What is the DPDP Act 2023?
The Digital Personal Data Protection Act 2023 (DPDP Act) is India's first comprehensive data protection legislation. Notified in August 2023 and progressively enforced from 2024, it governs how "data fiduciaries" — businesses that collect and process personal data — must handle the personal data of Indian citizens ("data principals").
For any company running a KYC flow — fintechs, NBFCs, logistics platforms, HR SaaS — the DPDP Act changes what you must do before, during, and after collecting a customer's identity data.
Bottom line: If your product verifies Indian users via Aadhaar, PAN, DigiLocker or any other identity data source, the DPDP Act applies to you and requires meaningful changes to how you capture and log consent.
The three things that change for KYC flows
1. Consent must be explicit and purposeful
Under the DPDP Act, you cannot bundle consent into your terms of service. Consent must be:
- Free — not a condition of service where another option is reasonably available
- Specific — for a clearly stated purpose, not a blanket "processing your data"
- Informed — the data principal must understand what data is collected and why
- Unambiguous — a pre-ticked checkbox does not count
In practice: your KYC consent screen must name the specific data being collected (e.g. "your Aadhaar number to confirm your identity for loan eligibility"), the entity collecting it, and how long it will be retained.
2. Data principals have withdrawal and access rights
After verifying, your customer can: request a summary of what data you hold and why, correct inaccurate data, and withdraw consent. Withdrawal must be as easy as granting it — you cannot require a support ticket when consent was granted with a single tap.
You must process withdrawal requests within 30 days. If you use a third-party verification vendor like Veriflow, ensure your vendor agreement specifies how data deletion requests flow through to the source.
3. Breach notification is mandatory
Any breach affecting personal data must be reported to the Data Protection Board and affected individuals "without delay." The Act does not define a specific hour window, but the Board has indicated 72 hours as a guideline consistent with global practice.
Your breach notification plan must cover: detection, internal escalation, Board notification, and communication to affected data principals. Update your incident response runbook now, not after a breach.
What a DPDP-compliant KYC consent screen looks like
A compliant consent screen must display: the name of your entity as data fiduciary, the categories of personal data collected, the purpose of collection, how long data will be retained, the data principal's right to withdraw consent, and a link to your grievance officer contact. The consent must be captured with a timestamp and stored in your audit log.
Veriflow note: Veriflow captures DPDP-compliant consent for all Aadhaar OTP and DigiLocker calls automatically. Consent timestamp, purpose text, IP address and session ID are logged and exportable for your DPO.
UIDAI and the DPDP Act
Aadhaar-based eKYC sits at the intersection of DPDP Act and the Aadhaar Act 2016. The Aadhaar Act already requires consent for authentication — the DPDP Act adds the obligation to log that consent and honour withdrawal. If you're using an AUA/KUA-licensed provider (required for Aadhaar OTP), confirm their consent logging meets DPDP standards. UIDAI's own guidelines were updated in 2024 to align with DPDP Act requirements.
Your DPDP KYC checklist
- Update consent screens to name the purpose, data categories, and retention period
- Remove pre-ticked consent checkboxes
- Implement a consent log with timestamp, purpose, and session ID
- Build a data principal request portal (access, correction, withdrawal)
- Update your vendor agreements to include data processor obligations
- Draft a breach notification runbook with 72-hour escalation path
- Appoint and publish your grievance officer contact