NO& pRcla PENSION FUND REGULATORY AND DEVELOPMENT AUTHORITY PFRDA/2017/20/NPST-REG/1 Date: 05/07/2017 To, NPS Trust, CRA, Trustee Bank, Govt. Nodal Offices, POPs, Aggregators and other stakeholders SUBJECT: Adherence to the provisions of the Aadhar Act, 2016 and Information Technology Act, 2000 1. All the intermediarie…
NO& pRcla PENSION FUND REGULATORY AND DEVELOPMENT AUTHORITY PFRDA/2017/20/NPST-REG/1 Date: 05/07/2017 To, NPS Trust, CRA, Trustee Bank, Govt. Nodal Offices, POPs, Aggregators and other stakeholders SUBJECT: Adherence to the provisions of the Aadhar Act, 2016 and Information Technology Act, 2000 1. All the intermediaries/Stakeholders under National Pension System are hereby informed that there shall be no public display of AADHAR number of residents in any manner which shall be in violation of Section 29(4) of the 'THE AADHAAR (TARGETED DELIVERY OF FINANCIAL AND OTHER SUBSIDIES, BENEFITS AND SERVICES) ACT, 2016'. 2. It may be further noted that wherein AADHAR number of a subscriber is used /involved for the purpose of any transaction of activity under NPS, or any other pension scheme governed by the provisions of the PFRDA Act, 2013, such transaction/activity shall be undertaken strictly in conformity with the provisions of the 'THE AADHAAR (TARGETED DELIVERY OF FINANCIAL AND OTHER SUBSIDIES, BENEFITS AND SERVICES) ACT, 2016', the relevant rules and regulations notified thereunder, the provisions of the Information Technology Act, 2000, the relevant rules and regulations notified thereunder as also the relevant provisions of the intermediary specific regulations notified under the PFRDA Act, 2013 (as may be applicable for NPS Trust/CRA/POP/Aggregators and other entities having interface with subscribers), relating to maintaining of confidentiality of data of subscribers. 3. In this regard, a list of DO's and DONT's received on onward transmission from the Ministry of Finance, Govt. of India, is also enclosed for guidance in the matter. 4. All intermediaries/stakeholders are requested take notice and observe strict compliance of the above, in respect of activities falling within the jurisdiction of this Authority. Venkateswarlu Peri (Chief General Manager) File No.PFRDA/16/02/06/0001/2017-REG-NPST 1 Receipt No : 2550/2017/REG-NPST -TItd PITT otlidg I It Thwpr cr" ?0, ;1- R€ GOVERMENT OF INDIA MINISTRY OF FINANCE DEPARTMENT OF FINANCIAL SERVICES "JEEVAN DEEP" le, PARLIAMENT STREET, NEW DELHI-110 001 F.No,20/2/2010-FI (Vol.II) (C-58530) fah Dated the .15.06.2017 20 To All CMDs of PSBs/Private Banks/Insurance Companies/FIs. Subject: Violations of the provision of the Aadhaar Act, 2016 and Information Technology Act, 2000. Sir, It may be noted that public display of Aadhaar No. of residents in any manner is violation of Section 29(4) of Aadhaar Act, 2016. Further, financial information such as Bank account details, linked Aadhaar No. which is also being used as financial address are sensitive personal data, the publishing of which is violation of provision of IT Act 2000 and the rules frame there under and constitute a convention under Section 72 of Information Technology Act, 2000. MEITY and UADI have issued guidelines and a list of do's and don'ts regarding usage of Aadhaar, a copy of which is enclosed for ready reference. Therefore, you are requested to kindly issue instructions to all concerned to ensure compliance of the above mentioned provisions of Aadhaar Act, 2016 and IT Act, 2000 and do's and don'ts regarding usage of Aadhaar. The receipt of this letter and action taken may please be communicated to the undersigned. Yours sincerely, (ANJANA DUBE) Dy. Director General To: JS(PJ), .15(AA), JS(MM), JS(MKM), JS(SM), IS(VIK), EA(RND) & EA(N5R) Copy for information to: PPS to Secy(F5), PPS to AS(FI) & PPS to AS(FS) File No.PFRDA/16/02106/0001/2017-REG-NPST Receipt No : 2550/2017/REG-NPST Do's FOR A.ADHA AR USER AG CO CIES/DEPARTMENTS 1. Read Aadhaar Act, 2016 and its Regulations carefully and ensure compliance of all the provisions of the Aadhaar Act; 2016 and its Regulations. 2. Ensure that everyone involved in Aadhaar related work is well conversant with provisions of Aadhaar Act, 2017 and its Regulations as well as processes, policies specifications, guidelines, circular etc issued by UIDAI from time to time. 3. Create internal awareness about consequences of breaches of data as per Aadhaar Act, 2015. 4. Follow the information security guidelines of UIDAI as released from time to time. 5. Full Aadhaar number display must be controlled only for the Aadhaar holder or various special roles/users haying the inn an in the agency/department. Otherw by c efault, all displays should be masked. 