The Undeniable Appeal of Seamless Travel
DigiYatra, an initiative by India's Ministry of Civil Aviation, is transforming the airport experience. By using facial recognition technology, it promises a paperless and contactless journey. Passengers enrol via a mobile app, linking their Aadhaar and uploading
a selfie. At the airport, dedicated e-gates scan your face, verifying your identity and travel documents in seconds, allowing you to bypass long manual checks at terminal entry, security, and boarding. The benefit is clear and tangible: reduced wait times and a hassle-free process. With passenger traffic projected to reach 500 million by 2030, the government sees DigiYatra as a critical piece of digital infrastructure to manage this growth. As of mid-2026, the system has already processed over 100 million journeys across dozens of airports, with more being added constantly. This rapid adoption signals that for many travellers, the convenience is too good to ignore.
The Privacy Policy on Paper
The DigiYatra Foundation, the joint venture of public and private bodies that manages the system, has built its privacy claims on a key promise: decentralisation. Officially, your biometric data is encrypted and stored only on your own mobile phone. When you travel, a temporary, single-journey token is shared with the airport's servers, and this data is meant to be purged within 24 hours of your flight's departure. The Ministry of Civil Aviation has stated that no central repository of facial biometrics is maintained. Furthermore, the system is designed to comply with India’s Digital Personal Data Protection (DPDP) Act, which requires explicit user consent and provides a right to data erasure. On paper, these measures suggest a system designed with privacy in mind.
Convenience, Coercion, and Consent
Despite official assurances, the reality on the ground has raised red flags for privacy advocates and even government think tanks like NITI Aayog. A significant concern is the quality of consent. Multiple reports have emerged of passengers feeling coerced or being signed up for the service without fully understanding it. When dedicated DigiYatra gates vastly outnumber conventional ones, the 'choice' to opt-out becomes inconvenient by design, nudging people toward adoption. This creates a habit of handing over biometric data without a complete understanding of the transaction. Critics argue that this dynamic turns convenience into a Trojan horse, normalising a level of surveillance that would otherwise face greater scrutiny. The Internet Freedom Foundation (IFF) has pointed to this environment of coercion and the lack of transparency as core problems with the rollout.
Unanswered Questions and Lingering Risks
The promise to delete data within 24 hours is a frequent talking point, but it also draws the most scrutiny. Who independently verifies this deletion? While the policy covers facial biometrics, NITI Aayog's own study pointed out that rules for deleting other passenger information collected by the system are not clearly defined. Accountability is another murky area. The DigiYatra Foundation is a private consortium, not a government body, and is not subject to transparency mandates like the Right to Information (RTI) Act. This makes it difficult to get clear answers about data sharing protocols, security audits, and potential breaches. Experts warn that without a robust legal framework specifically for facial recognition technology, and without independent oversight, wide and vague exemptions could allow passenger data to be shared with government agencies, potentially infringing on civil liberties.
A Call for Widespread Privacy Literacy
DigiYatra's success is not just a story about technological adoption; it is a critical test case for digital India. The convenience it offers is real, but it has arrived ahead of the widespread privacy literacy needed to navigate its implications. The solution is not to simply reject the technology, but to demand better. This starts with citizens becoming more informed and asking critical questions about the data they share. It requires demanding greater transparency from the DigiYatra Foundation, including independent, publicly available security and algorithmic audits. And it means pushing for stronger data protection laws that specifically address the unique challenges of biometric surveillance. As DigiYatra becomes an integral part of Indian travel, we must ensure it serves passengers not just with speed, but with respect for their privacy and autonomy. The 'mass habit moment' should be one of empowerment, not blind acceptance.
















