India’s Aadhaar biometric identification system faces increased scrutiny in 2025, as multiple issues regarding security, privacy, and authentication processes have emerged across both public and private sectors. The system, which serves over 1.3 billion residents, has become a cornerstone of India’s digital identity infrastructure since its launch in 2009.
A parliamentary Public Accounts Committee (PAC) led by MP KC Venugopal has initiated a scientific review of the Aadhaar central biometric database, following reports of high biometric authentication failure rates affecting access to government welfare schemes. While concerns about potential data breaches have been raised, UIDAI officials maintain that the Central Identities Data Repository (CIDR) remains secure, attributing reported breaches to third-party enrollment centres rather than the central system.
The government has taken action against websites exposing sensitive personal information, including Aadhaar and PAN card details. The UIDAI filed complaints under Section 29(4) of the Aadhaar Act, leading to intervention by CERT-In and the Ministry of Electronics and Information Technology. A regulatory framework now allows private sector enterprises in sectors such as e-commerce, healthcare, education, hospitality, credit rating, and aggregator platforms to apply for licenses to use Aadhaar authentication for identity verification and fraud detection.
A significant privacy violation has been identified in the telecommunications sector, where Airtel and Reliance Jio, which control 75 percent of India’s subscriber base, have been conducting Aadhaar face authentication for SIM card services without explicit user consent. The practice contradicts UIDAI guidelines that mandate consent-based face authentication and require alternative authentication options such as OTP or fingerprint/iris biometrics.
The authentication system’s challenges extend to the Aadhaar Enabled Payment System (AEPS), where biometric authentication failures and unauthorized usage of authentication methods have implications for transaction security. The expansion of Aadhaar authentication across various sectors has prompted increased regulatory oversight and the implementation of stricter control measures at enrollment centres. The development follows UIDAI’s recent expansion of its authentication capabilities to include face authentication for private sector applications.
“The Central Identities Data Repository (CIDR) remains secure. Reported breaches have originated from third-party enrolment centres, not from the central repository itself. Monitoring mechanisms at these centres have been strengthened,” UIDAI officials stated.
Sources: BW Security World, SS Rana & Co., The New Indian Express