Confidential Dispatch

How to collect customer documents and KYC with valid consent

4 min readUpdated 2026-07-04
On this page
  1. 01Why documents raise the stakes
  2. 02Step by step: collect documents compliantly
  3. 03Minimise before you collect
  4. 04The part people get wrong: where the files live
  5. 05FAQ
At a glance

Collecting documents or KYC from customers under India’s DPDP Act follows the same recipe as any collection, with the stakes turned up: give a clear notice of why you need each document, take specific consent for that purpose, ask for the minimum (and accept masked versions where the full document isn’t legally required), receive and store them through a secure channel, set a retention limit, and keep a record of the consent. The riskiest part isn’t asking — it’s where the copies end up and how long they linger.

Educational resource only. This explains how to collect documents and KYC in line with India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice, and DPDP compliance is an organisation-wide obligation broader than any single intake step.

The situation

Onboarding a client, running KYC, verifying an address — plenty of legitimate work needs documents. The trouble starts with how they’re gathered: emailed attachments, WhatsApp images, an open upload folder — each leaving copies of Aadhaar, PAN and bank statements scattered where you’ve half lost track of them. Getting the intake right at the point of collection is what prevents that.

Why documents raise the stakes

A document is denser and more sensitive than a form field — so the same duties bite harder. A single Aadhaar or bank statement carries identity, financial, and sometimes address and photo data all at once. That means more harm if it leaks, more to secure, and more reason to hold as little as possible for as short a time as possible. The DPDP Act doesn’t create a separate “sensitive document” tier, but its ordinary duties — notice, consent, minimisation, security, deletion — apply with real force where documents are involved.

Step by step: collect documents compliantly

Set the notice and consent first, then choose a secure channel, then control retention.

  1. State the purpose in a notice (Section 5). Before asking for anything, tell the customer which documents you need and exactly why — “PAN for tax reporting,” not “documents for our records.”
  2. Take specific consent (Section 6) for that purpose — a clear, recorded yes, separate from unrelated permissions.
  3. Ask for the minimum. Only the documents the purpose genuinely requires, and only the pages or fields that matter.
  4. Use a secure channel to receive them — not open email or a public link. Encrypted transfer and access-controlled storage, not a shared inbox.
  5. Set retention and delete. Decide up front how long you’ll hold each document and delete when the purpose is over, unless a law requires you to keep it for a set period.
  6. Record the consent. Keep a demonstrable record of what was asked, what notice was shown, and what the customer agreed to — the burden of proving consent is yours.

Minimise before you collect

The safest document is the one you never collected — and the second safest is a masked one. Before requesting anything, ask whether you need the full document at all. Often you don’t: a masked Aadhaar (first eight digits hidden) is enough where the full number isn’t legally required, and you rarely need every page of a bank statement. Collecting less isn’t just tidier — every full document you hold is a bigger liability if you’re breached. Accepting masked or redacted versions, and deleting originals you don’t need, is minimisation in practice.

The part people get wrong: where the files live

Most document risk isn’t in the asking — it’s in the sprawl of copies afterwards. An emailed PAN lives in your inbox, your sent folder, the customer’s sent folder, and any backup — indefinitely. A WhatsApp image sits in the chat and the phone’s gallery. To stay on the right side of security and retention duties, control the copies: receive documents into one access-controlled location, avoid forwarding them around, don’t let them settle in inboxes and chat threads, and delete them on a schedule. If you can’t say where every copy of a customer’s Aadhaar is, that’s the gap to close first.

FAQ

Do I need consent to collect a customer’s documents?

Yes — with a clear notice of the specific purpose, and consent for it (unless a defined legitimate use or a legal obligation applies). You should also record that consent.

Can I ask for a masked Aadhaar instead of the full one?

Usually yes, and you generally should — a masked Aadhaar suffices where the full number isn’t legally required, and it reduces your exposure. Collect the minimum the purpose needs.

Is it OK to collect KYC documents over email or WhatsApp?

It’s weak on security and retention — copies scatter and linger. Prefer an encrypted, access-controlled channel, and don’t leave documents sitting in inboxes or chats.

How long can I keep customer documents?

Only as long as the stated purpose needs them, unless a law requires a set retention period. Set a limit and delete when done.

Reviewed by Confidential Dispatch Editorial Team
Last updated 4 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →