MeitY's NeGD is outsourcing the expansion of DigiLocker into private sectors like finance and education, according to an RFE published September 21. This moves DigiLocker beyond a citizen utility to a core piece of private enterprise infrastructure, setting a new bar for digital identity and document exchange. For fintechs, ed-techs, and health-techs, this means grappling with both a new government-backed competitor and a potential mandate for compliance.
How We Got Here
DigiLocker has existed since 2015 as a secure cloud for government-issued documents. The push into private sectors follows the recent passage of the Digital Personal Data Protection (DPDP) Act, 2023, which places new obligations on data fiduciaries.
The Numbers
- NeGD seeks to outsource the identification of use cases and partners, as well as the technical integration work.
- Pre-listed use cases include KYC for lending, admission processing for education, and insurance claims in health.
- Empanelled agencies must comply with DPDP Act and CERT-In directions, and cannot store, cache, or profile user data.
- Agencies are mandated to host all development, test, and support infrastructure within India.
- The RFE prevents vendor lock-ins by requiring agencies to hand over documentation and destroy confidential data upon contract termination.
What Happens Next
🇮🇳 Why This Matters for India
For Bangalore fintech founders, this could mean an easier path to digital onboarding, but also mandates to integrate a government-controlled identity layer, potentially impacting their existing tech stack and compliance costs.
The Take
This is less about "digital empowerment" and more about MeitY extending its digital public infrastructure mandate deep into the regulated private sector. Identity verification startups will either pivot to become integration partners or face direct competition from government-mandated solutions.
Source:
MediaNama ↗