If you run a hotel, homestay or guest house in India, the Aadhaar rules for hotels have changed more in the last eighteen months than in the previous eight years. Guests now arrive at reception having watched a reel telling them that handing over an Aadhaar photocopy is illegal and quite often they are not entirely wrong. At the same time you still have a police register to maintain and an inspector who may walk in on a Sunday evening. This guide explains what the law requires in 2026 and how to run a compliant check-in desk.
The short version is this. You are legally obliged to verify the identity of every guest and to maintain a register. You are not obliged to collect Aadhaar specifically, you cannot make Aadhaar the only acceptable document, and the practice of photocopying or scanning the full Aadhaar card into a drawer or a shared folder is on its way out. What replaces it is a set of verification methods that confirm identity without leaving a copy of the twelve digit number in your possession. Properties that make this shift early will avoid a fairly painful correction later, and will also find that guests stop arguing at check-in.
Table of Contents
What Changed in the Aadhaar Rules for Hotels, and When
Four separate developments landed in quick succession, and because they came from four different directions most operators only noticed one or two of them. Taken together they rewrite the Aadhaar rules for hotels and how identity verification works at an Indian front desk. It is worth understanding the sequence, because when a guest quotes a rule at you it helps to know which rule they are actually talking about and whether it applies to your property. Here is the timeline in plain order, with the dates that matter for your compliance calendar.
- January 2025: The Aadhaar Authentication for Good Governance (Social Welfare, Innovation, Knowledge) Amendment Rules, 2025 were notified. For the first time these gave private entities, hospitality included, a formal route to perform Aadhaar authentication, but only after applying through the Aadhaar Good Governance Portal and receiving approval.
- 1 September 2025: The Immigration and Foreigners Act, 2025 came into force and repealed the Foreigners Act 1946, the Registration of Foreigners Act 1939, the Passport (Entry into India) Act 1920 and the Immigration (Carriers’ Liability) Act 2000. Form C became Form III.
- 13 November 2025: The Digital Personal Data Protection Rules, 2025 were notified. Substantive obligations take effect from 13 May 2027, which is your real deadline for getting guest data handling in order.
- December 2025: UIDAI moved to regulate private sector Aadhaar verification. Entities that verify Aadhaar are expected to register as an Offline Verification Seeking Entity through ovse.uidai.gov.in and to use approved flows such as offline QR checks or API based authentication. A formal prohibition on private entities collecting and storing Aadhaar photocopies has been announced but has not yet been notified.
- 30 April 2026: UIDAI formally recognised Aadhaar Verifiable Credentials shown or shared through the new Aadhaar app as a legally valid way of establishing identity.
- 12 June 2026: The Federation of Hotel and Restaurant Associations of India issued an advisory encouraging member properties to adopt the app based facility for guest check-in.
Why the Aadhaar Rules for Hotels Never Made It Mandatory
This is the part that surprises most owners, so it is worth being precise. Section 7 of the Aadhaar Act, 2016 permits Aadhaar to be made mandatory only for subsidies, benefits and services funded from the Consolidated Fund of India. A hotel room is not a subsidy, a benefit or a government service. The Supreme Court reinforced this boundary in its 2018 Aadhaar judgment, striking down the provision that had allowed private companies to demand Aadhaar authentication. What follows is straightforward. A private accommodation provider may accept Aadhaar if a guest chooses to offer it, but cannot require it as the sole acceptable identity document, and cannot refuse a room to a guest who offers a valid alternative.
Section 29(4) of the same Act adds a further restriction that many properties overlook. It prohibits publishing, displaying or posting an Aadhaar number publicly. A register left open on the reception counter where the next guest can read the previous guest’s Aadhaar number sits uncomfortably close to that line. So does a WhatsApp group where the front office team forwards ID images to the owner. These are not theoretical risks. They are the exact patterns UIDAI has repeatedly warned about, and they will become considerably more expensive once the DPDP framework is fully in force.
