In brief: the DPDP Act governs how businesses collect and use digital personal data in India, which includes almost everything gathered during KYC. This page explains what the DPDP Act means for verification systems.
What the DPDP Act is
The Digital Personal Data Protection Act (DPDP Act), 2023 is India’s data protection law governing how personal data is collected, processed, and stored, including data collected during KYC — identity documents, biometric data, and the verification results derived from them.

What it means for KYC data specifically
KYC data is personal data by definition, so its collection requires a lawful basis (consent or a specified legitimate use, such as a statutory KYC obligation), and the entity holding it takes on the DPDP Act’s obligations around purpose limitation, storage, and breach notification.
This is a general description, not compliance advice. DPDP Act rules and their interaction with sector-specific KYC requirements were still being finalised as of this writing — verify current rules before relying on this for a compliance decision.

Applying the DPDP Act to KYC data
KYC processes collect some of the most sensitive personal data a business holds: identity numbers, photographs, addresses and financial details. The DPDP Act sets expectations for how that data is handled, alongside the KYC rules that require it to be collected in the first place.
Key ideas for verification teams
- Clear purpose. Collect data for a specific, stated purpose, and use it only for that purpose.
- Consent and notice. Tell people what you are collecting and why, and record their consent where it is the basis for processing.
- Data minimisation. Collect and keep only what the purpose needs; mask identifiers you only need to reference.
- Security safeguards. Protect data with access controls, encryption and logging.
- Retention. Keep data only as long as it is needed or legally required, then delete it.
Where KYC rules and the DPDP Act meet
Some KYC records must be retained for set periods under financial regulations, even after a customer leaves. Map each data type to its retention requirement, so you keep what regulators require and delete what they do not. Document that mapping; it is the clearest evidence that your verification system respects both regimes.
Practical steps
Review each verification step and ask what data it collects, why, who can see it, how long it is kept and how it is deleted. Answering those questions for every check is the most practical way to align a KYC flow with the DPDP Act. India’s data protection framework is described on MeitY’s data protection framework page.
