THE AADHAAR (TARGETED DELIVERY OF FINANCIAL AND OTHER SUBSIDIES, BENEFITS AND SERVICES) ACT, 2016
Chapter VI PROTECTIONOF INFORMATION
Chapter VI PROTECTIONOF INFORMATION
28. Security and confidentiality of information
(1) The Authority shall ensure the security of identity information and authentication records of individuals. (2) Subject to the provisions of this Act, the Authority shall ensure confidentiality of identity information and authentication records of individuals. (3) The Authority shall take all necessary measures to ensure that the information in the possession or control of the Authority, including information stored in the Central Identities Data Repository, is secured and protected against access, use or disclosure not permitted under this Act or regulations made thereunder, and against accidental or intentional destruction, loss or damage. (4) Without prejudice to sub-sections (1) and (2), the Authority shall— (a) adopt and implement appropriate technical and organisational security measures; (b) ensure that the agencies, consultants, advisors or other persons appointed or engaged for performing any function of the Authority under this Act, have in place appropriate technical and organisational security measures for the information; and (c) ensure that the agreements or arrangements entered into with such agencies, consultants, advisors or other persons, impose obligations equivalent to those imposed on the Authority under this Act, and require such agencies, consultants, advisors and other persons to act only on instructions from the Authority. (5) Notwithstanding anything contained in any other law for the time being in force, and save as otherwise provided in this Act, the Authority or any of its officers or other employees or any agency that maintains the Central Identities Data Repository shall not, whether during his service or thereafter, reveal any information stored in the Central Identities Data Repository or authentication record to anyone: Provided that an Aadhaar number holder may request the Authority to provide access to his identity information excluding his core biometric information in such manner as may be specified by regulations.
Chapter VI PROTECTIONOF INFORMATION
29. Restriction on sharing information
(1) No core biometric information, collected or created under this Act, shall be— (a) shared with anyone for any reason whatsoever; or (b) used for any purpose other than generation of Aadhaar numbers and authentication under this Act. (2) The identity information, other than core biometric information, collected or created under this Act may be shared only in accordance with the provisions of this Act and in such manner as may be specified by regulations. (3) No identity information available with a requesting entity or offline verification-seeking entity shall be— (a) used for any purpose, other than the purposes informed in writing to the individual at the time of submitting any information for authentication or offline verification; or (b) disclosed for any purpose, other than purposes informed in writing to the individual at the time of submitting any information for authentication or offline verification: Provided that the purposes under clauses (a) and (b) shall be in clear and precise language understandable to the individual. (4) No Aadhaar number, demographic information or photograph collected or created under this Act in respect of an Aadhaar number holder shall be published, displayed or posted publicly, except for the purposes as may be specified by regulations.
Chapter VI PROTECTIONOF INFORMATION
30. Biometric information deemed to be sensitive personal information
The biometric information collected and stored in electronic form, in accordance with this Act and regulations made thereunder, shall be deemed to be “electronic record” and “sensitive personal data or information”, and the provisions contained in the Information Technology Act, 2000 (21 of 2000) and the rules made thereunder shall apply to such information, in addition to, and to the extent not in derogation of the provisions of this Act. Explanation.— For the purposes of this section, the expressions— (a) “electronic form” shall have the same meaning as assigned to it in clause (r) of sub-section (1) of section 2 of the Information Technology Act, 2000 (21 of 2000); (b) “electronic record” shall have the same meaning as assigned to it in clause (t) of sub-section (1) of section 2 of the Information Technology Act, 2000 (21 of 2000); (c) “sensitive personal data or information” shall have the same meaning as assigned to it in clause (iii) of the Explanation to section 43A of the Information Technology Act, 2000 (21 of 2000).
Chapter VI PROTECTIONOF INFORMATION
31. Alteration of demographic information or biometric information
(1) In case any demographic information of an Aadhaar number holder is found incorrect or changes subsequently, the Aadhaar number holder shall request the Authority to alter such demographic information in his record in the Central Identities Data Repository in such manner as may be specified by regulations. (2) In case any biometric information of Aadhaar number holder is lost or changes subsequently for any reason, the Aadhaar number holder shall request the Authority to make necessary alteration in his record in the Central Identities Data Repository in such manner as may be specified by regulations. (3) On receipt of any request under sub-section (1) or sub-section (2), the Authority may, if it is satisfied, make such alteration as may be required in the record relating to such Aadhaar number holder and intimate such alteration to the concerned Aadhaar number holder. (4) No identity information in the Central Identities Data Repository shall be altered except in the manner provided in this Act or regulations made in this behalf.
Chapter VI PROTECTIONOF INFORMATION
32. Access to own information and records of requests for authentication
(1) The Authority shall maintain authentication records in such manner and for such period as may be specified by regulations. (2) Every Aadhaar number holder shall be entitled to obtain his authentication record in such manner as may be specified by regulations. (3) The Authority shall not, either by itself or through any entity under its control, collect, keep or maintain any information about the purpose of authentication.
