Information Technology Act, 2000
IT Act and the Aadhaar Act: The Points of Interface Explained
The Aadhaar Act built an identity infrastructure, and the IT Act is what makes that identity usable for signing, protects its database, and increasingly governs the data it generates. The two meet at e-KYC, at the protected-system regime, at Puttaswamy, and at data protection. Topics 129, 135 and 63 carry the pieces; this note, as asked, maps the interface.
1. The Points of Contact
Figure 1: Four meeting points
- e-KYC and eSign. Aadhaar e-KYC is the authentication behind the Second Schedule e-authentication technique that powers eSign: a user verified by Aadhaar OTP or biometric receives a one-time key pair and signs, so the Aadhaar identity becomes an IT Act electronic signature (Topics 129, 135)
- CIDR as a protected system. The Central Identities Data Repository, the Aadhaar database, is notified as a protected system under s.70, so unauthorised access or attempted access draws up to ten years, the IT Act guarding the Aadhaar infrastructure (Topic 63)
- Puttaswamy (Aadhaar). The 2018 judgment upheld Aadhaar for welfare delivery on proportionality but struck s.57 of the Aadhaar Act, curbing private-party demands for Aadhaar, the constitutional limit that shapes how Aadhaar e-KYC may be used (Topic 122)
- Data protection. The Aadhaar Act's own data-security provisions govern the identity data, while the DPDP Act is the general regime over personal data, so Aadhaar-linked processing now answers to both, with the DPDP framework the broader discipline (Topics 87, 95)
2. How They Work Together
- Identity made signable. The Aadhaar Act supplies the verified identity; the IT Act supplies the legal signature, so Aadhaar e-KYC plus the Second Schedule technique equals a valid electronic signature under s.5, the practical core of the interface.
- Infrastructure made protected. The Aadhaar Act creates the CIDR; the IT Act's s.70 protected-system regime and the s.43 and s.66 offences guard it, so an attack on Aadhaar is prosecuted through the IT Act.
- Limits from the Constitution. Puttaswamy's proportionality and the striking of s.57 constrain how Aadhaar authentication may be demanded, a limit both statutes operate within, and voluntary e-KYC alternatives followed.
- The post-DPDP picture. As the DPDP Act commences, personal data generated through Aadhaar authentication falls within its consent, safeguard and breach regime, layering the general data-protection law over the Aadhaar-specific one (Topic 116)
⚠ Exam trap State the four contact points: e-KYC behind eSign (the Second Schedule technique), the CIDR as a s.70 protected system, Puttaswamy upholding Aadhaar while striking s.57, and the data-protection overlap now led by the DPDP Act. Keep the statutes' roles distinct, the Aadhaar Act supplies identity and the IT Act supplies the signature and the protection, and anchor the constitutional limit in the 2018 Aadhaar judgment rather than the 2017 privacy reference. |
3. Frequently Asked Questions
How do the IT Act and the Aadhaar Act interact?
At four points. Aadhaar e-KYC is the authentication behind the Second Schedule e-authentication technique that powers eSign, turning the Aadhaar identity into a valid electronic signature under the IT Act. The Central Identities Data Repository is notified as a protected system under Section 70, so attacks on it are prosecuted under the IT Act. The Puttaswamy Aadhaar judgment upheld Aadhaar with limits and struck Section 57, constraining private demands for Aadhaar. And the personal data generated through Aadhaar authentication falls under the Aadhaar Act's own rules and, increasingly, the DPDP Act as the general data-protection regime.
4. Related Topics
- Topic 135: CCA and eSign. Aadhaar e-KYC in the signature ecosystem.
- Topic 63: Protected systems and NCIIPC. The CIDR as a protected system.