Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Tsaaro got CERT-IN Empanelled | MeitY has published the DPDP Rules, 2023.
Back To Home
Data Minimisation

Introduction
Identity verification has become a routine part of using digital services in India. A person is required to submit all her IDs while opening a bank account, buying a financial product, accessing certain government services or completing a digital onboarding process. KYC plays an important role here. It helps regulated entities in establishing the identity of customers and meeting obligations related to money laundering and financial crime. The Reserve Bank of India (RBI) now allows various digital routes for customer identification, including Aadhaar-based verification, the Central KYC Records Registry (CKYCR), DigiLocker and Video-based Customer Identification Process (V-CIP).
However, digital KYC also creates a privacy question. Identity verification can involve names, addresses, dates of birth, photographs, PAN details, mobile numbers and, depending on the method used, biometric or video information. The fact that an organisation can collect this information does not always mean that it needs to keep all of it. The Digital Personal Data Protection Act, 2023 (DPDP Act) recognises both the need to process personal data for lawful purposes and the individual's interest in protecting personal data. The Act contains separate provisions on notice, consent and the obligations of Data Fiduciaries.
Therefore, the real question is not about the need for strong identity verification in India. The more relevant question is how identity can be verified by unnecessary collection, storage and sharing of personal information. This establishes greater relevance for privacy-preserving identity verification.
Why KYC and Privacy Need to Work Together
KYC and privacy are sometimes presented as competing interests. However, they do not have to be in reality. A bank may need to establish that ectioa customer is a real person and verify certain information before opening an account. The data protection law and rules in India clearly establish that it does not automatically mean that every piece of information available on an identity document needs to be copied, stored indefinitely or shared with another service provider.
The KYC framework of Reserve Bank of India (RBI) already provides more than one route for customer identification. Customers may use Aadhaar-based authentication or offline verification where permitted, submit officially valid documents, use digital KYC processes, use CKYCR records or complete V-CIP, depending on the circumstances and the applicable rules. It is very important because different verification methods expose different amounts and types of information. A process that simply confirms that an identity attribute is valid can involve less data than a process in which an organisation receives and stores a complete identity document. Therefore, privacy protection should not mean weakening KYC. It should mean choosing a method that meets the KYC requirement without creating unnecessary data collection.
Aadhaar and the Shift Towards User-Controlled Verification
Aadhaar has become an important part of India's digital identity infrastructure. However, its use for verification has also raised questions about privacy, consent and proportionality. The Supreme Court’s Aadhar judgement considered these issues in the context of the constitutional right to privacy and applied the doctrine of proportionality to measures involving Aadhaar.
One useful example of a privacy-conscious approach is Aadhaar Paperless Offline e-KYC. The Unique Identification Authority of India (UIDAI) describes it as a way for an Aadhaar holder to establish identity without requiring the service provider to collect or store the Aadhaar number. The offline XML is digitally signed, and the individual can choose the demographic information to be included. The mobile number and email address, where included, are provided in hashed form. This changes the way identity verification can work. In this way, the service provider will not simply ask for a copy of Aadhaar and keep it in its records. It provides an option that an individual can share a digitally signed verification file for the specific purpose of establishing identity.
The rules of Unique Identification Authority of India (UIDAI) also place conditions around consent and information provided to the Aadhaar holder. The holder must be informed about the information that will be shared and how it may be used, and consent is required for authentication or verification. This is an important distinction which establishes that verification does not always have to mean collecting everything.
CKYCR: Reducing Repeated Collection of KYC Data
The Central KYC Records Registry (CKYC) is another important part of the KYC system in India. CKYCR allows KYC records to be stored and retrieved digitally, which can reduce the need for customers to submit the same documents repeatedly to different regulated entities. KYC FAQs of the Reserve Bank of India (RBI) explain that a customer can provide a KYC Identifier and give consent to a regulated entity to download valid KYC information from CKYCR. The customer generally does not have to submit the same KYC records again in cases where the existing information is complete and meets current requirements. This has a clear privacy benefit, if it is implemented properly. Repeated collection creates more copies of the same personal information. More copies mean more places where the information can be accessed, stored, transferred or accidentally exposed.
CKYCR does not remove the need for KYC checks. It can instead reduce unnecessary duplication of those checks and records. This does not mean that the regulators do not have any authority. The regulated entities still have responsibilities under the KYC framework. They may need additional information where the existing record is incomplete, outdated or where further verification or enhanced due diligence is required. The principle is very simple that if reliable information already exists and can legally be retrieved, there must be a clear reason for the recollection of such information.
What Data Minimisation Means for Identity Verification
Data minimisation is usually referred to, based on its literal meaning, as the idea of collecting less data. However, it requires more careful understanding for identity verification. Data minimization means that personal data collected by an organization must be "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
An organisation should first identify what it actually needs to establish. Is it verifying a person's name or age or address? Whether the person is over a particular age? Whether the identity document is valid? Whether the person is the same individual shown in the document? These are basic questions which must be determined by an organisation before collecting data. The answer should determine the information that is requested. It means that if a service only needs to establish that a customer is above a particular age, retaining a full identity document may be unnecessary once the required verification has been completed. However, it also depends on the legal and regulatory requirements applicable to that service. Another example is that if a regulated entity can retrieve an existing KYC record through an authorised mechanism, repeatedly asking the customer to upload the same documents may not add much value.
