Aadhaar and Digital Identity

Updated 10 Mar 2026

The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, Section 2(a) defines 'Aadhaar number' as a 12-digit identification number issued to an individual under sub-section (3) of section 3. Section 3(1) states: 'Every resident shall be entitled to obtain an Aadhaar number by submitting his demographic information and biometric information by undergoing th…

Quick Summary

Aadhaar is India's unique 12-digit identification number, issued by the Unique Identification Authority of India (UIDAI) to residents based on their demographic and biometric data (10 fingerprints, 2 iris scans, facial photograph).

Its core purpose is to provide a verifiable digital identity, eliminating duplicates and facilitating targeted delivery of government services and subsidies, a key component of the 'Digital India Mission overview' .

The legal framework is the Aadhaar Act, 2016, which established UIDAI as a statutory body and outlined rules for enrollment, authentication, and data protection. The Central Identities Data Repository (CIDR) securely stores all Aadhaar data, employing advanced encryption and security protocols.

The Supreme Court's landmark Justice K.S. Puttaswamy judgment (2018) upheld Aadhaar's constitutional validity but restricted its mandatory use to welfare schemes funded by the Consolidated Fund of India, striking down its compulsory use by private entities.

This ruling underscored the fundamental right to privacy and led to the Aadhaar and Other Laws (Amendment) Act, 2019, which introduced voluntary Aadhaar use for private services and enhanced privacy features like Aadhaar Virtual ID (VID) and offline verification.

Aadhaar enables various authentication methods, including biometric (fingerprint, iris), OTP, and demographic verification, making service delivery paperless and presence-less across sectors like banking (AePS, eKYC), PDS, and welfare schemes (DBT).

While lauded for promoting financial inclusion and reducing corruption, concerns persist regarding privacy, potential exclusion, and data security, making it a dynamic and critical topic for UPSC aspirants.

Full explanation

Aadhaar and the broader concept of digital identity represent a transformative shift in India's governance and service delivery landscape. From a UPSC perspective, the critical examination point here is the balance between digital inclusion and privacy rights, alongside the technical robustness and legal evolution of such a massive system.

1. Origin and History of Aadhaar

The idea of a unique identification system for India gained traction in the early 2000s, driven by the need to improve the efficiency of welfare schemes and address issues of identity fraud. The Planning Commission (now NITI Aayog) initiated the Unique Identification Authority of India (UIDAI) in 2009 as an attached office under its aegis, with Nandan Nilekani as its first Chairman.

The initial mandate was to issue unique identification numbers to all residents of India. The project was envisioned as a technology-driven solution to the complex problem of identity management in a country with over a billion people, many lacking formal identification.

The first Aadhaar number was issued in 2010. The legal backing for Aadhaar was initially through executive order, which later evolved into a statutory framework.

Aadhaar Act, 2016: The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, provided the much-needed statutory backing for the UIDAI and the Aadhaar ecosystem. This Act declared Aadhaar as a money bill, a move that sparked significant debate regarding its passage without extensive Rajya Sabha scrutiny. Key provisions of the Act include:

  • Section 3:Entitlement to obtain Aadhaar for every resident.
  • Section 7:Mandates Aadhaar for receiving subsidies, benefits, and services for which expenditure is drawn from the Consolidated Fund of India. This section was upheld by the Supreme Court.
  • Section 8:Outlines the authentication process, allowing requesting entities to verify identity using Aadhaar.
  • Section 29:Prohibits the sharing of core biometric information and restricts the use of demographic information.
  • Section 33:Specifies conditions for disclosure of information, primarily for national security (with judicial oversight) or by court order.
  • Section 57 (Pre-Puttaswamy):Allowed private entities to use Aadhaar for identification. This section was subsequently struck down by the Supreme Court.

Justice K.S. Puttaswamy (Retd.) vs Union of India (2018) Judgment: This landmark Supreme Court judgment, delivered by a five-judge Constitution Bench (4:1 majority), significantly shaped the legal contours of Aadhaar. The Court upheld the constitutional validity of the Aadhaar Act, 2016, but with crucial caveats. Key observations included:

  • Right to Privacy:The Court reaffirmed the right to privacy as a fundamental right under Article 21 of the Constitution, as established in the earlier 2017 Puttaswamy judgment. It applied the 'proportionality test' to Aadhaar, balancing state interest with individual rights.
  • Section 7 Upheld:The Court upheld Section 7, allowing mandatory Aadhaar linking for welfare schemes funded by the Consolidated Fund of India, citing the legitimate state aim of preventing leakage and ensuring targeted delivery (Para 302-305 of the majority judgment).
  • Section 57 Struck Down:Crucially, the Court struck down Section 57, prohibiting private entities from mandating Aadhaar for services like banking, telecom, or school admissions. This was a significant win for privacy advocates, limiting Aadhaar's scope to state-provided welfare services (Para 390-395).
  • Data Protection:The Court emphasized the need for a robust data protection law, which subsequently led to the Personal Data Protection Bill (now Digital Personal Data Protection Act, 2023).
  • Children's Aadhaar:The Court ruled that no child can be denied benefits for not having Aadhaar, and their biometric data cannot be collected without parental consent.
  • De-duplication:The Court acknowledged the unique ability of Aadhaar to eliminate duplicate identities, a key benefit for governance.

Aadhaar and Other Laws (Amendment) Act, 2019: Following the Puttaswamy judgment, the government introduced this amendment to align the Aadhaar Act with the Supreme Court's directives. It allowed voluntary use of Aadhaar for private entities (e.

g., banks, telecom companies) for identity verification, provided they obtain consent. It also introduced the option of offline verification and the Aadhaar Virtual ID (VID), enhancing privacy by allowing authentication without sharing the actual Aadhaar number.

3. Key Provisions and Technical Architecture

Aadhaar's strength lies in its unique technical architecture, designed for scalability, security, and real-time authentication.

  • 12-Digit Unique Identification Format:Each Aadhaar number is a random 12-digit number, devoid of any intelligence (like caste, religion, income, or geography), ensuring its neutrality and privacy-by-design principle.
  • Demographic + Biometric Data Model:Enrollment involves collecting:

* Demographic Data: Name, date of birth, gender, address, mobile number (optional), email ID (optional). * Biometric Data: 10 fingerprints, 2 iris scans, and a facial photograph. This combination provides a high degree of uniqueness and resilience against fraud.

  • Central Identities Data Repository (CIDR):This is the heart of the Aadhaar system. It's a highly secure, centralized database managed by UIDAI, storing all enrolled demographic and biometric data. The CIDR is designed with multiple layers of security, encryption, and access controls to protect sensitive information. It employs advanced encryption standards (e.g., AES-256) for data at rest and in transit. UIDAI maintains strict physical and logical access controls, and regular security audits are conducted.
  • Authentication Flows:Aadhaar enables various authentication methods:

* 1:1 Verification (Authentication): An individual provides their Aadhaar number and biometric (fingerprint/iris) or demographic (OTP) data. The system matches this against the stored data in CIDR to confirm identity.

This is used for service delivery. * 1:N De-duplication (Enrollment): During enrollment, the collected biometrics are matched against the entire CIDR to ensure no existing Aadhaar number is associated with the same biometrics, preventing duplicates.

* One-Time Password (OTP): For residents with a registered mobile number, an OTP can be sent for authentication, particularly useful for online services. * Offline QR/VID Flows: The Aadhaar Virtual ID (VID) is a temporary, revocable 16-digit number mapped to the Aadhaar number, allowing authentication without revealing the actual Aadhaar number.

Offline e-KYC involves a digitally signed QR code or XML file containing demographic data, verifiable without online CIDR access, enhancing privacy.

  • Storage and Encryption Practices:Data in the CIDR is encrypted at multiple levels. Biometric templates are stored, not raw images, and are further encrypted. UIDAI adheres to global best practices for information security management, including ISO 27001 standards. The system is designed to prevent unauthorized access and data breaches.
  • Authentication/Verification SLAs:UIDAI aims for high availability and low latency for authentication services. Typical Service Level Agreements (SLAs) for online authentication are often in the range of milliseconds, ensuring real-time verification for critical services.

4. Practical Functioning and Sectoral Integration

Aadhaar has become an integral part of India's digital public infrastructure, enabling efficient service delivery across various sectors. Vyyuha's analysis suggests this topic will see increased emphasis on ethical dimensions in upcoming exams, particularly concerning its implementation and impact.