What You Must Collect Versus What You May Collect
The confusion around the Aadhaar rules for hotels comes from collapsing two separate obligations into one. Your statutory duty is to verify identity and record prescribed particulars in a register. Your duty is not to accumulate documents. Once you separate the act of verification from the act of retention, the correct workflow becomes obvious and a lot of the risk disappears. The table below sets out the split as it applies to a domestic guest at an ordinary hotel or homestay, leaving aside restricted areas and foreign nationals, which are covered further down.
| Activity | Position in 2026 |
|---|---|
| Verifying a government photo ID at check-in | Required |
| Recording name, address, ID type and check-in and check-out dates | Required |
| Insisting on Aadhaar and refusing all other IDs | Not permitted |
| Accepting Aadhaar when the guest volunteers it | Permitted |
| Retaining a full unmasked Aadhaar photocopy or scan | Being phased out, avoid |
| Accepting masked Aadhaar or the QR code | Recommended |
| Accepting Aadhaar app verifiable credentials | Recognised since 30 April 2026 |
| Performing Aadhaar API authentication yourself | Only with UIDAI and MeitY approval |
| Storing the twelve digit number in plain text | Not permitted |
| Using guest ID data for marketing | Not permitted |
The Four Compliant Ways to Verify Aadhaar
If a guest does choose to present Aadhaar, there are four methods that keep you on the right side of the current Aadhaar rules for hotels. They differ in cost and in how much technology you need at the desk, so pick the one that suits your property size. A six room homestay in the hills does not need the same setup as a hundred room city hotel, and nobody expects it to. What matters is that whichever method you pick, you end up with proof that you verified identity and you do not end up holding an unmasked copy of the card.
1. Masked Aadhaar
The guest downloads a version of the card from the UIDAI website in which the first eight digits are hidden and only the last four are visible, along with the name, photograph and address. This is the simplest option and it needs no equipment beyond what you already have. It satisfies your register requirement because you are recording the ID type and a partial reference, and it removes the single biggest liability in your files, which is a pile of full Aadhaar numbers sitting in a cupboard. Train your reception staff to ask for masked Aadhaar by name, because many guests do not know it exists.
2. The QR Code on the Aadhaar Letter
Every Aadhaar letter and PVC card carries a secure QR code that contains the holder’s name, photograph, address and a masked number, digitally signed by UIDAI. Scanning it with the free mAadhaar or UIDAI QR reader application confirms in a couple of seconds that the document is genuine and has not been edited, which is more than a photocopy has ever told you. This is a real security upgrade rather than a compliance chore, because forged Aadhaar photocopies are common and a scanned QR simply will not validate if the document has been tampered with.
3. Offline e-KYC XML
The guest generates a password protected XML file from the UIDAI portal and shares it with you along with the share code. You verify the digital signature, extract only the fields you need for the register, and discard the rest. This suits properties that already collect documents before arrival and want a clean audit trail without becoming an authentication agency. It takes slightly more effort to explain to a guest than masked Aadhaar, so it works best when your booking confirmation carries a short instruction with a link, rather than being sprung on the guest at the front desk.
4. The Aadhaar App and Verifiable Credentials
This is where the whole system is heading and it is worth preparing for now. Since 30 April 2026 a guest can present identity through the new Aadhaar app, sharing only the specific fields required rather than the whole document, and UIDAI treats this as legally valid proof of identity. The FHRAI advisory of 12 June 2026 encourages properties to adopt it for check-in. For you the attraction is obvious. You receive a signed confirmation of identity, you retain no document at all, and the guest leaves the desk in a better mood than they would have after an argument about photocopies.
How to Check In a Guest Without Taking an Aadhaar Photocopy
This is where the Aadhaar rules for hotels become a practical workflow rather than a legal debate. The following process works for a property of any size and requires no special hardware beyond a smartphone at reception. It is written for a domestic guest. Run through it once with your front office team, print it, and stick it behind the desk where it can be seen. The objective is that every arrival follows the same seven steps, so that when an inspection happens your register is consistent from the first entry of the year to the last, which is precisely what inspectors look for.