Chapter VI PROTECTIONOF INFORMATION
33. Disclosure of information in certain cases
(1) Nothing contained in sub-section (2) or sub-section (5) of section 28 or sub-section (2) of section 29 shall apply in respect of any disclosure of information, including identity information or authentication records, made pursuant to an order of a court not inferior to that of a Judge of a High Court: Provided that no order by the court under this sub-section shall be made without giving an opportunity of hearing to the Authority and the concerned Aadhaar number holder. Provided further that the core biometric information shall not be disclosed under this sub-section. (2) Nothing contained in sub-section (2) or sub-section (5) of section 28 and clause (b) of sub-section (1), sub-section (2) or sub-section (3) of section 29 shall apply in respect of any disclosure of information, including identity information or authentication records, made in the interest of national security in pursuance of a direction of an officer not below the rank of Secretary to the Government of India specially authorised in this behalf by an order of the Central Government: Provided that every direction issued under this sub-section, shall be reviewed by an Oversight Committee consisting of the Cabinet Secretary and the Secretaries to the Government of India in the Department of Legal Affairs and the Department of Electronics and Information Technology, before it takes effect: Provided further that any direction issued under this sub-section shall be valid for a period of three months from the date of its issue, which may be extended for a further period of three months after the review by the Oversight Committee.
Chapter VI PROTECTIONOF INFORMATION
33A. Penalty for failure to comply with provisions of this Act, rules, regulations and directions
(1) Where an entity in the Aadhaar ecosystem fails to comply with the provision of this Act, the rules or regulations made there under or directions issued by the Authority under section 23A, or fails to furnish any information, document, or return of report required by the Authority, such entity shall be liable to a civil penalty which may extend to Rs. 1,00,00,000 for each contravention and in case of a continuing failure, with additional penalty which may extend to Rs. 10,00,000 for every day during which the failure continues after the first contravention. (2) The amount of any penalty imposed under this section, if not paid, may be recovered as if it were an arrear of land revenue.
Chapter VI PROTECTIONOF INFORMATION
33B. Power to adjudicate
(1) For the purposes of adjudication under section 33A and imposing a penalty there under, the Authority shall appoint an officer of the Authority, who is not below the rank of a Joint Secretary to the Government of India and possessing such qualification and experience as may be prescribed, to be an Adjudicating Officer for holding an inquiry in such manner as may be prescribed. (2) No inquiry under sub-section (1) shall be initiated except by a complaint made by the Authority. (3) While holding an inquiry, the Adjudicating Officer shall— (a) provide the entity in the Aadhaar ecosystem against whom complaint is made, an opportunity of being heard; (b) have the power to summon and enforce the attendance of any person acquainted with the facts and circumstances of the case to give evidence or to produce any document which, in the opinion of the Adjudicating Officer, may be useful for or relevant to the subject matter of the inquiry. (4) If the Adjudicating Officer, on such inquiry, is satisfied that the entity in the Aadhaar ecosystem has failed to comply with any provision of this Act or the rules or regulations made there under or directions issued by the Authority under section 23A, or has failed to furnish any information, document, or return of report required by the Authority, the Adjudicating Officer may, by order, impose such penalty under section 33A as he thinks fit.
Chapter VI PROTECTIONOF INFORMATION
33C. Appeals to Appellate Tribunal
(1) The Telecom Disputes Settlement and Appellate Tribunal established under section 14 of the Telecom Regulatory Authority of India Act, 1997 (24 of 1997), shall be Appellate Tribunal for the purposes of hearing appeals against the decision of the Adjudicating Officer under this Act. (2) A person or entity in the Aadhaar ecosystem aggrieved by an order of the Adjudicating Officer under section 33B, may prefer an appeal to the Appellate Tribunal within a period of forty-five days from the date of receipt of the order appealed against, in such form and manner and accompanied with such fee as may be prescribed: Provided that the Appellate Tribunal may entertain an appeal after the expiry of the said period of forty-five days if it is satisfied that there was sufficient cause for not filing it within that period. (3) On receipt of an appeal under sub-section (2), the Appellate Tribunal may, after giving the parties to the appeal an opportunity of being heard, pass such orders thereon as it thinks fit, confirming, modifying or setting aside the order appealed against. (4) The Appellate Tribunal shall send a copy of every order made by it to the parties to the appeal and to the Adjudicating Officer. (5) Any appeal filed under sub-section (2) shall be dealt with by the Appellate Tribunal as expeditiously as possible and every endeavour shall be made by it to dispose of the appeal within six months from the date on which it is presented to it. (6) The Appellate Tribunal may, for the purpose of deciding an appeal before it, call for the records relevant to disposing of such appeal and make such orders as it thinks fit.
Chapter VI PROTECTIONOF INFORMATION
33D. Procedure and powers of the Appellate Tribunal
The provisions of sections 14-I to 14K (both inclusive), 16 and 17 of the Telecom Regulatory Authority of India Act, 1997 (24 of 1997) shall, mutatis mutandis, apply to the Appellate Tribunal in the discharge of its functions under this Act, as they apply to it in the discharge of its functions under that Act.
Chapter VI PROTECTIONOF INFORMATION
33E. Appeal to Supreme Court of India
(1) Notwithstanding anything contained in the Code of Civil Procedure, 1908 (5 of 1908) or in any other law for the time being in force, an appeal shall lie against any order, not being an interlocutory order, of the Appellate Tribunal to the Supreme Court on any substantial question of law arising out of such order. (2) No appeal shall lie against any decision or order made by the Appellate Tribunal which the parties have consented to. (3) Every appeal under this section shall be preferred within a period of forty-five days from the date of the decision or order appealed against: Provided that the Supreme Court may entertain an appeal after the expiry of the said period of forty-five days if it is satisfied that there was sufficient cause for not filing it within that period.
Chapter VI PROTECTIONOF INFORMATION
33F. Civil court not to have jurisdiction
No civil court shall have jurisdiction to entertain any suit or proceeding in respect of any matter which an Adjudicating Officer appointed under this Act or the Appellate Tribunal is empowered, by or under this Act to determine, and no injunction shall be granted by any court or other authority in respect of any action taken or to be taken in pursuance of any power conferred by or under this Act.
PDF: pending for this language.