NANHUA UNIVERSITY
DEPARTMENT OF BUSINESS ADMINISTRATION
Master Program in Management Sciences
-----------🙢🕮🙠-----------
Seminar on Business Ethics
“Privacy Concerns and Security Risks with
Aadhaar Card”
Professor 釋知賢(沈昭吟) 教授
Student ID: 11251026
Name: 李健福
Date: January 19, 2024
Abstract
This research study examines the breaches associated with Aadhar cards categorizing
them into four areas; data leaks, privacy concerns, security breaches and measures, for
data protection and privacy. The majority of threats arise from encryption in websites,
apps or online gateways while a smaller number of unintentional threats occur due to
issues like improper encryption, information disclosure and environmental risks.
Proposed actions to safeguard Aadhar information include access control, protection of
data legal measures implementation, data removal practices and shutting down
compromised websites. The research focuses on India's Aadhar project as an initiative
that has sparked debates on matters of data privacy and security. Its primary objective
is to understand the privacy concerns surrounding the implementation of Aadhaar while
analyzing its impact on the personal security of citizens. The analysis underscores the
need for a framework with regular policy updates. While acknowledging that Aadhar
was originally intended to streamline bureaucracy and combat fraudulence, this study
concludes that its current implementation poses risks to privacy and constitutional
rights of Indian citizens. As a recommendation, improvement measures are suggested
for the Unique Identification Authority of India (UIDAI) to protect the Aadhar ecosystem
and mitigate data breaches.
1. Introduction
India had major problems in identifying beneficiaries for social programmes. A
significant proportion of residents lacked formal identity credentials, and many of those
who had credentials possessed ones that were only recognised locally. Inadequate
identity records and verification processes meant that government agencies frequently
distributed social welfare benefits to the same people multiple times, or to people who
did not qualify. Prior to Aadhaar, it was estimated that 58% of subsidized food grains
and 38% of subsidized kerosene disbursed under government programmes did not
reach their intended beneficiaries (Government of India, 2005). This resulted in
tremendous waste of resources. Such issues also affected other social programmes
including scholarships, healthcare, pensions and subsidized household goods.
Significantly, some eligible households were denied social assistance for which they
qualified because they could not easily prove their identity.
Aadhaar, a twelve-digit unique identifier issued by the Government of India, is the
world's largest database, encompassing 1.2 billion subscribers in 2018 (Singh 2021;
Anand 2021). Introduced to create error-free identities for Indian citizens, the Aadhaar
card facilitates access to various services such as LPG and banking. Despite its
benefits, concerns regarding security and privacy persist. Security issues include
information privacy, unauthorized use of personal data, human errors, centralization of
databases, data decryption, and the risk of theft or loss. Privacy concerns involve the
potential identification of individuals without consent, surveillance, and tracking. Privacy
concerns identify individuals without consent, surveillance, and tracking people
(Agarwal et al. 2017).
While Aadhaar has the potential to digitize much of India’s cumbersome
bureaucracy, the project is not without its shortcomings—(1) its overreaching
influence and myriad data leaks pose a massive threat to the privacy of the
citizens of India, (2) its use as a substitute for official Photo-ID has introduced
new vulnerabilities into the system, and (3) the use of the data for AI software
development is on shaky ethical grounds. All of these issues exacerbate one
another and have the potential to turn the Aadhaar system into an oppressive
surveillance tool for the state.
The Unique Identification Authority of India (UDAI), which works under the Planning
Commission of India, is in charge of overseeing Aadhaar numbers and Aadhaar ID
cards. The Aadhaar venture was started as an endeavor towards having a solitary, one
of a kind recognizable proof report or number that would catch every one of the subtle
elements, including statistical and biometric data, of each occupant Indian person. At
present there are a plenty of character reports in India including travel papers, lasting
record numbers (PANs), driving licenses and apportion cards. The Aadhaar card/UID
won't supplant these ID reports however can be utilized as the sole recognizable proof
confirmation while applying for different things. It will likewise fill in as the reason for
Know Your Customer (KYC) standards utilized by banks, money related foundations,
telecom firms and different organizations that keep up client profiles. Aadhaar numbers
will in the end fill in as the reason for a database with which burdened Indian occupants
can get to administrations that have been denied to them because of absence of
recognizable proof archives.