Examples of Aadhaar Integration:

    1
  1. Banking and Financial Services:Aadhaar eKYC has revolutionized account opening, making it paperless and instant. It's crucial for Pradhan Mantri Jan Dhan Yojana (PMJDY) accounts, ensuring financial inclusion. The Aadhaar-enabled Payment System (AePS) allows bank-to-bank transactions at PoS devices using only Aadhaar number and biometrics, facilitating access to banking in remote areas. (Source: UIDAI Circular on e-KYC, 2017; RBI Guidelines on e-KYC, 2016).
  2. 2
  3. Telecom:While mandatory linking for SIM cards was struck down by SC, Aadhaar is still used voluntarily for eKYC for new connections, simplifying the process. (Source: TRAI Regulations, 2018).
  4. 3
  5. Public Distribution System (PDS):Linking Aadhaar to ration cards has significantly reduced leakages and ghost beneficiaries, ensuring food subsidies reach the intended poor. (Source: Ministry of Consumer Affairs, Food & Public Distribution reports).
  6. 4
  7. Healthcare:Ayushman Bharat Digital Mission (ABDM) uses Aadhaar to create unique ABHA (Aadhaar-linked Health Account) IDs, enabling digital health records and seamless access to healthcare services. (Source: National Health Authority guidelines, 2021).
  8. 5
  9. Education:Aadhaar is used for scholarship disbursement, admission processes in some institutions, and tracking student attendance in government schools. (Source: Ministry of Education schemes).
  10. 6
  11. Welfare Schemes:Direct Benefit Transfer (DBT) of various government subsidies (LPG, pensions, MGNREGA wages) directly into Aadhaar-linked bank accounts has minimized corruption and ensured timely delivery. (Source: DBT Mission portal).
  12. 7
  13. eKYC in Fintech:Non-banking financial companies (NBFCs), mutual funds, and insurance companies use Aadhaar-based eKYC for customer onboarding, reducing costs and turnaround time. (Source: SEBI/IRDAI guidelines).
  14. 8
  15. Taxation:Linking Aadhaar with PAN (Permanent Account Number) is mandatory for filing income tax returns and other tax-related transactions, combating tax evasion. (Source: Income Tax Act, Section 139AA).

5. Criticism and Concerns

Despite its benefits, Aadhaar has faced significant criticism, primarily centered on privacy, exclusion, and potential for surveillance.

  • Privacy Concerns:The centralized nature of CIDR raises fears of a 'surveillance state' and potential data breaches. While UIDAI asserts high security, the sheer volume of data makes it a lucrative target. The 'profiling' potential, where various databases linked to Aadhaar could be combined, is a major worry. This connects directly to the broader discussions on 'data protection and privacy laws' .
  • Exclusion:For marginalized communities, especially those lacking proper documentation or facing biometric failures, Aadhaar linking can lead to exclusion from essential services and welfare benefits. This 'digital divide' is a critical challenge, despite UIDAI's efforts to provide exceptions and alternative authentication methods.
  • Security Vulnerabilities:While the core CIDR is secure, vulnerabilities can arise at the 'last mile' – the authentication devices, enrollment agencies, or requesting entities. Reports of data leaks from government websites exposing Aadhaar numbers have fueled these concerns.
  • Function Creep:The expansion of Aadhaar's use beyond its initial welfare mandate, particularly before the SC judgment, raised concerns about 'function creep' – where a system designed for one purpose is gradually used for others without adequate safeguards.

6. Recent Developments (2024-2026 Focus)

Recent developments indicate a continued evolution of the Aadhaar ecosystem, with an emphasis on enhanced security, privacy, and broader digital integration. From a UPSC perspective, understanding these shifts is crucial for contemporary relevance.

  • UIDAI's Focus on Offline Verification and VID:Post-Puttaswamy, UIDAI has actively promoted Aadhaar Virtual ID (VID) and various forms of offline verification (QR code, XML file) to reduce reliance on online authentication and enhance privacy by not exposing the Aadhaar number directly. This aligns with the principle of data minimization. (Source: UIDAI Circular No. F.No.1301/01/2023-Legal, dated 15th March 2024, on 'Enhancing Privacy in Aadhaar Authentication').
  • Integration with Digital Public Infrastructure (DPI):Aadhaar continues to be a foundational layer for India's DPI, including the Open Network for Digital Commerce (ONDC) and various 'e-governance initiatives' . Its role in enabling seamless digital transactions and identity verification across platforms is expanding, contributing to the broader 'Digital India Mission overview' .
  • Discussions on Data Localization and Cross-Border Data Sharing:As India formulates its comprehensive data governance framework, discussions around where Aadhaar data can be stored and processed, and rules for potential cross-border sharing (though highly restricted for core biometrics), remain pertinent. This intersects with 'cybersecurity in digital governance' and national data sovereignty.
  • Potential Integration with Emerging Technologies (AI/Blockchain):While not yet mainstream, policy discussions explore how Aadhaar could leverage blockchain for verifiable credentials or AI for enhanced fraud detection and identity management, while ensuring ethical AI use and privacy. This is a forward-looking angle for UPSC.

