CKYC Download Consent Under DPDP: What Financial Institutions Need to Know

Table of Contents

CKYC download consent under DPDP showing customer consent, OTP verification, secure KYC data access and an auditable compliance trail.

CKYC has become increasingly digital and API-driven, making CKYC download consent an important compliance control for banks, NBFCs, fintechs and other Reporting Entities. In practice, CKYC download consent means a Reporting Entity must obtain explicit customer authorisation before downloading a CKYC record, give clear notice of the data being accessed, the purpose and the requesting entity, and validate the customer action through OTP-backed evidence that can be audited. RBI already requires explicit customer consent when the KYC Identifier is used to download KYC records from the Central KYC Records Registry (CKYCR).

The Digital Personal Data Protection (DPDP) framework adds a broader data-governance dimension around how personal data is processed, how notices are presented, how consent is managed, withdrawn and evidenced, and how customers can exercise their rights. It did not create the CKYC download-consent requirement, but it raises the importance of making that consent clear, traceable and auditable for institutions that need lawful access to customer KYC records and need to avoid regulatory and governance failures.

For compliance leaders, risk officers and teams inside regulated financial institutions, the practical question is therefore not simply whether an OTP was captured. It is whether the institution can demonstrate what the customer authorised, why the data was requested, when consent was given, which CKYC access that consent covered, and whether the process aligns with CKYCRR, RBI and DPDP expectations.

This article examines CKYC download-consent requirements, OTP validation, audit-trail design, withdrawal mechanisms and how to embed CKYC consent into a broader financial crime compliance framework. For broader context on the CKYC 2.0 transformation, see ZIGRAM’s CKYC 2.0: Real-Time KYC Verification in India.

Quick Answer: What Does CKYC Download Consent Require?

  • Explicit consent: Under the Reserve Bank of India (RBI)/CKYCR framework, the customer must provide explicit consent for applicable CKYC record downloads.

  • Download-specific control: Consent should be linked to the relevant CKYC download request rather than treated as a blanket authorisation.

  • Clear notice: Customers should understand what data is being accessed, why it is needed and which entity is requesting it.

  • OTP validation: For individual CKYC downloads, the updated CKYCRR mechanism uses OTP validation sent to the mobile number registered in the CKYC record.

  • Audit evidence: Institutions should link the consent event to the corresponding CKYC access/download and retain appropriate evidence.

How CKYCRR, RBI and DPDP Requirements Intersect

Three regulatory layers are relevant to CKYC consent requirements.

CKYCRR

The Central KYC Records Registry (CKYCR) is the central KYC registry and centralized repository managed by the Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI), a central registry linked to asset reconstruction oversight, and it reduces redundancy in KYC submissions across financial institutions. CERSAI issued a notification on September 29, 2023, on consent, and CKYCR’s download-consent framework requires Reporting Entities to obtain customer consent before downloading CKYC records. Its April 2024 notification specifically referenced the DPDP Act and RBI’s KYC framework in establishing this requirement. CKYC India

RBI

RBI’s KYC framework is explicit: when a customer provides a KYC Identifier, the Reporting Entity must obtain the customer’s explicit consent to download KYC records from CKYCR. The KYC Identifier can be used for account opening, KYC updation/periodic updation and identity verification in the circumstances specified by the framework.

DPDP and the Role of the Data Protection Officer

The DPDP framework provides the broader legal framework for processing digital personal data. The final DPDP Rules require notices to be understandable independently of other information, use clear and plain language, describe the personal data and purposes involved, and provide mechanisms for exercising rights and withdrawing consent where applicable. MeitY

The DPDP Rules have a staggered commencement schedule, with different provisions taking effect at different dates through May 2027. Institutions should therefore distinguish between requirements already applicable under the CKYC/RBI framework and those under the DPDP provisions, according to their respective commencement dates. MeitY

What the DPDP Framework Means for CKYC Consent

The DPDP framework makes consent management a broader governance issue rather than simply a transaction-level checkbox, placing CKYC compliance within the wider know your customer framework that supports centralised KYC processes across India’s financial ecosystem.

CKYC is mandatory for individuals engaging with financial institutions in India, and reporting timelines generally require institutions to complete the CKYC process within 7 days.

1. Clear and understandable notice

Customers should be able to understand what KYC data is being accessed and why. The DPDP Rules require the notice to be clear, plain and understandable independently of other information. MeitY

2. Specific purpose

The purpose for retrieving the CKYC record should be clearly communicated. For example, account opening, KYC updation or identity verification.

