Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018
(3) Upon expiry of the period specified in sub-regulation (2), the logs shall be archived for a period
of five years or the number of years as required by the laws or regulations governing the entity,
whichever is later, and upon expiry of the said period, the logs shall be deleted except those records
required to be retained by a court or required to be retained for any pending disputes.
(4) The requesting entity shall not share the authentication logs with any person other than the
concerned Aadhaar number holder upon his request or for grievance redressal and resolution of
disputes or with the Authority for audit purposes. The authentication logs shall not be used for any
purpose other than stated in this sub-regulation. (5) The requesting entity shall comply with all
relevant laws, rules and regulations, including, but not limited to, the Information Technology Act,
2000 and the Evidence Act, 1872, for the storage of logs.
(6) The obligations relating to authentication logs as specified in this regulation shall continue to
remain in force despite termination of appointment in accordance with these regulations.
xx xx xx
26. Storage and Maintenance of Authentication Transaction Data. (1) The Authority shall store and
maintain authentication transaction data, which shall contain the following information:
(a) authentication request data received including PID block;
(b) authentication response data sent;
(c) meta data related to the transaction;
(d) any authentication server side configurations as necessary Provided that the
Authority shall not, in any case, store the purpose of authentication.
The Aadhaar (Data Security) Regulations, 2016
3. Measures for ensuring information security. (1) The Authority may specify an
information security policy setting out inter alia the technical and organisational
measures to be adopted by the Authority and its personnel, and also security
measures to be adopted by agencies, advisors, consultants and other service
providers engaged by the Authority, registrar, enrolling agency, requesting entities,
and Authentication Service Agencies.
(2) Such information security policy may provide for:
(a) identifying and maintaining an inventory of assets associated with the
information and information processing facilities;
Indian Kanoon - http://indiankanoon.org/doc/127517806/
24