Jump to content

Draft:Unique Identification Authority of India (UIDAI)

From The Justice Definitions Project


1. What is UIDAI

1.1 Origins and Statutory Foundation

The Unique Identification Authority of India (UIDAI) issues, updates, and authenticates Aadhaar, the twelve-digit unique identification number assigned to Indian residents based on their demographic and biometric attributes[1]. UIDAI functions as a statutory body under the Ministry of Electronics and Information Technology (MeitY), having been re-established on 12 July 2016 pursuant to the provisions of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016[1]. Before its statutory creation, the body operated from 28 January 2009 as an attached office of the former Planning Commission of India, deriving its operational mandates from executive notifications rather than legislative enactments[2] . During this foundational phase, Nandan Nilekani, co-founder of Infosys, served as its initial Chairman, providing technological oversight and administrative direction during the infrastructure ramp-up[2].

1.2 Administrative Growth and Scale of Operations

In public administration, UIDAI is primarily recognized as the statutory body responsible for enrolment, demographic updates, biometric modifications, and grievance redressal concerning authentication failures [1]. The authority's operational significance is defined by its global scale. By September 2025, UIDAI had generated over 142.76 crore (1.427 billion) Aadhaar numbers, establishing the system as the world's largest biometric digital identity registry [3]. The inaugural Aadhaar identifier was issued to a resident of Tembhli village in Nandurbar, Maharashtra, on 29 September 2010, demonstrating the rapid deployment of national enrolment machinery following the initial executive notifications [2], [3].

1.3 Platform Logic and Integration into Digital Public Infrastructure

Unlike traditional physical identity documents, Aadhaar does not confer citizenship status nor does it mandate a physical card for verification [1]. Instead, it functions as a digital identity verification platform [1]. Registered identity requesters—including commercial banks, telecommunication operators, and state welfare agencies—query the Central Identities Data Repository (CIDR) to perform real-time identity verification [1]. This architecture positions Aadhaar as the foundational identity layer of "India Stack" and broader Digital Public Infrastructure (DPI) initiatives [1]. Interoperable digital platforms, such as the Unified Payments Interface (UPI) and DigiLocker, rely on Aadhaar-based authentication mechanisms for user onboarding and verification . Furthermore, since 2013, Aadhaar has served as the core identifier for the Direct Benefit Transfer (DBT) scheme within the "JAM Trinity" (Jan Dhan bank accounts, Aadhaar, and Mobile numbers), directing state subsidies, pensions, and educational scholarships directly to validated beneficiary bank accounts [4].

2. Official Definitions of UIDAI

2.1 Section 2, Aadhaar Act, 2016: Key Definitions and Thresholds

Section 2 of the Aadhaar Act, 2016 defines the core statutory terms governing UIDAI's regulatory domain :

  • Section 2(a) - "Aadhaar number": Refers to the unique identification number issued to an individual under sub-section (3) of Section 3[1].
  • Section 2(g) - "Biometric information": Encompasses photographs, fingerprints, iris scans, or other biological attributes specified by executive regulations [1].
  • Section 2(v) - "Resident": Defined as an individual who has resided in India for a period or periods totaling 182 days or more in the twelve months immediately preceding the date of application for enrolment[1].

Because statutory qualification is grounded in physical residency rather than legal citizenship, Aadhaar enrolment is open to non-citizens residing in India for the requisite statutory timeframe as well as Indian nationals.

2.2 Sections 3 and 7: Rights, Entitlements, and Statutory Conditionality

The Aadhaar Act contains an internal statutory dynamic regarding user rights versus state requirements:

  • Section 3 (Right to Enrolment): Establishes that every resident has a statutory entitlement to obtain an Aadhaar number, framing enrolment as a right guaranteed to eligible residents [1].
  • Section 7 (Statutory Conditionality): Grants the Central Government or State Governments the authority to mandate Aadhaar authentication or proof of enrolment as a prerequisite for receiving subsidies, benefits, or services funded through the Consolidated Fund of India [1].

Section 7 contains a proviso requiring governments to provide alternative identity documentation to unenrolled individuals to prevent complete denial of statutory entitlements [1]. The interaction between Section 3's rights-based formulation and Section 7's regulatory conditionality remains a focal point in academic, policy, and legal scholarship [4] [5].

2.3 Sections 11 and 23: Constitution, Functions, and Regulatory Scope

Section 11 formally establishes UIDAI as an autonomous statutory authority possessing perpetual succession and a common seal. Section 23 delineates its statutory functions, empowering the authority to :

  • Specify operational standards for enrolment agencies, registrars, and authentication user agencies .
  • Maintain, secure, and operate the Central Identities Data Repository (CIDR).
  • Promulgate data-security protocols, cryptographic guidelines, and privacy protections.
  • Formulate regulatory guidelines governing the delivery of government subsidies, welfare services, and digital financial transactions .

The Act's long title restricts its statutory purpose to facilitating "good governance, efficient, transparent, and targeted delivery of subsidies, benefits and services" drawn from the Consolidated Fund of India—a statutory limitation central to subsequent constitutional challenges regarding its passage as a Money Bill [1] [6] [7].

3. Appearance in Official Documents

3.1 Judicial Scrutiny: Justice K.S. Puttaswamy (Retd.) v. Union of India (2018)

In Justice K.S. Puttaswamy (Retd.) v. Union of India (2018), a five-judge Constitution Bench evaluated the constitutional validity of the Aadhaar project. The majority opinion, delivered by Justice A.K. Sikri, upheld the statutory scheme, observing that the system collects "minimal data... for the purposes of establishing identity" and utilizes de-duplication technology to ensure individual uniqueness[6]. The Court evaluated UIDAI's operational protocols under the proportional scrutiny standard articulated in the 2017 Right to Privacy judgment, requiring legality, a legitimate state goal, and proportionality[8] [6]. Justice Sikri characterized Aadhaar as an instrument designed to facilitate the objectives of a modern social welfare state.

Conversely, Justice D.Y. Chandrachud issued a dissenting opinion, concluding that pervasive cross-verification across public and private platforms risked establishing a "state of the panopticon" by facilitating personal profiling [6]. Justice Chandrachud highlighted a critical technical vulnerability: neither UIDAI nor the Central Government owns the source code for the proprietary automated biometric identification system (ABIS) de-duplication software. Because this core engine is leased from foreign commercial vendors, the dissent framed this licensing reliance as a national security risk and an institutional vulnerability[6].

3.2 Constitutional Oversight: Comptroller and Auditor General (CAG) Characterisation

In Performance Audit Report No. 24 of 2021, the Comptroller and Auditor General (CAG) of India classified UIDAI as the statutory authority "mandated to lay out plans and policies to implement the Aadhaar project". The audit traced UIDAI's structural evolution from its 2009 administrative origin under the Planning Commission through its 2016 statutory establishment . The report provided independent audit oversight of the authority's operations, record keeping, and internal data verification practices [9].

3.3 Data Protection Framework: Justice B.N. Srikrishna Committee Evaluation

The Committee of Experts on a Data Protection Framework for India, chaired by retired Supreme Court Justice B.N. Srikrishna, submitted its report A Free and Fair Digital Economy in July 2018 . While avoiding direct commentary on pending constitutional challenges, the Committee identified regulatory gaps in the original Aadhaar Act. Specifically, it highlighted that the statute lacked explicit enforcement mechanisms empowering UIDAI to penalize non-compliant private entities operating within the broader authentication ecosystem . The Committee recommended amending the Aadhaar Act to introduce formal enforcement penalties and regulatory oversight—provisions that influenced the drafting of the Digital Personal Data Protection Act, 2023 [10], [11].

4. System Architecture, Credential Types, and Ecosystem Entities

4.1 Categorisation of Credentials and Identification Models

While UIDAI operates as a centralized national authority, its regulatory framework specifies distinct credential classifications :

  • Standard Aadhaar: Issued to adult residents meeting the 182-day physical residency requirement [1].
  • Baal Aadhaar: Issued to children under five years of age. It is visually designated in blue and linked directly to a parent or guardian's Aadhaar credential without capturing child biometrics . Mandatory biometric updates (capturing 10 fingerprints, two iris scans, and a photograph) are required when the child reaches age 5 and age 15[1].
  • NRI Aadhaar: Non-Resident Indians holding valid Indian passports are eligible for Aadhaar credentials upon arrival in India without fulfilling the standard 182-day residency waiting period [1].
  • Virtual ID (VID): Introduced following legal developments and the 2019 legislative amendments, the VID is a temporary, revocable 16-digit random number mapped to a resident's Aadhaar. It allows residents to perform authentication without disclosing their actual Aadhaar number to verification entities[12].

