The Unique Identification Authority of India (UIDAI) and the Ministry of Electronics and IT were on an overdrive on Sunday.
After UIDAI’s Bengaluru regional office issued a press note last week cautioning Aadhaar-holders against sharing the photocopies with hotels or movie halls on the grounds that these were not licensed users, the ministry did an about-turn. It was withdrawn to eliminate the possibility of “misinterpretation.” “UIDAI issued Aadhaar card holders are only advised to exercise normal prudence in using and sharing their Aadhaar numbers. Aadhaar Identity Authentication ecosystem has provided adequate features for protecting and safeguarding the identity and privacy of the Aadhaar holder,” the clarification issued on May 29 said.
Users may have been asked to exercise ‘normal prudence’, but the ambiguous phrase will only add to their dilemma while dealing with entities that insist on Aadhaar as identity proof.
Hotels, movie-halls, gyms cannot insist on Aadhaar
Such entities might need to maintain your identity details in their records, but they cannot decide the identity proof you can provide. “Aadhaar serves as one of many valid identity and address proofs. However, the ubiquity and convenience of Aadhaar has resulted in rise in its use as proof of identity and address,” says Anupam Shukla, Partner, Pioneer Legal, a Mumbai-based law firm. You can look at furnishing other documents such as voter’s ID, driving licence or passport as alternatives. “Whenever a private organisation insists on obtaining your Aadhaar, always ask if you can give any other identity document. Insist on sharing a digital masked copy if you must share your Aadhaar,” says Rishi Wadhwa, a data privacy consultant.
Aadhaar not a must for investing in mutual funds
For investing in mutual funds, you can complete the know-your-customer (KYC) process either physically or online. For the physical process, you can submit your PAN, along with utility bills or identity cards issued by central governments, statutory bodies or PSUs as address proofs. Aadhaar is one of the officially valid documents. .
For online KYC, Aadhaar is required, but you need not send the Aadhaar copy to the mutual fund or registrar and transfer agents. The eKYC can be completed after Aadhaar is authenticated via OTP, which is sent by UIDAI on your registered mobile number and email ID, provided your PAN and Aadhaar are linked.
Aadhaar mandatory only for subsidy-linked bank accounts
By law, you have to furnish Aadhaar for opening bank accounts if you are availing of government subsidies. If you do not fall in this category, Aadhaar is not mandatory for opening bank accounts or taking loans, though you can choose to use it as your KYC document for the convenience it offers. “In such cases, they can generate a virtual ID from UIDAI and use that if they are not comfortable with sharing their complete Aadhaar number,” says a Bankbazaar spokesperson. Even when you submit physical copies, the Reserve Bank of India (RBI) has directed regulated entities redact or mask Aadhaar.
Banks such as SBI and Kotak Mahindra Bank offer digital accounts where your eKYC is completed using Aadhaar, provided your mobile number is linked to it. It will be verified through a one-time password (OTP) sent to on your registered mobile number. Similar is the case with video KYC. You need not carry your physical Aadhaar card during the video KYC process. “If a bank official asks for Aadhaar during the video KYC process, you must hide the middle four or six digits, so that your full Aadhaar number is not visible and it cannot be misused by anyone,” says Murali Nair, President-Banking, Indian Subcontinent at Zeta India.
Insurance policies can be purchased without Aadhaar
Again, Aadhaar is one of the officially valid identity documents for buying life and non-life insurance policies. “Insurance policies are not required to be linked to Aadhaar,” says Sanjib Jha, CEO and Executive Director, Coverfox.com. If you are quoting Aadhaar for e-KYC, you can take adequate precautions to protect your sensitive information. “We accept e-KYC where Aadhaar is linked to the proposer’s mobile number. However, the insured can submit the Aadhaar copy as address proof with masked details. He can also share the Virtual ID wherein an OTP will be sent for authentication,” says KV Dipu, Senior President and Head-Operations & Customer Service, Bajaj Allianz General Insurance.
Risks that Aadhaar data breach can pose
Once you share your Aadhaar data – or any other sensitive information – especially to unauthorised or unlicensed entities, there is a risk of misuse. “Considering Aadhaar is used so widely, in case of a data breach, the scope for misuse and risks to rights and freedom of people will be high. If you are handing over your Aadhaar photocopies to agents or others, you cannot necessarily sure about the authenticity of the person you are dealing with. Multiple people with easy access to your document can pose the risk of identity theft,” explains Wadhwa.
Sharing Aadhaar or any other crucial identity or personal information can cost you dearly, yet many share such documents indiscriminately. “UIDAI has put digital safeguards in place to protect Aadhaar data on its servers. An entire chapter of the Aadhaar Act (i.e. Chapter VI) deals with the protection, security and non-disclosure of Aadhaar data. The common man, however, has not been educated on the responsibilities of keeping such information confidential and the rights such an individual would have in case of unlawful disclosure of his Aadhaar data by third parties,” says Shukla.
How to safeguard your Aadhaar details
The IT ministry may have withdrawn the press note issue by UIDAI-Bengaluru, but the incident holds important lessons for Aadhaar-users. You must share all your identity documents with caution.
And it is easy to share Aadhaar details in a secure manner, even if you choose to furnish it voluntarily. UIDAI has already suggested the use of masked Aadhaar to overcome privacy and security challenges. You can download this document, where only last four digits of your Aadhaar would be visible, from the UIDAI website.The other option is to use the 16-digit virtual ID – a temporary ID in lieu of Aadhaar – to authenticate yourself. You can obtain it by sending an SMS from your registered mobile to 1947 with ‘GVID < last four digits of your Aadhaar number>’.