DPDP KYC Consent: Identity Verification, Retention and Choosing IDV Tools

Short answer: DPDP KYC consent is about how a business asks for, uses and keeps identity data when it verifies customers under India’s Digital Personal Data Protection Act, 2023 (DPDP Act). KYC rules from regulators such as the RBI still apply. The DPDP Act sits on top of them. As a result, you need a clear notice, purpose-specific consent where consent is the basis, strict purpose limits on identity data, and a retention plan that respects both laws.
Identity verification collects some of the most sensitive data a business holds, so DPDP KYC consent deserves careful design. That includes Aadhaar details, PAN, photographs, video and address proof. This guide explains how the DPDP Act, the RBI KYC Master Direction and the Aadhaar Act fit together. It also gives a neutral checklist for choosing identity verification (IDV) tools with built-in consent management. It is written for compliance, product and risk teams in fintech, lending, insurance and marketplaces.
What is DPDP KYC consent?
DPDP KYC consent is the consent layer around a know-your-customer process. It covers what you tell the customer, what they agree to, and what you may do with their identity data afterwards.
Under the DPDP Act, the business is the Data Fiduciary. The customer is the Data Principal. An IDV vendor that processes data on your behalf is a Data Processor. Section 8(2) says you may use a processor only under a valid contract. Therefore, your vendor contract is part of your KYC compliance, not just a procurement file.
How the DPDP Act, RBI KYC rules and the Aadhaar Act fit together
Three sets of rules overlap in most Indian KYC flows. Each one answers a different question.
- DPDP Act and Rules: may you process this personal data, for which purpose, and for how long? Section 38 says the Act applies “in addition to and not in derogation of” other laws. It also says the Act prevails where a real conflict exists.
- RBI KYC Master Direction: for regulated entities, it says what identity checks you must run. For example, the RBI Master Direction on KYC requires explicit customer consent for Aadhaar e-KYC authentication. It also requires identity and address records to be kept for at least five years after the business relationship ends.
- Aadhaar Act, 2016: it governs Aadhaar authentication. Under Section 8 of the Aadhaar Act, a requesting entity must obtain consent before collecting identity information. It must also inform the person about the nature of the information shared, its uses, and the alternatives to submitting it. In addition, Section 29(3) limits use to the purposes informed in writing.
In short, DPDP KYC consent does not replace your regulator’s KYC rules. Instead, it adds notice, purpose, rights and retention duties around them. Check the current version of your regulator’s directions before you design the flow, because they are amended from time to time.
What needs DPDP KYC consent, and what another law already requires
This is where DPDP KYC consent often gets confused. Some KYC processing happens because a law requires it. Other processing happens because the business wants it. The two need different handling.
Consider a lending app. Verifying identity and address before opening a loan account follows the lender’s regulatory duty. By contrast, reusing the selfie to train a fraud model, or sharing KYC data with a partner for cross-selling, is a separate purpose. Section 6(1) requires consent to be specific and limited to the data needed for the specified purpose. Therefore, you should not bundle these extra purposes into the KYC consent.
Interpretation, not settled law: which DPDP ground covers each KYC step is a legal judgement. Section 17(1)(c) exempts processing for preventing or detecting offences, and some teams rely on it for fraud checks. However, that reading has limits. Take legal advice before relying on an exemption instead of consent.
How DPDP KYC consent works in an onboarding flow

A sound DPDP KYC consent flow usually runs in six steps:
- Notice first. Show a standalone notice that lists the identity data, the purposes and how to withdraw consent. Rule 3 of the DPDP Rules sets these contents.
- Separate choices. Keep the mandatory KYC purpose apart from optional ones, such as marketing or model training.
- Verification by the processor. Next, the IDV vendor runs document, face or Aadhaar checks under your contract.
- Purpose-limited use. Then store the result and the minimum data you need. Keep raw images and video only if a rule requires them.
- Retention clock. Start a clock when the relationship ends. Keep KYC records for the period your regulator sets.
- Erasure. Finally, erase the data when that period ends. Section 8(7)(b) also requires you to make your processor erase it.
A practical example
A digital NBFC onboards 50,000 borrowers a month through a third-party IDV vendor. At onboarding, the customer sees a notice in her chosen language. She agrees to verification for the loan. She declines marketing. Consequently, the consent record shows one purpose accepted and one declined.
Two years later, she closes the loan. The NBFC’s system starts the five-year KYC retention clock under its RBI obligations. Meanwhile, marketing systems never received her data, because she never consented. When the clock ends, the NBFC erases the records and sends an erasure instruction to the vendor. The log of that instruction becomes its evidence.
Retention: Section 8(7) versus the KYC record rule
For DPDP KYC consent, retention is the hardest part. Section 8(7) of the DPDP Act normally requires erasure when consent is withdrawn or the purpose ends. However, the same section opens with an exception: “unless retention is necessary for compliance with any law”. So a regulated lender can keep KYC records for the period its KYC rules require, even after a customer withdraws consent.
That exception covers the record the law requires, not everything. For example, a marketing profile built from KYC data has no such cover. Similarly, extra selfies or video beyond what the rule requires may have none. Our guide to building a DPDP retention policy explains how to map each data item to its legal basis and clock.