4.2 Authentication Modes and Exception Handling Mechanisms

UIDAI provides multiple authentication mechanisms tailored to diverse technical environments[1]:

  • Demographic Authentication: Matches text attributes (name, address, date of birth) against CIDR records.
  • Biometric Authentication: Performs real-time matching of fingerprints, iris scans, or facial modalities against central biometric databases.
  • One-Time Password (OTP) Authentication: Sends a time-bound verification code to the resident's registered mobile number.
  • Offline Verification: Utilizes digitally signed QR codes, e-Aadhaar PDFs, or offline XML files, permitting identity verification without live queries to the CIDR.

For individuals suffering from physical biometric degradation—such as manual laborers or elderly residents with worn fingerprints—statutory regulations require registrars and service providers to implement non-biometric exception handling protocols, including demographic checks, OTP verification, or manual supervisor overrides [5].

4.3 Institutional Ecosystem: Registrars, AUAs, KUAs, and ASAs

The operational infrastructure managed by UIDAI relies on a distributed hierarchy of partner entities [1]:

  • Registrars: Central/state government departments or corporate entities authorized by UIDAI to collect demographic and biometric data during enrolment .
  • Enrolment Agencies (EAs): Field entities engaged by Registrars to operate enrolment centers, manage data capture hardware, and interface directly with residents.
  • Authentication User Agencies (AUAs) & e-KYC User Agencies (KUAs): Service providers (banks, telecommunication companies, government departments) that submit identity queries to the CIDR to verify individuals.
  • Authentication Service Agencies (ASAs): Specialized network entities that provide secure data connectivity pipelines between AUAs/KUAs and the central CIDR database .
  • State Resident Data Hubs (SRDHs): Databases maintained by individual state governments containing state-level resident records mapped to Aadhaar identifiers, designed to assist state welfare distribution[13].
+-----------------------------------------------------------------------+
|              Unique Identification Authority of India                 |
|                               (UIDAI)                                 |
|                                  |                                    |
|             Central Identities Data Repository (CIDR)                 |
+-----------------------------------------------------------------------+
                                   |
             +---------------------+---------------------+
             |                                           |
             v                                           v
+--------------------------+               +--------------------------+
|  Enrolment Architecture  |               |  Auth & KYC Architecture |
+--------------------------+               +--------------------------+
| * Registrars             |               | * ASAs (Service Ag.)     |
| * Enrolment Agencies     |               | * AUAs (User Agencies)   |
| * Field Operators        |               | * KUAs (e-KYC Agencies)  |
+--------------------------+               +--------------------------+
             |                                           |
             +---------------------+---------------------+
                                   |
                                   v
             +-------------------------------------------+
             | State Resident Data Hubs (SRDHs - States) |
             +-------------------------------------------+

4.4 Mandatory versus Voluntary Application post-2018

The legal landscape governing Aadhaar usage was altered by the 2018 Supreme Court ruling and the Aadhaar and Other Laws (Amendment) Act, 2019 [12]:

  • Mandatory Use: Restricted to welfare benefits and state subsidies funded via the Consolidated Fund of India under Section 7, alongside statutory obligations created by Parliamentary legislation (such as linking Aadhaar with Permanent Account Numbers [PAN] under Section 139AA of the Income Tax Act, 1961).
  • Voluntary Use: Private entities (including banking institutions and telecom service providers) may perform Aadhaar-based authentication only on a voluntary, consent-driven basis, subject to privacy standards established under statutory regulations.

5. Recent Policy and Technological Expansions (2026)

5.1 Decennial Document Update Framework and Document Liberalisation

UIDAI enforced structured compliance frameworks requiring residents whose credentials were generated or modified over ten years prior to submit updated Proof of Identity (POI) and Proof of Address (POA) documentation to preserve record integrity. Concurrently, under the Aadhaar (Enrolment and Update) Regulations, UIDAI broadened its schedule of acceptable supporting documentation—incorporating verified e-Voter IDs, e-Ration cards, registered marriage certificates, official divorce decrees, CGHS/ESIC cards, and municipal property tax receipts—to facilitate compliance for senior citizens, displaced populations, and rural demographics.

5.2 Demographic Provisions for Minors, Foreign Nationals, and OCIs

Updated regulatory directives formalize operational parameters across specific demographic classes:

  • Minors: Children under five years old undergo Head of Family (HoF)-based enrolment linked to a parent's credential and backed by an official birth certificate, triggering mandatory biometric enrolment upon reaching age 5 and age 15.
  • Foreign Nationals & OCIs: Fixed validity terms are assigned to non-citizen identity entries: Overseas Citizen of India (OCI) cardholders are granted a maximum 10-year validity window before mandatory re-verification, whereas Long-Term Visa (LTV) holders receive validity dates aligned directly with their statutory visa duration.

5.3 Mobile App-Based Self-Service and Processing Fee Waivers

To minimize reliance on physical enrolment centers for minor demographic modifications, UIDAI introduced expanded digital updating capabilities within its official mobile software application. This software allows residents to update non-biometric information—such as registered email addresses and residential locations—directly via smartphone interfaces. To promote adoption of these digital tools, standard administrative processing fees for app-based demographic adjustments were waived through December 31, 2026.

5.4 Open Innovation, Hackathons, and Technical Optimization

UIDAI introduced structured technical initiatives, including large-scale national developer hackathons targeting researchers, software engineers, and academic institutions. These collaborative projects focus on improving real-time optical text matching, reducing biometric rejection rates among manual workers, optimizing large-scale cryptographic data pipelines, and analyzing geographic enrolment patterns to enhance operational efficacy across rural deployment centers.

6. Coverage in Official and Primary Databases

6.1 UIDAI Aadhaar Dashboard

UIDAI maintains a public web analytics portal displaying national and state-level statistics on Aadhaar generation, demographic modifications, biometric updates, and transaction volumes . The portal provides longitudinal data visualisations detailing enrolment saturation metrics across geographical regions[14] .

6.2 UIDAI Monthly Press Releases and Transaction Metrics

Monthly operational updates are published through UIDAI's press office detailing systemic transaction figures . In August 2025, the authority logged over 221 crore (2.21 billion) biometric and demographic authentication transactions within a single month, marking a 10 percent year-over-year operational increase [14].

6.3 Statutory Annual Reports under Section 27

Pursuant to Section 27 of the Aadhaar Act, 2016, UIDAI submits an Annual Report containing its audited financial records, organizational expenditures, and operational summaries to the Central Government for parliamentary tabling . These self-authored publications represent the primary official account of the authority's administrative activities [15].

6.4 CAG Audit Report No. 24 of 2021

CAG Performance Audit Report No. 24 of 2021 represents the primary external constitutional audit of UIDAI's operational management covering FY2015 through FY2019. The audit identified procedural gaps in documentary verification during early enrolment drives and noted that over 4.75 lakh Aadhaar numbers had been canceled as duplicate entries by November 2019. The report qualified specific statistical findings with the caveat "to the extent... furnished [by UIDAI]," indicating data accessibility constraints during the audit process[16].

6.5 Parliamentary Standing Committee Reports and Legislative Records

MeitY periodically submits operational Aadhaar statistics in response to unstarred and starred questions in the Lok Sabha and Rajya Sabha. These records cover localized enrolment saturation rates, public grievance metrics, and reported system breaches. The Parliamentary Standing Committee on Communications and Information Technology periodically reviews UIDAI's operational performance, relying primarily on administrative documentation submitted directly by MeitY[16].

6.6 The State of Aadhaar Initiative (Dalberg / IDinsight Data)

The State of Aadhaar research project—conducted initially by IDinsight (2016–2018) and subsequently expanded by Dalberg (2019 onward) with philanthropic backing from Omidyar Network India—represents the largest independent empirical dataset evaluating Aadhaar's performance . The 2019 edition surveyed over 167,000 households across India, creating an open-access empirical dataset measuring enrolment coverage gaps, biometric authentication failure frequencies, and ground-level user experience[17].

