DigiLocker Verification: How Businesses Check Documents With Consent
Peneu Editorial Team · 28 September 2026 · 10 min read

Most document checks in onboarding start with a photo or a PDF the customer uploads, and then someone has to decide whether it's genuine. DigiLocker takes that question away for the documents it covers. When a customer shares a document from DigiLocker's issued section, it comes from the authority that issued it, such as a transport department, a school board or the income tax department, with that authority's digital signature. It isn't a picture of the document; it's the document.
That's what people usually mean by "DigiLocker verification": fetching an issued document from a customer's DigiLocker account, with their consent, instead of asking for a scan. This guide explains how it works, what it proves, and where it falls short.
What DigiLocker is
DigiLocker is the Government of India's platform for storing, sharing and verifying documents digitally, run by the National e-Governance Division under the Ministry of Electronics and Information Technology (MeitY). A person signs in, usually with their Aadhaar number and an OTP to their Aadhaar-linked mobile, and can pull documents that issuers have made available in their name.
Using it is optional for citizens. For businesses, it matters because a growing share of the documents customers need to show already sit there: driving licences, vehicle registration, school and university results, and banking documents such as account statements, Form 16 and interest certificates, among others.
Issued documents and uploaded documents are not the same
This distinction decides whether a DigiLocker document is worth anything to you as a verifier.
The same document can exist in both sections, which is where mistakes happen. DigiLocker's own guidance is to use documents from the issued section for official purposes. If your process accepts a file from the uploaded section, you're back to checking a scan.
Issued documents
- Pushed into the account by the issuing authority itself
- Carry the issuer's digital signature
- Only the issuer can correct or update them
- Legally at par with the original when used electronically
Uploaded documents (DigiLocker Drive)
- Scans or files the person uploaded themselves
- No issuer signature; the platform doesn't vouch for them
- The person can change or replace them
- Personal storage; treat them like any other upload
Legal standing
Documents in the issued section have a specific legal basis. Under Rule 9A of the Information Technology (Preservation and Retention of Information by Intermediaries Providing Digital Locker Facilities) Rules, 2016, added in February 2017, documents issued into a DigiLocker account are deemed to be at par with the original physical documents.
For entities regulated by RBI, the KYC Master Direction goes a step further. It defines an "equivalent e-document" as an electronic equivalent of a document issued by the issuing authority with its valid digital signature, including documents issued to the customer's digital locker account under those rules. That lets regulated entities accept such documents in place of physical copies of officially valid documents in their KYC processes.
Two caveats. Being legally valid doesn't mean every institution accepts it in practice; DigiLocker itself says it's still working to increase acceptance. And a valid document is only one part of KYC: it proves the document is genuine, not that the person presenting it is its owner, unless the sign-in and name checks tie them together.
How a consent-based fetch works
Organisations don't browse a customer's locker. They request specific documents, and the customer decides. DigiLocker says data is shared only with the user's explicit consent and that all access is logged.
Organisations do this through the services DigiLocker offers to authorised organisations, either by integrating directly or through a verification provider that has. DigiLocker's gateway passes documents between DigiLocker and the authorised organisation; DigiLocker says it doesn't access or store the data in transit.
- 1RequestYour onboarding flow asks for a specific document type
- 2Sign inThe customer signs in to DigiLocker, typically with Aadhaar and OTP
- 3ConsentThey see what you've asked for and choose whether to share it
- 4FetchYou receive the issued document or its data, signed by the issuer
- 5RecordKeep the consent record and only the data you need
What to check after you've fetched a document
A genuine document is a strong start, not the end of the check. Before you rely on it:
- Confirm it came from the issued section, not from the customer's uploads, and that the issuer's signature is valid.
- Match the name, date of birth and other details against what the customer entered and against your other checks, such as a PAN or bank account check.
- Check the document type is right for the purpose. A class 10 mark sheet proves date of birth for some purposes; it doesn't prove address.
- Check dates. A driving licence can be expired; a certificate can be superseded by a corrected one.
- Keep a record of the consent: what was requested, what was shared and when.
- Store only what you need. If you only need to know a licence is valid, don't keep a full copy of it.
When DigiLocker verification won't work
DigiLocker covers a lot, but not everyone and not every document. Build your flow so these customers have another way through:
| Situation | Why it happens | What to offer |
|---|---|---|
