Still taking Aadhaar photocopies at check-in?
Most Indian hotels still photocopy or photograph a guest’s Aadhaar at the front desk — often onto a staff member’s personal phone. That practice is already on shaky ground under the Aadhaar Act, and UIDAI has signalled it intends to close the gap further: moving toward mandatory registration before any private entity can verify Aadhaar, and away from photocopy collection altogether.
Check your exposure — freeWhat’s actually changing
Section 8A of the Aadhaar Act allows private entities to use Aadhaar for identity verification only under specific, UIDAI-notified conditions. Hotels collecting and retaining Aadhaar photocopies as a matter of routine have generally not been operating within a clearly notified basis for this — a gap that has existed for years and is now getting more attention, not less.
UIDAI’s direction of travel is toward an Offline Verification / Registered-entity model: requiring organisations to register before they can verify Aadhaar at all, using QR-code or offline methods that confirm identity without a copy ever being retained. Once notified for hospitality, photocopy-and-file will stop being an option, not just a bad habit.
None of this requires a DPDP Act to be a problem — it sits underneath it. A property that fixes this only because of DPDP timelines will still have to fix it again when the Aadhaar rule lands.
What good looks like
Verify identity without retaining a copy — QR or offline verification where your PMS supports it.
If a copy must be kept for statutory filing (Form C, police register), separate that record from your own guest database.
Never let Aadhaar images sit on a personal staff phone or in a shared WhatsApp thread — that alone is the single most common violation we see.
Set — and follow — a real deletion date for any ID copy you do retain.
See exactly how your front desk scores.
Domain A of the free Risk Scorecard is built entirely around this.