U.S. Social Security vs. India's Aadhaar
U.S. Social Security vs. India's Aadhaar
Report Part Title: Key Differences Between the U.S. Social Security System and India’s
Aadhaar System
Report Part Author(s): Kaliya Young
Report Title: The Promise of Public Interest Technology:
Report Subtitle: In India and the United States
Report Author(s): Richard Abisla, Subhodeep Jash, Aditya K. Kaushik, Sylvia Mishra,
Ananth Padmanabhan, Pranesh Prakash, Tanvi Ratna, Joshua Simons, Madhulika
Srikumar and Kaliya Young
New America (2019)
JSTOR is a not-for-profit service that helps scholars, researchers, and students discover, use, and build upon a wide
range of content in a trusted digital archive. We use information technology and tools to increase productivity and
facilitate new forms of scholarship. For more information about JSTOR, please contact support@[Link].
Your use of the JSTOR archive indicates your acceptance of the Terms & Conditions of Use, available at
[Link]
New America is collaborating with JSTOR to digitize, preserve and extend access to this
content.
Acknowledgments: The author would like to thank all the people she spoke with in
India about Aadhaar. This paper would not have been possible without the support of
New America and the guidance provided by Awista Ayub and Melissa Salyk-Virk. The
author would also like to thank the 2019 India-U.S. Fellows.
Introduction
As the world’s largest democracies, with 1.3 billion and 326 million people
respectively, India and the United States both need to support the abstract
representation of individuals and entities and support their transactions with
each other confidently in the digital world.
The United States began issuing Social Security numbers (SSN) to a small
515
segment of citizens in 1935. The system has evolved over the past 85 years and
now numbers are issued to children at birth. Today, Social Security numbers are
used by employers to verify employment eligibility and by the government to
track the collection of taxes, social benefit contributions by people, and to
support them receiving benefits. Most residents also have a state level driver’s
license or ID card that an SSN is required in the application process. This type of
516
ID has a photo biometric and is held by 87 percent of adults.
Over the past 10 years, India has rolled out an identity system based on the
collection of biometrics and simple demographic information from all of its
residents. The system is called Aadhaar, meaning foundation in Hindi. To date,
Aadhaar claims to have enrolled 1.3 billion residents.
Both Aadhaar numbers and SSN are unique numbers issued to residents by their
federal government. A card with the number on it is mailed to the resident. To
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 137
The first section provides context for each ID and considers the historical and
contemporary risks of identity systems.
The second section considers the role of the number itself, and, further, explains
how the creators of Aadhaar position the number within a sprawling system that
continues to add new features, particularly in contrast with the limited role of the
SSN within the U.S. context.
The third section looks at the very different legal and regulatory frameworks that
inform the operation of the agencies responsible for both Aadhaar and Social
Security, along with contrasts in the visibility of operations through the court
systems where challenges occur.
The fourth section outlines how the national-level UIDAI worked with state-level
governments and consultants in India to create vast databases of information
about residents at the local level. These state-level databases are called State
Resident Data Hubs. In the United States, there are no large scale databases of
this type. This section walks through the range of regulations that have been put
in place since the 1960s to guard against the creation of such databases in the
United States.
Finally, the paper concludes with a discussion in sections five and six about how
the use of the SSN has become limited to employee enrollment and financial
services in contrast to the ever-expanding use of Aadhaar in the private sector
and employment context.
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 138
Democracies benefit from diverse input into the design of identity systems and a
broad consensus about their operation, transparency, and accountability to the
citizens whose information is managed by these systems.
Existing mental models of how identity and identification systems work are
based on government registries for births, deaths, and marriages where events
are recorded on paper in a ledger book and certificates issued. Identifier oriented
systems like the SSN originated at a time when paper-based punch cards were the
latest technology. There were limits to how far and wide a number could circulate
when paper technologies like punch cards, index cards, and the physical mail
system were the only means of circulation.
Even when identity technology is limited to paper, its abuse could lead to horrific
results. IBM’s punch card technology was instrumental in facilitating the Nazi
520
genocide of Jews in Europe via the census records in various countries. Several
Indian subjects interviewed for this research paper pointed out that there have
been a number of significant events of communal and caste violence in India:
521
• Keezhvenmani (Tamil Nadu, 1968)
522
• Gujarat (1969)
523
• Nellie (Assam, 1983)
524
• The Anti-Sikh Riots (1984)
525
• Hashimpura (Uttar Pradesh, 1987)
526
• Lakshmanpur Bathe (Bihar, 1997)
527
• Gujarat (2002)
528
• Khairlanji (Maharashtra, 2006)
Some of these incidents were facilitated by datasets from Voter IDs and Ration
529
Cards, and some had implicit state involvement. Beyond these large incidents
involving thousands of deaths at one time, there are also tens of thousands of
530
reports of more isolated incidents of violence every year against Dalits.
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 139
Both the U.S. Social Security Number and Aadhaar Number are core to how the
respective systems work but the way the number is seen and how the designers of
the programs orient around it is quite different.
• VirtualID creation;
• DigiLocker, a service for people to download all the documents they have
been issued by different government departments; and
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 140
In the United States, public concern about the possible use of the SSN for
government surveillance has limited the use of the number and led to regulations
about its use in both the public and private sector.
On the other hand, in the India stack model, not only does the Indian
government provide an identity card to citizens, acknowledging them and giving
539
them a “proof ” to share, but it also provides authentication services. Indians
can use their UID to log in to services and then either use a biometric or get a
one-time password (OTP) sent to their phone which they then enter to complete
remote authentication. This means that the UIDAI has a record of all of the
places where a person authenticates their identity, and this information is kept in
Aadhaar’s logs for six months.
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 141
There is ongoing work in the United States to develop ways for individuals to
prove they are a particular person by leveraging government-issued identity
541
documents in digital form. An important feature of some of these systems is
that they do not rely on a connection to a central government database to prove
542
their veracity.
UIDAI and its leadership have a culture of operating just beyond or just within a
legal and regulatory framework. Two books about the story of the creation of
543
Aadhaar have been written by journalists. Both document how the project did
not have a legal or regulatory basis for six years between 2009 and 2016 and
operated with a startup culture. They describe how the UIDAI leaders pushed to
build out Aadhaar despite this legal limbo.
When it was finally made legal with the Aadhaar Act of 2016, the UIDAI was also
left as its own regulator with enormous freedom to expand aspects of the system
and build new “features” without any need to consult the public. UIDAI did not
do privacy impact or security assessments that would bring transparency to how
the system would work or change in the future and what the implications would
be. In my interviews with UIDAI leaders, they described the next new features
that were going to be appearing within the India Stack framework while at the
same time saying that the UIDAI had no responsibility for how people were asked
for their identity information or how that information was used by those
requesting it.
Unlike UIDAI, when the U.S. government changes any technology at the core of
its operations, it moves with a deliberate and careful approach bound by the legal
and regulatory framework of the government, particularly when working with
the sensitive personal information of its residents. For decades, there have been
extensive on-the-record hearings by various legislative committees and
presidential commissions addressing government systems for registering citizens
and collecting and using data about them. Hearings of this type are, by default,
not public in the Indian parliamentary system.
Another contrast between the two systems is a key mechanism for public
accountability. Challenges to U.S. government procedures happen in the courts,
where proceedings produce court transcripts. The 38 days of hearings about
Aadhaar before the Indian Supreme Court produced no transcripts: the best we
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 142
In contrast to the U.S. Social Security Administration, the UIDAI is its own
regulator. This is in part because, in India, most legislation is written in a way that
delegates significant regulatory power to the government while the law
concentrates on legal and policy issues. In the case of the Aadhaar Act,
substantial regulatory power was given not to the government but to UIDAI itself,
546
meaning it is not actually accountable to any other organization. And the
UIDAI is exempted from Right to Information [RTI] requests and it sets the
547
grievance mechanisms for itself. The UIDAI is responsible for regulating the
ecosystem around it. Many have questioned the revolving door that is seemingly
connecting the UIDAI and private industry and question whether this limits the
548
ability of UIDAI to regulate its own ecosystem.