A seven step check-in process for Indian hotels and homestays that verifies guest identity without retaining an Aadhaar photocopy.
Total Time: 5 minutes
Set the expectation at booking
Your confirmation message should state that a government photo ID will be verified at check-in, list the documents you accept, and mention that masked Aadhaar is welcome. Most disputes at the desk are really a failure of communication two weeks earlier.
Offer a pre-arrival upload
Send a secure link so the guest can submit their chosen document in advance. This shortens the arrival and gives you time to spot a problem while it can still be fixed calmly.
Ask which ID the guest prefers
Do not name Aadhaar first. Ask for a government photo ID and let the guest choose. This single change of phrasing removes most of the friction, because the guest feels they have been given an option rather than a demand.
Verify the original in person
Look at the physical or digital document, match the photograph to the person standing in front of you, and where possible scan the QR code to confirm the document is genuine. A pre-arrival upload never replaces this step.
Record only the prescribed fields
Enter name, permanent address, ID type, a masked or partial ID reference, check-in date and time, check-out date and room number. Do not copy the full Aadhaar number into the register.
Register every adult separately
If two or more unrelated adults are checking in, each one needs an individual entry with their own verified ID. Listing companions under the primary guest is one of the most commonly flagged errors.
Secure the record immediately
A physical register goes into a locked drawer when unattended. A digital register sits behind access control with an edit log. Either way it should not be visible to the next guest at the counter.
When a Guest Refuses to Share Aadhaar
This conversation now happens several times a week at busy properties, and the way your staff handle it decides whether it ends in thirty seconds or in a review. The important thing for your team to understand is that the guest is often partially correct, so arguing the point is a losing strategy. The guest is right that they cannot be compelled to give Aadhaar. They are wrong if they conclude that they need not give any identification at all. Separating those two propositions calmly is the entire skill, and it is easily taught.
“You are absolutely right that Aadhaar is not compulsory, sir. We do need to verify one government photo ID for the register, which is a legal requirement for every property in India. A driving licence, voter ID or passport works perfectly well. If you would prefer to use Aadhaar, a masked version is completely fine and we will not keep a copy of the full number.”
If the guest declines to produce any identification at all, you cannot accommodate them. This is not a matter of discretion or customer service judgment, and your staff should not be left to negotiate it on their own at eleven at night. Providing a room without verifying identity puts the property in violation of state lodging regulations and exposes you directly if anything subsequently happens on the premises. Make it clear to your team that refusing in this situation is the correct and expected action, and that you will back them.
Documents You Should Accept
Widening the list of acceptable documents is the cheapest single improvement you can make, because it defuses the Aadhaar argument before it starts. Keep a small laminated card at reception showing exactly what is acceptable, so that a new staff member on their second shift is not making the decision from memory. The distinction that matters is between documents issued by a government authority and documents issued by a private organisation, and it is the second category that repeatedly causes problems during inspections.
- Accept: passport, driving licence, voter ID card, masked Aadhaar, Aadhaar app verifiable credential, and government service identity cards.
- Do not accept: PAN card, since it carries no address, private company employee cards, private college or coaching institute cards, credit or debit cards, and utility bills on their own.
Foreign Guests: Aadhaar Does Not Enter the Picture
The Aadhaar rules for hotels do not apply to foreign nationals at all, and it is important that your staff do not blur the two workflows. A foreign guest must produce a passport, together with a valid visa where one is required. Note the exceptions your team will actually meet: an Overseas Citizen of India holder travels on a passport plus an OCI card rather than a visa, and Nepalese nationals do not require a visa. Both must still be recorded and reported. The reporting obligation now sits under the Immigration and Foreigners Act, 2025 and Rule 17 of the Immigration and Foreigners Rules, 2025, both in force since 1 September 2025.
