TL;DR: One lost phone takes down Aadhaar OTP, your bank, UPI, DigiLocker, the income tax and GST portals, EPFO and every email reset, because your SIM is the second factor for all of them. The order matters. In the first hour, block the SIM with your operator, block UPI and cards through the bank’s 24x7 line, report the IMEI on the Sanchar Saathi CEIR portal, and lock your Aadhaar biometric on UIDAI. In the first day, file the right kind of police report, since a lost-article report and an FIR are not the same document and portals ask for a specific one. Get a duplicate SIM with the same number within the week, since that single card unlocks nearly everything else, then work through each service. How fast you report an unauthorised transaction decides your liability under RBI’s rules, and that is the single most valuable fact in this piece.
On this page
- Why one phone takes down your entire identity
- The first hour
- The first day
- The first week: the duplicate sim is the master key
- Getting each service back
- Service by service: what breaks and how you fix it
- Who pays if money moved: the RBI liability framework
- When the bank refuses: the banking ombudsman
- Sim swap fraud and the operator’s share of blame
- DPDP Act rights when a service will not restore access
- Consumer forum for deficiency of service
- What people actually go through
- Prevention: build the ladder before you need it
- Frequently asked questions
Why one phone takes down your entire identity
India built its digital public infrastructure around one number. Your mobile number is the OTP channel for Aadhaar authentication, the second factor for net banking and UPI, the login for DigiLocker, the verification step for the income tax and GST portals, and the recovery route for your email. Lose the SIM and you do not lose one account. You lose the key that every other account trusts.
That design choice made onboarding fast for a billion people. It also means a stolen or lost handset is not a gadget problem. It is an identity problem, and the way you respond in the next few hours decides two separate things: how much money you can lose, and how long it takes to get every service back. Speed changes your legal liability under RBI’s rules, which is covered in detail further down, and speed also changes how many recovery paths are still open to you, because several of them are designed to be used before someone else uses your number first. If the lost device was employer-issued, or carried work data on a personal handset, a separate question follows once you replace it: what happens when your employer demands to inspect your personal device sets out where that right actually starts and stops.
This piece sets out the order to work in, not just the list of things to do. Order is the entire point. Doing the bank call before the SIM block, or the police report before the SIM block, wastes the hour where you have the most leverage.
The first hour
Everything in this hour runs in parallel where you can manage it, but if you can only do one thing at a time, do them in this order.
1. Block the SIM with your operator. Call your telecom operator’s customer care number from any other phone (a family member’s phone, a landline, a cyber cafe) and ask for immediate suspension of your number. Airtel, Jio, Vi and BSNL all run 24x7 lines for this. You do not need to visit a store to get the number suspended, only to get a replacement SIM later. This is the single fastest way to stop anyone using your number to receive OTPs.
2. Block UPI and cards through the bank’s 24x7 line. Every major bank has a toll-free number for blocking cards and UPI that does not require net banking access, because it assumes you may have lost the device that would normally get you in. Ask specifically for a temporary block on debit and credit cards and on UPI collect and pay. Note the complaint or reference number the bank gives you, since you will need it for every later step, including a liability dispute.
3. Report the handset on the Sanchar Saathi CEIR portal. The Department of Telecommunications runs Sanchar Saathi (sancharsaathi.gov.in, reviewed 19 August 2026) with a Central Equipment Identity Register that lets you block a lost or stolen handset’s IMEI so it cannot register on any Indian telecom network, across every operator, not just yours. Filing the block request generates a Request ID, and the block is intended to take effect within 24 hours of approval. Blocking the IMEI does not get your number back and does not stop someone from using the SIM in a different phone, which is why the operator call in step one still has to happen separately. It stops the handset itself from being usable on any Indian network, which matters if the phone, not just the number, is what was stolen.
4. Lock your Aadhaar biometric on the UIDAI portal. UIDAI’s portal and the mAadhaar app let you lock your biometric data (fingerprints and iris) so it cannot be used for biometric authentication, while OTP-based authentication using the Aadhaar app or the registered mobile number continues to work separately unless you also lock that. If your Aadhaar was linked to biometric-based authentication anywhere, a lost device on its own does not expose your fingerprints, but locking it costs a few minutes and closes one more door, particularly if you are worried about a stolen wallet or documents alongside the phone. You can unlock it again from the same portal when you have replaced the SIM.
None of these four steps needs the missing phone in hand. All four can be done from a borrowed phone or a laptop in the first hour, and all four should be done before you do anything else, including the police report.
The first day
File the right document, not just any document. This is where most people lose time, because a lost-article report and an FIR are two different documents and several portals specifically demand an FIR copy, not the lost-article receipt.
A lost-article report (sometimes called a General Diary or Daily Diary entry) records that you lost property. It is what most local police stations issue for a lost phone with no suspected crime. It is enough for a telecom operator’s duplicate SIM process and usually enough for an insurance claim.
An FIR (First Information Report) or its digital form, an e-FIR, records a cognizable offence, which theft is, under the Bharatiya Nagarik Suraksha Sanhita 2023 [BNSS, equivalent to the old Code of Criminal Procedure, CrPC]. Registration of an FIR for a cognizable offence is a statutory duty of the police under BNSS Section 173 [equivalent to old CrPC Section 154], and if the local station refuses to register one, there are remedies for that. Banks handling a disputed unauthorised transaction, insurers on a theft claim above a threshold, and some portals asking you to prove the device was stolen rather than misplaced will want this document specifically.
Work out which one you actually need before you go to the station. If money has not moved and you simply lost the phone, a lost-article report is usually sufficient and faster to get. If the phone was stolen, or if you later discover unauthorised transactions, get an FIR or e-FIR, since a lost-article report will not satisfy a bank’s or insurer’s documentation requirement for theft. Several States now let you file an e-FIR online for specific categories of theft without visiting a station first, though you will usually still need to visit to complete the process and sign the statement. Zero FIR and e-FIR filing covers how that process works and when a Zero FIR, filed at any station regardless of where the offence happened, is the right route instead. If an official notice, a bank letter, a summons, was already on its way to your old number while you were locked out, legal notice, police notice, or summons helps you work out what kind of document you are actually looking at and whether its clock has already started.
Report on cybercrime.gov.in and call 1930 if any money moved. If you find even one unauthorised transaction, on a card, UPI, or net banking, report it immediately on the National Cyber Crime Reporting Portal (cybercrime.gov.in, reviewed 19 August 2026) under the Financial Fraud category, and call the 1930 helpline in parallel. The mechanism behind 1930 works through banks’ fraud risk management systems to flag and, where the money has not yet moved out of the receiving account, freeze it before the fraudster withdraws it. This only works within a narrow window after the transaction, often described as the golden hour, so this step cannot wait for the FIR to be typed up. File the cyber complaint and make the call the moment you see the transaction, then handle the police report separately. Filing a cybercrime complaint in India walks through the portal’s categories and what evidence to upload. Two things can follow from this report that catch people off guard: your own account can end up frozen because of an NCRP fraud lien rather than the money you lost, which bank account frozen by a cyber fraud lien covers, and the investigation can later call you back in, not as a suspect but to depose about what you reported, which cyber fraud complainant summoned as witness covers.
Keep every reference number from today: the bank’s blocking complaint number, the Sanchar Saathi Request ID, the cybercrime.gov.in acknowledgment number, and the FIR or lost-article report number. You will be asked for at least three of these again this week. Beyond these reference numbers, the wider set of what to save in the first 48 hours of any dispute, so it survives being handed to a lawyer later, is covered in what to preserve before you call a lawyer.
The first week: the duplicate sim is the master key
Once the SIM is blocked and the reports are filed, get a duplicate SIM with your same number as the priority task of the week. This is the master key. Aadhaar OTP, net banking, UPI re-registration, DigiLocker, and most email recovery flows all assume you can receive an OTP on your registered number. Until you have that number back in your hand, on a working SIM, most of the individual service recoveries below are blocked or slower.
Operators generally require, for a duplicate SIM against a lost or stolen original:
- A government photo ID (Aadhaar, PAN, passport, voter ID; Aadhaar is the fastest since the operator can eKYC it)
- A signed application form (physical, at a store) or an app-based request where the operator supports it
- The lost-article report or FIR number, which most operators now accept as a reference rather than requiring the physical copy
- Biometric or OTP-based re-verification at the store, since the operator has to be confident the request is coming from the actual account holder and not from someone attempting a fraudulent SIM swap
Expect the new SIM to be active within a few hours to a day, with some operators enforcing a mandatory delay before the number becomes active specifically as an anti-fraud measure against SIM swap attacks, discussed further below. Once the number is live, immediately update it wherever it changed, and only then start re-registering each service.
