Question · Central government: ministries and departments
How should scheme systems handle Aadhaar numbers?
Short answer: Vault, mask, never publish
Use Aadhaar only where a law or notification allows it, store the number only in an Aadhaar Data Vault, show it masked on screens and in reports, and never publish it. Core biometric information must never be shared. Authentication devices at the field level need vendor and operator controls.
What the law says
Aadhaar Act Sections 7 and 29 and UIDAI rules, with DPDP Section 8(5).
Section 8(5) · Rule 6: Protect personal data with reasonable security safeguards. Rule 6 lists the minimum: encryption, masking or tokenisation; access control; logs and monitoring; backups for continuity; keeping logs for at least one year; and security terms in contracts with processors.
Section 7: Some uses need no consent: data a person gave voluntarily for a specified purpose, duties under law, medical emergencies involving a threat to life, health services during an epidemic, safety during a disaster, and purposes of employment.
Steps
Find every place Aadhaar numbers are stored.
Move them to a vault with reference keys.
Mask on screens, reports and files.
Check PoS and field device vendors.
Log access to the vault.
Evidence to keep
Vault design
Masking evidence
Access logs
Common mistakes
Aadhaar in spreadsheets
Full numbers on dashboards
Field operators keeping copies
From each seat
CISO: Watch vault access logs.
IT head / NIC coordinator: The vault is your job.
Scheme or programme head: Field devices and operators are part of your scheme.
IT department: Search shared drives for Aadhaar numbers.
What a good answer from management sounds like
“Aadhaar numbers sit only in a vault, are masked everywhere else, and access is logged.” Effort and time: Medium · 8 to 12 weeks.