The Casual Request with Hidden Risks
For years, it has been standard practice for hotels across India to request a guest's Aadhaar card and keep a photocopy for their records. While the intention is to comply with rules requiring them to verify a guest's identity, the method is dangerously
outdated. A physical copy of your Aadhaar is a treasure trove of sensitive information. In the wrong hands, it can be misused to apply for loans, obtain SIM cards in your name, or create fraudulent bank accounts. A stack of these photocopies in a hotel's back office, often stored with little to no digital security, becomes a prime target for identity thieves. Kolkata Police recently issued an advisory highlighting how criminals exploit these leaked documents, which are sometimes sourced from hotels, for financial crimes.
Is Demanding an Aadhaar Photocopy Legal?
The short answer is no. According to the Unique Identification Authority of India (UIDAI), unlicensed private entities like hotels are not permitted to collect or store physical copies of Aadhaar cards. Doing so is considered an offence under the Aadhaar Act 2016. The government body has repeatedly issued warnings and clarifications, urging the public not to share uncensored photocopies of their Aadhaar due to the potential for misuse. Hotels are required to verify the identity of their guests, but this does not give them the right to collect and store your most powerful identity document indefinitely. The government's stance is clear: verification is necessary, but indiscriminate data collection is not.
A Smarter Way: The Data-Minimisation Principle
This is where the principle of 'data minimisation' comes in. It’s a simple but powerful idea: an organisation should only collect the personal data that is strictly necessary for a specific purpose. For a hotel check-in, the purpose is to confirm your name and address. They do not need your unique 12-digit Aadhaar number, which acts as a key to your digital identity. By adopting a data-minimisation approach, hotels can fulfil their legal duty to verify guests without putting them at risk. This isn't just a theoretical concept; it's a core tenet of modern data protection laws, including India's Digital Personal Data Protection Act. It shifts the process from 'collect everything' to 'collect only what you need'.
Putting Minimisation into Practice
So, how can you practice data minimisation? Fortunately, UIDAI has provided several tools. The best option is to use a 'Masked Aadhaar'. This is an official, legally valid version of your e-Aadhaar where the first eight digits of your number are hidden, showing only the last four. It can be easily downloaded from the UIDAI website and contains your name, address, photo, and a QR code for verification, which is all a hotel needs. Another secure method is using the QR code on your Aadhaar card or the mAadhaar app. Hotel staff can scan this code to get instant verification of your details without needing to store a copy. UIDAI has been actively encouraging this shift towards paperless, offline verification.
The Way Forward for Guests and Hotels
As a guest, you have the right to push back. You can politely insist on using a Masked Aadhaar or another valid government ID like a passport or driver's license. While some hotels may be unaware of the rules and insist on a full Aadhaar copy, showing them a Masked Aadhaar is a valid form of KYC. The larger responsibility, however, lies with the hospitality industry and regulators. The government is already taking steps, planning to introduce rules that require entities like hotels to register as 'Offline Verification Seeking Entities' (OVSEs) and adopt secure QR code or app-based methods. This formalises the move away from risky photocopies. Hotels need to train their staff on these new, secure procedures and invest in the simple technology required to scan a QR code, protecting both their customers and themselves from liability.














