In 2009, I became extremely concerned with the concept of Unique Identity for various reasons. Connected with many like minded highly educated people who were all concerned.
On 18th May 2010, I started this Blog to capture anything and everything I came across on the topic. This blog with its million hits is a testament to my concerns about loss of privacy and fear of the ID being misused and possible Criminal activities it could lead to.
In 2017 the Supreme Court of India gave its verdict after one of the longest hearings on any issue. I did my bit and appealed to the Supreme Court Judges too through an On Line Petition.
In 2019 the Aadhaar Legislation has been revised and passed by the two houses of the Parliament of India making it Legal. I am no Legal Eagle so my Opinion carries no weight except with people opposed to the very concept.
In 2019, this Blog now just captures on a Daily Basis list of Articles Published on anything to do with Aadhaar as obtained from Daily Google Searches and nothing more. Cannot burn the midnight candle any longer.
"In Matters of Conscience, the Law of Majority has no place"- Mahatma Gandhi
Ram Krishnaswamy
Sydney, Australia.

Aadhaar

The UIDAI has taken two successive governments in India and the entire world for a ride. It identifies nothing. It is not unique. The entire UID data has never been verified and audited. The UID cannot be used for governance, financial databases or anything. It’s use is the biggest threat to national security since independence. – Anupam Saraph 2018

When I opposed Aadhaar in 2010 , I was called a BJP stooge. In 2016 I am still opposing Aadhaar for the same reasons and I am told I am a Congress die hard. No one wants to see why I oppose Aadhaar as it is too difficult. Plus Aadhaar is FREE so why not get one ? Ram Krishnaswamy

First they ignore you, then they laugh at you, then they fight you, then you win.-Mahatma Gandhi

In matters of conscience, the law of the majority has no place.Mahatma Gandhi

“The invasion of privacy is of no consequence because privacy is not a fundamental right and has no meaning under Article 21. The right to privacy is not a guaranteed under the constitution, because privacy is not a fundamental right.” Article 21 of the Indian constitution refers to the right to life and liberty -Attorney General Mukul Rohatgi

“There is merit in the complaints. You are unwittingly allowing snooping, harassment and commercial exploitation. The information about an individual obtained by the UIDAI while issuing an Aadhaar card shall not be used for any other purpose, save as above, except as may be directed by a court for the purpose of criminal investigation.”-A three judge bench headed by Justice J Chelameswar said in an interim order.

Legal scholar Usha Ramanathan describes UID as an inverse of sunshine laws like the Right to Information. While the RTI makes the state transparent to the citizen, the UID does the inverse: it makes the citizen transparent to the state, she says.

Good idea gone bad
I have written earlier that UID/Aadhaar was a poorly designed, unreliable and expensive solution to the really good idea of providing national identification for over a billion Indians. My petition contends that UID in its current form violates the right to privacy of a citizen, guaranteed under Article 21 of the Constitution. This is because sensitive biometric and demographic information of citizens are with enrolment agencies, registrars and sub-registrars who have no legal liability for any misuse of this data. This petition has opened up the larger discussion on privacy rights for Indians. The current Article 21 interpretation by the Supreme Court was done decades ago, before the advent of internet and today’s technology and all the new privacy challenges that have arisen as a consequence.

Rajeev Chandrasekhar, MP Rajya Sabha

“What is Aadhaar? There is enormous confusion. That Aadhaar will identify people who are entitled for subsidy. No. Aadhaar doesn’t determine who is eligible and who isn’t,” Jairam Ramesh

But Aadhaar has been mythologised during the previous government by its creators into some technology super force that will transform governance in a miraculous manner. I even read an article recently that compared Aadhaar to some revolution and quoted a 1930s historian, Will Durant.Rajeev Chandrasekhar, Rajya Sabha MP

“I know you will say that it is not mandatory. But, it is compulsorily mandatorily voluntary,” Jairam Ramesh, Rajya Saba April 2017.

August 24, 2017: The nine-judge Constitution Bench rules that right to privacy is “intrinsic to life and liberty”and is inherently protected under the various fundamental freedoms enshrined under Part III of the Indian Constitution

"Never doubt that a small group of thoughtful, committed citizens can change the World; indeed it's the only thing that ever has"

“Arguing that you don’t care about the right to privacy because you have nothing to hide is no different than saying you don’t care about free speech because you have nothing to say.” -Edward Snowden

In the Supreme Court, Meenakshi Arora, one of the senior counsel in the case, compared it to living under a general, perpetual, nation-wide criminal warrant.

Had never thought of it that way, but living in the Aadhaar universe is like living in a prison. All of us are treated like criminals with barely any rights or recourse and gatekeepers have absolute power on you and your life.

Announcing the launch of the # BreakAadhaarChainscampaign, culminating with events in multiple cities on 12th Jan. This is the last opportunity to make your voice heard before the Supreme Court hearings start on 17th Jan 2018. In collaboration with @no2uidand@rozi_roti.

UIDAI's security seems to be founded on four time tested pillars of security idiocy

1) Denial

2) Issue fiats and point finger

3) Shoot messenger

4) Bury head in sand.

God Save India

Showing posts with label Rakesh Dwivedi-UIDAI Lawyer. Show all posts
Showing posts with label Rakesh Dwivedi-UIDAI Lawyer. Show all posts

Wednesday, May 2, 2018

13411 - Telcos forcing you to link Aadhaar? This petition is urging TRAI to pull them up - The News Minute

Aadhaar
The petition is urging TRAI to pull up telecom service providers who are wrongfully forcing people to link their Aadhaar to their numbers.

Over the last few months, cell phone users must have grown all too used to telecom companies sending persistent messages, urging them to link their Aadhaar. This, even as the Supreme Court has said that linking of the Aadhaar cannot be made mandatory as long as the arguments against its constitutional validity are being heard.

Now, a petition is urging TRAI to pull up telecom service providers who are wrongfully forcing people to link their Aadhaar to their numbers, and even refusing to issue a new SIM unless Aadhaar is provided.

The petition on campaigning platform Jhatkaa, says:
“For more than a year, you, me and a billion of our fellow citizens have been receiving messages from the likes of Airtel, Vodafone and Reliance regarding “mandatory” linking. Many of us also had a difficult time in purchasing a SIM card. Did you know that at some places even foreigners were asked to provide their Aadhaar card to purchase SIM cards?

The Supreme Court finally gave us some clarity on this matter. The court says that Aadhaar is just one of the MANY verification options, and not the only one.

Until the case of Aadhaar’s constitutional validity is completely heard, telecom companies should not jump the gun and harass individuals by asking them to link their Aadhaar number. And this directive should come from TRAI, the body that regulates India’s telecom sector.”

The petition, which is addressed to TRAI chairperson RS Sharma, urges him to tell telcos to wait until the SC hears the arguments against Aadhaar and subsequently rules on the mandatory linking aspect.

It also explains how the government has been making another claim – that it is in fact the apex court which mandated linking Aadhaar to mobile number. But a few days ago, UIDAI counsel Rakesh Dwivedi even admitted to the SC that while the court had not demanded the linkage, the government had started pushing for it based on recommendations of Telecom Regulatory Authority of India (TRAI).

