UPSC CSE 2026 Essay Paper Discussion

The New Aadhaar App: Face Authentication, Consent and Digital Identity

Why in News?

The Unique Identification Authority of India (UIDAI) has rolled out a redesigned Aadhaar app that turns the 12-digit number into a fully digital, on-phone identity, replacing the practice of sharing printed copies of the Aadhaar letter for routine verification.

The headline feature is face authentication paired with a scannable QR code: a person can verify identity in seconds and share only the specific fields a checker needs, all gated by an explicit on-device consent step.

  • App enables QR-based offline verification — the verifier scans a code instead of photographing or photocopying the Aadhaar letter.
  • Face authentication on the phone confirms the holder is present, reducing reliance on fingerprint or OTP for in-person checks.
  • Selective disclosure lets a user share only name and photo (or only age band) rather than the full demographic record.
  • Aim, per UIDAI, is to cut physical-Aadhaar misuse and speed up offline KYC at hotels, airports, shops and counters.
  • The redesign sits on top of the existing Aadhaar Act, 2016 framework and the Digital Personal Data Protection (DPDP) Act, 2023 obligations on consent and data minimisation.

The development matters in the context of:

  • Why this matters in the context of digital public infrastructure (DPI): Aadhaar is the identity layer of India’s JAM trinity and the new app re-engineers how that layer is presented and consented to.
  • Why this matters in the context of privacy: the Puttaswamy (2017–2018) jurisprudence set limits on Aadhaar use that any new feature must respect.
  • Why this matters in the context of data protection: consent architecture and selective disclosure are the operational test of the DPDP Act, 2023 principle of data minimisation.
Flat illustration of a smartphone showing a digital identity card with a face-scan ring, QR code, consent toggle and a protective shield.
Illustration of consent-driven, face-authenticated digital identity verification on a smartphone. Illustration: AI-generated (Freepik)
The New Aadhaar App: Face Authentication, Consent and Digital Identity — quick facts

UPSC Relevance

Prelims Relevance

  • UIDAI is a statutory body under the Aadhaar Act, 2016, attached to the Ministry of Electronics and Information Technology (MeitY).
  • Aadhaar is a 12-digit random number; it is proof of identity, not of citizenship.
  • Puttaswamy v. Union of India (2017) recognised the right to privacy as part of Article 21; the 2018 Aadhaar verdict upheld the Act with limits.
  • Section 7 of the Aadhaar Act allows Aadhaar for subsidies, benefits and services funded from the Consolidated Fund of India.
  • The 2018 verdict struck down Section 57, restricting Aadhaar use by private entities without a backing law.
  • DPDP Act, 2023 rests on consent, purpose limitation and the role of the Data Principal and Data Fiduciary.
  • JAM trinity = Jan Dhan accounts + Aadhaar + Mobile, the backbone of Direct Benefit Transfer (DBT).
  • Offline verification modes already include the QR code on the Aadhaar letter and masked Aadhaar; the app extends this on-device.
  • Face authentication is an additional UIDAI modality alongside fingerprint, iris and OTP.

Mains Relevance

GS Paper 2

  • Role of digital public infrastructure and identity in welfare delivery and governance reform.
  • Tension between state-led identity systems and the fundamental right to privacy after Puttaswamy.

GS Paper 3

  • Data protection, consent architecture and cyber-security implications of a phone-resident national ID.
  • Use of biometrics and face recognition in citizen-facing services: benefits and risks.

GS Paper 2

  • Citizens’ charters of accountability and transparency for bodies like UIDAI handling sensitive data.

Essay

  • Convenience versus consent: who owns my identity in a digital republic?
  • Technology as an enabler of inclusion and a vector of surveillance.

Background and Context

What changed in the new app

The redesign shifts Aadhaar from a paper letter to a consent-gated digital wallet on the phone.

  • Identity lives on the device; verification happens by QR scan rather than by handing over a photocopy.
  • Face authentication ties the live holder to the record, useful where fingerprint readers or network OTP are impractical.
  • Selective disclosure means a hotel or shop can receive only the fields it needs — say name and photo — not the full demographic set.
  • Every share is preceded by an explicit consent prompt, logging that the holder authorised that specific disclosure.
  • UIDAI frames the goal as cutting physical-Aadhaar misuse — forged copies, retained photocopies and casual data leakage at counters.
The New Aadhaar App: Face Authentication, Consent and Digital Identity — exam lens

The statutory backbone: Aadhaar Act and UIDAI

The app does not create new powers; it operates inside the existing 2016 statute.

  • The Aadhaar Act, 2016 gives UIDAI statutory status and governs enrolment, authentication and the protection of the Central Identities Data Repository (CIDR).
  • Section 7 anchors Aadhaar to subsidies and services drawn from the Consolidated Fund of India.
  • UIDAI functions under MeitY and is responsible for security of biometric and demographic data.
  • Authentication today already supports fingerprint, iris, OTP and face; the app makes the face mode citizen-facing and offline-friendly.

Privacy and the Puttaswamy limits

Any expansion of Aadhaar’s reach is read against the Supreme Court’s privacy jurisprudence.

  • Justice K.S. Puttaswamy v. Union of India (2017) held that the right to privacy is intrinsic to Article 21.
  • The 2018 Constitution-bench verdict upheld the Aadhaar Act but read it down — proportionality and a legitimate state aim are required.
  • The court struck down Section 57, barring private companies from demanding Aadhaar absent a specific law.
  • A consent-led, minimal-disclosure design is, in effect, the architecture Puttaswamy’s proportionality test invites.
  • Mission creep — quietly widening the fields verifiers can pull — remains the live constitutional risk.

Data protection under the DPDP Act, 2023

The new features map directly onto the obligations the data-protection law imposes.

  • The Digital Personal Data Protection Act, 2023 makes consent the default basis for processing personal data.
  • Principles of purpose limitation and data minimisation are exactly what selective disclosure operationalises.
  • The holder is a Data Principal; verifiers act as Data Fiduciaries accountable for what they collect and retain.
  • A verifier that scans a QR and keeps only the consented fields should, in principle, hold far less than one that photographs a full Aadhaar letter.
  • The Data Protection Board envisaged under the Act is the grievance and enforcement channel if disclosure rules are breached.

Aadhaar in the JAM trinity and DPI stack

Identity is one rail of India’s wider digital public infrastructure.

  • The JAM trinity — Jan Dhan, Aadhaar, Mobile — powers Direct Benefit Transfer and has cut leakage in welfare delivery, anchoring India’s digital public infrastructure.
  • Aadhaar is the identity layer that sits alongside payments (UPI) and data-sharing (Account Aggregator) in the DPI stack.
  • A cleaner, consent-driven verification flow strengthens trust in this stack as services digitise.
  • Offline modes matter for inclusion where connectivity is weak, so face-plus-QR can reach beyond OTP-dependent users.

Concerns and the criticism

Convenience invites its own risks that the design must answer.

  • Face recognition carries error and bias risks; a false match or mismatch can wrongly deny or grant access.
  • On-device identity raises device security and lost-phone questions that the app’s safeguards must cover.
  • A friction-free share button can normalise over-collection unless verifiers are audited for what they actually request.
  • Exclusion persists — those without smartphones, or with biometrics that fail to read, still need a non-digital fallback.
  • Centralised identity remains a high-value cyber-security target; breach impact scales with adoption.

Way Forward

Consent and minimisation by design

  • Default every share to the fewest fields a use-case needs, with clear logs the holder can review.
  • Audit Data Fiduciaries for over-collection and enforce purpose limitation under the DPDP Act.

Guardrails for biometrics

  • Publish face-authentication accuracy and bias metrics, and keep a robust non-biometric fallback to prevent exclusion.
  • Mandate a manual verification route so a failed face match never becomes a denial of service or benefit.

Operationalise the Data Protection Board quickly so citizens have a real grievance forum, and run public-awareness drives so users understand consent, selective disclosure and how to revoke a share.

Conclusion

The redesigned Aadhaar app is less a new power than a new presentation layer — it tries to make identity verification convenient while honouring the consent and minimisation logic that the DPDP Act, 2023 and the Puttaswamy judgments demand.

Whether it earns trust will turn on the details: transparent biometric accuracy, audited verifiers, a working grievance board and a fallback for those the technology leaves behind. Done well, it is a model for citizen-controlled digital identity; done carelessly, it risks the very mission creep the courts warned against.

UPSC Practice Questions

Prelims MCQ 1

With reference to the Aadhaar framework in India, consider the following statements:

  1. UIDAI is a statutory body established under the Aadhaar Act, 2016.
  2. Aadhaar is proof of Indian citizenship.
  3. The Supreme Court in the 2018 verdict struck down Section 57, which had allowed private entities to seek Aadhaar.

How many of the above statements are correct?

(a) Only one (b) Only two (c) All three (d) None

Answer: (b) Only two

Explanation:

Statements 1 and 3 are correct: UIDAI is statutory under the 2016 Act and the 2018 verdict struck down Section 57. Statement 2 is wrong — Aadhaar is proof of identity, not citizenship.

Prelims MCQ 2

The right to privacy was recognised as a fundamental right intrinsic to Article 21 in which case?

(a) Kesavananda Bharati v. State of Kerala (b) Justice K.S. Puttaswamy v. Union of India (2017) (c) Maneka Gandhi v. Union of India (d) Minerva Mills v. Union of India

Answer: (b) Justice K.S. Puttaswamy v. Union of India (2017)

Explanation:

The 2017 nine-judge Puttaswamy bench unanimously held that the right to privacy is intrinsic to the right to life and liberty under Article 21.

UPSC Mains Questions

  1. India’s new Aadhaar app introduces face authentication, consent-gated sharing and selective disclosure of identity data. Examine how these features address — and where they fall short of — the principles laid down in the Puttaswamy judgments and the DPDP Act, 2023. (250 words)
  2. Digital public infrastructure has transformed welfare delivery in India but also concentrated sensitive personal data. Critically evaluate the governance and data-protection safeguards needed for a phone-resident national identity system. (250 words)
  3. Discuss the trade-off between convenience and consent in state-led digital identity systems, with reference to the design of the redesigned Aadhaar app. (150 words)

Sources: UIDAI, Ministry of Electronics and Information Technology and Press Information Bureau.

Frequently Asked Questions

What is new in the redesigned Aadhaar app?

The app turns the 12-digit Aadhaar into a fully digital, on-phone identity. Its headline features are face authentication, a scannable QR code for offline verification, and selective disclosure — letting a person share only the specific fields a verifier needs, each behind an explicit consent prompt, instead of handing over a printed photocopy.

How does selective disclosure protect privacy?

Selective disclosure lets the holder reveal only what a given check requires — say name and photo, or just an age band — rather than the full demographic record. This operationalises the data-minimisation and purpose-limitation principles of the DPDP Act, 2023, so a hotel or shop ends up holding far less personal data than when it photographs an entire Aadhaar letter.

Is the new app legally backed?

Yes. It operates within the existing Aadhaar Act, 2016, which gives UIDAI its statutory status, and must comply with the consent and accountability obligations of the Digital Personal Data Protection Act, 2023. It adds no new statutory power; it changes how identity is presented and consented to.

How does this relate to the Puttaswamy judgment?

The 2017 Puttaswamy verdict held privacy to be a fundamental right under Article 21, and the 2018 verdict upheld Aadhaar with proportionality limits while striking down Section 57. A consent-led, minimal-disclosure design is broadly the architecture that the court’s proportionality test invites, though mission creep remains a risk to watch.

What are the main concerns with face authentication?

Face recognition can produce false matches or mismatches and may carry bias, risking wrongful denial or access. On-device identity also raises device-security and lost-phone questions, and there is a risk of normalising over-collection. A robust non-biometric fallback is essential so a failed face match never becomes a denial of a service or benefit.

Where does Aadhaar fit in the JAM trinity?

Aadhaar is the identity rail of the JAM trinity — Jan Dhan accounts, Aadhaar and Mobile — that underpins Direct Benefit Transfer and has reduced leakage in welfare delivery. In the wider digital public infrastructure stack it sits alongside UPI for payments and the Account Aggregator for data sharing, acting as the trusted identity layer.

Tell Google you want more of this.

Add Anantam IAS as a preferred source

One tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.

Share this

PDF

Gaurav Tiwari

Written by

Gaurav Tiwari

UPSC Content Team Head · Web Developer & Designer · AnantamIAS

Recognized as one of India’s best content marketers, Gaurav Tiwari is an SEO strategist, WordPress developer, and founder of Gatilab. He builds websites that load in under a second, creates content that ranks on Google’s first page, and develops WordPress plugins and tools used on thousands of live sites.

Specialises in · Writing, web development, design — UPSC prep tooling Experience · 16+ years Visit website ↗

Want tomorrow's brief in your inbox before coffee?

We edit — we don't scrape. Every morning, one lean briefing written for UPSC Prelims + Mains relevance.