Form III, previously called Form C, is now submitted electronically through the FRRO portal at indianfrro.gov.in or the Indian Visa Su-Swagatam mobile application, rather than carried to the local police station. The twenty four hour clock runs from actual arrival, not from midnight, with no relaxation for weekends or public holidays. You must also report the guest’s departure, which is the step small properties most often miss, and preserve the submitted records for at least one year. Read our fuller walkthrough of the register in the Guest ID Compliance guide.
Storage, Retention and Deletion
Under the Digital Personal Data Protection Act, 2023 and the Rules notified on 13 November 2025, a property that holds guest identity data digitally is a data fiduciary. That brings four obligations that are easy to state and easy to neglect. Collect only what the law requires. Use it only for the purpose you collected it for. Keep it only as long as you need it. Delete it after that, and be able to show that you did. Substantive provisions bite from 13 May 2027, which sounds distant but is roughly one renewal cycle away for most software contracts.
In practice this means guest ID data belongs in an access controlled system with an edit log, not in a WhatsApp group, a personal Google Drive folder or the reception computer’s desktop. Retention rules differ by source. Form III submissions for foreign guests must be preserved for at least one year from the date of submission under the Immigration and Foreigners Rules, 2025, while register retention for domestic guests varies by state, so check your own state’s requirement rather than assuming. Whatever period you settle on, make the deletion automatic, because manual deletion policies are almost never carried out once the property gets busy.
Penalties
The exposure comes from three directions and they can stack, which is why treating this as a paperwork nuisance is a mistake. Under the DPDP Act, penalties for failure to take reasonable security safeguards run up to two hundred and fifty crore rupees, with other breaches attracting proportionately lower but still significant amounts. Under state police and lodging house acts you face fines, licence suspension and closure orders. Under the Immigration and Foreigners Act, failure to submit Form III within twenty four hours of arrival or departure attracts a penalty reported at fifty thousand rupees per case.
For a small property the realistic worst case is rarely the headline fine. It is having the premises sealed while an investigation runs, losing several weeks of bookings in peak season, and picking up a news mention that follows your property name in search results for years. Set against that, moving to masked Aadhaar and a proper digital register is an afternoon of work. The asymmetry here is unusually stark, which is the main argument for doing it before you are asked to.
Six Aadhaar Rules for Hotels Mistakes That Show Up Repeatedly
- Demanding Aadhaar and nothing else. Still the single most common breach, and now the most likely to be challenged by the guest.
- Keeping full photocopies in a file. A stack of unmasked Aadhaar copies in an unlocked cupboard is the worst combination of no compliance benefit and full liability.
- Forwarding ID images on WhatsApp. Convenient, and a clear breach of purpose limitation and security obligations once DPDP is fully in force.
- Registering only the primary guest. Every adult needs their own verified entry, whatever the booking said.
- Assuming platform verification counts. A verified badge on a booking platform satisfies that platform, not Indian law. Your obligation is independent.
- Not updating the register when a stay is extended. An inaccurate departure date is a reliable way to attract further questions during an inspection.
How OpenStays Handles Guest ID

OpenStays was built for Indian properties, so the guest ID module follows the Aadhaar rules for hotels as they actually apply here rather than a generic global template. Hosts can collect identity documents before arrival through a secure link sent with the booking confirmation, which means the register is largely complete before the guest reaches the gate. The system supports multiple document types instead of pushing Aadhaar, flags foreign guests automatically so that Form III is not forgotten, and exports the register in the format authorities ask for. Records sit behind access control with an edit log rather than in a shared folder.
We are honest about the limits. Direct FRRO integration is still in progress, restricted area requirements in places such as Spiti and the Andamans need steps beyond what any software automates, and Aadhaar app credential acceptance is something we are actively working on as the ecosystem settles. For the ordinary case of a domestic guest and an occasional foreign one, the compliance work happens as part of taking the booking rather than as a separate chore. You can try it for a year and see whether it fits the way your property actually runs.