Children and persons with disability
Some products onboard minors, such as student accounts or insurance for dependants. Section 9(1) requires verifiable consent from a parent or lawful guardian before processing a child’s data. The same applies to a person with disability who has a lawful guardian.
Rule 10 describes how to verify this. You can rely on reliable details of identity and age that you already hold. Alternatively, you can use a virtual token issued by an authorised entity, such as a Digital Locker service provider. For more detail, see our FAQ on verifiable parental consent.
Choosing IDV tools with built-in DPDP KYC consent
Many searches ask for the “best” identity verification tools with consent management built in. We do not rank vendors here, because product claims change quickly. Instead, use this checklist in your evaluation. Ask each vendor to show you, not just tell you.
- Notice and consent screens: can you show your own Rule 3 notice before capture, in the customer’s chosen language?
- Purpose separation: can mandatory KYC and optional purposes be captured as separate choices?
- Consent evidence: does each check return a record of the notice version, time and choices?
- Data minimisation: can you switch off storage of raw images or video where you do not need them?
- Erasure on instruction: will the vendor erase data on your instruction and confirm it in writing?
- Contract terms: does the contract cover processing limits, security safeguards and breach notice to you?
- Logs: can the vendor keep and share logs for at least one year, in line with Rule 6?
Treat the IDV vendor as part of your third-party risk programme, since it handles DPDP KYC consent data too. Our guide to vendor risk management under DPDP covers the due diligence steps.
Comparing approaches to DPDP KYC consent
| Approach | Strength | Weakness |
|---|---|---|
| In-house KYC build | Full control of data | High build and audit cost |
| IDV vendor only | Fast, proven checks | Consent and notices are often thin |
| IDV vendor plus a consent layer | Checks plus provable consent | Two systems to integrate |
For most regulated businesses, the third option balances speed and proof for DPDP KYC consent. The consent layer holds notices, choices, withdrawals and retention rules. Meanwhile, the IDV vendor does what it does best.
Pros and cons of a separate consent layer for DPDP KYC consent
Pros:
- Consent records stay the same even if you change IDV vendors.
- Withdrawal, rights requests and retention rules live in one place.
- Your processor register shows exactly which vendor holds which data.
Cons:
- Integration work is needed at onboarding.
- Teams must keep consent purposes and vendor settings aligned.
- No platform can make legal judgements for you, such as which exemption applies.
Common mistakes
- Bundled consent. One checkbox covers KYC, marketing and data sharing.
- Keeping everything forever. Teams keep raw video and images long after the rule period ends.
- No processor erasure. The business deletes its copy, but the vendor still holds data.
- Reusing Aadhaar data. Teams use Aadhaar details for purposes the customer was never told about.
- English-only notices. The customer cannot read what she is agreeing to.
Banks and NBFCs face added sector rules. Our overview of DPDP compliance for BFSI covers them.
How we measure success
These are the DPDP KYC consent measures we suggest. We do not publish benchmark numbers for them, because they vary by business and sector.
- Purpose separation: the share of onboarding flows where optional purposes are captured separately.
- Proof completeness: the share of KYC records linked to a notice version and consent record.
- Retention hygiene: the share of closed relationships with a running retention clock.
- Processor erasure: the share of erasure events confirmed by the IDV vendor.
- Vendor coverage: the share of IDV vendors with a signed DPDP-aligned contract.
Frequently asked questions
Does the DPDP Act replace RBI KYC rules?
No. Section 38 says the Act applies in addition to other laws. Your KYC duties continue. The DPDP Act adds notice, consent, rights and retention duties on top.
Can a customer ask us to delete KYC data?
She can ask. However, Section 8(7) lets you keep data where retention is necessary to comply with another law. You should explain that clearly and erase any data that no law requires you to keep.
Is consent needed for Aadhaar e-KYC?
Yes. The Aadhaar Act requires consent before collecting identity information for authentication. The RBI Master Direction also requires explicit consent for e-KYC by regulated entities.
Is the IDV vendor responsible under the DPDP Act?
The vendor is usually your Data Processor. You remain accountable as the Data Fiduciary. Therefore, your contract must set limits, safeguards and erasure duties.
How long must we keep logs of verification?
Rule 6 of the DPDP Rules requires logs and personal data to be kept for at least one year for security purposes. Your KYC rules may require longer retention of certain records.
When do these DPDP duties start?
The core consent, notice and security duties, including Rules 3, 6 and 10, commence on 13 May 2027.
Summary and next step
In summary, DPDP KYC consent means running your regulator’s checks inside a DPDP-grade wrapper. That wrapper includes a clear notice, separate purposes, purpose-limited use, a legal retention clock and processor erasure. Choose IDV tools that can prove consent, not just verify faces.
ProtectComply does not perform identity verification itself. It provides the consent layer around it, including Consent-as-a-Service, OTP-gated withdrawal and a RoPA with a vendor and processor catalogue. Explore the consent and RoPA features, compare the product modules, or talk to the team about your onboarding flow.
Published by Jupinder Singh Bedi, CEO and Co-Founder, ProtectComply. SEO: Yatin Chaudhary. Legal references: Digital Personal Data Protection Act, 2023, Sections 6, 8, 9, 17 and 38; Digital Personal Data Protection Rules, 2025, Rules 1, 3, 6 and 10; Aadhaar Act, 2016, Sections 8 and 29; RBI Master Direction on KYC. This article is general information, not legal advice.