---
layout: default
title: "Public Statement to Final Draft of UID Bill"
description: "A CIS blog post presenting civil society's evaluation of the final draft of the Unique Identification (UID) Bill released in November 2010, highlighting unresolved privacy and governance concerns."
authors: ["Elonnai Hickok"]
categories: [Elonnai Hickok]
date: 2010-12-07
source: "Centre for Internet and Society"
permalink: /elonnai/public-statement-to-final-draft-of-uid-bill/
created: 2026-08-03
---
**"Public Statement to Final Draft of UID Bill"** is a blog post by [Elonnai Hickok](/elonnai/) published by the [Centre for Internet and Society](/cis/) on 7 December 2010. It outlines civil society's critique of the final draft of the Unique Identification (UID) Bill released on 8 November 2010 prior to its submission to the Lok Sabha. The statement assesses key unaddressed concerns regarding architecture, privacy safeguards, scope, and governance, while evaluating notable legislative modifications made between the preliminary and final drafts.
## Contents
1. [Article Details](#article-details)
2. [Full Text](#full-text)
3. [Context and Background](#context-and-background)
4. [External Link](#external-link)
## Article Details
The final draft of the UID Bill that will be submitted to the Lok Sabha was made public on 8 November 2010. If the Bill is approved by Parliament, it will become a legal legislation in India. The following note contains Civil Society's response to the final draft of the Bill.
On 8 November 2010, the UID Authority issued the final draft of the UID Bill that will be submitted to the Lok Sabha for review and approval. Earlier this year in June 2010 the Authority issued a draft UID Bill to the public for comment and review. Civil Society responded with a detailed summary and high summary of points that amended the draft or were missing in the draft Bill. We are disappointed that none of the concerns raised by Civil Society, including those listed below, were addressed.
- Architecture
The centralized architecture of the UID project is unnecessary. A federated and decentralized structure to the UID project would achieve the same goal of providing identity, authentication, and delivery of benefits.
- Scope
The scope of the Bill is overboard. Though the main purpose of the Bill is to facilitate the delivery of benefits to residents, the loose language and intermixing of terms creates a threat that data will be collected and used beyond delivery of benefits.
- Voluntary and not Mandatory
The Bill should prohibit the denial of goods, services, entitlements, and benefits for lack of a UID number- provided that an individual furnishes equivalent ID, thus ensuring that the Aadhaar number is truly voluntary.
- Inadequate Privacy Safeguards
The Bill inadequately elaborates on the principles of privacy relating to identity and transaction data. The protections needed should be self-contained within the Bill. Thus, the UID Bill itself should be clear and concise about data collection, transfer, retention, security, and dissemination.
- Unwarranted Data Retention
The Bill does not provide adequate privacy protection for transaction data. In particular section 32(2) empowers the Authority to determine the duration that data is to be retained for.
- Lack of accountability for all Actors
The Bill holds only the Authority accountable for violations. Rather the Bill needs to hold enrolling agencies, registrars, and other service providers accountable. Furthermore, the Bill does not provide adequate regulations or accountability for the data that are outsourced.
- Lack of Exceptions
The Bill does not detail the circumstances and categories of people who will be excused or accommodated with respect to the issuing of Aadhaar numbers or authentication of transactions.
- Lack of Anonymity
The Bill does not provide adequate specificity as to the situations in which anonymity will be preserved and/or an Aadhaar number should not be requested.
- Inadequacy of Penalties
The penalties provided in the Bill are inadequate, because they do not cover several types of misuse.
- Unaffordability of Fees
It is incompatible with the Bill's stated purpose of inclusion to require an individual to pay to be authenticated.
- Lack of Rollback and Ombudsman Office
The Bill does not provide adequate redress for system/transaction errors and fraud.
- Inappropriate Structure and Governance
The Bill does not provide appropriate judicial and parliamentary oversight.
Upon comparison of the draft Bill and the final Bill, CIS finds the following changes the most significant:
- Definition of Resident
Section 2 (q): "resident" means an individual usually residing in a village or rural area or town or ward or demarcated area (demarcated by the Registrar General of Citizen Registration) within ward in a town or urban area"
Comment. This section clarifies the definition of 'resident' from the draft Bill, which defined resident as an "individual usually residing within the territory of India". By specifying that individuals in demarcated areas will not receive UID numbers, the definition of resident is brought into line with the scope of the Bill as laid out in the preamble. We see this change as a positive revision.
- Prohibition of Dissemination of Information
Section 30 (3): "Notwithstanding anything contained in any other law and save as otherwise provided in this Act, the Authority or any of its officer or other employee or any agency who maintains the Central Identities Data Repository shall not, whether during his service as such or thereafter, reveal any information stored in the Central Identities Data Repository to any person"
Comment. This section prohibits the dissemination of any information that is stored in the Central Identities Data Repository. This prohibition extends to anyone or any entity that handles information, and supersedes other laws that might permit dissemination of information. We see this change as a positive revision.
- Disclosure of Information in the Case of a National Security
Section 33 (b): "Any disclosure of information (including identity information) made in the interests of national security in pursuance of a direction to that effect issued by an order of the Central Government specifically authorised in this behalf by an officer or officers not below the rank of Joint Secretary or equivalent in the Central Government"
Comment. This section is a minor improvement on the previous draft since it requires specific authorization from the Central Government (rather than from a Minister in charge). Unfortunately, however, it retains the undesirable language of "national security" from the previous draft which, as we had previously pointed out, is not currently clearly defined under Indian law. An alternative phrase that we recommend instead is the Constitutional vocabulary of "public emergency" which already has a considerable volume of judicial reasoning that has elaborated what it means. Eg. in Hukam Chand v. Union of India (AIR 1976 SC 789) it was held that a public emergency "is one which raises problems concerning the interest of public safety", the sovereignty and integrity of India, the security of the State, friendly relations with foreign States or public order, or the prevention of incitement to the commission of an offence."
{% include back-to-top.html %}
## Context and Background
The statement reflects the critical period in late 2010 when India's Unique Identification (UID) framework was transitioning from an administrative initiative into formal statutory legislation. Following the release of the initial public draft in June 2010, civil society groups submitted substantial feedback aimed at preventing potential rights violations and administrative overreach. However, when the final draft was published on 8 November 2010 for legislative introduction in the Lok Sabha, it became clear that fundamental architectural and legal safeguards recommended by civil society had been left unaddressed.
A primary area of concern centered on the underlying technical architecture and operational parameters of the project. Civil society argued that the centralized design of the repository posed inherent systemic risks, favoring a federated approach that could accomplish identity authentication and social benefit delivery without creating single points of failure or centralized surveillance capabilities. Additionally, concerns were raised regarding the potential for function creep, as vague statutory language permitted data usage beyond welfare distribution, and the absence of strict non-denial provisions meant that possessing a UID number could become practically compulsory for accessing basic entitlements.
The analysis also highlights key gaps in privacy, accountability, and legal recourse within the draft framework. The text emphasizes that the Bill failed to establish comprehensive privacy principles directly within its text, leaving critical details regarding data retention, outsourcing, and third-party vendor accountability under-regulated. Furthermore, the lack of an independent ombudsman, insufficient judicial oversight, and user-borne authentication fees were identified as structural deficiencies that conflicted with the project's stated mission of socio-economic inclusion.
Despite these broader omissions, the statement acknowledges specific incremental revisions between the draft versions. Revisions such as refining the statutory definition of a "resident" under Section 2(q) and introducing explicit non-disclosure obligations for repository handlers under Section 30(3) were noted as positive adjustments. Nevertheless, provisions governing information disclosure under Section 33(b) remained controversial. Although authorization was narrowed to senior executive officials, the reliance on undefined "national security" grounds rather than established constitutional standards like "public emergency" left sensitive personal data vulnerable to broad administrative discretion.
## External Link
- [Public Statement to Final Draft of UID Bill](https://cis-india.org/internet-governance/blog/privacy/privacy-publicstatement-UID)
{% include navbox-elonnai.html %}