Getting each service back
Work through services in the order they unblock each other. Aadhaar and the bank come first because DigiLocker, GST, EPFO and several others depend on one or both being current.
Aadhaar: mobile number update
If your Aadhaar-linked mobile number itself needs updating (not just restoring OTP access on the same number, which resolves once your duplicate SIM is live), that requires a visit to an Aadhaar enrolment or update centre, since mobile number update is one of the fields that cannot be done purely online without existing OTP access to the old number. Carry your Aadhaar number or enrolment ID and a government photo ID. There is a prescribed fee for a mobile number update (uidai.gov.in, reviewed 19 August 2026).
Bank: KYC and mobile re-registration
Visit your home branch, not a random branch, with your account number, a photo ID, and the reference number from your card and UPI blocking complaint. The bank will re-register your number for net banking and SMS alerts and reissue a debit card if needed. Some banks allow this through video KYC now, but a branch visit is still the reliable fallback when OTP access itself is the thing that broke.
UPI apps
UPI apps like the ones from NPCI-linked banks and PSPs tie your account to the SIM in the phone, not to a saved password, so reinstalling the app on any phone with your duplicate SIM inserted and going through the bank account linking flow again restores UPI. You will need to re-set your UPI PIN, which typically requires the last six digits of your debit card and its expiry.
DigiLocker
DigiLocker login is Aadhaar-linked OTP by default. Once your number is live again on the duplicate SIM and Aadhaar OTP works, logging back into DigiLocker on a new device is usually immediate, since DigiLocker does not store a separate password by default for most users. If you had set a username and password as a secondary login method, that recovers through a standard forgot-password email flow instead.
Income tax e-filing and GST portals
The income tax e-filing portal lets you update your registered mobile number through the profile section once you can log in, which itself may require OTP to the old number as a first step, creating a chicken-and-egg problem that the portal resolves through an alternate verification path using your PAN, Aadhaar and, if needed, a request routed through your jurisdictional assessing officer. The GST portal follows a similar pattern for registered taxpayers, with the added detail that any GST-registered business needs its authorised signatory’s mobile and email current, since GST return filing and e-way bill generation depend on OTP to that number. If your practice touches this regularly, the income tax portal changes for 2025-26 and GST 2.0 changes are worth reading alongside this section.
EPFO UAN
The EPFO member portal ties your Universal Account Number to your Aadhaar-linked mobile for login OTP. Once Aadhaar OTP access is restored, UAN login typically follows automatically, since EPFO pulls the registered number from Aadhaar’s eKYC rather than storing an entirely separate number. If it does not sync automatically, the UAN portal has its own “update mobile number” flow that similarly needs your employer’s or a physical verification fallback.
The DSC that was on the lost device
If you are an advocate filing on the e-filing portals of the courts, or a company director signing MCA or GST filings, and your Digital Signature Certificate token or its private key was on the lost device, this is not a minor inconvenience, it is a security incident. A DSC is a cryptographic private key that can sign documents as you, legally, until it is revoked. Report the loss to your Certifying Authority immediately and get the certificate revoked, not merely suspended, then apply for a fresh DSC. Do not wait for the rest of this recovery ladder to get to this step, since an unrevoked DSC in the wrong hands can be used to sign pleadings, affidavits, or company filings in your name. If you rely on e-filing regularly, legal AI for solo practitioners covers the wider toolkit an independent advocate depends on, and a lost DSC is the one item in that toolkit you cannot afford to leave unresolved for even a day.
Email and cloud
Most email providers offer account recovery through a secondary email, a recovery phone number, or backup codes generated in advance. If you set any of these up before losing the phone, use them now rather than waiting for the SIM. If you did not, and your only recovery route was the lost number, expect the provider’s manual identity verification process to take longer than every other step on this list, sometimes days, because the provider has no independent way to confirm you are the account owner beyond documents you upload and a review queue.