What had actually happened was that in February 2017, the Supreme Court had ordered for verification of all cell phone subscribers within a year. However, while the recommendation that Aadhaar should be used for verification came up, there was no mandate to make it the only way to authenticate a SIM card.
The government however, took this to say that it was the Supreme Court which had directed for mandatory SIM-Aadhaar linking.  In fact, here’s a tweet by Law and Justice and IT Minister Ravi Shankar Prasad, making the claim on Twitter.
The Jhatkaa petition urges people to come together to urge TRAI to pull up telecom companies and stand against the telcos who force customers to provide Aadhaar details to recharge their phones, get a new SIM and so on.
You can access the petition here.

Sunday, April 29, 2018

13396 - Aadhaar Hearing: The Government’s Arguments So Far - Quint

Aadhaar Hearing: The Government’s Arguments So Far

Arpan Chaturvedi @arpanc_
28 April 2018, 4:30 PM28 April 2018, 4:30 PM

SUBSCRIBE to Bloomberg | Quint
The Daily Newsletter

The central and certain state governments and the Aadhaar-issuing body UIDAI continued to maintain that the biometric identification is voluntary and does not violate the right to privacy.

Attorney General of India KK Venugopal, Additional Solicitor General of India Tushar Mehta, senior advocates Rakesh Dwivedi, Jayant Bhushan, NK Kaul and other lawyers argued on behalf of the government in favour of the Aadhaar programme and the Aadhaar Act, 2016. Petitioners in the matter have completed their arguments, highlighting concerns about possible citizen profiling, state control, denial of public services and hasty passage of the Aadhaar Act.

A five-judge Constitution bench headed by Chief Justice of India Dipak Misra is hearing the matter that will decide the fate of the world’s largest biometric identification programme. Another Constitutional bench, in a verdict stemming from the Aadhaar matter, had earlier ruled that privacy is a fundamental right.

Here are the key arguments made for Aadhaar by the government and UIDAI’s counsels:

Right To Privacy Not An Absolute Right
The right to privacy is not absolute. There can be instances when this right can be curtailed and the Aadhaar programme is one such instance.
The Aadhaar programme satisfies the three conditions when right to privacy can be curtailed as laid down by the nine-judge bench. These include existence of a law, compelling state interest/larger public interest and test of proportionality.
There must be a balance between protecting right to privacy and ensuring right to a dignified life for all the citizens.
The Aadhaar programme ensures the right to dignified life for citizens by plugging leakages in distribution of subsidies.
The right to life is also a fundamental right under Article 21 of the Constitution.
Each of the subsidies provided under the Aadhaar Act is traceable to Article 21, ensuring a right to a dignified life and therefore it is a constitutionally valid scheme.


Also Read: Is Aadhaar Likely To Pass The Privacy Test?

Minimum Invasion Of Privacy In Aadhaar

Aadhaar does not violate the fundamental right to privacy, the Attorney General of India argued.
Data collected as part of the scheme is minimum.
If the top court feels any data should not have been taken, the government will delete that data and stop using it in the Aadhaar programme.

It requires only the bare demographic particulars while eschewing most other demographic particulars. It further requires the bare biometric factors, namely photograph, fingerprints and iris.KK Venugopal, Attorney General of India

Aadhaar-Mobile SIM Card Linkage

The government till now had said that mobile phone connections were being linked with Aadhaar on the directions of the Supreme Court in the Lokniti Foundation’s petition seeking verification of every user.
During the hearing, Justice DY Chandrachud said that the Supreme made no such direction in the Lokniti case.

In fact there was no such direction from the Supreme Court, but you took it and used it as a tool to make Aadhaar mandatory for mobile users. Justice DY Chandrachud (PTI Report Citing Court Proceedings)

The central government maintained there has no violation of any interim orders passed by the top court ever since the challenge to the Aadhaar was first heard.
It said before the Aadhaar Act was introduced, “obtaining an Aadhaar number or an enrollment number was voluntary, especially because of the interim orders passed by this court”.

UIDAI CEO’s Presentation

The UIDAI gets minimum information when transactions are carried out using Aadhaar authentication.
UIDAI does not get to know the purpose and details of those transactions, its Chief Executive Officer Ajay Bhushan Pandey said.
The e-KYC data is not shared with anyone except with the Aadhaar holder who does the transaction using Aadhaar authentication.
To counter petitioners’ argument of Aadhaar data leaks, Pandey said there has not been a single instance of any data leak from the UIDAI database.
The Attorney General also said the Aadhaar database has strong security features.


Also Read: India Cites Height of Database Center Wall as ID Leak Shield
BloombergQuint
Stay Updated With Law & Policy News On BloombergQuint

Saturday, April 28, 2018

13375 - Didn't Say It's Mandatory to Link Aadhaar With Mobile Numbers: Supreme Court - The Wire


"In fact there was no such direction from the Supreme Court, but you took it and used it as a tool to make Aadhaar mandatory for mobile users."


26/APR/2018

New Delhi: The Supreme Court on Wednesday raised questions over the government’s decision ordering mandatory seeding of mobile numbers with Aadhaar and said its earlier order on mandatory authentication of users was used as a “tool”.

A five-judge constitution bench headed by Chief Justice Dipak Misra, hearing a clutch of petitions challenging Aadhaar and its enabling 2016 law, said its order on a PIL filed by Lokniti Foundation had said that mobile users needed to be verified in the interest of national security.

“In fact there was no such direction from the Supreme Court, but you took it and used it as a tool to make Aadhaar mandatory for mobile users,” the bench, also comprising Justices A.K. Sikri, A.M. Khanwilkar, D.Y. Chandrachud and Ashok Bhushan, said.

Senior advocate Rakesh Dwivedi, appearing for the Unique Identification Authority of India (UIDAI), said the Department of Telecommunication (DoT) notification talked about re-verification of mobile numbers by using e-KYC process and the Telegraph Act gave “exclusive power to central government to decide license conditions” of service providers.

“How can you (DoT) impose condition on service recipients for seeding Aadhaar with mobile phones,” the bench said, adding that license agreements were between the government and the service providers.

“In the Lokniti Foundation case, the SC has not directed linking of SIM with UID. But the Union government’s circular says so. There was no direction by the court…” Economic Times quoted Justice Chandrachud as saying during the hearing.

In September 2017, law minister Ravi Shankar Prasad too had said that the Supreme Court had made it compulsory to link Aadhaar with mobile numbers.

Writing in The Wire then, Gopal Krishna had pointed out how the media was misrepresenting the Supreme Court’s words.
Dwivedi said the direction to seed mobile with Aadhaar was taken in pursuance of TRAIs recommendation. Besides, the government was entitled and had legitimate state interest to ensure that a sim card is given to only those who applied, he said, seeking to allay apprehensions that the state will surveil the people 24×7.

“My submission is that the government had a legal basis to link Aadhaar with SIM by virtue of section 4 of the Telegraph Act and also, the measure is reasonable in the interest of national security,” the lawyer stressed.

Dwivedi, at the outset, alleged that the Aadhaar scheme was being unfairly targeted as nobody was questioning the banks and the telecom firms on collection of information.

The banks and telecom companies have much “bigger data base” about the citizens, he said, adding, “For example, Vodafone has much bigger data base of information even without Aadhaar. The Aadhaar data is immaterial for them.”

“Appreciate the fact as to how much information a bank possesses about its customers. Every transaction as to what I purchase by using cards, where and when, all this information is with banks. Aadhaar does not tell all this. This information are already there and is being used for commercial purposes,” he said, adding that a person starts getting numerous calls before their car insurances expire.

