MeitY plans to expand DigiLocker into private sectors like finance


  • Access a copy of RFE on DigiLocker here: [pdf].

The Ministry of Electronics and Information Technology (MeitY), through its National e-Governance Division (NeGD), is intending to actively integrate DigiLocker services into private sectors like banks, insurers, educational institutions and healthcare firms, according to a Request for Empanelment (RFE) published on September 21. 

According to the document, NeGD palms to outsource the task of growing DigiLocker’s user base by identifying institutions and use cases. It will make use of the consumer citizens’ government-issued documents through DigiLocker, bringing them onto the platform, handling their technical integration. Addressig these, NeGD has invited feedback on the draft RFE from industry, prospective partners, government departments, institutions and the public, with comments. 

Some of the use cases pre-listed by MeitY: According to the document, if any company is selected, it has to work on identifying and mapping the demand side for DigiLocker’s use cases. The document already specifies some use case.

In financial sector, some of the the possible use cases could be:

  • customer KYC and onboarding for lending, account opening and insurance,
  •  income and address verification for underwriting, and 
  • Accessing documents such as Aadhaar, PAN, driving licences, voter ID, vehicle registration and insurance policies. 

In education sector,  some proposed usecases are:

  • admission and scholarship processing and 
  • verification of academic credentials using marksheets and degree certificates issued by CBSE, state boards, universities and NAD-integrated institutions.

In health sector, the use cases could be:  

  • Insurance claims processing patient registration, and 
  • verification of practitioner credentials, using Aadhaar, PAN, insurance policies and ABHA-linked documents. 

The RFE notes these are indicative only, and agencies may propose other use cases built around documents already integrated into DigiLocker.

Some of the terms defined by MeitY are:

  • DPDP obligations: The RFE places compliance obligations on empanelled agencies under the Digital Personal Data Protection (DPDP) Act, 2023 and CERT-In directions. Agencies cannot retain, store, cache, profile, or put Issued Document content to any secondary use. They must act only on the Requester’s documented instructions for the approved service.
  • Auditable logs and data localisation mandate: The agencies cannot hold production API credentials in their own name. They must keep logs preserved and auditable. They should report suspected security incidents to NeGD and CERT-In within the prescribed timelines. They are also mandated to host all development, test, and support infrastructure within India.
  • No vendor lockins: If the engagement ends, whether through exit, termination, or de-empanelment, the agency must hand over all Requester-related documentation to NeGD. The agency is also mandated to destroy confidential information and certify that destruction. The RFE also states that onboarded Requesters retain access to DigiLocker independent of the agency, and that “no vendor lock-in of any nature shall be created.”

The laste date to send responses is October 10, 2026. They have to send the responses via email to: [email protected] 

DigiLocker may soon have AI agents: In a separate tender MeitY has invited AI-capable companies to design, develop, and deploy AI-driven services, including AI agents across Digital India platforms such as UMANG, DigiLocker, and other government systems. Read more about it here. 

Also read:



Source link

Recent Articles

spot_img

Related Stories