2. Literature Review
2.1 Background
Aadhaar was first formulated as an idea in 2009 under the then ruling United Progressive
Alliance (UPA). Unique Identification Authority of India (UIDAI) was the main authority
responsible for the Aadhaar system and this agency was set up as an extension of the Planning
Commission of India (an important government-funded policy think tank).[6] The project was
headed by Nandan Nilekani, the co-founder of one of India’s premier IT firms, Infosys and was
designed to simplify the bureaucratic nature of government schemes in India.
Before the creation and advent of Aadhaar, availing the benefits of government programs was
very hard and taxing for the poor. It involved filing a lot of complicated paperwork, providing
several proofs of residence and identification and also required people to take time off work to
complete these requirements. Aadhaar has since then replaced most requirements for
identification proof and is usually the only document required to avail a government scheme.[7]
2.2 Features of Aadhaar Card
The first feature is the distinctiveness of the card. Aadhar cards offer biometric information and
demographic information. It eliminates the probability of duplicate information from the users. It
considers the uniqueness of the Aadhaar card. Once the user registers their details for Aadhar,
it is stored in the UIDAI database. If a person tries to enroll it again, it rejects the information and
matches it with the present one in the record. Hence, it makes it easier to identify the individual
distinctively. The second feature is availability. Aadhar information is in computerized form.
Anyone can access the information from anywhere in India. It shows a nationwide portability
benefit for Indian citizens. It is particularly helpful for the people who move around (or) travel
places. The third feature is based on randomized numbers. Numbers are generated for an
individual on a random basis. Individuals who want to enroll their demographic data have to
enclose biometric information. It did not ask for caste, religion, income, and health. The fourth
feature is centrally managed architecture. UID architecture is scalable. Individual information is
stored and managed centrally, making the information updated or authenticated easily done
from anywhere. The architecture has the potential of handling 100 million authentications per
day (ibid). The fifth feature is eased access to information through technology. Aadhar card
information does not sit on a single computer or any hardware; also, it is not managed by any
vendors. This is possible due to open-source technologies (Pali et al. 2020).
The Aadhaar card is now linked with services such as driving license, school scholarships,
cooking gas subsidies, passports, pensions and provident fund accounts.[8] The Aadhaar card
is also being considered for provision of the services provided by Indian Railway System,
especially the online reservation process.[9] The Developmental Cooperative Bank even
launched its first Aadhaar based ATM in June 2016 and aims to utilize the biometric fingerprint
as an additional security feature in customers accessing their money.[10]
2.3 Privacy concerns of Aadhaar card
The Aadhaar card raises significant privacy and security concerns, as outlined by various
sources. Bergström (2015) emphasizes the misuse of personal information, external
unauthorized secondary usage, and improper access to data. Sharma (n.d) identifies three main
issues: the global Aadhaar number allowing identification without consent, unauthorized access
to biometric and demographic information, and centralized database surveillance and tracking.
Raju et al. (2017) highlight privacy concerns, including unauthorized access to biometric data,
data leakage, intentional threats like malware and cyber espionage, and inadvertent threats
such as configuration errors and improper encryption. Banerjee and Sharma (2019) identify
theft, identification without consent, correlation of identities, illegal tracking, and the absence of
virtual identities as additional privacy concerns associated with Aadhaar cards.
As per Banerjee and Sharma (2019), the privacy concerns of Aadhar cards are identified theft,
identification without consent using Aadhar data, correlation of identities across domains,
illegal tracking of individual data and lack of virtual identities.
The first concern is identified theft. Aadhar card is endangered to bring in biometric information
illegally. There is a chance of leakage of information from the central Aadhaar repository. It may
lead to risk. Also, it may lead to engaging in fraudulent activities. It primarily owes to not
maintaining biometrics in a secret way which adds to the risk (Viswanath 2017; Khaira 2018). A
second concern is Aadhar card identification without any consent from the card holder. There is
a chance of accessing biometrics to find out the people without getting the department’s prior
approval (Banerjee and Sharma, 2019). The third concern is an association of identities over
domains. It may be possible in tracking individual personal information over multiple domains
of services through their global Aadhaar Id. Global Aadhaar ID is valid over domains. Hence,
illegal tracking of information may lead to identifying information without prior knowledge of an
individual (Banerjee and Sharma, 2019). The fourth concern is the illegal tracking of individual
information. There is a chance of tracking the individual information without proper
authorization. Also, any person can be easily put under surveillance using data from the
Aadhaar database or authentication requesting agencies databases without consent. Such
information can provide information like location, time and context of authentications and
services availed without recording the purpose of authentication. Authentication without proper
authorization may put users at a serious risk of fraud even though Aadhar KYC is for one
purpose that can be used for another (Viswanath 2017). Privacy by design is not accomplished
through self-imposed blindness.
