DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Under the right to information law, Aadhaar data breaches will remain a state secret

Posted on March 5, 2017 by Dissent

All one billion Aadhaar records could be hacked and stolen, and the government wouldn’t have to disclose it or answer any questions about it?

Anumeha Yadav explains that Section 6 of the Aadhaar (Sharing of Information) Regulations says:

The Aadhaar number of an individual shall not be published, displayed or posted publicly by any person or entity or agency.

However, at the same time, the Aadhaar Act lacks any provision for a mandatory notice to an individual in case of a breach of his or her information – which was a recommendation of the Justice Shah Committee on Privacy in 2012, which was set up to lay the ground for a comprehensive new privacy law.

Thus, under the law, Aadhaar users have no right to be informed when a crime related to their personal data occurs. And they cannot approach a court directly because under Section 47 (1) of the Aadhaar Act, the Unique Identification Authority of India has the exclusive power to make complaints in case of any violation or breach of privacy.

Read more on Scroll.in.

So no right to be notified and no right to file a complaint, and as Yadav explains, the government can (and does) deny requests under the right to information law, citing security and confidentiality exceptions.

According to technology lawyer Apar Gupta, “the UIDAI is a blackbox that cannot be opened even after a system crash”.

So everyone could be at risk and not know it and not be able to find out more.

Not good, folks.


Related:

  • Au: Qantas hackers gave airline 72-hour deadline
  • Au: Junior doctor faces fresh toilet spying charges as probe widens to other major hospitals
  • Russia suspected of hacking Dutch prosecution service systems
  • Korea imposes 343 million won penalty on HAESUNG DS for data breach of 70,000 shareholders
  • IVF provider Genea notifies patients about the cyberattack earlier this year.
  • Key figure behind major Russian-speaking cybercrime forum targeted in Ukraine
Category: FederalNon-U.S.

Post navigation

← Has W-2 fraud overtaken healthcare as the most lucrative target for cyber-criminals?
Allina Health notifies Minneapolis Heart Institute patients of data breach →

8 thoughts on “Under the right to information law, Aadhaar data breaches will remain a state secret”

  1. Anonymous says:
    March 5, 2017 at 7:06 pm

    All one billion Aadhaar records have been hacked and stolen, and the government does not want to disclose it or answer any questions about it.

    Your site comes up with some of the most recent Aadhaar results.

    1. Dissent says:
      March 5, 2017 at 9:07 pm

      I am still trying to get proof of the claim that the records have all been hacked/acquired. If you or anyone can help, CONTACT ME, please!!

      1. James says:
        March 6, 2017 at 8:50 am

        i found a very interesting article given the recent events http://www.financialexpress.com/india-news/no-breach-in-uidais-aadhaar-data-says-government/576255/

        they say ‘The UIDAI said there has been no breach to the UIDAI database of Aadhaar in any manner and the personal data of individuals is fully safe and secure.’

        1. Dissent says:
          March 6, 2017 at 9:57 am

          Yes, they say that, but do you believe them? Did you read my recent post on Aadhaar breaches?

          1. James says:
            March 6, 2017 at 10:11 am

            yes i read the post. i responded in comments.

          2. Dissent says:
            March 6, 2017 at 10:22 am

            And this is why I wish I could get in touch with “We are Legion” (a/k/a “Legion”) who claim to have the data.

          3. James says:
            March 6, 2017 at 10:26 am

            where did you hear about that claim?

          4. Dissent says:
            March 6, 2017 at 11:28 am

            There was a WaPo story in December that was the first I recall hearing about it, but other commenters on this site seem to believe it, so I keep asking whether any proof has been provided. I’d love if “Legion” would share some data they claim to have.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Au: Qantas hackers gave airline 72-hour deadline
  • Honeywell vulnerability exposes building systems to cyber attacks
  • Recent public service announcements of note — parents should take special note of these
  • Au: Junior doctor faces fresh toilet spying charges as probe widens to other major hospitals
  • Average Brit hit by five data breaches since 2004
  • BlackSuit ransomware site seized as part of Operation Checkmate
  • The day after XSS.is forum was seized, it struggles to come back online — but is it really them?
  • U.S. nuclear and health agencies hit in Microsoft SharePoint breach
  • Russia suspected of hacking Dutch prosecution service systems
  • Korea imposes 343 million won penalty on HAESUNG DS for data breach of 70,000 shareholders

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Indonesia asked to reassess data privacy terms in new U.S. trade deal
  • Meta Denies Tracking Menstrual Data in Flo Health Privacy Trial
  • Wikipedia seeks to shield contributors from UK law targeting online anonymity
  • British government reportedlu set to back down on secret iCloud backdoor after US pressure
  • Idaho agrees not to prosecute doctors for out-of-state abortion referrals
  • As companies race to add AI, terms of service changes are going to freak a lot of people out. Think twice before granting consent!
  • Uganda orders Google to register as a data-controller within 30 days after landmark privacy ruling

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.