Home India Ministry of Electronics and Information Technology Do’s and Don’ts for REs...
Date: 2022-10-31 Category: Not Applicable State: Union Government Country: India

Do’s and Don’ts for REs

Issued by Ministry of Electronics and Information Technology · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

## Aadhaar Usage Policy: Dos and Don'ts for Requesting Entities - Policy Analysis Report **1. Executive Summary:** This report analyzes a circular issued by the Unique Identification Authority of India (UIDAI) regarding the usage of Aadhaar and the "Dos and Don'ts" for Requesting Entities (REs). The policy focuses on ensuring responsible and secure use of Aadhaar authentication services by these entities. It emphasizes resident privacy, data security, informed consent, and compliance with the Aadhaar Act, 2016. Key findings include the detailed guidelines for REs pertaining to Aadhaar data handling, security protocols, and ethical responsibilities. This is a new policy outlining the expectations of Requesting Entities when handling Aadhaar data. **2. Introduction:** This report aims to provide a comprehensive overview of the UIDAI circular dated October 31st, 2022, concerning the usage of Aadhaar and associated guidelines for Requesting Entities (REs). The analysis is based solely on the provided text. **3. Policy Overview:** * **Core Objective(s):** The core objectives, as inferred from the text, are to: * Ensure the secure and confidential use of Aadhaar numbers during authentication. * Protect the privacy of Aadhaar number holders. * Establish clear guidelines for REs regarding data handling, storage, and sharing. * Promote ethical and responsible use of Aadhaar authentication services. * Ensure compliance with the Aadhaar Act, 2016, and its associated regulations. **4. Background and Rationale:** The policy addresses the potential risks associated with the widespread use of Aadhaar authentication services. These risks include data breaches, privacy violations, and unauthorized access to sensitive information. By establishing clear "Dos and Don'ts," the policy aims to mitigate these risks and ensure that REs handle Aadhaar data responsibly and in compliance with relevant regulations. The policy promotes responsible behavior and reduces the risk to individuals. **5. Key Provisions / Changes:** As a New Policy, the following are the key rules and actions mandated: * **Courtesy and Security:** REs must be courteous to residents and assure them of the security and confidentiality of their Aadhaar number. * **Informed Consent:** REs must ensure that residents clearly understand the type of data being collected and the purpose of Aadhaar authentication, obtaining informed consent before authentication. * **Data Storage:** Aadhaar numbers must only be stored if authorized and within a secure Aadhaar Data Vault as prescribed by UIDAI. * **Data Sharing:** Aadhaar data cannot be shared with any entity except as permitted by the Aadhaar Act and regulations. * **Transaction Logs:** Authentication transaction logs, including consent records, must be retained only for the period prescribed under Aadhaar regulations and purged upon expiry. * **Device Hygiene:** Authentication devices must be maintained to minimize authentication failures. * **Operator Training:** Regular training must be provided to staff on best practices and safeguards. * **Suspicious Activity Reporting:** Any suspicious activity around authentication must be immediately reported to UIDAI. * **Audit Cooperation:** REs must cooperate with UIDAI and its agencies during security process audits and address any non-compliances promptly. * **Grievance Handling:** An effective grievance handling mechanism must be provided to residents through multiple channels. * **Statutory Obligations:** REs must fulfill all statutory obligations under the Aadhaar Act, 2016, including penalties for contraventions. * **Unlawful Actions:** REs must not aid or abet any unlawful actions that violate laws, regulations, or prescribed processes. * **Authentication Keys and License:** REs must not share their authentication keys, certificates, or unique license keys with any other entity. * **Aadhaar Copies:** REs must not store photocopies of Aadhaar letters without masking the first 8 digits of the Aadhaar number. * **Biometric Information:** REs must not store, share, or publish biometric information collected from the Aadhaar number holder. * **Compliance with Aadhaar Act:** REs must not act in contravention of the Aadhaar Act, 2016, and its regulations. **6. Target Audience and Stakeholders:** The primary target audience is Requesting Entities (REs) engaged in providing Aadhaar authentication services. This includes government and private legal entities registered in India that are authorized to use UIDAI's authentication services. Ultimately, Aadhaar number holders also benefit from the enhanced security and privacy measures outlined in the policy. **7. Implementation Aspects (Inferred):** * **Responsible agency/bodies:** UIDAI is the responsible agency for overseeing and enforcing the policy. Authentication Service Agencies (ASAs) facilitate authentication services to REs. * **Timelines or procedures:** The text specifies timelines for retaining and purging authentication transaction logs, referencing the Aadhaar Authentication and Offline Verification Regulations. It also implies a process for security audits by UIDAI or its designated agencies. **8. Expected Outcomes / Impact of Changes:** The likely intended outcomes of this policy are: * Increased security and confidentiality of Aadhaar data. * Enhanced protection of resident privacy. * Reduced risk of data breaches and unauthorized access. * Improved compliance with the Aadhaar Act, 2016, and its regulations. * Greater transparency and accountability in Aadhaar authentication processes. * Increased trust and confidence among Aadhaar number holders. **9. Conclusion:** The UIDAI circular outlining the "Dos and Don'ts" for Requesting Entities is a significant step towards promoting responsible and secure use of Aadhaar authentication services. The policy establishes clear guidelines for REs, emphasizing data security, privacy protection, informed consent, and compliance with the Aadhaar Act. Adherence to these guidelines is crucial for maintaining the integrity of the Aadhaar ecosystem and safeguarding the privacy of Aadhaar number holders. This policy provides much needed clarity to Requesting Entities on best practices.

