Skip to content
KEDBYTE
How Identity Works
Chapter
50

A Billion People and One Number

Part V · Identity, Society and the Law|12,005 words|about 52 min read|Volume 5
Fast-moving material. Figures, model names, prices and version numbers in this chapter were verified in August 2026. Claims are separated into established fact, active research and marketing claim. Re-check anything you intend to rely on.

50.0 What this chapter gives you#

  1. You will be able to say exactly what an Aadhaar number is, what it legally is not, and describe the enrolment process step by step.
  2. You will be able to explain deduplication at one-to-many scale, why the work grows faster than the population, and what the accuracy figures do and do not prove.
  3. You will be able to name the four authentication modes in the regulations, describe the shape of the request that carries them, and say which parts are encrypted and where.
  4. You will be able to explain Virtual ID, UID Token and limited electronic know-your-customer, and say which problem each was built to solve.
  5. You will be able to state what the Supreme Court of India struck down on 26 September 2018, provision by provision, and what survived.
  6. You will be able to set out the three-part proportionality test from the 2017 privacy judgment and apply it to a proposed identity scheme.
  7. You will be able to describe how eSign, DigiLocker and the Account Aggregator network sit on top of the identity layer, with current figures.
  8. You will be able to quote real, sourced numbers for authentication failure and for exclusion from rations, and name the studies they come from.
  9. You will be able to say what the Digital Personal Data Protection Act, 2023 and its 2025 Rules change for anyone processing Aadhaar-linked data, and by which date.
  10. You will be able to judge a national identity proposal against the strongest evidence we have about what one actually does.

India did the experiment. Between 2009 and 2026 it enrolled almost every resident of a country of over 1.4 billion people into a single biometric database, gave each of them one twelve-digit number, wired that number into banking, telecoms, tax, food rations, pensions, school admission and wage payments, and then let its Supreme Court take the whole thing apart in public. Nothing else on this scale exists. Every other national digital identity programme now being designed is arguing about questions India has already answered in production, sometimes well and sometimes badly.

That makes Aadhaar the most important single case study in this book. Not because it is a model to copy, nor a warning to avoid, but because it is evidence. When someone tells you that biometric deduplication guarantees uniqueness, or that a national identifier inevitably becomes a surveillance tool, or that welfare fraud vanishes once you check fingerprints, India has run that claim against 1.4 billion people and there are audited numbers on the other side.

This chapter gives you those numbers with their sources and their dates, and separates three things that get mixed together constantly: what the system is designed to do, what it demonstrably does, and what its supporters and critics claim it does. We start with the plain version, told without a single technical word. Then we say where that plain version misleads. Then we do the whole thing again properly, with statute sections, regulation numbers, message formats, judgment dates and audited figures, carrying one woman’s enrolment through from the counter in a district office to a bank account and a failed fingerprint at a ration shop. The neighbouring chapters take the pieces that are properly theirs: chapter 49 covers what all this means for banking rules, and chapter 51 covers the European wallet that is being built with one eye on India.

The plain version#

The village register and the impossible question#

Imagine a very large village, so large that no one can know everyone. The village keeps a register of its people, because the village hands out food, pensions and work, and it wants to hand them out once each to each person.

The clerk who keeps the register has one hard job and one easy job. The easy job is looking someone up: a woman comes to the counter, says her name and her father’s name, and the clerk finds the line. The hard job is the other direction. A woman comes to the counter and says she is not in the register yet. Is that true? Or is she already in there under a slightly different name, collecting a second share?

The clerk cannot answer that by looking her up, because she may have given a different name last time. To answer honestly, the clerk has to compare her against every single line already in the book. Not one comparison. All of them. With a village of a hundred that is a morning’s work. With a hundred thousand it is a life’s work. With 1.4 billion it is not work at all, it is a machine, and that machine is the entire point of the system this chapter is about.

What Aadhaar actually is#

India built that machine. It is called Aadhaar, and it is much less than most people think.

It is a number. Twelve digits, given to a resident once, never given to anyone else, and meaningless by itself: it is not built out of your birth year or your state or your caste, it is drawn at random. That is deliberate, because a number that encodes facts about you leaks those facts to anyone who sees it.

Attached to that number, in one central store, is a small amount of information. Your name, your date of birth, whether you are male, female or a third category, and your address. Your photograph. Your ten fingerprints. Both of your irises, the coloured rings in your eyes, which are as individual as fingerprints and do not wear away with manual work. Optionally your mobile number and email address.

That is all. There is no record in that store of your religion, caste, income, health, job or spending, no record of the shops you visited or the benefits you drew, and no record of your ration card, bank account or phone.

The number is not a card. There is a printed letter, and there is a plastic card you can buy, but the paper is not the identity; the entry in the store is. The number is not proof that you are Indian: the law says in plain words that it confers no citizenship and proves none. It is not a licence, a permit or a passport. It is one thing only: a way of saying “this is the same person as before”, and a way of checking that claim quickly from anywhere.

What happens at the counter#

Let us follow one person, and we will keep following her for the rest of the chapter.

Sunita Mahato is thirty-four and lives in a village in Simdega district, in the state of Jharkhand, in eastern India. She goes to an enrolment centre. An operator types her name, date of birth, gender and address, and she brings a document to support each of those claims, or someone already enrolled who will vouch for her. Then she puts all ten fingers on a scanner, four at a time and then the thumbs. She looks into a second device that photographs both her eyes. A camera takes her picture. The operator shows her the screen so she can check the spelling of her name, and she signs or thumbprints the form.

She does not walk away with a number. She walks away with a receipt carrying a long reference code, and the packet of her details travels to the central store, where the machine does the hard job: it compares her fingerprints and her irises against everyone already in the register. If it finds no match, she is new, and a number is generated and posted to her. If it finds a match, she already has a number, and no second one is issued. That single comparison, done once per person, is the whole reason the system exists.

A few weeks later the letter arrives. Sunita’s number, made up for this book because real ones must never be printed, is 4321 9876 5432.

The three ways a shop can check it#

Now the number has to be useful, which means somebody has to check it. There are three basic ways, trading convenience against certainty.

The first is a finger or an eye. Sunita goes to the ration shop, says her number, and puts a finger on a small scanner. The scanner sends the number and a scrambled copy of the fingerprint to the central store, which compares that one fingerprint against the one it holds for that one number and sends back one word: yes or no. It does not send her name, her address or her photograph. Just yes or no.

The second is a one-time code. If Sunita has given a mobile number, the store sends a six-digit code to her phone and she reads it out with her number, and again the answer is yes or no. This works when there is no scanner and when her fingers do not read, but it needs a phone in her hand and a signal in her village.

The third is typed facts: the number plus her name and date of birth, and does that match. That is the weakest of the three, because anyone holding a photocopy of her letter can type those facts.

There is a fourth thing, not really checking at all but used constantly: she hands over a photocopy. That proves nothing, and it is where most of the real harm happens.

Getting the details back, not just yes or no#

Sometimes a shop needs more than yes or no. A bank opening an account needs her name and address in a form it can trust. So there is a second kind of request: she authenticates in one of the ways above, and gives permission, and the central store sends back her name, date of birth, gender, address and photograph, signed in a way that proves the store sent it and nobody altered it on the way. That is the difference between a doorman confirming you are on the list and the doorman handing your file across. Only one of them moves your personal details into somebody else’s computer, which is why the law treats them differently.

The mask over the number#

There is one more piece, added later, and it matters more than it looks.

The problem with a number that everyone accepts is that everyone collects it. Sunita’s number ends up in the ration shop’s book, the phone company’s database, her bank’s file and her employer’s spreadsheet. None of those has to be broken into for harm to happen. Two of them can simply lay their records side by side, match on the number, and learn things about her that neither was allowed to know alone.

So India added a mask. Sunita can generate a temporary sixteen-digit number that stands in for her real one. It works for checking, it can be replaced whenever she likes, and it cannot be used to line up her records elsewhere. Separately, a company that checks her identity can be given a long code unique to her and to that one company: the phone company’s code for Sunita and the bank’s code for Sunita are different strings, so the two files still cannot be joined.

That is the whole plain story: a random number, a small set of details, one hard comparison done once, three ways to check, an optional file transfer, and a mask. Everything else is detail, law, or the record of what went wrong.

Where the plain version stops being true#

The clerk analogy hides the arithmetic#

In the plain version the clerk compares the newcomer against every line in the book, and we waved at how big that is. The size is the story.

When Sunita enrols and the system already holds one billion people, that single enrolment costs one billion comparisons. The next person costs one billion and one. Enrolling a whole population is not proportional to the population; it grows roughly with the square of it. For a country of 1.4 billion the total number of comparisons over the life of the programme is on the order of a million million million, which is a number no amount of extra hardware makes go away.

The honest version: nobody does all those comparisons at full detail. The system sorts fingerprints into rough buckets first, so a print is compared carefully only against prints that could plausibly match, and splits the work across several matching engines from different suppliers. Those make the job cheaper, not more accurate, and the bucketing step can itself drop a true match into the wrong bucket.

“Unique” is a probability, not a promise#

The plain version says a second number is never issued. The system is designed so that it is never issued. Design is not outcome.

Biometric matching produces a score, not a fact. Set the threshold strict and you wrongly reject genuine matches, so a person who is already enrolled gets a second number. Set it loose and you wrongly declare a match, so a genuine newcomer is refused a number because the system thinks they are someone else. There is no setting that does neither, and India’s system has been tuned deliberately towards issuing a number rather than refusing one, because refusing is the crueller failure.

The honest version: uniqueness in a database this size is a statistical property with a measurable error rate, not a guarantee. India’s own national auditor found that hundreds of thousands of duplicate numbers had to be cancelled after issue, and that the deduplication process “remained vulnerable” to generating them. The exact figures are in the technical half. Anyone who tells you a biometric database cannot contain duplicates is describing a design document, not a system.

A fingerprint is not a password#

The plain version says she puts a finger on the scanner and gets a yes. For a great many people it comes back no, repeatedly, through no fault of theirs.

Fingerprints are worn away by manual labour. Masons, farm workers, cleaners, brick-kiln workers and older people often have ridges too shallow to read. The reader itself may be dusty, cheap or badly maintained. The network may be slow, so the request times out and is recorded as a failure. Nothing about any of this is the resident’s mistake, and none of it can be fixed by trying harder.

The honest version: authentication failure is not an edge case in this system, it is a routine event with a double-digit rate. The numbers, from the government’s own audit, are in the technical half and they are worse than most readers expect. This matters because a failed authentication at a bank means an inconvenience, and a failed authentication at a ration shop can mean a family does not eat that month.

The number was never a secret and cannot be treated as one#

The plain version implies that knowing Sunita’s number is worth something. The authority’s own position is the opposite: knowing the number alone does no harm, because you still need her finger, her eye or her phone.

That is true of the online checking path and false of everything else. Enormous numbers of Indian offices simply take a photocopy of the printed letter and file it, with no check of any kind, and that photocopy carries the number, name, address and photograph onward to the next office that also does no checking.

The honest version: the system runs two completely different security models side by side under one name. The online path, with an encrypted fingerprint and a signed response, is genuinely strong. The paper path, which is what most of the country experiences most of the time, is no stronger than any other photocopy. Almost every publicised Aadhaar harm has come from the paper path, or from a relying party misusing a legitimate online check, rather than from breaking the database.

The plain version does not say whether you have to have one, and the law is clear that for most purposes you do not. The lived experience is different. In a national survey of over 167,000 people conducted in 2019, sixty-five per cent believed, wrongly, that giving Aadhaar was required by law for a bank account, a phone connection or school enrolment, and more than half of the people who gave it for a phone or an account said the provider accepted nothing else.

The honest version: the legal answer and the practical answer differ. Since 2019 authentication can be made compulsory for a service only by a law of Parliament, alternatives must be offered, and service cannot be refused for failing authentication. In practice a clerk trained on one process insists on that process, and a person at the counter cannot enforce a Supreme Court judgment.

The savings claim measures the wrong thing#

You will read that Aadhaar has saved India enormous sums by removing fake beneficiaries. The government’s own direct-benefit-transfer programme puts cumulative gains at about 3.48 lakh crore rupees, a figure repeated widely by international institutions.

The honest version: this is a genuinely contested number and a place where experts disagree sharply. The critique, argued most persistently by the economist Reetika Khera, is that the headline figure conflates the total value of money routed through the new payment system with the amount of fraud actually stopped, and that a fall in beneficiary counts can equally mean eligible people were dropped. Supporters answer that ghost entries were real and are now gone. Both sides can point to evidence; nobody has produced a clean separation of ghosts removed from real people excluded, at national scale.

There is a subtler problem too. Checking identity stops one kind of theft only: the wrong person collecting. It says nothing about grain stolen from a warehouse before it reaches the shop, and nothing about a shopkeeper who correctly reads a fingerprint and then hands over less than the entitlement. A system built to check who you are cannot see how much you got.

The mask arrived late and is barely used#

The plain version presents the temporary number and the per-company code as part of the design. They are not. They were retrofitted in 2018, eight years after the first number was issued, after the linking risk had been demonstrated in print by computer scientists and after the Supreme Court had begun hearing the constitutional challenge.

The honest version: the same 2019 survey found that seventy-seven per cent of holders had never used any of the newer privacy features, and only five per cent had ever used the temporary number. A privacy control that almost nobody uses protects almost nobody.

The technical version#

A dated history, because the order matters#

The programme is older than the law that governs it, and that gap explains a great deal about the litigation.

Date Event
28 Jan 2009 UIDAI created by notification
29 Sep 2010 First number issued, Tembhali
31 Dec 2011 10 crore numbers issued
23 Jan 2012 First accuracy report out
25 Mar 2016 Aadhaar Act, Act 18 of 2016
24 Aug 2017 Privacy judgment, nine judges
10 Jan 2018 Virtual ID circular issued
26 Sep 2018 Aadhaar judgment, five judges
2 Mar 2019 Amendment Ordinance made
8 Nov 2021 2021 Regulations notified
31 Jan 2025 Private-entity route opened
13 Nov 2025 Data protection Rules notified

The Unique Identification Authority of India was created on 28 January 2009 by a notification of the Planning Commission, reference A-43011/02/2009-Admin.I, a fact recorded in section 22 of the eventual Act when it transferred that body’s assets. Nandan Nilekani, co-founder of the software company Infosys, was its first chairman. The first Aadhaar number was issued on 29 September 2010 at Tembhali in Maharashtra, and 10 crore, that is 100 million, numbers had been issued by 31 December 2011. A bill to give the authority a statutory footing was introduced in Parliament in 2010 and did not pass, so for six years the largest biometric enrolment in history ran on executive authority alone. It is that gap which section 59 of the eventual Act had to save retrospectively.

