Skip to main content
Industry Guides

KYC Record Retention Period in India: RBI, PMLA, and DPDP Rules

KYC records are retained five years after the relationship ends under the RBI KYC Direction and PMLA Rules. The retention matrix and where DPDP erasure fits.

10 min read
On This Page

Updated July 2026.

Banks, NBFCs, payment operators, and housing finance companies hold customer records that at least three frameworks govern at once: the RBI Master Direction on KYC, the Prevention of Money Laundering Act, and the DPDP Act 2023. The retention periods they impose are not identical, and the institution answers to all of them simultaneously.

The Short Answer: Five Years After the Relationship Ends

The RBI Master Direction on KYC, 2016, Chapter VII, Paragraph 46 sets the floor for regulated entities:

“(a) maintain all necessary records of transactions between the RE and the customer, both domestic and international, for at least five years from the date of transaction; (b) preserve the record pertaining to the identification of the customer and his address obtained while opening the account and during the course of business relationship, for at least five years after the business relationship has ended.” (Paragraph 46, RBI KYC Master Direction)

The PMLA (Maintenance of Records) Rules, 2005 carry the same five-year requirement for the records they govern. Two clocks, one floor: transaction records run five years from each transaction, identity records run five years from the end of the relationship.

The ten-year figure that circulates in compliance guidance is not the current statutory minimum for standard KYC. It traces to legacy provisions, to the Payment and Settlement Systems Act framework for certain payment operators, to litigation-driven retention under the Limitation Act for contested accounts, or to internal policies that chose the conservative number. Unless a specific instrument or an active dispute applies, five years is the floor.

The Retention Matrix by Regulator

Data typeGoverning instrumentPeriodClock starts
Customer identity records (PAN, Aadhaar, address proof, photographs)RBI KYC Direction Para 46(b); PMLA Rules 2005Minimum 5 yearsEnd of business relationship
Transaction recordsRBI KYC Direction Para 46(a); PMLA Rules 2005Minimum 5 yearsDate of each transaction
Broker books, records, and KYCSEBI Stock Brokers Regulations (5 years under the 1992 Regulations; 8 years under the 2026 Regulations); PMLA framework5 to 8 yearsPer the applicable regulation
Insurer KYC and transaction recordsIRDAI AML/CFT Master Guidelines 20225 yearsTransaction or end of relationship
Insurer claims investigation recordsIRDAI Investigation Regulations 20203 years (claims below Rs 1 lakh); 5 years (Rs 1 to 10 lakh)Per regulation
Pension subscriber KYCPMLA framework as applied to PFRDA-regulated entities5 yearsPost-exit
Board and general meeting minute booksCompanies (Management and Administration) Rules 2014, Rule 25Permanentn/a
Office copies of board notices and agendasSecretarial Standards read with the Companies Act 20138 financial yearsPer standard
App usage logs, marketing preferences, behavioural analyticsNo sectoral retention mandateNo statutory minimum beyond the DPDP Rules’ one-year log requirement where it appliesn/a

The line that matters runs between the first rows and the last one: data a law requires you to keep, and data that exists only because your systems collected it. The DPDP Act treats the two very differently.

Where the DPDP Act Fits

Section 8(7) of the DPDP Act requires a Data Fiduciary to erase personal data when consent is withdrawn or the specified purpose is no longer served, unless retention is necessary for compliance with any law in force. Section 12(3) gives the customer the right to request that erasure. The carve-out resolves the apparent conflict with the KYC mandates, on three conditions:

  1. Name the instrument. “RBI requirements” is not a legal basis. Paragraph 46 of the KYC Direction, or the applicable PMLA rule, is.
  2. Record the exact period. Five years from relationship end for identity records; five years from transaction date for transaction records.
  3. Confine the carve-out to the mandated fields. Everything else follows the standard erasure obligation, whatever else sits in the same customer file.

The RBI-DPDP retention conflict framework covers the resolution mechanism in depth; banks and NBFCs have sector-specific treatments.

The Three Retention Classes

ClassWhat it holdsOn an erasure request
Legally mandatedKYC identity records, transaction records, STRs, beneficial ownership documentationRetain for the statutory period; refuse erasure in writing with the instrument named; register the denial
Operationally necessaryLoan agreements, guarantees, account statements under contract or audit needRetain only while a specific law or live contract requires; erase otherwise
AncillaryMarketing preferences, campaign history, analytics, browsing logsErase on request or when the purpose is served

The audit risk lives at the boundary. Retain everything under a generic “regulatory requirements” label and the institution breaches the DPDP Act’s storage limitation for every ancillary field. Erase too aggressively and it breaches the PMLA. Only field-level classification satisfies both, which is why the classification, not the policy document, is the real control.

Two further DPDP Rules provisions shape the schedule. The Rules require retention of personal data, traffic data, and processing logs for one year for the security and investigation purposes they specify, which sets a floor for categories that previously had none. And Rule 8 with the Third Schedule imposes erasure timelines and a 48-hour pre-erasure notice on specified large classes only: e-commerce entities with 2 crore or more registered users, online gaming intermediaries, and social media intermediaries. A typical bank or NBFC sits outside those classes; its retention periods come from its specified purposes and the sectoral mandates above.

What Happens After Five Years

Expiry of the statutory period is a compliance event, not an automatic deletion. The legal basis under the KYC mandates ends, and the DPDP erasure obligation applies in full. The institution must then either erase proactively or respond to erasure requests, unless another live basis, pending litigation, a tax proceeding, an investigation, justifies continued retention with its own documented citation. An institution whose systems cannot tell which records crossed their expiry date cannot execute this step, which is why the retention schedule has to be enforced where the data lives, not in a policy binder.

Common Mistakes

Treating five years as a maximum. It is a minimum. Live disputes and investigations extend it, lawfully, under the same carve-out.

Retaining everything indefinitely. Ancillary data has no mandate behind it. Indefinite retention of marketing and analytics data breaches purpose and storage limitation the day enforcement begins.

One period for all data. Transaction records, identity records, and marketing data run on different clocks with different bases. A single “retain five years” policy is simultaneously too long and too short.

No denial register. Refusing erasure without a documented, instrument-specific record converts a lawful refusal into an undefendable one. The register is the artefact both the Board and an RBI inspection will ask for.

Where ConsentOS Fits

ConsentOS is built for the boundary this article describes. The Data Inventory portal holds the field-level map of what the institution stores and under which basis. When a customer requests erasure, the Legal Obligation Override flags the fields a statute requires the institution to keep and registers the denial with its named instrument and period, while consent records document the basis for everything else. The conflict-of-law register gives the compliance team one place where every retention-versus-erasure decision is documented for inspection.

Run the Gap Assessment to score your retention position against the DPDP Act and your sector’s mandates.

Know where you stand on DPDP compliance

Run the free Compliance Vault Assessment for a gap report scored against your DPDP Act 2023 obligations, work through the 26-point compliance checklist, or model your penalty exposure.

Enforcement milestones, rule notifications, and deadline analysis.

One email when it matters, no more.