The DPDP Act provides the broader legal framework for this approach by regulating the processing of digital personal data and placing obligations on Data Fiduciaries. Its framework includes requirements relating to notice, consent, security safeguards and the handling of personal data. The notified DPDP Rules, 2025 also provide a more detailed framework for implementation. The Rules were notified on 14 November 2025, with different provisions coming into force in phases. This phase-wise implementation is important at the time of assessing current compliance. Organisations should distinguish between provisions that are already in force and those scheduled to commence later. They should avoid treating the entire framework as if every obligation applies immediately.
Designing a More Privacy-Preserving KYC Process
A privacy-focused identity verification process does not require to be complicated. It can be designed with the help of a few practical questions:
Collect only what the KYC requirement actually needs: The organisations should identify the specific information they need and why they need it before asking for an identity document. They should collect only those information, which are essnetially required for KYC.
Use verification instead of copying wherever possible: The organisations should try to verify, if an authorised mechanism can confirm an identity attribute without handing over the underlying document or Aadhaar number. This approach can actually reduce unnecessary exposure of personal data and information.
Clear explanation: The organisations should provide clear explanations to the people. Customers should know what information is being collected, why it is needed and how it will be used. Consent should not be buried inside a long and difficult privacy notice.
Avoid creating unnecessary copies: The organisations should avoid creating unnecessary copies, if KYC information can be securely retrieved through CKYCR or another permitted digital mechanism. It would solve the problem of collecting the same document that may not be necessary.
Protect information that still has to be retained: It is necessary to clearly understand that data minimisation does not remove security obligations. Information that must be stored for legal or regulatory reasons still needs appropriate safeguards.
Build privacy into the process from the beginning: The question of privacy often comes after the deployment. The choice of identity-verification method, database design, access controls and retention period should be considered during the process of designing the KYC system. It must not become an issue after it has already been deployed.
These steps do not remove regulatory KYC requirements. They help organisations meet those requirements with a more careful approach to personal information.
The Role of V-CIP and Digital Identity Systems
The Video-based Customer Identification Process (V-CIP) shows another side of the issue. The Reserve Bank of India (RBI) permits V-CIP as a digital, consent-based method of customer identification. It involves a live interaction between the customer and an authorised official, along with prescribed checks and recording requirements.
V-CIP can make onboarding easier, specifically where a customer cannot or does not want to visit a branch. However, video-based verification also involves additional personal information and technical records. Therefore, a privacy-conscious implementation framework also needs to consider not only how the customer is verified, but also what happens to the video, photographs, metadata and other records generated during the process.
This is an important point for broader digital identity systems. A system can be convenient and secure for authentications. However, it may still create privacy risks if it collects more information than necessary or keeps that information for longer than needed. Privacy needs to be considered across the whole identity lifecycle, including collection, verification, storage, access, sharing and deletion.
Finding the Right Balance
India does not need to choose between effective KYC and privacy. The two can work together when identity systems are designed around the actual purpose of verification. A bank always needs to know its customer. A regulated entity still has to meet its obligations under the KYC framework. But these requirements do not automatically justify collecting every available piece of information or retaining every document indefinitely. India already has building blocks for a more careful approach, which include Aadhaar offline verification, CKYCR, consent-based V-CIP and the wider data protection framework.
The next step should focus on making better use of these existing models and frameworks. The goal should be simple and straightforward. It should verify the person, collect the information that is genuinely needed, protect what must be retained and avoid creating additional copies without a clear reason. It is a more practical way to think about privacy-preserving identity verification. It does not ask organisations to choose between compliance and privacy. It asks them to design KYC processes where both are considered from the start.
Conclusion
The whole digital economy system of India depends on trust. People need to prove their identity to access banking and other digital services, but they should not have to share more personal information than necessary. KYC will remain an important part of the financial system, and digital identity will continue to play a major role in making these checks faster and easier. The privacy question is about how these systems are designed and used.
Privacy-preserving identity verification offers a practical middle path. The existing tools and mechanisms, including Aadhaar offline e-KYC and CKYCR show that identity can sometimes be established without repeatedly collecting the same documents or unnecessarily exposing an Aadhaar number. The DPDP framework adds another layer by placing obligations around the processing of digital personal data. The real test will be in implementation. Organisations need to consider whether the information they collect at each stage of KYC is actually necessary or whether simply verifying a specific detail about the person would be sufficient. This small change in thinking and approach can make identity systems both easier to use and more respectful and concerned of personal privacy.
Want to Stay Ahead?
Want to build privacy-conscious identity and KYC processes? Connect with Tsaaro’s experts to strengthen your organisation's approach to data protection, digital identity and privacy-by-design.
Talk to a Privacy Expert
Get a free 1:1 session on AI compliance, DPDPA readiness, or incident response planning.
Related articles












