Home India Ministry of Electronics and Information Technology Aadhaar (Authentication and Offline Verification) Regulation...
Date: 2021-11-09 Category: Extra Ordinary State: Union Government Country: India

Aadhaar (Authentication and Offline Verification) Regulations, 2021

Issued by Ministry of Electronics and Information Technology · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

Executive Summary: This document outlines the Aadhaar Authentication and Offline Verification Regulations of 2021, superseding the 2016 regulations, effective upon publication in the Official Gazette on November 9, 2021. It defines the framework for Aadhaar authentication and offline verification, including the roles, responsibilities, and obligations of requesting entities, Authentication Service Agencies (ASAs), and Offline Verification Seeking Entities (OVSEs). It specifies the procedures for authentication, data security, and audit requirements. Key Points / Main Content: I. General Provisions: * These regulations are called the Aadhaar Authentication and Offline Verification Regulations, 2021. * The regulations come into force on the date of their publication in the Official Gazette. * Defines key terms such as "Aadhaar number," "Authentication," "Authentication facility," "Offline Verification", and "Requesting entity." II. Authentication and Offline Verification Framework: * Two types of authentication facilities: Yes/No authentication and eKYC authentication. * Types of Offline Verification services: QR Code verification, Aadhaar Paperless Offline eKYC verification, eAadhaar verification, and Offline Paper based verification. * Modes of authentication include demographic, OTP-based, biometric-based, and multi-factor authentication. * Virtual Identity (VID) is provided as an alternative to Aadhaar number for authentication. * Entities must inform Aadhaar number holders about information sharing, usage, and alternative identification methods. * Consent must be obtained from the Aadhaar number holder for authentication or verification. * Biometric information must be captured using certified devices and encrypted. III. Requesting Entities and Authentication Service Agencies: * Agencies seeking to become requesting entities or ASAs must apply and meet specific criteria. * The Authority may approve or reject applications and enter into agreements with entities. * Fees and charges may be determined by the Authority. * Requesting entities must establish necessary infrastructure, ensure network connectivity, and comply with security standards. * They must also monitor operations, employ qualified personnel, and undergo annual audits. IV. Data Handling and Security: * Requesting entities must not store core biometric information. * Identity information must only be used for specified purposes and kept confidential. * Logs of authentication transactions must be maintained for a specified period. * ASAs must provide secured connectivity, perform compliance checks, and comply with security standards. * Servers used for Aadhaar authentication must be located within data centers in India. V. Default and Liability: * The Authority may take action against entities that fail to comply with regulations. * Upon termination, entities must cease using the Aadhaar name and logo. VI. Data Storage and Access: * The Authority stores and maintains authentication transaction data for a limited period. * Aadhaar number holders have the right to access their authentication records. VII. Miscellaneous: * The Authority may issue clarifications and guidelines to address difficulties in interpreting the regulations. * Schedules A and B outline eligibility criteria for requesting entities and ASAs, respectively. * Existing AUAs, KUAs, ASAs, and KSAs are deemed requesting entities and ASAs under these regulations. Impact Analysis: Requesting Entities: * Impact: Must comply with the new regulations regarding authentication processes, data security, and reporting requirements. They are also responsible for the actions of SubAUAs/SubKUAs if applicable. * Action Required: Review and update systems and processes to align with the 2021 regulations, ensure compliance with data protection measures, and establish agreements with ASAs. Authentication Service Agencies: * Impact: Must ensure secure connectivity and compliance checks, and adhere to data security and management regulations. * Action Required: Review and update systems, undergo audits, and ensure compliance with all regulations and standards. Offline Verification Seeking Entities (OVSEs): * Impact: Must comply with regulations for Offline Verification, including consent, data storage, and security requirements. * Action Required: Implement processes for obtaining consent, secure data storage, and compliance with Authority guidelines. Aadhaar Number Holders: * Impact: Have the right to be informed about data usage, provide consent, and access their authentication records. * Action Required: Stay informed about their rights and available mechanisms for data access and grievance redressal.

Key Entities Referenced

Aadhaar Authentication and Offline Verification Regulations, 2021: The title of the policy document being analyzed. Unique Identification Authority of India (UIDAI): The authority responsible for Aadhaar and its authentication framework. Aadhaar Targeted Delivery of Financial and Other Subsidies, Benefits and Services Act 2016: The primary legislation governing Aadhaar. Aadhaar and Other Laws Amendment Act, 2019: An amendment to the original Aadhaar Act. Central Identities Data Repository (CIDR): The centralized database containing Aadhaar numbers and associated information. Authentication Service Agency (ASA): A licensed entity providing secure network connectivity for authentication. Authentication User Agency (AUA): A requesting entity that uses the Yes/No authentication facility. Information Technology Act 2000: Indian Legislation related to technology.
Official Source Record View Original Source →
See Full Document Text
रजिस्ट्री स.ं डी.एल.- 33004/99 REGD. No. D. L.-33004/99 सी.जी.-डी.एल.-अ.-09112021-230983 xxxGIDHxxx CG-DL-E-09112021-230983 xxxGIDExxx असाधारण EXTRAORDINARY भाग III—खण् ड 4 PART III—Section 4 प्राजधकार स ेप्रकाजित PUBLISHED BY AUTHORITY स.ं 542] नई दिल्ली, मगं लिार, निम्ब र 9, 2021/कार्तकव 18, 1943 No. 542] NEW DELHI, TUESDAY, NOVEMBER 9, 2021/KARTIKA 18, 1943 भारतीय जिजिष्ट पहचान प्राजधकरण अजधसचू ना नई दिल्ली, 8 निम्बर 2021 आधार (अजधप्रमाणन और ऑफलाइन सत्यापन) जिजनयम, 2021 (2021 का सख्ं या 2) स.ं के-11020/240/2021/अजध./भा.जि.प.प्रा. (2021 का सख्ं या 2 ).—आधार (जित्तीय और अन्य सहाजयदकयों, प्रसुजिधाओं और सेिाओं का लजित पररिान) अजधजनयम, 2016 यथा संिोजधत आधार एिं अन्य जिजधयां (संिोधन) अजधजनयम 2019 (2019 की संख्या 14) की उप धारा 54 धारा (1) की उप धारा (2) के उप खडं (क) (खक) (गक) (गख) (च) (चक) (चख) एिं (ब) और उप खंड (1) के तहत प्रित्त िजियों का प्रयोग करते हुए तथा आधार (अजधप्रमाणन) जिजनयम, 2016 के अजधक्रमण में, उि अजधक्रमण से पूिव दकए गए या दकए िाने िाले कायों को छोड़कर, भारतीय जिजिष्ट पहचान प्राजधकरण एतद्वारा जनम्नजलजखत जिजनयम बनाती ह:ै- अध्याय – 1 प्रारंजभक 1. सजं िप्त नाम और प्रारंभ:- (1) इन जिजनयमों को आधार (अजधप्रमाणन और ऑफलाइन सत्यापन) जिजनयम, 2021 कहा िाएगा। (2) ये जिजनयम सरकारी रािपत्र में इनके प्रकािन की जतजथ से लाग ूहोंगे। 6416 GI/2021 (1)2 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] 2. पररभाषाएं:- (1) िब तक दक संिभव में अन्यथा अपेजित न हो, इन जिजनयमों म,ें- (क) ’’अजधजनयम’’ से अजभप्राय आधार (जित्तीय और अन्य सहाजयदकयों, प्रसुजिधाओं और सेिाओं का लजित पररिान) अजधजनयम, 2016 से है; (कक) “आधार नबं र” से अजभप्राय आधार अजधजनयम की धारा 3 की उप-धारा (3) के अधीन दकसी व्यजि को िारी पहचान संख्या से ह,ै और इसमें उस धारा की उप-धारा (4) के अधीन सृजित कोई िैकजल्पक िचुवअल पहचान भी िाजमल है, (ख) ’’आधार नबं र धारक’’ का अजभप्राय कोई व्यजि, जिसे अजधजनयम के अंतगवत आधार नंबर िारी दकया गया है, से है; (खक) ‘आधार नबं र कैप् चर सर्िसव ोोकन या एएनसीएस ोोकन’ से तात् पय व अजधप्रमाणन प्रदक्रया को पूण व करन े के जलए प्राजधकरण द्वारा आधार नंबर के जलए िी गई कूोबद्ध संख्य ा से है। एएनसीएस ोोकन प्राजधकरण द्वारा यथा जनधावररत अल् प अिजध के जलए िैध होगा। (खख) ‘आधार कागि रजहत ऑफलाइन ई-केिाईसी’ से तात् पयव प्राजधकरण द्वारा िारी जडजिोल रूप स े हस्ट् तािररत िस्ट् तािेि से है, जिसमें आधार नंबर के अंजतम चार अंक, िनसांजख्य कीय संबंधी सूचना िैस े नाम, पता, ललंग और िन् म-जतजथ तथा आधार नंबर धारक की फोोो आदि अंतर्नवजहत ह।ै (खग) ‘आधार सुरजित क्य ूआर कोड’ से तात् पयव प्राजधकरण द्वारा सृजित त्िररत प्रजतदक्रया कोड से है, जिसमें जडजिोल रूप से हस्ट् तािररत डेोा िैसे आधार नंबर के अंजतम चार अंक, िनसांजख्यकीय संबंधी सूचना िैसे नाम, पता, ललंग तथा िन् म-जतजथ और आधार नंबर धारक की फोोो आदि अंतर्नवजहत ह।ै (ग) ‘‘अजधप्रमाणन’’ का अजभप्राय, ऐसी प्रदक्रया से है, जिसके द्वारा दकसी व्यजि की िनसांजख्यकीय सूचना अथिा बायोमेररक सूचना आधार नंबर सजहत उसके सत्यापन के जलए केंद्रीय पहचान डेोा ररपोजिोरी के पास िमा की िाती है और ऐसा ररपोजिोरी उसकी यथावथता अथिा कमी की अपने पास उपलब्ध सूचनाओं के आधार पर सत्याजपत करता है; (घ) 'अजधप्रमाणन सजु िधा' का अजभप्राय प्राजधकरण द्वारा प्रित्त ऐसी सुजिधा से है, जिसके अंतगवत, हां/ना प्रजतदक्रया या ई-केिाईसी डेोा, यथा लागू, को उपलब् ध कराने के द्वारा अजधप्रमाणन प्रदक्रया के िररए दकसी आधार नंबर धारक की िनसांजख्यकीय सूचना या बायोमेररक िानकारी के साथ आधार नंबर का अजधप्रमाणन दकया िाता ह।ै (च) ‘‘अजधप्रमाणन अजभलखे ’’ का अजभप्राय अजधप्रमाणन के समय तथा अनुरोधकताव संस्ट्था की पहचान एि ं उससे संबद्ध प्राजधकरण द्वारा उपलब्ध कराये गए प्रत्युत्तर के अजभलेख से है; (छ) ‘‘अजधप्रमाणन सिे ा एिसें ी’’ अथिा ‘‘एएसए’’ का अजभप्राय, ऐसी लाइसेंस प्राप्त संस्ट्था से होगा, िो प्राजधकरण द्वारा उपलब्ध कराई गयी अजधप्रमाणन सुजिधा का उपयोग करते हुए अजधप्रमाणन के जनष्पािन के संबंध में अनुरोधकताव संस्ट्था को समथव बनाने के जलए सुरजित नेोिकव संयोिन एि ं संबद्ध सेिाएं सुजनजित करने के जलए आिश्यक अिसंरचना उपलब्ध करा रही है; (ि) ‘‘अजधप्रमाणन प्रयोिा एिसें ी’’ अथिा ‘‘एयएू ’’ का अजभप्राय उस अनुरोधकताव संस्ट्था से है, िो प्राजधकरण द्वारा उपलब्ध कराई गयी हां/ना अजधप्रमाणन सुजिधा का उपयोग करती ह;ै (झ) ’’प्राजधकरण’’ का अजभप्राय अजधजनयम की धारा 11 की उप-धारा (1) के तहत स्ट्थाजपत भारतीय जिजिष्ट पहचान प्राजधकरण से है;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 3 (ो) ’’केंद्रीय पहचान डेोा ररपोजिोरी’’ अथिा ’’सीआईडीआर’’ का अजभप्राय एक या अजधक स्ट्थानों पर केंद्रीकृत डेोाबेस से है, जिसमें आधार नंबर धारक को िारी आधार नंबर के साथ ऐसे व्यजियों की िनसांजख्यकीय एि ंबायोमेररक सूचना और तत्संबंधी अन्य संबद्ध सूचना अंतर्नजव हत ह;ै (ोक) ‘बालक’ का अजभप्राय उस व्यजि से है, जिसने अठारह िषव की आयु पूणव नहीं की है; (ठ) ‘‘ई-केिाईसी अजधप्रमाणन सजु िधा’’ का अजभप्राय एक ऐसी अजधप्रमाणन सुजिधा से ह,ै जिसम ें अनुरोधकताव संस्ट्था के िररए आधार नंबर धारक की सहमजत से बायोमेररक सूचना तथा/अथिा ओोीपी एिं आधार नंबर को सुरजित रूप से िमा दकया िाता ह,ै जिसका जमलान सीआईडीआर में उपलब्ध डेोा से दकया िाता ह,ै और जिस पर प्राजधकरण, अजधप्रमाणन संव्यिहार से संबंजधत अन्य तकनीकी जििरण के साथ जडजिोल रूप से हस्ट्तािररत प्रजतदक्रया युि ई-केिाईसी डेोा प्रिान करता है; (ड) ‘‘ई-केिाईसी डेोा’’ का अजभप्राय दकसी आधार नबंर धारक की पूणव अथिा सीजमत िनसांजख्यकीय सूचना तथा/अथिा फोोोग्राफ से ह।ै ई-केिाईसी डेोा मे पूणव अथिा मास्ट्कड् आधार नंबर अंतर्नवजहत हो सकता ह;ै (ढ) ‘‘ई-केिाईसी प्रयोिा एिसें ी’’ अथिा ‘‘केयएू ’’ का अजभप्राय उस अनरु ोधकताव संस्ट्था से ह,ै िो एयूए होन े के अजतररि प्राजधकरण द्वारा प्रिान की गई ई-केिाईसी अजधप्रमाणन सुजिधा का उपयोग करती है; (ण) ’’लाइससें कुंिी’’ से अजभप्राय, प्राजधकरण द्वारा जनधावररत प्रदक्रया के अनुसार अनुरोधकताव संस्ट्था द्वारा सृजित कुंिी से है; (णक) “ऑफलाइन सत्यापन” का अजभप्राय ऐसे ऑफलाइन जिजधयों, िैसा जिजनयमों द्वारा यथा जिजनर्िष्टव हो, के द्वारा अजधप्रमाणन के जबना आधार नंबर धारक की पहचान सत्यापन करने की प्रदक्रया से है; (णख) “ऑफलाइन सत्यापन चाहन े िाली सस्ट्ं था” का अजभप्राय ऐसी संस्ट्था से है, िो दकसी आधार नंबर धारक का ऑफलाइन सत्यापन करना चाहती है; (णग) ‘ऑफलाइन आधार डेोा’ का तात्पयव ऑफलाइन आधार सत् यापन से संबंजधत डेोा से है, जिसमें भंडारण से पूिव आधार नंबरों की मालस्ट्कंग की आिश् यकता सजहत समय-समय पर प्राजधकरण द्वारा यथा जिजनर्िष्टव जििेषताएं िाजमल ह;ैं (त) ‘‘पीआईडी ब्लॉक’’ का अजभप्राय व्यजिगत पहचान डेोा घोक से ह,ै जिसके अंतगवत अजधप्रमाणन के िौरान आधार नंबर धारक से संगहृ ीत आिश्यक िनसांजख्यकीय तथा/अथिा बायोमेररक और/या ओोीपी िाजमल ह;ै (तक) ‘पिं ीकृत उपकरण’ से तात् पयव ऐसे बायोमेररक उपकरणों से ह ैिो प्राजधकरण में पंिीकृत हों। (थ) “अनरु ोधकता व सस्ट्ं था” का अजभप्राय ऐसी एिेंसी या व्यजि से है, िो दकसी व्यजि के आधार नंबर, और िनसांजख्यकीय सूचना या बायोमेररक सूचना केंद्रीय पहचान डेोा ररपोजिोरी को अजधप्रमाणन हते ु प्रस्ट्तुत करती है; (थक) ‘सब-एयएू ’ का तात् पयव ऐसी अनुरोधकताव संस्ट्था से है, िो जिद्यमान एयूए के िररए प्राजधकरण द्वारा उपलब् ध कराई गई हां/नहीं अजधप्रमाणन सुजिधा का उपयोग कर रही ह;ै (थख) ‘सब-केयएू ’ का तात् पयव ऐसी अनुरोधकताव संस्ट्था से है, िो जिद्यमान केयूए के िररए प्राजधकरण द्वारा उपलब् ध कराई गई ई-केिाईसी अजधप्रमाणन सुजिधा का उपयोग कर रही है; (थग) ‘यआू ईडी ोोकन’ का तात् पयव प्राजधकरण द्वारा सृजित 22 अंकों के अिरांकीय क्रम से है, िो आधार नंबर से मैप दकया हुआ और दकसी अनुरोधकताव संस्ट्था के जलए जिजिष् ो होता ह;ै4 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (थघ) ‘िचअुव ल पहचानकताव’ का तात् पयव अंतर-पररितवनीय 16 अंकीय यािजृ‍ छक संख्य ा से है, िो आधार नंबर धारक के आधार नंबर से मैप होती है, और (ि) ’’हा/ंना अजधप्रमाणन’’ का अजभप्राय एक प्रकार की अजधप्रमाणन सुजिधा से है, जिसमें दकसी अनुरोधकता व संस्ट्था के िररए आधार नंबर धारक की सहमजत द्वारा पहचान संबंधी सूचना एि ं आधार नंबर को सुरजित रूप से प्रस्ट्तुत दकया िाता ह ै और तत्पिात उसका जमलान सीआईडीआर में उपलब्ध डेोा से दकया िाता ह,ै तथा प्राजधकरण, अजधप्रमाणन संव्यिहार से संबंजधत अन्य तकनीकी जििरण के साथ जडजिोल रूप से हस्ट्तािररत प्रजतदक्रया से युि ‘‘हां’’ या ‘‘ना’’ िाले प्रत्युत्तर, पहचान संबंधी सूचना के जबना, प्रिान करता ह।ै (2) इन जिजनयमों में उपयोग दकए गए िब्ि एिं अजभव्यजियां, जिन्ह ें इन जिजनयमों में पररभाजषत नहीं दकया गया है, का िही अथव होगा िो दक अजधजनयम अथिा उसके तहत बनाए गए जनयमों और अन्य जिजनयमों अथिा सूचना प्रौद्योजगकी अजधजनयम, 2000 में पररभाजषत दकया गया है। अध्याय - 2 आधार अजधप्रमाणन तत्रं 3. अजधप्रमाणन सजु िधाओं के प्रकार: - प्राजधकरण द्वारा िो प्रकार की अजधप्रमाणन सुजिधाएं उपलब्ध करायी िाएंगी, नामत:- (i) हा/ंना अजधप्रमाणन सजु िधा, जिसका जनष्पािन जिजनयम 4(2) में जिजनर्िष्टव दकसी भी माध्यम से दकया िा सकता ह;ै तथा (ii) ई-केिाईसी अजधप्रमाणन सजु िधा, जिसका जनष्पािन केिल जिजनयम 4(2) में जिजनर्िष्टव ओोीपी तथा/अथिा बायामेररक अजधप्रमाणन के िररए ही दकया िा सकता है। 3क. ऑफलाइन सत्य ापन के प्रकार:- 1. प्राजधकरण द्वारा जनम् नजलजखत प्रकार की ऑफलाइन सत् यापन सुजिधाएं उपलब् ध कराई िाएंगी, नामत:- (i) क् यू आर कोड सत् यापन, (ii) आधार कागि रजहत ऑफलाइन ई-केिाईसी सत् यापन, (iii) ई-आधार सत् यापन, (iv) ऑफलाइन कागि आधाररत सत् यापन, और (v) समय-समय पर प्राजधकरण द्वारा लागू दकसी भी अन् य प्रकार का ऑफलाइन सत् यापन। उपयुवक् त ऑफलाइन सत् यापन दकसी संस्ट् था द्वारा समय-समय पर प्राजधकरण द्वारा दिए गए जिजनििे ों के अनुसार दकया िा सकता ह।ै 2. प्राजधकरण िेबसाइो, मोबाईल ऐप्ल ीकेिन या अन्य माध्यमों द्वारा क् यूआर कोड, ई-आधार या आधार कागि रजहत ऑफलाइन ई-केिाईसी को डाउनलोड करने हते ु जिजभन् न सुजिधाएं उपलब् ध कराएगा। 4. अजधप्रमाणन के माध्यम:- (1) इन जिजनयमों के अनुसार तथा प्राजधकरण द्वारा जनधावररत जिजनििे ों के अनुरुप इलेक्रॉजनक रूप में दकसी अनुरोधकताव संस्ट्था द्वारा प्रेजषत दकसी अनुरोध को ही प्राजधकरण द्वारा अजधप्रमाणन अनुरोध के रूप में स्ट्िीकार दकया िाएगा। (2) अजधप्रमाणन को जनम्नजलजखत माध्यमों द्वारा जनष्पादित दकया िा सकता ह:ै[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 5 (क) िनसाजं ख्यकीय अजधप्रमाणन: आधार नंबर धारक से प्राप्त आधार नंबर धारक की िनसांजख्यकीय सूचना और आधार नंबर का जमलान, सीआईडीआर में उपलब्ध आधार नंबर धारक की िनसांजख्यकीय सूचना के साथ दकया िाता ह।ै (ख) िन-ोाइम जपन आधाररत अजधप्रमाणन: सीजमत समय की िैधता िाले िन ोाइम जपन (ओोीपी) को, प्राजधकरण में पंिीकृत अथिा अन्य उपयुि साधनों द्वारा सृजित, आधार नंबर धारक के मोबाइल नंबर तथा/अथिा ई-मले पते पर भेिा िाता ह।ै अजधप्रमाणन के िौरान आधार नंबर धारक इस ओोीपी को अपने आधार नंबर के साथ उपलब्ध करायेगा, जिसका जमलान प्राजधकरण द्वारा सृजित ओोीपी से दकया िाएगा। (ग) बायोमरे रक आधाररत अजधप्रमाणन: आधार नंबर धारक द्वारा िमा दकया गया आधार नंबर तथा बायोमेररक सूचना का जमलान, सीआईडीआर में संजचत आधार नंबर धारक की बायोमेररक सूचना से दकया िाता ह।ै यह दफगंरलप्रंो आधाररत अथिा पुतली आधाररत अजधप्रमाणन अथिा अन्य बायोमेररक पद्धजतयों पर आधाररत हो सकती ह,ै िो सीआईडीआर में संजचत बायोमेररक सूचना के आधार पर होती ह।ै (घ) बहु-कारक अजधप्रमाणन: उपयुवि जिजधयों के िो अथिा िो से अजधक संयोिन का उपयोग अजधप्रमाणन के जलए दकया िा सकता ह।ै (3) कोई अनुरोधकताव संस्ट्था अपनी आिश्यकता के अनुसार दकसी जििेष सेिा अथिा व्यािसाजयक कायव के जलए उप- जिजनयम (2) में जिजनर्िष्टव माध्यमों से, िृहत्तर सुरिा के जलए, बहु-कारक अजधप्रमाणन सजहत, अजधप्रमाणन का उपयुि माध्यम चुन सकती है। 