DPDP Act & KYC Data

In brief: the DPDP Act governs how businesses collect and use digital personal data in India, which includes almost everything gathered during KYC. This page explains what the DPDP Act means for verification systems.

What the DPDP Act is

The Digital Personal Data Protection Act (DPDP Act), 2023 is India’s data protection law governing how personal data is collected, processed, and stored, including data collected during KYC — identity documents, biometric data, and the verification results derived from them.

DPDP Act: a personal data folder protected by a lock and a consent toggle switch

What it means for KYC data specifically

KYC data is personal data by definition, so its collection requires a lawful basis (consent or a specified legitimate use, such as a statutory KYC obligation), and the entity holding it takes on the DPDP Act’s obligations around purpose limitation, storage, and breach notification.

This is a general description, not compliance advice. DPDP Act rules and their interaction with sector-specific KYC requirements were still being finalised as of this writing — verify current rules before relying on this for a compliance decision.

DPDP Act: a personal data folder protected by a lock and a consent toggle switch

Applying the DPDP Act to KYC data

KYC processes collect some of the most sensitive personal data a business holds: identity numbers, photographs, addresses and financial details. The DPDP Act sets expectations for how that data is handled, alongside the KYC rules that require it to be collected in the first place.

Key ideas for verification teams

Where KYC rules and the DPDP Act meet

Some KYC records must be retained for set periods under financial regulations, even after a customer leaves. Map each data type to its retention requirement, so you keep what regulators require and delete what they do not. Document that mapping; it is the clearest evidence that your verification system respects both regimes.

Practical steps

Review each verification step and ask what data it collects, why, who can see it, how long it is kept and how it is deleted. Answering those questions for every check is the most practical way to align a KYC flow with the DPDP Act. India’s data protection framework is described on MeitY’s data protection framework page.

DPDP Act: a privacy shield over a database with consent checkmarks

Verify it with Veriqos Technologies

← Back to the verification glossary