<+------------------------------------------------------------------------------------+
|                         Primary Data Sources on UIDAI                              |
+------------------------------------------+-----------------------------------------+
|        Official / Government             |      Independent / Empirical            |
+------------------------------------------+-----------------------------------------+
| * UIDAI Dashboard & Monthly Releases     | * State of Aadhaar (Dalberg/IDinsight)  |
| * Statutory Annual Reports (Sec. 27)     | * Academic Field Studies (Khera et al.) |
| * CAG Audit Report No. 24 (2021)         | * Independent Technical Audits (IIT-D)  |
| * Parliamentary Q&A Repositories         | * Siasat Investigative Reporting        |
+------------------------------------------+-----------------------------------------+

6.7 Direct Benefit Transfer (DBT) Bharat Portal and PFMS

The DBT Mission under the Cabinet Secretariat operates the DBT Bharat portal (dbtbharat.gov.in), monitoring state and central welfare payment distributions routed via the Aadhaar Payment Bridge System (APBS) and the Public Financial Management System (PFMS). Beneficiaries use PFMS public tracking utilities ("Know Your Payments") to verify whether their Aadhaar numbers are seeded to valid bank accounts to receive statutory benefits[1].

6.8 Judicial Databases and Unmapped Case-Level Data

Aadhaar litigation records are accessible via legal repositories such as Indian Kanoon, e-Courts, the National Judicial Data Grid (NJDG), and Supreme Court judgment databases,. However, no consolidated official database exists that categorically tags cases by issues such as "authentication failure" or "denial of welfare entitlements." Legal researchers must reconstruct structural litigation trends through manual keyword filtering across disparate court indexes [6].[7]

7. Research that Engages with UIDAI

7.1 Technical Audits: IIT Delhi Computer Science Evaluation

Computer science researchers at IIT Delhi conducted a technical audit evaluating the security architecture of the Aadhaar platform . The published paper identified architectural vulnerabilities associated with centralized biometric repositories, including potential user profiling risks, replay attack vectors, biometric spoofing risks, and supply-chain vulnerabilities within authentication hardware endpoints [13].

7.2 Welfare Economics and Exclusion Analysis: EPW Studies (Khera et al.)

In the Economic and Political Weekly (December 2017), development economist Reetika Khera analyzed empirical field evidence concerning Aadhaar integration across the Public Distribution System (PDS), MGNREGA employment payments, and social security pensions. The study found limited empirical support for government claims regarding leak-reduction efficiencies, while documenting recurring instances where mandatory biometric authentication led to the exclusion of vulnerable households from statutory rations. Khera expanded these empirical findings in Dissent on Aadhaar: Big Data Meets Big Brother (2019)[5].

7.3 Large-Scale Population Studies: Dalberg's People's Perspective

The 2019 State of Aadhaar: A People's Perspective survey reported high population coverage (approximately 95 percent among adult residents), while noting that roughly 28 million adults remained unenrolled due to documentation barriers. While approximately 80 percent of respondents reported that Aadhaar simplified service access, a significant minority experienced recurring authentication failures that caused delays or complete denials of essential public benefits [17].

7.4 Systemic Design Critiques: ICT Project Ethics Literature

Academic literature examining the design assumptions of large-scale Information and Communication Technology (ICT) projects argues that systems presupposing high digital literacy, stable internet connectivity, and physical biometric readability produce systemic exclusion. These studies contend that exclusion risks are inherent to the platform's architectural design rather than mere temporary operational glitches[7].

7.5 Governance Gaps: Justice B.N. Srikrishna Committee Report

The 2018 Justice B.N. Srikrishna Committee report (A Free and Fair Digital Economy) identified structural governance gaps in the original Aadhaar framework . It highlighted that UIDAI lacked regulatory mechanisms to investigate and penalize non-compliant third-party entities operating within the external authentication ecosystem[11].

7.6 Ground-Level Entitlement Denials: Siasat Field Reporting

Investigative reporting published in Siasat (November 2025) detailed recurring e-KYC authentication failures at Point-of-Sale (PoS) ration distribution terminals in southern India, tracing food entitlement denials to persistent biometric matching failures among manual laborers[18] .

