KYC Retention vs DPDPA Erasure: What Banks Must Keep and What They Must Let Go
KYC Retention vs DPDPA Erasure: What Banks Must Keep and What They Must Let Go
‘Required by law’ is a reason for one file. It is not a reason for the building.
The scene
The retention schedule had one line for customer data: ‘ten years, regulatory’. It covered KYC, which the law names. It also covered marketing preferences, chatbot transcripts, app telemetry and an old rewards programme. None of those were named anywhere.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Everything is regulatory data in a bank.
Only records a statute or regulator specifies are covered by the legal-hold exception in Section 8(7).
List the records each law names, and the period it names.
Deletion is risky, so we archive.
An archive is still retention; the obligation is erasure when purpose ends.
Archive only what is held by law. Erase the rest on a schedule.
Building the split register
Two columns: records held because a law says so, with the citation and period; and records held because nobody deleted them. The second column is where DPDPA exposure lives.
Monday morning
01 Ask for the retention schedule. Count lines that say ‘regulatory’ without a citation.
02 Add the citation or move the line.
03 Set the first erasure run for data in the second column.
Questions, answered plainly
Can banks refuse a DPDPA erasure request because of PMLA? +
Where the law requires retention, such as KYC and transaction records under PMLA, the bank may retain those records for the required period. Data not covered by a legal requirement should be erased once its purpose is served.
How long must banks keep KYC records? +
Under the PMLA framework, records are generally kept for five years after the business relationship ends or the transaction, subject to the specific rule. Banks should confirm the period applicable to each record type.
Sector · Banking & BFSI Banks keep everything. The law now asks why. Read →
Banking & BFSI · Deep dive One incident. Three clocks start at once. Read →
Banking & BFSI · Deep dive Your DSA's phone is inside your perimeter. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).