← All posts

28 Sep 2026

DPDP KYC Consent: Identity Verification, Retention and Choosing IDV Tools

Short answer: DPDP KYC consent is about how a business asks for, uses and keeps identity data when it verifies customers under India’s Digital Personal Data Protection Act, 2023 (DPDP Act). KYC rules from regulators such as the RBI still apply. The DPDP Act sits on top of them. As a result, you need a clear notice, purpose-specific consent where consent is the basis, strict purpose limits on identity data, and a retention plan that respects both laws.

Identity verification collects some of the most sensitive data a business holds, so DPDP KYC consent deserves careful design. That includes Aadhaar details, PAN, photographs, video and address proof. This guide explains how the DPDP Act, the RBI KYC Master Direction and the Aadhaar Act fit together. It also gives a neutral checklist for choosing identity verification (IDV) tools with built-in consent management. It is written for compliance, product and risk teams in fintech, lending, insurance and marketplaces.

What is DPDP KYC consent?

DPDP KYC consent is the consent layer around a know-your-customer process. It covers what you tell the customer, what they agree to, and what you may do with their identity data afterwards.

Under the DPDP Act, the business is the Data Fiduciary. The customer is the Data Principal. An IDV vendor that processes data on your behalf is a Data Processor. Section 8(2) says you may use a processor only under a valid contract. Therefore, your vendor contract is part of your KYC compliance, not just a procurement file.

How the DPDP Act, RBI KYC rules and the Aadhaar Act fit together

Three sets of rules overlap in most Indian KYC flows. Each one answers a different question.

In short, DPDP KYC consent does not replace your regulator’s KYC rules. Instead, it adds notice, purpose, rights and retention duties around them. Check the current version of your regulator’s directions before you design the flow, because they are amended from time to time.

What needs DPDP KYC consent, and what another law already requires

This is where DPDP KYC consent often gets confused. Some KYC processing happens because a law requires it. Other processing happens because the business wants it. The two need different handling.

Consider a lending app. Verifying identity and address before opening a loan account follows the lender’s regulatory duty. By contrast, reusing the selfie to train a fraud model, or sharing KYC data with a partner for cross-selling, is a separate purpose. Section 6(1) requires consent to be specific and limited to the data needed for the specified purpose. Therefore, you should not bundle these extra purposes into the KYC consent.

Interpretation, not settled law: which DPDP ground covers each KYC step is a legal judgement. Section 17(1)(c) exempts processing for preventing or detecting offences, and some teams rely on it for fraud checks. However, that reading has limits. Take legal advice before relying on an exemption instead of consent.

How DPDP KYC consent works in an onboarding flow

DPDP KYC consent onboarding flow: notice, purpose-specific consent, identity verification by processor, purpose-limited use, retention clock and erasure
A DPDP-aware KYC onboarding flow. The retention clock and the processor erasure step are the ones most flows miss.

A sound DPDP KYC consent flow usually runs in six steps:

  1. Notice first. Show a standalone notice that lists the identity data, the purposes and how to withdraw consent. Rule 3 of the DPDP Rules sets these contents.
  2. Separate choices. Keep the mandatory KYC purpose apart from optional ones, such as marketing or model training.
  3. Verification by the processor. Next, the IDV vendor runs document, face or Aadhaar checks under your contract.
  4. Purpose-limited use. Then store the result and the minimum data you need. Keep raw images and video only if a rule requires them.
  5. Retention clock. Start a clock when the relationship ends. Keep KYC records for the period your regulator sets.
  6. Erasure. Finally, erase the data when that period ends. Section 8(7)(b) also requires you to make your processor erase it.

A practical example

A digital NBFC onboards 50,000 borrowers a month through a third-party IDV vendor. At onboarding, the customer sees a notice in her chosen language. She agrees to verification for the loan. She declines marketing. Consequently, the consent record shows one purpose accepted and one declined.

Two years later, she closes the loan. The NBFC’s system starts the five-year KYC retention clock under its RBI obligations. Meanwhile, marketing systems never received her data, because she never consented. When the clock ends, the NBFC erases the records and sends an erasure instruction to the vendor. The log of that instruction becomes its evidence.

