Open any onboarding folder in an Indian company and you will find Aadhaar cards. Full 12-digit numbers, front and back, sitting in shared drives and email threads.

For years that was treated as normal. Aadhaar masking rules said otherwise, but few teams read them.

That is changing fast. The DPDP Rules, 2025 name masking as a baseline security safeguard, and that obligation becomes enforceable on 13 May 2027.

UIDAI is also moving against the photocopy habit itself. It has approved a rule requiring private entities to register before they verify Aadhaar at all.

This guide explains what UIDAI and the DPDP Act actually require, where Aadhaar numbers hide in your files, and how to mask them at intake instead of cleaning up later.

Quick answer: what are the Aadhaar masking rules for businesses? Unless a law requires the full number, keep only the last 4 digits visible (XXXX XXXX 1234). UIDAI regulations bar publishing or displaying Aadhaar numbers and require any record made public to be redacted. The DPDP Rules, 2025 list masking among minimum security safeguards, with penalties up to ₹250 crore from May 2027.
⚖️
₹250 Cr
Max DPDP penalty for weak security safeguards
📅
13 May 2027
DPDP security and breach rules take effect
🔢
4 digits
All a masked Aadhaar shows
🏛️
₹1 Cr
Civil penalty ceiling under the Aadhaar Act

What Is Aadhaar Masking?

Aadhaar masking hides the first 8 digits of the 12-digit Aadhaar number and leaves only the last 4 visible. A masked number reads XXXX XXXX 1234.

UIDAI offers a masked Aadhaar download through myAadhaar. It stays valid for identity proof wherever the full number is not legally required.

Already have an unmasked card or PDF? Our Free Aadhaar Masking Tool masks it in your browser, and the file never leaves your device.

Masking is one of four techniques businesses confuse. They protect different things, and regulators use them for different purposes.

TechniqueWhat it doesTypical use
MaskingHides the first 8 digits, keeps the last 4Default for KYC copies, HR files, customer records
RedactionRemoves the number completely, often the whole fieldDocuments shared with third parties or published
TokenisationReplaces the number with a reference tokenSystems that must match records without seeing Aadhaar
Data vaultStores the full number encrypted, separate from other dataEntities legally allowed to keep the full number
Key point: A black rectangle drawn in a PDF editor is often not masking at all. If the text layer underneath survives, anyone can copy the full number out of the file.

What Do UIDAI Rules Require From Businesses?

UIDAI rules apply to any business that collects Aadhaar, not only banks and telecom firms. A hotel front desk and an HR team are covered too.

Three layers matter: the Aadhaar Act, UIDAI's regulations, and UIDAI circulars. The DPDP Act then sits on top of all three.

The Aadhaar Act, Section 29

Section 29(4) of the Aadhaar Act, 2016 bars publishing, displaying or posting an Aadhaar number publicly, except as regulations allow.

Since the 2019 amendment, UIDAI's adjudicating officer can levy civil penalties of up to ₹1 crore for violations.

The Sharing of Information Regulations, 2016

These regulations set the core duties for any business that is not a requesting entity. Regulation 5 says any entity collecting an Aadhaar number or a document containing it must:

🎯

Lawful purpose

Collect, store and use it only for a lawful purpose

📢

Tell the holder

Purpose, mandatory or not, and alternatives

✍️

Get consent

For collection, storage and use

🚫

No reuse

No other purpose or sharing without consent

Regulation 6 then adds the masking rule. No entity may make public any record containing Aadhaar numbers "unless the Aadhaar numbers have been redacted or blacked out through appropriate means, both in print and electronic form."

It also requires entities to keep any database of Aadhaar numbers secure and confidential. Read the full text in the UIDAI regulations.

The Aadhaar Data Vault

UIDAI's 2017 Data Vault circular requires entities permitted to store full Aadhaar numbers to keep them encrypted in a separate, access-controlled vault.

Every other system then works with a reference key, not the number. If you do not need a vault, you should not be keeping full numbers.