4क. िचअुव ल पहचान सख्ं य ा (िीआईडी) (1) प्राजधकरण अजधप्रमाणन के प्रयोिनाथव आधार नंबर से िुड़ी हुई एक िैकजल्पक पहचान संख्या (िीआईडी) उपलब् ध कराएगा। (2) आधार नंबर धारक अपनी िीआईडी को यूआईडीएआई की िेबसाइो, एसएमएस, मोबाईल ऐप्ल ीकेिन, ई-आधार डाउनलोड और समय-समय पर प्राजधकरण द्वारा उपलब् ध कराए गए दकसी अन् य माध्य म से सजृ ित कर सकते ह ैंया उसे पुन:प्राप्त कर सकते हैं। (3) ऑनलाइन अजधप्रमाणन या ई-केिाईसी के जलए आधार नंबर धारक, आधार नंबर के स्ट् थान पर िीआईडी का प्रयोग कर सकते हैं। (4) कोई भी संस्ट् था अपने जसस्ट् ोम में िचुवअल आईडी को संजचत नहीं करेगी। 5. आधार नबं र धारक के जलए सचू ना :- (1) अजधप्रमाणन या ऑफलाइन सत् यापन के समय, क्रमि: अनुरोधकताव संस्ट्था या ऑफलाइन सत् यापन मांगकताव संस्ट्था (ओिीएसई) आधार नंबर धारक को या बालक के मामले में उसके जपता या माता अथिा संरिक, को जनम् नजलजखत सूचनाएं प्रिान करेंगी:- (क) सूचना की प्रकृजत, जिसे अजधप्रमाणन पर प्राजधकरण द्वारा अनुरोधकताव संस्ट्था के साथ साझा दकया िाएगा; (ख) उपयोग जिसके जलए अजधप्रमाणन या ऑफलाइन सत्यापन के िौरान प्राप्त सूचना का उपयोग दकया िा सकता है; (ग) पहचान प्रस्ट् तुत करने के िैकजल्पक और ‍ यिहायव माध्य म तथा जनिासी द्वारा अजधप्रमाणन या ऑफलाइन सत् यापन के जलए इंकार करने या असमथव होने की जस्ट्थजत में, दकसी सेिा से िंजचत नहीं दकया िाएगा। (2) अनुरोधकताव संस्ट्था यह सुजनजित करेगी दक ऊपर उप-जिजनयम (1) में सिर्ं भवत सूचना स्ट्थानीय भाषा में भी आधार नंबर धारक को उपलब्ध करायी िायेगी। (3) अनुरोधकताव संस्ट्था या ओिीएसई यह सुजनजश् चत करेगी दक जनिासी द्वारा अजधप्रमाणन या ऑफलाइन सत् यापन करने से इंकार करने अथिा करने में असमथव होने पर जनिासी को दकसी भी सेिा से िंजचत नहीं दकया िाएगा बिते6 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] दक उपयुवक् त उप जिजनयम (1) (ग) के अंतगवत अनुरोधकताव संस्ट्था द्वारा सुझाए गए ‍ यिहायव िैकजल्पक माध्य म से जनिासी अपनी पहचान जसद्ध करने में समथव हो। 6. आधार नबं र धारक की सहमजतिः- (1) जिजनयम 5 के तहत सूचना प्रिान करने के बाि, अनुरोधकताव संस्ट्था या ऑफलाइन सत् यापन मांगकताव संस्ट्था (ओिीएसई) अजधप्रमाणन या सत् यापन के जलए आधार नंबर धारक या बालक के मामले में उसके जपता या माता अथिा संरिक की सहमजत प्राप्त करेगी। (2) अनुरोधकताव संस्ट्था या ओिीएसई उपयुवक् त उप जिजनयम (1) म ेंसंिर्भवत सहमजत भौजतक रूप से अथिा जििेषकर इलेक् रॉजनक प्रारूप में प्राप्त करेगी और इस उ्ेश् य के जलए प्राजधकरण द्वारा जिजनर्िष्व ो तरीके अथिा प्रारूप में प्राप्त सहमजत के लॉग अथिा अजभलेख रखेगी। 2. अनरु ोधकता वसस्ट्ं था द्वारा बायामरे रक सचू ना ग्रहण करना:- (1) अनुरोधकताव संस्ट्था, प्राजधकरण द्वारा जनधावररत प्रदक्रयाओं और जिजनििे नों के अनुसार प्रमाजणत बायामेररक उपकरणों के उपयोग द्वारा आधार नंबर धारक की बायामेररक सूचना को अजभग्रहण करेगी। (1क) अजधप्रमाणन के जलए प्रयोग दकए िाने िाले सभी बायोमेररक् स उपकरण प्राजधकरण द्वारा समय-समय पर जिजनर्िष्व ो मानकों के अंतगवत पंिीकृत उपकरण होंगे। (1ख) सभी बायोमेररक् स उपकरण अनुरोधकताव संस्ट्था के सिवर पर पंिीकृत दकए िाएंगे। (2) अनुरोधकताव संस्ट्था, प्राजधकरण द्वारा जनधावररत जिजनििे नों के अनुरूप बायोमेररक डेोा को अजभग्रहण करते समय उसे आिश्यक रूप से कूोबद्ध एि ंसुरजित करेगी। (3) बायामेररक सूचना अजभग्रहण करने में इष्टतम पररणाम हते ु अनुरोधकताव संस्ट्था इस उ्ेश्य के जलए प्राजधकरण द्वारा समय-समय पर यथा जिजनर्िष्टव प्रदक्रयाओं को अपनाएगी। 8. अजधप्रमाणन म ेंप्रयिु उपकरण, क्लाइंो एप्लीकेिन्स आदि:- (1) अजधप्रमाणन के जलए प्रयुि समस्ट्त यंत्र एि ं उपकरण इस प्रयोिनाथव प्राजधकरण द्वारा समय-समय पर िारी जिजनििे नों के अनसुार आिश्यक रूप से प्रमाजणत दकए िाएंगे। (2) अजधप्रमाणन के प्रयोिनाथव अनुरोधकताव संस्ट्था द्वारा प्रयोग में लाये िाने िाले क्लाइंो एप्लीकेिन्स अथावत सॉफ्ोिेयर इस उ्ेश्य के जलए समय-समय पर प्राजधकरण द्वारा जनधावररत मानक एपीआई और जिजनििे नों के अनुरूप होंगे। 9. अजधप्रमाणन अनरु ोध भिे ने की प्रदक्रया:- (1) अनुरोधकताव संस्ट्था द्वारा प्रिान आधार नंबर अथिा कोई अन्य पहचानकताव, िो आधार नंबर और आधार नंबर धारक से आिश्यक िनसांजख्यकीय तथा/अथिा बायोमेररक सूचना और/या ओोीपी से मैप ह,ै के संग्रहण के पिात प्राजधकरण द्वारा जनधावररत जिजनििे नों के अनुसार क्लाइंो एप्लीकेिन तुरन्त दकसी हस्ट्तांतरण से पूि व इन इनपुो पैरामीोरों को पीआईडी ब्लॉक में पैकेि और कूोबद्ध करेगा, और इस प्रयोिनाथव प्राजधकरण द्वारा यथा जनधावररत सुरिा प्रोोोकॉल के उपयोग द्वारा उसे अनुरोधकताव संस्ट्था के सिवर के पास भेि िेगा। (2) जिजधमान्यकरण के उपरांत, अनुरोधकताव संस्ट्था का सिवर प्राजधकरण द्वारा जनधावररत जिजनििे नों के अनुसार अजधप्रमाणन सेिा एिेंसी के सिवर के माध्यम से अजधप्रमाणन अनुरोध को सीआईडीआर को भेि िेगा। अजधप्रमाणन अनुरोध को अनुरोधकताव संस्ट्था तथा/अथिा अजधप्रमाणन सेिा एिसें ी द्वारा, उनके पारस्ट्पररक समझौते के अनुसार, जडजिोल रूप से हस्ट्तािररत होगा। (3) अजधप्रमाणन अनुरोध के माध्यम के आधार पर, सीआईडीआर अपने पास सजं चत डेोा के समि इनपुो पैरामीोर जिजधमान्य करेगा और जडजिोल रूप से हस्ट्तािररत ‘हां’ या ‘ना’ अजधप्रमाणन प्रत्युत्तर, अथिा कूोबद्ध ई-केिाईसी डेोा सजहत जडजिोल रूप से हस्ट्तािररत ई-केिाईसी, िैसी जस्ट्थजत हो, को अजधप्रमाणन संव्यिहार से संबद्ध अन्य तकनीकी जििरण के साथ िापस करेगा। (4) अजधप्रमाणन की सभी जिजधयों म,ें आधार नंबर अजनिायव ह ै और इसे उपयुवि उप-जिजनयम(1) में जिजनर्िष्टव इनपुो पैरामीोरों के साथ इस प्रकार िमा दकया िाता ह ैदक अजधप्रमाणन सििै 1:1 के जमलान के अनुसार रह।े[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 7 (5) अनुरोधकताव संस्ट्था सुजनजित करेगी दक प्राजधकरण द्वारा जनधावररत जिजनििे नों एि ं प्रदक्रयाओं के अनुसार अजधप्रमाणन उपकरण द्वारा अजभग्रहण करते समय पीआईडी ब्लॉक का एजन्क्रप्िन होता रह।े 10. आधार नबं र धारक को अजधप्रमाणन या ऑफलाइन सत्य ापन की अजधसूचना/अजभस्ट्ि ीकृजत:- (1) दकसी भी अजधप्रमाणन के संबंध में अनुरोधकताव संस्ट्था द्वारा आधार नंबर धारक को ई-मेल और/या एसएमएस और/या अन् य जडजिोल माध्य मों से और/या जलजखत अजभस्ट्ि ीकृजत के आधार पर अजधप्रमाणन के प्रत् येक अनुरोध के सफल या असफल होने की अजधसूचना प्रिान की िाएगी। ऐसी अजधसूचना/अजभस्ट्ि ीकृजत म,ें िैसा मामला हो, अनुरोधकताव संस्ट्था का नाम, जतजथ, अजधप्रमाणन का समय, अजधप्रमाणन प्रत्त्युतर कोड, आधार नंबर के अंजतम 4 अंक और अजधप्रमाणन का उ्ेश् य दिया िाएगा। (2) दकसी भी ऑफलाइन सत् यापन के जलए आधार नंबर धारक को ओिीएसई द्वारा ई-मेल और/या एसएमएस और/या अन् य जडजिोल माध्य मों से और/या जलजखत अजभस्ट्ि ीकृजत के आधार पर प्रत् येक ऑफलाइन सत् यापन अनुरोध के सफल या असफल होने की अजधसूचना प्रिान की िाएगी। (3) अजधप्रमाणन के असफल हो िाने के मामलों में, अनुरोधकताव संस्ट्था जनिासी को स्ट्प ष् ो एिं सहि भाषा में अजधप्रमाणन के असफल होने के कारणों िैसे स्ट् थजगत/र् आधार या बायोमरे रक् स/आधार लॉिंकंग की सूचना प्रिान करेगी। 11. बायामरे रक लॉिंकंग:- (1) प्राजधकरण आधार नंबर धारक को उसके बायोमेररक को स्ट्थायी तौर पर लॉक करने तथा आिश्यकतानुसार बायोमेररक अजधप्रमाणन हते ु अस्ट्थायी तौर पर अनलॉक करने की सुजिधा ि ेसकता ह।ै (2) ऐसे लॉक दकए गए बायोमेररक अजभलेख के समि समस्ट्त बायोमरे रक अजधप्रमाणन एक उजचत प्रत्युत्तर कोड सजहत ‘‘नहीं’’ जिकल्प के साथ असफल होंगे। (3) आधार नंबर धारक को अजधप्रमाणन हते ु अपने बायोमेररक को अस्ट्थायी तौर पर अनलॉक करने की अनमुजत िी िाएगी और ऐसी अस्ट्थायी अनलॉिंकंग, प्राजधकरण द्वारा जनर्िष्टव समयािजध के पिात अथिा अजधप्रमाणन संव्यिहार की पूणवता तक, िो भी पहले हो, िारी नहीं रहगे ी। (4) प्राजधकरण आधार नंबर धारक के जलए दकसी भी समय ऐसे स्ट्थायी लॉिंकंग को सुरजित तरीके से समाप्त करने का प्रािधान करेगा। 11क. आधार लॉिंकंग:- (1) प्राजधकरण आधार नंबर धारक को अपने आधार नंबर को लॉक करने तथा अजधप्रमाणन के जलए आिश् यक होने पर अनलॉक करने की सुजिधा प्रिान करेगा। (2) ऐसे लॉक दकए गए आधार नंबर के समि दकए गए सभी अजधप्रमाणन अनुरोधों का उत् तर ‘नही’ होगा और साथ ही उपयुक् त प्रजतदक्रया कोड दिया िाएगा। (3) आधार लॉक होने पर प्राजधकरण जनिासी को िचुवअल आईडी या अन् य माध्य मों से अजधप्रमाणन की अनुमजत प्रिान करेगा। अध्याय - 3 अनरु ोधकता वसस्ट्ं थाओं तथा अजधप्रमाणन सिे ा एिजें सयों की जनयजु ि 12. अनरु ोधकता वसस्ट्ं थाओं तथा अजधप्रमाणन सिे ा एिजें सयों की जनयजु ि :- (1) प्राजधकरण द्वारा प्रािधाजनत अजधप्रमाणन सुजिधा के उपयोग के जलए अनुरोधकताव संस्ट्था बनन े की इ‍छुक एिेंजसया,ं प्राजधकरण द्वारा इस उ्ेश्य के जलए समय समय पर यथा जिजनर्िष्टव प्रदक्रया के अनुसार अनुरोधकताव संस्ट्था के रूप में जनयुजि के जलए आिेिन करेंगी। केिल अनुसूची ‘क’ के मानिडं ों को पूरा करने िाली अनुरोधकताव संस्ट्थाएं ही आिेिन करने की पात्र होंगी। प्राजधकरण आििे द्वारा समय-समय पर अनुसूची ‘क’ में संिोधन कर सकता है, तादक पात्रता मानिडं को संिोजधत दकया िा सके। (1क) अनुरोधकताव संस्ट्था तथा एएसए समय-समय पर प्राजधकरण द्वारा यथा जिजनर्िष्व ो तकनीकी एिं सुरिा मानिडं ों को पूरा करेंगी।8 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (2) अजधप्रमाणन सेिा एिेंजसयों के रूप में जनयुजि चाहने िाली संस्ट्थाएं इस उ्ेश्य के जलए प्राजधकरण द्वारा यथा जिजनर्िष्टव प्रदक्रया के अनुरूप जनयुजि के जलए आिेिन करेंगी। केिल अनुसूची ‘ख’ के मानिडं ों को पूरा करने िाली संस्ट्थाएं ही आिेिन करने की पात्र होंगी। प्राजधकरण आििे द्वारा समय-समय पर अनुसूची ‘ख’ में संिोधन कर सकता है, तादक पात्रता मानिडं को संिोजधत दकया िा सके। (3) प्राजधकरण ऐसी आिेिक संस्ट्था अथिा अजधप्रमाणन सेिा एिेंजसयों, िैसी भी जस्ट्थजत हो, की गजतजिजधयों से संबद्ध मामलों के सबंध में आिेिक से अन्य सूचना अथिा स्ट्पष्टीकरण का उल्लेख करने के जलए कह सकता ह,ै जिसे आिेिन पर जिचार करने और जनपोान करने के जलए प्राजधकरण द्वारा जिचाराथव जलया िा सकता ह।ै (4) आिेिक, प्राजधकरण द्वारा इस सबंध में यथा जिजनर्िष्टव समय के अंिर, प्राजधकरण की संतुजष्ट के अनुरूप ऐसी सूचना तथा स्ट्पष्टीकरण को प्रस्ट्तुत करेगा। (5) आिेिन पर जिचार करते समय, आिेिक द्वारा प्रस्ट्तुत की गयी सूचना और उसकी पात्रता को प्राजधकरण िस्ट्तािेिों, अिसरंचना एिं तकनीकी सपोोव, जिन्ह ें आिेिक के पास होना आिश्यक है, के प्रत्यि सत्यापन द्वारा सत्याजपत कर सकता है, । (6) आिेिक द्वारा प्रस्ट्तुत दकए गए आिेिन, िस्ट्तािेिों तथा उसकी पात्रता के सत्यापन के पिात प्राजधकरण: (क) अनुरोधकताव संस्ट्था अथिा अजधप्रमाणन सेिा एिेंसी के आिेिन, िो भी जस्ट्थजत हो, को अनमुोदित कर सकता ह;ै तथा (ख) संस्ट्था अथिा एिेंसी के साथ प्राजधकरण की अजधप्रमाणन सुजिधा के अनुरोधकताव संस्ट्थाओं द्वारा उपयोग के जलए, या एएसए द्वारा सेिाओं के प्रािधान हते ु, िाजयत्िों के गैर-जनष्पािन की जस्ट्थजत में िजतयों तथा हतोत्साहन सजहत, जनबंधन एि ंितों को िाजमल करते हुए उपयुि अनुबंध कर सकती है। (7) प्राजधकरण, समय-समय पर संस्ट्थाओं द्वारा उनकी जनयुजि के िौरान उनके द्वारा िये िुल्क एिं प्रभार सजहत आिेिन िुल्क, िार्षवक सिस्ट्यता िुल्क तथा िैयजिक अजधप्रमाणन संव्यिहार के जलए िुल्क जनधावररत कर सकता ह।ै (8) प्राजधकरण समय-समय पर ऐसी अनुरोधकताव संस्ट्थाओं को जनयत करेगा जिन्ह ें आधार नंबर या मास्ट्क दकए गए आधार नंबर के संचयन की अनुमजत होगी। (9) प्राजधकरण समय-समय पर, जििेष अनुरोधकताव संस्ट्थाओं को ई-केिाईसी प्रजतदक्रया के रूप में उपलब् ध डेोा फील् ड के संबंध में जनणवय लेगा। (10) प्राजधकरण समय-समय पर यह जनधावररत करेगा दक अनुरोधकताव संस्ट्था को अजधप्रमाणन हते ु आधार नंबर या िचुवअल आईडी या यूआईडी ोोकन या एएनसीएस या दकसी अन् य पहचान माध्य म की अनमु जत प्रिान की िा सकती ह।ै 13. प्रदक्रया, िहा ंजनयजु ि के जलए आििे न अनमु ोदित नहीं है:- (1) यदि, अनुरोधकताव संस्ट्था अथिा अजधप्रमाणन सेिा एिेंसी, िैसी जस्ट्थजत हो, की जनयुजि के जलए आिेिन के प्राजधकरण द्वारा जिजनर्िष्टव अपेिाओं को सन्तुष्ट नहीं करने पर प्राजधकरण आिेिन जनरस्ट्त कर सकता है। (2) आिेिन जनरस्ट्त करने के प्राजधकरण के जनणवय की सूचना आिेिक को इस जनणवय के तीस दिनों के अंिर जलजखत रूप में ि ेिी िाएगी, जिसमें उसके आिेिन को जनरस्ट्त करने के कारणों का उल्लेख दकया िाएगा। (3) कोई भी आिेिक िो प्राजधकरण के जनणवय से असन्तुष्ट है, इस सूचना की प्राजप्त की जतजथ के तीस दिनों के अंिर जनणवय पर पुनर्िवचार करने के जलए प्राजधकरण के पास आिेिन कर सकता ह।ै (4) प्राजधकरण, आिेिक द्वारा भेिे गये आिेिन पर पुनर्िवचार करेगा और इससे संबंजधत जनणवय को यथािीघ्र आिेिक को जलजखत रूप में सूजचत करेगा।[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 9 14. अनरु ोधकता वसस्ट्ं थाओं की भजू मका और उत्तरिाजयत्ि:- (1) अनुरोधकताव संस्ट्था को जनम्नजलजखत कायव एि ंउत्तरिाजयत्िों का जनिवहन करना होगा: (क) अजधप्रमाणन से संबंजधत स्ट्ियं के तंत्र, प्रदक्रयाओं, अिसंरचना, तकनीक, सुरिा आदि सजहत आिश्यक प्रचालनों का संस्ट्थापन एि ंअनुरिण करना; (ख) अजधप्रमाणन अनुरोधों को भेिने के जलए प्राजधकरण द्वारा अनुमोदित एएसए के माध्यम से सीआईडीआर के साथ नेोिकव कनेजक्ोजिोी सुजनजित करना; (ग) यह सुजनजित करना दक अजधप्रमाणन अनुरोधों को भेिने के जलए प्रयुि अजधप्रमाणन उपकरणों तथा सीआईडीआर के मध्य नेोिकव कनेजक्ोजिोी इस उ्ेश्य के जलए प्राजधकरण द्वारा जनधावररत मानकों एिं जिजिजष्टयों के अनुरूप है; (गक) यह सुजनजश् चत करना दक जनिासी द्वारा अजधप्रमाणन अनुरोध के जलए उपलब् ध कराए गए आधार नंबर/िचुवअल आई डी/एएनसीएस ोोकन को उपकरण ऑपरेोर द्वारा अपने पास या उपकरण के अंिर या एयूए सिवर में न रख जलया िाए। (गख) यह सुजनजित करना दक िचुवअल आईडी का प्रयोग करते हुए अजधप्रमाणन के प्रािधान को उपलब् ध कराया िाए। (घ) केिल उन्हीं यन्त्रों, उपकरण, अथिा सॉफ्ोिेयर का उपयोग करना िो आिश्यक रूप से प्राजधकरण द्वारा पंिीकृत या अनुमोदित अथिा प्रमाजणत या प्राजधकरण द्वारा जिजनर्िष्टव ह ैंऔर इस उ्ेश्य हते ु प्राजधकरण द्वारा जनधावररत मानकों और जिजनििे नों के अनुरूप हैं; (च) इस संबंध में प्राजधकरण द्वारा समय-समय पर िारी एिं सूजचत जनयमों एि ं ितों, मानकों, जनििे ों तथा जिजनििे नों के जलए अपने यंत्रों तथा उपकरणों के प्रचालन की आिजधक आधार पर जनगरानी करना; (छ) यह सुजनजित करना दक अजधप्रमाणन कायों के जनष्पािन, तथा आिश्यक तंत्रों, अिसंरचना एि ं प्रदक्रयाओं के अनुरिण के जलए उसके द्वारा जनयुि कमवचाररयों के पास ऐसे कायों के जनष्पािन की अपेजित योग्यता ह;ै (ि) एएसए, जिसके साथ उसका समझौता हुआ ह,ै के जिषय में प्राजधकरण को सूजचत रखना; (िक) दकसी ततृ ीय पि सस्ट्ं थ ा को सब-एयएू /सब-केयएू के रूप में जनयक्ु त करन े से पिू व प्राजधकरण स ेअनजुमत प्राप्त करना। (झ) यह सुजनजित करना दक उसके प्रचालन तथा तंत्र प्राजधकरण के मानकों तथा जिजनििे नों के अनुरूप ह,ैं जिसे सुजनजित करने के जलए दकसी प्रजतजित जनकाय द्वारा प्रमाजणत सूचना पद्धजत लेखापरीिक द्वारा िार्षवक आधार पर लेखापरीिा करिाई गयी ह ै और अनुरोध दकए िाने पर लेखापरीिा ररपोोव प्राजधकरण के साथ साझा करनी होगी; (ो) जनिाजसयों को अजधप्रमाणन सेिाओं के जनबावध प्रािधान सुजनजित करने के जलए अपिाि संचलन दक्रयाजिजध तथा बैक-अप पहचान अजधप्रमाणन दक्रयाजिजध को कायावजन्ित करना; (ठ) अजधप्रमाणन से संबद्ध धोखाधड़ी अथिा जििाि संबंधी दकसी िांच की जस्ट्थजत में िह प्राजधकरण, अथिा इसके द्वारा जनयुि या प्राजधकृत दकसी एिेंसी अथिा दकसी अन्य प्राजधकृत िांच एिेंसी का पूणव सहयोग करेगी और अपने पररसर, अजभलेख, कार्मवक तथा दकसी अन्य संसाधन या सूचना तक उनकी पहुचं बनान े का प्रािधान करेगी। इसके साथ-साथ दकसी भी आधार डेोा से संबंजधत धोखाधड़ी के संबंध में िन सामान् य को सूचना प्रिान करने के जलए प्राजधकरण का सहयोग करेगी, तादक आधार नंबर धारक यह तय कर सके दक कहीं िे दकसी धोखाधड़ी का जिकार तो नही हो गए ह ैंऔर िे जनिारक कारविाई कर सकें।10 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (ड) अनुरोधकताव संस्ट्था द्वारा अपनी आधार अजधप्रमाणन प्रणाली को स्ट्थानीय अजधप्रमाणन प्रणाली के साथ एकीकृत करने की इ‍छा रखने की जस्ट्थजत में, ऐसे एकीकरण को समय-समय पर प्राजधकरण द्वारा िारी मानकों तथा जिजनििे नों के अनुरूप जनष्पादित करना होगा; (ढ) ि ेप्राजधकरण को अपने नेोिकव के भीतर आधार संबंधी सूचना अथिा तंत्र के आधार फ्रेमिकव अथिा दकसी अन्य समझौते से संबद्ध दकसी सचू ना अथिा तंत्र के दकसी िरुु पयोग के जिषय में सूजचत करेंगी; यदि अनुरोधकताव संस्ट्था धोखाधड़ी की जिकार है अथिा उसे आधार प्रमाणीकरण से संबंजधत धोखाधड़ी िाचं प्रणाली के माध्यम से दकसी धोखाधड़ी की िानकारी प्राप्त होती ह,ै ि े उस धोखाधड़ी से संबंजधत समस्ट्त िानकारी प्राजधकरण को साझा करेंगी। ि े उस धोखाधड़ी से संबंजधत समस्ट् त िानकारी जबना अनािश् यक जिलम् ब के प्राजधकरण को और प्रभाजित आधार नंबर धारक को साझा करेंगी। (ण) ि े अजधप्रमाणन प्रचालनों तथा पररणामों के जलए उत्तरिायी होंगी, भले ही अपने प्रचालनों को तीसरे पिों के साथ उप-अनुबजन्धत दकया हो। अनुरोधकताव संस्ट्था यह सुजनजित करने के जलए भी उत्तरिायी होगी दक ऐसे तीसरे पि की संस्ट्थाओं के अजधप्रमाणन से संबंजधत प्रचालन प्राजधकरण के मानकों एि ं जिजनििे नों के अनुरूप हैं और उनकी अनुमोदित स्ट्ितन्त्र लेखापरीिा एिेंजसयों द्वारा जनयजमत लेखापरीिा करिाई गयी है; (णक) ऐसे ग्राहकों के साथ, अपने ग्राहकों को अजधप्रमाणन सेिाएं उपलब्ध कराने के जलए अजधप्रमाणन प्रभारों हते ु सहमत हो सकती ह ै और दफलहाल प्राजधकरण का इस संबंध में कोई जनयंत्रण नहीं होगा; दकन्त ु भजिष्य में इस संबंध में प्राजधकरण को एक जभन्न दक्रयाजिजध जनधावररत करने का अजधकार सुरजित होगा; (णख) भौजतक रूप से प्राप्त की गई आधार नंबर या आधार पत्रों की फोोो प्रजतयों को अनुरोधकताव संस्ट्था द्वारा संजचत करने से पूि वआधार नंबर के पहले 8 अंकों को छुपाते हुए मास्ट् क दकया िाएगा। (त) ि े प्रत्येक समय प्राजधकरण द्वारा प्रिान की कई अजधप्रमाणन सुजिधाओं के उपयोग के प्रयोिनाथव प्राजधकरण द्वारा िारी अनुबजन्धत ितों एि ं समस्ट्त जनयमों, जिजनयमों, नीजतयों, जनयमािजलयों, प्रदक्रयाओं, जिजनििे नों, मानकों तथा जनििे ों का पालन करेंगी। (थ) प्राजधकरण से जििेष अनुमजत प्राप्त करेंगी और प्राजधकरण के साथ उपयुक् त अनुबंध पर हस्ट् तािर करेंगी, यदि गैर-अजधप्रमाणन उ्ेश् यों के जलए आधार नंबर का संचयन अपेजित ह।ै आधार नंबर को प्राजधकरण द्वारा समय-समय पर यथा जिजनर्िष्व ो सुरजित तरीके से संजचत करना होगा। (ि) अजधप्रमाणन में प्रयोग दकए िाने िाले डेोा की प्रकृजत, िरुु पयोग के िेत्र और ऐसे िरुु पयोगों या धोखाधड़ी से बचाि के किम उठाने के जलए आधार नंबर धारकों की िानकारी के जलए प्राजधकरण द्वारा चलाए िाने िाले दकसी भी ‍ यापक िागरूकता कायवक्रम में प्राजधकरण को पूणव सहयोग प्रिान करेंगी। 14क. ऑफलाइन सत्य ापन मागं कता वसस्ट्ं थ ाओं के िाजयत्ि :- (1) ओिीएसई के जनम् नजलजखत िाजयत्ि होंगे:- (क) आधार अजधजनयम और उसके अंतगवत बनाए गए जिजनयमों एिं संबंजधत नीजतयों, मैनुअल, प्रदक्रयाओं, जिजनििे ों, मानक एिं प्राजधकरण द्वारा िारी जनििे ों का अनुपालन सुजनजित करना। (ख) दकसी भी ‍ यजि जििेष के आाधार नंबर या बायोमेररक सूचना को दकसी भी उ्ेश् य के जलए एकत्र, उपयोग एिं संजचत नहीं दकया िाएगा तथा ऑफलाइन आधार डेोा को अजधजनयम एिं उसके अंतगवत जनर्मवत जिजनयमों के अन्यत्र दकसी अन् य संस्ट् था को साझा नहीं दकया िाएगा। (ग) आधार डेोा से संबंजधत धोखाधड़ी या जििाि की िांच के मामलों में संस्ट् था प्राजधकरण को या उनके द्वारा जनयुक्त अथिा प्राजधकृत दकसी एिेंसी को या दकसी अन् य प्राजधकृत िांच एिेंसी को पूणव सहयोग प्रिान करेगी और उन् ह ें अपने पररसर, ररकाडव, कार्मवकों एिं अन् य दकसी संगत संसाधन या सूचना तक पहुचं प्रिान करेगी। इसके साथ साथ आधार डेोा से संबंजधत धोखधड़ी के संबंध में िन सामान् य के जलए सूचना िारी करने में प्राजधकरण की सहायता करेगी तादक आधार नंबर धारक यह सुजनजित कर सके दक कही िह धोखाधड़ी का जिकार तो नहीं हो गया ह ैऔर साथ ही उपचारी कारविाई सुजनजित कर सके।[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 11 (घ) दकसी भी सूचना के िरुु पयोग या आधार फ्रेमिकव से संबंजधत प्रणाली या आधार संबंजधत सूचना के िरुु पयोग का पता लगने पर प्राजधकरण को जबना दकसी अनािश् यक जिलम् ब के और हर हालत में 22 घंोे के अंिर सूजचत करना होगा। यदि ओिीएसई धोखाधड़ी से पीज डत ह ैया ऑफलाइन सत् यापन से संबंजधत धोखाधड़ी जिश्लेषण प्रणाली के माध्य म से दकसी धोखाधड़ी के तरीके की पहचान होती ह ै तो िह धोखाधड़ी से संबंजधत सभी आिश् यक सूचना को प्राजधकरण के साथ साझा करेगी और जबना दकसी जिलंब के आधार नंबर धारक को भी सूजचत करेगी। (च) ऑफलाइन सत् यापन प्रचालन और पररणामों के जलए उत् तरिायी होगी चाह े अपने प्रचालन के कुछ भाग को तृतीय पाोी को उप-अनुबंजधत कर दिया हो। इसके अलािा ओिीएसई यह भी सुजनजित करेगी दक पाोी को दिए गए ऑफलाइन सत्य ापन से संबंजधत प्रचालनों में उक्त सस्ट् थाएं प्राजधकरण के मानकों एिं जिजनििे ों का अनुपालन सुजनजित करेगी। (छ) ऑफलाइन सत् यापन में प्रयोग की िा रही डेोा की प्रकृजत, िरुु पयोग की गुंिाइि और ऐसे िरुु पयोगों या धोखाधड़ी से बचाि के जलए किम के संबंध में आधार नंबर धारकों को िागरूक करने के जलए प्राजधकरण द्वारा चलाए िाने िाले ‍ यापक िागरुकता कायवक्रमों में प्राजधकरण को पूरा सहयोग िने ा। 15. हा/ंना अजधप्रमाणन सजु िधा का उपयोग:- (1) अनुरोधकताव संस्ट्था, अपने जनिी उपयोग अथिा अन्य एिेंलसंयों की ओर से दकसी आधार नंबर धारक की पहचान के सत्यापन के जलए प्राजधकरण की हां/ना अजधप्रमाणन सुजिधा का उपयोग कर सकती है। (2) अनुरोधकताव संस्ट्था, प्राजधकरण द्वारा स्ट्थाजपत पोोवल या अन्य दकसी तंत्र के माध्यम से दकसी अन्य एिेंसी अथिा संस्ट्था को, प्रत्येक ऐसी संस्ट्था के जलए एक अलग से लाइसेंस कुंिी के सृिन तथा सहभाजगता करने के द्वारा कजथत संस्ट्था को हां/ना अजधप्रमाणन जनष्पािन के जलए अनुमजत ि ेसकती ह।ै सन्िहे के जनराकरण के जलए, यह स्ट्पष्ट दकया िाता ह ै दक लाइसेंस कुंिी की ऐसी सहभाजगता की अनुमजत केिल हां/ना अजधप्रमाणन के जनष्पािन के जलए ही ह ै और यह ई-केिाईसी अजधप्रमाणन की जस्ट्थजत में जनजषद्ध ह।ै (3) ऐसी एिेंसी अथिा संस्ट्था: (क) दकसी उ्ेश्य के जलए दकसी अन्य व्यजि अथिा संस्ट्था के साथ लाइसेंस कुंिी साझा नहीं करेगी; तथा (ख) आधार नंबर धारक की व्यजिगत सूचना, डेोा सुरिा एि ं अनुरोधकताव संस्ट्था के जलए प्रयोज्य अन्य प्रासंजगक उत्तरिाजयत्िों से संबंजधत समस्ट्त िाजयत्िों का अनुपालन करेगी। (3क) आधार अनुप्रमाणन के जलए एयूए/केयूए/सब-एयूए/सब-केयूए अपने क्लाइंो ऐप् लीकेिन का प्रयोग करेंगी, जिस े अनुरोधकताव संस्ट्था द्वारा जडजिोल रूप में हस्ट् तािररत दकया िाएगा। (4) यह सुजनजित करना अनुरोधकताव संस्ट्था का उत्तरिाजयत्ि होगा दक कोई संस्ट्था अथिा एिेंसी जिसके साथ उसन े लाइसेंस कुंिी सहभाजित की ह,ै प्राजधकरण के अजधजनयम के प्रािधानों, जिजनयमों, प्रदक्रयाओं, मानकों, दििाजनििे ों, जिजनििे ों तथा प्रोोोकॉल के उपबंधों का अनुपालन करें, िो अनुरोधकताव संस्ट्था पर लाग ूहैं। (5) अनुरोधकताव संस्ट्था, प्राजधकरण के जिजनयमों, प्रदक्रयाओं, मानकों, दििाजनििे ों तथा प्रोोोकॉल के अननुपालन के जलए उस संस्ट्था या एिेंसी के साथ संयुि तथा पृथक रूप से उत्तरिायी होगी, जिसके साथ लाइसेंस कुंिी को साझा दकया गया ह।ै 16. ई-केिाईसी अजधप्रमाणन सजु िधा का उपयोग:- (1) केयूए अपने स्ट्ियं के उ्ेश्यों के जलए आधार नंबर धारक का ई-केिाईसी डेोा प्राप्त करने के जलए प्राजधकरण द्वारा प्रित्त ई-केिाईसी अजधप्रमाणन सुजिधा का उपयोग कर सकता है। (2) सब-केयूए के साथ ई-केिाईसी डेोा साझा करने के जलए केयूए प्राजधकरण से जििेष अनुमजत के जलए आिेिन प्रस्ट् तुत करेगी और आधार नंबर धारक की जिजिष् ो सहमजत के साथ ऐसे डेोा समय-समय पर प्राजधकरण द्वारा िारी दििाजनििे ों के अनुसार कूोबद्ध रूप में साझा दकए िाएंगे। (3) जिस सब-केयएू के साथ केयएू न ेआधार नबं र धारक के ई-केिाईसी डोे ा साझा दकए ह ैंिह इन्ह ें दकसी अन्य सस्ट्ं थ ा या एिेंसी के साथ आगे साझा नहीं करेगी।12 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (4) आधार नंबर धारक दकसी भी समय केयूए/सब-केयूए को अपने ई-केिाईसी डेोा को संजचत करने के जलए िी गई सहमजत को िापस ले सकता ह।ै सहमजत िापस लेने के उपरांत केयूए/सब-केयूए सत् यापन के आधार पर ई-केिाईसी डेोा को समाप्त कर िगे ा तथा इसकी पािती आधार नंबर धारक को उपलब् ध कराई िाएगी। (5) उप-जिजनयम (3) में उजल्लजखत भािी सहभाजगता के प्रजतबंध के अजतररि, आधार नंबर धारक की व्यजिगत सूचना से संबंजधत अन्य समस्ट्त िाजयत्ि, अनुरोधकताव संस्ट्थाओं के जलए लाग ू डेोा सुरिा एिं अन्य संबंजधत उत्तरिाजयत्ि उन सब केयूए के जलए भी लाग ू होंग,े जिनके साथ जिजनयम 16 के अनुरूप ई-केिाईसी डेोा साझा दकया िा चुका ह।ै (6) केयूए ऐसे सभी संव्यिहारों का प्राजधकरण द्वारा जिजनर्िष्टव समयािजध के जलए एक लेखापरीिणीय संलेख अनुरजित करेगा, िहां डेोा अन्य सब-केयूए के साथ साझा दकया गया ह।ै 16क ऑफलाइन सत्य ापन सजु िधा का उपयोग:- (1) आधार नंबर धारक के ऑफलाइन आधार डेोा को प्राप्त करने के जलए प्राजधकरण द्वारा उपलब् ध कराई गई ऑफलाइन सत् यापन सुजिधा का उपयोग ओिीएसई द्वारा केिल उन उ्ेश् यों के जलए दकया िाए जिन् हें सत् यापन के समय आधार नंबर धारक को जनर्िष्टव कर दिया गया हो। (2) दकसी अन् य संस्ट्था या ‍ यजि की ओर से कोई संस्ट् था ऑफलाइन सत् यापन नहीं करेगी। (3) ओिीएसई ऑफलाइन सत् यापन के समय आधार नंबर धारक से प्राप्त आधार डेोा को आधार नंबर धारक की सहमजत से, समय-समय पर प्राजधकरण द्वारा िारी दििाजनििे ों के अनुसार सुरजित रूप से संचजयत करेगी। (4) आधार नंबर धारक दकसी भी समय ओिीएसई को अपने ऑफलाइन आधार डेोा को संजचत करने के जलए िी गई सहमजत को िाजपस ले सकता ह।ै सहमजत िाजपस लेने की जस्ट्थजत में ओिीएसई सत् याजपत दकए िा सकने िाले रूप में ऑफलाईन आधार डेोा को समाप्त कर िगे ी और इसकी पािती आधार नंबर धारक को उपलब् ध कराई िाएगी। (5) चूक या अजतक्रमण या जिजध में पररितवन या दकसी अन् य कारण से, िो प्राजधकरण को संगत लगता ह ै तो िह ओिीएसई को ऑफलाइन सत् यापन सेिाओं के उपयोग को समाप्त करने के जनििे ि ेसकती ह।ै 17. अनरु ोधकता वसस्ट्ं था द्वारा पहचान सचू ना के उपयोग स ेसबं जं धत िाजयत्ििः- (1) अनुरोधकताव संस्ट्था सुजनजित करेगी दक: (क) आधार नंबर धारक से संगृहीत कोर बायोमेररक सूचना को दकसी भी उ्ेश्य के जलए संजचत, साझा अथिा प्रकाजित नहीं दकया गया है, और उसके पास कोर बायोमेररक सूचना की कोई प्रजत िेष नहीं है; (ख) संगृहीत कोर बायोमेररक सूचना को कूोबद्ध पीआईडी ब्लॉक के सृिन के जबना दकसी नेोिकव पर संप्रेजषत नहीं दकया गया ह,ै जिसे प्राजधकरण द्वारा जनधावररत जिजनििे नों तथा प्रदक्रयाओं के अनुरूप संप्रेजषत दकया िा सकता है; (ग) कूोबद्ध पीआईडी ब्लॉक संजचत नहीं दकया गया है, िब तक दक यह बफरकृत अजधप्रमाणन के जलए ह,ै िहां इसे अल्प समयािजध के जलए अजधप्रमाणन उपकरण पर अस्ट्थायी तौर पर रखा िा सकता ह,ै और संप्रेषण के पिात इसे समाप्त कर दिया गया है; (घ) अजधप्रमाणन के िौरान, प्राप्त पहचान सूचना केिल अजधप्रमाणन के समय आधार नंबर धारक के जलए जिजनर्िष्टव उ्ेश्य के जलए प्रयुि की गयी ह,ै और जिस आधार नंबर धारक से यह सूचना संबंजधत ह,ै उसकी पूि वसहमजत जलए जबना आग ेप्रको नहीं की िाएगी; (च) अजधप्रमाणन के िौरान संगृहीत आधार नंबर धारक की पहचान सूचना तथा अजधप्रमाणन प्रदक्रया के िौरान सृजित दकसी अन्य सूचना को ऐक्सेस, उपयोग एि ं प्रकोन के संबंध में सुरजित रखा गया ह ै जिसकी अजधजनयम तथा इसके जिजनयम के अधीन अनुमजत नहीं ह।ै[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 13 (छ) अजधप्रमाणन अनुरोध के जडजिोल रूप में हस्ट्तािर के जलए प्रयुि प्राइिेो कुंिी तथा लाइसेंस कुंिी को सुरजित रखा गया ह ैऔर ऐक्सेस जनयजन्त्रत ह;ै तथा (ि) अपनी प्रणाजलयों में आधार-आधाररत पहचान सूचना से संबंजधत डेोा संचयन तथा डेोा संरिण के संबंध में समस्ट्त प्रासंजगक कानून एि ंजिजनयम, िो उनके एिेंो (यदि लागू हो) के तथा अजधप्रमाणन उपकरण के जिषय में हैं, का अनुपालन दकया गया ह।ै 18. अनरु ोधकता वसस्ट्ं था द्वारा लॉग का रखरखाि :- (1) अनुरोधकताव संस्ट्था को अपने द्वारा अजधप्रमाजणत दकए गए कायव के संबंध में नीचे सूचीबद्ध जििरण सजहत कायव लॉग का रखरखाि करना होगा:- (क) आधार नंबर, िचुवअल आईडी, एएनसीएस ोोकन या यूआईडी ोोकन के अजतररक् त अजधप्रमाणन अनुरोध के जलए जिजनर्िष्व ो पैरामीोर प्रस्ट् तुत करना। (ख) मामले के अनुसार पूणव आधार नबं र या मास्ट्क्ड आधार सजहत अजधप्रमाणन प्रदक्रया के रुप में प्राप्त जिजनर्िष्व ो पैरामीोर। (ग) अजधप्रमाणन के समय आधार नंबर धारक या बालक के मामले में उसके माता या जपता अथिा अजभभािक को दकया गया सूचना प्रकोीकरण अजभलेख का उ्ेश्य। (ङ) अजधप्रमाणन के जलए आधार नंबर धारक या बालक के मामले में माता-जपता अथिा अजभभािक की सहमजत का अजभलेख, परन्तु, दकसी भी जस्ट्थजत में पीआईडी सूचना को अपने पास नही रखेगा। (2) अनुरोधकताव संस्ट्था द्वारा अजधप्रमाणन कायव के लॉग का रखरखाि 2 (िो) िष व की अिजध के जलए दकया िाएगा तथा इस िौरान आधार नंबर धारक को इस संबंध में जनधावररत प्रदक्रया के अनुसार ऐसे लॉग को एक्सेस करने का अजधकार प्राप्त होगा। (3) उप जिजनयम (2) में जिजनर्िष्व ो अिजध की समाजप्त के पश् चात, लॉग को 5 िषव की अिजध अथिा जिजध अनुसार अथिा संस्ट् था का संचालन करने िाले जिजनयमों के अनुसार अपजे ित िषों के जलए, इनमें से िो भी बाि में हो, पुरालेख के तौर पर रखा िाएगा जसिाय ऐसे अजभलेखों के जिन् हें उक् त अिजध की समाजप्त के बाि दकसी न् यायालय के आििे िो न्यूनतम उ‍ च न् यायालय के न् यायाधीि द्वारा दिया गया हो या दकसी बकाया जििाि के लंजबत रहने तक सुरजित रखना अपेजित होगा। (4) अनुरोधकताव संस्ट्था द्वारा संबंजधत आधार नंबर धारक से प्राप्त अनुरोध पर अथिा जिकायत के जनपोान तथा जििािों के समाधान के जलए अथिा न् यायालय के आििे िो न्यूनतम न् यायालय के न् यायाधीि द्वारा दिया गया हो, के अजतररि दकसी भी अन् य ‍ यजि के साथ अजधप्रमाणन लॉग को साझा नहीं दकया िाएगा। इस उप जिजनयम में उजल्लजखत उ्ेश् य के अलािा दकसी अन् य उ्ेश् य के जलए अजधप्रमाणन लॉग का प्रयोग नहीं दकया िाएगा। (5) अनुरोधकताव संस्ट्था द्वारा लॉग के संचयन के संबंध में सूचना प्रौद्योजगकी अजधजनयम, 2000 तथा भारतीय साक्ष्य अजधजनयम, 1822 सजहत, िंकंतु उन तक सीजमत नहीं, सभी संबंजधत जिजधयों, जनयमों तथा जिजनयमों का पालन दकया िाएगा। (6) इस जिजनयम में जिजनर्िष्टव अजधप्रमाणन लॉग से संबंजधत िाजयत्ि इन जिजनयमों के अनुसार संस्ट्था की जनयुजि जनरस्ट्त करने के बाििूि भी मान्य रहगे ें। 19. अजधप्रमाणन सिे ा एिजें सयों की भजू मका, उत्तरिाजयत्ि एि ंआचार सजं हता:- अजधप्रमाणन सेिा एिेंसी के दक्रयाकलाप तथा िाजयत्ि जनम्नानुसार होंग:े - (क) अनुरोधकताव संस्ट्था द्वारा अजधप्रमाणन अनुरोध हस्ट्तांतररत करने के जलए केंद्रीय पहचान डेोा ररपोजिोरी (सीआईडीआर) के साथ प्राजधकरण द्वारा इस उ्ेश्य हते ु जिजनर्िष्टव जिजध के अनुसार सुरजित क्नेजक्ोजिोी उपलब्ध करिाना;14 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (ख) सीआईडीआर को प्रेजषत करने से पूि व अजधप्रमाणन डेोा पैकेो से सबं ंजधत मूलभूत अनुपालन एि ं पूणवतिः िांच से संबंजधत अनुपालन करना; (ग) सीआईडीआर से प्रजतदक्रया प्राप्त होने पर अनुरोध करने िाली अनुरोधकताव संस्ट्था को दकए गए कायव के पररणाम संप्रेजषत करना; (घ) केिल प्राजधकरण द्वारा अनुमोदित अनुरोधकताव संस्ट्थाओं के साथ कायव करना तथा इसका जनष्पािन कर रहीं अनुरोधकताव संस्ट्थाओं की सूची की िानकारी प्राजधकरण को िने ा; (च) अनुरोधकताव संस्ट्था के साथ दकए गए अनुबंधों की प्रत्येक संबंजधत िानकारी प्राजधकरण को सूजचत करना; (छ) यह सुजनजित करना दक अजधप्रमाणन कायव तथा आिश्यक तंत्र, अिसंरचना, प्रदक्रयाओं इत्यादि के रखरखाि के जलए जनयुि व्यजि को अपेजित योग्यता प्राप्त ह;ैं (ि) प्रचालनों की लेखापरीिा दकसी मान्यताप्राप्त जनकाय द्वारा प्रमाजणत सूचना प्रणाली लेखापरीिकों द्वारा िार्षवक आधार पर की िाए तथा इस संबंध में समय-समय पर प्राजधकरण द्वारा िारी नीजतयों, प्रदक्रयाओं, कायवजिजधयों, मानकों एि ं जिजनििे नों के अनुपालन की प्रमाजणत लेखापरीिा ररपोोव प्राजधकरण को उपलब्ध करिाना सुजनजित करना; (झ) यह सुजनजित करना की तंत्र, प्रदक्रयाएं, उपकरण, सॉफ्ोिेयर एिं बायोमेररक अिसंरचना, सुरिा तथा अन्य संबंजधत घोकों सजहत सभी अिसरं चनाएं और प्रचालन इस उ्ेश्य के जलए प्राजधकरण द्वारा जिजनर्िष्टव मानकों एि ं जिजनििे नों के अनुरूप हैं; (ो) नेोिकव तथा अन्य सूचना प्रौद्योजगकी अिसंरचना, प्रदक्रयाओं, कायवजिजधयों इत्यादि के संबंध में प्राजधकरण द्वारा िारी जनििे ों, जिजनििे नों आदि का हमेिा अनुपालन करना; (ठ) सभी संबंजधत कानून तथा जिजनयमों, जििेषकर डेोा सुरिा तथा डेोा प्रबंधन का अनुपालन करना; (ड) अजधप्रमाणन सेिा एिेंजसयों द्वारा दकसी अनुरोधकताव संस्ट्था को अनबु ंध के अंतगवत प्रिान की गई अन्य मूल्यिर्धवत सेिाएं आधार अजधप्रमाणन प्रदक्रया का भाग नहीं होंगी; (ढ) अजधप्रमाणन सेिा एिेंसी के द्वारा उप-अनुबंध के अंतगवत अपने प्रचालन का कुछ भाग अन्य संस्ट्थाओं को दिए िान े के मामले में भी, अजधप्रमाणन से संबंजधत सभी प्रचालनों के जलए प्राजधकरण के प्रजत उत्तरिाजयत्ि अजधप्रमाणन सेिा एिेंसी का होगा; (ण) अजधप्रमाणन से सम्बद्ध धोखेबािी अथिा जििाि से सबंजधत मामले की िांच के जलए अजधप्रमाणन सेिा एिेंसी द्वारा प्राजधकरण (अथिा उसकी एिेंसी) तथा/अथिा अन्य प्राजधकृत िाच ं एिेंसी को अपने पररसर, अजभलेख, जसस्ट्ोम, कर्मवयों, अिसंरचना, अन्य दकसी संबंजधत संसाधन अथिा सूचना तथा अजधप्रमाणन प्रचालनों से संबंजधत अन्य संबंजधत पहलू तक ऐक्सेस उपलब्ध कराने सजहत पूणव सहयोग प्रिान दकया िाएगा; (त) दकसी अनुरोधकताव संस्ट्था को अजधप्रमाणन प्रभारों पर सेिाएं प्रिान करने की सहमजत िी िा सकेगी तथा, ऐसी अनुरोधकताव संस्ट्था पर, प्राजधकरण का इस मामले में सामजयक तौर पर कोई हस्ट्तिेप नहीं होगा, तथाजप, ऐसे मामले में प्राजधकरण के पास भजिष्य में दकसी जभन्न व्यिस्ट्था के जनधावरण करने का अजधकार सुरजित होगा; (थ) प्राजधकरण द्वारा िारी प्रत्येक संजििागत ितों तथा सभी जनयमों, जिजनयमों, नीजतयों, मैनुअलों, प्रदक्रयाओं, जिजिष्टताओं, मानकों तथा जनििे ों का सििै पूणवत: पालन दकया िाएगा। 20. अजधप्रमाणन सिे ा एिजें सयों द्वारा लॉग का रखरखाििः- (1) अजधप्रमाणन सेिा एिेंसी अपने द्वारा जनष्पादित अजधप्रमाणन कायों के लॉग का रखरखाि दकया िाएगा, जिसम ें जनम्नजलजखत संव्यिहार का ब्योरा िाजमल होगा, नामतिः-[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 15 (क) अनुरोधकताव संस्ट्था की पहचान; (ख) प्रस्ट्तुत अजधप्रमाणन अनुरोध के मानिडं ; तथा (ग) अजधप्रमाणन प्रजतदक्रया के रूप में प्राप्त मानिडं : बिते दक िहां लागू होगा, िहां आधार नंबर, िचुवअल आईडी, यूआईडी ोोकन, एएनसीएस ोोकन, पीआईडी सूचना, उपकरण पहचान संबंधी डेोा और ई-केिाईसी प्रजतदक्रया डेोा का प्रजतधारण नहीं दकया िाएगा। (2) अजधप्रमाणन सेिा एिेंसी द्वारा अजधप्रमाणन कायव के लॉग का रखरखाि 2 (िो) िष व की अिजध के जलए दकया िाएगा तथा इस िौरान प्राजधकरण तथा/अथिा अनुरोधकताव संस्ट्था द्वारा जिकायत जनिारण, जििाि जनपोान तथा लेखापरीिा कायों के जलए इन जिजनयमों में जिजनर्िष्टव प्रदक्रया के अनसुार ऐसे अजभलेख के प्रयोग की मांग की िा सकेगी। इस उप जिजनयम में उजल्लजखत उ्ेश्यों के अन्यत्र दकसी अन्य उ्ेश्य के जलए अजधप्रमाणन अजभलेख का प्रयोग नहीं दकया िाएगा। (3) उप जिजनयम (2) में जिजनर्िष्टव अिजध की समाजप्त के पिात, लॉग को 5 िषव की अिजध अथिा जिजध अनुसार अथिा संस्ट्था का सचंलन करने िाले जिजनयमों के अनुसार अपेजित िषों के जलए सुरजित रखा िाएगा तथा 5 िषव की अिजध की समाजप्त के उपरांत, इनमें से िो भी बाि में हो, पुरालेख के तौर पर रखा िाएगा तथा उि अिजध की समाजप्त के पिात, दकसी न्यायालय िो उच्च न्यायालय के न्यायाधीि से जनम्न नहीं होगा अथिा दकसी बकाया जििाि के जलए अपेजित लॉग के अलािा अन्य अजभलेखों को होा जलया िाएगा। (4) अजधप्रमाणन सेिा एिेंसी द्वारा लॉग के संचयन के संबंध में सूचना प्रौद्योजगकी अजधजनयम, 2000 सजहत सभी संबंजधत जिजधयों का पालन दकया िाएगा । (5) इस जिजनयम में जिजनर्िष्टव अजधप्रमाणन लॉग से संबंजधत िाजयत्ि इन जिजनयमों के अनुसार जनयुजि जनरस्ट्त होने के बाििूि भी मान्य रहगें े। 20क. ऑफलाइन सत्यापन मागं कता वसस्ट्ं था द्वारा लॉग का िैकजल्पक अनरु िण:- (1) ऑफलाइन सत् यापन मांगकताव संस्ट्था जनिासी की सहमजत से अपने द्वारा संसाजधत सत्यापन संव्यिहारों, यदि ओिीएसई आिश् यक समझे, के ऐसे लॉग का रखरखाि कर सकती है, जिनमें जनम्नजलजखत संव्यिहार का जििरण अंतर्नवजहत हो, नामतिः- क. जनिासी द्वारा साझा दकया गया ऑफलाइन आधार डेोा की उपयुि रूप से सुरिा करना; ख. जनिासी द्वारा सत् यापन के द्वारा साझा दकए गए मोबाईल नंबर, ई-मले आई डी, फोोो आदि सजहत कोई अन् य डेोा; ग. ओिीएसई और जनिासी के बीच स्ट् थानीय सत् यापन संबंधी कारविाई का लॉग; घ. आधार नंबर धारक को भेिे गए ऑफलाइन सत् यापन से संबंजधत अजधसूचना का ब् योरा। िंकंतु दकसी भी जस्ट्थजत में आधार नंबर धारक के आधार नंबर और िचुवअल आईडी को संजचत नहीं दकया िाएगा। (2) ओिीएसई संबंजधत आधार नंबर धारक के अजतररक् त दकसी भी ‍ यजि के साथ लॉग को साझा नहीं करेगी। जिकायत जनिारण या जििाि सुलझाने के जलए अजधजनयम के उपबंधों के अनुरूप कायव दकया िाएगा। उप जिजनयम में िर्णवत उ्ेश् य के अजतररक् त सत् यापन लॉग का उपयोग दकसी भी कायव के जलए नहीं दकया िाएगा। 21. अनरु ोधकता वसस्ट्ं थाओं, अजधप्रमाणन सिे ा एिजे न्स यों और ऑफलाइन सत्य ापन मागं कता वसस्ट्ं थाओं की लखे ापरीिा:- (1) यह सुजनजित करना दक संस्ट् थाएं प्राजधकरण द्वारा िारी अजधजनयम, जनयमों, जिजनयमों, नीजतयों, प्रदक्रयाओं, दििाजनििे ों के अनुरूप कायव कर रही हैं, प्राजधकरण सब-एयूए तथा सब-केयूए, अजधप्रमाणन सेिा एिेंजसयों तथा ऑफलाइन सत् यापन मांगकताव संस्ट्थाओं सजहत अनुरोधकताव संस्ट्थाओं का प्रचालन, अिसंरचना, प्रणाजलयों और प्रदक्रयाओं की लेखापरीिा स्ट्ि यं करेगी या प्राजधकरण द्वारा जनयुक्त लेखापरीिा एिेंसी के माध्य म से करायेगी।