KYC Record Retention Period in India: RBI, PMLA, and DPDP Rules
KYC records are retained five years after the relationship ends under the RBI KYC Direction and PMLA Rules. The retention matrix and where DPDP erasure fits.
On This Page
Updated July 2026.
Banks, NBFCs, payment operators, and housing finance companies hold customer records that at least three frameworks govern at once: the RBI Master Direction on KYC, the Prevention of Money Laundering Act, and the DPDP Act 2023. The retention periods they impose are not identical, and the institution answers to all of them simultaneously.
The Short Answer: Five Years After the Relationship Ends
The RBI Master Direction on KYC, 2016, Chapter VII, Paragraph 46 sets the floor for regulated entities:
“(a) maintain all necessary records of transactions between the RE and the customer, both domestic and international, for at least five years from the date of transaction; (b) preserve the record pertaining to the identification of the customer and his address obtained while opening the account and during the course of business relationship, for at least five years after the business relationship has ended.” (Paragraph 46, RBI KYC Master Direction)
The PMLA (Maintenance of Records) Rules, 2005 carry the same five-year requirement for the records they govern. Two clocks, one floor: transaction records run five years from each transaction, identity records run five years from the end of the relationship.
The ten-year figure that circulates in compliance guidance is not the current statutory minimum for standard KYC. It traces to legacy provisions, to the Payment and Settlement Systems Act framework for certain payment operators, to litigation-driven retention under the Limitation Act for contested accounts, or to internal policies that chose the conservative number. Unless a specific instrument or an active dispute applies, five years is the floor.
The Retention Matrix by Regulator
| Data type | Governing instrument | Period | Clock starts |
|---|---|---|---|
| Customer identity records (PAN, Aadhaar, address proof, photographs) | RBI KYC Direction Para 46(b); PMLA Rules 2005 | Minimum 5 years | End of business relationship |
| Transaction records | RBI KYC Direction Para 46(a); PMLA Rules 2005 | Minimum 5 years | Date of each transaction |
| Broker books, records, and KYC | SEBI Stock Brokers Regulations (5 years under the 1992 Regulations; 8 years under the 2026 Regulations); PMLA framework | 5 to 8 years | Per the applicable regulation |
| Insurer KYC and transaction records | IRDAI AML/CFT Master Guidelines 2022 | 5 years | Transaction or end of relationship |
| Insurer claims investigation records | IRDAI Investigation Regulations 2020 | 3 years (claims below Rs 1 lakh); 5 years (Rs 1 to 10 lakh) | Per regulation |
| Pension subscriber KYC | PMLA framework as applied to PFRDA-regulated entities | 5 years | Post-exit |
| Board and general meeting minute books | Companies (Management and Administration) Rules 2014, Rule 25 | Permanent | n/a |
| Office copies of board notices and agendas | Secretarial Standards read with the Companies Act 2013 | 8 financial years | Per standard |
| App usage logs, marketing preferences, behavioural analytics | No sectoral retention mandate | No statutory minimum beyond the DPDP Rules’ one-year log requirement where it applies | n/a |
The line that matters runs between the first rows and the last one: data a law requires you to keep, and data that exists only because your systems collected it. The DPDP Act treats the two very differently.
Where the DPDP Act Fits
Section 8(7) of the DPDP Act requires a Data Fiduciary to erase personal data when consent is withdrawn or the specified purpose is no longer served, unless retention is necessary for compliance with any law in force. Section 12(3) gives the customer the right to request that erasure. The carve-out resolves the apparent conflict with the KYC mandates, on three conditions:
- Name the instrument. “RBI requirements” is not a legal basis. Paragraph 46 of the KYC Direction, or the applicable PMLA rule, is.
- Record the exact period. Five years from relationship end for identity records; five years from transaction date for transaction records.
- Confine the carve-out to the mandated fields. Everything else follows the standard erasure obligation, whatever else sits in the same customer file.
The RBI-DPDP retention conflict framework covers the resolution mechanism in depth; banks and NBFCs have sector-specific treatments.
