NBFC KYC data retention is where most lenders freeze the wrong files. The Digital Personal Data Protection Act, 2023 asks for erasure when the purpose ends. The RBI KYC Master Direction, 2016 asks for a five-year keep on named classes. Treating those as one bucket is the 2027 liability.

TL;DR

  • NBFC KYC data retention is a record-class map, not a five-year freeze on Aadhaar sitting in WhatsApp, a shared drive, and three LSP exports.
  • Section 8(7) of the Digital Personal Data Protection Act, 2023 wants erasure once the specified purpose is served, subject to law in force. The KYC Direction is that law for the classes it actually names.
  • RBI Chapter VII, paragraph 46: transaction records at least five years from the date of transaction; identification and address records at least five years after the business relationship is ended.
  • Rejected-applicant packs, marketing lists, and duplicate CSVs are usually not that keep. Delete them. A live borrower cannot use erasure to punch a hole in a statutory freeze that still applies.
  • Substantive DPDP Rules, 2025 duties phase in on 13 May 2027. A leaked KYC copy still starts CERT-In (6 hours) and the Data Protection Board of India (DPB) under Rule 7 (72 hours). Section 8(5) sits under the ₹250 crore Schedule slab.

What does NBFC KYC data retention actually require under DPDPA?

NBFC KYC data retention work is two statutes on one loan file, not a vendor slide that says “keep everything five years.”

The NBFC is already a Data Fiduciary under Section 2(i) once KYC, bureau, LOS, LMS, CKYC, collections, DSAs and LSPs process digital personal data. Section 8(7) is the erasure duty: cease to retain personal data when it is reasonable to assume the specified purpose is no longer being served, unless retention is necessary for compliance with any law for the time being in force.

That last clause is the RBI keep. It is not a blanket. The Reserve Bank of India (Know Your Customer (KYC)) Direction, 2016, Chapter VII, paragraph 46, read with the Prevention of Money-Laundering Act, 2002 and the PML (Maintenance of Records) Rules, 2005, tells a regulated entity to:

  • maintain necessary transaction records for at least five years from the date of transaction;
  • preserve identification of the customer and their address, obtained while opening the account and during the business relationship, for at least five years after the business relationship is ended;
  • make those records available to competent authorities on request.

Write that as a keep on those classes, with a clock start you can defend. Do not paste it onto a reject, a marketing list, a test environment, or a WhatsApp export.

The DPDPA does not revive the old SPDI “sensitive personal data” category. Aadhaar KYC and bureau files are personal data under Section 2(t). There is no heavier retention tier because the file is “financial.” Dual-clock filings when a copy leaks are in DPDPA compliance for NBFCs. Stack-level consent is in consent across the NBFC/wealth stack. This piece is the keep-versus-erase cut.

Does the RBI five-year KYC keep cancel Section 8(7) erasure?

No. It narrows erasure for the classes and clocks the Direction actually writes. It does not swallow Section 8(7).

NBFC KYC data retention: Section 8(7) erasure versus the RBI KYC five-year keep

Record classTypical purposeLegal keep?What “done” looks like
Identification + address of a customer who opened a relationshipKYC / CDD under the DirectionYes: para 46(b), five years after the relationship endedOne governed store; clock from closure, not from first upload
Transaction records with that customerReconstruct the transactionYes: para 46(a), five years from the transaction dateRetrievable; not a dump in a shared drive
Rejected-applicant KYC (no account opened)Decision not to onboardUsually no para 46(b) relationshipErase when the decision purpose ends; do not freeze “in case”
Marketing / cross-sell list built from KYCSecondary purposeNo, unless a fresh Section 6 groundSeparate purpose; delete if you cannot name it
LSP / DSA / WhatsApp / test copiesConvenienceNoSurplus. Delete. Processor still holds personal data

A live borrower who asks for erasure does not punch through a keep the Direction still requires. Name the law in the notice and in the refusal. When the five years after closure actually end, Section 8(7) is waiting. Do not invent a tenth year from a Limitation Act slide unless counsel has put a named instrument on that file.

Rule 13 does not change this table. Annual DPIA and statutory audit start only after a Section 10 Significant Data Fiduciary notice. SDF extras: Significant Data Fiduciary under DPDPA.

The copies nobody titled “KYC register.”

Pick one closed account and one reject from last quarter. Ask: where does the Aadhaar image still sit? LOS, LMS, CKYC extract, collections LSP, DSA folder, CISO ticket, a credit analyst’s WhatsApp, a UAT database. Each extra copy is still personal data. The Direction’s keep is not a permission to scatter it.

NBFC KYC data retention: statutory keep versus surplus copies across the lending stack

SurfaceWhat usually failsOwner
LOS / LMS productionIdentifiers copied into every ticket, not tokenisedProduct / eng
CKYC / CKYCRR extractExtra fields retained locally after the upload purpose endedOps / compliance
LSP / DSA / collectionsCSV exports with no deletion date in the Section 8(2) contractLegal
Shared drive / email / WhatsApp”Working file” that never re-enters the keep registerCISO + ops
UAT / vendor sandboxProduction KYC used as test dataEng / vendor

Processor data is still personal data. An LSP export does not leave the Act. Section 8(2) wants a contract with deletion at exit and an hours-based incident SLA that lets you hit CERT-In 6h and Rule 7 72h. The runbook shape is in the NBFC breach SOP. Architecture that stops identifiers cloning into every system is the Privigo platform argument for this cohort — the financial solution cut. Software is not your statutory keep and it is not your Section 10(2)(b) auditor.

Can a live borrower demand erasure of KYC the Direction still freezes?

They can ask. You do not delete the statutory class while the clock is running.

Section 6 consent — free, specific, informed, unconditional, unambiguous, by clear affirmative action — governs purposes that sit on consent. Employment-necessary staff processing can sit under Section 7(i); borrower KYC cannot hide there. A named Section 7 legitimate use, where it actually applies, still needs a Section 5 notice.

When the keep is paragraph 46, the answer to the borrower is: this class is retained because of the KYC Direction / PMLA record rule, until [date]. That sentence belongs in the notice before they ask. After the keep ends, erasure is the default, not a favour.

Do not refuse erasure of a marketing flag, a stray screenshot, or a reject pack by pointing at paragraph 46. That is how an examiner decides you never read the Direction.

How should processors and CKYC copies sit on the same retention map?

Same map, different rows. CKYC upload is a purpose. Name it in the Section 5 notice. It does not freeze a local duplicate after the extract has been sent.

Every processor that still holds the identifier after you have erased the surplus copy is your problem. Put deletion dates in the Section 8(2) pack. Tokenise production identifiers (aligned to Rule 6(1)). An admin-editable folder called “KYC_archive” is not paragraph 46.

What should the compliance officer put in this month’s Board pack?

A map the MD can sign. Not a five-year slogan.

AreaOwnerStatus ☐
Record-class map: para 46(a) transactions / 46(b) ID+address / reject / marketing / surplus copiesCompliance + ops☐
Clock start for closed accounts: relationship-end date, not first uploadOps☐
One reject file erased this fortnight, date in the LOSProduct / ops☐
Surplus copy hunt: WhatsApp, shared drive, UAT, one LSP exportCISO☐
Section 8(2) deletion clause for LOS/LMS/LSP/DSA/CKYC vendorLegal☐
Notice language names the legal keep so erasure requests have an answerProduct / compliance☐
Dual-clock drill if a KYC copy leaks: CERT-In 6h + DPB 72hCISO☐
Do not buy a Rule 13 pack unless and until notified as an SDFFinance☐

Three moves, in order:

  1. Write the two-clock sentence — “Para 46 keep: [classes + start dates]. Section 8(7) erase: [rejects, marketing, surplus copies].” One page in the Board pack.
  2. Erase one reject pack this fortnight — then put the date in the LOS. One deletion beats a 20-page policy.
  3. Pull one closed-account Aadhaar out of WhatsApp and UAT — if you cannot find it, that is the gap, not the missing certificate.

Book a 30-minute DPDPA discovery call →

Sources

  1. Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), MeitY — Sections 2, 5–10, 33 and the Schedule: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
  2. Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), MeitY — Rules 6, 7, 9, 13: https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
  3. DPDP Act commencement, G.S.R. 843(E), 13 November 2025, MeitY: https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf
  4. Reserve Bank of India — Master Direction: Know Your Customer (KYC) Direction, 2016, Chapter VII paragraph 46: https://www.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=10292
  5. Press Information Bureau — Digital Personal Data Protection (DPDP) Rules, 2025: https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190014
  6. CERT-In — Directions under section 70B(6) of the IT Act, 2000, No. 20(3)/2022-CERT-In, 28 April 2022: https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04.2022.pdf

This article is operational commentary for NBFC compliance officers, not legal advice and not a determination that any named NBFC’s retention programme is lawful. Confirm positions with qualified Indian counsel. RBI, PMLA, and other laws in force continue in parallel with the DPDPA. Cite the current Master Direction paragraph in the Board pack.

FAQ

Does Section 8(7) let an NBFC delete KYC as soon as a loan is closed?

No. Section 8(7) of the Digital Personal Data Protection Act, 2023 requires erasure once the specified purpose is served, subject to any law for the time being in force. For a live or closed borrower relationship, the RBI KYC Master Direction’s five-year keep after the relationship ends is that kind of law. It is not a licence to keep every extra copy forever.

Does RBI’s five-year KYC keep apply to rejected applicants?

Usually no. Paragraph 46(b) of the KYC Direction preserves identification records obtained while opening the account and during the business relationship, for at least five years after that relationship ended. A reject who never became a customer typically never opened that relationship. Do not freeze the full pack because a vendor slide said ‘KYC is five years.‘

Does DPDPA keep the old SPDI sensitive personal data category for KYC files?

No. The DPDPA does not revive the old SPDI sensitive personal data category. Aadhaar, PAN, and bureau files are personal data under Section 2(t). Retention is purpose plus law in force, not a heavier KYC tier.

Does DPDPA software discharge NBFC KYC data retention duties?

No. Software is not the RBI keep and not the Section 8(7) erasure. You still write the record-class map, name the legal keep, delete surplus copies, and keep Section 8(2) processor contracts. Rule 13 annual DPIA and audit remain Significant Data Fiduciary only, after Section 10 notification.