Indian residents, when they go through the process of getting their Aadhaar
number for the first time, are enrolled in the UIDAI Central Identity Repository
553
and the State Resident Data Hub.
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 143
UIDAI created the software and required that states use this software if they
554
wanted to get UID information and additional KYR information.
Several years into enrollment, problems surfaced. Some residents were bypassing
State enrollment agents by enrolling through banks and other registrars, and
555
states did not have access to that data. In response, the UIDAI made a deal with
states to share the UID and demographic data from residents of their states that
556
enrolled with other registrars.
It is claimed that this activity stopped with the passage of the Aadhaar Act in 2016
557
and that all the State Resident Data Hubs were destroyed. However, there is
558
evidence that these Hubs are still operating. Even if the data is no longer sent
directly from the UIDAI to SRDH, each of the states has agreements to access the
KYC API of the UIDAI CIDR, so when they interact with residents they can pull
the data from the UIDAI into their state-level databases (see Figure 5).
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 144
The State Resident Data Hubs use the UID as the anchor to integrate all data
from different state databases together. This happens in two ways. One is a
linking process where residents who are recipients of a particular subsidy,
benefit, or service go to the agency and assert their ID from a given system and
provide their Aadhaar number. They may be asked to authenticate via a thumb
559
print. This process is known as linking, or organic seeding.
Another process, known as inorganic seeding, combines data from SRDH and
UIDs together with existing databases from various subsidies, benefits, or
services. This process occurs without the awareness or consent of residents.
Authorities might check with residents/beneficiaries to see if they made the
correct link or to find beneficiaries who “did not match” any particular Aadhaar
number and ask them what their number was. This human resolution requires
more effort to complete.
The assumption is that only those with matching UID Aadhaar numbers are
“real” beneficiaries. Everyone else is a ghost or fake and can be eliminated.
560
Indian naming conventions are very fluid, and the same people use different
561
names in different contexts. This strategy to address who is on different social
services programs is causing disruption to clients who have their benefits cut off
562
because their legitimate claims are not recognized by the system.
The State Resident Data Hubs have applied a computer science data modeling
563
idea of “single source of truth” and sought to impose it on Indian society and
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 145
Rather than creating mass databases and integrating all data about citizens
across all contexts, the U.S. government is actively taking steps to stop or reduce
565
the use of the SSN, even in unlinked discrete databases. Currently, the use of
the number at the federal level is mandated for only a few agencies and services,
such as the Internal Revenue Service (tax authority), Social Security
Administration, passport applications, and for loans by any federal agency. Other
agencies that request the number must inform residents that sharing it is
voluntary, and they will not be denied services if they do not share the number.
This was not always the case. Beginning with an executive order by President
Eisenhower in 1953, there was a phase where using the SSN as a key to interact
566
with various services was encouraged and even mandated.
In 1961 the Internal Revenue Service required the use of SNNs when filing taxes.
Increased digitization of records in the 1960s drove the need for common
reference systems across government agencies and within the private sector, and
they chose the SSN as a way to do this.
In 1965, there was a proposal to create a National Data Center that would pool
statistical information held by the Census Bureau, the Internal Revenue Service,
the Bureau of Labor Statistics, the Social Security Administration, the Federal
567
Reserve Board as well as a dozen other federal agencies. The public reaction to
merging all of these bureaucratic records caught proponents off guard because
they thought that the composite data were necessary for a well-ordered society,
568
and the benefits were self-evident. But the reaction by the public was hostile
and sustained when the proposal was floated in 1967, and again in 1970 when it
was finally rejected. There was widespread press coverage that looked at the
implications for the present and future by creating such databases (see Figure 8).