7.7 Global Policy Benchmarking: World Bank ID4D Case Studies

The World Bank's Identification for Development (ID4D) initiative documents Aadhaar as a benchmark model for foundational identity rollouts in low- and middle-income countries, emphasizing its cost-effective public-private enrolment ecosystem[19].

7.8 Civil-Liberties Advocacy: Usha Ramanathan’s Legal Scholarship

Legal scholar Usha Ramanathan has published critiques tracing Aadhaar's shift from an opt-in welfare identifier to an expansive identity requirement . Her scholarship highlights legal risks concerning surveillance, data function creep, and foreign vendor licensing of central de-duplication software—arguments reflected in Justice Chandrachud's 2018 constitutional dissent [8].

8. International Comparative Analysis

8.1 Estonian X-Road Model: Centralised Biometrics vs Decentralised Data Exchange

In contrast to India's centralized biometric architecture, Estonia's digital identity network—built upon the X-Road (X-tee) data exchange layer launched in 2001—operates on a decentralized architecture . Personal data remains distributed across separate agency databases linked via encrypted, auditable exchange protocols. Estonian citizens monitor system usage through a personal dashboard that records every instance a state or private entity queries their identity data [13].

8.2 National Implementations: Nigeria (NIN) and Rwanda

  • Nigeria: Modeled parts of its National Identification Number (NIN) framework on UIDAI's centralized system. By mid-2025, Nigeria's National Identity Management Commission (NIMC) had registered approximately 121 million residents toward a revised World Bank target of 180 million registrations by late 2026 [19].
  • Rwanda: Developed a centralized national population register achieving over 98 percent population coverage, serving as an example of centralized identity administration within a smaller geographic context[19].

8.3 Judicial Halts and Regulatory Limits: Kenya's Huduma Namba

In Kenya, the government initiated a centralized biometric identification rollout named Huduma Namba in 2019. However, the Kenyan High Court issued rulings in January 2020 and October 2021 halting mandatory deployment until comprehensive Data Protection Impact Assessments (DPIAs) and statutory privacy frameworks were established[8].

8.4 European Union eIDAS 2.0 Decentralised Architecture

The European Union's updated eIDAS 2.0 regulatory framework (Regulation [EU] 2024/1183) mandates European Digital Identity Wallets managed directly by member states. The framework explicitly rejects centralized biometric repositories, adopting decentralized, privacy-preserving cryptographic verification standards[20] .

8.5 Global Technical Export: MOSIP and International Deployments

The Modular Open Source Identity Platform (MOSIP)—developed at IIIT-Bangalore with philanthropic funding from the Bill & Melinda Gates Foundation, Tata Trusts, and Norad—adapts Aadhaar's core platform architecture into an open-source framework . MOSIP has been piloted or deployed in at least nine countries, including the Philippines, Morocco, Sri Lanka, Uganda, Ethiopia, and Sierra Leone [17]. The Philippine Identification System (PhilSys) represents the largest national deployment of MOSIP technology, registering over 71 million citizens by 2022 [19].

<+-----------------------------------------------------------------------------------+
|               Comparative Models of Foundational Digital Identity                 |
+-------------------+--------------------+--------------------+---------------------+
| Architectural     | Country / System   | Core Data Storage  | User Transparency   |
| Model             |                    | Architecture       | Features            |
+-------------------+--------------------+--------------------+---------------------+
| Centralized       | India (Aadhaar)    | Single CIDR        | Virtual ID, App-    |
| Biometric         |                    | Repository         | based lock          |
+-------------------+--------------------+--------------------+---------------------+
| Decentralized     | Estonia            | Distributed X-Road | Real-time citizen   |
| Data Exchange     | (e-ID / X-Road)    | Databases          | audit logs          |
+-------------------+--------------------+--------------------+---------------------+
| Decentralized     | European Union     | User-held Digital  | Zero-knowledge      |
| Digital Wallet    | (eIDAS 2.0)        | Wallets            | proofs              |
+-------------------+--------------------+--------------------+---------------------+
| Modular Open-     | Philippines        | Distributed or     | Configurable by     |
| Source (MOSIP)    | (PhilSys / MOSIP)  | Centralized        | adopting nation     |
+-------------------+--------------------+--------------------+---------------------+

9. Data Challenges

9.1 Data Access Gaps and Reliance on Institutional Self-Reporting

Public understanding of Aadhaar's systemic operational metrics relies almost entirely on self-reported data released by UIDAI via its public dashboard and annual publications . As noted in CAG Audit Report No. 24 of 2021, external oversight remains constrained when auditing bodies receive data only "to the extent... furnished" by the authority[2].

