What they may do · DPDP §6(4)
What DigiLocker does with your data
A 2017-era government policy predating the DPDP Act: it says it won't sell your data, but permits sharing with other organisations on a good-faith legal, fraud or safety belief — and says nothing at all about retention, AI or advertising.
-
Shares your data with partners
Passed to group companies, advertisers or analytics firms you never chose.
What this costs you. Your number and habits travel to companies you have never heard of and never agreed to. This is the step where the spam calls start.
Show me where they say that
DigiLocker’s own policy says “The personal and usage information, as collected may be shared with other Organizations, if Ministry of Electronics and Information Technology have a good faith belief that access, use, preservation or disclosure of the information is reasonably necessary to: Meet any applicable law, regulation, legal process or enforceable Government request; Detect, prevent or otherwise address fraud, security or technical issues as well as investigation of potential violations; Protect against harm to the rights, property or safety of DigiLocker System, other users or the public as required or permitted by law.”
Our summary personal and usage information may be shared with other organisations where MeitY forms a good-faith belief that disclosure is reasonably necessary for legal compliance, fraud/security handling, or protecting rights and safety.
What the policy does not mention
These are uses DigiLocker’s policy is silent on. Silence is not a promise — it means the document does not say, and we do not infer either way.
- Builds an advertising profile of you
- Follows you onto other websites and apps
- Keeps your records long-term
- Processes your face or other biometrics
- Trains AI models on your content
DigiLocker is one app. How many are on your phone?
Most people carry twenty to forty. Add yours and see the total in one screen — how many share your data, profile you for ads, or follow you across the web. Then take it back from all of them at once.
Manage my data with Saaph.in →Free to check · no account needed · built in India for the DPDP Act
Questions
What does DigiLocker do with my personal data?
According to DigiLocker's own privacy policy, read on 2026-08-14, it discloses 1 of the six uses we track: shares your data with partners.
Can I withdraw my consent from DigiLocker?
Section 6(4) of India's Digital Personal Data Protection Act 2023 gives you the right to withdraw consent for processing you agreed to. The Act's substantive provisions commence in stages up to May 2027, so a request made now asks for voluntary compliance and puts the date on record. Processing a company carries out under a legal obligation — such as KYC records the RBI requires — cannot be withdrawn.
Every use above is one DigiLocker declared in its own published privacy policy, which we
read on 2026-08-14. Quotes are verbatim; the summary beside each one is ours
and is labelled as ours. Nothing here is inferred.
Saaph.in is a DPDP consent and request management platform operated by Ronin Works
Private Limited. It is a communication facilitator, not your legal or authorised
representative. The DPDP Act 2023 commences in stages up to May 2027, so a request
made today asks for voluntary compliance and records the date you asked.
Our privacy policy