The law says keep.The Act asks: keep what, exactly?
A legal hold is a precise instrument. Most banks use it as a blanket.
In one line: Where the law requires retention, such as KYC and transaction records under PMLA, the bank may retain those records for the required period. Data not covered by a legal requirement should be erased once its purpose is served.
‘Required by law’ is a reason for one file. It is not a reason for the building.
The scene
The retention schedule had one line for customer data: ‘ten years, regulatory’. It covered KYC, which the law names. It also covered marketing preferences, chatbot transcripts, app telemetry and an old rewards programme. None of those were named anywhere.
Where the thinking breaks
Building the split register
Two columns: records held because a law says so, with the citation and period; and records held because nobody deleted them. The second column is where DPDPA exposure lives.
Monday morning
- 01Ask for the retention schedule. Count lines that say ‘regulatory’ without a citation.
- 02Add the citation or move the line.
- 03Set the first erasure run for data in the second column.
Questions, answered plainly
Can banks refuse a DPDPA erasure request because of PMLA?
Where the law requires retention, such as KYC and transaction records under PMLA, the bank may retain those records for the required period. Data not covered by a legal requirement should be erased once its purpose is served.
How long must banks keep KYC records?
Under the PMLA framework, records are generally kept for five years after the business relationship ends or the transaction, subject to the specific rule. Banks should confirm the period applicable to each record type.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner