Aadhaar now shapes daily life in India. Banks ask for it. Welfare schemes rely on it. Meanwhile, courts keep testing its limits. Therefore, you need clear answers about the law behind the number. This guide explains the Aadhaar Act 2016 in plain words. It covers the statute, the regulations, key court rulings, and updates through 2026. Moreover, it shows what individuals and businesses must do to stay compliant. Whether you run a fintech startup or apply for a welfare scheme, the Aadhaar Act 2016 affects you directly. Read on for a clear walkthrough, section by section.
Quick answer: The Aadhaar Act 2016 is the central law that creates the Aadhaar number and the Unique Identification Authority of India (UIDAI). It sets rules for enrolment, authentication, data security, and penalties. In short, it turns Aadhaar from an executive scheme into a statutory system. Readers who search for the Aadhaar Act 2016 bare act will find the full text on India Code, and this article explains it step by step.
What Is the Aadhaar Act 2016? Meaning and Purpose
Definition in Simple Words
The Aadhaar Act 2016 is Act No. 18 of 2016. Its full title is the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016. The law creates a legal basis for the Aadhaar number. It also creates UIDAI as a statutory authority.
Two features make the Aadhaar Act 2016 unusual. First, it regulates a database rather than a document. Second, it sits where welfare law, privacy law, and technology law meet. Accordingly, advocates in many fields now cite it.
Under the law, every resident can obtain a twelve-digit number. UIDAI issues it after collecting demographic and biometric data. Later, the number helps verify identity online or offline. Thus, the Act links identity, data, and public service delivery in one framework.
Long Title and Objectives
The long title reveals the goal. Parliament wanted efficient, transparent, and targeted delivery of subsidies, benefits, and services. The money must come from the Consolidated Fund of India. Besides, the law promotes good governance by reducing leakage and duplicate identities.
Notably, the Act does not create a general-purpose identity card. Instead, it ties Aadhaar to a welfare purpose. However, later amendments and rules widened the possible uses. The sections below trace that shift step by step.
Practitioners should read the preamble alongside Section 7. Together, they show that Parliament framed Aadhaar as a welfare-delivery tool, not a universal ID. In other words, the Aadhaar Act 2016 starts from subsidy delivery and grows outward.
Why Parliament Passed the Aadhaar Act 2016
The Road to a Statute
UIDAI began in 2009 through an executive notification. For that reason, the project ran for years without a parent statute. Critics questioned that gap. Courts also asked about legal backing. In response, Parliament passed the law in March 2016. The President gave assent on 25 March 2016. Most provisions took effect on 12 September 2016. This history explains why the Aadhaar Act 2016 opens with such detailed rules on authority, data, and offences.
The Money Bill Controversy
The government introduced the Bill as a Money Bill. As a result, the Rajya Sabha could only recommend changes. The Lok Sabha rejected those recommendations. Many lawyers objected to this route. They argued that the Bill covered far more than money matters. Later, the Supreme Court examined that argument. A majority accepted the Money Bill route. Justice D.Y. Chandrachud disagreed strongly. His dissent still shapes debates on parliamentary process. Critics argued that the Aadhaar Act 2016 touches privacy, so it deserved full debate in both Houses.
Key Definitions Every Reader Should Know
Terms You Must Know
The Aadhaar Act 2016 bare act opens with a list of defined terms. Each term carries legal weight. So, read them closely before applying any section.
- Aadhaar number: A twelve-digit number issued to an individual. Since 2019, it also covers an alternative virtual identity.
- Aadhaar number holder: A person who has received the number under the Act.
- Authentication: A process where the number, with demographic or biometric data, goes to the Central Identities Data Repository (CIDR) for verification.
- Resident: A person who lived in India for 182 days or more in the twelve months before applying.
- Requesting entity: An agency or person that submits the number and data to the CIDR for authentication.
- Core biometric information: Fingerprints, iris scans, and other attributes the regulations specify.
- Identity information: The Aadhaar number, biometric information, and demographic information of an individual.
- Offline verification: A way to verify identity without a live query to the CIDR, in the manner regulations specify.
Why Definitions Matter in Practice
Definitions decide who owes a duty. For example, a bank that uses authentication becomes a requesting entity. As a result, it must follow the consent and security rules. Similarly, an agency that only reads a QR code may qualify as an offline verification-seeking entity. That status carries different duties. Thus, your label determines your compliance burden. Anyone reading the Aadhaar Act 2016 bare act should keep this definitions page open at all times.
Enrolment: Who Can Apply and What Data Is Collected
Eligibility for Enrolment
Only residents may enrol. Citizenship is not a condition. Section 3 says every resident may obtain a number by submitting demographic and biometric information. Hence, foreign nationals who meet the residency test can also enrol. However, Section 9 states that Aadhaar does not, by itself, prove citizenship or domicile. Aadhaar proves identity only. Authorities and courts have repeated this point often. In effect, the Aadhaar Act 2016 works as an identity law, not a citizenship law.
Data Collected at Enrolment
Enrolment needs demographic and biometric information. Demographic data includes name, date of birth, and address. Biometric data includes a photograph, fingerprints, and iris scans. Notably, the Act bars UIDAI from collecting details about race, religion, caste, tribe, ethnicity, language, income, or medical history.
Enrolling agencies must also explain how UIDAI will use your data. Furthermore, they must tell you what choices you have about sharing it. Section 3 places this notice duty on the enrolling agency. Agencies must not collect anything beyond what the Act allows.
Children, Updates, and Virtual IDs
Children can enrol with limited data at first. Regulations then require biometric updates at set ages. Moreover, the Supreme Court held that a child may exit the system after reaching adulthood. Residents can also update details later, such as an address or a mobile number. Parents and guardians should watch update deadlines, since a lapse can block services.
The Act also recognises an alternative virtual identity. As a result, holders can avoid sharing the real number in many situations. Consider this a simple privacy tool.
How UIDAI Works Under the Aadhaar Act 2016
Composition and Powers
UIDAI is a statutory authority. A Chairperson, part-time members, and a Chief Executive Officer run it. Its powers include issuing numbers, framing regulations, and maintaining the CIDR. Moreover, it sets standards for security, enrolment, and authentication. Section 23 lists its major functions. Under the Aadhaar Act 2016, UIDAI also appoints and oversees the Registrars and enrolling agencies that run the ground network.
The Central Identities Data Repository
The CIDR stores enrolment data and authentication records. However, UIDAI cannot collect or keep the purpose of an authentication. Regulations also limit how long records may stay. In 2018, the Supreme Court cut the retention period for authentication data to six months.
Additionally, the repository confirms or rejects a match. It does not hand over your full record. Thus, the design tries to limit what leaves the system.
Authentication and Offline Verification Explained
Two Types of Authentication
Authentication answers one question: does this number match this person? The system replies in one of two ways. First, it can return a simple yes or no. Second, it can return e-KYC data, which includes limited demographic details and a photograph. In both cases, the holder must consent. Indeed, the Aadhaar Act 2016 and regulations require consent before authentication even begins. Moreover, the entity must explain how it will use the data.
What Happens During an Authentication Request
The process follows a clear path. First, the requesting entity captures the number and the biometric or demographic input. Next, it sends the request to the CIDR in encrypted form. Then, the CIDR compares the input with stored data. Finally, it returns a response. The entity never sees the full record.
Offline Verification
Offline verification does not query the CIDR. Instead, the holder shares a QR code, an XML file, or a paper printout. In turn, the entity avoids a live call to UIDAI. The 2019 amendment gave this method legal recognition. Businesses should map which method fits each use case under the Aadhaar Act 2016.
In addition, offline verification-seeking entities face limits. They must obtain consent. Holders also need to hear about alternatives. Finally, they cannot collect, use, or store the number or biometric data.