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 146
Today, India has the type of database the American public rejected in the 1960s
and 1970s. The process was started by the UIDAI and their approved consultants
(among them Accenture, Ernst and Young, KPMG, PwC, Wipro, and Deloitte)
570
with the software they developed and supported. This is particularly true in
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 147
How did the United States move from public outcry against a National Data
Center to developing actual laws and regulation that helped citizens accept the
same data being collected by discrete agencies to guard against information
sharing between agencies? While India adopted the use of Aadhaar across
several agencies to deliver services, the U.S. was slower to move in that direction
with the SSN, but did get there eventually.
In this time period the late 1960s and early 1970s there were multiple hearings,
task forces, and committees convened by various agencies of the federal
government and committees in United States Congress. These included The
573
Social Security Number Task Force in 1970. In 1973, the Secretary of Health
Education and Welfare Advisory Committee on Automated Personal Data
Systems issued a report entitled, “Records, Computers and the Rights of
574
Citizens.” The committee developed a code of fair information practices,
inspired by the code of fair labor practices.
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 148
• There must be a way for an individual to find out what information about
him is in a record and how it is used.
These were the starting points of what evolved to be the Fair Information
575 576
Practices and Principles, and later evolved into the Privacy Act of 1974, that
prohibits data sharing between government agencies. It states:
Over the next several years, the U.S. government began to move in a direction
that would result in expanded use of the SSN. In 1976, the Tax Reform Act
expanded the use of the SNN outside of Federal Agencies, by authorizing the
577
direct use of the SSN in state and local government programs. In 1977,
Personal Privacy in an Information Society by the Privacy Protection Study
578
Commission was delivered to President Carter. It covered the relationships
among government agencies across a broad range of services and had a special
579
chapter on the SSN. The Debt Collections Act of 1982 required that the SSN be
collected as part of the applications for all federal loans (student, agriculture,
580
small business—each administered by different departments) as a standard
practice.
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 149
The Driver’s License Protection Act of 1994 places strict limits on who can access
582
the Department of Motor Vehicles’ data, and under what circumstances. The
583
e-Government Act of 2002 requires agencies that collect data about citizens to
complete a Privacy Impact Assessment (PIA) for electronic information systems
and to make the results public. The PIA must be conducted before developing or
procuring an ID system that will collect, maintain, or disseminate information in
an identifiable form or about members of the public. They must also conduct this
assessment when merging databases, or when business processes change
significantly by adding new uses or disclosures of information. Here is what the
584
PIAs must analyze and describe:
Conducting a PIA.
4. with whom the information will be shared (e.g., another agency for a
specified programmatic purpose);
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 150
Throughout the last two decades, there have been more reports by the federal
585
government about the SSN.
Today, in the United States the use of the SSN is strictly regulated and culturally
limited, while, in India, there is currently no privacy protection bill of any kind
586
that applies to the government or the private sector.
In the United States, several federal government statutes mandate the use of the
SSN for particular financial service transactions, such as opening a bank account,
587
cashing a check over $3,000 USD, being the beneficial owner of businesses, or
applying for a home loan. Because the SSN card is literally just a paper card with a
name and number on it, agencies also conduct Know Your Customer (KYC)
checks with identity documents that have photographs, such as driver’s licenses,
passports, military IDs, and permanent resident cards. Laws require the
collection of this type of data, but they also mandate the protection of this
588
information.
India, like the United States, has a KYC requirement driven by international
589
requirements mandated by the Financial Action Task Force (FATF) that put
these requirements in place after the September 11, 2001 terrorist attacks. The
original design of the UIDAI database would permit residents to do
authentication of their name and address. This process would start with a
resident sharing personal information with a bank. The bank would then send it
to the UIDAI which would send back an affirmative or negative answer to
whether it matched. While this design is commonly used to preserve individual
privacy, it also limits the amount of information that leaves the database.