Service by service: what breaks and how you fix it
| Service | What breaks | Recovery route | Documents needed |
|---|---|---|---|
| Aadhaar OTP authentication | Cannot receive OTP for any Aadhaar-linked service | Restored once duplicate SIM is active; number change needs enrolment centre visit | Aadhaar number/enrolment ID, photo ID |
| Bank net/mobile banking | Login OTP fails, alerts stop | Branch visit for KYC and mobile re-registration | Account number, photo ID, blocking complaint reference |
| UPI apps | App re-link fails without SIM | Reinstall app on duplicate SIM, re-link account, reset UPI PIN | Duplicate SIM, debit card last 6 digits and expiry |
| DigiLocker | OTP login fails | Restored once Aadhaar OTP works again | None beyond Aadhaar OTP access |
| Income tax e-filing | Login OTP and 2FA fail | Profile update once logged in, or PAN/Aadhaar-based alternate verification | PAN, Aadhaar, possibly assessing officer request |
| GST portal | OTP for filings, e-way bills fails | Authorised signatory mobile update in registration | GSTIN, authorised signatory ID proof |
| EPFO UAN | Member portal login fails | Usually syncs after Aadhaar OTP restored; separate update flow if not | UAN, Aadhaar, employer verification if needed |
| DSC on lost device | Private key exposure risk for filings and signatures | Immediate revocation with Certifying Authority, fresh DSC application | Photo ID, existing DSC application records |
| Email and cloud | Recovery OTP/SMS fails | Backup codes if set up in advance, else manual identity verification | Government ID, account ownership proof, review queue |
Who pays if money moved: the RBI liability framework
This is the single most valuable legal fact in this piece, and it is why speed in the first hour matters more than anything else on this list. RBI’s framework on limiting customer liability in unauthorised electronic banking transactions sets your liability based on how the transaction happened and, critically, how fast you reported it (rbi.org.in, reviewed 19 August 2026).
| How the loss happened and when you reported | Your liability |
|---|---|
| Contributory fraud, negligence or deficiency on the bank’s part | Zero, regardless of when reported |
| Third-party breach unrelated to you or the bank, reported within 3 working days of the bank’s alert | Zero |
| Third-party breach, reported in 4 to 7 working days | Lower of the transaction amount or the capped amount in the table below |
| Third-party breach, reported after 7 working days | Governed entirely by the bank’s own board-approved policy, which can mean the full loss |
| You shared your PIN, password or OTP yourself | Full loss until you report it; the bank absorbs anything after that point |
The caps for the 4-to-7-working-day band are set by account and instrument type: ₹5,000 for Basic Savings Bank Deposit Accounts, ₹10,000 for all other savings accounts, prepaid instruments and gift cards, current, cash credit or overdraft accounts of MSMEs, current, cash credit or overdraft accounts of individuals with a limit up to ₹25 lakh, and credit cards with a limit up to ₹5 lakh, and ₹25,000 for current accounts and credit cards with a higher limit.
There is a second rule that matters just as much as the caps. Once you notify the bank of an unauthorised transaction, the bank must credit, or shadow-reverse, the disputed amount to your account within 10 working days of your complaint, regardless of who is ultimately found liable, so that the amount is not stuck in limbo during the investigation. If a bank sits on your complaint past that window without crediting the amount, that delay is itself a violation worth raising, first with the bank’s nodal officer and then with the ombudsman.
Read the table again with the first-hour steps above in mind. The three working day window for zero liability starts running from the bank’s own alert to you about the transaction, not from when the phone went missing, but every hour you delay reporting is an hour closer to leaving that window, and it is also an hour where more transactions can go through on the same compromised access. Report within the first hour, and you are very likely inside the zero-liability window regardless of when the bank’s own alert technically landed.
When the bank refuses: the banking ombudsman
If the bank denies your liability claim, drags past the 10 working day credit window, or simply stops responding, the next step is the Reserve Bank - Integrated Ombudsman Scheme, 2026 (cms.rbi.org.in, reviewed 19 August 2026), which covers complaints against banks, NBFCs and other RBI-regulated entities under one unified scheme. You generally need to have first raised the complaint with the bank and either received an unsatisfactory response or received no response within 30 days before the ombudsman will take it up. Filing is free, done online through the CMS portal, and does not require a lawyer, though nothing stops you from having one review your complaint before you file. The RBI also runs a 24x7 contact centre on 14448 for guidance in English, Hindi and ten regional languages if you are unsure whether your complaint is eligible.
