Section 34. Penalty for impersonation at time of enrolment
Whoever impersonates or attempts to impersonate another person, whether—
- dead or alive;
- real or imaginary,
by providing any false demographic information or false biometric information at the time of enrolment, shall be punishable with—
- imprisonment for a term which may extend to three years; or
- fine which may extend to ₹10,000; or
- both.
Important Points
- Impersonation at the time of Aadhaar enrolment is a criminal offence.
- False demographic or biometric information attracts criminal liability.
Section 35. Penalty for impersonation of Aadhaar number holder by changing demographic information or biometric information
Whoever, with the intention of—
- causing harm or mischief to an Aadhaar number holder; or
- appropriating the identity of an Aadhaar number holder,
changes or attempts to change the demographic information or biometric information of an Aadhaar number holder by impersonating another person, whether—
- dead or alive;
- real or imaginary,
shall be punishable with—
- imprisonment for a term which may extend to three years; and
- fine which may extend to ₹10,000.
Important Point: Identity theft through unauthorized alteration of Aadhaar information is specifically punishable under this section.
Section 36. Penalty for impersonation
Whoever, without being authorised under this Act to collect identity information, pretends by—
- words;
- conduct; or
- demeanour,
that he or she is authorised to collect such information, shall be punishable with—
In case of an individual
- imprisonment for a term which may extend to three years; or
- fine which may extend to ₹10,000; or
- both.
In case of a company
- fine which may extend to ₹1,00,000; or
- both, where applicable.
Important Point: Pretending to be an authorised Aadhaar enrolment or authentication agency is a punishable offence.
Section 37. Penalty for disclosing identity information
Whoever intentionally—
- discloses;
- transmits;
- copies; or
- otherwise disseminates
any identity information collected during enrolment or authentication—
- to any person not authorised under this Act or regulations; or
- in contravention of any agreement or arrangement entered into under this Act,
shall be punishable with—
In case of an individual
- imprisonment for a term which may extend to three years; or
- fine which may extend to ₹10,000; or
- both.
In case of a company
- fine which may extend to ₹1,00,000; or
- both, where applicable.
Important Point: Unauthorised disclosure of Aadhaar identity information is a criminal offence.
Section 38. Penalty for unauthorised access to the Central Identities Data Repository [1]
Whoever, without authorisation from the Authority, intentionally—
(a) Accesses or secures access to the Central Identities Data Repository (CIDR).
(b) Downloads, copies or extracts any data from the CIDR or any removable storage medium.
(c)Introduces any—
- virus; or
- computer contaminant,
into the CIDR.
(d) Damages or causes damage to the data contained in the CIDR.
(e) Disrupts or causes disruption of access to the CIDR.
(f) Denies or causes denial of access to any authorised person.
(g) Reveals, shares, uses or displays information in contravention of—
- Section 28(5);
- Section 29;
or assists another person in doing so.
(h) Destroys, deletes or alters any information stored—
- in the CIDR; or
- in any removable storage medium,
or diminishes its value or utility.
(i) Steals, conceals, destroys or alters any computer source code used by the Authority with the intention of causing damage.
Punishment
Such person shall be punishable with—
- imprisonment for a term which may extend to ten years [1]; and
- fine of not less than ₹10 lakh.
Important Points
- Unauthorised access to the Central Identities Data Repository is one of the most serious offences under the Aadhaar Act.
- Minimum fine is ₹10 lakh.
- Maximum imprisonment is ten years.
Explanation
For the purposes of this section—
- "computer contaminant"
- "computer virus", and
- "damage"
shall have the meanings assigned to them in the Explanation to Section 43 of the Information Technology Act, 2000.
The expression "computer source code" shall have the meaning assigned in the Explanation to Section 65 of the Information Technology Act, 2000.
Section 39. Penalty for tampering with data in Central Identities Data Repository [1]
Whoever, without being authorised by the Authority, uses or tampers with the data in the Central Identities Data Repository (CIDR) or in any removable storage medium with the intention of—
- modifying information relating to an Aadhaar number holder; or
- discovering any information relating thereto,
shall be punishable with—
- imprisonment for a term which may extend to ten years [1]; and
- fine which may extend to ₹10,000.
Important Points
- Unauthorised tampering with Aadhaar data is a serious criminal offence.
- Maximum imprisonment is ten years.
- The offence includes both modification of Aadhaar data and unauthorized discovery of information.
Section 40. Penalty for unauthorised use by requesting entity or offline verification-seeking entity [2]
Whoever—
(a) Requesting Entity
Being a requesting entity, uses the identity information of an individual in contravention of Section 8(2); or
(b) Offline Verification-Seeking Entity
Being an offline verification-seeking entity, uses the identity information of an individual in contravention of Section 8A(2)
shall be punishable with—
In case of an individual
- imprisonment for a term which may extend to three years; or
- fine which may extend to ₹10,000; or
- both.
In case of a company
- fine which may extend to ₹1,00,000; or
- both, where applicable.
Important Points
- Identity information collected for authentication or offline verification can be used only for the authorised purpose.
- Misuse of Aadhaar information by requesting entities is a punishable offence.