Indian addresses are much more complex than U.S. addresses: each building has
590
a name or number, within a block, within a district, and then a city. In addition
to this complexity, India has 22 official languages. Its administration uses English,
which most residents do not read or speak. Language barriers make it difficult to
get an accurate answer from the UIDAI database. Lastly, regulated banks require
a copy of an identity document, and many people do not have an appropriate one.
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 151
In the United States, there are very few services offered by any government that
allows private companies to connect with a government database and extract
592
private citizen data. The Social Security Administration has set up a system
known as Consent Based SSN Verification (CBSV). Various private companies
have been granted a special license for $5,000 USD to connect to the
government agency to do this type of check (CBSV).
Businesses use one of these agencies to check against the database with the
consent of the person whose information is being checked. They share the name,
SSN, and date of birth. These are sent to the government, checked against the
SSN Master File, and a Yes/No indicator is sent back to the business.
In contrast, in India residents are regularly asked to show their Aadhaar “card”
and this document is regularly photocopied. As a result of this process, a new
convention has arisen where individuals take a photocopy of their card and write
the purpose for which it was made across the image. This, users hope, is a way to
prevent the photo copy from being used by someone else to open an account or to
593
obtain a service in their name.
When people seek employment in the United States, they are required to share
their SSN with their employer. Employers are required by law to verify that the
people they are hiring have valid SSNs. The CBSV is used for employee SSN
verifications.
Individuals can also self-check via the e-Verify system set up by the Department
of Homeland Security on an online portal. Individuals can enter their SSN with
their current citizenship status and receive a report about their current eligibility
to work.
Employers can enroll to use the e-Verify system too. They log into the system
every time they want to check a potential employee’s status by using information
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 152
Employers who want to check if an SSN is valid for the purposes of tax
withholding can register with the Social Security Number Verification System
(SSNVS) to do so. Employers enter the names and SSN of employees that they
want to check. The system reports back if they match a person in the system.
Employers do this is to ensure that the taxes they are withholding from their
employees actually lines up with records at the Social Security Administration.
At the end of every quarter, employers send the government income taxes that
they withhold from their employees along with the name and SSN. The
government uses the SSN as an index to tax records and social benefit schemes
into which they pay social security and Medicare.
While these systems can potentially be used to extract information for other
594
purposes, this is explicitly prohibited.
Figure 11: Authentication Process of Matrix that Integrates with the AEBAS
server. [Link]
[Link].
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 153
The framing of how a national identity number can and must be used, along with
the regulation of its use, often determines how companies, other governments,
and citizens all use national identity numbers. It is vital that a global dialogue
continues about the specifics of how the identity systems work in the two largest
democracies.
While in India I learned there were a lot of assumptions made about how the U.S.
system works that are actually incorrect. I hope that this paper provides a starting
point to understand the key differences between the U.S. and Indian systems and
made clear to readers from both countries about how the systems work.
In the United States, there is significant regulation around the use of SSNs, and
extensive privacy protection rules about any personally identifiable information.
597
There is public dialogue, which has been ongoing since the creation of the
SSN, about how much information is appropriate for the U.S. government to have
on residents in order to provide them with services.
The Aadhar system is more exclusively digital because it was created in the last
10 years. There are no privacy or data protection laws in place in India. The
creators of the Aadhaar system chose to expand the features of the system
without public input and feedback, and because they are their own regulator.
Identity systems are powerful tools that have the potential for good, but also for
great harm. Those highlighting legitimate concerns in democracies should not be
fearful that their criticism will be criminalized. Public engagement and robust
public dialogue about identity systems in all countries should continue and be
supported.
[Link]/fellows/reports/anthology-working-papers-new-americas-us-india-fellows/ 154