Enrolment, and the number itself#

The Act draws a line that matters. Section 2(k) defines demographic information as name, date of birth, address and other information specified by regulations, and then expressly excludes race, religion, caste, tribe, ethnicity, language, records of entitlement, income and medical history. That exclusion is statutory, not a policy that can be changed by an official. Section 2(g) defines biometric information as photograph, fingerprint, iris scan or such other biological attribute as regulations may specify, and section 2(j) defines core biometric information more narrowly, as fingerprint and iris scan but not the photograph. The distinction runs through the whole Act, because core biometric information may never be shared with anyone, for any reason.

Enrolment under the Aadhaar (Enrolment and Update) Regulations, 2016 captures ten fingerprints, both irises and a facial photograph for every applicant aged five and over. Children under five are enrolled on the facial image alone, linked to a parent’s authentication, and must return at five and again at fifteen for a mandatory biometric update. Section 5 of the Act requires special measures for women, children, senior citizens, persons with disability, unskilled and unorganized workers, nomadic tribes and people with no permanent dwelling, and there is an exception process for residents who cannot give one or more biometrics at all.

Captured at enrolment Kind
Name, date of birth, gender Demographic
Address Demographic
Mobile and email (optional) Demographic
Facial photograph Biometric
Ten fingerprints Core biometric
Two iris scans Core biometric

Sunita leaves the counter with an Enrolment ID printed on an acknowledgement slip. That code is not her number and is not a substitute for it; it is a reference she can use to check whether her packet has been processed. Enrolment itself is free. Updates are charged, though the authority has repeatedly waived those charges: as of August 2026 an office memorandum dated 13 May 2026 extends free document update through the myAadhaar portal to 14 June 2027, and one dated 18 June 2026 waives the charge for updating an email address through the Aadhaar mobile application until 31 December 2026.

An Aadhaar number is twelve decimal digits. Section 4(1) says it shall never be reassigned to another individual; section 4(2) says it shall be a random number and bear no relation to the attributes or identity of the holder.

The last digit is a check digit computed with the Verhoeff algorithm, a decimal checksum published by the Dutch mathematician Jacobus Verhoeff in 1969 and notable for being the first decimal scheme able to detect all single-digit errors and all adjacent transpositions. That means a mistyped digit or two swapped digits will almost always be caught locally, before any request leaves the building. By convention the first digit is never 0 or 1, which keeps Aadhaar numbers distinguishable from other Indian numbering schemes. The random draw and the check digit together mean that a valid-looking number tells you nothing about its holder, and that a number invented at random has roughly a one in ten chance of passing the checksum and no chance at all of matching a biometric.

CIDR and deduplication at one-to-many#

The Central Identities Data Repository, defined in section 2(h) of the Act, is the central database holding every number with its demographic and biometric information. Section 10 permits the authority to engage one or more entities to establish and maintain it. It runs from Indian data centres, and the government’s position, stated to Parliament on 18 March 2026, is that storage and processing of Aadhaar data takes place within India and that demographic data is encrypted at rest and in transit. [UNVERIFIED: the current number and exact locations of the CIDR data centres.]

Deduplication is a one-to-many search: Sunita’s packet arrives and the system must decide whether her biometrics match anyone in a gallery of well over a billion. The architecture published by the authority in 2012 has three properties worth naming. It is multi-modal, fusing ten fingerprints with two irises rather than using them separately, because the failure modes differ: worn fingertips do not affect irises, and eye injury does not affect fingers. It is multi-vendor, putting the same packet to matching engines from three different biometric service providers, so a systematic weakness in one supplier’s algorithm does not become a weakness in the national register. And demographic deduplication runs alongside the biometric kind, catching the easy cases cheaply.

resident     device        AUA         ASA        CIDR
   |           |            |           |           |
   |  finger ->|            |           |           |
   |           | build PID  |           |           |
   |           | encrypt it |           |           |
   |           |----------->|           |           |
   |           |            | sign the  |           |
   |           |            | request   |           |
   |           |            |---------->|           |
   |           |            |           | private   |
   |           |            |           | link      |
   |           |            |           |---------->|
   |           |            |           |           | 1:1
   |           |            |           |  y or n   |
   |           |            |           |<----------|
   |           |            |<----------|           |
   | result <--|<-----------|           |           |

In February 2026 the authority began national rollout of a replacement deduplication platform built in-house, with fingerprint, face and iris matching models developed with the International Institute of Information Technology, Hyderabad, running on high-performance inference hardware, and described publicly as an “invisible shield” against enrolment fraud. It was rolled out in several states first, with completion expected within months of the February announcement. That a fourteen-year-old system is being replaced specifically to improve deduplication speed and accuracy is itself informative: the hard problem stayed hard.

The published accuracy figures, and their limits#

On 23 January 2012 the authority published “The Role of Biometric Technology in Aadhaar Enrolment”, an analysis of 8.4 crore, that is 84 million, enrolments. Its headline numbers are still the ones quoted fourteen years later.

Measure Value Meaning
Failure to enrol 0.14 per cent No usable biometrics
False negative identify 0.035 per cent Duplicate missed
Duplicates caught 99.965 per cent Complement of the above

Read those carefully. A failure-to-enrol rate of 0.14 per cent sounds tiny and, applied to 1.4 billion people, describes about two million residents whose biometrics the system could not use. A false negative identification rate of 0.035 per cent describes roughly half a million duplicates that would be expected to slip through. Those are not scandals; they are the arithmetic of the published figures working as advertised.

They are also self-reported. India’s Comptroller and Auditor General, in Report No. 24 of 2021, a performance audit of the authority tabled in Parliament in April 2022, made three findings that bear directly on the uniqueness claim. The authority’s stated deduplication accuracy of 99.9 per cent was its own figure, not independently verified. The deduplication process “remained vulnerable for generating multiple Aadhaar numbers”, requiring manual intervention. And more than 4.75 lakh, that is over 475,000, Aadhaar numbers had been cancelled as duplicates by November 2019, which the auditor calculated as an average of at least 145 duplicate numbers generated per day across the nine years since 2010. No outside body has been given access to the live database to test the accuracy claim independently. That is the single most important sentence in this section.

Authentication: the modes, the request, and the price#

The operative rules today are the Aadhaar (Authentication and Offline Verification) Regulations, 2021, notified on 8 November 2021 and published in the Gazette of India Extraordinary, Part III, Section 4, No. 542, dated 9 November 2021, superseding the 2016 Authentication Regulations, and amended on 4 February 2022, 27 February 2023, 3 October 2023 and 31 January 2024.

Regulation 3 creates two facilities. The Yes/No authentication facility returns a digitally signed yes or no and no identity information at all. The e-KYC authentication facility returns a digitally signed response carrying encrypted e-KYC data, and regulation 3 restricts it to one-time-pin and biometric modes only, so a purely demographic request can never pull a file.

Regulation 4(2) sets out the modes.

Mode What is submitted
Demographic Number plus typed details
One-time pin Number plus code to mobile
Biometric Number plus finger or iris
Multi-factor Any two or more of these

Face authentication has since been added as a biometric modality and, as the government told Parliament in March 2026, uses machine-learning models rather than classical template matching.