9.2 Downstream Data Breaches and SRDH Security Risks

Data security incidents highlight vulnerabilities located in external, downstream databases rather than within the core CIDR . Prominent incidents—including a 2017 incident where the Kerala pension portal exposed 3.5 million resident records and a 2018 vulnerability on a state-owned LPG distributor platform—involved exposed State Resident Data Hubs (SRDHs) and external API endpoints. While UIDAI maintained that the central CIDR remained uncompromised, these downstream incidents exposed sensitive resident information due to weaker security protocols in secondary systems[13].

9.3 Unresolved Constitutional and Legislative Questions

Two structural legal questions remain unresolved in Indian jurisprudence:

  1. The Seven-Judge Money Bill Reference: Following Rojer Mathew v. South Indian Bank Ltd. (2020), the question of whether passing the Aadhaar Act as a Money Bill violated Article 110 of the Constitution was referred to a seven-judge Constitution Bench, which remains pending adjudication [7].
  2. Statutory Alignment with DPDP Act, 2023: Reconciling the sector-specific Aadhaar Act, 2016 with the horizontal Digital Personal Data Protection Act, 2023 requires explicit legislative modifications regarding data retention, consent mechanisms, and independent regulatory oversight [11].

10. Way Ahead

10.1 Harmonisation with the Digital Personal Data Protection Act, 2023

Legislative proposals focus on amending the Aadhaar Act, 2016 to align its data retention guidelines, consent standards, and correction protocols with the provisions of the Digital Personal Data Protection Act, 2023. This statutory harmonisation fulfills recommendations original formulated in the 2018 Justice Srikrishna Committee report.

10.2 Adjudication of the Seven-Judge Money Bill Reference

Legal scholars and constitutional experts continue to emphasize the importance of scheduling the seven-judge Constitution Bench hearing to adjudicate the Money Bill reference from Rojer Mathew. Resolving this constitutional issue is essential to establish legislative clarity regarding the passage of foundational statutes .

10.3 Independent Auditing and Open Tracking Frameworks

Policy researchers advocate for establishing independent verification metrics to track biometric authentication failure rates and welfare exclusions. Expanding on the open-data research methodologies introduced by the State of Aadhaar surveys would provide reliable empirical oversight to supplement UIDAI's internal reporting .

10.4 User-Centric Privacy Enhancements and Independent Institutional Oversight

UIDAI has introduced privacy tools including Virtual IDs (VIDs), biometric locking features, and selective QR-based demographic sharing via its mobile app . Policy experts argue that introducing user-auditable access logs—similar to Estonia's X-Road model, where residents receive notifications whenever an agency accesses their identity records—would enhance user privacy and systemic transparency . Furthermore, civil liberties advocates continue to press for independent regulatory oversight of the Aadhaar ecosystem to ensure objective monitoring of vendor software, systemic security, and data handling practices.

11. Also Known As

  • Aadhaar Authority
  • UID Authority of India
  • "The Authority" (Statutory definition under Section 2(e) of the Aadhaar Act, 2016)
  • UID (Unique Identification) Project (Historical reference to the 2009–2016 executive initiative)

