Readiness assessment
Fintech & Banking · KYC · Aadhaar eKYC

The DPDP Act for Aadhaar eKYC & UIDAI

Aadhaar authentication and eKYC sit under the Aadhaar Act and UIDAI regulations, with the DPDP Act layered on and localisation preserved.

In short

Aadhaar eKYC operates under the Aadhaar Act, 2016 and UIDAI regulations, which impose data-vault, storage and authentication controls the DPDP Act expressly preserves. Handle Aadhaar data with minimal collection, strong security and a clear purpose. Penalties reach ₹250 crore under the Act, on top of UIDAI penalties.

Core impacts

What changes for this niche, and the specific rule it turns on.

UIDAI wins where stricter

The Aadhaar Act and UIDAI regulations apply alongside the DPDP Act; Section 16(2) preserves the stricter UIDAI localisation and vault rules.

Aadhaar data vault

Store Aadhaar numbers in a UIDAI-compliant data vault with tokenization and reference keys, not in plain application tables.

Purpose and minimization

Use Aadhaar only for the permitted authentication or eKYC purpose; do not retain the number where a token suffices.

Security and access

Aadhaar data is a top breach target; encrypt, log and tightly restrict access.

Common questions

Short, cite-able answers, mirrored in FAQPage schema.

Does the DPDP Act replace the Aadhaar Act for eKYC?
No. The Aadhaar Act and UIDAI regulations continue to apply; the DPDP Act adds to them and preserves the stricter UIDAI rules.
Can Aadhaar numbers be stored freely?
No. UIDAI requires a compliant data vault with tokenization; store the reference key, not plain Aadhaar numbers, and only where permitted.
Do UIDAI localisation rules still apply under DPDP?
Yes. Section 16(2) preserves stricter sectoral law, so UIDAI storage and localisation controls continue to bind.

Check your Aadhaar handling.

The readiness check flags vault, purpose and localisation gaps.

Take the readiness check