Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018
30. Biometric information deemed to be sensitive personal information. The biometric information
collected and stored in electronic form, in accordance with this Act and regulations made
thereunder, shall be deemed to be electronic record and sensitive personal data or information, and
the provisions contained in the Information Technology Act, 2000 (21 of 2000) and the rules made
thereunder shall apply to such information, in addition to, and to the extent not in derogation of the
provisions of this Act.
Explanation.For the purposes of this section, the expressions
(a) electronic form shall have the same meaning as assigned to it in clause (r) of sub-section (1) of
Section 2 of the Information Technology Act, 2000 (21 of 2000);
(b) electronic record shall have the same meaning as assigned to it in clause (t) of sub-section (1) of
Section 2 of the Information Technology Act, 2000 (21 of 2000);
(c) sensitive personal data or information shall have the same meaning as assigned to it in clause
(iii) of the Explanation to Section 43-A of the Information Technology Act, 2000 (21 of 2000).
37) Section 32 provides that the Authority shall maintain authentication records in such manner
and for such period as may be specified by regulations and enables every Aadhaar number holder to
obtain his authentication record in such manner as may be specified by regulations. This provision
also puts an embargo upon the Authority to collect, keep or maintain any information about purpose
of authentication. Section 33, however, creates an exception to the provisions of Section 28(ii) and
(v) as well as Section 29(ii) by stipulating that the information can be disclosed pursuant to an order
of a court not inferior to that of a District Judge. It also carves out another exception in those cases
where it becomes necessary to disclose the information in the interest of national security in
pursuance of a direction of an officer not below the rank of Joint Secretary to the Government of
India specially authorised in this behalf by an order of the Central Government.
38) Sections 34 to 47 in Chapter VII of the Act enumerate various kinds of offences and provide
penalties for such offences. For our purposes, relevant Section is Section 37 which makes act of
disclosing identity information as offence which is punishable with imprisonment for a term which
may extend to three years or with a fine which may extend to ten thousand rupees. In the case of a
company, this fine can extend to one lakh rupees. Likewise, Section 38 provides for penalty for
unauthorised access to the CIDR. Penalties for tampering with data in CIDR (Section 39) and
unauthorised use by requesting entity (Section 40) are also stipulated.
Cognizance of offences under this Chapter can be taken by a court only on a complaint made by the
Authority or any officer or person authorised by it.
39) Section 50 of the Act empowers the Central Government to issue directions to the Authority in
writing from time to time and the Authority shall be bound to carry out such directions on questions
of policy. Section 53 empowers the Central Government to make rules to carry out the provisions of
the Act generally as well as the specific matters enumerated in sub-section (2) thereof. Section 54
Indian Kanoon - http://indiankanoon.org/doc/127517806/
19