| The name doesn't match | DigiLocker only lets a person fetch documents whose name matches their Aadhaar. A spelling difference, a change after marriage or a different name order blocks the fetch | Another verification method. The fix on the customer's side is with the issuer or with Aadhaar, which takes time |
| The issuer hasn't put the document on DigiLocker | Records appear only after an issuer publishes them. Many boards and universities have only some years online | Accept the document another way, with a separate check |
| The document type isn't on DigiLocker | Not every department is integrated. Passports weren't available in 2024, for example | Use a different document or another check |
| The customer can't sign in | Sign-in needs an OTP to the Aadhaar-linked mobile. If that number has changed or was never linked, it fails | Another method now; the customer updates their mobile in Aadhaar for next time |
| The customer is abroad | Access from outside India needs an Indian mobile number or a verified email ID on the account | Check before sending them into the flow |
| The customer doesn't want to use it | DigiLocker is optional | Always keep a non-DigiLocker route |
DigiLocker next to other checks
DigiLocker verifies documents. Most onboarding needs a few other things verified too, and each has its own method.
| You need to know | A common way to check it | More detail |
|---|---|---|
| The customer's PAN is valid and matches their name | PAN verification against the income tax records | PAN verification guide |
| The customer holds the Aadhaar they gave you | Aadhaar authentication or offline verification, with consent | Aadhaar verification guide |
| A document is genuine and issued in their name | DigiLocker issued document, fetched with consent | This article |
| A bank account exists and belongs to them | Penny drop or penny-less account verification | Bank account verification |
| A business is registered and active | GST, company and other registry checks | KYB guide |
If you're a regulated entity
Accepting a DigiLocker document as an equivalent e-document doesn't change who owns the KYC obligation. You still decide what your customer due diligence requires, which documents you accept for which purpose, how you match them to the customer and how long you keep them. The KYC guide covers officially valid documents, digital KYC methods and risk-based checks in more depth.
Peneu provides verification checks; it doesn't take on a regulated entity's KYC obligations. Which checks are available through Peneu, and in what form, is confirmed during onboarding.
Quick answers
Questions that come up when businesses start accepting DigiLocker documents:
- Is a printout of a DigiLocker document valid? DigiLocker describes issued documents as legally valid and at par with originals when used electronically. A printout is a copy; if you need to rely on the document, fetch it electronically.
- Can a customer share a family member's documents? No. DigiLocker accounts are individual, and a person can only fetch documents issued in their own name.
- Does DigiLocker sell or share data with third parties? DigiLocker says documents are shared only with verified online consent, and that it acts as an intermediary between the user and authorised organisations.
- Can a customer have more than one account? Up to five Aadhaar-verified accounts can be created with one mobile number, for example when family members share a phone. Each account still holds only its owner's documents.
- Can an issued document be wrong? Yes, if the issuer's records are wrong. Only the issuer can correct it, so a mismatch with other checks should be resolved with the issuer, not overridden.
For customers: making DigiLocker work for you
If a business asks you to share documents through DigiLocker, a few things make it go smoothly:
- Make sure your Aadhaar has your current mobile number, because sign-in depends on it.
- Check that your documents appear under issued documents before you start. If one is missing, the issuer has to publish it; DigiLocker can't add it for you.
- Read what the business is asking for on the consent screen, and share only that.
- If a name difference blocks a fetch, the correction happens with the issuer or in Aadhaar, not in DigiLocker.
Go deeper
Official sources
- MeitY / NeGD — DigiLocker 'Ask our Experts' answers (18 Oct 2024)Issued vs uploaded (Drive) sections; issued documents at par with originals when used electronically; name must match Aadhaar; consent and access logging; gateway doesn't store data; banking documents; passport not integrated; access from abroad; optional for citizens.
- DigiLocker — About DigiLockerRule 9A of the IT (Preservation and Retention of Information by Intermediaries Providing Digital Locker Facilities) Rules, 2016, notified 8 Feb 2017.
- RBI — Master Direction – Know Your Customer (KYC) Direction, 2016 (as amended)Definition of 'equivalent e-document', including documents issued to the customer's digital locker account (inserted 9 Jan 2020).
Last reviewed . Examples, amounts and screens marked illustrative are not Peneu figures.
Questions about your own payment setup?
Talk to PeneuRelated reading

The Merchant Onboarding Checklist
A printable checklist for getting approved by a payment provider quickly: documents by business type, website pages reviewers look for, bank account checks, and what to have ready before go-live.

What Is AePS? How Aadhaar Enabled Payments Work
AePS lets anyone with an Aadhaar-linked bank account withdraw cash or check a balance at a local banking agent, using a fingerprint instead of a card or PIN. How a transaction flows, who is involved, how it compares with ATMs and UPI, what happens when it fails, and how to protect yourself.
