“Are we even allowed to verify visitors with Aadhaar?” is one of the first questions enterprises ask. The short answer: yes — when it's done with consent and within UIDAI's framework, and when you don't hoard the data. Here's what that means in practice.
The short answer
Verifying a person's identity against Aadhaar is permissible when it's consent-based and uses an approved method. For private workplaces the cleanest routes are offline verification (OVSE) — where the resident shares a UIDAI-signed artefact — or online authentication through a licensed AUA/KUA. In neither case do you need to store the Aadhaar number.
Online vs offline, in legal terms
Online authentication runs through a UIDAI-licensed AUA/KUA (often via a Sub-AUA arrangement). Offline verification under OVSE lets you validate a UIDAI-signed secure QR or Paperless Offline e-KYC the resident chooses to share — no live UIDAI call. Both are legitimate; offline is often the simpler footing for visitor entry.
What the DPDP Act expects
- Notice & consent — tell the visitor what you collect and why, and get consent.
- Purpose limitation — use it only to admit and account for the visit.
- Minimisation — never store the full Aadhaar number; keep only what you need.
- Retention — delete records when you no longer have a reason to hold them.
- Security — encrypt and restrict access to visitor data.
See the DPDP Act and visitor data for the front-desk detail.
How Certopact is designed for this
Aadhaar visitor verification in Certopact is consent-first and purpose-limited, supports OVSE and AUA/KUA, and never stores the Aadhaar number. This article is general information, not legal advice — confirm your obligations with your own counsel.