Aadhaar authentication and eKYC sit under the Aadhaar Act and UIDAI regulations, with the DPDP Act layered on and localisation preserved.
In short
Aadhaar eKYC operates under the Aadhaar Act, 2016 and UIDAI regulations, which impose data-vault, storage and authentication controls the DPDP Act expressly preserves. Handle Aadhaar data with minimal collection, strong security and a clear purpose. Penalties reach ₹250 crore under the Act, on top of UIDAI penalties.
What changes for this niche, and the specific rule it turns on.
The Aadhaar Act and UIDAI regulations apply alongside the DPDP Act; Section 16(2) preserves the stricter UIDAI localisation and vault rules.
Store Aadhaar numbers in a UIDAI-compliant data vault with tokenization and reference keys, not in plain application tables.
Use Aadhaar only for the permitted authentication or eKYC purpose; do not retain the number where a token suffices.
Aadhaar data is a top breach target; encrypt, log and tightly restrict access.
Short, cite-able answers, mirrored in FAQPage schema.
Vault Aadhaar numbers and fix purpose limits first.
The readiness check flags vault, purpose and localisation gaps.
Take the readiness check →