Consider the following statements: 1. Aadhaar metadata cannot be stored for more than three months. 2. State cannot enter into any contract with private corporations for sharing of Aadhaar data. 3. Aadhaar is mandatory for obtaining insurance products. 4. Aadhaar is mandatory for getting benefits funded out of the Consolidated Fund of India. Which of the statements given above is/are correct?

Updated 11 Apr 2026 · From UPSC Prelims GS Paper I 2020, Q33

Contents13
UPSC Prelims GS2020Indian Polity
  1. A1 and 4 only
  2. B2 and 4 only
  3. C3 only
  4. D1, 2 and 3 only
Show answer

Answer: (B) 2 and 4 only

This question is about the Aadhaar system and the Supreme Court's judgment on it.

Statement 1 (Metadata stored for max 3 months) — NOT CORRECT:

Authentication records (metadata) cannot be kept beyond 6 months (not 3 months), as per Regulation 27(1) of the Authentication Regulations.

The Supreme Court also ruled that retaining data beyond 6 months is "impermissible."

Statement 2 (State cannot share Aadhaar data with private corporations) — CORRECT:

The Supreme Court struck down Section 57 of the Aadhaar Act, which had allowed sharing of Aadhaar data with private entities.

This means telecom companies, e-commerce firms, etc. cannot ask for your biometric or Aadhaar data.

Statement 3 (Aadhaar required for insurance) — NOT CORRECT:

IRDAI (insurance regulator) has said insurers cannot MANDATORILY demand Aadhaar.

They can accept it as one of the identity documents only if the customer voluntarily provides it.

Statement 4 (Aadhaar required for government subsidies from Consolidated Fund of India) — CORRECT:

Under Section 7 of the Aadhaar Act, if you want government subsidies or benefits funded from the Consolidated Fund of India, you need to provide Aadhaar or enroll for it.

However, if you don't have Aadhaar, alternate identification must be offered.

Answer: B (2 and 4 only).

Key Takeaway:

Aadhaar metadata = 6 months (not 3).

No sharing with private entities.

Not mandatory for insurance.

But required for government subsidies from Consolidated Fund.

Why this was asked

The Supreme Court's 2018 Aadhaar judgment struck down Section 57, prohibiting private companies from accessing Aadhaar data while allowing government use for subsidies from the Consolidated Fund.

This question tests the specific technical details of the Court's ruling - the 6-month metadata storage limit, the private entity ban, and the government subsidy requirement under Section 7.

Supreme Court Aadhaar Judgment

Indian Polity Supreme Court Section 57

Supreme Court Aadhaar Judgment: Key Rulings & Impact

Must know

Section 57 struck down — private entities cannot demand Aadhaar

Section 7 upheld — Aadhaar valid for government subsidies from Consolidated Fund

Metadata retention allowed for 6 months maximum

Good to know

Right to privacy declared fundamental right under Article 21

In Justice K.S. Puttaswamy vs Union of India (2018), the Supreme Court delivered a landmark judgment on Aadhaar's constitutional validity. The Court upheld most provisions but struck down key sections that violated privacy rights.

Key Provisions: Upheld vs Struck Down

Provision

Status

Impact

Rationale

Section 7 (Govt subsidies)

Upheld

Aadhaar mandatory for benefits from Consolidated Fund

Legitimate state interest

Section 57 (Private entities)

Struck down

No mandatory Aadhaar for private services

Violates privacy

Section 33(2) (Court orders)

Struck down

No disclosure without judicial oversight

Inadequate safeguards

Section 47 (Penalties)

Struck down

Reduced criminal liability

Disproportionate punishment

Post-Judgment Changes

IRDAI clarified insurers cannot mandatorily demand Aadhaar — it's voluntary

Telecom companies stopped linking mobile numbers with Aadhaar after Section 57 removal

Banking services can use Aadhaar only under PMLA (money laundering) compliance, not mandatory KYC

Children's Aadhaar can be cancelled after turning 18 if they choose to opt out

Exam traps

Trap: Section 7 was upheld, not struck down — Aadhaar IS mandatory for government subsidies

Trap: Section 57 was struck down — private entities CANNOT demand Aadhaar

Trap: Insurance companies cannot make Aadhaar mandatory but can accept it voluntarily

Trap: Metadata stored for 6 months, not 3 months as in Statement 1

Aadhaar Data Retention Rules

Indian Polity metadata three months Authentication Regulations

Aadhaar Authentication Data Retention: Rules & Limits

Must know

Authentication metadata retained for maximum 6 months only

Regulation 27(1) of Authentication Regulations governs retention

Good to know

Biometric data cannot be stored by requesting entities

When you use Aadhaar for authentication (like banking or government services), metadata gets generated. This includes transaction logs, timestamps, and authentication responses — but not your actual biometric data.