Sim swap fraud and the operator’s share of blame
A SIM swap is different from a lost or stolen phone, and it is worth understanding the distinction because it changes where responsibility sits. In a SIM swap, a fraudster convinces or bribes someone at the telecom operator, or exploits a weak verification process, into issuing a duplicate SIM for your number without your knowledge, while your original SIM still works until it suddenly goes dead. If your phone still shows signal and suddenly loses it entirely with no warning, that is a SIM swap symptom, not a normal network issue, and it deserves the same first-hour urgency as an actual lost phone, because someone else now has your OTP channel.
Telecom operators owe a duty of care in verifying duplicate SIM requests, and a duplicate SIM issued on forged documents or without adequate verification is a failure on the operator’s part, not yours. This matters for the RBI liability analysis above, since a SIM swap where the operator’s verification failed strengthens an argument that the resulting unauthorised transaction falls under third-party breach rather than customer negligence, and it also gives you a separate complaint against the operator through the Telecom Regulatory Authority of India’s grievance process, independent of your bank complaint.
DPDP Act rights when a service will not restore access
If a private service, an app, a fintech company, an e-commerce account, refuses to restore your access even after you have proven your identity through other means, the Digital Personal Data Protection Act 2023 gives you a route that does not depend on the service’s own customer support goodwill. As a Data Principal under the DPDP Act, you have the right to seek information about what personal data a Data Fiduciary holds about you and how it is processed, and the right to grievance redressal directly from the Data Fiduciary within a time period it must disclose. If that grievance goes unresolved, you can escalate to the Data Protection Board established under the Act. This is a slower route than a phone call to support, but it exists specifically for the situation where a company’s automated recovery flow has failed you and its human support has stopped responding. DPDP Rules 2025 and the DPDP consent manager framework cover how these mechanisms are meant to work in practice as the rules roll out.
Consumer forum for deficiency of service
Where a bank, telecom operator, or DigiLocker-linked service causes you a quantifiable loss through delay or refusal that goes beyond what the RBI or DPDP routes above resolve, a complaint under the Consumer Protection Act 2019 for deficiency of service is available, and it does not require a lawyer to file. The e-Daakhil portal lets you file a consumer complaint online against a bank or telecom provider, and the relief available includes compensation for the loss and for the harassment caused by the runaround itself, not just the disputed amount. Consumer Protection Act 2019 and filing a consumer complaint on e-Daakhil cover the procedure, the jurisdiction thresholds, and what evidence a consumer forum expects. If you reach this stage, a well-drafted legal notice to the bank or operator before filing often resolves the matter faster than the forum itself, since it puts the deficiency on record in a way the institution’s own escalation process cannot ignore.
Checking whether a precedent you plan to cite in a consumer complaint on bank liability is still good law, rather than an older ruling that a later RBI circular or judgment has effectively overtaken, is exactly the kind of check Niyam is built for, since it answers plain-English questions against Indian judgments with the citation attached rather than leaving you to re-verify a case by hand.
What people actually go through
Ask around any group of people who have lost a phone with an active UPI account and a common pattern shows up: the panic is not about the ₹40,000 phone, it is about realizing within minutes that the same device controlled money movement, government ID access, and email recovery all at once, and that most people had never mapped which of their accounts depended on that one number until the moment it stopped working. The recurring complaint in online discussions of this exact situation is less about any single portal being broken and more about nobody having told them, in advance, which order to do things in, so they spend the first panicked hour on the wrong call first, usually the police station instead of the bank and the operator. That ordering mistake, more than any single portal’s design, is what turns a lost phone into a multi-day ordeal.
Prevention: build the ladder before you need it
Everything above is faster and safer if you set a few things up while nothing is wrong.
- Save offline backup codes. Most services that offer two-factor authentication, including major email providers, generate one-time backup codes at setup. Print them or write them down somewhere that is not the phone itself.
- Register a second number as an alternate. A trusted family member’s number, added as a secondary recovery contact on your bank account and email where the service allows it, gives you a working channel the moment the primary number goes down.
- Use a hardware key where a service supports it. A hardware security key is not tied to a SIM at all, and for high-value accounts it removes the single point of failure this entire piece is about.
- Set nominee and legacy contact details. Bank nominee details and, where offered, a digital legacy or trusted contact setting on major platforms, are not just for after death. Some services use the same trusted-contact mechanism to speed up recovery for a locked-out live account.
- Keep a paper record of what is tied to which number. A single page, kept somewhere other than the phone, listing which accounts use which mobile number for OTP, cuts the recovery time from a full week to a couple of days, because you are not rediscovering your own dependency map under pressure while also trying to remember your PAN number from memory.