Two provisions in regulation 9 do most of the security work. Regulation 9(4) states that in all modes the Aadhaar number is mandatory and is submitted with the input parameters “such that authentication is always reduced to a 1:1 match”. That is the difference between identification and verification, and it is a hard architectural boundary: the authentication service will never search the gallery for a face or a finger. Regulation 9(5) requires the PID block, the Personal Identity Data element carrying the demographic, biometric or one-time-pin values, to be encrypted at the moment of capture on the device, not on the merchant’s server.

The request itself is XML. The current published specification is Aadhaar Authentication API 2.5, Revision 1, of January 2022; version 2.5 of the authentication, e-KYC and one-time-pin APIs was published on 2 April 2018 to carry Virtual ID and limited KYC. The shape is stable across those revisions:

<Auth uid="431298765432" rc="Y" tid="" ac="AUACODE"
      sa="SUBAUA" ver="2.5" txn="TXN-0001" lk="LICENSEKEY">
  <Uses pi="n" pa="n" pfa="n" bio="y" bt="FMR"
        pin="n" otp="n"/>
  <Meta udc="UDC:0001" rdsId="" rdsVer="" dpId=""
        dc="" mi="" mc="" lot="P" lov="835223"/>
  <Skey ci="20270331">BASE64-RSA-WRAPPED-AES-KEY</Skey>
  <Data type="X">BASE64-AES-ENCRYPTED-PID-BLOCK</Data>
  <Hmac>BASE64-ENCRYPTED-SHA256-OF-PID</Hmac>
  <Signature>XML-DSIG-BY-THE-AUA</Signature>
</Auth>

Read it element by element. uid carries the Aadhaar number or a Virtual ID in its place; ac is the agency’s code and lk its licence key. Uses declares which factors the request contains, so bio="y" bt="FMR" means a fingerprint minutiae record and nothing else. Meta carries device provenance: which registered device, which provider, and the location. Skey is a fresh 256-bit AES session key wrapped with the authority’s 2048-bit RSA public key, its ci attribute naming the certificate’s expiry so the far end knows which private key to try. Data is the encrypted PID block, Hmac lets the authority detect tampering without decrypting first, and Signature is the requesting entity’s own signature over the whole document, which makes the request non-repudiable.

The response carries no identity data at all:

<AuthRes ret="n" code="a4f7c1" txn="TXN-0001"
         ts="2026-08-17T11:42:06" err="300"
         actn="A202" info="...">
  <Signature>XML-DSIG-BY-UIDAI</Signature>
</AuthRes>

ret is the answer, y or n. err carries a numbered reason when the answer is no, and error 300 means the biometric did not match. actn is an action code the authority added so that a device can show the resident a useful instruction rather than a bare failure. The whole response is signed by the authority, which is the only reason a relying party can later prove what it was told.

Sunita’s request at the ration shop is exactly this document, with her number, one fingerprint template, the shop’s device identifiers and the dealer’s agency code.

The Aadhaar (Pricing of Aadhaar Authentication Services) Regulations, 2019, published in March 2019, set the tariff: 20 rupees including taxes for each e-KYC transaction, and 50 paise, that is 0.5 rupees including taxes, for each Yes/No authentication. Government entities and departments are exempt. The auditor’s report noted, pointedly, that the authority had provided authentication free to banks and mobile operators until March 2019 contrary to its own regulations, forgoing revenue.

Those two prices explain a great deal of behaviour. A yes-or-no check costs a fortieth of what a file transfer costs, so a well-designed relying party asks the cheap question. In practice many ask the expensive one, because pulling a name and address into their own database saves them typing, and the pricing gap has not been enough to stop them.

Virtual ID, UID Token, ANCS Token and limited KYC#

By late 2017 the linking problem was undeniable. The same twelve digits sat in a bank’s file, a telecom operator’s file and a welfare register, and any two of those holders could join their records on it without breaching anything. Computer scientists had set the problem out formally that same year, in a paper by Agrawal, Banerjee and Sharma in the Economic and Political Weekly, which proposed exactly the fix later adopted, under the name virtual identities. The authority issued a circular on 10 January 2018 introducing three constructs, and Circular No. 05 of 2018, dated 16 May 2018, classified every requesting entity into one of two tiers with a hard migration deadline, extended from 1 June to 1 July 2018, after which non-migrating entities would lose authentication service.

Construct Length Scope
Virtual ID 16 digits Resident, revocable
UID Token 72 characters One entity, permanent
ANCS Token Encrypted number One transaction

The Virtual Identifier, defined in regulation 2(1)(od) of the 2021 Regulations, is an interchangeable sixteen-digit random number mapped to the Aadhaar number. The resident generates it, from the website, by SMS, from the mobile application or when downloading the electronic Aadhaar letter, and may replace it whenever they wish. Regulation 4A(4) is one line long and unusually strong: “No entity shall store Virtual ID in its system.” A Virtual ID is a bearer token for one session, not a substitute identifier to file away.

The UID Token, defined in regulation 2(1)(oc), is a 72-character alphanumeric string generated by the authority, mapped to the Aadhaar number, and specific to a requesting entity. This is the piece that actually solves the linking problem. The bank’s token for Sunita and the phone company’s token for Sunita are different strings that cannot be compared, but each is stable, so each company can still tell that this is the same customer as last time and can still detect a duplicate account. It gives a relying party the two properties it genuinely needs, uniqueness and persistence, without giving it the one it does not, a national correlation key.

The ANCS Token, the Aadhaar Number Capture Service Token defined in regulation 2(1)(ba), is an encrypted number generated for one Aadhaar number to complete one authentication transaction, valid for a short period. It exists so that the number itself need not travel through intermediate systems.

Around these, the circulars created two tiers. A Global authentication user agency is one that some specific law or regulation requires to verify customers with the Aadhaar number, which broadly meant banks, life insurers and the national payments body; only those may receive full e-KYC including the number, and only those may store it, and then only inside an Aadhaar Data Vault, a segregated store inside the entity’s own infrastructure with key management and access control. A Local agency, covering telecom operators, housing finance companies, prepaid payment instrument issuers, non-life insurers, non-banking financial companies and digital locker and eSign providers, receives limited KYC, must use a Virtual ID for one-time-pin authentication, and may not store the number at all.

This is tokenisation, arriving in production in mid-2018, eight years after the first number was issued and three months before the constitutional judgment. It works. Its weakness is uptake at the resident’s end: the 2019 national survey found that only five per cent of holders had ever used a Virtual ID and seventy-seven per cent had never used any of the newer features. The UID Token, being invisible to the resident and mandatory for the entity, has been far more effective than the Virtual ID, which is voluntary and requires the resident to do something.

Puttaswamy 2017: privacy, and the three-part test#

On 24 August 2017 a nine-judge bench of the Supreme Court of India decided Justice K.S. Puttaswamy (Retd.) v Union of India, Writ Petition (Civil) No. 494 of 2012, reported at (2017) 10 SCC 1. It held unanimously that the right to privacy is protected as an intrinsic part of the right to life and personal liberty under Article 21 of the Constitution and as part of the freedoms in Part III, and it overruled the contrary holdings in M.P. Sharma, decided in 1954, and Kharak Singh, decided in 1962, to the extent they said otherwise.

The reason this matters to engineers rather than only to lawyers is the test it produced. A law or state action that intrudes on privacy must satisfy three requirements, and failing any one of them is fatal.

