MeitY just published an RFE to outsource DigiLocker's expansion into private sectors. The initiative shifts MeitY's role from sole platform builder to a demand-side facilitator, pushing a government identity layer into banking, healthcare, and education. For startups and larger tech firms, the RFE opens up a new public-private integration market, but with strict data compliance.
How We Got Here
MeitY's National e-Governance Division (NeGD) published the Request for Empanelment (RFE) on September 21, inviting bids for agencies to drive this integration. DigiLocker, launched in 2015, allows citizens to store and access government-issued documents digitally, aiming to reduce physical paperwork.
The Numbers
- Agencies will identify and map demand-side use cases across finance (KYC, lending), education (admissions, scholarships), and health (insurance claims, patient registration).
- The DPDP Act, 2023, and CERT-In directions mandate strict data handling: no retention, storage, caching, profiling, or secondary use of issued documents by empanelled agencies.
- All development, test, and support infrastructure for the integrated services must be hosted within India, ensuring data localisation.
- Agencies cannot hold production API credentials in their own name and must provide auditable logs for all transactions.
- MeitY ensures no vendor lock-in; agencies must hand over all Requester-related documentation and certify destruction of confidential information upon exit.
What Happens Next
🇮🇳 Why This Matters for India
For FinTech founders in Mumbai, HealthTech startups in Hyderabad, and EdTech platforms in Bangalore, this is a massive greenfield opportunity to build on national digital public infrastructure.
The Take
The unstated goal here is to push reluctant regulated entities into digital identity standards, making the DPDP Act real for everyone, fast. The compliance burden on banks and insurers will be immense, but the upside for onboarding efficiency is hard to ignore.
Source:
MediaNama ↗