He said people are being “scared” about Aadhaar but “nobody questions the telecom companies, banks…. Their single target is Aadhaar”.

Dwivedi informed the bench about an app, available on Google Playstore and said it has so many personal information about a person. He gave details, procured by using the app, about him, his family members to the bench.

The bench was pleasantly surprised. Dwivedi said it has details regarding how much he charged the Jammu and Kashmir government for appearing in a case.

The lawyer referred to the control being enjoyed by the UIDAI over entities, private and government, which seek Aadhaar authentication for providing services and benefits to citizens.
These entities cannot track any individual by using these information and moreover, they themselves have enough information with them, he said, adding that Aadhaar cannot lead to surveillance as apprehended by the petitioners.
“Vodafone can do targeted advertising using the data which is already happening without Aadhaar. Vodafone has far more demographic data about an individual than UIDAI has,” Dwivedi said, adding that at the most, such details can lead to formation of a directory and targeted advertisements is happening already.

“Google and Facebook process tremendous data on a daily basis. UIDAI does not have that kind of algorithm,” he said and urged the court to save the Aadhaar law and suggest measures, if any, to make it work.

He referred to a list of entities and said most of them required one-time authentication and hence there was no question that State will surveil the people 24×7. He also referred to inbuilt security features in the law and system of Aadhaar authentication.

Dwivedi concluded his arguments on behalf of UIDAI saying that CIDR was safe, data was encrypted and was held offline and above all, the Aadhaar scheme was safer than smart cards as there was no chance of data breach.

Lawyer Gopal Shankarnarayan, who started his submissions, said the right to identity was an “absolute fundamental right” and Aadhaar provided a kind of proof of identification to all Indians.


(With PTI inputs)

Thursday, April 26, 2018

13363 - Aadhaar hearing: Senior counsel Rakesh Dwiwedi argues that the UIDAI is constantly improving and upgrading its systems - First Post

News-Analysis Asheeta Regidi Apr 25, 2018 18:50 PM IST

On Day 32 of the Aadhaar hearings, senior counsel Rakesh Dwiwedi continued his arguments on behalf of the state. First, he argued that the reasonable expectation of privacy, in terms of permissible invasions of the right to privacy, was not subject to the standard of the least intrusive invasion, as argued by the petitioners. Instead, the standard was whether the invasion was proportional to the state's purpose for which it (the invasion) was being made.

He further disputed the applicability of many of the foreign judgments cited by the petitioners in support of their arguments. Lastly, the issue of metadata was discussed, where he argued that the metadata collected was in relation to the machine, and not the person.

No reasonable expectation of privacy in the public sphere
Dwiwedi commenced his arguments for the day with a discussion on the reasonable expectation of privacy. He first quoted a judgment from the Constitutional Court of South Africa, which found that privacy is the strongest in the inner sanctum of the mind, but shrinks as you move outside into the world. Based on this, he questioned if private life is entitled to protection outside the home, since there, people often given up their privacy. He further argued that in Europe, the concept of a reasonable expectation of privacy was not considered by the Courts, making US and UK laws and judgments more relevant in the Indian context.

Next, it was argued that in India there is a need for innovation and development of knowledge, along with the right to privacy. The correct test, he argued, was therefore not whether the invasion of privacy was least intrusive, but whether it was proportional to the purpose sought to be achieved. To emphasise the purpose sought to be achieved through Aadhaar, he quoted from the Puttaswamy judgment, arguing that ensuring that welfare benefits are not dissipated is a vital state interest.

Expectation of privacy varies according to the context
Next, he argued that in the public sphere, the right to privacy is diluted. The entire Aadhar project, he argued, is in the public sphere. Privacy concerns or reasonable expectation of privacy, further, could not be attached to information collected via Aadhaar, like demographic information and photographs. He further argued that since at the requesting entity level, the entities and the information in them are dispersed and decentralised, these don’t deserve the same level of protection as the CIDR storing centralised information.
The Bench, here, observed that core biometric information has higher privacy concerns, but this does not imply that there are no concerns with other information. Dwiwedi agreed, stating that his point was that the reasonable expectation of privacy varies according to context.

Applicability of EU and US judgment
Next, he argued that 120 countries use biometric information, and nineteen European countries use biometric ID cards. Neither the Court of Justice of the European Union nor the European Court of Human Rights ever expressed any issued with such biometric cards.

Further, he argued that there was no need to refer to European laws for tests on proportionality for an invasion of privacy since this had already been developed by the Indian Supreme Court in the case of State of Madras v. VG Row. The Supreme Court, he argued, has never accepted the proposition that a restriction of fundamental rights must be the least intrusive one.

He also cited the US judgment of Ohio v. Akron, which dealt with disclosure requirements to authorities in relation to abortions, and Doe v. Reed, which dealt with the disclosure of signatures on a referendum campaign. Further, he cited the UK judgment of Wood v. Commissioner of Police, which held that taking of photographs in itself does not violate privacy.

Marper case supports the case for the State
Further, Dwiwedi also argued that the ECHR’s judgment in S and Marper v. UK, which had been quoted extensively by the petitioners, was actually in support of the State’s arguments. He argued that in Marper, it was held that whether retention of data raises privacy concerns depends on the context. He further argued that Marper had been decided in a very specific context, which was different from Aadhaar.

First, a difference had been drawn out between collection of fingerprints and the collection of DNA. DNA collection was held to be an issue because it contained non-neutral information. Fingerprint collection was also held to be non-neutral when collected in the context of crime. Aadhaar, it was argued, does not deal with the collection and retention of data in the context of crime, and also does not involve the collection of DNA. Further, he argued that Marper discussed appropriate safeguards, not 100 percent safeguards.

He also argued that most of the cases cited by the petitioners were similarly, in the context of crime or about censuses, and therefore inapplicable in the context of Aadhaar.
Aadhaar only collects limited technical metadata
Dwiwedi next turned to the issue of metadata. He argued that the cases cited by the petitioners, such as the Digital Rights Ireland case, involved the large-scale storage of metadata which bore no relation to any State purpose, unlike the metadata collected via Aadhaar. The metadata being collected in the cases cited, he argued, was a lot more intrusive. The U.S. v. Jones case, additionally, dealt with GPS systems, which is not used in Aadhaar.

He argued that Aadhaar, instead, only involved the collection of limited technical data. He argued that the need for the collection of metadata arose due to the need to exercise control over the REs. Further, no data was collected on the location or purpose of a transaction, but merely on the system. The Bench observed that the metadata collection was of the machine, but not of the person.

Adequate safeguards and data collection
Considering that surveillance and similar concerns with privacy invasions were cited by the petitioners with respect to the metadata collection in Aadhaar, he then cited the Supreme Court’s judgment in G. Sundarrajan v. Union of India. This case dealt with the setting up of a nuclear power plant in Kundankulam. He argued that here, the Court held that apprehensions of a Fukushima like incident should not prevent the setting up of the power plant. The Court found that the power plant would help guarantee the right to life and that there were adequate safety measures in place.