The first is legality: there must be an actual law. Not a policy, not a circular, not a contract. The second is need, meaning a legitimate state aim that the intrusion serves. The third is proportionality, meaning a rational connection between the aim and the means chosen, and that the means chosen are no more intrusive than necessary to achieve it.

That third limb is the one identity system designers should have taped to the wall. It is not enough that your data collection helps. You must be unable to achieve the same aim with less. A system that collects ten fingerprints where two would do, or stores five years of logs where six months would do, fails proportionality even if everything it does is useful.

The court’s own reasoning imported a fourth consideration in later application: procedural safeguards against abuse. In practice you will see the test stated as three parts or four depending on which judgment is being followed, and this is a real, live divergence in Indian constitutional doctrine rather than sloppiness by commentators.

Puttaswamy 2018: what was struck down#

On 26 September 2018 a five-judge bench decided the challenge to the Aadhaar Act itself, reported at (2018) 1 SCC 809. The outcome was 4 to 1. Sikri J wrote the majority for himself, Chief Justice Dipak Misra and Khanwilkar J; Bhushan J concurred separately on different reasoning; Chandrachud J dissented and would have struck the entire Act down, principally because it had been passed as a Money Bill, which limits the role of the upper house, and he held that this “debased” a constitutional institution.

The majority upheld the Act in the main, and applied the 2017 proportionality test to reach that result. It found that the enrolment data collected is minimal, that collection is purpose-blind in that the authority does not learn why an authentication is happening, and that information remains in silos. On that footing it held that Aadhaar does not create a surveillance state.

Then it dismantled specific provisions.

Provision Outcome in 2018
Section 7, subsidies Upheld
Section 57, private use Struck down in part
Section 33(2), security Struck down
Section 33(1), disclosure Read down
Regulation 27, retention Struck down
Section 2(d), metadata Struck down in part
Rule 9, bank linking Struck down
Mobile SIM linking Struck down
Section 139AA, PAN Upheld
Section 59, savings Upheld

Section 7, which lets government require authentication or proof of possession as a condition of a subsidy, benefit or service funded from the Consolidated Fund of India, survived, with its own proviso that a person without a number must be offered alternate and viable means of identification. Section 57, which had let any body corporate or person require authentication under a law or “any contract to this effect”, was struck down so far as it enabled private entities to compel authentication; the phrase about contracts was the target, because a contract is not a law and so fails the first limb of the proportionality test. Section 33(2), allowing disclosure on a senior officer’s authorization in the interest of national security, was struck down; section 33(1), allowing disclosure on a court’s order, was read down to require that the affected individual be heard. Regulation 27 of the 2016 Authentication Regulations, permitting five years’ retention of authentication transaction data, was struck down, the court holding retention beyond six months impermissible. The definition of authentication record in section 2(d) was struck down so far as it swept in transaction metadata. Mandatory linking of bank accounts under Rule 9 of the Prevention of Money-laundering (Maintenance of Records) Rules, 2005, and mandatory linking of mobile connections by departmental circular, both failed proportionality. Tax linking under section 139AA of the Income-tax Act was upheld. Section 47, allowing a prosecution only on the authority’s own complaint, was held by the majority to need amendment so that a victim can complain; Bhushan J would have upheld it as it stood.

The court also held that Aadhaar could not be made mandatory by the school examination boards or for university and medical entrance, since these are neither subsidies nor benefits from the Consolidated Fund, that no child may be denied a benefit for want of a number, that a parent’s consent is required to enrol a child, and that a child may opt out on turning eighteen. The banking consequences of all this are chapter 49’s subject and we leave them there.

The 2019 amendment and the 2025 rules#

Parliament answered with the Aadhaar and Other Laws (Amendment) Act, 2019, Act 14 of 2019, preceded by an Ordinance promulgated on 2 March 2019 and a Cabinet approval on 12 June 2019.

The substituted section 4(3), in force from 25 July 2019, is the pivot of the current regime. Every holder “may voluntarily use his Aadhaar number in physical or electronic form by way of authentication or offline verification”, and the explanation defines voluntary use as use “only with the informed consent” of the holder. Section 4(4) permits an entity to authenticate only if it is compliant with the authority’s privacy and security standards and either is permitted to offer authentication under a law made by Parliament or is seeking authentication for a purpose the central government prescribes in the interest of the State. Section 4(5) lets the authority decide by regulation whether an entity gets the real number or only a virtual identity. Section 4(6) obliges every requesting entity to inform the holder of alternate means of identification and forbids denial of service for refusing or failing authentication. Section 4(7) states that mandatory authentication for any service can be imposed only by a law made by Parliament. Section 57 was deleted outright. A new section 8A created offline verification as a distinct statutory mode, in which no request reaches the central database at all. New civil penalties, adjudicated by an officer of the authority with appeal to the telecom tribunal, reach one crore rupees per contravention.

Offline verification is the underrated part. Under regulation 3A of the 2021 Regulations there are five kinds: QR code verification, Aadhaar Paperless Offline e-KYC, electronic Aadhaar verification, offline paper-based verification, and anything else the authority adds. The paperless package is a digitally signed XML file containing the last four digits of the number, name, address, gender, date of birth and photograph, with mobile number and email present only as hashes, protected by a share code the resident chooses. The verifier validates the authority’s signature with a published public key and never contacts the authority at all. An Offline Verification Seeking Entity may not collect biometrics and must mask the number before storing anything. That is a verifiable credential in everything but name, and it predates most of the wallet standards now being written.

On 31 January 2025, notification G.S.R. 88(E) amended the Aadhaar Authentication for Good Governance (Social Welfare, Innovation, Knowledge) Rules, 2020, originally G.S.R. 490(E) of 5 August 2020. It added “promoting ease of living of residents and enabling better access to services for them” to the permitted purposes and, more significantly, rewrote rule 4 to create a route by which an entity other than a ministry or department may prepare a proposal, justify that it is for a permitted purpose and in the interest of the State, and submit it to the relevant ministry, which may forward it with a recommendation to the central government for reference to the authority. That is the door through which private entities re-entered the authentication ecosystem after section 57 was deleted, and it is narrow and supervised rather than the open door of before 2018. Rule 3(2) still says such authentication is voluntary.

India Stack: what was built on top#

The identity layer was designed as a base for other things, and the other things are now larger than the base in daily use. Three matter most.

eSign is an electronic signature service. Its legal basis is section 3A of the Information Technology Act, 2000, which recognizes electronic signatures using techniques listed in the Act’s Second Schedule, into which the e-authentication technique using Aadhaar e-KYC was notified. A signer authenticates to the authority, usually by one-time pin, and a Certifying Authority licensed by the Controller of Certifying Authorities issues a signing key and certificate that exist for one signature and are then discarded. There is no smart card, no token and no key for the signer to lose. The architecture separates the Application Service Provider, which holds the document, from the eSign Service Provider, which performs the authentication and signature, so the document never has to be handed to the certificate authority.

DigiLocker is a document store. It holds documents issued directly by their issuers in signed electronic form, so that a driving licence pulled from DigiLocker carries the transport authority’s signature rather than being a scan of a card. Per a government statement to Parliament on 18 March 2026, it had 67 crore registered users and over 967 crore documents issued through it. It is the answer to the photocopy problem, and its adoption is the best evidence that the photocopy problem was real.