The Three Retention Classes
| Class | What it holds | On an erasure request |
|---|---|---|
| Legally mandated | KYC identity records, transaction records, STRs, beneficial ownership documentation | Retain for the statutory period; refuse erasure in writing with the instrument named; register the denial |
| Operationally necessary | Loan agreements, guarantees, account statements under contract or audit need | Retain only while a specific law or live contract requires; erase otherwise |
| Ancillary | Marketing preferences, campaign history, analytics, browsing logs | Erase on request or when the purpose is served |
The audit risk lives at the boundary. Retain everything under a generic “regulatory requirements” label and the institution breaches the DPDP Act’s storage limitation for every ancillary field. Erase too aggressively and it breaches the PMLA. Only field-level classification satisfies both, which is why the classification, not the policy document, is the real control.
Two further DPDP Rules provisions shape the schedule. The Rules require retention of personal data, traffic data, and processing logs for one year for the security and investigation purposes they specify, which sets a floor for categories that previously had none. And Rule 8 with the Third Schedule imposes erasure timelines and a 48-hour pre-erasure notice on specified large classes only: e-commerce entities with 2 crore or more registered users, online gaming intermediaries, and social media intermediaries. A typical bank or NBFC sits outside those classes; its retention periods come from its specified purposes and the sectoral mandates above.
What Happens After Five Years
Expiry of the statutory period is a compliance event, not an automatic deletion. The legal basis under the KYC mandates ends, and the DPDP erasure obligation applies in full. The institution must then either erase proactively or respond to erasure requests, unless another live basis, pending litigation, a tax proceeding, an investigation, justifies continued retention with its own documented citation. An institution whose systems cannot tell which records crossed their expiry date cannot execute this step, which is why the retention schedule has to be enforced where the data lives, not in a policy binder.
Common Mistakes
Treating five years as a maximum. It is a minimum. Live disputes and investigations extend it, lawfully, under the same carve-out.
Retaining everything indefinitely. Ancillary data has no mandate behind it. Indefinite retention of marketing and analytics data breaches purpose and storage limitation the day enforcement begins.
One period for all data. Transaction records, identity records, and marketing data run on different clocks with different bases. A single “retain five years” policy is simultaneously too long and too short.
No denial register. Refusing erasure without a documented, instrument-specific record converts a lawful refusal into an undefendable one. The register is the artefact both the Board and an RBI inspection will ask for.
Where ConsentOS Fits
ConsentOS is built for the boundary this article describes. The Data Inventory portal holds the field-level map of what the institution stores and under which basis. When a customer requests erasure, the Legal Obligation Override flags the fields a statute requires the institution to keep and registers the denial with its named instrument and period, while consent records document the basis for everything else. The conflict-of-law register gives the compliance team one place where every retention-versus-erasure decision is documented for inspection.
Run the Gap Assessment to score your retention position against the DPDP Act and your sector’s mandates.
Know where you stand on DPDP compliance
Run the free Compliance Vault Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.
Enforcement milestones, rule notifications, and deadline analysis.
One email when it matters, no more.
Resources
Continue Reading
Related DPDP Act 2023 guidance from the ConsentOS knowledge base.
RBI-DPDP Retention Conflict: KYC Erasure Rules for Indian Fintechs
The RBI and PMLA mandate five-year KYC retention. The DPDP Act requires erasure on request. For Indian fintechs and NBFCs, these obligations are in direct conflict. This article explains the Legal Obligation Override framework that resolves both simultaneously.
9 min read
Industry GuidesDPDP Compliance for Banks: RBI KYC Retention vs Erasure Rights
RBI requires 5-year KYC retention. The DPDP Act grants erasure rights. Section 8(7) decides which wins. How banks resolve the conflict field by field.
10 min read
Industry GuidesNBFC DPDP Compliance: RBI KYC Retention and PMLA Overrides in India
How NBFCs reconcile DPDP Act 2023 with RBI KYC retention, PMLA record-keeping, CIBIL consent and FIU-IND reporting. Legal Obligation Override explained.
11 min read
Implementation GuidesBuild a Personal Data Inventory for DPDP Compliance (India 2026)
Step-by-step guide to auditing and documenting personal data flows for India's DPDP Act. The data inventory is the foundation of every DPDP compliance programme.
12 min read