Types of Aadhaar Data & Retention Rules

Data Type

What It Contains

Storage Period

Who Can Store

Authentication metadata

Transaction logs, timestamps, responses

6 months maximum

Requesting entities

Biometric data

Fingerprints, iris scans

Cannot be stored

No one except UIDAI

Demographic data

Name, address, phone

As per entity's policy

Requesting entities

Aadhaar number

12-digit unique ID

As per purpose limitation

Authorized entities only

Key Safeguards

Purpose limitation — data can only be used for the stated authentication purpose

Encryption mandatory during transmission and storage of any Aadhaar-related data

Audit trails must be maintained by all requesting entities for compliance checks

UIDAI regulations override any conflicting private contracts or policies

Exam traps

Trap: Metadata retention limit is 6 months, not 3 months as stated in Statement 1

Trap: Biometric data cannot be stored at all — only metadata has the 6-month rule

Trap: Don't confuse authentication metadata with the actual Aadhaar database storage

Aadhaar Private Entities Ban

Indian Polity private corporations sharing

Aadhaar & Private Entities: Supreme Court Ban Explained

Must know

Section 57 struck down — no mandatory Aadhaar for private services

Private entities can accept Aadhaar only on voluntary basis

State cannot contract with private firms for Aadhaar data sharing

The Supreme Court's striking down of Section 57 fundamentally changed how private companies can interact with Aadhaar data. The Court ruled this protects citizens' privacy rights under Article 21.

Before vs After Section 57 Removal

Service Type

Before (Section 57)

After Supreme Court Judgment

Current Status

Telecom/Mobile

Mandatory Aadhaar linking

Cannot demand Aadhaar

Alternative KYC accepted

Banking

Could demand for KYC

Only under PMLA compliance

Mostly voluntary

Insurance

Could make mandatory

IRDAI banned mandatory use

Voluntary only

E-commerce/Apps

Could demand for verification

Cannot make mandatory

Alternative IDs accepted

Digital wallets

Aadhaar-based KYC

Cannot insist on Aadhaar

Other documents accepted

What Private Entities Cannot Do

Cannot make Aadhaar mandatory for any service or product

Cannot deny services if customer refuses to provide Aadhaar

Cannot store biometric data even if customer volunteers Aadhaar number

Cannot share Aadhaar data with third parties without explicit consent

Exam traps

Trap: Statement 2 is correct — state cannot contract with private firms for Aadhaar sharing

Trap: Private entities can accept Aadhaar voluntarily but cannot demand it

Trap: IRDAI specifically banned mandatory Aadhaar for insurance, making Statement 3 wrong

Aadhaar Consolidated Fund Benefits

Indian Polity Consolidated Fund of India insurance products benefits funded

Aadhaar for Government Benefits: Section 7 Explained

Must know

Section 7 allows Aadhaar mandate for benefits from Consolidated Fund of India

Covers subsidies, welfare schemes, DBT — not private insurance

Alternative identification must be provided if person lacks Aadhaar

Section 7 of the Aadhaar Act permits the government to make Aadhaar mandatory for receiving subsidies or benefits that come from the Consolidated Fund of India. This covers government welfare schemes but excludes private sector services.

Aadhaar Requirements: Government vs Private

Sector

Aadhaar Status

Legal Basis

Examples

Government subsidies

Mandatory (with exceptions)

Section 7 of Aadhaar Act

LPG subsidy, MGNREGA, PDS

Central govt schemes

Required for DBT

Section 7 + scheme guidelines

PM-KISAN, Ayushman Bharat

State welfare schemes

Can be made mandatory

If funded from Consolidated Fund

State pension schemes

Private insurance

Cannot be mandatory

IRDAI guidelines post SC judgment

Life, health, general insurance

Banking services

Mostly voluntary

Post Section 57 removal

Savings accounts, loans

Consolidated Fund of India Benefits

# Aadhaar-Linked Benefits
## Direct Benefit Transfer
- LPG Subsidy
- Fertilizer Subsidy
- Kerosene Subsidy
## Employment Schemes
- MGNREGA
- Urban Employment Guarantee
## Agricultural Support
- PM-KISAN
- Crop Insurance
- MSP Payments
## Social Security
- Pension Schemes
- Scholarship Programs
- Healthcare (Ayushman Bharat)

Important Exceptions & Safeguards

Exception clause — if person doesn't have Aadhaar, alternative identification must be accepted

Offline verification allowed in areas with poor internet connectivity

Children above 5 must enroll for Aadhaar to continue receiving benefits

Sufficient cause provision protects those unable to authenticate due to technical issues

Exam traps

Trap: Statement 4 is correct — Aadhaar IS mandatory for Consolidated Fund benefits

Trap: Statement 3 is wrong — insurance is private sector, not government benefit

Trap: Don't confuse Consolidated Fund (government money) with private sector funding

Trap: Section 7 was upheld by SC, unlike Section 57 which was struck down