The Account Aggregator network is consent infrastructure for financial data. It rests on the Reserve Bank of India’s Master Direction for non-banking financial companies acting as account aggregators, dated 2 September 2016, and works on a three-role model: a Financial Information Provider holds the data, a Financial Information User wants it, and the Account Aggregator brokers a signed, revocable, time-limited and purpose-limited consent between them without being able to read the data, which is encrypted end to end. The Department of Financial Services reports that as at 31 March 2026, 179 institutions were live as providers, 989 as users, over 2.88 billion accounts were enabled for sharing, and 284.6 million accounts had actually been linked by users. Seventeen aggregators hold a certificate of registration.

Layer Since Scale reported
Aadhaar numbers 2010 143 crore issued
DigiLocker 2015 967 crore documents
Account Aggregator 2016 284.6 mn accounts linked

Note the pattern. The identity layer answers “is this the same person”. The document layer answers “did an authority really say this”. The consent layer answers “did this person agree to this specific sharing”. Those are three different questions, and it took three separate systems to answer them.

The documented failures#

This is the part of the record that is most often skipped, and it is the reason this chapter exists.

Start with authentication failure. The Comptroller and Auditor General’s Report No. 24 of 2021 records what the authority told the auditor in October 2020: transaction-wise fingerprint authentication success had improved to 74 to 76 per cent in 2019-20, from 70 to 72 per cent in 2016-17. Read that as a failure rate. Roughly one in four fingerprint authentication attempts did not succeed, on the authority’s own numbers, at a point when the system was a decade old. The auditor added that the authority “did not have a system to analyse the factors leading to authentication errors”, and recommended that it build one.

The auditor found more. During 2018-19, over 73 per cent of 3.04 crore biometric updates were paid voluntary updates by residents whose biometrics were not reading, which the auditor read as evidence that the original capture quality had been inadequate, and it recommended that the authority stop charging people to fix its own capture failures. Some 37,551 numbers had been deactivated by 1 November 2019 over disputed identity documents. The authority had no data archival policy, and had not verified the infrastructure of requesting entities before onboarding them, despite the regulations requiring it.

Finding Figure As at
Fingerprint auth success 74 to 76 pc 2019-20
Duplicates cancelled over 4.75 lakh Nov 2019
Biometric updates, paid over 73 pc of 3.04 cr 2018-19
Deactivated, documents 37,551 Nov 2019

Now the survey evidence. The 2019 State of Aadhaar report, produced by Dalberg with funding from Omidyar Network India, covered over 167,000 residents across a 147,868-household pulse survey in 28 states and union territories and a 19,209-household in-depth survey in 16 states and one union territory, with fieldwork from May to September 2019. It remains the largest primary dataset on digital identity use anywhere.

Its findings cut both ways, and honest use of it means quoting both halves. Ninety-five per cent of adults had a number. Forty-nine per cent had used it to access at least one service for the first time, and for eight per cent it was their first identity document of any kind. Eighty per cent of recipients felt it had made rations, employment-guarantee work or pensions more reliable. Ninety-two per cent were satisfied and ninety per cent believed their data was safe.

And: eight per cent of people, an estimated 102 million, did not have a number, three-quarters of them children. Enrolment was 10 per cent in Assam and 39 per cent in Meghalaya, where residency disputes had stalled the rollout. Thirty per cent of homeless people and 27 per cent of third-gender people had no number, and of those, 84 and 85 per cent respectively wanted one and had failed to get it. Four per cent had an error on their card, most often the date of birth. Fifteen per cent had a wrong mobile number linked and another 39 per cent had none linked at all, so under half of adult holders could receive a one-time pin. A third of those who tried to correct an error found the process difficult and one in five failed outright.

On exclusion the survey is precise, and the precision is the point. Zero point eight per cent of people had been excluded, for Aadhaar-related reasons, from a welfare service they had previously received; the comparable figure for non-Aadhaar reasons was 3.3 per cent. One and a half per cent of ration users had a biometric authentication failure and did not get their rations at their last attempt, while 3.2 per cent had a failure and got their rations anyway, because the shopkeeper used an override. Sixty-seven per cent of the people who had been excluded because of Aadhaar were nonetheless satisfied with it.

Take that figure seriously in both directions. Zero point eight per cent is small, and it is also, across India’s welfare population, millions of people who lost a food entitlement they previously had. A rate that would be excellent uptime for a web service is unacceptable for a food ration, because the consequence is not a retry.

The research literature is sharper still, and this is where the experts genuinely disagree. Drèze, Khalid, Khera and Somanchi published “Aadhaar and Food Security in Jharkhand: Pain without Gain?” in the Economic and Political Weekly of 16 December 2017, arguing that compulsory biometric authentication in Jharkhand’s public distribution system imposed real costs on users while addressing only a minor channel of corruption. Muralidharan, Niehaus and Sukhtankar, in National Bureau of Economic Research working paper 26744 of February 2020, revised September 2021, evaluated the same reforms with randomized and natural experiments and reached a mixed result: corruption fell, but “1.5 to 2 million” legitimate beneficiaries lost access to benefits at some point during the reforms, and the adverse effects were driven primarily by how the transition was managed rather than by the technology itself. Those two teams have publicly disputed each other’s reading of overlapping data. Both agree that exclusion happened at the scale of millions.

There is one more category: misuse by legitimate participants. In December 2017 the authority suspended Airtel and Airtel Payments Bank’s authentication licence after finding that retail agents verifying customers’ fingerprints for SIM cards were using the same verification to open bank accounts the customers had not asked for. Because subsidy payments route to whichever account is most recently linked to a person’s number, cooking-gas subsidy of the order of 190 crore rupees was redirected into over three million unrequested accounts. Nothing was hacked; every authentication was valid. The design flaw was that a single “yes” carried no statement of what the person was consenting to, so one authentication could be spent on a second, unrelated action.

In January 2018 The Tribune reported that its journalists had paid a small sum over a messaging application for ten minutes of unrestricted access to a portal returning name, address, photograph and phone number for any Aadhaar number. The authority called the report misreporting and filed a police complaint. Whatever view one takes of that response, the episode is why the Global and Local classification and the storage prohibition arrived four months later.

DPDP 2023 and what changes for Aadhaar-linked processing#

The Digital Personal Data Protection Act, 2023 was enacted by Parliament on 11 August 2023 and sat without operative rules for over two years. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and they bring the Act into force in stages.

Stage Date What starts
One 13 Nov 2025 Data Protection Board
Two 13 Nov 2026 Consent Manager registry
Three 13 May 2027 Main duties apply

For anyone building on Aadhaar, five changes matter.

First, consent becomes itemised. A notice must list each item of personal data being processed and tie it to a specified purpose, with a link by which consent can be withdrawn and complaints filed. A blanket “I agree to Aadhaar e-KYC” will not survive that. Where a relying party today pulls a full e-KYC file because it is easier, it will have to justify each field.

Second, security safeguards become prescriptive rather than aspirational. Rule 6 requires encryption or masking, access control, logging and monitoring, backups, and retention of logs of unauthorized access for at least one year. For an entity holding Aadhaar numbers, this stacks on top of the existing Aadhaar Data Vault obligation rather than replacing it.

Third, breach notification is unconditional. Affected individuals must be told promptly, in plain language, and a detailed report goes to the Board within 72 hours. There is no harm threshold: on a plain reading, every personal data breach is reportable. The Schedule to the Act sets maximum penalties measured in hundreds of crores of rupees, with the largest attaching to failure to take reasonable security safeguards.