16 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (2) प्राजधकरण स्ट्ियं अथिा प्राजधकरण द्वारा जनयुि लेखापरीिा के माध्यम से उप-जिजनयम (1) में सिर्ं भवत संस्ट्थाओं के प्रचालनों तथा प्रणाली की लेखापरीिा कर सकता है। ऐसी लेखापरीिा की बारंबारता, समय एि ं प्रदक्रया समय- समय पर प्राजधकरण द्वारा अजधसूजचत की िाएगी । (3) लेखापरीिा की िाने िाली संस्ट्था द्वारा प्राजधकरण अथिा प्राजधकरण द्वारा अनुमोदित तथा/अथिा प्राजधकरण द्वारा जनयुि एिेंसी को लेखापरीिा प्रदक्रया के िौरान पूणव सहयोग प्रिान दकया िाएगा तथा प्राजधकरण अथिा प्राजधकरण द्वारा अनुमोदित तथा/या जनयुि एिेंसी को अपनी प्रदक्रया, अजभलेखों तथा प्राजधकरण से प्राप्त सेिाओं से संबंजधत सूचना के जलए पूणव ऐक्सेस प्रिान की िाएगी। लेखापरीिा की लागत का िहन संबंजधत संस्ट्था द्वारा दकया िाएगा। (4) प्राजधकरण द्वारा दकसी प्रकार की त्रुरो की जिनाख्त दकए िाने पर प्राजधकरण संबंजधत संस्ट्था से आिश्यक स्ट्पष्टीकरण तथा/अथिा इसके दक्रयाकलापों से संबंजधत सूचना प्रस्ट्तुत करने के जलए कहा िा सकेगा तथा ऐसी संस्ट्था से ऐसी त्रुरो के जनिारण अथिा इन जिजनयमों में जिजनर्िष्टव कारविाई करने की अपेिा की िा सकेगी। (5) खंड (4) की दकसी बात के होते हुए भी और अजधजनयम के अंतगवत उठाए गए दकसी किम पर प्रजतकूल प्रभाि डाले जबना, प्राजधकरण लेखापरीिा के आधार पर पाई गई कजमयों पर जिजनयम 25(1क) के अंतगवत कारविाई कर सकता ह।ै 22. डेोा सुरिा:- (1) अनुरोधकताव संस्ट्था तथा अजधप्रमाणन सेिा एिेंसी/ओिीएसई द्वारा आधार अजधप्रमाणन अनुरोध कायों एिं क्रमि: सीआईडीआर/ऑफलाइन सत् यापन की रूंोंग के जलए डेोा केंद्र के अंिर जस्ट्थत या भारत में जस्ट्थत क् लाउड स्ट् ोोरेि केंद्रों में अपने सिवर का उपयोग दकया िाएगा। (1क) भारत की िेत्रीय सीमाओं से बाहर जस्ट्थत संस्ट् थाओं से अजधप्रमाणन अनुरोध स्ट् िीकार नहीं दकए िाएंगे। भारत से बाहर के अजधप्रमाणन अनुरोधों को स्ट् िीकार करने के जलए अनुरोधकताव संस्ट्था प्राजधकरण से जििेष अनुमजत प्राप्त करेगी। (2) अजधप्रमाणन सेिा एिेंसी प्राजधकरण के डेोा केंद्र के साथ इस उ्ेश्य से प्राजधकरण द्वारा जनर्िष्टव प्रदक्रया तथा सुरिा कार्यविजधयों के अनसुार डूअल रेडन्डेंो, सुरजित लीज्ड लाइनें अथिा एमपीएलएस कनेजक्ोजिोी की स्ट्थापना करेगी। (3) अनुरोधकताव संस्ट्था अजधप्रमाणन सेिा ऐक्सेस के जलए केिल प्राजधकरण द्वारा उपलब्ध करिाई गई अजधप्रमाणन सुजिधा का उपयोग प्राजधकरण द्वारा जिजनर्िष्टव उ्ेश्य के जलए एएसए के सुरजित नेोिकव के माध्यम से दकया िाएगा। (4) अनुरोधकताव संस्ट्था, अजधप्रमाणन सेिा एिेंजसयााँ तथा ओिीएसई प्राजधकरण द्वारा समय-समय पर िारी सभी जिजनयमों, सूचना, सुरिा नीजतयों, प्रदक्रयाओं, मानकों, जिजनििे नों तथा दििाजनििे ों का अनुपालन करेंगी। 23. अनरु ोधकता वसस्ट्ं था अथिा अजधप्रमाणन सिे ा एिसें ी द्वारा अजधप्रमाणन सजुिधा के ऐक्ससे को छोड़ना: (1) प्राजधकरण द्वारा अजधप्रमाणन सुजिधा के जलए प्रिान की गई ऐक्सेस को छोड़ने की इ‍छकु अनुरोधकताव संस्ट्था अथिा अजधप्रमाणन सेिा एिेंसी, िो इन जिजनयमों के अंतगवत जनयिु की गई हैं, ऐसे सरडेंर के जलए अपना आिेिन प्राजधकरण को प्रस्ट्तुत कर सकती हैं। (2) इन जिजनयमों के अंतगवत सरेंडर के अनुरोध का जनपोान करते समय, प्राजधकरण द्वारा अनुरोधकताव संस्ट्था अथिा अजधप्रमाणन सेिा एिेंसी से अपेिा की िाती है दक िह जनम्नजलजखत सजहत सेिाओं को जनबावध रूप से रोकने या समाप्त करने के जलए दकसी भी आिश्यक मामले में प्राजधकरण को संतुष्ट करेगा:- (क) अजधप्रमाणन अजभलेख के रखरखाि तथा परररिण के जलए अनुरोधकताव संस्ट्था द्वारा की गई व्यिस्ट्था तथा इन जिजनयमों एि ंप्रदक्रयाओं के अनुसार इस उ्ेश्य से प्राजधकरण द्वारा जिजनर्िष्टव अन्य िस्ट्तािेि; (ख) अनुरोधकताव संस्ट्था द्वारा संबंजधत आधार नंबर धारक से अनुरोध प्राप्त होने पर उपलब्ध कराने हेत ु अजधप्रमाणन अजभलेख के रखरखाि की व्यिस्ट्था;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 17 (ग) जिकायतों के जनपोान, यदि कोई हों, का अजभलेख; (घ) प्राजधकरण के साथ दकया गया लेखा जनपोान, यदि कोई हो; (च) अजधप्रमाणन सेिा एिेंसी द्वारा सरडेंर दकए िाने के मामले में, अजधप्रमाणन सेिा एिेंसी अपना ऐक्सेस छोड़ने से पूिव अपनी संबद्ध अनुरोधकताव संस्ट्थाओं को अन्य अजधप्रमाणन सेिा एिेंजसयों के प्रचालन म ें िाने के जलए पयावप्त समय िने ा सुजनजित करेगी। 24. इन जिजनयमों के लाग ूहोन ेस ेपिू वजनयिु एिजें सया ं:- (1) इन जिजनयमों के अंतगवत, इन जिजनयमों के लागू होने से पूि व जनयुि की गई अजधप्रमाणन प्रयोिा एिेंसी (एयूए) अथिा ई-केिाईसी प्रयोिा एिेंसी (केयूए) को अनुरोधकताव संस्ट्था तथा अजधप्रमाणन सेिा एिेंसी (एएसए) अथिा ई-केिाईसी सेिा एिेंसी (केएसए) को अजधप्रमाणन सेिा एिेंसी माना िाएगा तथा ऐसी एिेंजसयों एि ं योिना आयोग, भारत सरकार के दिनाकं 28 िनिरी, 2009 की अजधसूचना संख्या ए-43011/02/2009-प्रिासन-1 के अधीन स्ट्थाजपत भारतीय जिजिष्ट पहचान प्राजधकरण अथिा ऐसे प्राजधकरण के दकसी अजधकारी के मध्य अजधजनयम के अंतगवत दकए गए सभी अनुबंध प्राजधकरण द्वारा िारी अजधजनयम के उपबंधों, इनके जिजनयमों तथा अन्य जिजनयमों, नीजतयों, प्रदक्रयाओं, कायवजिजधयों, मानकों तथा जिजनििे नों के साथ असंगत न होने की सीमा तक प्रभािी रहेंग।े (2) उप-जिजनयम (1) में उजल्लजखत होने के बाििूि भी उप-जिजनयम (1) में सिर्ं भवत दकसी मान्यताप्राप्त अनुरोधकता व संस्ट्था अथिा अजधप्रमाणन सेिा एिेंसी से अजधजनयम के उपबंधों, इन जिजनयमों, प्राजधकरण द्वारा जनर्मवत अन्य जिजनयमों तथा प्राजधकरण द्वारा िारी नीजतयों, प्रदक्रयाओं, कायवजिजधयों, मानकों तथा जिजनििे नों का अनपुालन करने की अजनिायवता होगी। (3) उप-जिजनयम (1) में सिर्ं भवत दकसी एिेंसी द्वारा इन जिजनयमों में जनर्िष्टव अजधप्रमाणन सेिाओं से जिलग होने की अपेिा की जस्ट्थजत में िह अपने प्रत्यय पत्र एिं अपने दक्रयाकलापों की तुरंत समाजप्त के जलए आिेिन प्रस्ट्तुत कर सकती ह:ै बिते दक ऐसे मामले में सेिाएं समाप्त करने पर एिेंसी अथिा प्राजधकरण को दकसी मुआििे का भुगतान नहीं दकया िाएगा। (4) उप-जिजनयम (3) के अधीन सेिाएं समाप्त दकए िाने की जस्ट्थजत में संबंजधत संस्ट्था से जिजनयम 23(3) उजल्लजखत कायव समापन अपेिाओं का पालन करने की अजनिायवता होगी । 25. चूक की जस्ट्थजत म ेंिये ताएं एि ंकारविाई:- (1) इस अजधजनयम के अंतगवत जनयुि दकसी संस्ट्था अथिा अजधप्रमाणन सिे ा एिेंसी यदि:- (क) प्राजधकरण द्वारा समय-समय पर िारी दकन्हीं प्रदक्रयाओं, कायवजिजधयों, मानकों, जिजनििे नों अथिा जनििे ों का अनुपालन नहीं करती ह;ै (ख) अजधजनयम तथा इन जिजनयमों के िाजयत्िों का उल्लंघन करती है; (ग) आधार अजधप्रमाणन सुजिधाओं का उपयोग, अनुरोधकताव संस्ट्था अथिा अजधप्रमाणन सेिा एिेंसी की जनयुजि के जलए दिए गए आिेिन में की गई जिजनर्िष्टव के अन्यत्र दकन्हीं अन्य उ्ेश्यों के जलए करती है; (घ) इन जिजनयमों के उ्ेश्यों से प्राजधकरण द्वारा अपेजित दकसी सूचना को प्रस्ट्तुत नहीं कर पाती है; अथिा (च) प्राजधकरण द्वारा दकसी जनरीिण अथिा िांच अथिा पूछताछ अथिा लेखापरीिा के िौरान सहयोग नहीं करती है, तो प्राजधकरण द्वारा, इस अजधजनयम के अध्यधीन दकसी अन्य कारविाई के प्रजत दकसी प्रजतकूलता के जबना, अनुरोधकताव संस्ट्था अथिा अजधप्रमाणन सेिा एिेंसी के जिरूद्ध अजधजनयम के उपबंधों, उससे संबंजधत जनयमों एि ं जिजनयमों का उल्लंघन करने पर ऐसी संस्ट्था अथिा एिेंसी के दक्रयाकलापों को समाप्त करने सजहत िंडात्मक18 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] कारविाई के उपाय अथिा ऐसे अन्य उपाय दकए िा सकेंगे, जिनके संबंध में ऐसी संस्ट्था तथा प्राजधकरण के मध्य दकए गए अनुबंध में जिजिष्ट व्यिस्ट्था की गई हो। बिते दक आधार अजधप्रमाणन से संबंजधत सेिाओं तथा प्रचालनों की समाजप्त से पूिव ऐसी संस्ट्था अथिा एिेंसी को सुनिाई का अिसर प्रिान दकया िाएगा। (1क) िब कोई ऑफलाइन सत् यापन मांगकताव संस्ट्था :- क. प्राजधकरण द्वारा समय-समय पर िारी प्रदक्रया, कायवजिजध, मानकों, जिजनििे नों या जनिेिों के अनुपालन में असफल होती है; अजधजनयम और इन जिजनयमों के अधीन िाजयत् िों के उल्लंघन में पाया िाता ह।ै ख. जिजनर्िष्व ो कायों के अलािा दकन् हीं अन् य कायों के जलए यदि आधार ऑफलाइन सत् यापन सुजिधा का उपयोग दकया िाता ह।ै ग. इन जिजनयमों के अंतगवत प्राजधकरण द्वारा अपजे ित सूचना को उपलब् ध कराने में असफल रहने पर, या घ. प्राजधकरण द्वारा कराए गए दकसी जनरीिण या िांच या पूछताछ या लेखापरीिा में सहयोग िने े म ें असफल रहने पर। प्राजधकरण, अजधजनयम के अंतगवत की िाने िाली दकसी अन् य कारविाई पर प्रभाि डाले जबना और दकसी आपराजधक कारविाई सजहत, जिसे प्राजधकरण सही समझे, अजधजनयम, जनयमों और जिजनयमों के उपबंधों का उल् लंघन करने के जलए ऑफलाइन सत् यापन मांगकताव संस्ट्था पर हतोत्साहन लगाने के जलए किम उठा सकता ह।ै बिते दक कारविाई करने से पूिव संस्ट् था या एिेंसी को सुने िाने का अिसर प्रिान दकया िाएगा। (2) उप जिजनयम (1) में संिर्भवत ऐसी कोई भी कारविाई दकसी भी संस्ट् था या सब-एयूए या सब-केयूए के जिरुद्ध भी की िा सकती ह।ै (3) प्राजधकरण द्वारा सेिाएं समाप्त दकए िाने पर अनुरोधकताव संस्ट्था अथिा अजधप्रमाणन सेिा एिेंसी द्वारा आधार नाम तथा लोगो का प्रयोग, दकसी भी स्ट्िरूप तथा उ्ेश्य, कारण चाह े कुछ भी हो, से नहीं दकया िा सकेगा तथा उसे जिजनयम 23(2) में सचूीबद्ध घोकों सजहत समापन के आिश्यक घोकों के प्रजत प्राजधकरण को संतुष्ट करना होगा। अध्याय-4 अजधप्रमाणन सव्यं िहार डेोा और अजधप्रमाणन अजभलखे 26. अजधप्रमाणन सव्यं िहार डेोा का सचं यन एि ंरखरखाि:- (1) प्राजधकरण द्वारा जनम्नजलजखत सूचना से युि अजधप्रमाणन संव्यिहार डेोा का संचयन एि ंरखरखाि दकया िाएगा:- (क) पीआईडी ब्लॉक सजहत प्राप्त अजधप्रमाणन अनुरोध डेोा; (ख) प्रेजषत अजधप्रमाणन प्रजतदक्रया डेोा; (ग) आिश्यकतानुसार कोई अजधप्रमाणन सिवर साईड संरूपण बिते दक प्राजधकरण द्वारा दकसी भी मामले में अजधप्रमाणन के उ्ेश् य या दकसी कायव सम् पािन के जलए कोई मेोा डेोा (प्रोसेस मेोा डेोा को छोड़कर) का भंडारण नहीं दकया िाएगा। 22. सचं यन की अिजध: (1) प्राजधकरण द्वारा अजधप्रमाणन संव्यिहार डेोा का प्रजतधारण 6 माह की अिजध के जलए दकया िाएगा। पररपत्र के रूप में सामूजहक और जबना नाम के अजधप्रमाणन संव्यिहार डेोा को अनुसंधान कायों के जलए पुरालेख करने और उनके मूल् यांकन के संबंध में प्राजधकरण द्वारा प्रदक्रया जनधावररत की िा सकती ह।ै[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 19 (2) उप जिजनयम (1) में जिजनर्िष्व ो 6 माह की अिजध की समाजप्त के पश् चात अजधप्रमाणन संव्यिहार डेोा को होाया िाएगा। िंकंतु न्यूनतम उ‍ च न् यायालय के न् यायाधीि स्ट् तर के दकसी न् यायालय के आिेि पर या लंजबत जििाि से संबंजधत होने पर अजधप्रमाणन संव्यहार डेोा को बरकरार रखा िाएगा। 28. आधार नबं र धारक द्वारा ऐक्ससे :- (1) आधार नंबर धारक को, अजभलेखों का पुरालेख दकए िाने से पूिव अनुरिण दकए िाने की अिजध के िौरान, जिजहत ितों तथा प्राजधकरण द्वारा जनधावररत िुल्क का भुगतान करने पर प्राजधकरण के सम्मुख आिेिन प्रस्ट्तुत करके अपने अजधप्रमाणन अजभलेख को ऐक्सेस करने का अजधकार प्राप्त होगा। (2) इन जिजनयमों में जिजनर्िष्टव के अनुसार, पुरालेख से पूि व अनुरिण की अिजध के िौरान, आधार नंबर धारकों को अपने जडजिोल रूप से हस्ट्तािररत सत्याजपत अजभलेख की प्राजप्त के जलए प्राजधकरण द्वारा ऑनलाइन पोोवल अथिा मोबाइल एप्लीकेिन अथिा अजभजहत सपंकव केंद्रों की सुजिधा उपलब्ध कारिाई िा सकती ह।ै (3) प्राजधकरण, बायामेररक अथिा ओोीपी अजधप्रमाणन के उपरांत, जनधावररत िुल्क के भुगतान तथा प्रदक्रयाओं के अनुसार आधार नंबर धारकों को जडजिोल रूप से हस्ट्तािररत ई-केिाईसी डेोा उपलब्ध करिा सकता ह।ै (4) सत्याजपत अजभलेख तथा ई-केिाईसी डेोा को दकसी व्यजि अथिा संस्ट्था के साथ साझा नहीं दकया िा सकेगा:- (क) आधार नंबर धारक जिनसे जिजनर्िष्टव अजधप्रमाणन प्रदक्रया के अनुसार अजभलेख या ई-केिाईसी डेोा संबंजधत है, के अलािा दकसी अन्य के साथ। आधार नंबर धारक द्वारा अपने जडजिोल रूप से हस्ट्तािररत सत्याजपत अजभलेख तथा ई-केिाईसी डेोा को अन्य संस्ट्थाओं के साथ साझा दकया िा सकेगा, िो आग े दकसी अन्य संस्ट्था के साथ आधार नंबर धारक से प्रत्येक बार अनुमजत प्राप्त दकए जबना साझा नहीं करेंगे। (ख) अजधजनयम में दकए गए उपबंधों के अन्यत्र। अध्याय - 5 जिजिध 29. जनरसन एि ंव्यािजृ त्त:- (1) भारत सरकार के योिना आयोग के दिनाकं 28 िनिरी, 2009 की अजधसूचना संख्या ए-43011/02/2009- प्रिासन-1 के माध्यम से स्ट्थाजपत भारतीय जिजिष्ट पहचान प्राजधकरण अथिा प्राजधकरण की स्ट्थापना से पूि व ऐसे प्राजधकार प्राप्त दकसी अजधकारी अथिा अजधजनयम के तहत िारी सभी कायवपद्धजत, आििे , प्रदक्रयाएं, मानक तथा नीजतयां अथिा हस्ट्तािर दकए सभी समझौता ज्ञापन, करार अथिा सजििाएं उस सीमा तक लागू रहेंगी, िब तक दक ि ेअजधजनयम के उपबधों तथा इनके तहत तैयार दकए गए अजधजनयम अथिा जिजनयम के तहत असगंत जसद्ध न हो िाएं । (2) आधार (अजधप्रमाणन) जिजनयम 2016 के जनरसन होते हुए भी, उक् त जिजनयम के तहत दकए गए कायों या उक् त जिजनयमों के अंतगवत की गई कारविाई को पूणव हुआ माना िाएगा या उन् ह ें इन जिजनयमों के तितं र उपबंधों के अंतगवत जलया िाएगा। 30. स्ट्पष्टीकरण तथा दििाजनििे ों को िारी करन ेकी िजि तथा करठनाईयों का जनराकरणिः- इन जिजनयमों के अनुप्रयोग अथिा जनिचवन से संबंजधत मामलों को स्ट्पष्ट करने अथिा इन जिजनयमों के कायावन्ियन में दकन्ही करठनाइयों का जनराकरण करने के जलए, प्राजधकरण के पास पररपत्र के रूप में स्ट्पष्टीकरण तथा दििाजनििे ों िारी करने की िजि होगी, जिनका प्रभाि जिजनयम के समान होगा । 31. नीजतया ंिारी करन,े िस्ट्त ाििे ों के प्रसस्ट्ं करण आदि की िजिया:ं- प्राजधकरण इन जिजनयमों स े असंगत ऐसी नीजतयों, आििे ों, प्रदक्रयाओं, मानकों, जिजनििे ों या अन् य िस्ट् तािेिों को िारी कर सकता ह ै जिन् ह ें इन जिजनयमों के अंतगवत जनर्िष्व ो करना अपेजित हो या इन जिजनयमों को प्रभािी बनाने के जलए उक् त प्रािधान आिश् यक हों।20 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] अनसु चू ी - क अनरु ोधकता वसस्ट्ं थाओं की जनयजु ि के जलए पात्रता मापिंड जिजनयम 12(1) िेख ें 1. अनुरोधकताव संस्ट्था के रूप में प्राजधकरण द्वारा उपलब्ध करायी िाने िाली अजधप्रमाणन सुजिधा के प्रयोग की अपेिा रखन े िाली संस्ट्थाओं के जलए अजधप्रमाणन प्रयोिा एिेंसी (एयूए ) तथा/अथिा ई-केिाईसी प्रयोिा एिेंसी (केयूए ), िैसा भी मामला हो, की जनयुजि के जलए जनम्नजलजखत श्रेजणयां िगीकृत की गई ह:ैं- क्रम सख्ं या सस्ट्ं था श्रणे ी श्रणे ी - 1 सरकारी सस्ट्ं थाएं 1.1 केंद्र/राज्य सरकार के मंत्रालय/जिभाग तथा उनके संबद्ध अथिा अधीनस्ट्थ कायावलय 1.2 केंद्र/राज्य सरकार के स्ट्िाजमत्ि तथा अधीन उपक्रम (सरकारी िेत्र के उपक्रम) 1.3 केंद्रीय/राज्य अजधजनयम के अंतगवत स्ट्थाजपत प्राजधकरण/केंद्र/राज्य सरकार द्वारा गरठत प्रयोिन जििेष संगठन श्रणे ी - 2 जिजनयजमत सिे ा प्रिाता 2.1 भारतीय ररििव बैंक द्वारा जिजनयजमत/लाइसेंस प्राप्त-बैंक तथा भुगतान एिं जनपोान प्रणाली 2.1.1 सरकारी िेत्र के बैंक 2.1.2 जनिी बैंक, भारत में प्रचालन के जलए भारतीय ररििव बैंक से लाइसेंस प्राप्त जिििे ी बैंक, भुगतान बैंक, लघु जित्त बैंक 2.1.3 िेत्रीय ग्रामीण बैंक 2.1.4 सहकारी बैंक 1. राज्य सहकारी बैंक 2. जिला सहकारी बैंक 3. अनुसूजचत िहरी सहकारी बैंक 4. गैर अनुसूजचत िहरी सहकारी बैंक 2.1.5 भुगतान एिं जनपोान प्रणाली नेोिकव 1. जित्तीय बािार अिसंरचना 2. खुिरा भुगतान संस्ट्था 3. काडव भुगतान नेोिकव 4. एोीएम नेोिकव 5. पूि-व भुगतान प्रपत्र 6. ‍हाईो लेबल एोीएम ऑपरेोर 7. इंस्ट्ोेंो मनी रांसफर 2.1.6 गैर बैंिंकंग जित्त कंपजनयां 2.2 आईआरडीए/पीएफआरडीए द्वारा जिजनयजमत-जित्तीय संस्ट्थान[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 21 2.3 भारतीय िरू संचार जिजनयामक प्राजधकरण द्वारा जिजनयजमत - िरू संचार 2.4 सीसीए द्वारा जिजनयजमत-प्रमाणन प्राजधकरण, जडिीोल लॉकर प्रिाता, ई-हस्ट्तािर प्रिाता 2.5 सेबी द्वारा जिजनयजमत - केिाईसी पंिीकरण एिेंसी (केआरए), जडपोजिोरी पार्ोवजसपेंो (डीपी), एस्ट्सेो मैनिेमेंो कंपनी (एएमसी), रेलडंग एक्सचेंि, रजिस्ट्रार एंड रांसफर एिेंो 2.6 राष्ट्रीय आिास बैंक द्वारा संचाजलत श्रणे ी - 3 अन्य सस्ट्ं थाएं 3.1 3.1.1 कपंनी अजधजनयम, 1956/कपंनी अजधजनयम, 2013 के अंतगवत भारत में पंिीकृत कंपनी (समूह कंपजनयों के अंतगवत दकसी कंपनी को अलग से आिेिन करना होगा ) 3.1.2 भारतीय साझेिारी अजधजनयम, 1932 अथिा सीजमत िाजयत्ि साझेिारी अजधजनयम, 2008 के अंतगवत भारत में पंिीकृत साझेिारी 3.1.3 स्ट्िाजमत्ि िाली फमव 3.1.4 गैर लाभकारी संगठन (कपंनी अजधजनयम 1956 के धारा 25 के अधीन) 3.1.5 अकािजमक संस्ट्थान/अनुसंधान एिं जिकास सगंठन 3.1.6 इंजडयन सोसायरोि रजिस्ट्रेिन अजधजनयम, 1860 अथिा भारतीय न्यास अजधजनयम, 1882 अथिा कपंनी अजधजनयम, 2013 (खंड 8)/सहकारी सजमजत अजधजनयम, 1912 के अंतगवत पंिीकृत सोसायोी 3.1.2 उपयुवि श्रेजणयों के अलािा अन्य संस्ट्था 2. अनुरोधकताव संस्ट्था के तौर पर संस्ट्थाओं की जनयुजि के जलए तकनीकी एिं जित्तीय मापिडं जनम्नानुसार ह:ैं - श्रेणी अजधप्रमाणन प्रयोिा एिसें ी (एयएू ) ई-केिाईसी प्रयोिा एिसें ी के जलए अजतररि अपिे ाएं तकनीकी अपिे ाएं जित्तीय अपिे ाएं (केयएू ) श्रणे ी - 1 1. संस्ट्था के पास बैकएंड अिसंरचना िैसे सिवर, कोई जित्तीय अपेिाएं नहीं केयूए के जलए कोई अजतररि अपेिाएं नहीं डेोाबेस इत्यादि िैसी जििेषकर आधार अजधप्रमाणन श्रणे ी - 2 प्रयोिनाथव अपेजित, भारतीय िेत्र में स्ट्थाजपत होनी कोई जित्तीय अपेिाएं नहीं केयूए के जलए कोई चाजहए । अजतररि अपेिाएं नहीं 2. संस्ट्था के पास अपने स्ट्िाजमत्ि अथिा बाह्य स्रोतों से प्राप्त प्रजत माह 1 लाख अजधप्रमाणन कायों के जलए सिम आईोी अिसंरचना होनी चाजहए। 3. लाभाथी की गोपनीयता के संरिण के जलए संस्ट्था के पास जनधावररत डेोा गोपनीयता नीजत होनी चाजहए । 4. संगठन सूचना प्रौद्योजगकी अजधजनयम 2000 या अन् य लागू डेोा सुरिा कानूनों के अनुसार डेोा सुरिा अपेिाओं को अपनाया िाना चाजहए। श्रणे ी – 3 1. संस्ट्था के पास बैकएंड अिसंरचना िैसे सिवर, न्यनूतम 1 (एक) करोड़ की संस्ट्था प्राजधकरण द्वारा प्रित्त पूंिी समय- समय पर जनधावररत डेोाबेस इत्यादि िैसी जििेषकर आधार अजधप्रमाणन अजधप्रमाणन संव्यिहार प्रयोिनाथव अपेजित, भारतीय िेत्र में स्ट्थाजपत होनी अथिा मापिडं ों के अनुरूप होनी चाजहए । जपछले जित्त िषव के िौरान चाजहए । न्यनूतम 5 (पांच) करोड़22 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] 2. संस्ट्था के पास अपने स्ट्िाजमत्ि अथिा बाहय् स्रोतों रुपए का िार्षवक ोनवओिर से प्राप्त प्रजत माह 1 लाख अजधप्रमाणन कायों के जलए सिम आईोी अिसंरचना होनी चाजहए। 3. लाभाथी की गोपनीयता के संरिण के जलए संस्ट्था के पास जनधावररत डेोा गोपनीयता नीजत होनी चाजहए । 4. संगठन सूचना प्रौद्योजगकी अजधजनयम 2000 या अन् य लागू डेोा सुरिा कानूनों के अनुसार डेोा सुरिा अपेिाओं को अपनाया िाना चाजहए। 5. संस्ट्था को इस व्यिसाय के प्रारम्भ करने की जतजथ से न्यूनतम 1 िषव से इस व्यिसाय में होना चाजहए। अनसु चू ी- ख अजधप्रमाणन सिे ा एिजें सयों के जलए पात्रता मानिडं जिजनयम 12(2) िखे ें 1. अजधप्रमाणन सेिाओं के जलए अनुरोधकताव संस्ट्थाओं के जलए केंद्रीय पहचान डेोा ररपॉजिोरी(सीआईडीआर) ऐक्सेस करने की अपेिा रखने िाली संस्ट्थाओं को अजधप्रमाणन सेिा एिेंसी के तौर पर जनयुजि के जलए जनम्नजलजखत श्रेजणयों में िगीकृत दकया गया ह:ै - क्र.स.