Digital Policy

India’s Aadhaar Faces Scrutiny Over Privacy, Accuracy, and Design Flaws

India’s Aadhaar biometric identity system has been globally heralded as a model for digital public infrastructure, lauded by institutions such as the World Bank and highlighted during India’s 2023 G20 presidency. However, a growing body of research and legal critique within India points to significant concerns regarding its technical accuracy, privacy safeguards, and the fundamental design choices embedded in the program.

What Happened

Aadhaar, launched in 2009 and anchored nationwide by 2016, has become India’s central digital ID system, linking biometric identifiers to banking, telecommunications, taxation, and welfare distribution. In 2018, India’s Supreme Court upheld Aadhaar’s constitutionality in a 4-1 ruling, emphasizing its ability to prevent duplicate identities as a key justification. Despite this, the Court’s dissenting opinion warned of privacy and surveillance risks created by Aadhaar’s single permanent identifier used across multiple sectors.

The Comptroller and Auditor General of India issued a 2022 report highlighting that the system’s reported 99.9% biometric deduplication accuracy is self-assessed and lacks independent verification, cautioning that multiple Aadhaar numbers remain a vulnerability. In response to these and computational challenges inherent to biometric matching at scale, the Unique Identification Authority of India (UIDAI) is rolling out a new AI-based matching platform in 2026 to improve accuracy and speed.

Further scrutiny revealed incidents of misuse, notably in 2017 when Airtel’s license to perform Aadhaar verification was suspended after agents exploited biometric checks intended for SIM issuance to open unauthorized bank accounts, redirecting fuel subsidies to phantom accounts. This improper linkage and repurposing risk stem directly from Aadhaar’s single-identifier design.

Key Facts

  • Aadhaar uses a single, permanent biometric identifier across banking, telecom, taxation, and welfare programs.
  • India’s Supreme Court upheld Aadhaar’s constitutionality on September 26, 2018, with Justice D.Y. Chandrachud dissenting.
  • India’s Comptroller and Auditor General reported to Parliament in 2022 the lack of independent auditing of Aadhaar’s deduplication accuracy.
  • UIDAI plans to introduce an AI-based biometric matching system in 2026.
  • In 2017, Airtel’s Aadhaar verification license was suspended following misuse of biometric authentication to silently open bank accounts.
  • Tokenization—issuing separate, revocable, purpose-bound credentials—is proposed as a solution but was only retrofitted subsequently as “Virtual ID.”

What This Means

The scrutiny surrounding Aadhaar highlights profound challenges with the design and governance of national digital identity systems. The reuse of a single permanent biometric identifier across diverse sectors introduces risks of unauthorized data repurposing and privacy infringements, undermining trust in government welfare programs. The lack of independent auditing of the system’s biometric deduplication accuracy raises questions about how effectively Aadhaar prevents identity duplication, a core legal justification for the system’s wide scope and data centralization.

For ordinary citizens, these design flaws translate into tangible risks: exclusion from essential welfare benefits due to authentication failures, unintended redirection of subsidies, and potential surveillance through cross-sector data linking. The Airtel incident serves as a cautionary example of how verification can be manipulated absent structural safeguards.

The ongoing rollout of AI-driven biometric matching and the implementation of tokenization technologies, although promising, also underscore that Aadhaar’s original architecture did not anticipate evolving privacy standards or computational complexities. This exemplifies the need for AI and digital ID regulation that demands transparency, independent oversight, and design principles prioritizing user consent and unlinkability.

Background

Aadhaar was established between 2009 and 2016 as a foundational digital identity system for India’s 1.4 billion population, aimed at curbing fraud in welfare disbursement and streamlining identification. The system’s constitutional challenge culminated in the Supreme Court’s 2018 judgment affirming its legality but acknowledged dissent on privacy grounds. Over the past decade, independent economists and technologists have critically analyzed Aadhaar’s purported fiscal savings, deduplication success, and privacy protections with mixed conclusions.

Analysis

Justice D.Y. Chandrachud’s 2018 dissent highlighted key privacy risks inherent in Aadhaar’s approach, noting how the singular, permanent identifier facilitates cross-silo data convergence, enabling profiling and surveillance by both government and private entities. Indian computer scientists have flagged the computational hardness of truly eliminating duplicate biometric records at this scale, explaining why Aadhaar relies on expedient approximations rather than definitive accuracy. Policy experts argue that the retrofit “Virtual ID” tokenization approach represents an acknowledgement that the initial design inadequately protected users from linkage and repurposing threats.

What Remains Unclear

The reviewed sources do not confirm how UIDAI’s forthcoming AI-based biometric matching platform will address prior accuracy shortcomings or whether independent audits will be institutionalized. It also remains uncertain how India’s judiciary or legislature will respond to ongoing critiques in terms of new regulatory frameworks or amendments to data protection laws governing Aadhaar and allied platforms.

Sources

This article is based on reporting and publicly available information from the following source:

Read more Digital Policy stories on Goka World News.

Nora Lindholm
About the editor

Nora Lindholm

Nora Lindholm Role: Digital Policy Editor Nora Lindholm writes about digital rights, online safety, data privacy, internet regulation, and technology policy. Her articles focus on how digital rules affect users, platforms, companies, and public institutions. She emphasizes official documents, clear sourcing, and balanced explanations.

View all posts by Nora Lindholm