Frequently Asked Questions
Is it illegal for a hotel to take a photocopy of an Aadhaar card?
It is not automatically illegal today, but it is strongly discouraged and the direction of regulation is clearly against it. UIDAI has moved to regulate private sector verification, with entities expected to register as an Offline Verification Seeking Entity and to use approved flows such as QR verification or API based authentication. A formal ban on private entities storing Aadhaar photocopies has been announced but is not yet notified. Retaining the full unmasked number also creates avoidable exposure under the Aadhaar Act and the DPDP framework. The safe position for any property is to accept masked Aadhaar, verify the QR code, and retain no copy of the full number.
Can a hotel refuse a booking if the guest will not give Aadhaar?
You cannot refuse solely because the guest declines Aadhaar, since Aadhaar cannot lawfully be made the only acceptable document by a private business. You can and indeed must refuse if the guest declines to produce any valid government photo identification at all, because accommodating an unidentified guest breaches state lodging regulations and leaves the property exposed. In practice, offering the guest a choice of passport, driving licence or voter ID resolves almost every instance of this without any confrontation at the desk.
What is masked Aadhaar and is it acceptable at check-in?
Masked Aadhaar is an official version downloadable from the UIDAI website in which the first eight digits of the number are hidden and only the last four remain visible, alongside the name, photograph and address. It is a genuine UIDAI issued document, not a workaround, and it is perfectly acceptable for hotel check-in. It gives you everything the register requires while removing the part of the data that creates the most risk if your records are ever lost, stolen or accessed by someone who should not have them.
Do the Aadhaar rules for hotels apply to a small homestay?
Yes, in full. There is no room count threshold that exempts a property from identity verification, register maintenance or foreign guest reporting. A two room homestay taking paying guests is a lodging house in the eyes of the law regardless of how the booking platform describes it. The compliance burden is genuinely lighter for small properties in terms of volume, but the obligations themselves are identical, and the foreign guest reporting requirement in particular applies from your very first international booking.
My guest booked through an OTA that verified their identity. Do I still need to check?
Yes, without exception. Verification carried out by a booking platform satisfies that platform’s internal policy, not your statutory obligation as an accommodation provider in India. The register requirement sits on the property, not on the intermediary, and an inspector will not accept a platform badge as a substitute for a register entry. Treat every arrival as requiring independent verification, whatever channel the booking came through, and make sure your staff understand that the platform’s checks have no legal bearing on yours.
How long should we keep guest ID records?
Retention requirements vary by state and there is no single national figure, which is a genuine source of confusion. Many legal practitioners advise retaining records for several years to cover civil liability windows, while the DPDP framework pushes in the opposite direction by requiring deletion once the purpose is served. The workable answer is to identify your own state’s minimum, adopt it as policy, write it down, and automate the deletion so that it actually happens rather than depending on someone remembering during a quiet week.
In Summary
The Aadhaar rules for hotels in India have moved decisively from collecting documents towards verifying identity, and properties that understand this distinction will find the next two years much easier than those that do not. Stop asking for Aadhaar by name, widen the list of documents you accept, move to masked Aadhaar and QR verification, keep your register in a system with access control and an edit log, and file Form III at check-in rather than the following morning. None of this is expensive or technically difficult, and all of it removes risk that currently sits squarely on you.
The deadline that matters is 13 May 2027, when the substantive provisions of the DPDP framework take effect. That is enough time to make the change calmly and not enough time to ignore it. If you want the compliance workflow built into your booking process rather than bolted on afterwards, that is exactly the problem OpenStays was built to solve. For further reading, UIDAI publishes current guidance at uidai.gov.in and the full text of the Immigration and Foreigners Act, 2025 is available on India Code.
This guide is an informational resource for accommodation operators in India and does not constitute legal advice. Regulations vary by state and continue to evolve, particularly around Aadhaar verification methods. Please consult a qualified legal professional for advice specific to your property and jurisdiction.