Institutions should not assume that every downstream use of KYC information has the same legal basis. Each processing activity should be mapped to its applicable regulatory and legal requirements.

3. Affirmative action

Where consent is the applicable basis, it should involve a clear affirmative action rather than silence, inactivity or pre-selected options.

4. Withdrawal

Where processing is based on consent, customers need an accessible mechanism to withdraw it. Withdrawal does not automatically override another applicable legal basis or mandatory retention requirement.

5. Evidence

Institutions should be able to demonstrate the notice provided, the consent obtained and the CKYC transaction to which that consent related.

CKYC OTP Consent: From Customer Action to Evidence

The updated CKYCRR mechanism for individual CKYC downloads uses an OTP-based consent mechanism. As part of the CKYC process, the operational flow can be understood as:

CKYC request → consent notice → customer authorisation → OTP validation → CKYC download → audit record

The OTP is sent to the mobile number registered in the customer’s CKYC record. Customers also receive SMS notifications for each CKYC record download as an added consent and data-access safeguard. The important distinction is that OTP validates the customer’s action; it does not, by itself, constitute the complete consent framework.

The customer should first receive sufficiently clear information about the data being accessed, the requesting entity and the purpose. OTP then provides an additional mechanism for validating and evidencing the customer’s affirmative action.

This distinction is important for institutions designing CKYC OTP consent journeys. A technically successful OTP transaction should not be treated as a substitute for an appropriately designed consent notice.

What Should a DPDP-Ready CKYC Consent Interface Include?

A practical CKYC customer consent interface should make the relevant information visible before the customer authorises the request.

Consent control

What the customer should see

Data accessed

Identity/KYC information being retrieved

Source

Central KYC Records Registry (CKYCR)

Requesting entity

Bank, NBFC or other Reporting Entity

Purpose

Clear reason for downloading the CKYC record

Action

Explicit affirmative authorisation

Verification

OTP validation where applicable

Consent version

Applicable version of the consent notice

Evidence

Consent linked to the specific CKYC request

Institutions should avoid pre-ticked boxes, vague “I agree” language, buried consent within lengthy terms and conditions, or combining CKYC access consent with unrelated marketing permissions.

The consent interface is therefore not merely a UX component. It forms part of the institution’s regulatory evidence chain.

For the role of customer-facing controls within a broader CKYC workflow, see ZIGRAM’s CKYC 2.0 Application-First Approach.

Managing the CKYC Consent Lifecycle

A defensible CKYC consent management process should be treated as a lifecycle:

Capture → Verify → Authorise → Access → Log → Withdraw → Retain

  • Capture: Record the consent notice/version, purpose, channel and timestamp, and retain the CKYC consent form obtained directly from the specific financial institution channel handling the request.

  • Verify: Validate the customer’s action, including OTP where applicable.

  • Authorise: Associate the consent with the relevant CKYC download request.

  • Access: Permit the download only after the required controls are satisfied, and it maps to the customer’s record in the CKYC database and CKYC registry.

  • Log: Record the consent and corresponding CKYC access/download event for customer KYC records.

  • Withdraw: Support withdrawal where processing is based on consent.

  • Retain: Preserve appropriate evidence according to applicable legal and regulatory requirements.

Withdrawal should not be interpreted as an automatic requirement to erase every related record. Other lawful bases or statutory retention obligations may continue to apply.

What Should a CKYC Consent Audit Trail Capture?

Consent evidence answers: What did the customer agree to?

Download logs answer: What did the institution do?

A linked audit trail helps answer the more important regulatory question:

Was the CKYC access connected to the appropriate customer authorisation?

An effective CKYC consent audit trail should capture:

  • Consent ID

  • Consent notice/version

  • Purpose of data access

  • Customer/reference ID

  • Timestamp

  • Communication channel

  • OTP verification status

  • CKYC request/download ID

  • Initiating user or system

  • Withdrawal event, where applicable

At scale, automated records allow institutions to reconstruct a consent and CKYC access event without relying on screenshots, emails or manual spreadsheets.

This also supports broader accountability around CKYC reliance. See ZIGRAM’s RBI CKYC Reliance Guidance.

