DPDP for Finance Teams: KYC Data, Vendor Payments and Retention
Finance handles bank details, KYC documents and vendor payment data daily — much of it under retention rules from other laws too. Here's how DPDP fits in.
Finance data often has more than one legal master
Finance teams are used to retention and record-keeping rules from tax, corporate, and sector-specific regulation — and those obligations don't disappear under DPDP. Section 17 exemptions for legal compliance mean you can generally keep statutory financial records for as long as other law requires, even where a customer or vendor has asked for erasure elsewhere.
The practical task is separating what's held because a specific law requires it (invoices, tax records, audit trails) from what's held simply because deleting it was never prioritised. Only the former has a clean legal answer to 'why do we still have this.'
KYC and vendor onboarding data
PAN details, bank account numbers, identity documents and address proofs collected during vendor or customer onboarding are personal data (for individual vendors, proprietors, and signatories), and typically rely on legitimate use or consent depending on context. Make sure the notice given at onboarding actually describes what finance collects and why, rather than pointing to a generic company privacy policy that was written with a different audience in mind.
Where KYC verification is outsourced to a third-party verification service, that vendor needs a Section 8(2) contract before documents are shared with them, and the contract should specify what the vendor does with copies of identity documents after verification completes.
Payment processing and shared responsibility
Payment gateways, payroll processors and expense-management platforms all touch personal financial data as Data Processors acting on your instructions. Review these contracts for security safeguard commitments and breach-notification timelines that mirror your own obligations under Section 8(5) and 8(6) — a payment vendor's breach is still your data, and your Data Principals will expect to hear from you, not the vendor.
Where finance systems feed personal data into decision-affecting processes — credit checks, expense fraud flags, vendor risk scores — Section 8(3)'s accuracy requirement applies. If a vendor is flagged and blocked based on a data error, there should be a way to correct it.
Retention discipline for closed accounts
For former vendors and customers, set a retention schedule that separates statutory-minimum records (kept for the mandated period) from operational data (bank details, contact records) that should be erased once the relationship ends and no other legal basis for retention applies, consistent with Section 8(7).
Watch for KYC documents and bank details that persist in shared drives, email attachments or spreadsheet exports outside the core finance system — these copies are easy to forget and rarely covered by the same access controls as the system of record.
Where to go next
Use the Retention Planner to separate statutory retention periods from discretionary ones, and run payment and KYC vendors through the Vendor Assessment to confirm contracts are in place.