The Aadhaar App has crossed 50 million (5 crore) downloads, with more than 60 lakh mobile number updates, over 15 lakh address updates and more than 23 lakh email updates carried out through it.
The app is built around the principle of 'Show, Share and Verify', giving Aadhaar number holders control over how their Aadhaar information is used.
UIDAI has onboarded more than 200 entities as Offline Verification Seeking Entities (OVSEs) since the rollout in January, enabling consent-based, paperless verification.
Offline verification uses QR code-based checks and digitally signed documents, so a verifying entity does not need real-time connectivity to UIDAI's central database.
The stated design goal is data minimisation - the Aadhaar number holder shares only the minimum necessary data, in line with the Government's Digital India vision.
In online authentication, a requesting entity sends the Aadhaar number along with a biometric or an OTP to UIDAI's Central Identities Data Repository, and UIDAI returns a yes or no. UIDAI is in the loop for every transaction, and an authentication record is created. In offline verification, nothing is sent to UIDAI at all. The resident supplies a UIDAI-issued artefact - the secure QR code on the Aadhaar letter or PVC card, the e-Aadhaar, or an Aadhaar Paperless Offline e-KYC XML file - and the entity verifies the digital signature UIDAI has placed on it. If the signature checks out, the data inside is genuine and untampered. The consequences follow from that difference: offline verification works without connectivity, creates no central record of where a person used their identity, and lets the resident disclose selected fields rather than the whole record. It also cannot confirm that the person presenting the document is the person it describes unless a separate check is done, which is the trade-off for removing UIDAI from the loop.
Simple Analogy: Online authentication is like a shop phoning the bank to confirm your cheque before accepting it. Offline verification is like the shop examining a banknote's watermark and security thread - the issuer's mark is checked on the spot, and the issuer never learns that the transaction happened.
Issues Aadhaar numbers, maintains the Central Identities Data Repository, and regulates authentication and offline verification, including the registration of OVSEs. It was first set up in January 2009 as an attached office of the then Planning Commission by a Gazette notification dated 28 January 2009, and became a statutory authority on 12 July 2016 under the Aadhaar Act, 2016.
The parent statute. It gave UIDAI statutory status on 12 July 2016 and governs enrolment, authentication and the use of Aadhaar for delivering subsidies, benefits and services funded from the Consolidated Fund. Note the full title - the linkage to subsidies and benefits is what the Act was justified on, and it is frequently the subject of a question.
A nine-judge Bench of the Supreme Court held unanimously on 24 August 2017 that the right to privacy is a fundamental right, protected under Article 21 and flowing from Articles 14, 19 and 21. It overruled the earlier decisions in M. P. Sharma and Kharak Singh. This is the doctrinal foundation against which the Aadhaar scheme was then tested.
A five-judge Bench headed by Chief Justice Dipak Misra upheld the constitutional validity of the Aadhaar Act but struck down the part of Section 57 that enabled a body corporate or individual to seek Aadhaar authentication. That is why private entities rely on offline verification rather than online authentication, and therefore why the OVSE framework exists.
The subordinate legislation that governs offline verification and the registration of Offline Verification Seeking Entities. An OVSE may use the retrieved Aadhaar data only for the purpose the Aadhaar number holder unambiguously and explicitly specified at the time of verification, and must verify UIDAI's digital signature in the secure QR code before accepting the identity.
The general data protection statute that now overlays all of this. It received Presidential assent on 11 August 2023; the provisions establishing the Data Protection Board of India came into force on 13 November 2025. It requires a notice to accompany or precede every request for consent, and requires consent to be free, unconditional and unambiguous, with withdrawal as easy as giving it - the standard the release's 'consent-driven' language is written against.
UIDAI constituted by Gazette notification as an attached office of the then Planning Commission
UIDAI becomes a statutory authority under the Aadhaar Act, 2016
Nine-judge Bench in Puttaswamy holds the right to privacy to be a fundamental right
Five-judge Bench upholds the Aadhaar Act but strikes down Section 57 insofar as it allowed private entities to seek authentication
UIDAI introduces AI/ML-based Aadhaar face authentication
Aadhaar Authentication and Offline Verification Regulations, 2022 notified
The Digital Personal Data Protection Act, 2023 receives Presidential assent
Aadhaar face authentication crosses 200 crore transactions
Provisions establishing the Data Protection Board of India come into force
Rollout of the Offline Verification Seeking Entity onboarding referred to in the release
Aadhaar App crosses 5 crore downloads; over 200 OVSEs onboarded
The release's emphasis on sharing 'only the minimum necessary data' is the purpose-limitation and minimisation principle that runs through both the Aadhaar offline verification regulations and the DPDP Act, 2023. It is the doctrinal answer to the surveillance objection raised in the Aadhaar litigation.
Aadhaar is the identity layer of India's DPI stack, alongside UPI as the payments layer and the account aggregator and consent frameworks as the data layer. Offline verification is what lets that identity layer be used by private entities after Section 57 was read down.
The Aadhaar line of cases is the standard GS-2 example of courts shaping the design of a technology programme rather than merely permitting or forbidding it - the Section 57 holding changed the engineering, not just the law.
Offline verification is heavily used for customer onboarding by banks, NBFCs and telecom operators. For banking exams, the practical point is that Aadhaar-based e-KYC by private entities today generally runs through offline routes or through statutorily permitted channels, not through open online authentication.
GS Paper 2 > Governance > e-Governance, and Fundamental Rights including the right to privacy
General Awareness > Government Bodies and Current Affairs
General Awareness > KYC, Digital Identity and Regulatory Framework
General Awareness > Current Affairs
Which of the following statements is/are correct regarding Smart India Hackathon 2017? 1. It is a centrally sponsored scheme for developing every city of our country into Smart Cities in a decade. 2. It is an initiative to identify new digital technology innovations for solving the many problems faced by our country. 3. It is a programme aimed at making all the financial transactions in our country completely digital in a decade. Select the correct answer using the code given below:
Answer: 2 only
Aadhaar, UIDAI and the right to privacy are perennial across UPSC Prelims and Mains, SSC general awareness and banking KYC-related questions.
An entity registered with UIDAI to verify an Aadhaar number holder's identity offline, by checking UIDAI's digital signature on a QR code or an Aadhaar Paperless Offline e-KYC XML file, without querying UIDAI's database.
A digitally signed QR code printed on the Aadhaar letter, PVC card and e-Aadhaar; verifying UIDAI's signature in it is what proves the document is genuine and untampered.
The design principle of the Aadhaar App, under which the Aadhaar number holder decides what identity information is displayed, what is shared and what is verified.
The provision that permitted the State or any body corporate or person to use Aadhaar for establishing identity; the part enabling body corporates and individuals to seek authentication was struck down in 2018.
The principle that only the personal data necessary for a stated purpose should be collected or disclosed - the basis of selective field sharing in offline verification.