The 2025 Offline Verification Amendment

The Aadhaar (Authentication and Offline Verification) Amendment Regulations, 2025 created a formal registration framework for Offline Verification Seeking Entities (OVSEs).

In December 2025, UIDAI also approved a rule requiring hotels, event organisers and other private entities to register before verifying Aadhaar. The stated aim is to end the practice of collecting photocopies.

Registered entities are expected to use QR-based checks, API authentication or the new Aadhaar app instead of keeping copies.

A common myth: In May 2022 a UIDAI regional office told citizens to share only masked Aadhaar, and the government withdrew that advisory two days later. The withdrawal changed citizen guidance only. Regulations 5 and 6 still bind businesses.

Masking Aadhaar at onboarding volume?

Run a real KYC batch through DocuExprt on a call.

  • Bulk and API Aadhaar masking
  • UIDAI Secure QR decoding
  • DigiLocker pulls with consent
  • Tamper detection on every file
Book a Free Demo →

Or try a free tool first.

🔒 CERT-IN Certified🛡 ISO 27001🎟 Free trial tokens

What the DPDP Act Adds to Aadhaar Masking

An Aadhaar number is personal data under the Digital Personal Data Protection Act, 2023. So every DPDP duty applies on top of the UIDAI rules.

The DPDP Rules, 2025 were notified on 14 November 2025 with an 18-month runway. Most substantive duties, including security safeguards and breach notice, apply from 13 May 2027.

Rule 6 names masking directly

Rule 6 lists minimum security safeguards. The first is securing personal data "through its encryption, obfuscation or masking or the use of virtual tokens mapped to that personal data."

For Aadhaar, that turns masking from good practice into a named, auditable control.

Four more DPDP duties that touch Aadhaar files

  • Purpose limitation: process Aadhaar only for the purpose in your consent notice.
  • Data minimisation: if the last 4 digits answer the question, the full number is excess data.
  • Storage limitation: erase personal data once the purpose is served, unless a law requires retention.
  • Breach notice: report personal data breaches to the Data Protection Board and affected people.

❌ Unmasked intake

  • Breach scope: every leaked file exposes full Aadhaar numbers
  • Penalty exposure: up to ₹250 crore for weak safeguards
  • Erasure: copies in inboxes and drives you cannot find
  • Audit: no proof of who saw which number
VS

✅ Masked at intake

  • Breach scope: leaked files show 4 digits only
  • Penalty exposure: a documented Rule 6 safeguard
  • Erasure: one controlled store to delete from
  • Audit: logged access per user and action
QuestionUIDAI rulesDPDP Act and Rules
Who must complyAnyone collecting AadhaarEvery data fiduciary processing digital personal data
MaskingRedaction required before any record is made publicMasking listed as a minimum safeguard (Rule 6)
ConsentConsent for collection, storage and useItemised notice and specific consent
RetentionLawful purpose onlyErase when purpose is served
Maximum penalty₹1 crore civil penalty₹250 crore per breach category

Sector Rules: When You May Keep the Full Number

Masking is the default, but some laws do require the full number. The test is simple: can you name the law that makes you keep it?

Banks show how narrow the exception is. RBI's 2019 KYC amendment requires regulated entities to ensure customers who are not seeking DBT benefits redact or black out their Aadhaar number when submitting it as a KYC document.

So even in banking, the full number is the exception, tied to authentication under the Aadhaar Act.

Business scenarioWhat to keep
Bank or NBFC, Aadhaar used as an officially valid documentMasked copy plus verification result
Licensed AUA or KUA running authenticationFull number in an Aadhaar Data Vault only
Employer verifying a new hire's identityMasked copy, or verification result only
Employer seeding UAN where EPFO requires itFull number in the EPFO flow, masked everywhere else
Hotel, event or housing society check-inNothing beyond the QR or app verification outcome
Insurer, hospital or university admission fileMasked copy unless a specific law says otherwise
Rule of thumb: If you cannot point to the clause that needs the full number, keep the last 4 digits and the verification outcome, nothing more.

Where Aadhaar Numbers Hide in Your Files

Most masking failures are not policy failures. The policy says "mask Aadhaar", and the team masks the obvious number on the front of the card.

Our team uses the checklist below when reviewing onboarding files. Each item is a place where a full Aadhaar number survives a manual mask.

Two of these need a closer look.

QR codes. The current Secure QR is digitally signed and carries only the last 4 digits as part of a reference ID. Older Aadhaar prints used QR formats that could hold the full number in plain text, so masking the printed digits alone is not enough.

PDF text layers. e-Aadhaar and scanned files often carry machine-readable text. A mask must flatten the page so the hidden digits are removed from the file, not just covered.

How to Mask an Aadhaar Card Correctly: 4 Steps

For a single card, the process takes about a minute. The steps below close every gap shown above.

📤

Step 1: Upload both sides

Front, back or the full e-Aadhaar PDF

🔍

Step 2: Find every instance

Card, letter section and any older QR code

⬛

Step 3: Mask and flatten

Hide the first 8 digits, export as one image layer

🗑️

Step 4: Share and delete

Send the masked file, delete the original

Try it free: The Free Aadhaar Masking Tool runs steps 1 to 3 in your browser and exports a flattened PDF. Nothing is uploaded to a server.

How to Automate Aadhaar Masking at Intake

Manual masking works for one card. It breaks at onboarding volume, because every reviewer becomes a single point of failure.

The fix is to mask at the moment of intake, before a file reaches any shared drive or reviewer.

Verification and masking belong in one flow. You confirm the document is genuine first, then keep only what the purpose needs.

Verification-first platforms make this a pipeline step rather than a person with a cropping tool. DocuExprt decodes the UIDAI Secure QR on Aadhaar, pulls issued documents from DigiLocker with the holder's consent, and runs tamper detection on every file.

For masking itself, the DocuExprt Aadhaar masking tool blacks out the first 8 digits and exports a flattened PDF. Teams running KYC at volume use bulk masking or API access inside their onboarding workflow.

Around that, the controls auditors ask about come built in: role-based access control, audit logs with IP monitoring, encryption in transit and at rest, and an option for immediate deletion after processing.

🔍

Secure QR decoding

Checks the UIDAI-signed QR on Aadhaar

⬛

Bulk masking

Batch and API masking for KYC flows

🔐

Access control

Role-based access and audit logs

🗑️

No retention option

Immediate deletion after processing

For regulated teams: DocuExprt runs as SaaS, private cloud or on-premise, so Aadhaar data can stay inside your own network perimeter. See the enterprise verification guide for deployment details.

Make masking a step, not a chore

Tell us your onboarding volume and document mix.

  • Verify first, then mask
  • Role-based access and audit logs
  • Immediate deletion option
  • SaaS, private cloud or on-prem
Talk to Our Team →

Or book a demo on your own files.

🔒 CERT-IN Certified🛡 ISO 27001🎟 Free trial tokens

Aadhaar Masking Compliance Checklist

Use this list to test your current process before May 2027. Each item maps to a UIDAI regulation or a DPDP duty.

  • ✅ Every form that asks for Aadhaar states the purpose and offers an alternative ID.
  • ✅ Consent covers collection, storage and use, and is recorded.
  • ✅ You can name the law for every system that keeps the full number.
  • ✅ Full numbers, where allowed, sit in an encrypted vault, not in shared drives.
  • ✅ Masking covers the card back, e-Aadhaar letter and QR code, not just the front.
  • ✅ Masked PDFs are flattened so no text layer survives.
  • ✅ Original unmasked uploads are deleted after verification.
  • ✅ Reports, exports and dashboards show only the last 4 digits.
  • ✅ Access to Aadhaar records is role-based and logged.
  • ✅ Your breach response plan covers Aadhaar files and DPDP notice timelines.
Start here: Search your shared drives for files named "aadhaar". The count usually ends the debate about whether intake automation is needed.

