Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018 (3) Upon expiry of the period specified in sub-regulation (2), the logs shall be archived for a period of five years or the number of years as required by the laws or regulations governing the entity, whichever is later, and upon expiry of the said period, the logs shall be deleted except those records required to be retained by a court or required to be retained for any pending disputes. (4) The requesting entity shall not share the authentication logs with any person other than the concerned Aadhaar number holder upon his request or for grievance redressal and resolution of disputes or with the Authority for audit purposes. The authentication logs shall not be used for any purpose other than stated in this sub-regulation. (5) The requesting entity shall comply with all relevant laws, rules and regulations, including, but not limited to, the Information Technology Act, 2000 and the Evidence Act, 1872, for the storage of logs. (6) The obligations relating to authentication logs as specified in this regulation shall continue to remain in force despite termination of appointment in accordance with these regulations. xx xx xx 26. Storage and Maintenance of Authentication Transaction Data. (1) The Authority shall store and maintain authentication transaction data, which shall contain the following information: (a) authentication request data received including PID block; (b) authentication response data sent; (c) meta data related to the transaction; (d) any authentication server side configurations as necessary Provided that the Authority shall not, in any case, store the purpose of authentication. The Aadhaar (Data Security) Regulations, 2016 3. Measures for ensuring information security. (1) The Authority may specify an information security policy setting out inter alia the technical and organisational measures to be adopted by the Authority and its personnel, and also security measures to be adopted by agencies, advisors, consultants and other service providers engaged by the Authority, registrar, enrolling agency, requesting entities, and Authentication Service Agencies. (2) Such information security policy may provide for: (a) identifying and maintaining an inventory of assets associated with the information and information processing facilities; Indian Kanoon - http://indiankanoon.org/doc/127517806/ 24

Select target paragraph3