Based on this, he argued that this case establishes that safeguards can be read into Article 21. Further, with respect to the CIDR, this case establishes that the standard to be applied to the safety measures must be of ‘adequate’ safety measures, and not of zero risk. Further, constant vigilance will be required to ensure safety. In the case of Aadhaar, he argued, the UIDAI was constantly improving and upgrading its safety measures.
He further argued that a similar position had been adopted by the US Supreme Court in NASA v. Nelson. The US, he argued, had discarded the standard of the least restrictive invasion. He further argued that as per this case, the possibility of a data breach was not a ground to strike down the collection of data.

Aadhaar completely bars the sharing of data
To emphasise the protection of data in the case of Aadhaar, he argued, there is a bar on the sharing of data, and the data with the REs is completely dispersed. He argued that in Aadhar, further, there was consent for the data collection, and also a bar on using the data for anything other than authentication. He argued that if there are data breaches, they should be pointed to the UIDAI.

Next, he pointed out that the data protection law will be in place by May. The Court, here, pointed out that an area that requires consideration is remedies for data breaches. The counsel pointed to the Information Technology Act and Section 43A Act as remedies, and to the actions taken against Airtel, etc. The EU’s General Data Protection Regulation, he argued, dealt with balancing the free flow of data with data protection, while Aadhaar, dealt not with free flow, but no flow of data.
The arguments will continue on 25 April.

Sources of arguments include LiveTweeting of the case by Gautam Bhatia and Prasanna S.

You can read our complete coverage of the Aadhaar Supreme Court case below



The author is a lawyer and author specialising in technology laws. She is also a certified information privacy professional.

13361 - Aadhaar supported by UPA, NDA: UIDAI to SC - TNN


PTI | Apr 25, 2018, 22:28 IST

NEW DELHI: The Aadhaar scheme has the support of two successive governments and senior advocate Kapil Sibal, who had opposed it for a party in the Supreme Court, was part of the empowered Group of Ministers which had dealt with the 12-digit unique national identifier issue, the UIDAI counsel said on Wednesday. 

In a veiled attack on Sibal who was at the forefront of the move by opposition MPs to impeach the Chief Justice of India, senior advocate Rakesh Dwivedi, representing Unique Identification Authority of India (UIDAI), said the Congress leader was part of the Empowered Group of Minister (EGoM) that had dealt with the Aadhaar scheme. 

He said now the same person, who was once advocating the Aadhaar scheme, was making a submission that data would be compromised with private players. 

"Mr Sibal argued that the government is collecting data and would give them to private players," Dwivedi took a dig at Sibal while making his submission before a five-judge constitution bench headed by Chief Justice Dipak Misra. 

"The (Aadhaar) policy had the support of two successive governments," he told the bench which also comprised Justices A K Sikri, A M Khanwilkar, D Y Chandrachud and Ashok Bhushan.

"I will not say much," Dwivedi said and indicated about the recent developments involving the top judiciary.

Sibal, who had appeared for some petitioners opposed to the Aadhaar scheme, was not present in the courtroom. He recently said he would not be appearing before the CJI as he was a signatory to the impeachment notice.

TOP COMMENT
But UPA did not ask anyone to link all the personal to one number. It was for security and welfare scheme distribution purposes only. But NDA is trying to put the life of people at risk. Many students and people are still suffering only because of vague implementation of aadhaar by NDA. Gov trying to surveil each and every move of all the citizens which is always a very bad idea.

Bharath Kumar

Earlier, Sibal had opposed the Aadhaar scheme and said "our identity cannot be confined to mere Aadhaar numbers, we are all much more ... I am against the this one-nation-one-identity move."

The apex court is hearing a clutch of petitions challenging Aadhaar and its enabling 2016 law. 


13360 - Never directed Aadhaar-mobile number linkage, says Supreme Court - TNN


Dhananjay Mahapatra | TNN | Updated: Apr 26, 2018, 05:09 IST

HIGHLIGHTS
  • The apex court on Wednesday clarified that it had not ordered mandatory linkage of mobile phone numbers with Aadhaar
  • The CJI-led bench pointed out that the February 6, 2017, order merely recorded then Attorney General’s submission on Aadhaar
NEW DELHI: The mad rush to link mobile phone numbers with Aadhaar supposedly to comply with a directive of the Supreme Court was uncalled for. The apex court on Wednesday clarified that it had not ordered mandatory linkage, and said the government misinterpreted its February 6, 2017, observation and insisted on doing it. 

“In the Lokniti Foundation case, the SC has not directed linking of SIM with UID. But the Union government’s circular says so. There was no direction by the court...” Justice D Y Chandrachud said during the hearing before a bench that included Chief Justice Dipak Misra and Justices A K Sikri, A M Khanwilkar and Ashok Bhushan

The CJI-led bench pointed out that the February 6, 2017, order merely recorded then Attorney General Mukul Rohatgi’s submission that Aadhaar was one of the documents used for verification of subscriber identity. 

Significantly, senior advocate Rakesh Dwivedi, who appeared for UIDAI, agreed with the bench and said the government appeared to have taken the SC’s observations for verification of mobile phone subscribers seriously. 

Drawing Dwivedi’s attention to the February 6 order, the bench said the court merely recorded the AG’s submission that “an effective programme for the same would be devised at the earliest and the process of identity verification will be completed within one year”. 

The bench set the record straight when Dwivedi argued that one-time seeding of mobile number with Aadhaar was not a big ask and would not lead to intrusion into citizens’ privacy as no call records were maintained through Aadhaar.

UIDAI’s insistence that the Supreme Court had mandated that all mobile connections be linked with Aadhaar had led to a scramble of sorts, with mobile service providers, nudged by the government, inundating subscribers with dire messages on the need to abide by the alleged order.

TOP COMMENT
linking Aadhar to mobile numbers will stop blackmails, threat calls and ransom calls by 99%.... it should be definitely implemented...

Romanov Avtachika

The SC on March 13 had indefinitely extended the deadline for linkage of Aadhaar with mobile numbers and bank accounts of individuals and asked the government to wait till the constitution bench decided the validity of Aadhaar to take further steps in this regard.

The Centre had in the interim agreed to extend the deadline for bank account linkage with Aadhaar till March 31. 


13353 - Adopt doctor’s approach, try to save Aadhaar law: UIDAI - TNN


Dhananjay Mahapatra | TNN | Updated: Apr 25, 2018, 02:56 IST

HIGHLIGHTS
  • UIDAI on Tuesday urged the Supreme Court to test the constitutional validity of Aadhaar Act by adopting a doctor’s approach
  • UIDAI’s counsel Rakesh Dwivedi said the Indian law was much more stringent in protection of data
  • Aadhaar is a work under progress, so there is always scope for improvement, Dwivedi said

NEW DELHI: The Unique Identification Authority of India (UIDAI) on Tuesday urged the Supreme Court to test the constitutional validity of Aadhaar Act by adopting a doctor’s approach to make the best attempt to save the law rather than kill it. 

Responding to a five-judge constitution bench’s query about data safety measures, UIDAI’s counsel Rakesh Dwivedi compared Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, with the European Union’s General Data Protection Regulation (GDPR), which will come into effect from May 25, and said the Indian law was much more stringent in protection of data. 

Dwivedi said, “The EU data protection regime allows a host of purposes for which core biometrics of individuals can be shared. Under the Aadhaar Act, core biometrics can never be shared by the UIDAI. Anyone sharing it will be committing an offence and will be punished. The Aadhaar Act makes data more secure, sharing punishable and prescribes specific purposes for which only demographic data, which is in public domain, is used for authentication.”