Key Takeaways

  1. A masked Aadhaar shows only the last 4 digits: XXXX XXXX 1234.
  2. UIDAI's Regulation 5 requires a lawful purpose, notice and consent before you collect Aadhaar.
  3. Regulation 6 bars publishing Aadhaar numbers unless redacted, in print and electronic form.
  4. DPDP Rule 6 names masking as a minimum security safeguard from 13 May 2027.
  5. Weak safeguards can draw DPDP penalties of up to ₹250 crore.
  6. Keep the full number only where a named law requires it, and then only in a vault.
  7. Manual masking misses the card back, e-Aadhaar letters, older QR codes and PDF text layers.
  8. Masking at intake, after verification, is the only approach that scales.

Frequently Asked Questions

Is Aadhaar masking mandatory for businesses?

UIDAI regulations require Aadhaar numbers to be redacted before any record is made public and require entities to keep stored numbers secure and confidential. The DPDP Rules, 2025 add masking as a listed minimum safeguard from 13 May 2027. In practice, masking is mandatory wherever the full number is not legally required.

Can a company store a copy of an employee's Aadhaar card?

Only for a lawful purpose, after telling the employee why and getting consent, under UIDAI's Sharing of Information Regulations. A masked copy or a verification result is usually enough. The full number should sit only in flows that legally require it, such as EPFO UAN seeding.

Is a masked Aadhaar valid for KYC?

Yes, where the full number is not required for authentication. RBI's KYC rules require banks to ensure customers who are not seeking DBT benefits redact their Aadhaar number when submitting it as a KYC document. Verification can then rely on the Secure QR, DigiLocker or offline e-KYC.

What is the penalty for not masking Aadhaar?

Under the Aadhaar Act, UIDAI's adjudicating officer can impose civil penalties of up to ₹1 crore. Under the DPDP Act, failing to take reasonable security safeguards can draw up to ₹250 crore, and failing to report a breach up to ₹200 crore.

Does masking the printed number make an Aadhaar copy safe?

Not always. The number is printed on both sides of the card and more than once on e-Aadhaar, older QR codes can encode it, and PDFs can keep it in a hidden text layer. A safe mask covers every instance and flattens the file.

Do hotels need to register with UIDAI to verify Aadhaar?

UIDAI approved a rule in December 2025 requiring hotels, event organisers and other private entities to register before carrying out Aadhaar verification. Registered entities are expected to use QR-based checks, API authentication or the Aadhaar app instead of collecting photocopies.

Mask First, Then Keep Only What You Need

Aadhaar masking used to be a privacy courtesy. Under UIDAI's regulations and the DPDP Rules, it is now a control you will be asked to prove.

The deadline is fixed: 13 May 2027. The teams that move first will mask at intake, verify at source and delete the rest.

That is the same approach behind deployments such as SBTE Bihar, where 50,000+ documents were verified within a couple of days.

Get DPDP-ready before May 2027

Bring a sample batch. We run it live on the demo.

  • 50,000+ documents in days
  • 99% accuracy
  • PAN, Aadhaar, GST + 30+ govt DBs
  • CERT-IN certified security

Trusted by enterprises and government boards

Roche Products (India) Pvt. Ltd. logo
Elbrit Life Sciences Pvt. Ltd. logo
Haryana Knowledge Corporation Limited (HKCL) logo
Maharashtra Council of Agricultural Education and Research (MCAER) logo
State Board of Technical Education, Bihar (Patna) logo
SVKM's NMIMS Deemed-to-be University logo
CERT-IN CertifiedISO/IEC 27001:2013Data stays in India

Free trial tokens available for testing.

Mask a card now with the Free Aadhaar Masking Tool. Related reading: document verification for BFSI, background verification, insurance document verification and our free verification tools.