Almost every organisation that asks for your Aadhaar tells you it is required. Most of the time that is wrong, and the rules that make it wrong are clearer than their reputation suggests.

There is a persistent confusion in India about what an Aadhaar number is for. It is treated as a universal identity document — produced at hotel check-ins, gym memberships, courier pickups and school admissions — when the law that created it is considerably narrower than that. Understanding the difference is what tells you when a masked copy is acceptable, which is nearly always.

What the Aadhaar Act actually permits

The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 was written for a specific purpose, visible in its title: delivering subsidies and benefits funded from the Consolidated Fund of India. Section 7 is the operative provision, and it allows the government to require Aadhaar for those benefits.

What it does not do is create a general-purpose identity requirement for private commerce. That distinction was tested and settled.

The 2018 Supreme Court judgment

In Justice K.S. Puttaswamy (Retd.) v. Union of India, the Supreme Court upheld the Aadhaar Act in the main but struck down Section 57, which had permitted body corporates and individuals to require Aadhaar under contract. The practical consequence: a private company cannot make Aadhaar mandatory simply because it would find it convenient. It needs a statutory basis.

The judgment also mandated Aadhaar for linking to bank accounts and mobile connections — and then that requirement itself was read down. The position that emerged is that Aadhaar-based verification for those purposes is voluntary, with alternatives that must be offered.

Where Aadhaar genuinely is required

A short and specific list. Subsidy and benefit delivery under Section 7. Income tax filing and PAN linkage under Section 139AA of the Income Tax Act. Certain regulated financial verifications where a specific statute or regulator mandates it. And that is broadly it.

Everything else — the hotel, the gym, the courier, the private tuition centre — is a request, not a requirement, and you may offer a different document or a masked copy.

What "masked Aadhaar" means, precisely

A masked Aadhaar is the same document with the first eight digits of the twelve-digit number obscured, leaving the last four visible. 1234 5678 9012 becomes XXXX XXXX 9012.

The last four digits are deliberately retained. They let an organisation match a document against a record it already holds — confirming that the Aadhaar you are producing now is the one you produced at account opening — without the full number, which is what enables authentication and lookup. It is the same reasoning behind showing the last four digits of a card number on a receipt.

UIDAI's own e-Aadhaar download offers a masked version for exactly this purpose, which is the clearest possible signal that a masked copy is intended to be sufficient for ordinary sharing.

Who may hold a full Aadhaar number

This is the part that most often surprises people on the receiving end of a request.

Only entities registered with UIDAI in defined roles may perform Aadhaar authentication and handle full numbers in that capacity: Authentication User Agencies, KYC User Agencies, and their sub-agencies. These are licensed, audited, and bound by specific security obligations. Becoming one is a deliberate regulatory undertaking.

An organisation that is not one of these has no authentication capability. It cannot verify your Aadhaar against UIDAI at all. So when it asks for the full number, that number is not being verified — it is being filed, in a system whose security you cannot inspect, serving no purpose the last four digits would not serve.

The question worth asking a requester is not "are you allowed to ask for this?" but "what are you going to do with it?" If the answer is "keep it on file", a masked copy does that job identically.

The offence nobody mentions

Section 29(4) of the Aadhaar Act restricts publishing or displaying an Aadhaar number publicly. Chapter VII creates offences around unauthorised disclosure and use of identity information, carrying imprisonment and fines.

Those provisions matter to organisations more than to individuals. A company that collects full Aadhaar numbers and then leaks them — through a misconfigured storage bucket, a departing employee, or a vendor breach — is not merely embarrassed. It has an offence to answer for under a statute with criminal provisions, alongside its obligations under the RBI and sectoral rules that apply to it.

The practical implication runs the other way from how most organisations think about it. Collecting a full Aadhaar number is not the safe, thorough, diligent option. It is the option that creates a liability, and it usually does so without gaining anything the masked version would not have provided.

What to do when someone insists

Politely, and in order:

If an organisation still insists without pointing to a legal basis, you can escalate to UIDAI — but in practice, offering the masked copy resolves the overwhelming majority of these interactions before it gets that far.

If you are on the receiving end

If you run the organisation asking, the position is simpler than it looks. Accept masked copies as standard. Ask for a full number only where a statute or your regulator requires it, and be able to name which. Where you do hold full numbers, mask them at the point of collection so that what lands in your document store is already redacted — not masked later, by someone remembering to.

That last point is the whole argument for automating it. A masking step that depends on a person is a step that gets skipped on a busy day, and nobody finds out which day that was until a bucket is audited.

Questions

Is a masked Aadhaar card legally valid?

Yes, for the overwhelming majority of uses. A masked Aadhaar shows the last four digits, which is enough for an organisation to match the document against a record it already holds. UIDAI offers a masked version of the e-Aadhaar download itself, which is a clear signal that it is intended to be sufficient for ordinary sharing. Only entities registered with UIDAI as authentication or KYC user agencies can actually verify an Aadhaar number, and everyone else is simply filing it.

Can a private company demand my full Aadhaar number?

Generally not. The Supreme Court struck down Section 57 of the Aadhaar Act in the 2018 Puttaswamy judgment, which had allowed private bodies to require Aadhaar under contract. A private company now needs a statutory basis to make it mandatory. Hotels, gyms, courier services and similar businesses are making a request, not enforcing a requirement, and you may offer a masked copy or an alternative document.

Which digits are hidden in a masked Aadhaar?

The first eight of the twelve digits are obscured and the last four remain visible, so 1234 5678 9012 becomes XXXX XXXX 9012. The last four are retained deliberately: they let an organisation match the document against its own records without holding the full number that enables authentication and lookup.

Where is Aadhaar genuinely mandatory?

A short list: delivery of subsidies and benefits funded from the Consolidated Fund of India under Section 7 of the Aadhaar Act, income tax filing and PAN linkage under Section 139AA of the Income Tax Act, and specific regulated financial verifications where a statute or regulator mandates it. Most everyday requests fall outside all of these.

What are the penalties for mishandling Aadhaar numbers?

Section 29(4) of the Aadhaar Act restricts public display or publication of an Aadhaar number, and Chapter VII creates offences around unauthorised disclosure and use of identity information, carrying imprisonment and fines. This matters mainly to organisations: collecting full Aadhaar numbers creates a liability that a masked copy would have avoided, usually without gaining anything in return.

Masking Aadhaar at volume?

One REST call takes a document and returns it redacted, for KYC and document pipelines. Free browser tools for everything smaller — those never upload the document at all.

Request API access