The Unique Identification Authority of India (UIDAI) is a statutory authority established by the Government of India in 2016 under the provisions of the Aadhaar Act, 2016 . It is responsible for issuing Aadhaar, a 12-digit individual identification number to all residents of India .
Key Functions and Responsibilities of UIDAI:
- Aadhaar Issuance: UIDAI is mandated to issue Aadhaar numbers to all residents of India after verifying their demographic and biometric information .
- Enrolment and Updates: UIDAI oversees the Aadhaar enrolment and update processes through enrolment centers and online services . Residents can update their information, such as address and mobile number, in their Aadhaar records .
- Authentication Services: UIDAI provides authentication services that allow residents to verify their identity using Aadhaar . This is used for various services, including banking, government benefits, and other identity-related applications .
- Data Security: UIDAI is responsible for ensuring the security and privacy of the data collected for Aadhaar . It implements various security measures to protect against unauthorized access and misuse of data .
- Aadhaar Ecosystem: UIDAI manages the Aadhaar ecosystem, which includes enrolment agencies, authentication service agencies, and other stakeholders . It also develops and maintains the technology infrastructure for Aadhaar .
- Policy and Guidelines: UIDAI formulates policies and guidelines related to Aadhaar enrolment, authentication, and data security . It also issues circulars, notifications, and office memorandums to provide clarity on various aspects of Aadhaar .
- Awareness and Outreach: UIDAI conducts awareness campaigns to educate residents about the benefits and uses of Aadhaar . It also provides support and assistance to residents through its website, call centers, and regional offices .
- Grievance Redressal: UIDAI provides a grievance redressal mechanism for residents to address issues related to Aadhaar enrolment, updates, and authentication .
- Regional Offices: UIDAI has regional offices across India to manage Aadhaar-related activities in different regions . These offices are located in cities like Delhi, Mumbai, Chennai, Kolkata, Guwahati, Hyderabad, Lucknow, and Ranchi .
- Contact Information: Residents can contact UIDAI through the toll-free number 1947 or by email at help@uidai.gov.in .
Key Services Offered by UIDAI:
- Update Aadhaar: Allows residents to update their demographic data (address, name, etc.) and documents in their Aadhaar .
- Get Aadhaar: Provides options to download Aadhaar, order Aadhaar PVC card, and locate enrolment centers .
- Aadhaar Services: Offers services such as verifying Aadhaar number, verifying email/mobile number, retrieving lost EID/UID, and locking/unlocking biometrics .
UIDAI plays a critical role in providing a unique and verifiable identity to residents of India, enabling them to access various services and benefits . It also ensures the security and privacy of the data collected for Aadhaar .
How does UIDAI protect user data ?
UIDAI employs multiple measures to protect user data, focusing on data security, privacy, and confidentiality . These measures are implemented from the point of data collection through to storage and usage .
Key Data Protection Measures Used by UIDAI:
- Limited Information Collection: UIDAI collects only basic data fields required for issuing Aadhaar numbers and confirming the identity of Aadhaar holders . This includes name, date of birth, gender, address, parent/guardian’s name (for children), photo, ten fingerprints, and iris scans .
- Prohibition of Sensitive Information Collection: UIDAI’s policy strictly prohibits collecting sensitive personal information like religion, caste, community, class, ethnicity, income, and health details . This prevents profiling based on such sensitive attributes .
- Data Encryption: Enrolment data is collected using UIDAI-provided client applications and is encrypted at the source before secure transmission . Strong 2048-bit PKI encryption technologies ensure that resident data cannot be accessed, modified, or misused during field enrolment .
- Secure Data Centers: The Central Identities Data Repository (CIDR) is guarded physically and electronically by select individuals with high clearance . Access to the CIDR database is strictly controlled and periodically reviewed . The data is secured with robust encryption and stored in highly secure data vaults .
- Data Security Policies: UIDAI has a comprehensive security policy to ensure the safety and integrity of its data, including an Information Security Plan and policies for the CIDR .
- Authentication Restrictions: UIDAI only responds with a ‘yes’ or ‘no’ to identity verification requests and is barred from revealing personal information in the Aadhaar database . Exceptions are made only under court orders or orders from a Joint Secretary in cases of national security .
- No Data Linking: The UID database is not linked to other databases or information held in other databases . Its sole purpose is to verify a person’s identity with their consent at the point of service delivery .
- Regular Audits and Security Upgrades: UIDAI uses advanced security technologies and continuously upgrades them to address emerging security threats and challenges . Regular reviews and audits of IT systems handling Aadhaar data are conducted, incorporating encryption and secure transmission protocols .
- Strict Access Protocols: CIDR operations follow strict access protocols to limit access to the database by administrators .
- Legal Framework and Penalties: The Aadhaar Act, 2016, details penalties for unauthorized access to the Central Identities Data Repository . Penalties include imprisonment and fines for offenses such as impersonation, unauthorized access, and data tampering .
- Biometric Security: Biometrics are encrypted as soon as a person places their finger on a fingerprint sensor, and this encrypted data is sent to UIDAI for verification . Requesting entities, including mobile phone companies and banks, are strictly prohibited from storing, sharing, or publishing fingerprints .
- Compliance with Data Protection Laws: UIDAI is working to align with the Digital Personal Data Protection Act, 2023, to ensure that the Aadhaar law is compatible with current data protection standards .
These measures collectively ensure that Aadhaar data is protected against unauthorized access, misuse, and breaches, maintaining the privacy and security of individuals’ information .