Home India ELECTRONICS AND INFORMATION TECHNOLOGY Parliament Question: Aadhaar leaks...
Date: 2025-12-17 Category: Not Applicable State: Union Government Country: India

Parliament Question: Aadhaar leaks

Issued by ELECTRONICS AND INFORMATION TECHNOLOGY · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary** This report addresses Unstarred Question No. 2855 in Lok Sabha, concerning potential Aadhaar data leaks from government websites. It acknowledges that Aadhaar is the world’s largest biometric identity system and assures that comprehensive measures are in place to protect Aadhaar data. The answer, provided by the Minister of State for Electronics and Information Technology, also states that no breach of Aadhaar card holders' data has occurred from the UIDAI database till date. The question was set to be answered on 17.12.2025. **Key Points / Main Content** * **Aadhaar Security Measures:** * Multi-layered security infrastructure with defence-in-depth. * Continuous reviews/audits to protect systems. * Advanced encryption technologies for data protection during transmission and storage. * **Certifications and Compliance:** * UIDAI's Information Security Management System is ISO 27001:2022-certified by STQC. * UIDAI is also certified ISO/IEC 27701:2019 (Privacy Information Management System). * UIDAI is declared as a protected system, with NCIIPC providing continuous security advice. * **Oversight and Audits:** * An independent audit agency is engaged for the creation of the Governance, Risk, and Compliance and Performance (GRCP) framework for the Aadhaar ecosystem and oversight for adherence to the same. * Continuous cybersecurity audits of UIDAI applications, including Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST). * **Breach Status:** * No breach of Aadhaar card holders' data has occurred from the UIDAI database to date. **Impact Analysis** **Stakeholder: Citizens with Aadhaar** * **Impact:** Assurance that their Aadhaar data is protected by multi-layered security measures and continuous audits. They are informed that no breach has occurred from the UIDAI database. * **Action Required:** No immediate action required. Citizens should remain vigilant about protecting their personal information and report any suspected misuse of their Aadhaar data. **Stakeholder: Unique Identification Authority of India (UIDAI)** * **Impact:** Reinforces the importance of maintaining high security standards and continuous improvement of security measures. * **Action Required:** Continue to implement and enhance security measures, conduct regular audits, and comply with relevant certifications and guidelines. Maintain vigilance against potential threats and vulnerabilities. **Stakeholder: Ministry of Electronics and Information Technology** * **Impact:** Demonstrates the government's commitment to data protection and transparency regarding Aadhaar security. * **Action Required:** Continue to oversee UIDAI's security practices, provide necessary support and resources, and address any concerns raised by citizens or stakeholders regarding Aadhaar data security.

Key Entities Referenced

Aadhaar: India's biometric identity system Unique Identification Authority of India (UIDAI): The organization entrusted to issue Aadhaar and protect its data. Ministry of Electronics and Information Technology: The ministry responsible for answering the question about Aadhaar leaks. National Critical Information Infrastructure Protection Centre (NCIIPC): Provides security advices to maintain UIDAI's cybersecurity posture.
Official Source Record View Original Source →
See Full Document Text
GOVERNMENT OF INDIA MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY LOK SABHA UNSTARRED QUESTION NO. 2855 TO BE ANSWERED ON: 17.12.2025 AADHAAR LEAKS 2855. SHRI KHALILUR RAHAMAN: Will the Minister of ELECTRONICS AND INFORMATION TECHNOLOGY be pleased to state: (a) whether the Government is aware of the leaks of Aadhaar details of citizens from its very own websites and if so, the details thereof; (b) the numbers of such leaks during the last three years and its impact on individual privacy; and (c) the steps taken by the Government to ensure that there are no further breaches of Aadhaar data of citizens? ANSWER MINISTER OF STATE FOR ELECTRONICS AND INFORMATION TECHNOLOGY (SHRI JITIN PRASADA) (a) to (c): Aadhaar is the world's largest biometric identity system with approximately 134 crores live Aadhaar holders. It has completed more than 16,000 crore authentication transactions. Unique Identification Authority of India (UIDAI), the organisation entrusted to issue Aadhaar, has comprehensive measures in place to protect the personal data of Aadhaar number holders. • It has implemented multi-layered security infrastructure with defence-in-depth concept to protect its database and continuously reviews/audits the same to protect its systems. • It uses advanced encryption technologies for protecting data during transmission and storage. • UIDAI’s Information Security Management System is ISO 27001:2022-certified by STQC. UIDAI is also certified ISO/IEC 27701:2019 (Privacy Information Management System). • Further, UIDAI is declared as a protected system and hence the National Critical Information Infrastructure Protection Centre (NCIIPC) continuously provide security advices to maintain its cybersecurity posture. An independent audit agency is engaged for the creation of the Governance, Risk, and Compliance and Performance (GRCP) framework for the Aadhaar ecosystem and oversight for adherence to the same. It continuously conducts cybersecurity audit of UIDAI application including Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST). Till date, no breach of Aadhaar card holders’ data has occurred from the UIDAI database.******

Continue your research