One of the most common — and most misunderstood — questions in Indian identity is whether a private company can ask for your Aadhaar. The honest answer is: it depends on how, why and with what consent. This is a plain-English explainer of the landscape, not legal advice.
Why it is nuanced
Aadhaar use is governed by the Aadhaar Act and its amendments, UIDAI regulations, and now the DPDP Act — and the rules have evolved over time, including around what private entities may do. Because the framework is detailed and has changed, blanket statements like “anyone can ask” or “no one can ask” are both wrong.
The safer footings for private use
- Offline verification (OVSE) — the resident chooses to share a UIDAI-signed artefact (secure QR or Paperless Offline e-KYC), with no live UIDAI call.
- Online authentication through a licensed AUA/KUA, often via a Sub-AUA arrangement — see Sub-AUA explained.
- In both, consent is essential, and the full Aadhaar number need not be stored — see Aadhaar masking.
Principles that always apply
- Consent — the individual must agree, with a clear notice.
- Purpose limitation — use it only for the stated purpose.
- Minimisation — do not collect or store more than you need.
- A person can generally decline and be offered an alternative.
Bottom line
Verifying identity against Aadhaar can be legitimate for private organisations when it is consent-based and uses an approved method — for a fuller treatment see is Aadhaar-based visitor verification legal? This article is general information, not legal advice — the Aadhaar Act, UIDAI rules and the DPDP Act set the boundaries, so confirm your specific situation with your own counsel.