ं सस्ट्ं था श्रणे ी श्रणे ी - 1 केंद्र/राज्य सरकार के मंत्रालय/जिभाग तथा केंद्र/राज्य सरकार के स्ट्िाजमत्ि एिं प्रबंजधत उपक्रम श्रणे ी - 2 केंद्र/राज्य सरकार के अधीन गरठत कोई प्राजधकरण श्रणे ी - 3 प्राजधकरण द्वारा यथा जनधावररत राष्ट्रीय महत्ि की कोई संस्ट्था श्रणे ी - 4 कपंनी अजधजनयम, 1956 के अधीन भारत में पंिीकृत कोई कंपनी श्रणे ी - 5 अजधप्रमाणन प्रयोिा एिेंसी (एयएू )/ई-केिाईसी प्रयोिा एिेंसी(केयूए) 2. अजधप्रमाणन सेिा एिेंसी के तौर पर संस्ट्थाओं की जनयुजि के जलए तकनीकी एि ंजित्तीय मानिडं जनम्नानुसार ह:ै- श्रणे ी जित्तीय अपिे ाएं तकनीकी अपिे ाएं श्रेणी 1, 2 तथा 3 कोई जित्तीय अपेिाएं नहीं कोई तकनीकी अपेिाएं नहीं श्रेणी – 4 जपछले तीन जित्त िषों में िार्षवक िरू संचार सेिा प्रिाता (ोीएसपी) सजहत ोनवओिर न्यूनतम 100 करोड़ रुपए सभी एकीकृत लाइसेंसी (ऐक्सेस सेिा प्राजधकार से युि / एकीकृत लाइसेंसी (एएस)/एकीकृत ऐक्सेस सेिा लाइसेंसी/ सेल्युलर मोबाइल ोेलीफोन सेिा लाइसेंस धारक, िो पैन-इंजडया फाइबर ऑजप्ोक नेोिकव का प्रचालन कर रहे ह ैं तथा जिनके पास सभी राज्यों के जलए न्यनूतम 100 एमपीएलएस प्िाइंो ऑफ प्रेसेन्स(पीआऐस) उपलब्ध है। अथिा नेोिकव सेिा प्रिाता (एनएसपी) अथिा डेोा रांसजमिन के जलए पैन-इंजडया नेोिकव कनेजक्ोजिोी हते ु जसस्ट्ोम इंोीग्रेोर होना चाजहए तथा भारत में 100 एमपीएलएस प्िाइंो ऑफ प्रेसेन्स[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 23 (पीओपी) होनी चाजहए। श्रेणी – 5 कोई जित्तीय अपेिाएं नहीं प्राजधकरण द्वारा समय-समय पर जनधावररत अजधप्रमाणन सव्यं िहार मानिडं ों को पूरा करने िाली अजधप्रमाणन प्रयोिा एिेंसी (एयूए) अथिा ई-केिाईसी प्रयोिा एिेंसी। डॉ. सौरभ गगव, मुख्य कायवकारी अजधकारी [जिज्ञापन-III/4/असा./408/2021-22] रोप्प णी : मुख्य जिजनयमों यथा आधार (अजधप्रमाणन) जिजनयम, 2016 जिनका प्रकािन भारत के रािपत्र, असाधारण भाग-III, खंड- 4 में दिनांक 14 जसतंबर, 2016 की अजधसूचना संख्य ा 13012/64/2016/ जिजध/यूआईडीएआई (2016 की संख्य ा-3) के अंतगवत दकया गया, के अजधक्रमण में। UNIQUE IDENTIFICATION AUTHORITY OF INDIA NOTIFICATION New Delhi, the 8th November, 2021 AADHAAR (AUTHENTICATION AND OFFLINE VERIFICATION) REGULATIONS, 2021 (No. 2 of 2021) No. K-11020/240/2021/Auth/UIDAI (No. 2 of 2021).—In exercise of the powers conferred by sub-section (1), and sub-clauses (a), (ba), (ca), (cb), (f), (fa), (fb) and (w) of sub-section (2) of Section 54 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016 as amended vide the Aadhaar and Other Laws (Amendment) Act, 2019 (No.14 of 2019) and in supersession of the Aadhaar (Authentication) Regulations, 2016 except as respects things done or omitted to be done before such supersession, the Unique Identification Authority of India, hereby makes the following regulations, namely:— CHAPTER I PRELIMINARY 1. Short title and commencement.—(1) These regulations may be called the Aadhaar (Authentication and Offline Verification) Regulations, 2021. (2) These regulations shall come into force on the date of their publication in the Official Gazette. 2. Definitions.-- (1) In these regulations, unless the context otherwise requires,— (a) “Act” means the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016; (aa) “Aadhaar number” means an identification number issued to an individual under sub-section (3) of section 3 of Aadhaar Act, and includes any alternative virtual identity generated under sub-section (4) of that section; (b) “Aadhaar number holder” means an individual who has been issued an Aadhaar number under the Act; (ba) “Aadhaar Number Capture Service Token or ANCS Token” means an encrypted number generated for an Aadhaar number by the Authority for completion of an authentication transaction. ANCS Token shall be valid for a short period of time as prescribed by the Authority; (bb) “Aadhaar Paperless Offline e-KYC” means a digitally signed document generated by the Authority containing last 4 digits of Aadhaar number, demographic data like name, address, gender, and date of birth, and photograph of the Aadhaar number holder etc.; (bc) “Aadhaar Secure QR Code” means a quick response code generated by the Authority which contains digitally signed data like last 4 digits of Aadhaar number, demographic data like name, address, gender, and date of birth, and photograph of the Aadhaar number holder etc.;24 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (c) “Authentication” means the process by which the Aadhaar number along with demographic information or biometric information of an individual is submitted to the Central Identities Data Repository for its verification and such Repository verifies the correctness, or the lack thereof, on the basis of information available with it; (d) “Authentication facility” means the facility provided by the Authority for authenticating the Aadhaar number along with demographic information or biometric information of an Aadhaar number holder through the process of authentication, by providing a Yes/ No response or e-KYC data, as applicable; (e) “Authentication record” means the record of the time of authentication and identity of the requesting entity and the response provided by the Authority thereto; (f) “Authentication Service Agency” or “ASA” shall mean a licensed entity providing necessary infrastructure for ensuring secure network connectivity and related services for enabling a requesting entity to perform authentication using the authentication facility provided by the Authority; (g) “Authentication User Agency” or “AUA” means a requesting entity that uses the Yes/ No authentication facility provided by the Authority; (h) “Authority” means the Unique Identification Authority of India established under sub-section (1) of section 11 of the Act; (i) “Central Identities Data Repository” or “CIDR” means a centralised database in one or more locations containing Aadhaar numbers issued to Aadhaar number holders along with the corresponding demographic information and biometric information of such individuals and other information related thereto; (ia) “child” means a person who has not completed eighteen years of age; (j) “e-KYC authentication facility” means a type of authentication facility in which the biometric information and/or OTP and Aadhaar number securely submitted with the consent of the Aadhaar number holder through a requesting entity, is matched against the data available in the CIDR, and the Authority returns a digitally signed response containing e-KYC data along with other technical details related to the authentication transaction; (k) “e-KYC data” means full or limited demographic information and/or photograph of an Aadhaar number holder. The e-KYC data may contain full or masked Aadhaar number; (l) “e-KYC User Agency” or “KUA” shall mean a requesting entity which, in addition to being an AUA, uses e-KYC authentication facility provided by the Authority; (m) “License Key” is the key generated by a requesting entity as per the process laid down by the Authority; (ma) "Offline Verification” means the process of verifying the identity of the Aadhaar number holder without authentication, through such offline modes as may be specified by regulations; (mb) “Offline Verification Seeking Entity” or “OVSE” means any entity desirous of undertaking offline verification of an Aadhaar number holder; (mc) “Offline Aadhaar Data” means the data relating to offline Aadhaar verification, having characteristics as specified by the Authority from time to time including the requirement of masking Aadhaar numbers before storing; (n) “PID Block” means the Personal Identity Data element which includes necessary demographic and/or biometric and/or OTP collected from the Aadhaar number holder during authentication; (na) “Registered Devices” means biometric devices that are registered with the Authority; (o) “Requesting entity” means an agency or person that submits the Aadhaar number, and demographic information or biometric information, of an individual to the Central Identities Data Repository for authentication; (oa) “Sub-AUA” means a requesting entity that uses the Yes/ No authentication facility provided by the Authority through an existing AUA; (ob) “Sub-KUA” means a requesting entity that uses e-KYC authentication facility provided by the Authority through an existing KUA; (oc) “UID Token” means a 72-character alphanumeric string generated by the Authority mapped to the Aadhaar number and specific to a requesting entity;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 25 (od) “Virtual Identifier” means an interchangeable 16-digit random number mapped with the Aadhaar number of the Aadhaar number holder; and (p) “Yes/No authentication facility” means a type of authentication facility in which the identity information and Aadhaar number securely submitted with the consent of the Aadhaar number holder through a requesting entity, is then matched against the data available in the CIDR, and the Authority responds with a digitally signed response containing “Yes” or “No”, along with other technical details related to the authentication transaction, but no identity information. (2) Words and expressions used and not defined in these regulations shall have the meaning assigned thereto under the Act or under the rules or regulations made there under or under the Information Technology Act 2000. CHAPTER II AADHAAR AUTHENTICATION FRAMEWORK 3. Types of Authentication Facilities.— There shall be two types of authentication facilities provided by the Authority, namely— (i) Yes/No authentication facility, which may be carried out using any of the modes specified in regulation 4(2); and (ii) e-KYC authentication facility, which may be carried out only using OTP and/ or biometric authentication modes as specified in regulation 4(2). 3A. Types of Offline Verification.— 1. There shall be following types of Offline Verification services provided by the Authority, namely— (i) QR Code verification, (ii) Aadhaar Paperless Offline e-KYC verification, (iii) e-Aadhaar verification, (iv) Offline Paper based verification, and (v) Any other type of Offline verification introduced by the Authority from time to time. Offline Verification as above may be carried out by the entity as per the specifications given by the Authority from time to time. 2. The Authority shall provide various means to download QR Code, e-Aadhaar or Aadhaar Paperless Offline e-KYC through website, mobile application or other means. 4. Modes of Authentication — (1) An authentication request shall be entertained by the Authority only upon a request sent by a requesting entity electronically in accordance with these regulations and conforming to the specifications laid down by the Authority. (2) Authentication may be carried out through the following modes: (a) Demographic authentication: The Aadhaar number and demographic information of the Aadhaar number holder obtained from the Aadhaar number holder is matched with the demographic information of the Aadhaar number holder in the CIDR. (b) One-time pin based authentication: A One Time Pin (OTP), with limited time validity, is sent to the mobile number and/ or e-mail address of the Aadhaar number holder registered with the Authority, or generated by other appropriate means. The Aadhaar number holder shall provide this OTP along with his Aadhaar number during authentication and the same shall be matched with the OTP generated by the Authority. (c) Biometric-based authentication: The Aadhaar number and biometric information submitted by an Aadhaar number holder are matched with the biometric information of the said Aadhaar number holder stored in the CIDR. This may be fingerprints-based or iris-based authentication or other biometric modalities based on biometric information stored in the CIDR. (d) Multi-factor authentication: A combination of two or more of the above modes may be used for authentication. (3) A requesting entity may choose suitable mode(s) of authentication from the modes specified in sub-26 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] regulation (2) for a particular service or business function as per its requirement, including multiple factor authentication for enhancing security. 4A. Virtual Identity number (VID).— (1) Authority shall provide an alternate identification number mapped with Aadhaar number for the purpose of authentication. (2) Aadhaar number holder may generate or retrieve his/her VID through UIDAI website, SMS, mobile application, eAadhaar download and any other means as provided by Authority from time to time. (3) The Aadhaar number holder may use VID in lieu of Aadhaar number for online authentication or e-KYC. (4) No entity shall store Virtual ID in its system. 5. Information to the Aadhaar number holder.— (1) At the time of authentication or Offline Verification, a requesting entity or Offline Verification Seeking Entity(OVSE) respectively shall inform the Aadhaar number holder or in case of a child, inform the parent or guardian, of the following details:— (a) the nature of information that will be shared by the Authority upon authentication with the requesting entity; (b) the uses to which the information received during authentication or offline verification may be put; and (c) alternate and viable means of submission of identification and that no service to the resident will be denied for refusing to, or being unable to, undergo authentication or offline verification. (2) A requesting entity shall ensure that the information referred to in sub-regulation (1) above is provided to the Aadhaar number holder in local language as well. (3) A requesting entity or OVSE shall ensure that the no service is denied to any resident for refusing to or being unable to undergo authentication or offline verification provided that the resident is able to identify himself through a viable alternative means as suggested by the requesting entity under sub-regulation (1) (c) above. 6. Consent of the Aadhaar number holder.— (1) After communicating the information in accordance with Regulation 5, a requesting entity or Offline Verification Seeking Entity (OVSE) shall obtain the consent of the Aadhaar number holder or in case of a child, the consent of the parent or guardian of the child for the authentication or verification. (2) A requesting entity or OVSE shall obtain the consent referred to in sub-regulation (1) above in physical or preferably in electronic form and maintain logs or records of the consent obtained in the manner and form as may be specified by the Authority for this purpose. 7. Capturing of biometric information by requesting entity— (1) A requesting entity shall capture the biometric information of the Aadhaar number holder using certified biometric devices as per the processes and specifications laid down by the Authority. (1a) All biometric devices used for authentication shall be Registered Devices as per the standards specified by the Authority from time to time. (1b) All the biometric devices shall be registered with the server of the requesting entity. (2) A requesting entity shall necessarily encrypt and secure the biometric data at the time of capture as per the specifications laid down by the Authority. (3) For optimum results in capturing of biometric information, a requesting entity shall adopt the processes as may be specified by the Authority from time to time for this purpose. 8. Devices, client applications, etc. used in authentication.— (1) All devices and equipment used for authentication shall be certified as required and as per the specifications issued, by the Authority from time to time for this purpose. (2) The client applications i.e. software used by requesting entity for the purpose of authentication, shall conform to the standard APIs and specifications laid down by the Authority from time to time for this purpose.[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 27 9. Process of sending authentication requests.