In the context of the DPDP Act, 2024, assess how the design principles of the new Aadhaar App address constitutional right to privacy while expanding the utility of digital identity.
Q. In the context of the DPDP Act, 2024, assess how the design principles of the new Aadhaar App address constitutional right to privacy while expanding the utility of digital identity. (15 marks, 250-350 words)
The Digital Personal Data Protection Act (enacted 2023, with Rules notified in 2025) codifies data minimisation, purpose limitation and data-principal rights [3], while Puttaswamy (2018) requires Aadhaar's use to satisfy proportionality [4]. The new Aadhaar App, dedicated to the nation in January 2026, largely operationalises these principles in design, though inclusion gaps persist.
Privacy-by-design consistent with DPDP - Selective credential sharing: residents disclose only the identity fields a use-case requires, through customised QR codes generated by requesting entities — direct data minimisation [1]. - Non-retention: the Aadhaar number is not stored by verifiers; only digitally signed verifiable credentials are shared, limiting purpose creep [1]. - Biometric lock/unlock in a single click and face verification for proof of presence keep collection proportionate to purpose [1].
Strengthening the constitutional privacy guarantee - Puttaswamy barred mandatory Aadhaar use by private entities; offline QR-based verification lets hotels or cinemas confirm identity or age without routing an authentication request under Section 8, Aadhaar Act, 2016 [4][5]. - Authentication history view gives residents an audit trail of who verified them — an accountability mechanism mirroring the DPDP Act's rights of the data principal [1][3].
Expanding utility of digital identity - Over 31 million downloads within five months, with about 4 million mobile-number updates and 850,000 address updates completed in-app [2] — self-service that reduces dependence on enrolment centres and particularly aids internal migrants. - Management of up to five profiles per device ("One Family – One App") extends access to households with limited smartphones [1].
Residual concerns - Downloads are not active users; residents without smartphones or digital literacy remain reliant on legacy channels. - Consent quality, grievance redress capacity and the app's expanding attack surface still require sustained regulatory attention.
The App therefore converts privacy from a post-hoc legal remedy into an architectural default, aligning welfare delivery with proportionality. Extending its assisted-access modes and pairing it with a fully functional data-protection grievance machinery would make India's digital identity both rights-respecting and genuinely universal.
(~340 words)
Sources: 1. New Aadhaar App dedicated to the nation — PIB, MeitY — selective credential sharing, non-storage of Aadhaar number, biometric lock, face verification, authentication history, five profiles per device 2. Aadhaar App crosses 31 million downloads — MeitY/UIDAI — adoption figures, mobile-number and address update numbers 3. The Digital Personal Data Protection Act, 2023 — MeitY — data minimisation, purpose limitation, data-principal rights 4. Justice K.S. Puttaswamy (Retd.) v. Union of India, 26.09.2018 (5-Judge Bench) — UIDAI legal framework — proportionality standard; restriction on mandatory private-entity use 5. The Aadhaar Act, 2016 — UIDAI legal framework — Section 8 authentication framework