Voluntary or Mandatory? Sections 4 and 7 Explained
Section 7: Welfare Benefits
Section 7 lets the government require Aadhaar for subsidies, benefits, or services paid from the Consolidated Fund of India. However, a genuine beneficiary cannot lose a benefit only because authentication fails. The government must offer another way to prove identity. Here, the Supreme Court stressed this safeguard, especially for children.
Moreover, the Court read “benefits” and “services” narrowly. They must carry the colour of a subsidy or a targeted welfare scheme. For this reason, exam bodies and universities cannot rely on Section 7 to demand Aadhaar.
Practical Impact on Welfare Schemes
Agencies that run pensions, rations, and scholarships must plan for failures. For instance, a worn fingerprint should not end a person’s claim. Instead, the agency must accept another valid document. Furthermore, officers should record each failed attempt and its reason.
Section 4 After 2019: Voluntary Use
Section 4, as amended, says a holder may voluntarily use the number to establish identity. Voluntary use means use with informed consent. Furthermore, only a law made by Parliament can make Aadhaar authentication mandatory for a service.
Consequently, banks, telecom firms, and schools cannot simply insist on Aadhaar under the Act itself. They need separate legal authority. Otherwise, they must offer another proof of identity. Overall, the Aadhaar Act 2016 leans toward consent as the norm for every use outside Section 7.
Privacy and Data Protection Under the Aadhaar Act 2016
Confidentiality and Security
Section 28 makes UIDAI responsible for the security and confidentiality of identity information. It must keep records safe from unauthorised access. Additionally, the Act treats biometric information as sensitive personal information. Hence, stronger protection applies. Every data rule in the Aadhaar Act 2016 flows back to consent and purpose limits.
Restrictions on Sharing
Section 29 bars anyone from sharing core biometric information. Likewise, no one may use it for any purpose other than generating a number or authentication. Identity information may travel only with the holder’s consent and in the manner the regulations specify. Similarly, requesting entities cannot display numbers in public. Moreover, a requesting entity may pass on identity information only in the manner the regulations set. Any other sharing risks a penalty.
Disclosure in Court and Security Cases
Section 33 allows disclosure in narrow cases. A court order is one route. The Supreme Court added safeguards, including a chance for the affected person to be heard. However, it struck down Section 33(2), which allowed disclosure on national security grounds by a senior official. Thus, the disclosure powers now look narrower than the original text.
How Regulations Support Privacy
The Aadhaar Act 2016 and regulations work as one system. The Act sets principles. Regulations then add procedures for consent, storage, and audits. For example, the data security regulations require agencies to protect records with technical and organisational measures. Hence, a compliance review must cover both layers. In short, the Aadhaar Act 2016 and regulations answer different questions: the Act says what is allowed, and the regulations explain how.
Offences and Penalties You Should Know
Criminal Offences
Chapter VII creates several offences. Examples include impersonation during enrolment, disclosing identity information, unauthorised access to the CIDR, and tampering with stored data. Punishments include imprisonment up to three years and fines. For the gravest offences, such as unauthorised access and tampering, the statute sets a minimum fine of ten lakh rupees. Companies also face liability when officers or directors are at fault. The Aadhaar Act 2016 treats data misuse as a serious wrong, so businesses cannot treat penalties as a minor risk.
Civil Penalties After 2019
The 2019 amendment added civil penalties. Adjudicating officers now handle penalty cases against entities in the Aadhaar ecosystem. Moreover, UIDAI can act when an entity fails to follow the law, ignores directions, or withholds information. An appeal route to an appellate tribunal follows.
Who Can File a Complaint
Originally, only UIDAI could file a complaint about an offence. Critics said this left victims without a remedy. The 2019 amendment fixed part of that gap. Individuals can now complain about matters such as impersonation and disclosure of their own identity information. Even so, many offences still require UIDAI to act first.
Offences Committed Outside India
The Act also reaches offences committed outside India by any person. As a result, a foreign vendor that misuses Indian residents’ identity data may face action. However, enforcement across borders remains difficult in practice.
