In early 2026 India’s Finacial Intelligence Unit published updated AML and CKY guildelines for Reporting Entities Providing Services Related to Virtual Digital Assests. In short, they require that Aadhaar card data, including the ID number, facial photograph, and biometric information, be handled with strict privacy controls. Persona has implementing automated redactions to ensure all customers processing India-issued IDs mitigate risks by default.
What this means for your configuration: If you accept Indian (Aadhaar) IDs in your verification flows, the following will happen automatically:
ID images will redact the below details immediately after processing. The original unredacted version of the images will not be retained.
- Aadhaar number
- QR/barcode
- Portrait
⚠️ A hashed identifier will be stored for repeat detection and graph matching if applicable, but the raw Aadhaar number will no longer be accessible post-verification.
Biometrics: All biometric data, including the ID portrait photo, facial feature vectors, and any derived biometric artifacts, will be redacted for India ID verifications. This applies to both new and existing records. Any downstream integrations that consume biometric data from India ID verifications will no longer receive it.
Additionally, certain verification checks that require biometrics result in not_applicable since they will not have the data to make a pass / fail determination.