Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018
provisions of the Act, the same are reproduced verbatim in their entirety:
28. Security and confidentiality of information. (1) The Authority shall ensure the
security of identity information and authentication records of individuals.
(2) Subject to the provisions of this Act, the Authority shall ensure confidentiality of
identity information and authentication records of individuals.
(3) The Authority shall take all necessary measures to ensure that the information in
the possession or control of the Authority, including information stored in the
Central Identities Data Repository, is secured and protected against access, use or
disclosure not permitted under this Act or regulations made thereunder, and against
accidental or intentional destruction, loss or damage.
(4) Without prejudice to sub-sections (1) and (2), the Authority shall
(a) adopt and implement appropriate technical and organisational security measures;
(b) ensure that the agencies, consultants, advisors or other persons appointed or
engaged for performing any function of the Authority under this Act, have in place
appropriate technical and organisational security measures for the information; and
(c) ensure that the agreements or arrangements entered into with such agencies,
consultants, advisors or other persons, impose obligations equivalent to those
imposed on the Authority under this Act, and require such agencies, consultants,
advisors and other persons to act only on instructions from the Authority.
29. Restriction on sharing information. (1) No core biometric information, collected or created
under this Act, shall be
(a) shared with anyone for any reason whatsoever; or
(b) used for any purpose other than generation of Aadhaar numbers and authentication under this
Act. (2) The identity information, other than core biometric information, collected or created under
this Act may be shared only in accordance with the provisions of this Act and in such manner as may
be specified by regulations. (3) No identity information available with a requesting entity shall be
(a) used for any purpose, other than that specified to the individual at the time of submitting any
identity information for authentication; or
(b) disclosed further, except with the prior consent of the individual to whom such information
relates. (4) No Aadhaar number or core biometric information collected or created under this Act in
respect of an Aadhaar number holder shall be published, displayed or posted publicly, except for the
purposes as may be specified by regulations.
Indian Kanoon - http://indiankanoon.org/doc/127517806/
18