Urgent.News

What's breaking now, across thousands of outlets.

Tech

DPDP Act Compliance for Fintech KYC: What Changes, and What Your Stack Needs to Handle It

India's DPDP Act doesn't replace RBI's KYC Master Directions it runs alongside them, with a different legal basis, different retention logic, and its own penalties. Here's what that means for a fintech's KYC stack, mapped to the controls that actually satisfy it. Most fintechs operating in India built their KYC stack around one rulebook: RBI's KYC Master Directions collect documents, verify…

The DPDP Act doesn't replace RBI's KYC Master Directions but operates alongside them, introducing a different legal basis, retention logic, and penalties. For fintechs, the Act primarily impacts retention policies, consent processes, user rights, and vendor contracts. Most KYC systems were designed with RBI's rules in mind, storing all data indefinitely, whereas DPDP mandates deletion once the legal purpose for holding data has concluded.

A significant hurdle for most KYC stacks is the retention logic, which must now be technically enforced rather than left to policy documents. To achieve DPDP compliance, fintechs should implement granular, revocable consent per purpose, selective data minimization via zero-knowledge proofs, and automated deletion workflows triggered by defined events.

Additionally, signed, auditable contracts with verification vendors are essential to ensure adherence to DPDP requirements.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Thursday 17 September →