Presenting submissions before a bench of CJI Dipak Misra and Justices A K Sikri, A M Khanwilkar, D Y Chandrachud and Ashok Bhushan, Dwivedi said the court, while examining validity of Aadhaar, must adopt a doctor’s approach and try to save the law as far as possible rather than guillotine it.

“The SC can provide more safety guidelines if it feels so but let Aadhaar work. While testing the requirement of safeguards, please keep in mind the context and purpose for which Aadhaar is being used,” he said.

TOP COMMENT
Link Aadhar to Voter ID first to see it's true credibility... surely the cat will be out of the bag..!

Radhakrishnan Nair

“A fine infrastructure has been built for establishing identity of citizens for a host of purposes. The court can suggest additional safeguards for making it more secure. The UIDAI is open to suggestions and will do its best to implement it. Justice Srikrishna Commission is looking into the working of Aadhaar and it is a work under progress. So there is always scope for improvement,” Dwivedi said.


Justice Chandrachud said one area the UIDAI would do well to focus was on how to retrieve the situation in case of data leak or accidental sharing of data by requesting agencies for authentication purposes. Dwivedi said such lapses were taken care of by the Aadhaar Act. 

Wednesday, April 25, 2018

13345 - No indignity in submitting ID proof, UIDAI tells SC at Aadhaar hearing - Hindustan Times


If the government asks for Aadhaar for every transaction, the court could step in, UIDAI said.

INDIA Updated: Apr 19, 2018 01:12 Ist

HT Correspondent 
Hindustan Times, New Delhi

There was no aggregation of data at UIDAI, Unique Identity Authority of India’s counsel senior advocate Rakesh Dwivedi said.(Sonu Mehta/HT PHOTO)

There was no indignity in furnishing a proof of identity as it was only a regulatory procedure, UIDAI told the Supreme Court that on Wednesday which expressed concern that biometric authentication could lead to surveillance of Aadhaar users.
The court, which is hearing a set of petitions challenging the 12-digit number and its enabling law, said insisting to biometric authentication for every transaction could lead to aggregation of metadata of users, which could be used for various purposes, including surveillance.

“Fingerprint by itself does not disclose any information. But, when it attaches with all the other information, it forms a wealth of information and then comes the need for data protection,” said the bench, also comprising justice AK Sikri, justice AM Khanwilkar, justice DY Chandrachud and justice Ashok Bhushan.
There was no aggregation of data at UIDAI, Unique Identity Authority of India’s counsel senior advocate Rakesh Dwivedi said, once again seeking to allay fears that iris scan and finger prints collected for Aadhaar could be misused.

If the government asks for Aadhaar for every transaction, the court could step in, he said.

“The insistence of any form of identity must be relatable to its purpose,” the court said. Justice Chandrachud wanted to know if people could be given the choice of identity documents.
An institute and not the beneficiary would decide on the type of identity proof, Dwivedi said. These days every organisation asked for ID proof, he said, adding Aadhaar was one of the documents the top court asked for while accepting a petition.
“There is no indignity. These are regulatory procedures,” Dwivedi said, pointing to the SC-issued proximity cards that lawyers need to enter the court complex. “I don’t think my fundamental rights are breached if I am asked for proximity card.”

Aadhaar was universal and portable and use of biometrics made it safe. “All other cards are sectoral,” Dwivedi said.

Saturday, April 21, 2018

13335 - Aadhaar linkages case: Govt counsel explains that no human rights issues will arise from Aadhaar data - India Legal Bureau

April 19, 2018

The Supreme Court Constitution Bench of Chief Justice Dipak Misra and Justices AK Sikri, AM Khanwilkar, DY Chandrachud and Ashok Bhushan resumed hearing on the batch of petitions challenging the validity of Aadhaar Act and Aadhaar linkages on Thursday (April 19) with senior counsel Rakesh Dwivedi, speaking for the government.

Justice Sikri said: “If there would be no conflict, there would be no courts.”

Dwivedi said: “Parallely we witnessed we had slaves and in India too, we’re wrapped in the casteism. There are humans who were criminals and who were not. Those who were untouchables, were suffering double apartheid.”

He also quoted Nobel Laureate economist Amartya Sen, saying: “Development requires the removal of major sources of un-freedom, poverty as well as tyranny.”

Referring to the ration card, Dwivedi submits: “I can directly go under the food act and switch from ration card to Aadhaar card. Adhaar card brings an individual face to face with the service provider. I think this is a very powerful advancement.”

justice Chandrachud said: “I don’t think this is the best model of governance. An individual should not be a mode for benefits. Better alternatives are present.”

Section 2(d) and 2(f) of the protection of human rights Act mentioned. He refers to the Asha Ranjan vs State of Bihar. He said the basic minimum requirement for human rights must be taken care of by the legislature. Various judgments of the Supreme Court on economic and social welfare culminated into the Parliament framing the Aadhaar Act.

Next he quotes Subramanian Swamy judgment on balancing of fundamental rights wherein A.19(1)(a) was balanced against right to reputation. Balancing of fundamental rights is a very important aspect. He refers to a 2017 judgment- the choice to have this or that is very important. This case pertains to the abortion of an HIV positive woman wherein the MCI did not grant the permission to abort the child.

This is a much more important right involved under article 21.  The Act draws an important distinction between demographic information, optional demographic information and biometrics photographs. Biometrics cannot be shared, as per the status under the Act. Giving your information is a normal routine. No reasonable expectation can be achieved as far as demographic information is concerned. He said Aadhaar does not include caste religion etc., so that these things can be used against the user.
—India Legal Bureau


13329 - Aadhaar is operationally different from smart cards and Google, which presents them with little incentive to work against UIDAI - First Post

News-Analysis Nimish Sawant Apr 19, 2018 18:25 PM IST

In the on-going Aadhaar Supreme Court hearings, senior counsel Rakesh Dwivedi was alleged to have made a statement to the extent that Google and smart card companies had created a lobby against Aadhaar.

Later in the day, UIDAI sent out a series of tweets stating that Dwivedi's arguments that Google is trying to fail Aadhaar were not correct.

It is clarified that the media reports which were published today quoting UIDAI’s Counsel Shri Rakesh Dwivedi’s argument yesterday in the Supreme Court that Google is trying to fail Aadhaar, are not correct. 1/n


Shri Rakesh Dwivedi, Senior Advocate had submitted that as far as Google, Facebook and Twitter are concerned, they cannot be compared with Aadhaar due to the nature of information being different and also due to difference in the nature of algorithms being used. 2/n

Lawyers and witnesses present in the court state otherwise and this is open to debate.

Dwivedi also clarified that the Aadhaar data is not available on the internet, from where it can be stolen. We'd like to point out that it's not clear whether he's talking about biometric data or demographic data. Multiple leaks in the past, especially from government entities, has resulted in the leak of demographic data (name, address, contact details, etc.) of several thousand Indians, if not millions of Indians.

While UIDAI has stated that there is no attempt by Google to fail Aadhaar, the question of a Google lobby seems moot. But smart cards are a means of identification in many nations, and while in India a lot of the petitioners have expressed an interest to have a smart card in case of an Aadhaar number for verification and authentication purposes, it has so far remained just an idea.