Key Entities Referenced

HQ1503542021AUHQ: Document identifier Unique Identification Authority of India: Issuing Authority of the circular Aadhaar Usage Division: Division of the UIDAI UIDAI: Unique Identification Authority of India, issuing body of the document. Bangla Sahib Road, Behind Kali Mandir, Gole Market, New Delhi. 110001: Address of the UIDAI headquarters. 31st October, 2022: Date of the circular. CIRCULAR: Type of document. Aadhaar Dos Donts for Requesting Entities: Subject of the circular. Requesting Entity: An entity responsible for submitting resident's Aadhaar number and information for authentication. RE: Abbreviation for Requesting Entity. Aadhaar number: Identification number demographic biometric OTP information: Types of information submitted by the Requesting Entity. Central Identities Data Repository: Repository to which the information is submitted CIDR: Abbreviation for Central Identities Data Repository. Authentication Service Agency: Agency facilitating Aadhaar authentication Services ASA: Abbreviation for Authentication Service Agency Section 2 Definitions, Aadhaar Authentication and Offline Verification Regulations: Reference to the definition of RE. Aadhaar Data Vault: Secure location to store Aadhaar number. Aadhaar Act: The relevant act regarding Aadhaar. Aadhaar Act, 2016: The relevant act regarding Aadhaar. Penalties for contraventions Section 29 and Chapter VIA of Aadhaar Act: Reference to penalties within the Aadhaar Act. Kuldeep Singh: Asstt. Director AU
Official Source Record View Original Source →
See Full Document Text
HQ-15035/4/2021/AU-HQ Unique Identification Authority of India (Aadhaar Usage Division) UIDAI HQs, Bangla Sahib Road, Behind Kali Mandir, Gole Market, New Delhi. 110001 Dated: 31st October, 2022 CIRCULAR Subject: Usage of Aadhaar - Dos & Don’ts for Requesting Entities- Regarding A Requesting Entity (RE) is responsible for submitting the resident’s Aadhaar number and demographic/ biometric/ OTP information, to the Central Identities Data Repository (CIDR), for the purpose of authentication. 2. An RE is engaged in providing Aadhaar authentication Services to an Aadhaar number holder, as facilitated by the Authentication Service Agency (ASA). The RE may be a government / private legal entity registered in India, which is authorized to use Aadhaar authentication services of UIDAI and sends authentication requests to enable its services / business functions. [Ref. Section ‘2- Definitions’, Aadhaar (Authentication and Offline Verification) Regulations] 3. Following are the Dos and Don’ts to be followed by the REs: DOs i. Be courteous to residents. Assure the resident about the security & confidentiality of their Aadhaar number being used for authentication. ii. Ensure that the resident clearly understands the type of data being collected and the purpose of Aadhaar authentication. Obtain resident’s informed consent either on paper or electronically, prior to carrying out authentication. iii. Store Aadhaar number only if you are authorized to do so and in the manner as prescribed by UIDAI i.e. within a secure Aadhaar Data Vault. iv. Ensure that Aadhaar data collected is not shared with any entity except in accordance with the Aadhaar Act and/or regulations thereof. v. Retain the logs of authentication transactions (including that of consents taken) only for the period as prescribed under Aadhaar (Authentication and Offline Verification) Regulations. Purging of such logs upon expiry of the period shall also be in accordance to the Aadhaar Act or regulations thereof. vi. Ensure proper hygiene of the authentication devices being used so that there are minimal authentication failures2 vii. Ensure regular training of operators/staff carrying out Aadhaar authentication on the best practices and safeguards involved in doing so. viii. Immediately report any suspicious activity around authentication to UIDAI namely, suspected impersonation by resident, likely compromise of authentication keys of RE, likely fraud by authentication operator(s) etc. ix. Cooperate with UIDAI and/or agencies deputed by UIDAI for the purpose of any security/ process audit as required by the Aadhaar Act/ Regulations or any other directions in this regard from UIDAI. Ensure timely closure of audit observations/non-compliances, if any. x. Provide effective grievance handling mechanism to the resident via multiple channels like website, call center, mobile app, SMS, physical center, etc. xi. Fulfill all your statutory obligations under the Aadhaar Act, 2016 including Penalties for contraventions (Section 29 and Chapter VIA of Aadhaar Act). DON’Ts i. Do not aid or abet any unlawful action of any resident/authentication operator/ other entity that is in contravention of the laws / regulations and prescribed processes & directions. ii. Do not share your authentication keys/ certificates with any other entity. iii. Do not share unique license keys/ code as provided by UIDAI with any other entity. iv. Do not store photocopies of Aadhaar letters and/or other physical/electronic forms of Aadhaar, if used for collecting Aadhaar, without first masking / redacting the first 8 digits of the Aadhaar number displayed on those documents. v. Do not store/share/publish the biometric information collected from the Aadhaar number holder for authentication. vi. Do not act in contravention of the Aadhaar Act, 2016 and regulations thereof. --------sd-------- (Kuldeep Singh) Asstt. Director (AU) Tel: 2347 8511 2

Continue your research