Bangladesh asked Google to pull predatory loan apps. Weeks on, several are still on the Play Store

Google built that licence-verification machinery in response to almost exactly this crisis in India, Kenya, Nigeria and Pakistan between 2021 and 2023. It has not extended it to Bangladesh, a market of some 190 million people where every one of the preconditions — heavy microcredit demand, near-universal mobile wallets, and an app economy running well ahead of its regulator — is present.
DHAKA, September 4, Bangladesh's telecom regulator asked Google to remove a set of digital lending applications from the Play Store a month ago, warning that they were harvesting borrowers' contacts, messages and photographs and using the data for blackmail.
A check of the store on Thursday found at least two of the flagged apps still live and available to download, one of them updated as recently as Wednesday.
The Bangladesh Telecommunication Regulatory Commission (BTRC) sent two removal requests to Google LLC in August, both now published in the Lumen database, the Harvard Law School repository to which Google voluntarily forwards legal takedown demands.
The first, dated August 4, listed five Play Store lending apps.
The second, dated August 25, listed 18 further apps and framed the problem as one of illegal online loans and online gambling.
What the notices said
The August 4 notice states that BTRC had received a complaint from an unnamed government organisation about digital loan apps operating through deceptive advertising and fabricated user reviews.
The apps, it says, seek unnecessary permissions to collect contacts, SMS, photographs and device information, and there are serious concerns the data is being misused for fraud, identity theft, harassment and intimidation.
It cites sections 21 and 22 of the Cyber Security Act, 2026, the statute that replaced the interim Cyber Security Ordinance, 2025.
The August 25 notice goes further in tone, describing borrowers lured by advertisements into surrendering call logs, SMS, gallery contents and location data, which is then used for "intimidation, harassment, blackmail, fraud" under the pretext of lending.
It asks Google to review, verify and, where violations are found, block or remove the material, and to prevent further dissemination.
Verification: what is still available
Checked against the Play Store on September 4, the five apps named in the August 4 notice split as follows.
Still live. Dost Loan (package com.aosnbuh.olna.darodin) remains published, with more than 100,000 downloads, a 4.2 rating from roughly 680 reviews, and a listing updated on September 3, thirty days after the notice was sent.
It is credited to "SoftNova Digital," while Google's verified developer panel names a different entity, BFK Creative LLC, at an address in Mesa, Arizona, with a Gmail address for support.
Its listing declares a maximum APR of 14.6% and a minimum 91-day term.
Its data-safety card says no data is shared with third parties, while simultaneously disclosing that the app may collect users' Messages.
PopKash (com.popkash.cashloan.lending.bd) is also still published, with more than 1 million downloads and 65,400 reviews.
Its listed operator is Brandopedia Trade Corporation, registered to an address in Makati, Philippines.
It advertises an 18% maximum APR and a 90-to-180-day term.
Its most recent reviews, posted in early August, are strikingly uniform in phrasing and register, the pattern BTRC's notice describes as misleading or fake.
Not found. Listings for com.Vn.dhaka.loan, com.Vncash.kash.loan.bd and com.hunsoab.xjd.ban no longer surface.
Their absence is consistent with removal, but cannot be confirmed as such; Google publishes no per-app enforcement record.
That distinction is less reassuring than it looks.
A near-identically named app, DhakaFin – CashLoan (com.fin.dhaka.loan), remains published with 100,000-plus downloads under a Bangkok-registered developer.
So does FinCash (com.fincash.kash.loan.bd).
The naming convention, a swapped prefix on an otherwise identical package string, is the signature of a portfolio operation rather than a single rogue developer.
The regulator's own blacklist
Three days after BTRC's second notice, on August 27, the Bangladesh Financial Intelligence Unit issued a public warning naming 30 unauthorised lending apps.
Under the guise of quick loans, the BFIU said, the operators collect national ID details, contact lists and photographs, then move to harassment, extortion and threats to publish personal data.
Lending without Bangladesh Bank approval is illegal, it said, and proceeds from fraudulent lending are a predicate offence under section 4 of the Money Laundering Prevention Act, 2012.