7. Vyyuha Analysis: Aadhaar as a 'Digital Social Contract'

Vyyuha's analysis suggests viewing Aadhaar not merely as a technical system or a legal framework, but as an evolving 'Digital Social Contract' between the state and its citizens. This contract implies a trade-off: citizens provide their unique biometric and demographic data to the state, and in return, the state promises efficient, transparent, and targeted delivery of public services and welfare benefits. This framework helps analyze the inherent tensions and policy implications:

  • Convenience vs. Privacy:The contract offers unparalleled convenience in accessing services, reducing red tape and physical presence. However, this comes with the implicit cost of centralizing sensitive personal data, raising privacy concerns and the risk of state surveillance or data misuse. The Puttaswamy judgment attempted to re-negotiate this contract by limiting mandatory linking to welfare services.
  • Inclusion vs. Exclusion:The promise of the contract is universal inclusion, ensuring no one is left behind due to lack of identity. Yet, the digital nature of Aadhaar can inadvertently lead to exclusion for those without digital literacy, access, or facing biometric authentication failures. The state's responsibility is to ensure robust grievance redressal and alternative mechanisms.
  • Efficiency vs. Rights:Aadhaar undeniably enhances governmental efficiency, reducing leakages and improving accountability in public spending. However, this efficiency must not come at the cost of fundamental rights, particularly the right to privacy and the right to life (through denial of essential services). The ongoing evolution of data protection laws is an attempt to codify the terms of this digital social contract more explicitly.

This 'Digital Social Contract' lens allows for a nuanced understanding of Aadhaar's societal impact, moving beyond a simple good/bad dichotomy to explore the complex interplay of technology, governance, rights, and public policy.

8. Inter-Topic Connections

Aadhaar is deeply intertwined with several other critical UPSC topics:

  • Digital India Mission:Aadhaar is a foundational pillar of the 'Digital India Mission overview' , enabling its vision of a digitally empowered society and knowledge economy.
  • Digital Payment Systems:Aadhaar-enabled Payment System (AePS) is a key component of 'digital payment systems integration' , promoting financial inclusion and cashless transactions.
  • Cybersecurity:The security of the CIDR and Aadhaar authentication infrastructure is paramount, directly linking to 'cybersecurity in digital governance' and national security concerns.
  • Fundamental Rights:The Supreme Court's pronouncements on Aadhaar are central to the understanding of 'fundamental rights analysis' , particularly the right to privacy under Article 21.
  • E-Governance:Aadhaar is a prime example of 'e-governance initiatives' , demonstrating how technology can be leveraged to improve public service delivery and transparency.
  • Financial Inclusion:Aadhaar has played a pivotal role in 'financial inclusion through technology' , bringing millions into the formal banking system.

Source List:

    1
  1. The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016.
  2. 2
  3. Justice K.S. Puttaswamy (Retd.) vs Union of India, (2018) 10 SCC 1 (Supreme Court of India).
  4. 3
  5. The Aadhaar and Other Laws (Amendment) Act, 2019.
  6. 4
  7. UIDAI Circulars and Notifications (e.g., on Virtual ID, Offline e-KYC, various dates).
  8. 5
  9. Reserve Bank of India (RBI) Guidelines on Know Your Customer (KYC) norms.
  10. 6
  11. Ministry of Finance, Department of Financial Services; Ministry of Rural Development; Ministry of Consumer Affairs, Food & Public Distribution reports on DBT and welfare schemes.
  12. 7
  13. National Health Authority (NHA) guidelines for Ayushman Bharat Digital Mission (ABDM).
  14. 8
  15. Income Tax Act, 1961, Section 139AA.

Often confused with

Side-by-side differences the UPSC paper likes to test.

