Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018
(a) unless otherwise provided in this Act, obtain the consent of an individual before collecting his
identity information for the purposes of authentication in such manner as may be specified by
regulations; and
(b) ensure that the identity information of an individual is only used for submission to the Central
Identities Data Repository for authentication.
(3) A requesting entity shall inform, in such manner as may be specified by regulations, the
individual submitting his identity information for authentication, the following details with respect
to authentication, namely
(a) the nature of information that may be shared upon authentication;
(b) the uses to which the information received during authentication may be put by the requesting
entity; and
(c) alternatives to submission of identity information to the requesting entity.
(4) The Authority shall respond to an authentication query with a positive, negative or any other
appropriate response sharing such identity information excluding any core biometric information.
33) Under Section 10, the Authority is given power to engage one or more entities to establish and
maintain the CIDR and to perform any other functions as may be specified by regulations.
34) Chapter IV deals with the Establishment of the Authority. As per Section 11, the Central
Government, by notification, shall establish an Authority to be known as the Unique Identification
Authority of India. Notification dated July 12, 2016 was issued by the Central Government
establishing the Authority. Other provisions in this Chapter deal with the composition of the
Authority, qualifications for appointment of the Chairperson and Members of Authority; term of
their office and their removal; and restrictions on their employment after cessation of office. It also
provides for the functions of Chairperson as well as office of the Chief Executive Officer (CEO) and
his functions and the meetings of the Authority etc. Powers and functions of the Authority are
stipulated in Section 23.
35) Chapter V talks of grants to the Authority by the Central Government as well as accounts and
audit and annual report of the Authority.
36) Chapter VI deals with the important aspects pertaining to protection of information. Section 28
of the Aadhaar Act puts an obligation on the Authority to ensure the security of identity information
and authentication records of individuals. Likewise, Section 29 imposes certain restrictions on
sharing information i.e. core biometric information collected or created under the Act or the identity
information. The biometric information collected and stored in electronic form, in accordance with
this Act and regulations made thereunder, is treated as electronic record and sensitive personal data
or information by virtue of Section 30 of the Act. As these are very material and significant
Indian Kanoon - http://indiankanoon.org/doc/127517806/
17