**Executive Summary**
This report outlines the scale, security architecture, and regulatory framework of the Aadhaar biometric identity system as submitted to the Lok Sabha on March 18, 2026. It details the authentication services provided by the Unique Identification Authority of India (UIDAI), the mandatory three-tier audit framework for partner agencies, and strict data retention protocols. The document emphasizes that all Aadhaar data storage and processing is localized within India to ensure privacy and security.
**Key Points / Main Content**
**Authentication Services and Technology**
* **Scale of Operations:** Aadhaar is the world's largest biometric system, with approximately 134 crore live holders and over 17,000 crore authentication transactions completed.
* **Verification Methods:** UIDAI offers authentication via OTP, biometrics (fingerprint, iris, face), or demographic details to authorized entities.
* **AI Integration:** Face authentication utilizes AI and Machine Learning technology to ensure accurate biometric verification.
* **Onboarding Requirements:** Any entity seeking to use these services must be formally onboarded as an Authentication User Agency (AUA) or KYC User Agency (KUA) under the Aadhaar Act.
**Data Protection and Privacy Measures**
* **Encryption:** Demographic data is encrypted both at rest and during transit.
* **Data Residency:** All Aadhaar data is stored and processed exclusively within India.
* **Prohibited Practices:** No entity is permitted to retain biometric data; authentication responses are secure and limited in scope.
* **Aadhaar Data Vault:** Entities are required to use secure storage via the Aadhaar Data Vault for data management.
**Governance and Audit Framework**
* **Three-Tier Audit:** Entities must undergo a multi-layered audit process consisting of a Self-Compliance Audit, an Information Security Annual Audit, and a Governance, Risk, Compliance, and Privacy (GRCP) Audit.
* **Standard Operating Procedures (SOPs):** Key provisions include mandatory informed consent from holders, use of certified devices only, and purpose-specific authentication.
* **Audit Trails:** Maintaining mandatory audit trails is required to ensure the integrity and effectiveness of the ecosystem.
**Log Retention and Access**
* **Retention Period:** AUAs and KUAs must retain authentication logs for two years.
* **Archiving:** Following the initial two years, logs are archived for five years and subsequently deleted.
* **Access Rights:** Aadhaar holders can access these logs, and they may be shared for grievance redressal or dispute resolution.
**Impact Analysis**
**Aadhaar Number Holders**
**Impact**
Holders benefit from a secure identity verification system designed to protect privacy through encryption and localized data storage. They have the right to provide informed consent and access their authentication logs for grievance redressal.
**Action Required**
Holders must provide informed consent before any authentication transaction is processed by an authorized entity.
**Authentication User Agencies (AUA) and KYC User Agencies (KUA)**
**Impact**
These entities are subject to strict legal and technical constraints under the Aadhaar Act, including limitations on data retention and the mandatory use of certified hardware.
**Action Required**
Entities must onboard with UIDAI, implement the Aadhaar Data Vault, maintain logs for the specified 2+5 year period, and comply with the three-tier audit framework.
**Unique Identification Authority of India (UIDAI)**
**Impact**
As the maintaining authority, UIDAI is responsible for the integrity of the database and the oversight of the authorized entities within the ecosystem.
**Action Required**
UIDAI must manage the authentication infrastructure, oversee the onboarding of agencies, and ensure that the three-tier audit framework is strictly followed to mitigate risks.
Key Entities Referenced
Unique Identification Authority of India (UIDAI): The primary regulatory body responsible for maintaining the Aadhaar biometric identity system and providing authentication services.
Aadhaar Act: The legislative framework that governs the collection, retention, use, and security of Aadhaar data and mandates specific compliance for authorized entities.
Authentication User Agencies (AUA) and KYC User Agency (KUA): Authorized entities onboarded with UIDAI to perform identity verification, subject to mandatory audit frameworks and log retention requirements.
Ministry of Electronics & IT: The primary central ministry overseeing the implementation, security, and policy updates related to the Aadhaar ecosystem.
Ministry of Electronics & IT
Aadhaar is the world's largest biometric identity
system with approximately 134 crore live
Aadhaar holders
The Aadhaar ecosystem is designed to protect privacy, with
demographic data remaining encrypted both at rest and in
transit
Storage and processing of Aadhaar data takes place within
India
Posted On: 18 MAR 2026 4:03PM by PIB Delhi
Aadhaar is the world's largest biometric identity system maintained by Unique Identification Authority of
India (UIDAI) with approximately 134 crore live Aadhaar holders. It has completed more than 17,000
crore authentication transactions.
Aadhaar authentication service of UIDAI:
UIDAI provides Aadhaar authentication service to authorized entities using which an individual’s Aadhaar
number and related identity information are verified with the Aadhaar database. This verification confirms
the individual’s identity using OTP, biometric (fingerprint, iris, face) or demographic details to deliver the
services offered by such entity.
Aadhaar Face Authentication used by authorised entities is based on AI/Machine Learning technology
which enables accurate authentication of face biometric.
Any entity desiring to use Aadhaar authentication services must be onboarded with UIDAI as
Authentication User Agencies (AUA) or KYC User Agency (KUA), in accordance with the provisions of
the Aadhaar Act.
Access to authentication logs:
Every AUA or KUA must retain authentication logs for two years. These logs can be accessed by Aadhaar
number holder or can be shared for grievance redressal and dispute resolution. After two years, the logs are
archived for five years and subsequently deleted.Protection of Aadhaar data:
The Aadhaar ecosystem is designed to protect privacy, with demographic data remaining encrypted both at
rest and in transit. The Aadhaar Act also imposes restrictions on the collection, retention, access, and use of
Aadhaar data.
UIDAI has implemented a three-tier audit framework, comprising the Self-Compliance Audit, the
Information Security Annual Audit, and the GRCP (Governance, Risk, Compliance, and Privacy) Audit,
for entities in the Aadhaar Authentication Ecosystem.
This multi-layered approach ensures the integrity, security, and effectiveness of the ecosystem and helps
mitigate risks to Aadhaar number holders.
The detailed Standard Operating Procedures (SOPs) and guidelines governing the collection, retention,
access, and use of Aadhaar data are available in public domain. Key provisions include:
● Mandatory informed consent of Aadhaar Number holder
● Purpose-Agnostic authentication
● Aadhaar authentication only for predefined and explicitly permitted purposes
● Secure and limited authentication response
● Secure storage in Aadhaar Data Vault
● Use of certified devices only
● Limited and encrypted data retention
● No biometric data retention by any entity
● Mandatory audit trails
By design and architecture, the storage and processing of Aadhaar data takes place within India, and
safeguards are in place to ensure that this is not breached.
This information was submitted by Union Minister of State for Electronics and Information Technology
Shri Jitin Prasada in Lok Sabha on 18.03.2026.
****
MSZ
(Release ID: 2241778) Visitor Counter : 185
Read this release in: Urdu , ही