Supreme Court Rulings on the Aadhaar Act 2016
The 2017 Privacy Judgment
In August 2017, a nine-judge bench held that privacy is a fundamental right under Article 21. As a result, the Aadhaar challenge took a new shape. The Court asked whether the Act met the tests of legality, legitimate aim, and proportionality. In each later ruling, the Court tested the Aadhaar Act 2016 against fundamental rights.
The 2018 Aadhaar Judgment
On 26 September 2018, a five-judge bench upheld the Act by a 4:1 majority. The majority found no architecture for pervasive surveillance. Furthermore, it held that collecting limited demographic and biometric data serves a legitimate aim. However, the Court also drew firm limits.
What the Court Struck Down
The Court struck down Section 57 to the extent it let private entities use Aadhaar authentication under contract. It also struck down Section 33(2). As a result, banks and mobile companies could not require Aadhaar for account opening or SIM verification. In addition, schools and national exam bodies could not insist on it. Still, the Court upheld Section 139AA of the Income-tax Act, so PAN linkage survived. Because of that ruling, the Aadhaar Act 2016 no longer supports Aadhaar checks by private parties under Section 57.
The Dissent and the Review
Justice Chandrachud held that passing the Act as a Money Bill bypassed the Rajya Sabha and violated the Constitution. Later, in January 2021, the Court dismissed review petitions against the verdict. Nevertheless, the dissent remains a common reference in academic and policy writing.

How the 2019 Amendment Reshaped the Law
Why Parliament Amended the Act
After the 2018 verdict, private use of Aadhaar hit a wall. Banks and telecom firms wanted a legal route. Accordingly, the government issued an ordinance in March 2019. Thus, the Aadhaar Act 2016 changed shape within months of the verdict. Parliament then passed the Aadhaar and Other Laws (Amendment) Act, 2019.
Main Changes at a Glance
- Section 57 omitted: The provision that the Court struck down left the statute book.
- Voluntary use: Section 4 now stresses informed consent.
- Offline verification: The law recognises QR codes and similar methods.
- Aadhaar ecosystem: The Act now names enrolling agencies, registrars, and verifying entities as one group.
- Civil penalties: Adjudicating officers can penalise ecosystem entities.
- Complaints: Individuals gained a limited right to complain.
- KYC amendments: Changes to the Telegraph Act and the Prevention of Money-laundering Act allow voluntary Aadhaar-based KYC.
Lawyers now read the Aadhaar Act 2016 bare act together with the amending text, because the two must match.
Aadhaar Regulations and Rules You Should Track
The Core Regulations
UIDAI issued its first set of regulations in September 2016. Together with the statute, they form the Aadhaar Act 2016 and regulations framework. The main regulations cover enrolment and updates, authentication, data security, sharing of information, and business at UIDAI meetings. Each one fills operational gaps that the Act leaves open. For instance, the data security regulations require agencies to adopt technical and organisational safeguards. Likewise, the sharing regulations set the terms for passing on identity information.
Newer Regulations
Meanwhile, UIDAI has replaced and added rules. The Aadhaar (Authentication and Offline Verification) Regulations, 2021 now govern both methods. Separately, the Aadhaar (Payment of Fees for Performance of Authentication) Regulations, 2023 address fees. UIDAI amended the authentication rules again in December 2025. Then, in May 2026, it notified the Aadhaar (Enrolment and Update) First Amendment Regulations, 2026. Anyone studying the Aadhaar Act 2016 and regulations should therefore track each amendment date.
Where to Read Them
UIDAI hosts updated versions of its regulations online. Readers who want the Aadhaar Act 2016 bare act can start with India Code. Always check the consolidated text, because amendments change wording and numbering. Otherwise, you risk relying on a superseded rule. A trusted Aadhaar Act 2016 bare act copy should show the 2019 amendments in place.
Latest Developments From 2025 to 2026
Private Entities and Authentication
On 31 January 2025, MeitY notified the Aadhaar Authentication for Good Governance (Social Welfare, Innovation, Knowledge) Amendment Rules, 2025. The rules let government and non-government entities seek authentication for specified public-interest purposes. First, an entity applies to the concerned ministry or department. Next, UIDAI examines the proposal. Finally, MeitY approves it on UIDAI’s recommendation.
