Anantam IASCurrent Affairs · 29 January 2026

The New Aadhaar App: Face Authentication, Consent and Digital Identity

General Studies · Governance · GS II · Science & Tech

Why in News?

The Unique Identification Authority of India (UIDAI) has rolled out a redesigned Aadhaar app that turns the 12-digit number into a fully digital, on-phone identity, replacing the practice of sharing printed copies of the Aadhaar letter for routine verification.

The headline feature is face authentication paired with a scannable QR code: a person can verify identity in seconds and share only the specific fields a checker needs, all gated by an explicit on-device consent step.

The development matters in the context of:

Flat illustration of a smartphone showing a digital identity card with a face-scan ring, QR code, consent toggle and a protective shield.
Illustration of consent-driven, face-authenticated digital identity verification on a smartphone. Illustration: AI-generated (Freepik)
The New Aadhaar App: Face Authentication, Consent and Digital Identity — quick facts

UPSC Relevance

Prelims Relevance

Mains Relevance

GS Paper 2

GS Paper 3

GS Paper 2

Essay

Background and Context

What changed in the new app

The redesign shifts Aadhaar from a paper letter to a consent-gated digital wallet on the phone.

The New Aadhaar App: Face Authentication, Consent and Digital Identity — exam lens

The statutory backbone: Aadhaar Act and UIDAI

The app does not create new powers; it operates inside the existing 2016 statute.

Privacy and the Puttaswamy limits

Any expansion of Aadhaar’s reach is read against the Supreme Court’s privacy jurisprudence.

Data protection under the DPDP Act, 2023

The new features map directly onto the obligations the data-protection law imposes.

Aadhaar in the JAM trinity and DPI stack

Identity is one rail of India’s wider digital public infrastructure.

Concerns and the criticism

Convenience invites its own risks that the design must answer.

Way Forward

Consent and minimisation by design

Guardrails for biometrics

Operationalise the Data Protection Board quickly so citizens have a real grievance forum, and run public-awareness drives so users understand consent, selective disclosure and how to revoke a share.

Conclusion

The redesigned Aadhaar app is less a new power than a new presentation layer — it tries to make identity verification convenient while honouring the consent and minimisation logic that the DPDP Act, 2023 and the Puttaswamy judgments demand.

Whether it earns trust will turn on the details: transparent biometric accuracy, audited verifiers, a working grievance board and a fallback for those the technology leaves behind. Done well, it is a model for citizen-controlled digital identity; done carelessly, it risks the very mission creep the courts warned against.

UPSC Practice Questions

Prelims MCQ 1

With reference to the Aadhaar framework in India, consider the following statements:

  1. UIDAI is a statutory body established under the Aadhaar Act, 2016.
  2. Aadhaar is proof of Indian citizenship.
  3. The Supreme Court in the 2018 verdict struck down Section 57, which had allowed private entities to seek Aadhaar.

How many of the above statements are correct?

(a) Only one (b) Only two (c) All three (d) None

Answer: (b) Only two

Explanation:

Statements 1 and 3 are correct: UIDAI is statutory under the 2016 Act and the 2018 verdict struck down Section 57. Statement 2 is wrong — Aadhaar is proof of identity, not citizenship.

Prelims MCQ 2

The right to privacy was recognised as a fundamental right intrinsic to Article 21 in which case?

(a) Kesavananda Bharati v. State of Kerala (b) Justice K.S. Puttaswamy v. Union of India (2017) (c) Maneka Gandhi v. Union of India (d) Minerva Mills v. Union of India

Answer: (b) Justice K.S. Puttaswamy v. Union of India (2017)

Explanation:

The 2017 nine-judge Puttaswamy bench unanimously held that the right to privacy is intrinsic to the right to life and liberty under Article 21.

UPSC Mains Questions

  1. India’s new Aadhaar app introduces face authentication, consent-gated sharing and selective disclosure of identity data. Examine how these features address — and where they fall short of — the principles laid down in the Puttaswamy judgments and the DPDP Act, 2023. (250 words)
  2. Digital public infrastructure has transformed welfare delivery in India but also concentrated sensitive personal data. Critically evaluate the governance and data-protection safeguards needed for a phone-resident national identity system. (250 words)
  3. Discuss the trade-off between convenience and consent in state-led digital identity systems, with reference to the design of the redesigned Aadhaar app. (150 words)

Sources: UIDAI, Ministry of Electronics and Information Technology and Press Information Bureau.

Frequently Asked Questions

What is new in the redesigned Aadhaar app?

The app turns the 12-digit Aadhaar into a fully digital, on-phone identity. Its headline features are face authentication, a scannable QR code for offline verification, and selective disclosure — letting a person share only the specific fields a verifier needs, each behind an explicit consent prompt, instead of handing over a printed photocopy.

How does selective disclosure protect privacy?

Selective disclosure lets the holder reveal only what a given check requires — say name and photo, or just an age band — rather than the full demographic record. This operationalises the data-minimisation and purpose-limitation principles of the DPDP Act, 2023, so a hotel or shop ends up holding far less personal data than when it photographs an entire Aadhaar letter.

Is the new app legally backed?

Yes. It operates within the existing Aadhaar Act, 2016, which gives UIDAI its statutory status, and must comply with the consent and accountability obligations of the Digital Personal Data Protection Act, 2023. It adds no new statutory power; it changes how identity is presented and consented to.

How does this relate to the Puttaswamy judgment?

The 2017 Puttaswamy verdict held privacy to be a fundamental right under Article 21, and the 2018 verdict upheld Aadhaar with proportionality limits while striking down Section 57. A consent-led, minimal-disclosure design is broadly the architecture that the court’s proportionality test invites, though mission creep remains a risk to watch.

What are the main concerns with face authentication?

Face recognition can produce false matches or mismatches and may carry bias, risking wrongful denial or access. On-device identity also raises device-security and lost-phone questions, and there is a risk of normalising over-collection. A robust non-biometric fallback is essential so a failed face match never becomes a denial of a service or benefit.

Where does Aadhaar fit in the JAM trinity?

Aadhaar is the identity rail of the JAM trinity — Jan Dhan accounts, Aadhaar and Mobile — that underpins Direct Benefit Transfer and has reduced leakage in welfare delivery. In the wider digital public infrastructure stack it sits alongside UPI for payments and the Account Aggregator for data sharing, acting as the trusted identity layer.