Section 41. Penalty for non-compliance with intimation requirements [3]
Whoever, being—
- an enrolling agency; or
- a requesting entity
fails to comply with—
- Section 3(2); or
- Section 8(3)
shall be liable to—
In case of an individual
- penalty which may extend to ₹1,00,000.
In case of a company
- penalty which may extend to ₹10,00,000.
Important Point: Failure to provide mandatory information to an individual before enrolment or authentication attracts monetary penalties.
Section 42. General penalty [4]
Whoever commits an offence under this Act or any rules or regulations made thereunder, for which no specific penalty is provided elsewhere in this Act, shall be punishable with—
In case of an individual
- imprisonment for a term which may extend to three years [4]; or
- fine which may extend to ₹25,000; or
- both.
In case of a company
- fine which may extend to ₹1,00,000; or
- both, where applicable.
Important Point: Section 42 acts as a residuary penal provision where no specific punishment is prescribed elsewhere in the Act.
Section 43. Offences by companies
(1) Liability of Company and Persons in Charge
Where an offence under this Act has been committed by a company—
- every person who, at the time of the offence, was in charge of and responsible for the conduct of the business of the company, and
- the company itself
shall be deemed to be guilty of the offence and shall be liable to be proceeded against and punished accordingly.
Proviso
Such person shall not be liable if he proves that—
- the offence was committed without his knowledge; or
- he had exercised all due diligence to prevent the commission of the offence.
Important Point: Both the company and its responsible officers may be held criminally liable for offences under the Aadhaar Act.
(2) Liability of Directors and Other Officers
Notwithstanding sub-section (1), where an offence has been committed by a company and it is proved that the offence was committed with the—
- consent;
- connivance; or
- neglect
of any—
- director;
- manager;
- secretary; or
- other officer,
such person shall also be deemed guilty and shall be liable to be proceeded against and punished accordingly.
Important Point: Directors and senior officers are personally liable where the offence results from their consent, connivance or negligence.
Explanation
For the purposes of this section—
(a) Company
"Company" means any body corporate and includes—
- a firm; or
- any other association of individuals.
(b) Director
In relation to a firm, "Director" means a partner of the firm.
Section 44. Act to apply for offence or contravention committed outside India
The provisions of this Act shall apply also to any offence or contravention committed outside India by any person, irrespective of nationality, if the act or conduct has a nexus with the provisions of this Act.
Important Points
- The Aadhaar Act has extra-territorial application for offences and contraventions committed outside India.
- A person may be proceeded against under this Act even if the offence is committed outside India, subject to the provisions of the Act.
Section 45. Power to investigate offences
No court shall take cognizance of any offence punishable under this Act except upon a complaint made by, or under the authority of, the Authority.
The Authority may authorise any of its officers to investigate offences punishable under this Act.
Such authorised officer shall exercise the powers of investigation in accordance with the provisions of law applicable to criminal investigations.
Important Points
- Investigation of offences under the Aadhaar Act can be carried out only by officers authorised by UIDAI.
- The Authority controls initiation of investigation under the Act.
Section 46. Penalties not to interfere with other punishments
The penalties provided under this Act shall be in addition to, and not in derogation of, any punishment or liability provided under any other law for the time being in force.
Important Point: A person may be liable under both the Aadhaar Act and any other applicable law for the same act, wherever legally permissible.
Section 47. Cognizance of offences
(1) Complaint by the Authority
No court shall take cognizance of any offence punishable under this Act except upon a complaint made by—
- the Authority; or
- any officer or person authorised by it.
(2) Complaint by Aadhaar Number Holder
An Aadhaar number holder may also make a complaint in respect of an offence under—
- Section 34;
- Section 35;
- Section 36;
- Section 37;
- Section 40; or
- Section 41
where such offence relates to his or her identity information or Aadhaar number.
Important Points
- Ordinarily, prosecution under the Aadhaar Act is initiated by UIDAI or its authorised officer.
- An Aadhaar number holder has an independent right to file a complaint for specified offences affecting his or her Aadhaar or identity information.
Footer Notes
[1] In Section 38, the words "ten years" were substituted for the words "three years" by the Aadhaar and Other Laws (Amendment) Act, 2019 (Act 14 of 2019), Section 16, with effect from 25-07-2019.
[2] In Section 39, the words "ten years" were substituted for the words "three years" by the Aadhaar and Other Laws (Amendment) Act, 2019 (Act 14 of 2019), Section 16, with effect from 25-07-2019.
[3] Section 40 was substituted by the Aadhaar and Other Laws (Amendment) Act, 2019 (Act 14 of 2019), Section 17, with effect from 25-07-2019.
[4] In Section 41, the punishment was substituted by the Aadhaar and Other Laws (Amendment) Act, 2019 (Act 14 of 2019), Section 18, with effect from 25-07-2019, replacing imprisonment with monetary penalties.
[5] In Section 42, the words "three years" were substituted for the earlier punishment by the Aadhaar and Other Laws (Amendment) Act, 2019 (Act 14 of 2019), Section 19, with effect from 25-07-2019.
No statutory footer notes are provided for Sections 44 to 47 in the Act.