No data breach from UIDAI’s data repository: RS Prasad

Strengthening of security of data is an ongoing process and all possible steps are being taken, said Ravi Shankar Prasad

GN Bureau | February 8, 2018


#RS Prasad   #UIDAI   #Lok Sabha   #Aadhaar   #Privacy  


The government maintains that there has been no breach of Aadhaar data.

“As on date, no incident of data breach has been reported from Central Identities Data Repository (CIDR) of Unique Identification Authority of India (UIDAI),” union minister Ravi Shankar Prasad informed parliament.

He said that UIDAI has a well-designed, multi-layered robust security system in place and the same is being constantly upgraded to maintain the highest level of data security and integrity. UIDAI has adequate legal, organizational and technological measures in place for the security of the data stored with UIDAI. Data Protection measures have also been mandated for the requesting entities and ecosystem partners to ensure the security of data.

Read: Aadhaar database: Not secure anymore?

The minister said that the government is fully alive to the need to maintain highest level of data security, privacy and is deploying the necessary technology and infrastructure. The architecture of Aadhaar ecosystem has been designed to ensure non-duplication, data integrity and other related management aspects of security & privacy in Aadhaar database. Additionally, various policies and procedures have been defined clearly which are reviewed and updated periodically, thereby, appropriately controlling and monitoring security of data.

Some of the security measures adopted by UIDAI are:

Information security policy has been established based on the ISO 27001:2013 standard. The policy covers all areas of Information Security such as Organization of Information Security, Asset management, Access control, Technical vulnerability management, Change management, Patch management, Encryption, Service continuity, Operations security, Communications security, Supplier security, Human resources security etc.

Chief Information Security officer has been appointed to drive Information security measures in UIDAI along with a dedicated security team to implement the various security processes and technology to ensure security of CIDR.

UIDAI-CIDR is ISO 27001:2013 certified since 2015 and since then undergoes through yearly surveillance audits from STQC.

GRCP-SP (Governance, Risk, Compliance, Performance service provider) has been appointed to perform periodic monitoring of the security of internal and external ecosystem.

The security audit of UIDAI is conducted by three separate entity viz. Internal, External (GRCP) and STQC on a periodic basis.

Periodic assessments are conducted for the ecosystem partners to ensure compliance on the Information Security policy.

Prasad went on to say that there are multiple layers of security at physical level in UIDAI Data Centres and is being managed by armed CISF personnel round the clock. Strengthening of security of data is an ongoing process and all possible steps are being taken in this regard.

The minister said that the Aadhaar Act, 2016 and subsequent regulations framed thereunder, have adequate safeguards. Sharing of information or seeding of Aadhaar information with the authorised agencies is governed as per the provisions of the Aadhaar Act 2016 which categorically states that no core biometric information, collected or created under the Aadhaar Act, shall be shared with anyone for any reason whatsoever; or used for any purpose other than generation of Aadhaar numbers and authentication under the Act. Also, Regulation 4(1) of the Aadhaar (Sharing of information) Regulations, 2016 provides that core biometric information collected or captured by a requesting entity from Aadhaar number holder at the time of authentication shall not be shared for any reason whatsoever.

He added that regulation 4(2) of the Aadhaar (Sharing of information) Regulations, 2016 provides that identity information available with a requesting entity shall not be used for any purpose other than that specified to the Aadhaar number holder at the time of submitting identity information for authentication and shall not be disclosed further without the prior consent of the Aadhaar number holder.

Any violation to the provisions of the Aadhaar Act, 2016 is a criminal offence.

Read: Aadhaar: On a sticky wicket

 

Comments

 

Other News

How Rafi, Raj Kapoor helped pave the way for a great uranium deal

There`s a certain moment in diplomacy that`s too personal to be captured in a communiqué, too small to make the front page, but more revealing than the front page. This week, prime minister Narendra Modi reached Tashkent and, amid the pomp of state visits, managed to evoke the old Bollywood tunes

Distinguishing Fish 1 and Fish 2: The pragmatism behind India’s WTO ratification

 India became the 123rd WTO member to ratify the multilateral Agreement on Fisheries subsidies (AoFS) when it deposited the Instrument of Acceptance for Phase 1 on July 20, 2026. The ratification is restricted to disciplining Illegal, Unreported and Unregulated fishing (IUU), protection for overfished

The 7% growth problem: Why the next 7% will be harder

India has become accustomed to hearing the 7% growth number. It is now less a milestone than an expectation. Yet the paradox is becoming clearer: maintaining 7% growth may be considerably harder than achieving it once. India’s real GDP grew 7.7% in FY2025–26, following growth of 6.5% in FY202

The Constitution cannot be altered: Justice Abhay Oka

Justice Abhay Oka, who retired from the Supreme Court in May 2025, has said that the Constitution of India cannot be altered. Explaining the landmark Kesavananda Bharati judgment (1973) on the basic structure of the Constitution, he said, “This is one judgment that has saved democracy in India.&rdq

How the flora and fauna evolved in the Indian subcontinent

Mammals of India  By A.J.T. Johnsingh and P.O. Nameer HarperCollins India in association with Bombay Natural History Society  

India`s renewable race is moving beyond megawatts

When Shell bought Sprng Energy in 2022, India`s renewable energy market appeared to offer precisely what global energy majors were seeking: scale, growth and a place in one of the world`s largest energy transitions. Four years later, Shell is selling the same business to Aditya Birla Group for an enterpris

Upcoming Conferences



-->

Archives

Current Issue

Opinion

Facebook Twitter Google Plus Linkedin Subscribe Newsletter

Twitter