Fourth, verifiable parental consent is required for anyone under eighteen, and the Rules specifically name virtual identity tokens as one acceptable mechanism, which points directly back at the Virtual ID construct built in 2018 for a different reason.

Fifth, and most contested, the Act preserves broad room for the State. Processing by the State to provide a subsidy, benefit, service, certificate, licence or permit is a listed legitimate use needing no fresh consent where the individual has previously consented or the data sits in a notified government database, and the central government may exempt notified instrumentalities of the State from most of the Act. The same Act amended section 8(1)(j) of the Right to Information Act, 2005, removing the public-interest override that previously allowed disclosure of personal information. Supporters say this aligns transparency law with privacy law; critics say it weakens the main tool citizens had for auditing exactly the kind of programme this chapter describes. That disagreement is live as of August 2026.

Sunita, end to end#

Let us finish the worked example, because the abstractions land differently when they happen to one person.

Sunita enrolled, was deduplicated against the gallery, and received the number 4321 9876 5432. At the ration shop the dealer’s device builds an Auth document with uid set to her number, Uses bio="y" bt="FMR", a PID block encrypted on the device with a fresh AES-256 key that is itself wrapped with the authority’s RSA public key, and the dealer’s signature over the whole thing. It travels to an authentication service agency and over a private link to the repository, which does a one-to-one comparison and returns a signed AuthRes.

The first attempt returns ret="n" with err="300", biometric mismatch. Sunita has worked in fields for twenty years and her ridges are shallow. She tries a second finger. It fails again. On the published figures, roughly one attempt in four ends like this, and the failure is not hers.

Four things can save this, and each needs something she may not have. If her phone number is correctly linked, the dealer can switch to a one-time pin, but under half of adult holders have a correct number linked. If the device supports iris, her irises are unaffected by manual work and will very likely read. If the state permits it, the dealer can override and record the reason, as happened to the 3.2 per cent of ration users in the 2019 survey who got grain despite a failure. If none is available she goes home, and she is in the 1.5 per cent.

Later she opens a bank account. Here the bank uses e-KYC, not Yes/No: she consents, authenticates by one-time pin, and the repository returns a signed package with her name, date of birth, gender, address and photograph. Because a scheduled commercial bank is a Global agency, the response may include her Aadhaar number, and the bank may store it, but only inside an Aadhaar Data Vault. The bank pays 20 rupees. Her mobile operator, a Local agency, gets limited KYC keyed to a UID Token, cannot store her number, and must use a Virtual ID. From 13 May 2027 the bank’s consent notice must itemise every field it takes and why.

If she wants to prove her address to a landlord, the best answer is none of the above. It is offline verification: she downloads a signed XML package with a share code of her choosing, or lets him scan the secure QR code on her letter, and he verifies the authority’s signature with a published public key. No request reaches the repository and he may not take her biometrics. It is the safest path in the system, and in 2019 only nineteen per cent of holders had ever used a QR code at all.

50.98 Common wrong ideas#

Wrong: Aadhaar is an identity card. Right: It is a twelve-digit number held in a central database with a small set of demographic and biometric fields; the printed letter and the plastic card merely carry the number, and under section 4 of the Aadhaar Act, 2016 it is the number, verified by authentication or offline verification, that has legal effect.

Wrong: Aadhaar proves you are an Indian citizen. Right: Section 9 of the Act says in terms that the number and its authentication shall not by themselves confer any right of, or be proof of, citizenship or domicile; eligibility rests on residence in India for 182 days or more in the preceding twelve months under section 2(v), which the Comptroller and Auditor General found in its 2021 report was established only by self-declaration.

Wrong: Biometric deduplication guarantees that nobody holds two numbers. Right: Matching produces scores against a threshold, and the authority’s own 2012 analysis of 84 million enrolments reported a false negative identification rate of 0.035 per cent, while the Comptroller and Auditor General’s Report No. 24 of 2021 found more than 4.75 lakh duplicates cancelled by November 2019 and a deduplication process that “remained vulnerable” to generating them.

Wrong: The Supreme Court banned Aadhaar, or alternatively upheld it entirely. Right: The judgment of 26 September 2018, reported at (2018) 1 SCC 809, upheld the Act 4 to 1 including section 7 for subsidies and section 139AA for tax linking, while striking down section 33(2), the private-use limb of section 57, Regulation 27’s five-year retention in favour of six months, the metadata limb of section 2(d), Rule 9 bank linking and mandatory mobile linking.

Wrong: Knowing someone’s Aadhaar number lets you impersonate them. Right: The online path requires a fingerprint, an iris, a face or a one-time pin in addition to the number, and the authority returns only yes or no; the real exposure is the paper path, where a photocopy carrying the number, name, address and photograph is accepted with no check at all, which is what DigiLocker and offline verification exist to displace.

Wrong: Virtual ID and tokenisation were part of the original design. Right: They arrived by circular on 10 January 2018, with a migration deadline of 1 July 2018 set by Circular No. 05 of 2018, eight years after the first number was issued and during the constitutional hearings; the 2019 national survey found only five per cent of holders had ever used a Virtual ID.

Wrong: Authentication failure is rare. Right: The authority told the national auditor in October 2020 that transaction-wise fingerprint authentication success had reached 74 to 76 per cent in 2019-20, up from 70 to 72 per cent in 2016-17, meaning roughly a quarter of fingerprint attempts failed, and the auditor separately found that the authority had no system for analysing the causes of those failures.

Wrong: Aadhaar has saved India lakhs of crores by removing fake beneficiaries. Right: The government’s direct-benefit-transfer programme reports cumulative gains of about 3.48 lakh crore rupees, but that figure has been challenged in detail for conflating money routed through the new payment system with fraud actually eliminated, and for counting excluded eligible people as removed ghosts; no study has cleanly separated the two at national scale.

Wrong: The Digital Personal Data Protection Act, 2023 is already in force for everyone. Right: The Act was passed on 11 August 2023 but the Rules notified on 13 November 2025 phase it in, with the Data Protection Board from 13 November 2025, Consent Manager registration from 13 November 2026, and the substantive obligations on notice, security, breach reporting and data principal rights only from 13 May 2027.

Wrong: Aadhaar authentication tells the central database what you were buying. Right: The request carries the number, the factors used and device metadata but not the purpose, which is why the 2018 majority called the collection purpose-blind; the correlation risk lies in relying parties storing the same number in their own systems, which is what UID Token and the storage ban on Local agencies were built to prevent.