Supporters say the route helps e-commerce, travel, and healthcare services. Critics, however, want clearer approval criteria. They also recall the concerns behind the Section 57 ruling.
Aadhaar App and Verifiable Credentials
UIDAI’s December 2025 amendment recognises an official Aadhaar app. It also introduces the Aadhaar Verifiable Credential. Users can choose which details to share, from the number alone to specific demographic fields. As a result, data minimisation gets a practical tool.
Enrolment Reforms in 2026
In May 2026, UIDAI expanded the list of documents accepted for enrolment and updates. It also clarified rules for children, foreign nationals, and OCI holders. In practice, people without traditional documents may face fewer rejections.
Authentication Authority for NIC
In July 2025, MeitY granted Aadhaar authentication authority to the National Informatics Centre. The notification stresses consent. It also says authentication stays voluntary. Agencies cannot deny service when a person refuses or cannot authenticate.
These steps show that the Aadhaar Act 2016 keeps growing through rules rather than fresh legislation.
How the Act Works With Other Laws
PAN and Income Tax
Section 139AA of the Income-tax Act, 1961 requires holders to quote Aadhaar for PAN and returns. The Supreme Court upheld it in Binoy Viswam in 2017. Its 2018 judgment confirmed the point. Afterwards, the CBDT made quoting Aadhaar mandatory for return filing from 1 April 2019. Note that a newer Income-tax Act, 2025 now exists, so verify the matching provision before relying on old section numbers.
KYC, Banking, and Telecom
The 2019 amendments to the Prevention of Money-Laundering Act, 2002 and the Telegraph Act allow voluntary Aadhaar authentication as a KYC method. As a result, banks and telecom operators can offer Aadhaar-based onboarding. However, they must still offer another identity option. Otherwise, they may breach the voluntary-use rule. Thus, the Aadhaar Act 2016 rarely operates alone.
Data Protection Law
The Digital Personal Data Protection Act, 2023 now sits beside the Aadhaar framework. MeitY notified the DPDP Rules, 2025 on 13 November 2025. So, businesses that handle Aadhaar data must think about two regimes. The Aadhaar statute governs identity information and authentication. Meanwhile, the DPDP framework governs notice, consent, and breach response for personal data. The Aadhaar Act 2016 bare act also defines identity information, so check that definition when you assess overlap.
Major Legal Issues and Criticisms
Exclusion and Authentication Failure
Biometric mismatches can block benefits. Manual workers and older adults often report fingerprint failures. Although the Act requires alternative means, field practice varies. Hence, exclusion remains the strongest criticism. Scholars often test the Aadhaar Act 2016 against the proportionality standard, and exclusion cases weigh heavily in that test.
Surveillance and Function Creep
Critics fear that one number linked to many databases can enable profiling. The Supreme Court rejected the claim of pervasive surveillance under the Act. Even so, expanding use cases keep the debate alive. Moreover, the 2025 private-sector route revives older worries.
Oversight and Audit
The Comptroller and Auditor General has audited UIDAI’s functioning. Its report also summarises the safeguards the Supreme Court required. Accordingly, audit findings offer a useful check on real-world compliance.
Litigation Trends
Litigants now raise disputes over refusal of services, wrong records, and correction of details. Often, they argue that the entity ignored the voluntary-use rule. Courts then ask whether the person offered another valid document. Hence, documentation matters as much as the law itself.
Compliance Checklist for Businesses
Before You Use Aadhaar
Follow these steps in order. Compliance under the Aadhaar Act 2016 starts with one simple question: why do we need this data?
- Confirm your legal basis. Point to a law made by Parliament or an approved purpose.
- Choose the method. Pick authentication or offline verification.
- Obtain informed consent. Explain the purpose in plain words.
- Offer alternatives. Accept another valid identity proof.
- Limit storage. Do not keep numbers or biometrics unless the law permits.
- Mask displays. Hide most digits on forms and screens.
