Discuss the role of Aadhaar-based Face Authentication in strengthening India's Digital Public Infrastructure. What are the associated privacy concerns?
Digital Public Infrastructure (DPI) refers to population-scale, interoperable digital systems for identity, payments and data exchange. Aadhaar, under the Aadhaar Act, 2016, forms its identity layer, and UIDAI's in-house AI/ML-based Face Authentication is deepening that layer — even as it sharpens long-standing privacy questions.
Strengthening the identity layer of DPI
- Scale and reliability: Face Authentication doubled from 100 crore to 200 crore transactions in under six months (August 2025) [1], within a base of 2,707 crore Aadhaar authentications in FY 2024-25 [2] — evidence of a genuinely population-scale rail.
- Inclusion: A smartphone camera replaces dedicated fingerprint scanners, helping elderly and manual workers with worn fingerprints access pensions, PDS and DBT.
- Ease of integration: The Face Authentication SDK and testing Sandbox, with an Innovation Lab at the UIDAI Tech Centre, were launched at the 7th Global Fintech Fest, Mumbai (September 2026) [3], letting banks, telecoms and fintechs embed verification inside their own apps and validate it before going live — lowering e-KYC cost and onboarding friction.
- Widening public use: The NEET examination pilot with NTA and NIC [4] shows extension beyond finance into examination integrity and public administration.
- Technological sovereignty: Indigenous AI/ML liveness engines reduce dependence on foreign biometric vendors.
Associated privacy concerns
- Sensitivity of facial data: Unlike a fingerprint, a face can be captured remotely and without consent, enabling covert profiling; Puttaswamy (2018) requires any such intrusion to satisfy legality, necessity and proportionality [5].
- Function creep and surveillance: Ubiquitous face capture risks drifting from authentication towards identification and tracking.
- Spoofing and deepfakes: UIDAI's own 2025 call for real-time detection of deepfakes, mask and spoof attacks [6] acknowledges an evolving threat surface.
- Consent and redress: Meaningful consent and grievance remedies depend on full operationalisation of the DPDP Act, 2023 [7]; authentication failure can also mean welfare exclusion.
Face Authentication thus makes India's DPI more inclusive and frictionless, but its legitimacy rests on trust. Purpose limitation, independent audit of liveness systems, an assured offline fallback for every entitlement, and prompt enforcement of the DPDP framework can align the technology with the constitutional promise of dignity and privacy — ensuring that a stronger identity layer strengthens the citizen, not merely the system.
Sources
- 1Aadhaar Face Authentication Sets New Benchmark, Doubling from 100 Crore to 200 Crore Transactions in Just 6 Months, PIB (10 Aug 2025)200 crore face authentication milestone
- 2Aadhaar authentication surges past 2,707 crore in 2024-25; UIDAI's face authentication gains momentum, PIBFY 2024-25 authentication volume
- 37th Global Fintech Fest 2026: Potential to Impact, PIB (8 Sep 2026)Face Authentication SDK, Sandbox and Innovation Lab
- 4UIDAI successfully conducts Face Authentication pilot for NEET Exam, PIBNEET UG 2025 proof of concept with NTA and NIC
- 5Justice K.S. Puttaswamy (Retd.) v. Union of India, Supreme Court of India (26 Sep 2018)privacy and proportionality standard for Aadhaar
- 6UIDAI Seeks Real-Time Attack Detection Solutions to Defeat Deepfakes, Mask Attacks and Spoofing in Aadhaar Face Authentication, PIB (2025)spoofing and deepfake threat to face authentication
- 7The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYconsent, obligations and redress framework for personal data