DigiYatra has emerged as one of India’s most visible digital identity initiatives in aviation. However, questions around facial recognition, personal data and privacy have remained an important part of the conversation around its adoption. Addressing these concerns at the GRC India AI Conclave 2026, hosted by Ampcus Cyber, Asit Kumar, CISO and Data Protection Officer, Digi Yatra Foundation, offered a straightforward explanation of the platform’s approach: DigiYatra does not retain passengers’ personal credentials in its central ecosystem.
Kumar explained that privacy has been built into DigiYatra’s architecture through a self-sovereign identity model, where the passenger remains the holder and controller of their digital credentials. The credentials are stored on the passenger’s own device rather than in a central database. The scale of DigiYatra also highlights why its approach to identity and privacy has become significant. Launched in December 2022 at Delhi, Bengaluru and Varanasi airports, the platform is now live at 38 airports, with another 27 airports targeted by 2027.
More than 24 million people have downloaded the DigiYatra app, and over 100 million passenger journeys have already been processed through the platform. DigiYatra currently operates in 11 Indian languages, with plans to expand to all 22 scheduled Indian languages. The platform can also process a passenger through an airport checkpoint in approximately five seconds. These numbers put the privacy architecture of DigiYatra at considerable scale, particularly as the platform expands across more airports and potentially towards international travellers towards the end of this year.
“We Are Not Storing Any Data in the Central Ecosystem”
Explaining the fundamental design principle behind DigiYatra, Kumar said the platform was designed to ensure that personal credentials do not become part of a central repository. “The three basic things that we talk about are a seamless journey, privacy preservation and user control. In Digi Yatra, we are not storing any data in the central ecosystem that is known. Although there are some places where data is held, it remains under the control of the user. That is called self-sovereign identity. So, privacy preservation is about the data that the user wishes to share, and with Digi Yatra, that is the control that the user has,” Kumar said.

According to Kumar, this architecture is intended to give passengers control over their identity rather than making the central platform the permanent custodian of their credentials. He explained that DigiYatra follows a three-party model comprising the holder, issuer and verifier. The passenger is the holder of the identity, DigiYatra acts as the issuer, and the airport environment performs verification when the passenger reaches the e-gate.
Passenger Remains the Holder of the Digital Identity
Kumar explained that the process begins with the creation of a digital identity from the passenger’s existing identity credentials. “In Digi Yatra, we provide the Aadhaar number and authenticate it. We download the KYC information, and the photograph is already there. We then take a selfie, and if the selfie matches to a certain extent, the Aadhaar photograph is discarded. Your photograph then becomes your digital identity, and it is stamped with a digital signature by the Digi Yatra ecosystem. That is the work of the issuer,” he said.
The important distinction, Kumar said, is what happens after that credential has been created “When the credential goes to the issuer, the data is sent to the passenger. The identity or photograph is digitally signed and sent back to the holder, who retains that identity in their wallet. Once this is done, the issuer’s role is complete. The issuer does not retain the data. In our case, we are the issuers, and we do not retain any of that data,” Kumar added.
What Happens at the Airport When Using DigiYatra?
The actual verification happens when the passenger reaches the airport gate. Kumar explained that the photograph captured at the e-gate is matched against the identity credential previously signed by the issuer. The system verifies whether the credential is genuine and whether it has been tampered with before allowing the passenger through. “The verification process takes place when a passenger stands in front of the DigiYatra gate. The passenger’s photo is captured and the identity is sent to the airport, where it is matched against the digitally signed identity credential issued by DigiYatra. If the match meets the required threshold, the gate opens. The data retained at the airport is stored only for a limited period and is purged shortly after the passenger completes the journey,” he said. Kumar described this as an example of privacy by design, with self-sovereign identity and decentralised identifiers forming the foundation of the architecture.
A key component of this architecture is the use of verifiable credentials. Kumar explained that these credentials allow identity claims to be checked cryptographically without requiring the underlying identity information to be permanently stored with the verifier. “Verifiable credentials are digital representations of claims provided by an identity or an individual, which can also be verified at runtime. They are cryptographically secure because they use digital signatures. If a forgery is detected, the system rejects it. This makes the credentials instantly verifiable and user-controlled, as users remain in control of what data they hold and what information they choose to share,” Kumar said.
The model also creates a distinction between possessing an identity and verifying it. The passenger holds the credential, while the verifier checks whether it is authentic and has not been altered. Kumar said this approach can help address a weakness in conventional physical identity verification, where a document may be presented but there is no immediate mechanism to establish whether it is genuine.
“With the help of verifiable credentials, we can achieve instant verification. This enables us to cross-check whether the identity belongs to the individual and whether it has been tampered with. The key benefits include enhanced security, reduced fraud through cryptographic verification, and a decentralised architecture,” he said. Kumar also placed DigiYatra within the wider evolution of digital identity, arguing that traditional password-based authentication is increasingly inadequate for modern digital environments.
“Digital identity matters because the traditional systems where we use passwords are not capable enough to challenge the modern needs of the systems and the technologies which are emerging. Password fatigue is also an issue, and data breaches expose billions of data annually,” he said. He pointed to growing demand for digital identity across multiple sectors, driven by both regulation and consumer expectations around privacy. Kumar cited a market estimate of $30 billion for digital identity by 2026, while approximately 5.2 billion users are expected to use digital identity services across sectors including financial services, healthcare, education and government.
Kumar also explained that the architecture separates the holder, issuer and verifier, allowing these entities to operate independently rather than placing identity control with a single central authority. “First, with Aadhaar, all three entities are supposed to work independently of each other. If any one of the systems or entities goes down, the other two entities continue to function. So, there is a decentralised architecture but there is no centralised control,” he said. This separation is central to DigiYatra’s approach to identity management, particularly as the platform moves towards interoperability with other digital identity systems.
DigiYatra Prepares for International Travellers
DigiYatra is also expanding its work on verifiable credentials to support international identity documents. Kumar said the foundation has developed a verifiable credential mechanism for Type 2 passports, using the digitally signed information contained in the passport’s Machine Readable Card (MRC) chip. “The MRC chip is actually signed by ICAO, the International Civil Aviation Organization, and the public can directly provide it to certain registered organisations. We have got that, and we have done trials with this. We have done trials with IndiGo, and the live trials are going on as we are talking here,” Kumar said.

The objective is to create a digital identity mechanism that can work with international biometric standards and eventually support foreign travellers using the DigiYatra ecosystem. DigiLocker Integration Could Expand Verifiable Credentials Another area Kumar highlighted was the potential integration of verifiable credentials with DigiLocker. “DigiLocker has 170 billion pieces of user data on board. So, the direct extraction or retrieval of those users with verifiable credentials in the digital wallet is going to have a major impact,” he said. The broader objective is to move towards an identity ecosystem where credentials can be securely issued, held and verified without requiring every organisation in the chain to maintain copies of the underlying personal information.
For DigiYatra, the challenge ahead is therefore not only scaling the number of airports and passengers. It is also demonstrating that digital identity can operate at national scale without turning personal credentials into a centralised data repository. As Kumar’s remarks at the GRC India AI Conclave highlighted, the core proposition is built around self-sovereign identity, selective disclosure, cryptographic verification and user control.