DPDP penalty exposure

The DPDP Act provides for significant monetary penalties, including penalties of up to ₹250 crore for specified failures, such as failure to take reasonable security safeguards to prevent a personal data breach. Other breaches carry different maximum penalties. A CKYC consent issue should therefore not automatically be characterised as a ₹250 crore violation; the applicable penalty depends on the nature of the breach. India Code

Integrating CKYC Consent Into Financial Institutions' Financial Crime Compliance

CKYC does not operate in isolation. Retrieved KYC information can feed customer risk assessment, sanctions and PEP screening, transaction monitoring, fraud controls and ongoing KYC reviews.

Institutions therefore benefit from connecting identity data, consent records, risk decisions and audit evidence within a consistent financial crime architecture.

ZIGRAM’s Complete FRAML System brings KYC, screening, risk assessment, transaction monitoring and fraud controls together within an integrated financial crime framework. This can help institutions connect customer-risk workflows with the broader controls and evidence generated across the financial crime lifecycle.

The system should not be viewed as a substitute for an institution’s legal or regulatory obligations. Rather, an integrated architecture can help make consent and access evidence part of a wider, connected compliance environment.

CKYC Download Consent Compliance Checklist

  • Obtain explicit consent before applicable CKYC downloads.

  • Clearly identify the data accessed, purpose and requesting entity.

  • Use an affirmative consent mechanism.

  • Implement the applicable CKYCRR OTP validation mechanism.

  • Verify whether the customer can use the CKYC portal to access or directly download the CKYC e-Card through the Central KYC Registry Portal, when appropriate.

  • Link each consent event to the relevant CKYC download.

  • Maintain tamper-evident consent and access audit trails.

  • Provide an accessible withdrawal mechanism where consent is the applicable basis.

  • Align retention and deletion decisions with applicable legal and regulatory requirements.

For broader implementation controls, see ZIGRAM’s CKYC 2.0 Compliance Checklist.

Frequently Asked Questions About CKYC Download Consent

Is customer consent required to download customer KYC records?

Yes. RBI requires explicit customer consent when the KYC Identifier is used to download KYC records from CKYCR. The CKYC number is a unique 14-digit identifier used by financial institutions to access the customer’s CKYC record. CKYCRR’s download-consent framework operationalises this requirement. Reserve Bank of India

What is CKYC download consent?

CKYC download consent is the customer’s specific authorisation for a Reporting Entity to retrieve their CKYC record for an applicable purpose. It should be linked to the relevant CKYC access/download event and supported by appropriate evidence.

Does CKYC require OTP-based consent?

For individual CKYC downloads, the updated CKYCRR mechanism uses OTP validation. OTP validates the customer’s action, but it does not replace the broader requirements around clear notice, purpose and consent governance.

Can a customer withdraw CKYC consent?

Where consent is the applicable basis for processing, the customer can withdraw consent under the DPDP framework. Withdrawal affects future processing based on that consent but does not automatically override another lawful basis or mandatory retention requirement.

What should a CKYC consent audit trail contain?

A robust audit trail should connect the consent version, purpose, customer/reference ID, timestamp, channel, OTP status, CKYC request/download ID and any subsequent withdrawal event.

Conclusion: CKYC Consent Must Become a Governed Control

CKYC download consent should be treated as a governed, auditable control—not a one-time checkbox. RBI and CKYCRR establish the specific consent requirement for CKYC downloads, while the DPDP framework adds broader considerations around notice, purpose, consent management and data governance.

For financial institutions, the practical test is simple: can you demonstrate what the customer authorised, why it was authorised, when it occurred and how that authorisation was managed afterwards?

Connecting that evidence with wider KYC, AML and fraud controls can help institutions build a more accountable financial crime compliance environment.

Enhance Your AML Compliance Efforts

Empower your organization with ZIGRAM's integrated RegTech solutions

Financial Crime Prevention Image

Articles

Explore insightful articles on cutting-edge topics like regulations, technological advancements, and critical insights into AML and financial crime risks
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/08/Article-Banner-8-scaled.webp

CKYC Download Consent Under DPDP: What Financial...

9 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/08/Article-Banner-6-scaled.png

The Role of Perpetual KYC (pKYC) in...

11 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/08/False-Positives-AML-Fraud-scaled.webp

How to Reduce False Positives in AML...

9 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/08/Article-Banner-3-scaled.png

From KYC Onboarding to Ongoing Monitoring: A...

12 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/08/Article-Banner-3-scaled.webp

CKYC 2.0 API Integration for Loan Origination:...

10 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/08/Article-Banner-2-scaled.png

Real-Time Transaction Monitoring For Faster Fraud Detection

13 Min