RBI vs DPDP: Erasure When KYC Retention Still Applies
Understand the five-year KYC and transaction-record rules, DPDP erasure exceptions, purpose restriction and a defensible BFSI retention workflow.
DPDP implementation in banking, fintech and lending must be layered onto existing RBI, PMLA, CERT-In, payment, securities, insurance and contractual obligations. The result is not “privacy versus regulation”; it is a purpose-and-record map showing which rule governs each activity, what must be retained, who may use it and what evidence is required. Current status, verified 29 August 2026: most substantive DPDP duties are notified but scheduled to commence around May 2027, while many sectoral and CERT-In duties already apply.
During onboarding, separate identity and KYC records, account or credit application data, fraud checks, optional analytics and marketing. Record the exact purpose and governing source for each. A consent screen should not imply that a customer can withdraw processing required to evaluate or perform the requested regulated service, and a statutory or permitted-use decision should not be stretched into unrelated cross-sell or profiling.
Map roles activity by activity. A bank, NBFC, fintech, account aggregator, payment participant, bureau, KYC utility and cloud provider may be a Fiduciary for one purpose and a Processor for another. The Data Fiduciary remains accountable for processing on its behalf. Contracts should define instructions, security, sub-processors, audit evidence, incident escalation, rights support, retention, deletion and cross-border responsibilities without presenting every negotiated clause as an express universal statutory processor duty.
Retention needs record-level precision. Customer-identification records, account files and business correspondence are generally retained for five years after the business relationship ends under the relevant KYC/PML framework, while transaction records are generally retained for five years from the transaction date; other RBI, tax, securities, insurance, fraud, dispute or enforcement sources may differ. Restrict retained records to the required purpose and access, archive them appropriately and erase residual marketing or profiling data when no justification remains. Use the dedicated KYC-retention guide for the dated source analysis.
Rights workflows must reconcile identity, fraud and confidentiality risks. Verify the requester proportionately, locate data across core systems and processors, correct customer-supplied facts without rewriting immutable transaction history, explain lawful retention exceptions and log every system outcome. Children, nominees, joint accounts, authorised representatives and deceased customers require specialised authority checks rather than a generic self-service flow.
Security and breach playbooks must run parallel clocks. Future DPDP breach notifications and current CERT-In or sectoral reporting obligations are different duties with different triggers, recipients and content. Preserve an awareness timestamp, evidence chain, decision log and consistent external facts. Rehearse processor escalation because outages or delayed incident details can consume the response window.
Governance should join product, compliance, legal, fraud, information security, operations, procurement and customer service. Monitor consent and preference drift, unexplained data use, KYC archive access, processor exceptions, rights ageing, deletion failures, incident escalation and remediation closure. Use the linked breach, KYC-retention, fiduciary-versus-processor, security and SDF guides for the specialist analysis; this hub remains the BFSI journey map.
2 articles
Back to home
Understand the five-year KYC and transaction-record rules, DPDP erasure exceptions, purpose restriction and a defensible BFSI retention workflow.
How Indian banks, NBFCs, and fintech LSPs can design an auditable co-lending consent chain from lead source to NBFC to bank under RBI and DPDP requirements.
Here to help
Share your details and the team can take it forward from here.