— (1) After collecting the Aadhaar number or any other identifier provided by the requesting entity which is mapped to Aadhaar number and necessary demographic and / or biometric information and/ or OTP from the Aadhaar number holder, the client application shall immediately package and encrypt these input parameters into PID block before any transmission, as per the specifications laid down by the Authority, and shall send it to server of the requesting entity using secure protocols as may be laid down by the Authority for this purpose. (2) After validation, the server of a requesting entity shall pass the authentication request to the CIDR, through the server of the Authentication Service Agency as per the specifications laid down by the Authority. The authentication request shall be digitally signed by the requesting entity and/or by the Authentication Service Agency, as per the mutual agreement between them. (3) Based on the mode of authentication request, the CIDR shall validate the input parameters against the data stored therein and return a digitally signed Yes or No authentication response, or a digitally signed e-KYC authentication response with encrypted e-KYC data, as the case may be, along with other technical details related to the authentication transaction. (4) In all modes of authentication, the Aadhaar number is mandatory and is submitted along with the input parameters specified in sub-regulation (1) above such that authentication is always reduced to a 1:1 match. (5) A requesting entity shall ensure that encryption of PID Block takes place at the time of capture on the authentication device as per the processes and specifications laid down by the Authority. 10. Notification/Acknowledgement of authentication or offline verification to Aadhaar number holder.— (1) The Aadhaar number holder shall be notified by the requesting entity about any authentication, through email and/or SMS and/or other digital means and/or paper based acknowledgement about success or failure of authentication on each request. Such notification/acknowledgement shall include requesting entity’s name, date and time of authentication, auth response code, last 4 digits of Aadhaar number and purpose of authentication, as the case may be. (2) The Aadhaar number holder shall be notified by the OVSE about any offline verification, through email and/or SMS and/or other digital means and/or paper based acknowledgement about success or failure of offline verification on each request. (3) In case of authentication failure the requesting entity should, in clear and precise language, inform the resident about the reasons of authentication failure such as Suspended/Cancelled Aadhaar or Biometric/Aadhaar Locking. 11. Biometric locking.— (1) The Authority may enable an Aadhaar number holder to permanently lock his biometrics and temporarily unlock it when needed for biometric authentication. (2) All biometric authentication against any such locked biometric records shall fail with a “No” answer with an appropriate response code. (3) An Aadhaar number holder shall be allowed to temporarily unlock his biometrics for authentication, and such temporary unlocking shall not continue beyond the time period specified by the Authority or till completion of the authentication transaction, whichever is earlier. (4) The Authority may make provisions for Aadhaar number holders to remove such permanent locks at any point in a secure manner. 11A. Aadhaar locking.— (1) The Authority shall enable an Aadhaar number holder to lock his/her Aadhaar number and unlock it when needed for authentication. (2) All authentication requests using Aadhaar number against any such locked Aadhaar number shall result with a “No” answer with an appropriate response code. (3) In case of a locked Aadhaar, the Authority will allow the resident to authenticate using Virtual ID or other means.28 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] CHAPTER III APPOINTMENT OF REQUESTING ENTITIES AND AUTHENTICATION SERVICE AGENCIES 12. Appointment of Requesting Entities and Authentication Service Agencies.— (1) Agencies seeking to become requesting entities to use the authentication facility provided by the Authority shall apply for appointment as requesting entities in accordance with the procedure as may be specified by the Authority for this purpose from time to time. Only those entities that fulfill the criteria laid down in Schedule A are eligible to apply. The Authority may by order, amend Schedule A from time to time so as to modify the eligibility criteria (1A) Requesting entity and ASA shall meet technical and security criteria as specified by the Authority from time to time. (2) Entities seeking appointment as Authentication Service Agencies shall apply for appointment to the Authority in accordance with the procedure as may be specified by the Authority for this purpose. Only those entities that fulfill the criteria laid down in Schedule B are eligible to apply. The Authority may by order, amend Schedule B from time to time so as to modify the eligibility criteria. (3) The Authority may require the applicant to furnish further information or clarifications, regarding matters relevant to the activity of such a requesting entity or Authentication Service Agencies, as the case may be, which may otherwise be considered necessary by the Authority, to consider and dispose of the application. (4) The applicant shall furnish such information and clarification to the satisfaction of the Authority, within the time as may be specified in this regard by the Authority. (5) While considering the application, the information furnished by the applicant and its eligibility, the Authority may verify the information through physical verification of documents, infrastructure, and technological support which the applicant is required to have. (6) After verification of the application, documents, information furnished by the applicant and its eligibility, the Authority may: a. approve the application for requesting entity or Authentication Service Agency, as the case may be; and b. enter into appropriate agreements with the entity or agency incorporating the terms and conditions for use by requesting entities of the Authority’s authentication facility, or provision of services by ASAs, including damages and disincentives for non-performance of obligations. (7) The Authority may from time to time, determine the fees and charges payable by entities during their appointment, including application fees, annual subscription fees and fees for individual authentication transactions. (8) The Authority may from time to time, determine requesting entities which may be allowed to store Aadhaar number or masked Aadhaar number. (9) The Authority may from time to time, determine the data fields to be provided as part of e-KYC response to particular requesting entities. (10) The Authority may from time to time, determine if requesting entities will be allowed to perform authentication using Aadhaar number or Virtual ID or UID Token or ANCS or any other identifier. 13. Procedure where application for appointment is not approved. — (1) In the event an application for appointment of requesting entity, Authentication Service Agency, as the case may be, does not satisfy the requirements specified by the Authority, the Authority may reject the application. (2) The decision of the Authority to reject the application shall be communicated to the applicant in writing within thirty days of such decision, stating therein the grounds on which the application has been rejected. (3) Any applicant, aggrieved by the decision of the Authority, may apply to the Authority, within a period of thirty days from the date of receipt of such intimation for reconsideration of its decision. (4) The Authority shall reconsider an application made by the applicant and communicate its decision thereon, as soon as possible in writing. 14. Roles and responsibilities of requesting entities. — (1) A requesting entity shall have the following functions and obligations:—[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 29 (a) establish and maintain necessary authentication related operations, including own systems, processes, infrastructure, technology, security, etc., which may be necessary for performing authentication; (b) establish network connectivity with the CIDR, through an ASA duly approved by the Authority, for sending authentication requests; (c) ensure that the network connectivity between authentication devices and the CIDR, used for sending authentication requests is in compliance with the standards and specifications laid down by the Authority for this purpose; (ca) ensure that the Aadhaar number/Virtual ID/ANCS Token provided by the resident for authentication request shall not be retained by the device operator or within the device or at the AUA server(s); (cb) ensure that the provision of authentication using Virtual ID is provided; (d) employ only those devices, equipment, or software, which are duly registered with or approved or certified by the Authority or agency specified by the Authority for this purpose as necessary, and are in accordance with the standards and specifications laid down by the Authority for this purpose; (e) monitor the operations of its devices and equipment, on a periodic basis, for compliance with the terms and conditions, standards, directions, and specifications, issued and communicated by the Authority, in this regard, from time to time, (f) ensure that persons employed by it for performing authentication functions, and for maintaining necessary systems, infrastructure and processes, possess requisite qualifications for undertaking such works. (g) keep the Authority informed of the ASAs with whom it has entered into agreements; (ga) obtain approval from the Authority before appointing any third party entity as Sub-AUA/Sub-KUA. (h) ensure that its operations and systems are audited by information systems auditor certified by a recognised body on an annual basis to ensure compliance with the Authority’s standards and specifications and the audit report should be shared with the Authority upon request; (i) implement exception-handling mechanisms and back-up identity authentication mechanisms to ensure seamless provision of authentication delivery of services to the residents; (j) in case of any investigation involving authentication related fraud(s) or dispute(s), it shall extend full cooperation to the Authority, or any agency appointed or authorised by it or any other authorised investigation agency, including, but not limited to, providing access to their premises, records, personnel and any other relevant resources or information as well to assist the Authority in disseminating information to the general public about any Aadhaar data related fraud to enable Aadhaar number holders to evaluate whether they were victims of the fraud and take remedial action; (k) in the event the requesting entity seeks to integrate its Aadhaar authentication system with its local authentication system, such integration shall be carried out in compliance with standards and specifications issued by the Authority from time to time; (l) shall inform the Authority of any misuse of any information or systems related to the Aadhaar framework or any compromise of Aadhaar related information or systems within their network. If the requesting entity is a victim of fraud or identifies a fraud pattern through its fraud analytics system related to Aadhaar authentication, it shall share all necessary details of the fraud with the Authority as well as to affected Aadhaar number holders without undue delay; (m) shall be responsible for the authentication operations and results, even if it sub-contracts parts of its operations to third parties. The requesting entity is also responsible for ensuring that the authentication related operations of such third party entities comply with Authority standards and specifications and that they are regularly audited by approved independent audit agencies; (ma) may agree upon the authentication charges for providing authentication services to its customer, with such customer, and the Authority shall have no say in this respect, for the time being; however, the Authority’s right to prescribe a different mechanism in this respect in the future shall be deemed to have been reserved; (mb) Aadhaar numbers collected through physical forms or photocopies of Aadhaar letters shall be masked by the requesting entity by redacting the first 8 digits of the Aadhaar number before storing the physical copies.30 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (n) shall, at all times, comply with any contractual terms and all rules, regulations, policies, manuals, procedures, specifications, standards, and directions issued by the Authority, for the purposes of using the authentication facilities provided by the Authority. (o) shall take specific permission of the Authority and sign appropriate agreement with the Authority, if requiring storage of Aadhaar number for non-authentication purposes. Aadhaar number shall be stored in a secure manner as specified by the Authority from time to time (p) extend full co-operation to the Authority for any mass awareness programmes that the Authority may undertake to sensitize Aadhaar number holders about the nature of data being used in authentication, the scope of misuse as well as steps to protect against such misuse or fraud 14A. Obligations of Offline Verification Seeking Entities.— (1) An OVSE shall have the following obligations:— (a) ensure compliance of Aadhaar Act and Regulations framed thereunder as well as relevant policies, manuals, procedures, specifications, standards, and directions issued by the Authority; (b) shall not collect, use or store Aadhaar number or biometric information of any individual for any purpose or share offline Aadhaar data with any other entity except in accordance with the Act and Regulations framed thereunder; (c) in case of any investigation involving Aadhaar data related fraud(s) or dispute(s), it shall extend full cooperation to the Authority, or any agency appointed or authorised by it or any other authorised investigation agency, including, but not limited to, providing access to their premises, records, personnel and any other relevant resources or information as well to assist the Authority in disseminating information to the general public about any Aadhaar data related fraud to enable Aadhaar number holders to evaluate whether they were victims of the fraud and take remedial action; (d) shall inform the Authority, without undue delay and in no case beyond 72 hours after having knowledge of misuse of any information or systems related to the Aadhaar framework or any compromise of Aadhaar related information. If the OVSE is a victim of fraud or identifies a fraud pattern through its fraud analytics system related to Offline Verification, it shall share all necessary details of the fraud with the Authority as well as to affected Aadhaar number holders without undue delay; (e) shall be responsible for the Offline Verification operations and results, even if it sub-contracts parts of its operations to third parties. Further, the OVSE is responsible for ensuring that the Offline Verification related operations of such third-party entities comply with the Authority standards and specifications; (f) extend full co-operation to the Authority for any mass awareness programmes that the Authority may undertake to sensitize Aadhaar number holders about the nature of data being used in offline verification, the scope of misuse as well as steps to protect against such misuse or fraud. 15. Use of Yes/ No authentication facility.— (1) A requesting entity may use Yes/ No authentication facility provided by the Authority for verifying the identity of an Aadhaar number holder for its own use or on behalf of other agencies. (2) A requesting entity may permit any other agency or entity to perform Yes/ No authentication by generating and sharing a separate license key for every such entity through the portal or any other mechanism provided by the Authority to the said requesting entity. For the avoidance of doubt, it is clarified that such sharing of license key is only permissible for performing Yes/ No authentication, and is prohibited in case of e-KYC authentication. (3) Such agency or entity: a. shall not further share the license key with any other person or entity for any purpose; and b. shall comply with all obligations relating to personal information of the Aadhaar number holder, data security and other relevant responsibilities that are applicable to requesting entities. (3A) AUAs/KUAs/Sub-AUAs/Sub-KUAs shall use their client application for Aadhaar authentication which shall be digitally signed by the requesting entity. (4) It shall be the responsibility of the requesting entity to ensure that any entity or agency with which it has shared a license key, complies with the provisions of the Act, regulations, processes, standards, guidelines,[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 31 specifications and protocols of the Authority that are applicable to the requesting entity. (5) The requesting entity shall be jointly and severally liable, along with the entity or agency with which it has shared a license key, for non-compliance with the regulations, processes, standards, guidelines and protocols of the Authority. 