Retention: Section 8(7) versus the KYC record rule

For DPDP KYC consent, retention is the hardest part. Section 8(7) of the DPDP Act normally requires erasure when consent is withdrawn or the purpose ends. However, the same section opens with an exception: “unless retention is necessary for compliance with any law”. So a regulated lender can keep KYC records for the period its KYC rules require, even after a customer withdraws consent.

That exception covers the record the law requires, not everything. For example, a marketing profile built from KYC data has no such cover. Similarly, extra selfies or video beyond what the rule requires may have none. Our guide to building a DPDP retention policy explains how to map each data item to its legal basis and clock.

Children and persons with disability

Some products onboard minors, such as student accounts or insurance for dependants. Section 9(1) requires verifiable consent from a parent or lawful guardian before processing a child’s data. The same applies to a person with disability who has a lawful guardian.

Rule 10 describes how to verify this. You can rely on reliable details of identity and age that you already hold. Alternatively, you can use a virtual token issued by an authorised entity, such as a Digital Locker service provider. For more detail, see our FAQ on verifiable parental consent.

Choosing IDV tools with built-in DPDP KYC consent

Many searches ask for the “best” identity verification tools with consent management built in. We do not rank vendors here, because product claims change quickly. Instead, use this checklist in your evaluation. Ask each vendor to show you, not just tell you.

Treat the IDV vendor as part of your third-party risk programme, since it handles DPDP KYC consent data too. Our guide to vendor risk management under DPDP covers the due diligence steps.

Comparing approaches to DPDP KYC consent

Approach Strength Weakness
In-house KYC build Full control of data High build and audit cost
IDV vendor only Fast, proven checks Consent and notices are often thin
IDV vendor plus a consent layer Checks plus provable consent Two systems to integrate

For most regulated businesses, the third option balances speed and proof for DPDP KYC consent. The consent layer holds notices, choices, withdrawals and retention rules. Meanwhile, the IDV vendor does what it does best.

Pros and cons of a separate consent layer for DPDP KYC consent

Pros:

Cons:

Common mistakes

Banks and NBFCs face added sector rules. Our overview of DPDP compliance for BFSI covers them.

How we measure success

These are the DPDP KYC consent measures we suggest. We do not publish benchmark numbers for them, because they vary by business and sector.

Frequently asked questions

Does the DPDP Act replace RBI KYC rules?

No. Section 38 says the Act applies in addition to other laws. Your KYC duties continue. The DPDP Act adds notice, consent, rights and retention duties on top.

Can a customer ask us to delete KYC data?

She can ask. However, Section 8(7) lets you keep data where retention is necessary to comply with another law. You should explain that clearly and erase any data that no law requires you to keep.

Is consent needed for Aadhaar e-KYC?

Yes. The Aadhaar Act requires consent before collecting identity information for authentication. The RBI Master Direction also requires explicit consent for e-KYC by regulated entities.

Is the IDV vendor responsible under the DPDP Act?

The vendor is usually your Data Processor. You remain accountable as the Data Fiduciary. Therefore, your contract must set limits, safeguards and erasure duties.

How long must we keep logs of verification?

Rule 6 of the DPDP Rules requires logs and personal data to be kept for at least one year for security purposes. Your KYC rules may require longer retention of certain records.

When do these DPDP duties start?

The core consent, notice and security duties, including Rules 3, 6 and 10, commence on 13 May 2027.

Summary and next step

In summary, DPDP KYC consent means running your regulator’s checks inside a DPDP-grade wrapper. That wrapper includes a clear notice, separate purposes, purpose-limited use, a legal retention clock and processor erasure. Choose IDV tools that can prove consent, not just verify faces.

ProtectComply does not perform identity verification itself. It provides the consent layer around it, including Consent-as-a-Service, OTP-gated withdrawal and a RoPA with a vendor and processor catalogue. Explore the consent and RoPA features, compare the product modules, or talk to the team about your onboarding flow.

Published by Jupinder Singh Bedi, CEO and Co-Founder, ProtectComply. SEO: Yatin Chaudhary. Legal references: Digital Personal Data Protection Act, 2023, Sections 6, 8, 9, 17 and 38; Digital Personal Data Protection Rules, 2025, Rules 1, 3, 6 and 10; Aadhaar Act, 2016, Sections 8 and 29; RBI Master Direction on KYC. This article is general information, not legal advice.