Science & TechnologyGS325 September 2026
Digi Yatra to Pilot Face-Based Boarding for International Departures at Five Airports, Seeks EU Interoperability
Open in the app — quiz, notes, Mistake Vault हिंदी में पढ़ें
The news
New Delhi. Digi Yatra, the facial-recognition system that lets domestic passengers pass airport gates without paper ID, is preparing to extend its biometric travel system to international departures and is working on interoperability with the European Union’s equivalent framework, The Hindu reports. Facial recognition here means a camera at the gate compares a traveller’s live face with a photograph already verified and linked to the boarding pass. A pilot for international departures will run between October and December at Bengaluru, Delhi, Hyderabad, Kochi and Mumbai airports, Digi Yatra CEO Suresh Khadakbhavi told the paper. It will test electronic passport-based enrolment: a traveller scans an e-passport — a passport carrying a chip that stores the holder’s data and photograph — and verifies identity with a selfie. The resulting digital credential will be stored on the passenger’s phone and linked to a boarding pass that the airline issues before the passenger reaches the terminal. Air India and IndiGo are expected to join; the trial covers Indian and foreign nationals departing on international flights. It will first be used at entry points and security checkpoints; immigration stays out of phase one because of its regulatory and operational sensitivity. The trial will gather passenger feedback before any wider rollout, including possible domestic use by foreign travellers. Digi Yatra is also working on interoperability with the EU Digital Identity, which lets EU citizens, residents and businesses store and share verified identity data and official documents. Through their APTITUDE consortium, the platform aims to enable cross-border sharing of travel credentials within three to six months; the longer-term objective is for a passenger flying from India to Europe to share verified credentials with both the departure and destination airports. The effort is part of a broader “self-sovereign identity” push — a model in which the individual, not a central database, holds and chooses to share verified credentials — under the International Air Transport Association’s One ID initiative for contactless air travel. Domestically, Digi Yatra is active at 39 airports and should reach 64 by March 2027, per the Civil Aviation Ministry. The report says face recognition is “mandatory” at terminal entrances and security checkpoints where the system is available, but face-based boarding remains uneven across airports and airlines; officials attribute the inconsistency to investment decisions, infrastructure gaps and differing operational priorities. The syllabus link is GS3 on IT awareness and GS2 on e-governance and privacy.
The chain in one line: Airports face congestion at entry and security gates → the Civil Aviation Ministry backs a biometric boarding system run by a not-for-profit company owned by AAI and five airport operators → Digi Yatra goes live domestically in December 2022 and spreads to 39 airports → the DPDP Act, 2023 sets consent and security duties for handlers of personal data → Digi Yatra now pilots e-passport enrolment for international departures and seeks credential-sharing with the EU Digital Identity framework
Static syllabus linkage
- Digi Yatra is run by a not-for-profit company, not by a government department. The Digi Yatra Foundation was set up in 2019 as a joint venture company under Section 8 of the Companies Act, 2013, which governs companies formed to promote objects such as commerce, science or social welfare that apply their income to those objects and pay no dividend. Per a PIB release of the Civil Aviation Ministry, the Airports Authority of India holds 26% of its shares and the operators of Bengaluru, Delhi, Hyderabad, Mumbai and Kochi airports hold the remaining 74% equally. The Ministry describes it as a decentralised, mobile wallet-based identity management platform. Because it is a company rather than a department, questions have been raised about whether it is fully answerable under the Right to Information Act, 2005.
- The DPDP Act, 2023 governs how Digi Yatra may use a face. Under the Digital Personal Data Protection Act, 2023, personal data may be processed on the basis of the data principal’s consent, which must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action, or for certain legitimate uses listed in the Act. The data fiduciary must use the data only for the stated purpose, erase it when that purpose is served, and protect it with reasonable security safeguards. A data principal may withdraw consent as easily as it was given. Unlike the European law, the Act does not create a separate category of sensitive personal data, so biometric data gets no higher tier of protection in the statute itself.
