Confidential Dispatch

Is video KYC safe, and who holds the recording?

5 min readUpdated 2026-09-09
On this page
  1. 01Is video KYC actually recorded?
  2. 02Who holds the recording, and is it safe?
  3. 03How long is it kept, and when must it be deleted?
  4. 04How to protect yourself during the call
  5. 05What you can do about it
  6. 06FAQ
At a glance

Yes, video KYC is generally safe when it’s done through a Reserve Bank of India regulated bank or Non-Banking Financial Company (NBFC) on its own official app, because RBI’s rules for this process require encryption, geo-tagging and secure India-based storage. The recording and your live photograph are held by that bank or NBFC as your Data Fiduciary, kept for as long as your KYC records must legally be retained, and must be deleted once that requirement ends.

Educational resource only. This explains how video KYC recordings are handled under RBI’s KYC framework and India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal or regulatory advice.

The situation

You’re opening a bank account, a mutual fund folio, an insurance policy or a wallet, and instead of visiting a branch, you’re asked to join a short video call. An agent asks you to hold up your PAN and Aadhaar, take a photo, and answer a few questions, all on camera. It’s quick, but it’s natural to wonder where that recording ends up, who can see it, and how long it sits somewhere before it’s deleted.

Is video KYC actually recorded?

Yes, this is a legal requirement, not something the company chooses to do. RBI’s rules for the Video-based Customer Identification Process (V-CIP) require the Regulated Entity (RE), the bank, NBFC, fintech or insurer conducting the call, to record the audio-visual interaction and capture a photograph of you for identification. The recording must be geo-tagged with your live location and carry a date-time stamp, and the bank or NBFC has to maintain a log of which official conducted the call. Every bank, NBFC and regulated fintech in India relies on this same legal basis for video KYC, so a “no recording” video KYC call isn’t actually compliant with RBI’s own framework.

Who holds the recording, and is it safe?

The bank or NBFC you’re onboarding with holds it, as your Data Fiduciary, and RBI requires it to be secured. Under the DPDP Act, the bank or NBFC collecting your data through video KYC is a Data Fiduciary, meaning it decides why and how your personal data is processed and is accountable for it. RBI’s framework backs this up on the technical side: the recording must be stored in India-based, secure systems with end-to-end encryption, and the platform must undergo regular vulnerability testing. If the bank or NBFC outsources the video call itself to a KYC vendor, the vendor acts only as a processor following the bank or NBFC’s instructions, and the bank or NBFC remains the one accountable to you.

  • Reasonable: the call happens on the bank or NBFC’s own verified app or a link that clearly matches the company you applied to, and it can tell you, if asked, what happens to the recording afterwards.
  • A red flag: a generic “KYC agent” video call outside your bank or NBFC’s own app or portal, or no clear answer about storage when you ask.

How long is it kept, and when must it be deleted?

As long as your KYC records must legally be kept, and no longer. RBI’s KYC framework requires identity records, a category that includes your video KYC recording, to be preserved for at least five years after your relationship with that bank or NBFC ends. The DPDP Act’s Section 8 requires a Data Fiduciary to erase your personal data once the purpose it was collected for is served, but the Act also allows retention where another law specifically requires it, and RBI’s five-year rule is exactly that kind of requirement. In practice, that means the recording is expected to sit with the bank or NBFC for as long as your relationship with it lasts, plus five years after you close the account, and there’s no remaining legal basis for keeping it once that period lapses.

How to protect yourself during the call

A few checks before and during the call keep you from handing your recording to the wrong place.

  1. Confirm it’s the bank or NBFC’s own official app or a verified link, not a call redirected through a third-party page or a link sent over WhatsApp or SMS from an unfamiliar number.
  2. Check that the required prompts appear. RBI’s process expects location and liveness checks, such as a random action prompt; a call that skips these isn’t following the framework.
  3. Do the call somewhere private, on a network you trust, since the same PAN and Aadhaar details you’re reading aloud or showing on screen are visible to anyone nearby.
  4. Ask what happens to the recording if the notice you were given doesn’t already say.

What you can do about it

Ask the right questions up front, and follow up once the legal retention window has passed.

  • Ask for the privacy notice before or at the start of the call if one wasn’t already shared with you.
  • Request confirmation of deletion once you close the account and the five-year retention period that follows has run its course.
  • Escalate to the grievance officer named in the bank or NBFC’s notice, or to the Data Protection Board of India, if it refuses to explain its retention practice or keeps your recording longer than the law requires.

FAQ

Is video KYC as safe as visiting a branch in person?

It’s built to be, when done through the bank or NBFC’s own official app. The encryption, geo-tagging and logging requirements exist specifically because the interaction happens remotely rather than face to face.

Can I refuse video KYC and ask for another method instead?

Often, yes. Most banks and NBFCs offer more than one KYC method, so you can ask whether Aadhaar-based e-KYC or in-person verification is available if you’d rather not do a video call.

What happens to the recording if I don’t complete the KYC process?

It should still be treated as personal data collected for that attempt and handled under the same security and retention rules, even if your onboarding doesn’t go through.

Can the bank share my video KYC recording with anyone else?

Only for the purpose it was collected for, such as regulatory reporting or fraud checks, not as a general practice. Sharing it for an unrelated purpose would need its own basis under the DPDP Act.

Can I ask for my video KYC recording to be deleted immediately?

Not immediately. RBI requires your bank or NBFC to keep KYC records, including this recording, for five years after your relationship with it ends, so it can’t be deleted before that period is over. Once your account closes and those five years have passed, you can ask.

Reviewed by Confidential Dispatch Editorial Team
Last updated 9 September 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →