Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018 possibility of use of stored biometric and replay of biometrics captured from other source. Requesting entities are not legally allowed to store biometrics captured for Aadhaar authentication under Regulation 17(1)(a) of the Authentication Regulations. (9) Referring to slide/page 13, please confirm that the architecture under the Aadhaar Act includes: (i) authentication user agencies (e.g. Kerala Dairy Farmers Welfare Fund Board); (ii) authentication service agencies (e.g. Airtel); and (iii) CIDR. Ans.: UIDAI appoints Requesting Entities (AUA/KUA) and Authentication Service Agency (ASA) as per Regulation 12 of Authentication Regulations. List of Requesting Entitles (AUA/KUA) and Authentication Service Agency appointed by UIDAI is available on UIDAIs website. An AUA/KUA can do authentication on behalf of other entities under Regulation 15 and Regulation 16. (10) Please confirm that one or more entitles in the Aadhaar architecture described in the previous paragraph record the date and time of the authentication, the client IP, the device ID and purpose of authentication. Ans.: UIDAI does not ask requesting entities to maintain any logs related to IP address of the device, GPS coordinates of the device and purpose of authentication. However, AUAs like banks, telecom etc., in order to ensure that their systems are secure, frauds are managed, they may store additional information as per their requirement under their respective laws to secure their system. Section 32(3) of the Aadhaar Act specifically prevents the UIDAI from either by itself or through any entity under its control to keep or maintain any information about the purpose of authentication. Requesting entities are mandated to maintain following logs as per Regulation 18 of the Authentication Regulations. These are: (i) the Aadhaar number against which authentication is sought; (ii) specified parameters of authentication request submitted; (iii) specified parameters received as authentication response; (iv) the record of disclosure of information to the Aadhaar number holder at the time of authentication; and (v) record of consent of the Aadhaar number holder for authentication, but shall not, in any event, retain the PID information. Further, even if a requesting entity captures any other data as per their own requirement, UIDAI will only audit the authentication logs maintained by the requesting entity as per Regulation 18(1) of the Authentication Regulations. Indian Kanoon - http://indiankanoon.org/doc/127517806/ 39

اختر الفقرة المستهدفة3