Any entity registered with UIDAI to verify a person's Aadhaar details offline, with consent and without ever connecting to the CIDR.
An Offline Verification Seeking Entity, or OVSE, is defined in the Aadhaar (Authentication and Offline Verification) Regulations, 2021 as any entity desirous of undertaking offline verification of an Aadhaar number holder. The defining feature is the word offline: the entity checks a person's identity against a digitally signed artefact the person supplies - a QR code, an offline e-KYC XML file, an e-Aadhaar - without querying UIDAI's Central Identities Data Repository (CIDR). No online authentication request is sent, and the verifier does not need a licensed channel into the Aadhaar database. The framework exists because of a constitutional constraint. In the 2018 Aadhaar judgment (K.S. Puttaswamy v. Union of India) the Supreme Court struck down Section 57 of the Aadhaar Act, which had let private body corporates use Aadhaar authentication. Parliament's response was the Aadhaar and Other Laws (Amendment) Act, 2019, which inserted Section 8A into the Aadhaar Act to provide for offline verification as a privacy-preserving route, and amended Section 4 so that an individual may voluntarily use their Aadhaar number to establish identity by authentication OR by offline verification. Entities apply to UIDAI in the prescribed form; registration was made compulsory for offline e-KYC and verifiable-credential verification by the Amendment Regulations of December 2025.
Type: ProcessNO CIDR CONNECTION - verification is performed locally against a UIDAI-digitally-signed artefact the resident supplies. No request goes to UIDAI's central database and no licensed authentication channel is needed
THE AADHAAR NUMBER IS NOT SHARED - the offline e-KYC XML carries name, address, photograph, gender, date of birth, a HASH of the registered mobile number, a HASH of the registered email and a reference id. Hashes let a verifier confirm a contact detail it already holds without receiving it
NO BIOMETRICS ARE SHARED - fingerprints and iris data never leave UIDAI by this route. The 2025 amendment added Offline Face Verification, in which a live facial image is matched against the Aadhaar photograph held inside the resident's own official app
CONSENT IS MANDATORY AND INFORMED - under Section 8A the entity must obtain consent, use the information only for the verification purpose, and inform the individual of alternatives to sharing Aadhaar information
NO COLLECTING, USING OR STORING THE AADHAAR NUMBER OR BIOMETRIC INFORMATION except as the Act and Regulations permit; data retained must be masked or redacted
SELECTIVE DISCLOSURE - Aadhaar Verifiable Credentials, introduced by the 2025 amendment, let the holder choose which fields to share, from minimal identity details up to name, address, date of birth and photograph
ACCOUNTABILITY - obligations under Regulation 14A include notifying the individual of verification success or failure, cooperating in fraud investigations, supporting public awareness, and reporting security breaches within 72 hours
WIDE ADOPTION - the Ministry of Electronics and IT reported in April 2026 that 100 entities had been onboarded as OVSEs within three months of rollout, spanning central and state government departments, fintechs, hospitality and event management, education and exam bodies, and background-verification firms
Frequency: Aadhaar's legal architecture is a recurring UPSC Prelims and GS-2 theme and a favourite in banking exams; OVSE specifically has been in the news since the December 2025 amendment and the 2026 onboarding wave
Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016
The parent statute establishing UIDAI, the Aadhaar number, the CIDR and the authentication framework
K.S. Puttaswamy v. Union of India (2018), the Aadhaar judgment
Upheld Aadhaar but struck down Section 57, ending private body corporates' use of Aadhaar authentication - the gap offline verification was designed to fill
Aadhaar and Other Laws (Amendment) Act, 2019
Inserted Section 8A on offline verification and amended Section 4 so identity may be established voluntarily by authentication or offline verification
Section 8A, Aadhaar Act
The operative provision: requires consent, use of information only for verification, informing the individual of alternatives, and bars collecting, using or storing the Aadhaar number or biometric information
Aadhaar (Authentication and Offline Verification) Regulations, 2021 - notified 8 November 2021
Defines OVSE, lists the permitted types of offline verification (Regulation 3A) and the obligations of an OVSE (Regulation 14A), including 72-hour breach reporting
Aadhaar (Authentication and Offline Verification) Amendment Regulations, 2025 - gazetted 9 December 2025
Restructured the types of offline verification, introduced Aadhaar Verifiable Credentials and Offline Face Verification, and made UIDAI registration compulsory for offline e-KYC or AVC verification, while exempting those merely using physical or electronic copies of Aadhaar
Aadhaar Authentication for Good Governance (Social Welfare, Innovation, Knowledge) Rules, 2020, as amended on 31 January 2025
The parallel ONLINE track - lets government and, after the 2025 amendment, non-government entities authenticate against the CIDR for notified purposes such as good governance, ease of living, preventing leakage of welfare benefits and enabling innovation, on a proposal routed through a ministry or department
Digital Personal Data Protection Act, 2023
The general consent and purpose-limitation regime within which any processing of personal data during verification must sit
Offline verification replaces a live database lookup with a digital signature. UIDAI signs a small bundle of the resident's details; a verifier can check that signature and be certain the data is genuine and unaltered without sending any query to UIDAI.