None of this is expensive or technically demanding. It is the difference between a bad Tuesday and a bad month.
Frequently asked questions
Do I have to file a police report before I can block my SIM or my Aadhaar biometric?
No. Blocking your SIM with the operator, blocking cards and UPI with the bank, reporting the IMEI on Sanchar Saathi, and locking your Aadhaar biometric are all things you can do immediately, without a police report. Only later steps like a duplicate SIM, an insurance claim, or a fraud investigation may require the report.
What is the difference between a lost-article report and an FIR?
A lost-article report or General Diary entry simply records that you lost property, with no suspected crime. An FIR records a cognizable offence such as theft under BNSS. Telecom operators generally accept either for a duplicate SIM, but banks handling a disputed fraud claim, and insurers on a theft claim, usually specifically require an FIR or e-FIR, not a lost-article report.
How quickly does the Sanchar Saathi IMEI block actually work?
The portal targets a 24-hour window from approval of your CEIR blocking request to the handset being blocked across all Indian telecom networks. This blocks the physical device from registering on any network in India. It does not restore or protect your phone number, which is handled separately by your operator’s SIM block.
If a fraudster used my old SIM before I could block it, am I automatically liable for the loss?
No. Liability depends on how fast you reported the unauthorised transaction to your bank once you noticed it, not on when the phone was lost. If you report within three working days of the bank’s own alert about the transaction, and the loss traces to a third-party breach rather than your own negligence, your liability is zero under RBI’s framework.
Can I get my Aadhaar-linked mobile number changed without visiting an enrolment centre?
Not for a full number change, because that update requires biometric or in-person verification at an Aadhaar enrolment or update centre. If you only need OTP access restored on the same number, that resolves automatically once your duplicate SIM with the same number is active again, with no centre visit needed.
My bank is refusing to reverse an unauthorised transaction. What is my next step?
First put the complaint in writing to the bank’s nodal officer for grievance redressal and ask for a response within a reasonable, documented period. If the bank does not resolve it within 30 days, or the response is unsatisfactory, you can escalate to the Reserve Bank - Integrated Ombudsman Scheme, 2026, which is free to file and does not require a lawyer.
Is a SIM swap the same as a lost phone for liability purposes?
Not exactly. A SIM swap where the telecom operator issued a duplicate SIM on weak or forged verification is arguably a failure on the operator’s part, which can strengthen your case that the resulting transaction was a third-party breach rather than your own negligence, relevant to the RBI liability table above. It is also a separate ground for a complaint against the operator.
What happens to my Digital Signature Certificate if the token was on the lost device?
Report the loss to your Certifying Authority immediately and get the certificate revoked, not just suspended. An unrevoked DSC in someone else’s possession can be used to sign documents as you, which is a live legal exposure until revocation takes effect, whether you are an advocate on an e-filing portal or a company director on MCA filings.
Do I need a lawyer to file a complaint with the banking ombudsman or a consumer forum?
No. Both the RBI Integrated Ombudsman Scheme and the Consumer Protection Act 2019 complaint process through e-Daakhil are designed to be filed by an individual without legal representation, and both are free to file. A lawyer can still help you frame the complaint and gather documentation more effectively, particularly where the amount involved is significant.
Will locking my Aadhaar biometric stop me from using Aadhaar OTP authentication too?
No, biometric lock and OTP-based authentication are separate settings on the UIDAI portal. Locking your biometric prevents fingerprint or iris-based authentication while OTP-based authentication using your registered mobile number continues to work unless you also disable that separately.
If money moved from my account, should I report it to cybercrime.gov.in or to my bank first?
Do both immediately, in parallel if you can, since they serve different purposes and neither substitutes for the other. The bank’s 24x7 blocking line stops further transactions and starts your RBI liability clock running in your favor. The cybercrime.gov.in report and the 1930 helpline call feed into a bank-to-bank freeze mechanism that only works within a short window after the transaction, so delay on either side costs you.
Does DigiLocker store a copy of my documents that survives even if I never recover the original device?
Yes. DigiLocker’s stored documents are tied to your Aadhaar-linked account on NeSL’s or the issuing authority’s servers, not to the device. Once you regain OTP access to your account, whether on the recovered phone or a new one, your stored documents are still there exactly as they were.