Readiness assessment
Fintech & Banking · KYC · Video-KYC

The DPDP Act for Video-KYC (V-CIP)

Video-based customer identification captures live video, facial and document data under RBI V-CIP norms, raising the security bar.

In short

Video-KYC runs under the RBI Video-based Customer Identification Process (V-CIP) norms and the DPDP Act. The live video, facial-match and liveness data you capture is high-risk, so reasonable security safeguards, minimization and clear consent are central. Penalties reach ₹250 crore.

Core impacts

What changes for this niche, and the specific rule it turns on.

RBI V-CIP norms apply

V-CIP sits under the RBI KYC Master Direction; the DPDP Act adds the data-protection layer.

High-risk capture

Live video, facial-match and liveness data demand strong security under Section 8(5); encrypt and restrict access.

Minimize and do not over-retain

Capture only what identification needs; keep the recording only as long as KYC rules require.

Vendors as processors

Video-KYC and liveness vendors are processors; contract and oversee them.

Common questions

Short, cite-able answers, mirrored in FAQPage schema.

Does the DPDP Act apply to video-KYC?
Yes. The video and facial data captured is personal data; the Act applies alongside the RBI V-CIP norms.
Is facial or biometric data special under the DPDP Act?
The Act scales duties to the risk of harm rather than naming a category; facial and liveness data is high-risk and needs strong safeguards.
How long can V-CIP recordings be kept?
For the period KYC rules require, then deleted; document the retention basis.

Check your V-CIP flow.

The readiness check flags capture-security, minimization and vendor gaps.

Take the readiness check