## Report on UIDAI Circular No. 1503542021AUHQ: Aadhaar Usage Dos and Don'ts for Offline Verification Seeking Entities (OVSEs)
**1. Executive Summary:**
This report analyzes UIDAI Circular No. 1503542021AUHQ, dated October 31st, 2022, concerning the appropriate usage of Aadhaar for offline verification by Offline Verification Seeking Entities (OVSEs). This is a *new* policy guidance, establishing rules for how OVSEs handle Aadhaar data during offline verification. The core purpose of this circular is to ensure the security, confidentiality, and lawful use of Aadhaar data during offline verification processes, and to prevent misuse while providing alternative identification means. Key findings emphasize the mandatory verification of digital signatures, obtaining explicit consent, and restrictions on data storage post-verification.
**2. Introduction:**
This report aims to provide a comprehensive overview of UIDAI Circular No. 1503542021AUHQ, focusing on the guidelines for Offline Verification Seeking Entities (OVSEs) regarding Aadhaar usage for offline verification purposes. The analysis is based solely on the information provided within the circular text.
**3. Policy Overview:**
* Core Objective(s) as stated or inferred from the provided text:
* To regulate the use of Aadhaar for offline verification by OVSEs.
* To ensure the security and confidentiality of Aadhaar data during offline verification.
* To ensure lawful use of Aadhaar with explicit consent from the Aadhaar holder.
* To prevent denial of services based solely on the inability to undergo Aadhaar verification.
**4. Background and Rationale:**
As a new policy, this circular likely addresses the need for clear guidelines and standardization in the offline verification of Aadhaar. The rapid adoption of Aadhaar for various services necessitates a framework to prevent misuse, unauthorized storage, and ensure adherence to the Aadhaar Act and related regulations. This policy intends to reduce security vulnerabilities that might arise from insecure offline verification processes, such as data breaches or identity theft.
**5. Key Provisions / Changes:**
This circular establishes the following requirements for OVSEs:
* **Verification Mandate:** OVSEs *must* carry out offline verification of Aadhaar via Secure QR Code or Paperless Offline eKYC XML before accepting it as proof of identity. They must validate the UIDAI's digital signature.
* **Consent Requirement:** Explicit consent (physical or electronic) *must* be obtained from the Aadhaar holder for offline verification, and logs/records of consent *must* be maintained.
* **Alternative Identification:** OVSEs *must* provide alternative means of identification in addition to Aadhaar.
* **Data Security:** Aadhaar data collected *cannot* be shared with any entity except in accordance with the Aadhaar Act.
* **Service Denial Prohibition:** Service *cannot* be denied if a resident refuses or is unable to undergo Aadhaar verification, provided they can identify themselves through alternative means.
* **Cooperation with Authorities:** OVSEs *must* fully cooperate with the UIDAI or authorized agencies in fraud investigations.
* **Reporting Misuse:** OVSEs *must* inform the UIDAI and the Aadhaar holder of any misuse or compromise of Aadhaar-related information within 72 hours.
* **Compliance:** OVSEs *must* strictly comply with the Aadhaar Act and any directions from UIDAI.
* **Data Handling Restrictions:** OVSEs cannot collect, use, or store Aadhaar number or biometric information after offline verification. If storing a copy of Aadhaar is necessary, the Aadhaar number *must* be redacted (masked and irretrievable).
* **Prohibitions:** OVSEs *cannot* accept Aadhaar without verifying the digital signature, perform verification without explicit consent, or perform offline verification on behalf of another entity.
**6. Target Audience and Stakeholders:**
The primary target audience and stakeholders are Offline Verification Seeking Entities (OVSEs). These include businesses, organizations, and government agencies that utilize Aadhaar for identity verification and KYC processes in an offline setting. The Aadhaar number holders are indirectly affected as the policy aims to protect their data and ensure they are not denied services solely based on Aadhaar verification.
**7. Implementation Aspects (Inferred):**
* **Responsible agency/bodies mentioned:** The Unique Identification Authority of India (UIDAI) is the responsible body.
