Is It Legal for a Business to Store Customer Aadhaar Numbers in India?
Aadhaar numbers carry stricter handling rules than ordinary personal data under Indian law — here's what businesses actually need to know before collecting or storing one.


💡 In Simple Terms (For Beginners)
Aadhaar numbers are treated more strictly than a normal ID under Indian law. Most private businesses can't require Aadhaar as mandatory ID, and storing it insecurely — like keeping a plain-text copy — creates real legal exposure.
- Private businesses generally cannot mandate Aadhaar as a condition of service — it must be voluntary, with a valid alternative offered.
- The Aadhaar Act restricts sharing and storing Aadhaar numbers and core biometric data more strictly than ordinary personal data.
- Masked or tokenised Aadhaar references, not the raw number, are the safer practice for any business that still needs to reference it.
COMPLIANCE · September 16, 2026 · 7 min read · By Hardik Patel
Is it legal for a business to store customer Aadhaar numbers in India? Private businesses generally cannot make Aadhaar mandatory for service, and any storage of Aadhaar numbers that does happen carries stricter handling obligations under the Aadhaar Act than ordinary personal data does under the DPDP Act.
Why Aadhaar Is Treated Differently
Aadhaar numbers and the biometric data behind them are treated as a distinct, more sensitive category than ordinary personal data because a leaked Aadhaar number, combined with other details, can be used to attempt identity fraud against a national identity system almost every Indian resident is enrolled in.
This is why Aadhaar handling sits under its own dedicated law — the Aadhaar Act — with its own restrictions, layered on top of whatever general obligations the DPDP Act separately imposes on personal data handling more broadly.
What Private Businesses Can and Can't Do
Private businesses generally cannot require Aadhaar as a mandatory condition for providing goods or services — a valid alternative form of identification must be offered, and Aadhaar collection, where it happens at all, needs to be genuinely voluntary and consented to for a specific, stated purpose.
This is a meaningfully stricter standard than how most businesses treat other ID documents like a PAN card or driving licence, and it's a common compliance gap — many businesses still default to "Aadhaar required" in onboarding forms out of habit rather than a specific legal basis.
Safer Practices If You Still Need to Reference It
Where a business has a genuine, specific reason to reference an Aadhaar number, using a masked or tokenised version — showing only the last few digits, or a UIDAI-issued reference token instead of the number itself — meaningfully reduces exposure compared to storing the full number in plain text.
Full, unmasked Aadhaar numbers stored in a database, spreadsheet, or backup are a significant liability if that storage location is ever breached — treat it with at least the same access controls and encryption standard you'd apply to financial account details, not as routine contact information.
Key Takeaways
- Private businesses generally cannot mandate Aadhaar — a valid alternative must be offered.
- Aadhaar sits under its own dedicated law with stricter handling rules than general personal data.
- Masked or tokenised references are safer than storing the raw number.
- Treat stored Aadhaar data with the same rigour as financial account details, not routine contact info.
Frequently Asked Questions
Q: Can we ask customers for Aadhaar as ID during onboarding?
A: Only voluntarily, with a valid alternative offered — making it a mandatory condition of service is generally not permitted for private businesses under the Aadhaar framework.
Q: Does the DPDP Act cover Aadhaar data too?
A: Aadhaar numbers are personal data and fall under the DPDP Act's general obligations, but the Aadhaar Act layers additional, stricter-specific restrictions on top — both apply, not just one.
Q: What's the safest way to store an Aadhaar number if we must keep one on file?
A: Use a masked or tokenised reference rather than the full number where possible, and apply the same encryption and access-control rigour you'd use for financial account details.
How iTechFixr Can Help
Our DPDP compliance readiness assessments cover how sensitive identifiers like Aadhaar numbers are collected, stored, and secured — helping you close this specific, often-overlooked compliance gap.

Need Help With This?
Talk to Hardik directly about your organisation's cybersecurity needs — get a tailored response within 24 hours.