6. Verify that all data capture point and information dissemination points (website, tap, cat s security' requirements. if agency lc: sta must be encrypted and stored. Encryption keys must be pro-ter :tee securely preferably using HSMs. if simple spreadsheets are used, it mu sr tic eacctvard protected and seam* stored. 8. Access controls to data must be in place to make sure Aadhaar number along with personally identifiable demographic data is protected. 9. For Aadhaar number look up in database, either encrypt the input and then look up the record or use hashing to create Aadhaar number based index. 10. Regular audit must be conducted to ensure Aadhaar number and linked data is protected. 11. Ensure that employees and officials understand the implications of the confidentiality and data privacy breach. 12. An individual in the organization roust be made responsible for protecting Aadhaar linked personal data. That person should be in charge of the security of system, access control, audit, etc. 13. Identify andprevent any potential databreach pub!ira tion of eersonai 2 File No.PFRDA/16/02/06/0001/2017-REG-NPST a. Receipt No : 2550/2017/REG-NPST 14. Ensure swift action on any breach personal data. 15. Ensure no Aadhaar data is displayed or disclosed to external agencies or unauthorized persons. 16. informed consent - Aadhaar holder sho clearly be made aware of the usage, the data being collected, and its usage. Aadhaar holder consent should be taken either on paper or electronically. 17. Authentication choice - \/Vhen doing ntication, agency should provide multiple ways to authenticate (fingerprint, iris, OTP) to ensure all Aadhaar holders are able to use it of 18. Multi-factor for high security - When doing high value transactions, multi- factor authentication must be considered. 19. Create Exception handling mechanism on following lines- 20. It is expected that a small percentage of Aadhaar holders will not be able to do biornetric authentication. It is necessary that a well-defined exception handling mechanism be put in place to ensure inclusion. 21. if fingerprint is not working at all even after using multi-tinge authentication then alternate such as iriS OTP must he provided. 22. If the schemes terpiliy based (like PDSsystein), anyone in the family must he able to authenticate to avail the benefit. This ensures that even if one person is unable to do any fingerprint authentication, someone eke in the family is able to authenticate. This reduces the error rate significantly. 23. If none of the above is working (multi-finger, iris, anyone in family, etc.), then agency must allow alternate exception handling schemes using card or PIN or other means. 74. All authentication usage must follow with notifications/receipts of transactions. 75. All agencies Implementing Aadhaar authendcation must provide effective grievances handling mechanism via multiple channels (website, call-center, mobile app, sms, physical-center, etc.). 76. Get all the applications using AdicilHE:tar ausii ! cc or its date ourity by appropriate 3,..11ThOrity such as 5T Use only ., eilDAI certified biometric drha s tor Aadhaar atrtheI ti'-anon. 3 laced intoim 'or File No.PFRDA/16/02/06/0001/2017-REG-NPST Receipt No : 2550/2017/REG-NPST DOMTis FOR AADHAAR USER AGENCIES/DEPARTMENTS 1. Do not pub' - l5 data inciud ng, Aadhaar in public domaintwebsite Publication of Aadhaar details is punishable under Aadhaar act. 2. Do not store tisk_ mica niantiu holders con:anted for authentication. 3. Do not store any !Haar based data in ny unprotected endpoint devices, apt as PCs, laptops or smart phonesor tablets or any other devices. 4. Do not print/display out personally identifiable Aadhaar data mapped with any other departmental data such as on radon card/birth certificate/caste certificate/any other certificate/document. Aadhaar number ii required to be printed, Aadhaar number should be truncated or masked. Only last four digits of Aadhaar can be displayed/printed. 5. Do not capturelstoreluse Aadhaar data a;consent the resident as per As l! a cTh S purpose ot eSe of .A.Eidli.:-tt:H r' disclosed to the FESICiFFi' 6. Do not disci e any /\&L agency or individual of e dm/ir hs /3a G. a outside of a locked, fay secured and access-controlled room 8. Do not permit any unauthorized people to access stored Aadhaar data 9. Do not share Authentication license key with any other entity Do not iocaFte sy±rv(,..,rs o any external/unauthorized 4
Research the source law
This record is not yet linked to a specific provision. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source laws