16. Use of e-KYC authentication facility.— (1) A KUA may use the e-KYC authentication facility provided by the Authority for obtaining the e-KYC data of the Aadhaar number holder for its own purposes. (2) A KUA shall obtain specific permission from the Authority by submitting an application for sharing of e-KYC data with Sub-KUA and such data may be shared in encrypted form as per the guidelines issued by the Authority from time to time, with specific consent of Aadhaar number holder. (3) The Sub-KUA with whom the KUA has shared the e-KYC data of the Aadhaar number holder shall not share it further with any other entity or agency. (4) The Aadhaar number holder may, at any time, revoke consent given to a KUA/Sub-KUA for storing his e-KYC data, and upon such revocation, the KUA/Sub-KUA shall delete the e-KYC data in a verifiable manner and provide an acknowledgement of the same to the Aadhaar number holder. (5) In addition to the restriction on further sharing contained in sub-regulation (3), all other obligations relating to the personal information of the Aadhaar number holder, data security and other relevant responsibilities applicable to requesting entities, shall also apply to the Sub-KUA with whom e-KYC data has been shared in accordance with this regulation 16. (6) The KUA shall maintain auditable logs of all such transactions where e-KYC data has been shared with Sub- KUAs, for a period specified by the Authority. 16A. Use of Offline Verification facility.— (1) An OVSE may use the Offline Verification facility provided by the Authority for obtaining the offline Aadhaar data of the Aadhaar number holder only for the purpose specified to the Aadhaar number holder at the time of verification. (2) No entity shall perform Offline Verification on behalf of another entity or person. (3) An OVSE may store, with consent of the Aadhaar number holder, offline Aadhaar data of the Aadhaar number holder, received upon Offline Verification, securely as per the guidelines issued by the Authority from time to time. (4) The Aadhaar number holder may, at any time, revoke consent given to an OVSE for storing his/her offline Aadhaar data, and upon such revocation, the OVSE shall delete the offline Aadhaar data in a verifiable manner and provide an acknowledgement of the same to the Aadhaar number holder. (5) The Authority in cases of default or breach or change in law or any other circumstance as may be deemed appropriate by it, may direct the OVSE to discontinue the use of Offline Verification services. 17. Obligations relating to use of identity information by requesting entity.— (1) A requesting entity shall ensure that: (a) the core biometric information collected from the Aadhaar number holder is not stored, shared or published for any purpose whatsoever, and no copy of the core biometric information is retained with it; (b) the core biometric information collected is not transmitted over a network without creation of encrypted PID block which can then be transmitted in accordance with specifications and processes laid down by the Authority. (c) the encrypted PID block is not stored, unless it is for buffered authentication where it may be held temporarily on the authentication device for a short period of time, and that the same is deleted after transmission; (d) identity information received during authentication is only used for the purpose specified to the Aadhaar number holder at the time of authentication, and shall not be disclosed further, except with the prior consent of the Aadhaar number holder to whom such information relates. (e) the identity information of the Aadhaar number holders collected during authentication and any other information generated during the authentication process is kept confidential, secure and protected against access, use and disclosure not permitted under the Act and its regulations;32 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (f) the private key used for digitally signing the authentication request and the license keys are kept secure and access controlled; and (g) all relevant laws and regulations in relation to data storage and data protection relating to the Aadhaar- based identity information in their systems, that of their agents (if applicable) and with authentication devices, are complied with. 18. Maintenance of logs by requesting entity. — (1) A requesting entity shall maintain logs of the authentication transactions processed by it, containing the following transaction details, namely:— (a) specified parameters of authentication request submitted excluding Aadhaar number, Virtual ID, ANCS Token or UID token; (b) specified parameters received as authentication response including full Aadhaar number or masked Aadhaar, as the case may be; (c) the record of disclosure of purpose for which the authentication was performed, to the Aadhaar number holder or parent or guardian, in case of a child, at the time of authentication; and (d) record of consent of the Aadhaar number holder, or parent or guardian, in case of a child, for authentication, but shall not, in any event, retain the PID information. (2) The logs of authentication transactions shall be maintained by the requesting entity for a period of 2 (two) years, during which period an Aadhaar number holder shall have the right to access such logs, in accordance with the procedure as may be specified. (3) Upon expiry of the period specified in sub-regulation (2), the logs shall be archived for a period of five years or the number of years as required by the laws or regulations governing the entity, whichever is later, and upon expiry of the said period, the logs shall be deleted except those records required to be retained upon the order of a court not inferior to that of a Judge of a High Court or required to be retained for any pending disputes. (4) The requesting entity shall not share the authentication logs with any person other than the concerned Aadhaar number holder upon his/her request or for grievance redressal and resolution of disputes or upon the order of a court not inferior to that of a Judge of a High Court. The authentication logs shall not be used for any purpose other than those stated in this sub-regulation. (5) The requesting entity shall comply with all relevant laws, rules and regulations, including, but not limited to, the Information Technology Act, 2000 and the Evidence Act, 1872, for the storage of logs. (6) The obligations relating to authentication logs as specified in these regulations shall continue to remain in force despite termination of appointment in accordance with these regulations. 19. Roles, responsibilities and code of conduct of Authentication Service Agencies.— An Authentication Service Agency shall have the following functions and obligations:— (a) provide secured connectivity to the CIDR to transmit authentication request from a requesting entity in the manner as may specified by the Authority for this purpose; (b) perform basic compliance and completeness checks on the authentication data packet before forwarding it to CIDR; (c) on receiving the response from CIDR, transmit the result of the transaction to the requesting entity that has placed the request; (d) only engage with the requesting entities approved by the Authority and keep the Authority informed of the list of requesting entities that it serves; (e) communicate to the Authority, all relevant information pertaining to any agreement that it may enter into with a requesting entity; (f) ensure that the persons employed by it for performing authentication and for maintaining necessary systems, infrastructure, processes, etc., possess requisite qualifications for undertaking such works; (g) ensure that its operations are audited by an information systems auditor certified by a recognized body on an annual basis, and provide a certified audit report, to the Authority, confirming its compliance with the policies, processes, procedures, standards, or specifications, issued by the Authority in this regard, from time to time;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 33 (h) ensure that all infrastructure and operations including systems, processes, devices, software and biometric infrastructure, security, and other related aspects, are in compliance with the standards and specifications as may specified by the Authority for this purpose; (i) at all times, comply with directions, specifications, etc. issued by the Authority, in terms of network and other Information Technology infrastructure, processes, procedures, etc. (j) comply with all relevant laws and regulations relating, in particular, to data security and data management; (k) any value added service that an ASA provides to a requesting entity under a contract shall not form part of the Aadhaar authentication process; (l) shall be responsible to the Authority for all its authentication related operations, even in the event the ASA sub-contracts parts of its operations to other entities, the responsibility shall remain with the ASA; (m) in case of investigations relating to authentication related fraud or dispute, the ASA shall extend full co- operation to the Authority (or their agency) and/or any other authorized investigation agency, including providing access to its premises, records, systems, personnel, infrastructure, any other relevant resource or information and any other relevant aspect of its authentication operations; (n) may agree upon the authentication charges for providing services to a requesting entity, with such requesting entity, and the Authority shall have no say in this respect, for the time being; however, the Authority’s right to prescribe a different mechanism in this respect in the future shall be deemed to have been reserved; (o) shall, at all times, comply with any contractual terms and all rules, regulations, policies, manuals, procedures, specifications, standards, and directions issued by the Authority. 20. Maintenance of logs by Authentication Service Agencies.— (1) An Authentication Service Agency shall maintain logs of the authentication transactions processed by it, containing the following transaction details, namely:— (a) identity of the requesting entity; (b) parameters of authentication request submitted; and (c) parameters received as authentication response: Provided that Aadhaar number, Virtual Id, UID Token, ANCS Token, PID information, device identity related data and e-KYC response data, where applicable shall not be retained. (2) Authentication logs shall be maintained by the ASA for a period of 2 (two) years, during which period the Authority and/or the requesting entity may require access to such records for grievance redressal, dispute redressal and audit in accordance with the procedure specified in these regulations. The authentication logs shall not be used for any purpose other than stated in this sub-regulation. (3) Upon expiry of the period specified in sub-regulation (2), the authentication logs shall be archived for a period of five years, and upon expiry of the said period of five years or the number of years as required by the laws or regulations governing the entity whichever is later, the authentication logs shall be deleted except those logs required to be retained by a court not inferior to that of a Judge of a High Court or which are required to be retained for any pending disputes. (4) The ASA shall comply with all applicable laws in respect of storage and maintenance of these logs, including the Information Technology Act, 2000. (5) The obligations relating to authentication logs as specified in this regulation shall continue to remain in force despite termination of appointment in accordance with these regulations. 20A. Optional Maintenance of Logs by Offline Verification Seeking Entity (1) An Offline Verification Seeking Entity may maintain logs of the verification transactions processed by it, if deemed necessary by the OVSE and with consent of the resident, containing any of the following transaction details, namely:— (a) the offline Aadhaar data document shared by the resident in a suitably secure manner ; (b) any other data shared by the resident during the course of verification including mobile number, email id, photo etc;34 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (c) local verification transaction logs between OVSE and the resident; (d) details of the notification related to the Offline Verification sent to the Aadhaar number holder. but shall not, in any event, store the Aadhaar number or Virtual ID of the Aadhaar number holder. (2) The OVSE shall not share the logs with any person other than the concerned Aadhaar number holder or for grievance redressal and resolution of disputes in accordance with the provisions of the Act. The verification logs shall not be used for any purposes other than those stated in this sub-regulation. 21. Audit of requesting entities, Authentication Service Agencies and Offline Verification Seeking Entities.— (1) The Authority may undertake audit of the operations, infrastructure, systems and procedures, of requesting entities, including their Sub-AUAs and Sub-KUAs, Authentication Service Agencies and Offline Verification Seeking Entities, either by itself or through audit agencies appointed by it, to ensure that such entities are acting in compliance with the Act, rules, regulations, policies, procedures, guidelines issued by the Authority. (2) The Authority may conduct audits of the operations and systems of the entities referred to in sub-regulation (1), either by itself or through an auditor appointed by the Authority. The frequency, time and manner of such audits shall be as may be notified by the Authority from time to time. (3) An entity subject to audit shall provide full co-operation to the Authority or any agency approved and/or appointed by the Authority in the audit process, and provide to the Authority or any agency approved and/or appointed by the Authority, complete access to its procedures, records and information pertaining to services availed from the Authority. The cost of audits shall be borne by the concerned entity. (4) On identification of any deficiency by the Authority, the Authority may require the concerned entity to furnish necessary clarifications and/or information as to its activities and may also require such entity either to rectify the deficiencies or take action as specified in these regulations. (5) Notwithstanding anything contained in clause (4), and without prejudice to any action which may be taken under the Act, the Authority may initiate action under Regulation 25(1A) on identification of any deficiency pursuant to the audit conducted. 22. Data Security.— (1) Requesting entities and Authentication Service Agencies/OVSEs shall have their servers used for Aadhaar authentication request formation and routing to CIDR/Offline Verification respectively, to be located within data centres or cloud storage centres located in India. (1A) Authentication requests shall not be accepted from entities located outside the territorial borders of India. For allowing authentication requests from outside India, the requesting entity shall take specific permission from the Authority. (2) Authentication Service Agency shall establish dual redundant, secured leased lines or MPLS connectivity with the data centres of the Authority, in accordance with the procedure and security processes as may be specified by the Authority for this purpose. (3) Requesting entities shall use appropriate license keys to access the authentication facility provided by the Authority only through an ASA over secure network, as may be specified by the Authority for this purpose. (4) Requesting Entities, Authentication Service Agencies and Offline Verification Seeking Entities shall adhere to all regulations, information security policies, processes, standards, specifications and guidelines issued by the Authority from time to time. 23. Surrender of the access to authentication facility by requesting entity or Authentication Service Agency. — (1) A Requesting Entity or ASA, appointed under these regulations, desirous of surrendering the access to the authentication facility granted by Authority, may make a request for such surrender to the Authority. (2) While disposing such surrender request under these regulations, the Authority may require the requesting entity or ASA to satisfy the Authority about any matter necessary for smooth discontinuance or termination of services, including– (a) the arrangements made by the requesting entity for maintenance and preservation of authentication logs and other documents in accordance with these regulations and procedures as may be specified by the Authority for this purpose;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 35 (b) the arrangements made by the requesting entity for making authentication record available to the respective Aadhaar number holder on such request; (c) records of redressal of grievances, if any; (d) settlement of accounts with the Authority, if any; (e) in case of surrender by ASAs, the ASA, prior to the surrender of its access, shall ensure that its associated requesting entities are given adequate time to migrate to other ASAs in operation. 