2.4 Data Leakage
Data breaches may result in misuse or leakage of highly confidential data (Sundareswaran
2018). Data leakages are mainly caused by internal information breaches and external
information breaches, either inadvertently or intentionally leaking sensitive information. Data
leakages may be done by insider or outsider threats. Insider threats are espionage, accidental
sharing of information, transmitting without proper encryption and more. External threats are
caused by hackers, malware, social engineering, and viruses (Cheng et al., 2017). The
classification of data leakages of parties illustrates in the below figure.
3. Methodology
Research Design :
Qualitative Approach: This research employs a qualitative research design to gain in-depth
insights into privacy concerns associated with Aadhaar cards.
Data collection :
Literature review : Conducting a comprehensive review of academic articles, research papers,
and publications related to Aadhaar card privacy concerns and security risks.
Online News Websites: Scrutinizing online news articles from reputable news websites, both
national and international, to gather real-time information and perspectives on Aadhaar privacy
concerns and security risks.
Case Studies: Analyzing relevant case studies that provide detailed accounts of specific
instances or scenarios related to Aadhaar privacy issues and security risks.
Magazine Analysis: Examining articles in magazines and periodicals that discuss privacy issues
related to Aadhaar. Magazines from various domains, including technology, law, and social
issues, will be considered.
4. Findings or Results
Major Concerns
Aadhaar’s importance cannot be understated—it contains the data of billions of people, and the
security of this data and the system itself is an incredibly important point of political contention.
Complicating the issue is the fact that ever since its inception, Aadhaar has been plagued by a
myriad of internal and legal problems, as well as major leaks and vulnerabilities in the overall
security of the system.
4.1 Internal Problems and Leaks
A big problem with Aadhaar is that it often faces serious security issues, making it prone to data
leaks. The organization in charge (UIDAI) has to frequently shut down fake websites that
pretend to be official and try to trick people into giving away personal information. In 2018,
about 200 government websites unintentionally exposed personal Aadhaar data, making it
possible for anyone to access sensitive information just by searching on Google. The
government had to block around 5,000 officials because unauthorized people within the
government were accessing Aadhaar data. In a separate incident, a state website in Jharkhand
mistakenly released data of 1.6 million pension beneficiaries, including their addresses and
bank details. Another report mentioned that around 130 million Aadhaar numbers and
confidential data were accidentally made public. Even though some argue it was not a true leak
but a mistake, it shows a bigger issue of the government being careless with citizens' data,
causing problems for regular people. [17]
4.2 Vulnerability in photocopying ID
Because the government wants everyone to link Aadhaar to essential services, it has become
the most commonly used photo ID in India. However, this creates problems because Aadhaar
wasn't designed to replace other IDs directly. It was meant for biometric verification using
fingerprints or iris scans, matching them with the Aadhaar number in a central database. When
used just as a photo ID, it becomes easier to duplicate or fake because it lacks standard
security features like a microchip or hologram.[18]
A notable incident highlighting Aadhaar's security issues happened when RS Sharma, the
chairman of India’s telecom regulator, shared his Aadhaar number publicly to show confidence
in the system. People were able to find his personal information, and someone even created a
fake Aadhaar card. This fake card was accepted by Amazon and Facebook for services under
Sharma’s name. The problem gets worse as many businesses ask for photocopies of Aadhaar
as proof, which are stored on unprotected networks, increasing the risk of misuse. [19]
4.3 Legal and Privacy Issues
Aadhaar suffers from a myriad of security issues and the system has repeatedly proven to be
vulnerable to both internal leaks and external abuse of the data. The NDA had argued that the
right to privacy was not a fundamental right but was proven wrong by the Supreme Court
verdict, which guaranteed the fundamental right to privacy under the Indian Constitution.
The SC allowed the mandatory linking of Aadhaar for filing tax returns and accessing welfare
schemes but removed the requirement for bank accounts and SIM cards. It also struck down
section 57 of the Aadhaar Act, which allowed corporations and individuals to ask for Aadhaar in
exchange for goods and services. The court also demanded that the Central Government pass
a strong data protection law as soon as possible. Although the limited power of the private
sector and the requirement to pass a strong data protection law are crucial in guaranteeing the
right to privacy, the overall judgement did not go far enough in limiting government abuse of the
program and of the data collected under the program.[23]
4.4 Impact on Artificial Intelligence Research
The government of India thus has access to the data of nearly all its citizens. They can track
activities of suspicious individuals through their Aadhaar number which will connect them to
other services that they use. It is highly likely that the government will push for AI programs that
will scan citizens' activities and their patterns to automatically flag certain individuals as
dangerous or suspicious. While this may help with crime and controlling terrorism, it has the
potential to turn India into an oppressive surveillance state.
The strength of an AI system or research is directly linked to the number and kind of data that is
fed into the machine learning process. With the biometric data of more than a billion people, the
Aadhaar system has the potential to revolutionize the pace and growth of AI research in India.
Aadhaar’s data pool isn’t just limited to the system itself, the government has essentially
mandated the linking of Aadhaar to other individual information as well. Aadhaar is now the
standard identity proof document and is required for accessing a lot of public services such as
opening a bank account and getting a new SIM card.[29]
Police officers in Punjab are already using the Punjab Artificial Intelligence System (PAIS)— an
artificial-intelligence assisted face-recognition algorithm—to catch [Link] hope to
tremendously increase the accuracy and strength of this AI by linking it with Aadhaar data.[31]
5. Conclusions
In conclusion, Aadhaar, India's ambitious biometric identification system, plays a pivotal role in
the nation's digital landscape. However, it grapples with significant internal and legal
challenges. Security lapses, including major leaks and vulnerabilities, have exposed citizens'
data to risks. The government's mandate to link Aadhaar with essential services has led to its
widespread use as a photo identification document, making it susceptible to duplication.
Legal and privacy issues, particularly the debate over the right to privacy, have been
contentious. While the Supreme Court validated the Aadhaar project, it imposed restrictions on
mandatory linking and invalidated certain provisions to protect privacy. Despite these measures,
concerns linger regarding potential misuse of data and government surveillance.
References :
[6] About UIDAI, Unique Identification Authority of India, Government of India.
[7] Raja Siddharth Raju et al, Aadhaar Card: Challenges and Impact on Digital Transformation,
2.
[8] Raja Siddharth Raju et al, Aadhaar Card: Challenges and Impact on Digital Transformation,
3.
[9] Ibid.
[10] Raja Siddharth Raju et al, Aadhaar Card: Challenges and Impact on Digital Transformation,
4.
[17] 130 Mn Aadhaar Numbers Were Not Leaked, They Were Treated as Publicly Shareable
Data, Tech2.
[18] Aria Thaker, Aadhaar’s Most Common Use Is Also One of Its Most Dangerous Problems,
Quartz India.
[19] Ibid.
[20] Varun HK, Aadhaar: A History of the Controversy, Deccan Herald.
[21] Lok Sabha Clears Aadhaar Bill, The Hindu.
[22] Varun HK, Aadhaar: A History of the Controversy, Deccan Herald.
[23] Supreme Court Verdict on Right to Privacy, The Hindu.
[24] Initial Analysis of Indian Supreme Court Decision on Aadhaar, Privacy International.
[25] Ananya Bhattacharya Anand, Aadhaar Is Voluntary—but Millions of Indians Are Already
Trapped, Quartz India.
[26] Initial Analysis of Indian Supreme Court Decision on Aadhaar, Privacy International.
[29] Anirudh VK, How Aadhaar Can Be Used To Train A Surveillance AI For India, Analytics
India Magazine
[30] Gopal Sathe, Cops In India Are Using Artificial Intelligence That Can Identify You In a
Crowd, HuffPost India.
[31] Gopal Sathe, Cops In India Are Using Artificial Intelligence That Can Identify You In a
Crowd, HuffPost India.
Banerjee, S., Sharma, S. (2019). Privacy concerns with Aadhaar. Communications of the ACM,
62(11), 80-80.
[Link]
[Link]
experiment/#_ftnref12
[Link]