12. References

  1. 1.00 1.01 1.02 1.03 1.04 1.05 1.06 1.07 1.08 1.09 1.10 1.11 1.12 1.13 1.14 1.15 1.16 1.17 1.18 Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016 (No 18 of 2016) ss 2, 3, 7, 11, 23, 27.
  2. 2.0 2.1 2.2 2.3 Comptroller and Auditor General of India, Report No 24 of 2021: Performance Audit of Aadhaar (2021).
  3. 3.0 3.1 Unique Identification Authority of India (UIDAI), ‘UIDAI records 221 crore Aadhaar authentication transactions in August 2025, 10% increase over August 2024’ (8 September 2025) https://www.digitalindia.gov.in/press_release/uidai-records-221-crore-aadhaar-authentication-transactions-in-august-2025-10-increase-over-august-2024/ accessed 30 August 2026.
  4. 4.0 4.1 Reetika Khera, ‘Impact of Aadhaar in Welfare Programmes’ (SSRN, 29 September 2017) https://papers.ssrn.com/sol3/papers.cfm?abstract_id=3045235 accessed 30 August 2026.
  5. 5.0 5.1 5.2 Reetika Khera, ‘Aadhaar Failures in Food Services and Welfare’ (EPW Engage, 2019) https://www.epw.in/engage/article/aadhaar-failures-food-services-welfare accessed 30 August 2026.
  6. 6.0 6.1 6.2 6.3 6.4 6.5 Justice K S Puttaswamy (Retd) v Union of India (2019) 1 SCC 1.
  7. 7.0 7.1 7.2 7.3 Rojer Mathew v South Indian Bank Ltd (2020) 6 SCC 1.
  8. 8.0 8.1 8.2 Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.
  9. Comptroller and Auditor General of India, Report No 24 of 2021: Performance Audit on Functioning of Unique Identification Authority of India (2022) https://cag.gov.in/en/audit-report/details/116042 accessed 30 August 2026.
  10. Digital Personal Data Protection Act 2023 (No 22 of 2023).
  11. 11.0 11.1 11.2 Committee of Experts under the Chairmanship of Justice B N Srikrishna, A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians (Ministry of Electronics and Information Technology 2018) https://www.meity.gov.in/static/uploads/2024/10/325b042fa11300e06839fdfdb01a0aef.pdf accessed 30 August 2026.
  12. 12.0 12.1 PRS Legislative Research, ‘The Aadhaar and Other Laws (Amendment) Bill, 2019’ (24 June 2019) https://prsindia.org/billtrack/the-aadhaar-and-other-laws-amendment-bill-2019 accessed 30 August 2026.
  13. 13.0 13.1 13.2 13.3 Shweta Agrawal, Subhashis Banerjee and Subodh Sharma, ‘Privacy and Security of Aadhaar: A Computer Science Perspective’ (2017) 52(37) Economic and Political Weekly 93 https://www.cse.iitd.ac.in/~suban/reports/aadhaar.pdf accessed 30 August 2026.
  14. 14.0 14.1 Unique Identification Authority of India (UIDAI), ‘UIDAI records 221 crore Aadhaar authentication transactions in August 2025, 10% increase over August 2024’ (8 September 2025) https://www.digitalindia.gov.in/press_release/uidai-records-221-crore-aadhaar-authentication-transactions-in-august-2025-10-increase-over-august-2024/ accessed 30 August 2026.
  15. Unique Identification Authority of India (UIDAI), Annual Report 2023–24 (2024) https://uidai.gov.in/images/2023-24_Final_English_Final.pdf accessed 30 August 2026.
  16. 16.0 16.1 Comptroller and Auditor General of India, Report No 24 of 2021: Performance Audit on Functioning of Unique Identification Authority of India (2022) https://cag.gov.in/en/audit-report/details/116042 accessed 30 August 2026.
  17. 17.0 17.1 Swetha Totapally, Petra Sonderegger, Priti Rao, Jasper Gosselt and Gaurav Gupta, State of Aadhaar: A People’s Perspective (Dalberg 2019) https://dalberg.com/wp-content/uploads/2025/06/State-of-Aadhaar_2019_Report_web.pdf accessed 30 August 2026.
  18. Arnav Panwar, ‘Call for better regulations on Aadhaar governance and privacy’ (The Siasat Daily, 7 November 2025) https://www.siasat.com/aadhaar-data-collection-through-false-promise-of-inclusion-3292723/amp/ accessed 30 August 2026.
  19. 19.0 19.1 19.2 19.3 World Bank, ID4D Global Dataset 2025 (2025) https://id4d.worldbank.org/global-dataset accessed 30 August 2026.
  20. Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework [2024] OJ L 2024/1183 https://eur-lex.europa.eu/eli/reg/2024/1183/oj accessed 30 August 2026.
Cookies help us deliver our services. By using our services, you agree to our use of cookies.