← Back to Insights
DPDP Act 2023: How Data Minimisation Is Rewriting KYC Data Handling in India
By AssureLocker Team

DPDP Act 2023: How Data Minimisation Is Rewriting KYC Data Handling in India

Under the DPDP Act, every redundant Aadhaar and PAN scan a bank hoards is now unpriced liability — up to ₹250 crore of it. The fix isn't deleting the KYC record; it's proving the fact without keeping the document.

The customer uploaded her Aadhaar once. The bank kept it forty times.

One copy sat in the core KYC record, where the law wanted it. The other thirty-nine were the sediment of ordinary banking: a scan in the account-opening officer's email, a PDF on a branch shared drive, an image attached to a loan file, a row in the CRM the cross-sell team queried, a backup of the backup, a vendor's onboarding portal that never purged its cache. None of those copies were malicious. Every one of them is now a liability with a statutory price tag.

The cost was never the KYC record. It's the copies.

In July 2026, a breach at Bank of Baroda exposed the Aadhaar numbers, loan files and account photos of roughly 300,000 customers after attackers used a single compromised employee email account, with the group behind it dumping around a terabyte of data (TechTimes). The instructive part is not the intrusion. It's that one mailbox held that much identity data at all. The damage scales with how many raw documents an institution keeps lying around — and most keep far more than any regulation asks them to.

That is precisely the surface the Digital Personal Data Protection Act, 2023 is built to shrink. The DPDP Rules were notified on 14 November 2025, with substantive obligations enforceable from a compliance deadline of 13 May 2027 (India Briefing). Two of its seven principles land directly on KYC hoarding: data minimisation (collect only what the stated purpose needs) and storage limitation (retain only as long as that purpose or a legal obligation requires, then erase or anonymise) (K&K). The Rules go further, requiring a data fiduciary to notify the individual at least 48 hours before erasing their data at the end of a retention window (Seqrite).

The teeth are real: up to ₹250 crore for failure to maintain reasonable security safeguards, and up to ₹200 crore for failing to notify a breach (DPDPA.com). Under DPDP, every redundant Aadhaar scan is no longer clutter. It is unpriced exposure.

The compliance officer's genuine bind

Here is where honest advice matters, because banks are not simply free to delete. The RBI Master Direction on KYC, 2016 requires regulated entities to preserve customer identification records for at least five years after the business relationship ends, and transaction records for five years from the transaction date — obligations that sit alongside the Prevention of Money Laundering Act (ConsentOS). So a bank answers to three regimes at once: RBI KYC, PMLA, and DPDP, and their retention clocks do not agree.

The resolution is not to delete the KYC record. It's to recognise that the five-year mandate covers one controlled record. It never authorised the thirty-nine copies. DPDP's minimisation duty and the RBI/PMLA retention duty are only in tension if you conflate "keep the record" with "keep raw identity documents everywhere they happened to land." They don't conflict; they point at the same discipline from opposite ends.

What already exists — and the gap that remains

It would be dishonest to imply Indian KYC infrastructure is a blank field. The Central KYC Records Registry run by CERSAI already lets a regulated entity fetch an existing record instead of re-collecting documents, and CKYCRR 2.0 is steadily improving that reuse. This genuinely reduces re-collection.

But note what CKYC returns: the full record. The prevailing model — whether via CKYC, a fresh upload, or a video-KYC vendor — is still full-document disclosure. To confirm a customer is over 18, PAN-verified, and name-matched to their bank account, institutions pull and store the entire Aadhaar and PAN. The verifier learns a dozen facts it never needed, and inherits the duty to protect all of them. The residual gap DPDP now prices is the gap between the fact a lender needs to check and the raw document it ends up storing to check it.

Prove the fact, don't hoard the document

The design that closes that gap is a consent-backed, selectively-disclosable credential. The customer's identity is verified once at source; what a lender receives afterwards is a signed, tamper-evident proof of exactly the attributes it asked for — "over 18," "PAN validated," "name matches" — released under the holder's explicit consent, with an auditable record of what was shared and why. The lender gets a faster, provable check. It does not get a copy of the Aadhaar to safeguard for five years and a DPDP officer to answer to for the other thirty-nine.

This is what AssureVerifID is built for: source-verified reusable identity for businesses (DigiKYB) and individuals (DigiKYC), where disclosure is the holder's choice — full, lite, or a custom subset — and reuse is scoped to the lender relationship, not scattered across systems. AssureLocker is a technology provider: it verifies and proves; it never lends, prices, or decides credit. It makes the lender's judgement fast and its file defensible.

DPDP has turned document hoarding from an operational habit into a board-level exposure. The institutions that come out ahead will be the ones that learned to check the fact without keeping the file.

Explore AssureVerifID and consent-backed reusable identity →

About AssureLocker

AssureLocker is the independent evidence-and-control layer for regulated lending — starting with co-lending. Across four suites — AssureCLA (co-lending assurance), AssureSCF (supply-chain finance), AssureVerifID (reusable identity) and AssureLens(credit-velocity intelligence), on one neutral layer — we make a lender’s controls and evidence fast, reproducible and governed. We are a technology provider: we never lend, price, or decide credit.

Read more on the AssureLocker blog · assurelocker.com