Confidential Dispatch

Collecting Aadhaar, PAN and KYC from customers: what you can ask for and how

4 min readUpdated 2026-07-04
On this page
  1. 01Start with “do I actually need it?”
  2. 02What you can ask for — and the masked-Aadhaar rule
  3. 03How to collect it compliantly
  4. 04What not to do
  5. 05FAQ
At a glance

Under India’s DPDP Act you can ask a customer for Aadhaar, PAN, or KYC documents only where the purpose genuinely needs them — and you should ask for the minimum. Give a clear notice of why, take specific consent, and accept a masked Aadhaar (first eight digits hidden) wherever the full number isn’t legally required. Collect the least you can, store it securely, keep a consent record, and delete it when the purpose is over. The default question isn’t “how do I collect Aadhaar?” — it’s “do I actually need it, or will less do?”

Educational resource only. This explains collecting Aadhaar, PAN and KYC in line with India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice, and DPDP compliance is an organisation-wide obligation broader than any single intake step.

The situation

Asking for Aadhaar and PAN has become a reflex at onboarding — for gyms, societies, brokers, clinics, coaching classes. Often the business doesn’t strictly need them, or needs far less than it collects. Under the DPDP Act, sensitive identity documents are where over-collection hurts most, so this is worth getting deliberately right.

Start with “do I actually need it?”

The first compliance decision is whether to ask at all — minimisation applies hardest to identity documents. Before requesting Aadhaar or PAN, ask what purpose it serves and whether a lighter alternative works. A gym recording attendance doesn’t need your Aadhaar; a service that just needs to reach you needs a phone number, not a PAN. Collecting a national ID “for our records” isn’t a purpose — and every full Aadhaar or PAN you hold is a serious liability if you’re breached. The Act’s data-minimisation principle means the strongest position is not holding the document in the first place.

What you can ask for — and the masked-Aadhaar rule

Ask only for what the purpose requires, and prefer masked or partial versions. Where you do have a genuine need:

  • Aadhaar: where the full number isn’t specifically required by law for the service, a masked Aadhaar — with the first eight digits hidden and only the last four visible — is the norm to accept. It verifies without exposing the full unique number. Don’t demand the full Aadhaar by default, and don’t store more than you need.
  • PAN: collect it only where there’s a real purpose (e.g. a tax-reporting requirement), not as a routine field.
  • KYC documents: take only the specific documents the purpose needs, and only the relevant pages or fields — not a full stack “to be safe.”

Being able to point to why each item is needed is the test. If you can’t name the purpose, don’t collect it.

How to collect it compliantly

Notice and consent first, a secure channel next, tight retention last.

  1. State the purpose in a notice (Section 5) — which document, exactly why, how long you’ll keep it, how to withdraw.
  2. Take specific consent (Section 6) for that purpose, and record it.
  3. Accept the minimum — masked Aadhaar where possible, only the pages that matter, only the documents the purpose needs.
  4. Use a secure, access-controlled channel — not open email, chat images, or a public upload link.
  5. Set retention and delete — hold it only as long as the purpose (or a specific legal duty) requires, then erase it, including stray copies.
  6. Keep a consent record — you must be able to prove what was asked and agreed.

What not to do

A few habits turn routine KYC into a standing liability — avoid them.

  • Demanding a full Aadhaar when a masked one, or no Aadhaar at all, would do.
  • Collecting “just in case” — extra documents with no named purpose.
  • Storing copies in inboxes, chats, or open folders where you lose track of them.
  • Keeping documents forever after the purpose is over.
  • Instead: ask less, mask where possible, secure what you keep, and delete on schedule.

FAQ

Can I ask customers for their Aadhaar?

Only where the purpose genuinely needs it, with notice and consent — and you should accept a masked Aadhaar wherever the full number isn’t legally required. Don’t collect it by default.

What is a masked Aadhaar, and should I accept one?

It hides the first eight digits, showing only the last four. Yes — accept it wherever the full number isn’t specifically required; it verifies identity while reducing exposure.

Is it okay to collect PAN routinely?

No. Collect PAN only where there’s a genuine purpose, such as a tax-reporting need — not as a standard onboarding field.

How long can I keep KYC documents?

Only as long as the purpose needs, unless a specific law requires a set retention period. Then delete them, including any scattered copies.

Reviewed by Confidential Dispatch Editorial Team
Last updated 4 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →