Section 28. Security and confidentiality of information
(1) Security of Information
The Authority shall ensure the security of—
- identity information; and
- authentication records
of individuals.
Important Point: UIDAI has a statutory duty to protect the security of identity information and authentication records.
(2) Confidentiality of Information
Subject to the provisions of this Act, the Authority shall ensure the confidentiality of—
- identity information; and
- authentication records
of individuals.
Important Point: Identity information and authentication records must remain confidential except where disclosure is expressly permitted by the Act.
(3) Protection of Information
The Authority shall take all necessary measures to ensure that the information in its possession or control, including information stored in the Central Identities Data Repository (CIDR), is protected against—
- unauthorised access;
- unauthorised use;
- unauthorised disclosure;
- accidental destruction;
- intentional destruction;
- loss; and
- damage.
Important Point: The Authority is legally bound to safeguard all information stored in the CIDR against misuse and loss.
(4) Security Measures
Without prejudice to sub-sections (1) and (2), the Authority shall—
(a) Adopt and implement appropriate—
- technical; and
- organisational
security measures.
(b) Ensure that agencies, consultants, advisers and other persons engaged by the Authority maintain appropriate technical and organisational security measures.
(c) Ensure that every agreement or arrangement with such agencies or persons—
- imposes obligations equivalent to those imposed on the Authority under this Act; and
- requires them to act only on the instructions of the Authority.
Important Point: All entities engaged by UIDAI are bound to maintain the same level of confidentiality and security as UIDAI itself.
(5) Restriction on Disclosure
Notwithstanding anything contained in any other law for the time being in force, and except as otherwise provided in this Act—
- the Authority;
- its officers;
- its employees; and
- any agency maintaining the Central Identities Data Repository,
shall not, whether during service or after leaving service, reveal any information stored in the Central Identities Data Repository or any authentication record to any person.
Proviso
An Aadhaar number holder may request the Authority to provide access to his or her identity information, excluding core biometric information, in the manner specified by regulations.
Important Points
- Disclosure of information stored in the CIDR is strictly prohibited except under the Act.
- Core biometric information cannot be accessed even by the Aadhaar holder under this proviso.
Section 29. Restriction on sharing information [1]
(1) Restriction on Core Biometric Information
No core biometric information collected or created under this Act shall—
(a) Be shared with any person for any reason whatsoever.
(b) Be used for any purpose other than—
- generation of Aadhaar numbers; and
- authentication under this Act.
Important Point: Core biometric information can never be shared and may be used only for Aadhaar generation and authentication.
(2) Sharing of Other Identity Information
Identity information, other than core biometric information, may be shared only—
- in accordance with the provisions of this Act; and
- in the manner specified by regulations.
(3) Restrictions on Requesting Entities and Offline Verification-Seeking Entities [1]
No identity information available with a—
- requesting entity; or
- offline verification-seeking entity,
shall—
(a) Be used for any purpose other than the purpose informed in writing to the individual at the time of authentication or offline verification.
(b) Be disclosed for any purpose other than the purpose informed in writing to the individual.
Proviso
The purposes referred to above shall be expressed in clear and precise language capable of being understood by the individual.
Important Point: Identity information cannot be used or disclosed beyond the purpose for which informed consent has been obtained.
(4) Publication of Aadhaar Information
No—
- Aadhaar number;
- demographic information; or
- photograph [1]
collected or created under this Act shall be—
- published;
- displayed; or
- posted publicly,
except for purposes specified by regulations.
Important Point: Public display or publication of Aadhaar numbers or demographic information is prohibited unless authorised by regulations.
Section 30. Biometric information deemed to be sensitive personal information
Biometric information collected and stored in electronic form under this Act shall be deemed to be—
- an electronic record; and
- sensitive personal data or information.
Accordingly, the provisions of the Information Technology Act, 2000 and the rules made thereunder shall apply, in addition to the provisions of this Act.
Important Point: Biometric information enjoys statutory protection under both the Aadhaar Act and the Information Technology Act, 2000.
Explanation
For the purposes of this section—
(a) "Electronic form" shall have the meaning assigned in Section 2(1)(r) of the Information Technology Act, 2000.
(b) "Electronic record" shall have the meaning assigned in Section 2(1)(t) of the Information Technology Act, 2000.
(c) "Sensitive personal data or information" shall have the meaning assigned in the Explanation to Section 43A of the Information Technology Act, 2000.
Section 31. Alteration of demographic information or biometric information
(1) Alteration of Demographic Information
Where any demographic information of an Aadhaar number holder—
- is found to be incorrect; or
- changes subsequently,
the Aadhaar number holder shall request the Authority to alter such demographic information in the Central Identities Data Repository (CIDR) in the manner specified by regulations.