24. Agencies appointed before commencement of these regulations. — (1) Any Authentication User Agency (AUA) or e-KYC User Agency (KUA), appointed prior to the commencement of these regulations shall be deemed to be a requesting entity, and any Authentication Service Agency (ASA) or e-KYC Service Agency (KSA) shall be deemed to be an Authentication Service Agency, under these regulations, and all the agreements entered into between such agencies and the Unique Identification Authority of India, established vide notification of the Government of India in the Planning Commission number A-43011/02/2009-Admin. I, dated the 28th January, 2009 or any officer of such authority shall continue to be in force to the extent not inconsistent with the provisions of the Act, these regulations, and other regulations, policies, processes, procedures, standards and specifications issued by the Authority. (2) Notwithstanding anything contained in sub-regulation (1), any deemed requesting entity or Authentication Service Agency referred to in sub-regulation (1) shall be required to comply with the provisions of the Act, these regulations, other regulations framed by the Authority, and the policies, processes, procedures, standards and specifications issued by the Authority. (3) In the event any such agency referred to in sub-regulation(1) seeks to discontinue using the authentication facility as specified in these regulations, it may immediately make an application for termination of its credentials and stop its functions forthwith: Provided that in such cases, no compensation shall be payable to the agency or to the Authority upon such termination. (4) On discontinuance under sub-regulation (3), the concerned entity shall be required to comply with the closure requirements listed in regulation 23(2). 25. Liability and action in case of default. — (1) Where any requesting entity or an ASA appointed under the Act, (a) fails to comply with any of the processes, procedures, standards, specifications or directions issued by the Authority, from time to time; (b) is in breach of its obligations under the Act and these regulations; (c) uses the Aadhaar authentication facilities for any purpose other than those specified in the application for appointment as requesting entity or ASA, (d) fails to furnish any information required by the Authority for the purpose of these regulations; or (e) fails to cooperate in any inspection or investigation or enquiry or audit conducted by the Authority, the Authority may, without prejudice to any other action which may be taken under the Act, take such steps to impose disincentives on the requesting entity or an ASA for contravention of the provisions of the Act, rules and regulations thereunder, including suspension of activities of such entity or agency, or other steps as may be more specifically provided for in the agreement entered into by such entities with the Authority: Provided that the entity or agency shall be given the opportunity of being heard before the termination of appointment and discontinuance of its operations relating to Aadhaar authentication. (1A).Where any Offline Verification seeking entity, (a) fails to comply with any of the processes, procedures, standards, specifications or directions issued by the Authority, from time to time; is in breach of its obligations under the Act and these regulations; (b) uses the Aadhaar Offline Verification facilities for purposes other than those specified; (c) fails to furnish any information required by the Authority for the purpose of these regulations; or (d) fails to cooperate in any inspection or investigation or enquiry or audit conducted by the Authority,36 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] the Authority may, without prejudice to any other action which may be taken under the Act, including such criminal action as it may deem fit, take such steps to impose disincentives on the Offline Verification seeking entity for contravention of the provisions of the Act, rules and regulations thereunder. Provided that the entity or agency shall be given the opportunity of being heard before any action is taken. (2) Any such action referred to in sub-regulation (1) may also be taken against any entity or Sub-AUA or sub- KUA. (3) Upon termination of appointment by the Authority, the requesting entity or the ASA shall, forthwith, cease to use the Aadhaar name and logo for any purposes, and in any form, whatsoever, and may be required to satisfy the Authority of necessary aspects of closure, including those enumerated in regulation 23(2). CHAPTER IV AUTHENTICATION TRANSACTION DATA AND AUTHENTICATION RECORDS 26. Storage and Maintenance of Authentication Transaction Data. — (1) The Authority shall store and maintain authentication transaction data, which shall contain the following information:— (a) authentication request data received including PID block; (b) authentication response data sent (c) any authentication server side configurations as necessary Provided that the Authority shall not, in any case, store the purpose of authentication or any meta data (other than process meta data) about any transaction. 27. Duration of storage. — (1) Authentication transaction data shall be retained by the Authority for a period of 6 months. The Authority may prescribe procedure to archive and perform analysis, for research purposes, from aggregated and anonymised authentication transaction data in the form of circulars. (2) Upon expiry of the period of six months specified in sub-regulation (1), the authentication transaction data shall be deleted except when such authentication transaction data are required to be maintained by the order of a court not inferior to that of a Judge of a High Court or in connection with any pending dispute. 28. Access by Aadhaar number holder. — (1) An Aadhaar number holder shall have the right to access his authentication records subject to conditions laid down and payment of such fees as prescribed by the Authority by making requests to the Authority within the period of retention of such records before they are archived. (2) The Authority may provide mechanisms such as online portal or mobile application or designated contact centers for Aadhaar number holders to obtain their digitally signed authentication records within the period of retention of such records before they are archived as specified in these regulations. (3) The Authority may provide digitally signed e-KYC data to the Aadhaar number holder through biometric or OTP authentication, subject to payment of such fees and processes as specified by the Authority, (4) The authentication records and e-KYC data shall not be shared with any person or entity: (a) other than with the Aadhaar number holder to whom the records or e-KYC data relate in accordance with the verification procedure specified. Aadhaar number holder may share their digitally signed authentication records and e-KYC data with other entities which shall not further share with any other agencies without obtaining consent of the Aadhaar holder every time before such sharing. (b) Except in accordance with the provisions of the Act. CHAPTER V MISCELLANEOUS 29. Repeal and savings.— (1) All procedures, orders, processes, standards, specifications and policies issued and MOUs, agreements or contracts entered by the Unique Identity Authority of India, established vide notification of the Government of[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 37 India in the Planning Commission number A-43011/02/2009-Admin. I, dated the 28th January, 2009 or any officer of such authority, prior to the establishment of the Authority under the Act shall continue to be in force to the extent that they are not inconsistent with the provisions of the Act and regulations framed thereunder. (2) Notwithstanding the repeal of the Aadhaar (Authentication) Regulations, 2016, anything done or any action taken under the said Regulations shall be deemed to have been done or taken under the corresponding provisions of these Regulations. 30. Power to issue clarifications, guidelines and removal of difficulties. — In order to remove any difficulties or clarify any matter pertaining to application or interpretation of these regulations, the Authority may issue clarifications and guidelines in the form of circulars. 31. Power to issue policies, process documents, etc.- The Authority may issue policies, orders, processes, standards, specifications and other documents not inconsistent with these regulations, which are required to be specified under these regulations or for which provision is necessary for the purpose of giving effect to these regulations. Schedule A Eligibility criteria for appointment as requesting entities See Regulation 12 (1) 1. Entities seeking to use authentication facility provided by the Authority as requesting entities are classified under following categories for appointment as Authentication User Agency (AUA) and/or e-KYC User Agency (KUA), as the case may be: S.No. Organisation Category Category 1 Government Organisation 1.1 A Central/ State Government Ministry/Department and their attached or sub-ordinate offices. 1.2 An undertaking owned and managed by Central / State Government (PSU) 1.3 An Authority constituted under the Central / State Act/Special Purpose Organisation constituted by Central/State govt. Category 2 Regulated Service Providers 2.1 Regulated / Licensed by RBI – Banks and Payment & Settlement System 2.1.1 Public Sector Banks (PSB) 2.1.2 Private Banks, Foreign Banks Licensed by RBI to operate in India, Payment Banks, Small Finance Banks 2.1.3 Regional Rural Banks 2.1.4 Co-operative Banks 1. State Co-operative Banks 2. District Co-operative Banks 3. Scheduled Urban Cop-operatives Banks 4. Non Scheduled Urban Co-operative Banks 2.1.5 Payment& Settlement System Network 1. Financial market infrastructure 2. Retails payments Organisation 3. Cards payment network 4. ATM networks 5. Pre-paid payment instruments38 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] S.No. Organisation Category 6. White label ATM operators 7. Instant Money Transfer 2.1.6 Non-Banking Financial Company 2.2 Regulated by IRDA/PFRDA - Financial Institutions 2.3 Regulated by TRAI – Telecom 2.4 Regulated by CCA – Certifying Authority, Digital Locker providers, e-Sign providers 2.5 Regulated by SEBI – KYC Registration Agency (KRA),Depository Participant (DP), Asset Management Company (AMC), Trading Exchanges, Registrar and Transfer Agents 2.6 Regulated by National Housing Bank Category 3 Other Entities 3.1 3.1.1 Company registered in India under the Companies Act 1956 / The companies Act 2013 (Company under group of companies has to apply individually) 3.1.2 Partnership registered under the India Partnership Act 1932 or under the Limited Liability Partnership Act, 2008 3.1.3 Proprietorship firm 3.1.4 Not-for-profit Organisations (under section 25 under The Companies Act 1956) 3.1.5 Academic Institutions / Research and Development Organisations 3.1.6 Societies registered under Indian Societies Registration Act, 1860 or The Indian Trust Act, 1882 or The Companies Act, 2013 (Sec 8) / The Co-operative Societies Act 1912 3.1.7 Any entity other than above mentioned categories 2. Technical and Financial criteria for entities for appointment as requesting entity are as under:- Authentication User Agency (AUA) Additional requirements for Category eKYC User Agency (KUA) Technical Requirements Financial Requirements Category 1 1. Backend infrastructure, No financial requirement No additional requirement for such as servers, databases KUA etc. of the entity, required Category 2 No financial requirement No additional requirement for specifically for the KUA purpose of Aadhaar authentication, should be located within the territory of India. 2. Entity should have IT Infrastructure owned or outsourced capable of carrying out minimum 1 Lakh Authentication transactions per month. 3. Organisation should have a prescribed Data Privacy policy to protect beneficiary privacy. 4. Organisation should have adopted data security requirements as per the IT Act 2000 or other[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 39 applicable Data Protection laws. Category 3 1. Backend infrastructure, 1. Paid up capital of such as servers, databases minimum ₹ 1 (one) etc. of the entity, required Crore. specifically for the OR purpose of Aadhaar authentication, should be located within the territory Entity should meet Annual turnover of of India. Authentication Transaction minimum ₹5 (Five) Crore Criteria as laid down by the 2. Entity should have IT during the last Financial Authority from time to time. Infrastructure owned or year. outsourced capable of carrying out minimum 1 Lakh Authentication transaction per month. 3. Organisation should have a prescribed Data Privacy policy to protect beneficiary privacy. 4. Organisation should have adopted Data security requirements as per the IT Act 2000 or other applicable Data Protection laws. 5. Entity should be in business for minimum of 1 year from date of commencement of Business. Schedule B Eligibility criteria of Authentication Service Agencies See Regulation 12(2) 1. Entities seeking to provide secure access to CIDR to requesting entities for enabling authentication services are classified under following categories for appointment as Authentication Service Agency: S. No Organisation Category Category 1 A Central/ State Government Ministry / Department or an undertaking owned and managed by Central / State Government Category 2 An Authority constituted under the Central / State Act Category 3 Any other entity of national importance as determined by the Authority Category 4 A company registered in India under the Indian Companies Act 1956 Category 5 AUA / KUA40 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] 2. Technical and Financial criteria for entities for appointment as Authentication Service Agency are as under:- Category Financial Requirement Technical Requirement Category 1, 2 No financial requirements No technical requirements and 3 Category 4 An annual turnover of at least A Telecom Service Provider (TSP) including All Unified ₹100 crores in last three Licensees (having Access Service Authorization) / Unified financial years Licensees (AS) / Unified Access Services Licensees / Cellular Mobile Telephone Service Licensees operating pan-India fiber optics network and should have a minimum of 100 MPLS Points of Presence (PoP) across all states OR Should be a Network Service Provider (NSP) or System Integrator having pan-India network connectivity for data transmission and should have 100 MPLS PoPs in India, Category 5 No Financial requirements Any AUA or KUA meeting authentication transaction criteria as laid down by the Authority from time to time Dr. SAURABH GARG, Chief Executive Officer [ADVT.-III/4/Exty./408/2021-22] Note: In supersession of the Principal regulations i.e. the Aadhaar (Authentication) Regulations, 2016, which were published in the Gazette of India, Extraordinary, Part III, Section 4 vide Notification No. 13012/64/2016/Legal/UIDAI (No. 3 of 2016) dated 14th September 2016. Uploaded by Dte. of Printing at Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054.

Continue your research