A woman goes through the process of finger scanning for the Unique Identification (UID) database system, also known as Aadhaar. Image: Reuters

Smart Cards as a national ID 
A smart card is like any other debit or credit card, made of plastic with embedded chips which could be RFID compatible. The chips in these smart cards house the personal data of the user, which can only be read by an authorised authenticating machine. A lot of countries use smart cards as a national identification tool. These include Brazil, Israel, Malaysia, Estonia, Indonesia, among others. You can read a detailed comparison of how Aadhaar compares with other biometric national identification systems around the world.

While there was no clarification of what was meant by a 'smart card lobby', it was reported that the UIDAI felt like 'a campaign had been unleashed to ensure Aadhaar should be a smart card, 'a European based commercial venture'. Since UIDAI has distanced itself from this, we will not get into the semantics of it, as this is as vague a statement as any.

Smart cards, specifically in Europe are quite popular. Estonia has been the leader when it comes to smooth implementation of smart cards and their use in governmental as well as non-governmental services.

Smart ID is an Estonian company which allows you to find out the real identity of users. "Smart ID has implemented many different identification methods to identify people because each country has its own popular methods and this list just keeps on growing. Currently, it is possible to identify people securely in Estonia, Latvia, Lithuania and Portugal. Each method has its own security level. National ID cards with smart cards are considered one of the most secure," says its website.

Here is a list of all the national smart ID cards in use in various European nations. Norway, Denmark, Iceland, the UK are some exceptions, however. Each country has its own rules, whether to make a national ID card compulsory or optional for authentication and services. In an exceptional case, the UK even destroyed its ID card system.

On days 8 and 9 of the Aadhaar Supreme Court hearings, petitioners drew the attention of the Bench to Israel’s smart ID system, where users could use the card to avail benefits and services if they wished to do so. The system used biometric authentication and has a database, but the database lacks any identifying information. In summary, the petitioners argued that there can be an ID card, but it must be voluntary, authentication data must be on the card, it should not collect data, and the people should have the right to alternatives.
According to experts we have spoken to, making Aadhaar a national smart card would take quite a while and would involve a lot of logistics. But the allegation of a smart card lobby sounds like speculation at best, without any proof being presented as to which are the parties that may be interested in this.

Estonia has one of the most advanced Smart ID Card systems. Image: Wikipedia

Google has little incentive to lobby against Aadhaar
Unlike Aadhaar, Google is a private company and provides services to users for which there are alternatives. If I want to use Google services, I have to make an ID on Google and as I use more Google services, it gets to know me better. I have to opt-in for Google Assistant as it gives me an experience which adds value to my online journey. If I decide that I don't want to associate with Google services, I can do a 'Google Takeout' ie. take a backup of all my data, delete my Google accounts and opt-in for any other alternative service for mail, search, video viewing and so on.

Bottomline — as a user, I have an option to choose if I want to remain with Google.

With Aadhaar becoming a national ID and one that is intricately linked to so many services, there is no option for me to opt out if I don't want to share my Aadhaar details with services which mandate it.

As rightly pointed out by the UIDAI counsel, unlike Aadhaar, Google uses machine learning algorithms to learn more about me. Well, Google is a technology company first, and its use of machine learning and AI should not come as a surprise. This is done to give users an online experience that is catered to their habits and personas. There is an incentive for companies such as Google, Facebook and others to use machine learning and artificial intelligence in their services. Of course, there is scope for misuse too, as we have all seen with the Facebook Cambridge Analytica scandal.

Aadhaar, on the other hand, is primarily meant to be used to authenticate you, as you. UIDAI has also stated that not every private entity will be given access to Aadhaar authentication machines. This same private entity can ask you to register or login using your Google ID to access its services. So there again, is a big difference in how these systems work.
When you look at the differing use cases that each of these services such as Aadhaar, smart cards and Google provide, one thing that emerges is that there is no real motivation for a 'Google and Smart card lobby' to work against Aadhaar.
The UIDAI distancing itself from these statements is an added validation of how it may have been a slip of tongue.


Updated Date: Apr 19, 2018 18:25 PM

13328 - Not sure if Aadhaar is best model to accord benefits, Supreme Court says - Times of India


PTI | Updated: Apr 19, 2018, 21:57 IST

HIGHLIGHTS
  • The counsel for UIDAI told SC that Aadhaar brought the citizens face to face with the service providers
  • "The individual should not be a supplicant. The state should go to him and give him benefits," the bench responded

NEW DELHI: The Supreme Court on Thursday said it was not sure whether bringing people "face to face" with authorities through Aadhaar was the best model as the state should reach them to accord the benefits of the welfare schemes. 

A five-judge Constitution bench headed by Chief Justice Dipak Misra, hearing a clutch of petitions challenging Aadhaar and its enabling 2016 law, was told by the counsel for the Unique Identification Authority of India (UIDAI) that the 12-digit national identifier brought the citizens face to face with the service providers for getting the benefits. 

"We are not sure if that is the best model. The individual should not be a supplicant. The state should go to him and give him benefits," the bench, also comprising Justices A K Sikri, A M Khanwilkar, D Y Chandrachud and Ashok Bhushan, said. 

The bench observed that the UIDAI says Aadhaar is a means for identification, but the "only caveat to that is that there should be no exclusion". 

Senior advocate Rakesh Dwivedi, appearing for UIDAI and the Gujarat government, said the development was necessary to ensure that people are freed from poverty. 

Liberating people from poverty is at one end of the spectrum and the right to privacy is on the other, the bench observed. 

The UIDAI referred to social ills like manual scavenging and prostitution and said that despite laws, these evils were rampant in the society and the apex court should strike a balance while dealing with the competing fundamental rights of citizens. 

Referring to apex court judgements, the senior lawyer said it has been held that to save the freedom of speech and expression, the right to reputation of a citizen under Article 21 cannot be crucified. 

The apex court, besides being the protector of fundamental rights, is also a "balancing wheel" to ensure that competing fundamentals co-exist. 


Dwivedi then referred to a verdict by which a HIV+ve rape victim was denied the permission to abort the foetus after a doctors' panel gave the report that it could be fatal for the woman. 

Friday, April 20, 2018

13322 - Aadhaar leak may sway polls, fears Supreme Court - The Hindu



NEW DELHI, APRIL 17, 2018 21:37 IST


It is a “real apprehension” that a leak in the Aadhaar data may sway elections and cause a severe dent to democracy, the Supreme Court expressed its fears about data protection at an age when private players are increasingly taking over what used to be exclusively governmental functions.Bench expresses concern about data protection

Data protection
Senior advocate Rakesh Dwivedi, for Aadhaar’s nodal agency UIDAI, tried to allay the fears of the Constitution Bench led by Chief Justice Dipak Misra, by submitting that the Aadhaar Act provides for data protection.

Mr. Dwivedi countered that the UIDAI cannot be compared to any Cambridge Analytica. He submitted that data protection should be “fair, reasonable and just.” In fact, no one could assure 100% data protection.

The senior advocate said the UIDAI did not have any learning algorithms, which can aggregate and analyse data. Besides the UIDAI can refuse a private enterprise from becoming a requesting entity under the Aadhaar Act. He said whether the requesting entity is a taxi aggregator or a software app, it has to have a prior contract with the UIDAI.

Personal data
But Justice D.Y. Chandrachud expressed fears about what use the requesting entities themselves would make of the personal data provided to them by the public. The judge said the interaction of Aadhaar with the “outside world” was indeed an area of concern for the court.

