure pipe between institutions that hold your data (banks, insurers, mutual funds, tax platforms) and institutions that want to use it (lenders, wealth managers, insurers underwriting a policy). Crucially, the AA itself never stores or reads your data. It just passes it along, encrypted, once you approve a specific request.

Before AAs existed, "sharing your bank statement" usually meant emailing a PDF or handing over net-banking screenshots, or a company might use screen-scraping tools that logged into your account on your behalf — a genuinely risky practice. The AA framework replaced that mess with a standardised, consent-based, API-driven system. In theory, it's a big upgrade in both convenience and safety.

  • Financial Information Provider (FIP): the bank, insurer, or depository that holds your data
  • Financial Information User (FIU): the lender, advisor, or platform requesting your data
  • Account Aggregator: the licensed go-between that carries your consent and the data, without storing either

Where the "paradox" comes in

Here's the tension worth understanding, even without the legal jargon. The AA framework was designed around detailed, purpose-specific consent — you approve a named entity to access a named set of data, for a named purpose, for a fixed time window, and you can revoke it later. That's a fairly granular, transaction-level idea of consent.

India's newer Digital Personal Data Protection (DPDP) rules take a broader view of consent — covering any personal data processed by any company, not just financial data moving through a regulated pipe. The two frameworks weren't built at the same time or by the same people, so there are real questions about how they interact: does giving AA-style consent for a loan application satisfy DPDP's broader consent requirements too? Who do you complain to if something goes wrong — the AA regulator or the data protection authority? These are legitimate, unresolved questions that policy experts are actively debating.

You don't need to resolve that debate to protect yourself. What you do need is to understand what you're agreeing to every time that consent screen pops up.

What to actually check before you tap "Approve"

The AA consent screen is designed to show you specifics — but most people don't read past the headline. Here's what's actually worth 30 seconds of attention:

  • Who is requesting the data. Is it the lender you applied with directly, or an unfamiliar third-party name? Sometimes loan apps route requests through partner NBFCs — check the name matches who you expect.
  • What data is being pulled. A personal loan app asking for your last 6 months of bank statements is normal. The same app asking for your mutual fund holdings and insurance policies is worth questioning — unless it's a wealth advisory tool, that's more than it needs.
  • How long the consent lasts. Good consent requests are time-bound — say, 24 hours for a one-time loan check. If the request asks for a standing, long-duration pull without a clear reason, be cautious.
  • Whether you can revoke it. Every licensed AA app should let you view and cancel active consents. Check this in the AA app itself (not the lender's app) periodically — old, forgotten approvals are how data keeps flowing long after you've stopped using a service.

The difference between AA-based sharing and a shady app reading your SMS

It's worth separating two very different things that often get confused in the same breath. The AA framework is RBI-regulated, consent-first, and doesn't let anyone see your net-banking password. A different, much riskier category is apps that ask for SMS or contact list permissions directly on your phone — these bypass the AA system entirely and have been the subject of repeated RBI warnings and app-store bans for predatory lending practices.

If a lending app is asking to read your SMS inbox or your contacts "to verify your identity," that is not how legitimate data-sharing works in India today — walk away. If it's routing you through a proper AA consent screen with a named aggregator, that's the system working as designed.

A simple habit worth building

Treat your AA consent dashboard the way you'd treat your credit report — something to check periodically, not just at the moment you need a loan. Most AA apps (available from RBI-licensed players) let you see every active consent across every institution you've linked. Revoke anything you don't recognise or no longer use. It takes a few minutes and closes a door that many people don't realise is still open.

The regulatory debate over how AA consent and DPDP rules should fit together will likely take a while to settle, and that's fine — these frameworks evolve. What doesn't need to wait is your own habit of reading the request, checking the duration, and revoking what you no longer need shared. That single habit does more for your financial privacy than any policy clarification will.

Check your credit score before you share it anywhere
Know what lenders will see before you consent to share your data
Check Credit Score
This article is general information, not financial, tax or legal advice, and does not constitute a recommendation. Rates, limits and tax rules referenced are indicative and change over time — verify current details with your bank, employer or a qualified professional before acting.
More from the desk
Home Loans
18 Jun 2026 · 7 min read

How much home loan EMI can you comfortably afford?

Banking Safety
17 Jun 2026 · 5 min read

The 10-minute digital banking fraud safety check

Money Guide
15 Jun 2026 · 8 min read

Selling property? Understand the banking and tax paperwork