50.99 Chapter summary in 20 lines#

  1. Aadhaar is a twelve-digit random number issued to a resident of India and held with a small set of demographic and biometric fields in the Central Identities Data Repository; it is neither a card nor proof of citizenship.
  2. Section 2(k) of the Aadhaar Act, 2016 excludes race, religion, caste, tribe, ethnicity, language, records of entitlement, income and medical history from the demographic data that may be collected.
  3. Enrolment captures ten fingerprints, both irises and a facial photograph for everyone aged five and over, with children under five enrolled on the facial image alone and required to update at five and fifteen.
  4. The last digit of the number is a Verhoeff check digit, an algorithm published in 1969 that catches every single-digit error and every adjacent transposition before a request leaves the building.
  5. Deduplication is a one-to-many search whose cost grows with the square of the population, mitigated by bucketing, by fusing fingerprints with irises, and by running three independent matching engines.
  6. The authority’s January 2012 analysis of 84 million enrolments reported a failure-to-enrol rate of 0.14 per cent and a false negative identification rate of 0.035 per cent, figures that scale to millions of people at national population size.
  7. The Comptroller and Auditor General’s Report No. 24 of 2021, tabled in April 2022, found the 99.9 per cent accuracy claim self-reported, the deduplication process vulnerable, and over 4.75 lakh duplicate numbers cancelled by November 2019.
  8. Regulation 4(2) of the Aadhaar (Authentication and Offline Verification) Regulations, 2021 provides four modes: demographic, one-time pin, biometric and multi-factor, with face added later as a biometric modality.
  9. Regulation 9(4) requires the Aadhaar number in every request so that authentication is always reduced to a one-to-one match, and regulation 9(5) requires the personal identity data block to be encrypted at the moment of capture on the device.
  10. Aadhaar Authentication API 2.5 wraps a fresh AES-256 session key with the authority’s 2048-bit RSA public key, carries the encrypted data block and a keyed hash, and returns a signed response carrying only yes or no.
  11. The Aadhaar (Pricing of Aadhaar Authentication Services) Regulations, 2019 charge 20 rupees for an e-KYC transaction and 50 paise for a Yes/No authentication, with government entities exempt.
  12. Virtual ID is a revocable sixteen-digit alias that no entity may store, UID Token is a 72-character string unique to one requesting entity that solves the cross-database linking problem, and ANCS Token covers a single transaction.
  13. Circular No. 05 of 2018 split requesting entities into Global agencies, which may store the number in an Aadhaar Data Vault, and Local agencies, which get limited KYC and may not store it at all.
  14. The nine-judge judgment of 24 August 2017, reported at (2017) 10 SCC 1, held privacy a fundamental right under Article 21 and set the test of legality, legitimate state aim and proportionality.
  15. The five-judge judgment of 26 September 2018, reported at (2018) 1 SCC 809, upheld the Act 4 to 1 but struck down section 33(2), the private-use limb of section 57, five-year log retention, the metadata limb of section 2(d), and mandatory bank and mobile linking.
  16. The Aadhaar and Other Laws (Amendment) Act, 2019 deleted section 57, made use voluntary and consent-based under a substituted section 4(3), created statutory offline verification in section 8A, and added civil penalties up to one crore rupees.
  17. Notification G.S.R. 88(E) of 31 January 2025 reopened a supervised route by which non-government entities may apply, through a sponsoring ministry, to perform Aadhaar authentication in the interest of the State.
  18. India Stack layers eSign under section 3A of the Information Technology Act, DigiLocker with 67 crore users and 967 crore documents, and the Account Aggregator network with 284.6 million linked accounts as at 31 March 2026.
  19. The 2019 State of Aadhaar survey of over 167,000 residents found 95 per cent adult coverage and 92 per cent satisfaction alongside 102 million people without a number, 0.8 per cent excluded from a welfare service for Aadhaar reasons, and 1.5 per cent of ration users denied grain after a biometric failure.
  20. The Digital Personal Data Protection Rules, 2025, notified on 13 November 2025, phase the 2023 Act in over eighteen months, with itemised consent, prescriptive security safeguards, 72-hour breach reporting and data principal rights all applying from 13 May 2027.

Chapter sources: the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, Act 18 of 2016, enacted 25 March 2016, in particular sections 2(d), 2(g), 2(h), 2(j), 2(k), 2(v), 3, 4, 5, 7, 8, 9, 10, 22, 23, 33, 47, 53, 54, 57 and 59, as amended by the Aadhaar and Other Laws (Amendment) Act, 2019, Act 14 of 2019, whose substituted section 4(3) took effect on 25 July 2019, following the Ordinance of 2 March 2019 and Cabinet approval of 12 June 2019; the Aadhaar (Enrolment and Update) Regulations, 2016; the Aadhaar (Authentication and Offline Verification) Regulations, 2021, notification No. K-11020/240/2021/Auth/UIDAI (No. 2 of 2021) of 8 November 2021, Gazette Extraordinary Part III Section 4 No. 542 of 9 November 2021, amended 4 February 2022, 27 February 2023, 3 October 2023 and 31 January 2024, in particular regulations 2(1)(ba), 2(1)(oc), 2(1)(od), 3, 3A, 4, 4A, 9, 16A and 18; the Aadhaar (Pricing of Aadhaar Authentication Services) Regulations, 2019; UIDAI Circular No. K-11020/217/2018-UIDAI (Auth-I) of 10 January 2018 and Circular No. 05 of 2018 of 16 May 2018, with the migration deadline of 1 July 2018; Aadhaar Authentication API 2.5, Revision 1, of January 2022, and the version 2.5 authentication, e-KYC and OTP request APIs of 2 April 2018; the Aadhaar Authentication for Good Governance (Social Welfare, Innovation, Knowledge) Rules, 2020, G.S.R. 490(E) of 5 August 2020, as amended by G.S.R. 88(E) of 31 January 2025; Justice K.S. Puttaswamy (Retd.) v Union of India, Writ Petition (Civil) No. 494 of 2012, judgment of 24 August 2017, (2017) 10 SCC 1; Justice K.S. Puttaswamy (Retd.) v Union of India, judgment of 26 September 2018, (2018) 1 SCC 809, with the majority of Sikri J, the concurrence of Bhushan J and the dissent of Chandrachud J; the Digital Personal Data Protection Act, 2023, enacted 11 August 2023, and the Digital Personal Data Protection Rules, 2025 notified 13 November 2025 with the phased commencement announced by the Ministry of Electronics and Information Technology on 14 November 2025; the Information Technology Act, 2000 section 3A and its Second Schedule; the Reserve Bank of India Master Direction for Non-Banking Financial Company Account Aggregators of 2 September 2016, with the Department of Financial Services progress update as on 31 March 2026; UIDAI, “The Role of Biometric Technology in Aadhaar Enrolment”, 23 January 2012, with the Press Information Bureau release of the same date; Comptroller and Auditor General of India, Report No. 24 of 2021, performance audit of the Unique Identification Authority of India, tabled April 2022; Press Information Bureau releases of 18 March 2026 on live Aadhaar holders, cumulative authentication transactions and DigiLocker; UIDAI announcements of February 2026 on the in-house AI-based deduplication platform built with IIIT Hyderabad and the Aadhaar mobile application launched in January 2026; UIDAI office memoranda of 13 May 2026 and 18 June 2026 on update fee waivers; Totapally, Sonderegger, Rao, Gosselt and Gupta, State of Aadhaar Report 2019, Dalberg; Dreze, Khalid, Khera and Somanchi, “Aadhaar and Food Security in Jharkhand: Pain without Gain?”, Economic and Political Weekly volume 52 issue 50, 16 December 2017; Muralidharan, Niehaus and Sukhtankar, “Identity Verification Standards in Welfare Programs: Experimental Evidence from India”, NBER Working Paper 26744, February 2020, revised September 2021; Agrawal, Banerjee and Sharma, “Privacy and Security of Aadhaar: A Computer Science Perspective”, Economic and Political Weekly volume 52 issue 37, 2017; Subhashis Banerjee, “Aadhaar’s Success Story Deserves a Closer Look”, Tech Policy Press, 14 August 2026; the Direct Benefit Transfer Mission’s estimated cumulative gains and Reetika Khera’s published critique of that figure; the UIDAI suspension of Airtel and Airtel Payments Bank’s authentication licence in December 2017; and The Tribune report of January 2018 on unrestricted portal access with the authority’s response.