SEBI KRA–IFSCA KYC Sharing Circular 2026: Fintech and GIFT City Startup Compliance Checklist
KYC sharing can reduce onboarding friction, but only if consent, system controls and audit evidence are built correctly.
Direct answer
SEBI’s KRA–IFSCA KYC sharing update is a useful onboarding reform, but startups should treat it as a controlled data-sharing workflow, not a free data pipe.
The official SEBI circular dated 20 August 2026 on enabling sharing of information by KYC Registration Agencies with IFSCA-regulated entities should be read alongside the IFSCA official site, securities-market KYC rules and the Digital Personal Data Protection Act, 2023. A Best CS Firm In India interpretation is practical: faster KYC reuse works only when consent, API security, logs, vendor contracts and exception handling are documented.
What changed?
| Area | Founder interpretation | Action needed |
|---|---|---|
| KYC data sharing | KRA-held KYC information can be shared with IFSCA-regulated entities under SEBI’s framework | Map whether your workflow requests, transmits or consumes KYC data |
| IFSC onboarding | GIFT City and IFSC-facing platforms may see smoother customer onboarding | Update onboarding SOPs and customer disclosures |
| Data controls | KYC data remains sensitive personal/business information | Implement consent, access logs, encryption and retention controls |
| Vendor role | KYC/regtech vendors may process or route information | Refresh DPAs, audit rights and breach responsibilities |
Who should track this?
- Fintech and wealthtech platforms serving NRIs, FPIs, IFSC clients or global investors.
- Broker-tech, investment-tech and securities onboarding vendors.
- Regtech and KYC automation startups integrating with KRAs or regulated entities.
- GIFT City-facing fund, treasury, PMS, advisory or capital-market platforms.
- Compliance and product teams handling identity, address, PAN, passport or beneficial-ownership data.
Implementation checklist
| Control | What to verify | Evidence to keep |
|---|---|---|
| Consent | Customer authorisation for KYC sharing and purpose | Consent logs and customer disclosure version |
| Purpose limitation | Use data only for permitted onboarding/compliance workflows | Product flow and access-control matrix |
| API security | Encryption, authentication, rate limits and monitoring | Technical architecture and security test records |
| Audit logs | Who requested, accessed, shared or changed KYC data | System logs and retention policy |
| Vendor contracts | Processor obligations, breach notice and deletion terms | DPA, MSA, SLA and subprocessor list |
| Exception handling | Name mismatch, expired document, address conflict, duplicate records | Operations SOP and escalation tracker |
Compliance steps for founders
- Identify whether the startup is regulated, a vendor to a regulated entity, or only a technology provider.
- Map the exact KYC fields touched by the product.
- Update customer disclosures, consent language and privacy notice.
- Revisit DPDP, cybersecurity, retention and breach-response controls.
- Test API and operational exception workflows before launch.
- Keep board/product approval notes for any material onboarding change.
Mistakes to avoid
- Assuming KYC sharing means data can be reused for marketing or unrelated analytics.
- Not identifying whether the startup is a processor, fiduciary, intermediary or vendor.
- Skipping consent logs and relying on generic privacy policy language.
- Letting support teams download KYC documents without role-based access.
- Failing to update vendor DPAs after changing the onboarding flow.
Founder / Business Takeaway
KYC portability is useful, but regulated customers will ask how your system controls it. Build the KYC sharing workflow with consent, security, logs, vendor contracts and deletion rules from day one.
Suggested internal links
FAQ
What did SEBI issue on KRA and IFSCA KYC sharing?
SEBI issued an August 2026 circular enabling KYC Registration Agencies to share information with IFSCA-regulated entities, subject to the circular framework.
Free Weekly Newsletter
Subscribe to BSA startup funding alerts
- Every Sunday, all Indian startup funding alerts in one place
- Monthly funding report on the last day of the month
- Free, concise, founder-focused, and easy to unsubscribe
Get the complete Indian startup funding roundup in your inbox, covering deals, sectors, investor moves, and founder readiness notes from the week.
Built for founders, investors, CFOs, and advisors
No spam. Unsubscribe anytime.
Who should track this circular?
Fintech, wealthtech, broker-tech, KYC, regtech, IFSC-facing platforms and onboarding vendors should track it.
Does this remove data-protection work?
No. KYC sharing still needs consent, purpose limitation, security controls, logs, vendor contracts, retention rules and DPDP-aligned handling.
