UIDAI- Use & Misuse in India :

Aadhar card pic by TEN

The Unique Identification Authority of India (UIDAI) is a statutory authority established by the Government of India in 2016 under the provisions of the Aadhaar Act, 2016 . It is responsible for issuing Aadhaar, a 12-digit individual identification number to all residents of India .

Key Functions and Responsibilities of UIDAI:

  • Aadhaar Issuance: UIDAI is mandated to issue Aadhaar numbers to all residents of India after verifying their demographic and biometric information .
  • Enrolment and Updates: UIDAI oversees the Aadhaar enrolment and update processes through enrolment centers and online services . Residents can update their information, such as address and mobile number, in their Aadhaar records .
  • Authentication Services: UIDAI provides authentication services that allow residents to verify their identity using Aadhaar . This is used for various services, including banking, government benefits, and other identity-related applications .
  • Data Security: UIDAI is responsible for ensuring the security and privacy of the data collected for Aadhaar . It implements various security measures to protect against unauthorized access and misuse of data .
  • Aadhaar Ecosystem: UIDAI manages the Aadhaar ecosystem, which includes enrolment agencies, authentication service agencies, and other stakeholders . It also develops and maintains the technology infrastructure for Aadhaar .
  • Policy and Guidelines: UIDAI formulates policies and guidelines related to Aadhaar enrolment, authentication, and data security . It also issues circulars, notifications, and office memorandums to provide clarity on various aspects of Aadhaar .
  • Awareness and Outreach: UIDAI conducts awareness campaigns to educate residents about the benefits and uses of Aadhaar . It also provides support and assistance to residents through its website, call centers, and regional offices .
  • Grievance Redressal: UIDAI provides a grievance redressal mechanism for residents to address issues related to Aadhaar enrolment, updates, and authentication .
  • Regional Offices: UIDAI has regional offices across India to manage Aadhaar-related activities in different regions . These offices are located in cities like Delhi, Mumbai, Chennai, Kolkata, Guwahati, Hyderabad, Lucknow, and Ranchi .
  • Contact Information: Residents can contact UIDAI through the toll-free number 1947 or by email at help@uidai.gov.in .

Key Services Offered by UIDAI:

  • Update Aadhaar: Allows residents to update their demographic data (address, name, etc.) and documents in their Aadhaar .
  • Get Aadhaar: Provides options to download Aadhaar, order Aadhaar PVC card, and locate enrolment centers .
  • Aadhaar Services: Offers services such as verifying Aadhaar number, verifying email/mobile number, retrieving lost EID/UID, and locking/unlocking biometrics .

UIDAI plays a critical role in providing a unique and verifiable identity to residents of India, enabling them to access various services and benefits . It also ensures the security and privacy of the data collected for Aadhaar .

How does UIDAI protect user data ?

UIDAI employs multiple measures to protect user data, focusing on data security, privacy, and confidentiality . These measures are implemented from the point of data collection through to storage and usage .

Key Data Protection Measures Used by UIDAI:

  • Limited Information Collection: UIDAI collects only basic data fields required for issuing Aadhaar numbers and confirming the identity of Aadhaar holders . This includes name, date of birth, gender, address, parent/guardian’s name (for children), photo, ten fingerprints, and iris scans .
  • Prohibition of Sensitive Information Collection: UIDAI’s policy strictly prohibits collecting sensitive personal information like religion, caste, community, class, ethnicity, income, and health details . This prevents profiling based on such sensitive attributes .
  • Data Encryption: Enrolment data is collected using UIDAI-provided client applications and is encrypted at the source before secure transmission . Strong 2048-bit PKI encryption technologies ensure that resident data cannot be accessed, modified, or misused during field enrolment .
  • Secure Data Centers: The Central Identities Data Repository (CIDR) is guarded physically and electronically by select individuals with high clearance . Access to the CIDR database is strictly controlled and periodically reviewed . The data is secured with robust encryption and stored in highly secure data vaults .
  • Data Security Policies: UIDAI has a comprehensive security policy to ensure the safety and integrity of its data, including an Information Security Plan and policies for the CIDR .
  • Authentication Restrictions: UIDAI only responds with a ‘yes’ or ‘no’ to identity verification requests and is barred from revealing personal information in the Aadhaar database . Exceptions are made only under court orders or orders from a Joint Secretary in cases of national security .
  • No Data Linking: The UID database is not linked to other databases or information held in other databases . Its sole purpose is to verify a person’s identity with their consent at the point of service delivery .
  • Regular Audits and Security Upgrades: UIDAI uses advanced security technologies and continuously upgrades them to address emerging security threats and challenges . Regular reviews and audits of IT systems handling Aadhaar data are conducted, incorporating encryption and secure transmission protocols .
  • Strict Access Protocols: CIDR operations follow strict access protocols to limit access to the database by administrators .
  • Legal Framework and Penalties: The Aadhaar Act, 2016, details penalties for unauthorized access to the Central Identities Data Repository . Penalties include imprisonment and fines for offenses such as impersonation, unauthorized access, and data tampering .
  • Biometric Security: Biometrics are encrypted as soon as a person places their finger on a fingerprint sensor, and this encrypted data is sent to UIDAI for verification . Requesting entities, including mobile phone companies and banks, are strictly prohibited from storing, sharing, or publishing fingerprints .
  • Compliance with Data Protection Laws: UIDAI is working to align with the Digital Personal Data Protection Act, 2023, to ensure that the Aadhaar law is compatible with current data protection standards .

These measures collectively ensure that Aadhaar data is protected against unauthorized access, misuse, and breaches, maintaining the privacy and security of individuals’ information .

Join WhatsApp

Join Now

Leave a Comment