Pop Cash, Dost Loan, Dhaka Fin, FinCash and Quick Loan are all on that list.
All five remain traceable on the Play Store today, either under their original package or a near-clone.
Bangladeshi regulators have moved in parallel on the payments rails, closing more than 20,000 mobile financial service accounts linked to lending, gambling and unlicensed crypto trading in recent weeks, according to trade reporting.
That reporting puts effective rates on some of these loans at up to 800%, against the 14.6% to 21.9% figures the same apps publish on Google's store.
The gap in Google's country specific policy
Google's Financial Services policy states that personal loan apps must be listed under Finance, must disclose a maximum APR, minimum and maximum repayment periods and a worked example of total cost, and may not require full repayment within 60 days.
They are barred outright from requesting READ_CONTACTS, READ_MEDIA_IMAGES, READ_EXTERNAL_STORAGE, ACCESS_FINE_LOCATION, READ_PHONE_NUMBERS and QUERY_ALL_PACKAGES, precisely the permissions BTRC and the BFIU describe being abused.
But the policy's country-specific annex, which requires developers to file proof of a lending licence with the regulator of the market they target, covers eight jurisdictions: the United States, India, Indonesia, the Philippines, Nigeria, Kenya, Pakistan and Thailand.
Bangladesh is not among them.
A developer can publish a loan app aimed at Bangladeshi borrowers without ever demonstrating to Google that Bangladesh Bank has authorised it to lend.
Google built that licence-verification machinery in India, Kenya, Nigeria and Pakistan between 2021 and 2023.
It has not extended it to Bangladesh, a market of some 190 million people where every one of the preconditions, heavy microcredit demand, near-universal mobile wallets, and an app economy running well ahead of its regulator, is present.
The result is a disclosure regime that grades operators on their own paperwork.
Under one still-live listing, a borrower wrote in June that after applying for 1,500 taka she received 900, an origination fee amounting to 60% of the loan, and noted that this was nowhere near the 21.9% the listing advertised.
The developer's public reply invited her to contact in-app support.
The review, and the listing, are both still up.
A request, not an order
The most consequential weakness may be Bangladesh's own.
BTRC's notices are, on their face, requests.
They set no deadline, name no compliance officer, cite no enforcement instrument and attach no penalty.
The August 25 filing closes by asking that the matter "kindly be accorded due priority."
Compare that with what other governments filed with Google in the same weeks.
Singapore's Digital Disruption Centre served a direction under sections 6(1)(b) and 12 of the Online Criminal Harms Act 2023 that named the app, set a compliance deadline of 7 p.m. the following day, required written confirmation to a specified police address, ordered records preserved until November, and stated that non-compliance without reasonable excuse is an offence punishable under section 50(8).
It also set out Google's rights of reconsideration and appeal.
Taiwan's interior ministry invoked a statute that obliges platforms to restrict access on notification.
Those are instruments a compliance team must process.
A courteous request with a URL list is one a compliance team may triage.
What happens next
The Cyber Security Act, 2026 is understood to empower BTRC to order the removal of harmful content, subject to expedited judicial review, a power distinct from the advisory posture the August notices adopt.
Whether the commission escalates from request to order, and whether it pairs cyber-law grounds with the licensing case that Bangladesh Bank and the BFIU have already made in public, will determine how much of this is enforcement and how much is correspondence.
For now, the regulator has told Google in writing that these apps are extorting Bangladeshi borrowers, the central bank's financial intelligence unit has named them illegal, and a borrower in Dhaka can still install several of them today.
Sources: BTRC removal notices dated 4 and 25 August 2026 as published in the Lumen database; Google Play Store listings checked 4 September 2026; Bangladesh Financial Intelligence Unit press release of 27 August 2026 as reported by The Daily Star and BSS; Google Play Financial Services developer policy; Gambling Prevention Act, 2026 (Act No. 98 of 2026). Download figures and ratings are as displayed by Google Play at the time of checking and are Google's own rounded estimates.