Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018 30. Biometric information deemed to be sensitive personal information. The biometric information collected and stored in electronic form, in accordance with this Act and regulations made thereunder, shall be deemed to be electronic record and sensitive personal data or information, and the provisions contained in the Information Technology Act, 2000 (21 of 2000) and the rules made thereunder shall apply to such information, in addition to, and to the extent not in derogation of the provisions of this Act. Explanation.For the purposes of this section, the expressions (a) electronic form shall have the same meaning as assigned to it in clause (r) of sub-section (1) of Section 2 of the Information Technology Act, 2000 (21 of 2000); (b) electronic record shall have the same meaning as assigned to it in clause (t) of sub-section (1) of Section 2 of the Information Technology Act, 2000 (21 of 2000); (c) sensitive personal data or information shall have the same meaning as assigned to it in clause (iii) of the Explanation to Section 43-A of the Information Technology Act, 2000 (21 of 2000). 37) Section 32 provides that the Authority shall maintain authentication records in such manner and for such period as may be specified by regulations and enables every Aadhaar number holder to obtain his authentication record in such manner as may be specified by regulations. This provision also puts an embargo upon the Authority to collect, keep or maintain any information about purpose of authentication. Section 33, however, creates an exception to the provisions of Section 28(ii) and (v) as well as Section 29(ii) by stipulating that the information can be disclosed pursuant to an order of a court not inferior to that of a District Judge. It also carves out another exception in those cases where it becomes necessary to disclose the information in the interest of national security in pursuance of a direction of an officer not below the rank of Joint Secretary to the Government of India specially authorised in this behalf by an order of the Central Government. 38) Sections 34 to 47 in Chapter VII of the Act enumerate various kinds of offences and provide penalties for such offences. For our purposes, relevant Section is Section 37 which makes act of disclosing identity information as offence which is punishable with imprisonment for a term which may extend to three years or with a fine which may extend to ten thousand rupees. In the case of a company, this fine can extend to one lakh rupees. Likewise, Section 38 provides for penalty for unauthorised access to the CIDR. Penalties for tampering with data in CIDR (Section 39) and unauthorised use by requesting entity (Section 40) are also stipulated. Cognizance of offences under this Chapter can be taken by a court only on a complaint made by the Authority or any officer or person authorised by it. 39) Section 50 of the Act empowers the Central Government to issue directions to the Authority in writing from time to time and the Authority shall be bound to carry out such directions on questions of policy. Section 53 empowers the Central Government to make rules to carry out the provisions of the Act generally as well as the specific matters enumerated in sub-section (2) thereof. Section 54 Indian Kanoon - http://indiankanoon.org/doc/127517806/ 19

Select target paragraph3