- Log and train. Keep records and train staff on breach response.
Common Mistakes
Many firms photocopy Aadhaar cards by habit. Others print full numbers on forms. Some deny service when a customer prefers another ID. Each practice can trigger complaints, penalties, or both. Another frequent error involves storing scanned cards in shared folders. Staff then copy them freely, which multiplies the risk. Thus, a short internal audit pays off quickly.
Records to Keep
Maintain a consent log for every authentication. Keep a written policy that names the legal basis. Record staff training dates. In addition, store incident reports and the steps you took. A sound plan for the Aadhaar Act 2016 and regulations should be short, written, and reviewed every year.
Your Rights and Remedies as an Aadhaar Holder
Practical Protections
You can lock your biometrics online. Generate a virtual ID as well. Share a masked copy of your card when possible. Also check your authentication history through UIDAI channels. Use these tools often. Every holder can treat the Aadhaar Act 2016 as a shield against misuse.
Where to Complain
First, write to UIDAI through its grievance channels. Next, approach the police for offences such as impersonation. If a regulated entity misuses your data, seek a remedy under the penalty provisions. Finally, a writ petition before a High Court remains available for serious rights violations. Keep copies of your requests and the replies. These records strengthen any later case. Seek advice from a qualified advocate before you file.
Final Thoughts on the Aadhaar Act 2016
The Aadhaar Act 2016 remains one of India’s most debated laws. It delivers real benefits. Yet it also raises real privacy questions. Courts have trimmed its reach. Parliament and ministries have since reshaped it. Overall, the safest approach is simple: read the current text, follow the regulations, and respect consent. Start with the Aadhaar Act 2016 bare act, then move to the regulations. Follow the Aadhaar Act 2016 and regulations as one package, and update your policies whenever UIDAI issues a change.
Key Takeaways
- Parliament created Aadhaar and UIDAI in law and set penalties for misuse.
- Use of Aadhaar stays voluntary unless a law of Parliament says otherwise.
- In 2018, the Supreme Court struck down private use under Section 57.
- Later, the 2019 amendment and the 2025 rules reopened limited private use.
- Consent, alternatives, and secure storage remain the core compliance duties.
Next Steps
Businesses should audit their Aadhaar practices now. Citizens should use the privacy tools UIDAI provides. Above all, both groups should check for updates, because this area of law keeps moving. This article offers general information. It is not legal advice.
References
- India Code – The Aadhaar Act, 2016: https://www.indiacode.nic.in/handle/123456789/21584
- BNB Legal – Aadhaar Act, 2016 (Bare Act): https://bnblegal.com/bareact/aadhaar-targeted-delivery-financial-subsidies-benefits-services-act-2016/
- UIDAI – Updated Regulations: https://uidai.gov.in/en/updated-regulations
- UIDAI – Regulations (Legal Framework): https://uidai.gov.in/en/about-uidai/legal-framework/regulations.html
- UIDAI – Aadhaar (Sharing of Information) Regulations, 2016: https://www.uidai.gov.in/images/The_Aadhaar_Sharing_of_information_regulation_2016.pdf
- Vidhi Centre for Legal Policy – Regulations Under the Aadhaar Act: https://vidhilegalpolicy.in/research/2016-10-4-regulations-under-the-aadhaar-act/
- S.S. Rana & Co. – Validity and Authentication of Aadhaar: https://ssrana.in/articles/validity-and-authentication-of-aadhaar-much-awaited-judgment-by-honble-supreme-court-of-india/
- Khaitan & Co – Supreme Court Upholds the Constitutionality of Aadhaar: https://www.khaitanco.com/thought-leadership/supreme-court-upholds-the-constitutionality-of-Aadhaar-albeit-conditionally
- Vinod Kothari Consultants – The Supreme Court Aadhaar Verdict: https://vinodkothari.com/2018/10/the-supreme-court-aadhaar-verdict-major-blow-to-fintech-companies/
- PRS Legislative Research – The Aadhaar and Other Laws (Amendment) Bill, 2019: https://prsindia.org/billtrack/the-aadhaar-and-other-laws-amendment-bill-2019
