IT Grids Aadhaar data leak: UIDAI’s implicit acknowledgement of a large-scale data breach will be very welcome to anti-Aadhaar activists
The breach points, yet again, to major concerns with the security of data in the Aadhaar ecosystem.


Representational image.[/caption]The breach points, yet again, to major concerns with the security of data in the Aadhaar ecosystem. The UIDAI, in fact, has also not ruled out the possibility of an internal breach by its employees. Apart from this, there is a possibility of offshore transfer of the data, leading to fears of exposure to foreign elements.
On the find of 7.8 crore data records
‘Surprisingly similar’ database to that of the UIDAI’s
The UIDAI in its complaint states that the structure and size of this database is ‘surprisingly very similar’ to the databases that were originally owned by the UIDAI. Of the numerous fields of data that were found, the complaint takes particular note of the presence of Aadhaar enrolment IDs, stating that this indicates that the data was either from the CIDR or the SRDHs. The complaint thus, for the first time, shows the UIDAI acknowledging a possible breach of the CIDR and SRDHs, as opposed to its characteristic denial.
UIDAI acknowledges possible internal breach as well as hacking
Provisions for the breach of the database itself
Apart from these, a number of additional sections have been listed for the theft of the data in itself. These include Section 29 of the Aadhaar Act for the sharing and use of the identity information for a purpose outside the scope of the Act, Section 40 of the Aadhaar Act for the misuse of identity information by the requesting entities and Section 42 for any residuary violations. It also lists other violations of the IT Act, including Section 66B for the dishonest receipt of a stolen computer resource (i.e., the receipt and use of the Aadhaar database) and Section 72A for the disclosure of information in breach of a lawful contract.Though not listed, the breach also points to the violation of Sections 38(a) and (b) of the Aadhaar Act for access to and download of data from the CIDR.
Offshore storage of data
Another particular concern is that the data with IT Grids is suspected to have been hosted with Amazon Web Services in the US and other offshore facilities, raising questions as to the extent to which the data has been exposed to foreign elements as well. Even though the data exposed does not appear to include biometric data, it is a point of concern that the laws at present do not propose separate or heightened penalties for the disclosure of such sensitive data to foreign locations.
Penalties up to a crore and three years of imprisonment
It is clear that the UIDAI is considering violations at various levels including internally, through the requesting entities, or through any other entity in the Aadhaar ecosystem. The violations listed together draw a penalty of up to three years of imprisonment, and fines of up to Rs 10 lakhs. A more major penalty is under Section 33A of the Aadhaar and Other Laws (Amendment) Ordinance, 2019, which allows a penalty of up to Rs 1 crore for an entity failing to comply with the Aadhaar Act (the Ordinance has currently been challenged before the Delhi High Court). This section, however, has currently not been listed under the complaint.
Moving forward

China has dominated Myanmar’s rare earth mines — now India eyes deal to harness country’s critical minerals
CJP protest in Delhi: New videos of stone pelting, violence emerge as police, agitators trade charges
'From make in India to launch from India': Skyroot COO on why Vikram-1 could change India’s space sector
Choke terror funding, keep international shipping lanes safe: Jaishankar at Asean Regional Forum
PM Modi announces fast-track courts for paper leak cases; CJP responds ‘Dharmendra Pradhan must go’
