KYC turns identity documents, Aadhaar, PAN and biometrics into the front door of every financial relationship.
In short
KYC processes some of the most sensitive identifiers there are. The Act demands consent and strict purpose limitation for that data, while RBI KYC rules set retention periods you must reconcile with the right to erasure. Penalties reach ₹250 crore.
What changes for this sub-sector.
KYC data collected to verify identity cannot be reused for marketing or unrelated products without fresh consent.
Aadhaar, PAN and biometrics need strong safeguards and minimal collection; capture only what verification requires.
RBI mandates KYC-record retention; the erasure right yields to that legal obligation, so document why you keep what you keep.
KRAs, video-KYC vendors and onboarding SDKs are processors; their mishandling is your liability.
An identity-data breach must be reported to the affected people and the Board.
Niche guides for this area, each naming the specific regulation.
Lock down purpose and retention first, then vendors.
The readiness check flags purpose-creep, retention conflicts and vendor gaps in KYC.
Take the readiness check →