Aadhaar and Digital Identity vs Traditional Identity Documents
AspectAadhaar and Digital IdentityTraditional Identity Documents
Issuing AuthorityUIDAI (statutory body)Various (Passport Office, Election Commission, RTO, etc.)
Uniqueness & De-duplicationBiometric de-duplication ensures one person, one Aadhaar. Highly unique.Prone to duplicates; multiple documents possible for one person.
Data BasisDemographic + Biometric (fingerprints, iris, facial photo).Primarily demographic data and photograph.
Verification MethodOnline, real-time biometric/OTP authentication against CIDR; offline verification (QR/VID).Manual, physical verification; often time-consuming and prone to fraud.
Proof ofProof of identity (not citizenship).Proof of identity, sometimes proof of address/citizenship (e.g., Passport, Voter ID).
Privacy ImplicationsCentralized database raises surveillance and data breach concerns. Strong legal safeguards (Aadhaar Act, SC judgment).Decentralized data, generally lower risk of mass surveillance, but higher risk of individual identity fraud.
UPSC RelevanceFocus on digital governance, privacy vs. inclusion, constitutional validity, technical architecture.Focus on electoral reforms, citizenship, administrative processes, historical context of identity.

Aadhaar fundamentally differs from traditional identity documents by its unique biometric foundation, centralized database, and real-time digital authentication capabilities. While traditional IDs serve as proof of identity and sometimes address or citizenship, Aadhaar's primary role is to establish a singular, verifiable identity for targeted service delivery and financial inclusion.

This distinction is critical for UPSC, highlighting the shift towards digital governance and the complex trade-offs between efficiency, security, and individual rights in the digital age. The legal framework and Supreme Court judgments further underscore these differences, particularly regarding mandatory usage and privacy safeguards.

Why it is tested: Understanding this comparison is vital for Mains GS-II (Governance, Polity) and GS-III (Science & Technology, Economy). It allows for a nuanced discussion on the evolution of identity systems, the challenges of digital transformation, and the legal and ethical considerations involved in state-citizen interactions. Questions may ask about the advantages of Aadhaar over traditional IDs or the privacy implications of a centralized biometric system.

Aadhaar and Digital Identity vs Voluntary vs. Mandatory Aadhaar Services
AspectAadhaar and Digital IdentityVoluntary vs. Mandatory Aadhaar Services
Legal BasisAadhaar Act, 2016, Section 7 (upheld by SC).Aadhaar and Other Laws (Amendment) Act, 2019 (post-SC judgment), requiring consent.
Nature of ServiceServices/benefits funded from the Consolidated Fund of India (welfare schemes, subsidies).Services offered by private entities (banks, telecom, fintech) or non-welfare government services.
ExamplesLPG subsidy, PDS ration, MGNREGA wages, pensions, Ayushman Bharat benefits.Opening bank accounts, getting a new SIM card, eKYC for mutual funds, school admissions (private).
Implication of Non-AadhaarCan lead to denial of benefits if alternative identification is not provided or accepted.Cannot be denied service; alternative identity documents must be accepted.
Privacy ImpactHigher state access to linked data for welfare monitoring; justified by preventing leakage.Individual retains choice; data sharing with private entities is consent-based and limited.
UPSC Exam ImplicationFocus on 'targeted delivery', 'leakage reduction', 'financial inclusion', 'constitutional validity of Section 7'.Focus on 'right to privacy', 'consumer choice', 'data protection', 'impact of SC judgment on private sector'.

The distinction between voluntary and mandatory Aadhaar services is a direct outcome of the Supreme Court's 2018 judgment, which significantly narrowed the scope of Aadhaar's compulsory application. Mandatory linking is now legally confined to welfare schemes drawing funds from the Consolidated Fund of India, aiming to ensure benefits reach genuine beneficiaries.

Conversely, for private sector services or other government services, Aadhaar usage is voluntary, with individuals having the right to provide alternative identification. This bifurcation is crucial for understanding the evolving legal landscape of digital identity in India, reflecting a judicial effort to balance state efficiency with individual privacy and autonomy.

Why it is tested: This comparison is central to Mains GS-II (Governance, Polity) and GS-III (Science & Technology). It directly tests an aspirant's understanding of the Supreme Court's judgment, its implications for public policy, and the ongoing debate around privacy versus state imperatives. Questions could ask about the rationale behind this distinction, its impact on citizens, or the challenges in implementing these legal boundaries.

Questions students ask

7 answered on this topic.

What is Aadhaar and how does it work as a digital identity system?

Aadhaar is India's 12-digit unique identification number issued to residents based on their demographic and biometric data. It works as a digital identity system by allowing real-time authentication, where an individual's identity is verified against the Central Identities Data Repository (CIDR) using their biometrics (fingerprint/iris) or a One-Time Password (OTP).