The judge illustrated that a private hospital, which may have data about the number of visits of its patients and their medication, could possibly pass the information over to insurance or pharma companies for commercial use.
Justice Chandrachud referred to Sections 8(3) and 29(3) of the Aadhaar Act which shows that requesting entities have “identity information” of citizens with them. They get access to this information when individuals come to them for authentication.
Justice Chandrachud said the authorities cannot risk a blinkered vision of reality. Mr. Dwivedi dissuaded the court from giving into the “hyperphobia” of the petitioners challenging the Aadhaar scheme. He reiterated that Aadhaar data was not subject to any kind of analysis and the people should trust the UIDAI with their data.

Mr. Dwivedi sought to reply to allegations made by the petitioners that Aadhaar reduces a person to a number, robbing him of his individuality. He said human beings were not reduced to numbers just because they were assigned a number as in proximity cards, passports, etc.


13315 - Google, Facebook, Twitter can't be compared with Aadhaar, clarifies UIDAI - Times of India


TIMESOFINDIA.COM | Updated: Apr 18, 2018, 22:35 IST

HIGHLIGHTS
  • The nature of information and the algorithms being used by global companies like Google and Aadhaar is different, UIDAI counsel Rakesh Dwivedi told the SC
  • Unlike Google, UIDAI does not plan on using data analytics and learning tools to analyse Aadhaar data, Dwivedi had said
NEW DELHI: Unique Identification Authority of India (UIDAI) has clarified that media reports quoting UIDAI’s Counsel Rakesh Dwivedi’s argument yesterday in the Supreme Court that Google is trying to fail Aadhaar are inaccurate. 

Senior advocate Rakesh Dwivedi had submitted before a CJI-headed Constitution bench that as far as Google, Facebook and Twitter are concerned, they cannot be compared with Aadhaar due to the nature of information being different and also due to difference in the nature of algorithms being used. While Aadhaar is only matching biometrics, the other global companies are using learning tools for analysis of data, which creates knowledge. 


Further, UIDAI is prohibited under the law to do any such data analysis and therefore cannot conduct surveillance of any kind. He further said that UIDAI does not permit any Requesting Entity (RE) to collect and analyse Aadhaar data and use the same for any commercial purposes. 

Thursday, April 19, 2018

13309 - Google, card lobby want Aadhaar to fail: UIDAI to Supreme Court - TNN


Dhananjay Mahapatra | TNN | Updated: Apr 18, 2018, 18:47 IST

HIGHLIGHTS
  • Senior advocate Rakesh Dwivedi told a CJI-headed Constitution bench that a campaign had been unleashed that Aadhaar should’ve been like smart cards, a Europe-based commercial venture
  • “If Aadhaar succeeds, smart cards will be out of business. Google does not want it. Smart card lobby does not want Aadhaar to succeed," Dwivedi said
NEW DELHI: The UIDAI on Tuesday made a startling charge before the Supreme Court that Google and the smart card lobby did not want Aadhaar to succeed because if UID emerges as a foolproof way to authenticate identity, they will be out of business. 


Appearing for the Unique Identity Authority of India, senior advocate Rakesh Dwivedi told a CJI-headed Constitution bench that a campaign had been unleashed that Aadhaar should’ve been like smart cards, a Europe-based commercial venture. “If Aadhaar succeeds, smart cards will be out of business. Google does not want it. Smart card lobby does not want Aadhaar to succeed. That’s why these allegations are being made,” he said. 


* ‘Aadhaar data not on internet, can’t be stolen’

Some of the petitioners, who have challenged the validity of Aadhaar Act, had also mentioned that instead of Aadhaar authentication sourced from UIDAI, which stored huge meta data about citizens’ biometric and demographic details, it would be better to put whatever data was needed for authentication purpose in a smart card, like credit or debit cards, for authentication by swiping. 

The bench asked Dwivedi whether Aadhaar could function a corresponding robust data protection regime. “The real apprehension is the use of social network site data to affect elections in democracies. The problem is symptomatic and we do not live in isolation. We cannot have a blinkered approach as when we write the judgment on this, it could govern citizens for generations,” it said.

Dwivedi responded, “Please don’t bring in Cambridge Analytica into Aadhaar. Unlike Cambridge Analytica, Aadhaar has not use artificial intelligence. Aadhaar only has a matching algorithm to establish ‘I am me’. A phobia is being created that Aadhaar meta data is a like an atom bomb which can go off any time. But the truth is it is secured in the best possible way. It is not connected to the internet to allow online stealing of data. The data cannot be analysed by anyone.”



Tuesday, April 17, 2018

13298 - Aadhaar Hearings: SC Now Refers To Cambridge Analytica Fiasco On Aadhaar Leakage - Newburgh Gazette


Dwayne Harmon
14 April 2018, 04:20 

 The constitution bench is hearing a batch of petitions by former Karnataka High Court Judge K.S. Puttuswamy, Magsaysay awardee Shanta Sinha, feminist researcher Kalyani Sen Menon, social activist Aruna Roy, Nikhil De, Nachiket Udupa and others challenging the constitutional validity of the Aadhaar scheme on the touchstone of the fundamental right to privacy. 

Rakesh Dwivedi, counsel for the Unique Identification Authority of India (UIDAI), which administers Aadhaar, dismissed such fears, saying the authority doesn't have the tools or the algorithms used by Facebook and Google. UIDAI counsel has however denied any such possibility on grounds that they neither have tools nor power to do such level of data analysis. The counsel referred to the Aadhaar law and said the UIDAI had no power to analyse data at all and "I challenge the other side to show us the provision to that effect and if that power is there, then please strike that down". The Act precludes us from getting any. The court said, "When we mean surveillance it is not real or physical surveillance but commercial surveillance". 

First Concern: What is the goal of storing metadata? The bench gave the example that even judges in an African country can get the access to his or her chamber by using his finger prints, which are used only for the goal of the entry and the problem was that such data was being stored at a central repository. Technology is a great enabler to surveillance. "If the government wishes to surveil, it will do so without Aadhaar", he said. UIDAI: "We can not even tamper with the servers"

The bench also referred to the testimony of Facebook CEO Mark Zuckerberg before the US Congress and said "you open the newspapers every day and see reports of how elections in even some of the most powerful nations were influenced". "The 1.2 Bn Indians may be poor, but their data is a goldmine of commercially sensitive information." Mr. Mehta responded that the court was right in thinking why the government should "intrude into the privacy of the entire population merely to weed out a few crores. but when tax evasions amount to Rs. 33,000 crore, it is a serious problem which Aadhaar linkage may curb". To enable and boost offline Aadhaar verification process, the UIDAI has replaced the existing QR code on eAadhaar having resident's demographic details now with a secured digitally-signed QR Code which contains demographics along with the photograph of the Aadhaar holder. Regarding use of stored metadata by UIDAI, Dwivedi said that the metadata was of authentication records and did not reveal anything about individuals. Also, IDAI (Unique Identification Authority of India) has introduced the beta version of the VID (virtual ID) feature. Generate your VID from Resident.uidai.gov.in/web/resident/vidgeneration. Not only financial services, even telecom companies have asked to link mobile with the Aadhaar number. "If the government wants to do, it will do without Aadhaar", he said. While it seems that the court is not convinced with the facts and measures brought on stage by the Aadhaar team, UIDAI does not seem to take a step back here. Take the instance of Cambridge Analytica. 

