HomeCirculars › RBI/2013-14/213

RBI Cracks Down on Excessive KYC Data Collection

Current · Source: Reserve Bank of India · RBI/2013-14/213 · issued 03 Sep 2013 · ~2 min read
Quick answerRBI has warned banks against collecting intrusive personal details like family info, assets, and lifestyle data for KYC. Only mandatory information relevant to risk assessment should be sought; optional data requires customer consent post-account opening.
The rule, in the simplest words
How it plays out — a real example

A KYC & compliance officer in Indore is updating a customer's KYC form. She removes questions about the customer's spouse's name and number of children because those are not needed to assess risk for a gold loan. Later, if she wants to offer a credit card, she asks the customer separately and gets a signed consent before collecting optional details like monthly expenses.

What changed

RBI observed banks overstepping by asking for non-mandatory personal details (e.g., number of dependents, spouse details, assets) during KYC. It reiterates that only risk-relevant mandatory info should be collected; optional info needs explicit consent after account opening. Confidentiality of all customer data is stressed, prohibiting use for cross-selling.

What it means for you

Banks must immediately review KYC forms to remove intrusive questions not tied to risk assessment. This reduces customer friction and privacy complaints but may limit data for profiling. Lenders must clearly distinguish mandatory vs. optional fields and obtain separate consent for optional data, impacting CRM and cross-sell strategies.

What you must do

Who it affects

All scheduled commercial banks (excluding RRBs), Local Area Banks, All India Financial Institutions, Compliance and KYC teams, Branch staff handling account opening

❓ Common questions

What specific information is now considered intrusive for KYC?

RBI flagged details like number of dependents, names of children, lifestyle, foreign visits in last 3 years, family members abroad, assets/liabilities, spouse name/date of birth, wedding date, and investments as non-mandatory and intrusive.

Can we still collect optional customer information for cross-selling?

Yes, but only after account opening and with explicit customer consent. The customer must know which data is mandatory for KYC and which is optional. Such data cannot be used for cross-selling without separate consent.

What should we do with existing customer data collected earlier?

Ensure all customer data is treated as confidential. For non-mandatory data collected without explicit consent, seek fresh consent or stop using it for cross-selling. Review periodic updation processes to align with this circular.

📜 Read the original circular — full text as issued by RBI
RBI/2013-14/213 DBOD. AML.BC. No. 50/14.01.001/2013-14 September 3, 2013 The Chairmen / CEOs of all Scheduled Commercial Banks (Excluding RRBs)/ Local Area Banks / All India Financial Institutions Dear Sir, Know Your Customer (KYC) Norms / Anti-Money Laundering (AML) Standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under PMLA, 2002 – Information sought by banks from customers Please refer to the Master Circular DBOD.AML.BC. No. 24/14.01.001/2013-14 dated July 01, 2013 on Know Your Customer (KYC) Norms / Anti-Money Laundering (AML) Standards/Combating of Financing of Terrorism (CFT)/Obligation of banks under PMLA, 2002. The objective of these guidelines is to prevent banks from being used, intentionally or unintentionally, by criminal elements for money laundering or terrorist financing activities. The KYC procedures also enable banks to know/understand their customers and their financial dealings better which in turn help them manage their risks prudently. However, it has come to the notice of Reserve Bank that banks are seeking personal information/details like number of dependents, the names of sons and daughters, lifestyle, number of foreign visits undertaken during the last three years, details of family members/relatives settled abroad, assets and liabilities, name and date of birth of spouse, wedding date, investments, etc,. from customers which are not mandatory and relevant to perceive risk of a prospective customer while complying with KYC/AML requirement during the process of opening an account or during periodic updation. This has led to customer complaints that banks are going overboard in seeking information for KYC compliance and thereby invading into their privacy. 2. In this connection, attention of banks is drawn to paragraph 2.1 of the Master Circular that information sought from customer is relevant to the perceived risk, is not intrusive, and is in conformity with the guidelines issued in this regard. Any other information from the customer should be sought separately with his/her consent and after opening the account. 3. It is, therefore, reiterated that ‘mandatory’ information required for KYC purpose which the customer is obliged to give while opening an account only should be obtained at the time of opening the account/during periodic updation. 4. Other ‘optional’ customer details/additional information, if required may be obtained separately after the account is opened only with the explicit consent of the customer. The customer has a right know what is the information required for KYC that she/he is obliged to give, and what is the additional information sought by the bank that is optional. 5. Further, it is reiterated that banks should keep in mind that the information (both ‘mandatory’ – before opening the account as well as ‘optional’- after opening the account with the explicit consent of the customer) collected from the customer is to be treated as confidential and details thereof are not to be divulged for cross selling or any other like purposes. 6. Banks are advised to ensure strict adherence to the same. Yours faithfully, (Prakash Chandra Sahoo) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2013-14/213 · issued 03 Sep 2013. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Who does what — compliance checklist
🏦 Branch Manager
  • Separate mandatory KYC fields from optional ones; obtain explicit customer consent for optional data after account opening.
📜 Compliance
  • Audit current KYC forms and processes to remove non-mandatory personal questions (e.g., family details, assets, lifestyle).
  • Train frontline staff on permissible KYC data collection and confidentiality rules to avoid privacy violations.
  • Update internal policies to ensure customer data is not used for cross-selling without separate consent.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All scheduled commercial banks (excluding RRBs), Local Area Banks, All India Financial Institutions, Compliance and KYC teams, Branch staff handling account opening), your first concrete step on “RBI Cracks Down on Excessive KYC Data Collection” is: “Audit current KYC forms and processes to remove non-mandatory personal questions (e.g., family details, assets, lifestyle).” (RBI issued this 03 Sep 2013).

  1. Circular: RBI/2013-14/213 -- RBI Cracks Down on Excessive KYC Data Collection
  2. Issued: 03 Sep 2013
  3. Action required: Audit current KYC forms and processes to remove non-mandatory personal questions (e.g., family details, assets, lifestyle).
  4. Action required: Separate mandatory KYC fields from optional ones; obtain explicit customer consent for optional data after account opening.
  5. Action required: Train frontline staff on permissible KYC data collection and confidentiality rules to avoid privacy violations.
  6. Action required: Update internal policies to ensure customer data is not used for cross-selling without separate consent.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=8362&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