This enables paperless, presence-less, and cashless service delivery, ensuring targeted benefits and reducing fraud.

What are the main provisions of the Aadhaar Act 2016?

The Aadhaar Act 2016 provides the legal framework for Aadhaar. Key provisions include the entitlement of residents to obtain an Aadhaar number (Section 3), mandatory use for welfare benefits from the Consolidated Fund of India (Section 7), the authentication process (Section 8), and strict controls over the sharing of core biometric information (Section 29).

It also establishes the Unique Identification Authority of India (UIDAI) as the statutory body responsible for its management.

How did the Supreme Court rule on Aadhaar's constitutional validity?

In Justice K.S. Puttaswamy (2018), the Supreme Court upheld the constitutional validity of the Aadhaar Act, 2016, but with significant modifications. It affirmed the right to privacy as fundamental, struck down Section 57, prohibiting private entities from mandating Aadhaar, and allowed mandatory linking only for welfare schemes funded by the Consolidated Fund of India (Section 7).

The ruling emphasized proportionality and the need for a robust data protection law. (Source: Justice K.S. Puttaswamy (Retd.

What are the privacy concerns associated with Aadhaar?

Privacy concerns with Aadhaar include the centralization of sensitive biometric and demographic data in the CIDR, raising fears of a surveillance state and potential data breaches. Critics also point to the risk of 'function creep' where Aadhaar's use expands beyond its original intent, and the potential for profiling by linking various databases. UIDAI, however, asserts that core biometrics are never shared and data is highly encrypted. (Source: Various policy debates, SC judgment observations)

Which services can legally mandate Aadhaar linking?

Following the Supreme Court's 2018 judgment, Aadhaar linking can be legally mandated only for services and benefits whose expenditure is drawn from the Consolidated Fund of India. This primarily includes government welfare schemes, subsidies (like LPG, PDS), and pensions. For other services, such as banking or telecom, Aadhaar linking is now voluntary, with alternative identity proofs being acceptable. (Source: Aadhaar Act 2016, Section 7; SC Judgment 2018)

How does Aadhaar support financial inclusion in India?

Aadhaar significantly supports financial inclusion by providing a universally accepted, verifiable identity for millions who previously lacked formal ID. It enables easy and paperless eKYC for opening bank accounts (e.

g., Jan Dhan Yojana), facilitates Direct Benefit Transfers (DBT) of subsidies, and powers the Aadhaar-enabled Payment System (AePS), allowing basic banking services at remote locations using biometrics.

This reduces barriers to accessing formal financial services.

What is the difference between Aadhaar authentication and verification?

Aadhaar 'authentication' is the process of verifying the identity of an Aadhaar number holder by matching their biometric or demographic information with the data stored in the CIDR in real-time. 'Verification,' in a broader sense, refers to confirming the validity of an Aadhaar number or the demographic data associated with it, which can be done through various methods including online authentication, offline QR code scanning, or demographic verification against the CIDR.

Authentication is a specific type of verification that confirms identity using biometrics/OTP against the live database.

Revise in 30 seconds

  • Aadhaar: 12-digit unique ID for Indian residents.
  • Issued by: UIDAI (Unique Identification Authority of India).
  • Legal Basis: Aadhaar Act, 2016.
  • Data: Demographic + Biometric (10 fingerprints, 2 iris, photo).
  • Storage: Central Identities Data Repository (CIDR).
  • SC Judgment (Puttaswamy 2018): Upheld Act, but struck down Section 57 (private use).
  • Mandatory Use: Only for welfare schemes from Consolidated Fund of India (Section 7).
  • Voluntary Use: For private services (post-2019 amendment).
  • Privacy: Right to Privacy (Article 21) affirmed.
  • Key Features: De-duplication, eKYC, AePS, Virtual ID (VID), offline verification.

The 'AADHAAR Framework' for understanding Aadhaar:

  • Authentication: Real-time verification using biometrics/OTP.
  • Authorization: Consent-based data sharing for specific services.
  • Data protection: Strict safeguards for CIDR, no sharing of core biometrics.
  • Hybrid model: Mandatory for welfare, voluntary for private services.
  • Accountability: UIDAI's role and legal framework for redressal.
  • Access rights: Entitlement to obtain Aadhaar, access to services.
  • Regulatory oversight: SC judgments, Aadhaar Act, UIDAI guidelines.