Newburgh Gazette http://newburghgazette.com/2018/04/14/aadhaar-hearings-sc-now-refers-to-cambridge-analytica/

Monday, April 16, 2018

13291 - Aadhaar hearing: Senior counsel calls surveillance possibilities as mere rhetoric, says fingerprint data is only relevant for palmistry - First Post


News-Analysis Asheeta Regidi Apr 13, 2018 17:44 PM IST

On Day 28 of the Aadhaar hearing, Additional Solicitor General Tushar Mehta concluded his arguments on the Aadhaar-PAN and the Aadhaar-Bank account linkages. The Bench also questioned the counsels extensively on the justification of these linkages, noting that the freezing of accounts thereby was a deprivation of the constitutional right to property.

Senior counsel Rakesh Dwivedi then commenced his arguments, arguing that the surveillance possibilities discussed by the petitioners were ridiculous and mere rhetoric. The purpose of Aadhaar, he argued, was authentication alone.

Aadhaar as a compulsory document for bank accounts
First, the Additional Solicitor General continued his arguments, that the amendments to the Prevention of Money Laundering (Maintenance of Records) Rules (PML), on Aadhaar-bank account linkage were for the benefit of the public. These rules, he stated were neither ultra vires the Aadhaar Act nor the RBI Rules.
The Bench, here, first observed that the challenge to the PMLA Rules was proportionality and on why there was a need to make Aadhaar compulsory when the RBI KYC Master Directions recognised six forms of Officially Valid Documents. To this, it was argued that the purpose was to prevent impersonation. Aadhaar, further, is one of the most robust IDs which cannot be faked, unlike others which are not based on biometrics.

On rendering bank accounts non-operational
The Bench, here, asked the Additional Solicitor General to specifically address Arvind Datar’s arguments for the petitioners, that the PMLA Rules are ultra vires the PML Act, and that no provision of the PMLA allowed validly opened bank accounts to be rendered non-operational. Further, the rationale behind linking with insurance as well as mutual funds was questioned.

To this, it was argued that the freezing of accounts in this manner was not permanent. The Bench, here, further observed that such freezing of accounts could amount to a violation of Article 300A of the Constitution, or the constitutional right to property. To this, it was argued that the freezing would only amount to a reasonable restriction on this right.

Is freezing of accounts a valid, penal consequence?
The Bench, further questioned if the penal consequence of freezing accounts was authorised by the PML Act. The Act, they said, only discussed the verification of bank accounts. To this, it was argued first that this was not a penalty but a mere consequence. Secondly, the rules were part of the Act.

The Bench, however, did not agree with this, observing that the prescription of penalties via rule-making powers had not been sanctioned by the Aadhaar Act. Further, freezing of accounts did amount to a penalty, since it amounted to a deprivation of property under Article 300A. The Bench further stated that their question was on whether the freezing of accounts was authorised under the law, or was it a case of judicial overreach.
Can penal consequences be prescribed via rule-making power
The Bench directed the Additional Solicitor General to show how rules may prescribe such drastic consequences when the Act did not allow it. The Additional Solicitor General cited judgments that rules once issued are effectively part of the Act. The Bench, however, observed that this cannot apply to rules made outside of rule-making power.
Senior counsel Rakesh Dwivedi, arguing for the State, intervened here, arguing that Aadhaar was a just a condition for opening and continuing a bank account, to meet the need to re-verify bank accounts. The Bench here, again questioned how a validly opened bank account could be frozen under the PMLA.
The Additional Solicitor General then summed up his arguments, discussing the threat from terror financing and also of cross-border offences. He argued that the purpose behind the PMLA Rules is threefold: zero tolerance to money laundering, curbing black money and reaching beneficiaries.

The Bench stated that the poor had an equal right to privacy. Reuters.
Petitioners are using rhetoric to rubbish Aadhaar
Senior counsel Rakesh Dwivedi then commenced his arguments for the State, arguing that he never felt that he was under surveillance while using Aadhaar, and further, that Aadhaar was voluntary. He argued that it was ridiculous to consider that the government would surveil people like a farmer and that the government had ample means of conducting surveillance if it needed to, without the need for Aadhaar. The petitioners, he argued, were using rhetoric to rubbish Aadhaar.
Technology as an enabler of mass surveillance
The Bench, here, observed that technology was a very powerful enabler of mass surveillance, with even elections being swayed using it. To this, it was argued that the technology in use by Facebook and Google could not be compared to that in use by the UIDAI. For instance, there were no learning algorithms in use by the UIDAI.
The Bench, to this, observed that the Aadhaar Act does not preclude the UIDAI from acquiring that kind of technology, to which Dwivedi responded that this would amount to an offence under Section 33 of the Aadhaar Act.
Authentication metadata reveals very little
Further, he argued that the only purpose behind Aadhaar was authentication, and there was no authorisation under the Aadhaar Act to analyse the data. The Bench questioned the collection of metadata, to which it was argued that the metadata collected was limited to that related to authentication, i.e., of the authentication request, the result, and the time of the authentication. The Bench, here, observed that even this data could reveal a lot about a person.
To this, it was argued that this was not possible unless such data is sought in collusion with the CBI, which is far-fetched. For a specific authentication, it was argued that the authentication request would reveal the place where the request arose from (such as Apollo Hospitals), but not specific location (such as which Apollo hospital).
The Bench here observed that the requesting entity itself may store data, and that surveillance need not be interpreted in the traditional sense only. The prevalence of commercial surveillance, and also the absence of a data protection law to protect the data was also pointed to.
Most people are not concerned with privacy
Dwivedi further argued that individual information is of no value. Further, most people were unconcerned about privacy. The Bench, here stated that the issue was not of whether 1.9 billion people are concerned with privacy. Regarding the information being available, he further argued that fingerprints were only of interest to palmists and for palmistry. To this, the Bench observed that the question was not of fingerprints per se, such as their use for a limited purpose. The issue, instead, was of storing them in a central database, followed by their use for authentication.
To this, it was argued that biometrics are encrypted, and the data is not shared with anyone. It was argued that it was understandable if the people had a problem with the implementation and enforcement of the Aadhaar Act, but there is no issue with the law itself and the technology.
Sharing of data under Aadhaar Act
A discussion then ensued on Section 29 of the Aadhaar Act, which permits the sharing of data. The Bench here observed that Section 29(3)(b) of the Aadhaar Act allowed the sharing of data with requesting entities to third parties. Further, Section 29 read with 57 allowed the information to be shared with third parties even under contracts.
To this, it was argued that this section should be read in context with Section 29(1), which completely bars the sharing of biometric data. The Bench, here, observed that the issue was not only about Section 7 or the UIDAI but goes far beyond that. Further, Section 29(3) uses the word ‘identity information’, which indicates that biometric data can also be transferred. To this, it was suggested that the Court read this provision down to prevent the sharing of biometric data.
The arguments will continue on 17 April.
Sources of arguments include live-tweeting of the case by SFLC.in, Prasanna S, and  Gautam Bhatia.
You can read out coverage of the Aadhaar Supreme Court case below.
The author is a lawyer and author specialising in technology laws. She is also a certified information privacy professional.


Updated Date: Apr 13, 2018 17:44 PM