* **Timelines or procedures specified:** The circular specifies a 72-hour timeframe for reporting any misuse or compromise of Aadhaar-related information. The procedure for offline verification involves using the Aadhaar Secure QR code scanner application or the mAadhaar application, both freely available. The scanner application validates UIDAIs digital signature.
**8. Expected Outcomes / Impact of Changes:**
The intended outcomes of this policy are likely to be:
* Increased security and confidentiality of Aadhaar data used for offline verification.
* Reduced instances of Aadhaar misuse by OVSEs.
* Greater awareness among OVSEs regarding their responsibilities under the Aadhaar Act and related regulations.
* Enhanced protection of Aadhaar holders' rights, ensuring they are not denied services if unable to undergo Aadhaar verification.
* Improved compliance with the Aadhaar Act and related guidelines.
**9. Conclusion:**
UIDAI Circular No. 1503542021AUHQ provides essential guidelines for Offline Verification Seeking Entities (OVSEs) regarding the appropriate and secure use of Aadhaar for offline verification. The policy emphasizes verification protocols, consent requirements, and data protection measures. By adhering to these guidelines, OVSEs can contribute to a more secure and trustworthy Aadhaar ecosystem, protecting the privacy and rights of Aadhaar holders. The circular's significance lies in its attempt to formalize and standardize offline Aadhaar verification processes, thereby mitigating potential risks associated with data security and misuse.
Key Entities Referenced
Unique Identification Authority of India: The issuing authority of Aadhaar, also referred to as UIDAI.
Aadhaar: A 12-digit individual identification number issued by the Unique Identification Authority of India.
UIDAI HQs, Bangla Sahib Road, Behind Kali Mandir, Gole Market, New Delhi. 110001: The address of the UIDAI headquarters.
31stOctober, 2022: The date of the circular.
CIRCULAR Subject: Usage of Aadhaar Dos Donts for Offline Verification Seeking Entities OVSEs: The subject of the notification.
Offline Verification Seeking Entities: Organizations conducting offline verification of Aadhaar number holders for lawful purposes, abbreviated as OVSEs.
Offline verification: The use of Aadhaar for identity verification and KYC processes locally, without connecting to the Central Identities Data Repository (CIDR) of UIDAI.
Central Identities Data Repository: The central database of UIDAI, abbreviated as CIDR.
Section 2 Definitions, Aadhaar Authentication and Offline Verification Regulations: Reference to a section in the Aadhaar regulations providing definitions.
Secure QR Code: A mode of offline verification displayed on Aadhaar letter, eAadhaar, Aadhaar PVC card and mAadhaar.
Aadhaar letter: A physical form of Aadhaar document.
eAadhaar: An electronic form of Aadhaar.
Aadhaar PVC card: A physical plastic card form of Aadhaar.
mAadhaar: A mobile application form of Aadhaar.
Aadhaar Paperless Offline eKYC XML: A mode of offline verification downloaded from the UIDAI website and mAadhaar.
Aadhaar Secure QR code scanner application: Application to scan and validate the secure QR code.
Android: Mobile operating system supported by the Aadhaar Secure QR code scanner application.
iOS: Mobile operating system supported by the Aadhaar Secure QR code scanner application.
Windows: Operating system supported by the Aadhaar Secure QR code scanner application.
Aadhaar Act: The legal framework governing the use of Aadhaar.
Kuldeep Singh: Asstt. Director AU. The signatory of the circular.
No-15035/4/2021/AU-HQ
Unique Identification Authority of India
(Aadhaar Usage Division)
UIDAI HQs,
Bangla Sahib Road, Behind Kali Mandir,
Gole Market, New Delhi. 110001
Dated: 31stOctober, 2022
CIRCULAR
Subject: Usage of Aadhaar- Do’s & Don’ts for Offline Verification Seeking Entities (OVSEs).
Offline verification is the use of Aadhaar for carrying out identity verification and KYC
processes locally, without connecting to the Central Identities Data Repository (CIDR) of UIDAI.
