Readiness assessment
Fintech & Banking · KYC

The DPDP Act for KYC & Onboarding

KYC turns identity documents, Aadhaar, PAN and biometrics into the front door of every financial relationship.

In short

KYC processes some of the most sensitive identifiers there are. The Act demands consent and strict purpose limitation for that data, while RBI KYC rules set retention periods you must reconcile with the right to erasure. Penalties reach ₹250 crore.

Core impacts

What changes for this sub-sector.

Purpose limitation

KYC data collected to verify identity cannot be reused for marketing or unrelated products without fresh consent.

Sensitive identifiers

Aadhaar, PAN and biometrics need strong safeguards and minimal collection; capture only what verification requires.

Retention vs erasure

RBI mandates KYC-record retention; the erasure right yields to that legal obligation, so document why you keep what you keep.

Third-party KYC

KRAs, video-KYC vendors and onboarding SDKs are processors; their mishandling is your liability.

Breach reporting

An identity-data breach must be reported to the affected people and the Board.

Go deeper

Niche guides for this area, each naming the specific regulation.

Check your onboarding flow.

The readiness check flags purpose-creep, retention conflicts and vendor gaps in KYC.

Take the readiness check