Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018
possibility of use of stored biometric and replay of biometrics captured from other
source. Requesting entities are not legally allowed to store biometrics captured for
Aadhaar authentication under Regulation 17(1)(a) of the Authentication Regulations.
(9) Referring to slide/page 13, please confirm that the architecture under the Aadhaar Act includes:
(i) authentication user agencies (e.g. Kerala Dairy Farmers Welfare Fund Board);
(ii) authentication service agencies (e.g. Airtel); and (iii) CIDR. Ans.: UIDAI appoints Requesting
Entities (AUA/KUA) and Authentication Service Agency (ASA) as per Regulation 12 of
Authentication Regulations. List of Requesting Entitles (AUA/KUA) and Authentication Service
Agency appointed by UIDAI is available on UIDAIs website. An AUA/KUA can do authentication on
behalf of other entities under Regulation 15 and Regulation 16.
(10) Please confirm that one or more entitles in the Aadhaar architecture described in the previous
paragraph record the date and time of the authentication, the client IP, the device ID and purpose of
authentication.
Ans.: UIDAI does not ask requesting entities to maintain any logs related to IP address of the device,
GPS coordinates of the device and purpose of authentication. However, AUAs like banks, telecom
etc., in order to ensure that their systems are secure, frauds are managed, they may store additional
information as per their requirement under their respective laws to secure their system. Section
32(3) of the Aadhaar Act specifically prevents the UIDAI from either by itself or through any entity
under its control to keep or maintain any information about the purpose of authentication.
Requesting entities are mandated to maintain following logs as per Regulation 18 of the
Authentication Regulations. These are:
(i) the Aadhaar number against which authentication is sought;
(ii) specified parameters of authentication request submitted;
(iii) specified parameters received as authentication response;
(iv) the record of disclosure of information to the Aadhaar number holder at the time
of authentication; and
(v) record of consent of the Aadhaar number holder for authentication, but shall not,
in any event, retain the PID information.
Further, even if a requesting entity captures any other data as per their own
requirement, UIDAI will only audit the authentication logs maintained by the
requesting entity as per Regulation 18(1) of the Authentication Regulations.
Indian Kanoon - http://indiankanoon.org/doc/127517806/
39