Step 1: The entity registers with UIDAI as an OVSE in the prescribed form, stating its lawful purpose. Since 9 December 2025 registration is compulsory for offline e-KYC and Aadhaar Verifiable Credential verification
Step 2: The resident generates the artefact - a digitally signed offline e-KYC XML, an e-Aadhaar, or the secure QR code on Aadhaar - through UIDAI's official channels
Step 3: The resident gives informed consent; the entity states the purpose and tells the resident what alternatives exist
Step 4: The resident shares only the fields they choose - with Aadhaar Verifiable Credentials, the disclosure can be kept to what the purpose needs
Step 5: The entity verifies UIDAI's digital signature on the artefact. A valid signature proves authenticity - no request reaches the CIDR
Step 6: Where a person-present check is needed, the entity matches the photograph, or uses Offline Face Verification against the Aadhaar photograph held in the resident's official app
Step 7: The entity informs the resident of success or failure, stores no Aadhaar number or biometric information, masks what it retains, and reports any security breach within 72 hours
| Aspect | Offline verification - OVSE | Online authentication - AUA / KUA |
|---|---|---|
| Contact with UIDAI's CIDR | None - verification is local, against a UIDAI-signed artefact the resident supplies | Yes - a live request goes to the CIDR through a licensed ASA |
| What proves authenticity | UIDAI's digital signature on the XML, QR code, e-Aadhaar or verifiable credential | UIDAI's real-time response - Yes/No for an AUA, an e-KYC payload for a KUA |
| Biometrics | Not shared; any face match happens against the photo in the resident's own app | Fingerprint, iris or face may be captured and sent for matching |
| Aadhaar number | Not shared in offline e-KYC; must not be stored; retained data masked | Submitted as part of the authentication request |
| Who may do it | Entities with a lawful purpose, on registration with UIDAI | Entities and purposes permitted under the Act and the Good Governance Rules |
| Legal basis | Section 8A (inserted 2019) and the 2021 Regulations as amended in 2025 | Aadhaar Act authentication provisions and the Good Governance Rules, 2020 as amended in 2025 |
| Typical users | Hotels, event and exam bodies, universities and school boards, employers and background-verification firms, fintechs | Banks and financial institutions, telecom operators, government departments delivering benefits |
OVSE = Offline Verification Seeking Entity - any entity desirous of undertaking offline verification of an Aadhaar number holder
One-line test: an OVSE never connects to the CIDR; an AUA or KUA does
Section 8A, inserted by the Aadhaar and Other Laws (Amendment) Act, 2019, after the 2018 Aadhaar judgment struck down Section 57
Aadhaar (Authentication and Offline Verification) Regulations, 2021, notified 8 November 2021; Amendment Regulations gazetted 9 December 2025
Types: QR code, paperless offline e-KYC, verifiable credential (AVC), e-Aadhaar, paper-based - with or without face verification
Offline XML: name, address, photo, gender, DOB, hash of mobile, hash of email, reference id - no Aadhaar number, no biometrics
Duties: informed consent, purpose limitation, inform of alternatives, store no Aadhaar number or biometrics, report breaches within 72 hours
2025 additions: Aadhaar Verifiable Credentials and Offline Face Verification; registration compulsory for offline e-KYC/AVC
100 OVSEs onboarded within three months of rollout (MeitY, April 2026); PSEB first school board, MDU Rohtak first university
Not to be confused with the Good Governance Amendment Rules of 31 January 2025, which opened ONLINE authentication to private entities
It is an entity registered with UIDAI to verify a person's Aadhaar details offline - by checking a UIDAI-signed QR code, offline e-KYC file, e-Aadhaar or verifiable credential the person supplies - without sending any request to UIDAI's Central Identities Data Repository.
Authentication is a live query to the CIDR by an AUA or KUA and may involve biometrics. Offline verification involves no contact with the CIDR: the verifier validates UIDAI's digital signature on data the resident hands over, and no biometrics are shared.
Section 8A of the Aadhaar Act, 2016, inserted by the Aadhaar and Other Laws (Amendment) Act, 2019, read with the Aadhaar (Authentication and Offline Verification) Regulations, 2021 as amended by the Amendment Regulations gazetted on 9 December 2025.
No. The offline e-KYC file carries name, address, photograph, gender and date of birth, with hashes of the registered mobile number and email and a reference id - not the Aadhaar number and not biometrics. An OVSE is barred from collecting, using or storing the Aadhaar number.
Because the Supreme Court's 2018 Aadhaar judgment struck down Section 57, which had allowed private companies to use Aadhaar authentication. In 2019 Parliament created offline verification, letting entities confirm identity with consent while keeping biometrics and the central database out of the transaction.