- Puttaswamy (2017) requires any intrusion into privacy to be proportionate. In Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), a nine-judge bench of the Supreme Court held that privacy is a fundamental right protected under Article 21 and Part III. Any State intrusion must satisfy legality (a law must exist), a legitimate aim, proportionality between the measure and the aim, and procedural safeguards against abuse. In the Aadhaar judgment of 2018, the Court applied this test to biometric identification and struck down certain uses while upholding the core scheme. A facial-recognition system backed by the state must pass the same test, and voluntariness is one of the strongest arguments in its favour.
- The EU’s rules and the aviation bodies set the terms for cross-border identity. The EU General Data Protection Regulation (GDPR) treats biometric data used to identify a person as a special category whose processing is prohibited except under listed conditions such as explicit consent. Under Article 45 of the GDPR, the European Commission may adopt an adequacy decision finding that a non-EU country offers an essentially equivalent level of protection, allowing data to flow freely; India has no such decision. The International Civil Aviation Organization (ICAO), a UN specialised agency created by the Chicago Convention of 1944 and headquartered in Montreal, sets the global standard for machine-readable and electronic passports in its Document 9303. The International Air Transport Association (IATA), whose One ID initiative Digi Yatra is following, is an industry association of airlines, not an inter-governmental body.
Why UPSC loves this
- Digital public infrastructure and privacy are paired themes in GS2 and GS3. UPSC has asked about the right to privacy after Puttaswamy, about Aadhaar, and about the risks and benefits of facial recognition in governance. Digi Yatra is the live example of a biometric system run through a company rather than a statute, which is exactly the kind of institutional question Mains examiners like to probe.
- Prelims tests which body does what. Questions distinguishing ICAO from IATA, asking under which Act a not-for-profit company is registered, or what the DPDP Act means by a data fiduciary are likely. Learn the pairs: ICAO sets passport standards and is a UN agency; IATA is an airline trade body that runs One ID.
- Cross-border data flows are a trade and foreign-policy question. Questions on India–EU relations and on data localisation can use this story, since interoperability with the EU Digital Identity will test whether Indian protections are accepted as adequate by European regulators. It links GS2 bilateral relations to GS3 technology.
Prelims nuggets
- The Digi Yatra Foundation is a not-for-profit company registered under Section 8 of the Companies Act, 2013, in which the Airports Authority of India holds 26% of the shares.
- Under the Digital Personal Data Protection Act, 2023, consent for processing personal data must be free, specific, informed, unconditional and unambiguous, and may be withdrawn by the data principal.
- In Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), a nine-judge bench of the Supreme Court held the right to privacy to be a fundamental right protected under Article 21 and Part III of the Constitution.
- The International Civil Aviation Organization, a UN specialised agency established under the Chicago Convention of 1944, sets the global specifications for machine-readable and electronic passports.
- The International Air Transport Association, which runs the One ID initiative for contactless travel, is a trade association of airlines and not an inter-governmental organisation.
- Under Article 45 of the EU General Data Protection Regulation, the European Commission may decide that a non-EU country ensures an adequate level of data protection, permitting personal data transfers without further authorisation.
Analysis
- Holding the credential on the phone is the design choice that makes this defensible. The strongest privacy criticism of biometric systems is the central honeypot: one database of faces that can be breached or repurposed. A credential stored on the traveller’s phone and shared only at the gate is the self-sovereign model, and if the design really keeps no central store, most of that risk falls away. The catch is that the promise is architectural and can be changed quietly by a software update. That is why the design should be written into binding rules and audited, not left to the goodwill of a company.
- Keeping immigration out is prudent, but it also limits the gain. Immigration is where a traveller’s identity is checked against watch lists by the state, and mixing that with a private company’s credential would raise serious questions of legality under the Puttaswamy test. Leaving it out of the first phase is therefore wise. But the queues that frustrate international passengers are largely at immigration, so the pilot covers the easy parts of the journey. The real test of the EU link will come only when a border authority, not an airport operator, is asked to rely on the credential.