The organizations conducting offline verification of an Aadhaar number holder for a lawful purpose
are termed as Offline Verification Seeking Entities (OVSE). [Ref. Section ‘2- Definitions’, Aadhaar
(Authentication and Offline Verification) Regulations]
2. There are two modes of offline verification, viz the Secure QR Code (displayed on Aadhaar
letter, e-Aadhaar, Aadhaar PVC card and m-Aadhaar ) and the Aadhaar Paperless Offline e-KYC
XML (downloaded from the UIDAI website and m-Aadhaar). Both the Secure QR Code and the
Aadhaar Paperless Offline e-KYC XML contain the resident’s data that is digitally signed by UIDAI.
This is an essential security component that establishes the authenticity of the document, as
presented by the resident seeking service from an OVSE. Scanning of secure QR code (which
includes validation of UIDAI’s digital signature) is possible using Aadhaar Secure QR code scanner
application. This scanner application is freely available for both Android and iOS based mobile
phones as well as Windows based applications. The scanner is also available as part of UIDAI’s m-
Aadhaar mobile application, for both Android and iOS phones.
3. Residents may voluntarily use the Aadhaar number for a lawful purpose, to establish their
identity by way of offline verification by an OVSE. For the purpose of offline verification by an
OVSE, the Aadhaar number holder may use his/her Aadhaar either in (i) the physical form like
Aadhaar letter (or copy thereof) or printed e-Aadhaar or Aadhaar PVC Card; or in (ii) the electronic
form like e-Aadhaar/ Aadhaar Paperless Offline e-KYC (XML)/ mAadhaar.
4. Following are the Dos and Don’ts to be followed by the OVSEs:
(A) Dos:-
i. Be courteous to residents. Assure the resident about the security & confidentiality of their
Aadhaar being used for offline verification.
ii. Be sure to carry out offline verification of Aadhaar (as per para 2 above) prior to accepting it
as proof of identity. This applies to all modes of offline usage of Aadhaar, ie. secure QR
Code on Aadhaar Letter (or copy thereof) / e-Aadhaar/ m-Aadhaar or in the Aadhaar
Paperless Offline e-KYC (XML), as the case may be.2
iii. Carry out offline verification of Aadhaar only for the lawful purpose specified to the Aadhaar
number holder along with his/ her explicit consent for verification taken either in physical or
electronic form. Maintain logs/ records of the consent for any future audit by UIDAI or any
agency thereof.
iv. Provide the resident, desirous of availing any service from OVSE, other viable alternative
means of identification, in addition to Aadhaar, as required for rendering the service.
v. Ensure that Aadhaar data collected is not shared with any entity except in accordance with
the Aadhaar Act and/or regulations thereof.
vi. Ensure that no service is denied to any resident for refusing to or being unable to undergo
offline verification of Aadhaar provided that the resident is able to identify himself/ herself
through other viable alternative means, as suggested by the OVSE.
vii. Ensure full cooperation to the Authority, or any agency appointed or authorized by it or any
other authorized investigation agency, in case of any fraud investigation involving Aadhaar,
viii. Do inform the Authority and the Aadhaar number holder, without undue delay and in no case
beyond 72 hours after having knowledge of misuse of any information or systems related to
the Aadhaar framework or any compromise of Aadhaar related information.
ix. Ensure strict compliance to the Aadhaar Act and Regulations and to any other directions
received from UIDAI from time to time, with respect to obligations of OVSEs.
(B) Don’ts:-
i. Do not accept Aadhaar number, in physical or electronic form, as a proof of identity for a
lawful purpose, without first verifying the digital signature of the Authority as provided in the
Aadhaar Secure QR Code on Aadhaar Letter or e-Aadhaar or m-Aadhaar or Aadhaar
Paperless Offline e-KYC (XML), as the case may be.
ii. Do not perform verification of Aadhaar without explicit consent of the Aadhaar number
holder in the form & manner as prescribed.
iii. Do not perform offline verification on behalf of any other entity or person.
iv. Do not collect, use or store Aadhaar number or biometric information of the resident after
having conducted offline verification of Aadhaar. Post verification, if the OVSE finds it
necessary for any reason, to store a copy of Aadhaar letter/ e-Aadhaar, the OVSE must ensure
that Aadhaar number is redacted/ masked and irretrievable through any means by any entity,
including by OVSE itself.
---------Sd/-------
(Kuldeep Singh)
Asstt. Director (AU)
Tel: 2347 8511