Important Point: The Aadhaar holder is responsible for requesting correction or updating of demographic information whenever necessary.
(2) Alteration of Biometric Information
Where any biometric information of an Aadhaar number holder—
- is lost; or
- changes subsequently for any reason,
the Aadhaar number holder shall request the Authority to alter such biometric information in the Central Identities Data Repository in the manner specified by regulations.
Important Point: Biometric information may also be updated whenever it changes or is lost.
(3) Action by the Authority
Upon receiving a request under sub-section (1) or sub-section (2), the Authority may—
- verify the request;
- make the required alteration in the record; and
- intimate the Aadhaar number holder regarding such alteration.
(4) Restriction on Alteration
No identity information contained in the Central Identities Data Repository shall be altered except—
- in the manner provided under this Act; or
- under the regulations made thereunder.
Important Point: Identity information can be altered only through the statutory procedure prescribed under the Aadhaar Act.
Section 32. Access to own information and records of requests for authentication
(1) Maintenance of Authentication Records
The Authority shall maintain authentication records—
- in such manner; and
- for such period,
as may be specified by regulations.
(2) Right to Obtain Authentication Records
Every Aadhaar number holder shall be entitled to obtain his or her authentication record in the manner specified by regulations.
Important Point: Every Aadhaar holder has the statutory right to access his or her own authentication records.
(3) Restriction on Collection of Purpose of Authentication
The Authority shall not, either by itself or through any entity under its control—
- collect;
- keep; or
- maintain
any information regarding the purpose for which authentication was carried out.
Important Point: UIDAI does not maintain records of the purpose for which Aadhaar authentication is performed, thereby protecting user privacy.
Section 33. Disclosure of information in certain cases [1][2][3]
(1) Disclosure pursuant to Court Order
Nothing contained in—
- Section 28(2);
- Section 28(5); or
- Section 29(2),
shall prevent disclosure of—
- identity information; or
- authentication records,
where such disclosure is made pursuant to an order of a Court not inferior to a Judge of a High Court [2].
First Proviso [3]
No order under this sub-section shall be passed without giving an opportunity of hearing to—
- the Authority; and
- the concerned Aadhaar number holder.
Second Proviso [3]
Core biometric information shall not be disclosed under this sub-section.
Important Points
- Only a Court not inferior to a High Court Judge can order disclosure under Section 33(1).
- The Aadhaar holder must be given an opportunity of being heard before such disclosure.
- Core biometric information can never be disclosed even under a Court order.
(2) Disclosure in the Interest of National Security
Nothing contained in—
- Section 28(2);
- Section 28(5); or
- Section 29(1)(b);
- Section 29(2); or
- Section 29(3),
shall prevent disclosure of—
- identity information; or
- authentication records,
where such disclosure is made in the interest of national security pursuant to the direction of an officer not below the rank of Secretary to the Government of India [1], specially authorised by an order of the Central Government.
First Proviso
Every such direction shall be reviewed by an Oversight Committee consisting of—
- the Cabinet Secretary;
- the Secretary, Department of Legal Affairs; and
- the Secretary, Department of Electronics and Information Technology,
before it takes effect.
Second Proviso
Such direction shall remain valid for a period of three months from the date of issue.
After review by the Oversight Committee, it may be extended for a further period of three months.
Important Points
- National security disclosures require authorisation by an officer not below the rank of Secretary to the Government of India.
- Every such direction must undergo review by the Oversight Committee before becoming effective.
- Each direction is valid for only three months unless extended after review.
Footer Notes
[1] Section 29 was amended by the Aadhaar and Other Laws (Amendment) Act, 2019 (Act 14 of 2019), Section 13, with effect from 25-07-2019—
[2] In Section 33(2), the words "Secretary to the Government of India" were substituted for the words "Joint Secretary" by the Aadhaar and Other Laws (Amendment) Act, 2019 (Act 14 of 2019), Section 14, with effect from 25-07-2019.
[3] In Section 33(1), the words "Judge of a High Court" were substituted for the words "District Judge" by the Aadhaar and Other Laws (Amendment) Act, 2019 (Act 14 of 2019), Section 14, with effect from 25-07-2019.
[4] In Section 33(1), the following were inserted by the Aadhaar and Other Laws (Amendment) Act, 2019 (Act 14 of 2019), Section 14, with effect from 25-07-2019—
- the requirement of giving an opportunity of hearing to the concerned Aadhaar number holder; and
- the proviso that core biometric information shall not be disclosed under this sub-section.
- Sub-section (3) was substituted.
- In sub-section (4), the words "or core biometric information" were substituted with ", demographic information or photograph".