- Interoperability with Europe is really a test of India’s data law. The EU treats biometric data as a special category and allows transfers abroad freely only to countries it finds adequate, and India has no adequacy decision. A traveller sharing credentials voluntarily may be enough for a pilot, but a scaled system linking airports will invite scrutiny of India’s DPDP Act, especially its broad exemptions for government processing and its lack of a sensitive-data tier. The counter-view is that consent-based, user-held credentials may not need adequacy at all. Either way, the project could become a quiet lever for strengthening Indian data protection.
- “Mandatory” is the word to watch. The report says face recognition is mandatory at entrances and checkpoints where the system exists, while Digi Yatra has been sold as optional. If a manual lane remains, consent is real; if the manual lane shrinks through neglect, consent becomes a formality, which is how voluntary systems drift into compulsory ones. A proportionality analysis turns on this detail. The Civil Aviation Ministry should publish a clear rule that manual verification will always be available and equally quick.
- The governance model needs to catch up with the scale. A company owned by AAI and five airport operators is now running identity checks at 39 airports, heading to 64, and wants to plug into a foreign identity system. Section 8 status gives flexibility but weak public accountability, and a statute or at least binding rules would settle questions of RTI coverage, audit, grievance redress and liability for errors. Uneven adoption, which officials blame on investment and infrastructure gaps, also shows that without a framework the benefits depend on each airport’s commercial choices. Scale should bring statutory clarity, not just more gates.
Possible Mains question
Biometric travel systems such as Digi Yatra promise convenience but raise questions of consent, accountability and cross-border data protection. Critically examine in the light of the Digital Personal Data Protection Act, 2023 and the Supreme Court’s privacy jurisprudence. (15 marks, 250 words)
Model approach
- Introduction. State that Digi Yatra, active at 39 airports and expected at 64 by March 2027, will pilot e-passport-based enrolment for international departures at five airports between October and December and seeks interoperability with the EU Digital Identity framework.
- Body — benefits. Explain faster, contactless processing, reduced document fraud, the phone-held credential under the self-sovereign identity model, and alignment with IATA’s One ID and ICAO passport standards.
- Body — legal tests. Apply the Puttaswamy proportionality test and the DPDP Act’s consent, purpose limitation and security duties; note the absence of a sensitive-data category for biometrics and the question of whether consent is real if manual lanes shrink.
- Body — accountability and cross-border issues. Discuss the Section 8 company structure and RTI coverage, the exclusion of immigration from the pilot, and the EU’s special-category treatment of biometrics and lack of an adequacy decision for India.
- Conclusion. Conclude that the design is promising but should be anchored in binding rules that guarantee an equally fast manual option, independent audits and clear liability, so that convenience does not quietly become compulsion.
Administrator's brainstorm
You are the director of an airport joining the pilot. Several elderly passengers complain that staff pushed them towards Digi Yatra gates. What do you do?
I would issue a written instruction that Digi Yatra is optional and that manual verification must be offered without delay or pressure, and put up clear signs saying so. I would station staff at manual lanes during peak hours so that choosing them is not a penalty. Complaints would be logged and reviewed weekly. Consent that is extracted by queue length is not consent.
As a Joint Secretary in the Civil Aviation Ministry, what safeguards would you insist on before linking Digi Yatra with the EU Digital Identity?
I would require that credentials remain on the traveller’s device and are shared only with explicit consent for each journey, with no central Indian or European store of faces. I would seek an independent security audit and a data protection impact assessment made public in summary. I would ensure that the DPDP Act’s duties apply fully and that there is a grievance officer for passengers. Immigration integration would wait until a statutory basis exists.
An interview board asks: should a private not-for-profit company run a biometric identity system at public airports?
A company structure can move faster and bring in airport operators who pay for the gates, which explains why it was chosen. But identity verification is a public function, and people must be able to seek information, appeal errors and know who is liable. I would keep the operational model but add binding rules or a statute on data use, audit, RTI coverage and grievance redress. Efficiency and accountability can coexist if the rules are written down.