Examine the role of data minimization and consent-based design in India's digital identity architecture, with reference to the Aadhaar ecosystem and the DPDP Act.
Q. Examine the role of data minimization and consent-based design in India's digital identity architecture, with reference to the Aadhaar ecosystem and the DPDP Act. (15 marks, 250-350 words)
Data minimization — collecting and disclosing only the data strictly needed for a stated purpose — and consent-based design are two of the seven principles underpinning the Digital Personal Data Protection Act, 2023 [3]. In a digital identity system of Aadhaar's scale, they are the safeguards that convert a mass authentication database into a rights-respecting public infrastructure.
How the principles operate in the Aadhaar ecosystem - The redesigned Aadhaar App, dedicated to the nation in January 2026, is explicitly built around resident control, consent and data minimization, aligning UIDAI's practice with the DPDP framework [2]. - QR-based selective sharing lets a resident disclose only the specific credential a verifier needs, rather than the full Aadhaar letter — minimization made operational [2]. - Face verification and biometric lock/unlock place the decision to authenticate with the resident, making consent an affirmative act rather than a default [2].
Enabling ease of living without expanding data collection - Free, app-based email ID addition/update, effective 1 July 2026 for six months, removed the need to visit an Aadhaar Seva Kendra; over 2.5 lakh updates occurred in two days [1]. - A linked email triggers real-time alerts on every authentication request, turning consent into a continuously auditable relationship [1]. - Earlier self-service reforms, such as 'Head of Family'-based online address update, show the same design logic of reducing intermediaries who would otherwise handle resident data [4].
Limitations that persist - App-only, smartphone-dependent delivery risks excluding low-connectivity and low-literacy users, making consent formal rather than informed. - Consent quality depends on grievance redress and enforcement machinery under the DPDP Rules, still maturing [3].
Data minimization and consent-based design have shifted Aadhaar from an authentication utility toward a privacy-by-design public good. Sustaining this requires assisted-consent channels for offline populations and time-bound operationalization of DPDP institutions, so that the constitutional right to privacy affirmed in Puttaswamy is realized in practice, not merely in architecture.
(~320 words)
Sources: 1. UIDAI Enables Free Email Update in Aadhaar through Aadhaar App, PIB (3 July 2026) — free app-based email update effective 1 July 2026, 2.5 lakh updates in two days, real-time authentication alerts 2. New Aadhaar App dedicated to the nation, PIB (28 January 2026) — consent, resident control and data minimization design; QR-based selective sharing; biometric lock 3. The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitY — consent, transparency and data minimization as statutory principles 4. UIDAI enables 'Head of Family' based online address update in Aadhaar, PIB — earlier paperless self-service update mechanism