- AMSS Advocates – The Aadhaar Amendment and Its Discontent: https://www.amsshardul.com/insight/the-aadhaar-ammendment-and-its-discontent/
- Legal 500 – Aadhaar Authentication for Private Entities: https://www.legal500.com/intelligence/india/privacy/aadhaar-authentication-for-private-entities-navigating-the-2025-amendment
- TechCrunch – India Expands Aadhaar Authentication for Businesses: https://techcrunch.com/2025/02/02/india-expands-aadhaar-authentication-for-businesses-raising-privacy-concerns/
- TeamLease RegTech – Aadhaar Authentication Authority Granted to NIC: https://www.teamleaseregtech.com/updates/article/45165/meity-notified-the-grant-of-aadhaar-authentication-authority-to-nic/
- Legal 500 – Aadhaar Authentication and Offline Verification Amendment: https://www.legal500.com/intelligence/india/media-telecoms-it-entertainment/aadhaar-authentication-and-offline-verification-amendment-rules
- Business Standard – Aadhaar Eases Enrolment for Children, Vulnerable Groups: https://www.business-standard.com/amp/finance/personal-finance/aadhaar-eases-enrolment-for-children-vulnerable-groups-indians-abroad-126051300783_1.html
- CBDT Circular No. 6/2019 (via GConnect) – PAN-Aadhaar Linking for Filing ITR: https://www.gconnect.in/news/supreme-court-judgement-pan-aadhaar-linking-itr.html
- LiveLaw – Linkage of PAN With Aadhaar Mandatory, Reiterates SC: https://livelaw.in/top-stories/aadhaar-pan-linkage-mandatory-142688
- CAG – Audit Report Chapter on UIDAI Functioning: https://cag.gov.in/webroot/uploads/download_audit_report/2021/chap_1-0624d8136cc9ea5.81980172.pdf
FAQs About the Aadhaar Act 2016
- 1. What is the Aadhaar Act 2016?
The Aadhaar Act 2016 is the primary Indian law governing the Aadhaar identification system. It establishes the Unique Identification Authority of India (UIDAI) and provides rules for Aadhaar enrolment, authentication, identity information, data security, and targeted delivery of specified subsidies, benefits, and services. The Act also creates offences, penalties and safeguards against unauthorised access or disclosure of Aadhaar information. For accurate legal research, readers should consult the current statute along with amendments, rules and regulations.
- 2. Is Aadhaar mandatory under the Aadhaar Act 2016?
Aadhaar is not universally mandatory for every service or transaction. Whether it can be required depends on the applicable law, scheme, or regulatory framework. The Supreme Court’s 2018 Aadhaar judgment placed important constitutional limits on mandatory Aadhaar use. Therefore, individuals should identify the specific legal provision requiring Aadhaar before assuming that it is compulsory.
- 3. Where can I find the Aadhaar Act 2016 bare act?
The Aadhaar Act 2016 bare act can be accessed through official government legal resources, including India Code and UIDAI. However, readers should not rely solely on the original 2016 version. Amendments have changed several provisions. Consequently, the current text should be checked before relying on any section for legal or compliance purposes.
- 4. What do the Aadhaar Act 2016 and regulations cover?
The Aadhaar Act 2016 and regulations collectively govern several aspects of the Aadhaar ecosystem. These include enrolment, updating information, authentication, offline verification, information sharing, and data security. UIDAI regulations provide detailed operational requirements that supplement the principal legislation. Businesses and institutions handling Aadhaar information should therefore review both the Act and applicable regulations.
- 5. Does the Aadhaar Act protect personal and biometric information?
Yes. The statutory framework contains safeguards relating to identity information and core biometric information. It also regulates access, disclosure, authentication and information security. The Aadhaar Act 2016 and regulations should be read together when assessing a particular data-handling practice. Organisations should collect only information permitted by the applicable legal framework and maintain appropriate security controls.
