SC Constitution Bench on Aadhaar- Final Hearing (Day XXXII)

In October 2015, a 3-judge bench of the Supreme Court of India referred challenges to the Aadhaar program to a constitution bench. One of the primary concerns of this petition was to decide on the existence of a fundamental right to privacy, which has since been upheld. Other similar petitions, concerned with the legitimacy of Aadhaar had been tagged with this petition. While the existence of the fundamental right to privacy has been upheld, challenges against the Aadhaar programme and linking services to this programme were yet to be adjudicated upon.

An interim order was passed in December of 2017, a summary of the arguments can be found here and here.

The final hearing commenced on January 17, 2017. Summaries of the arguments advanced in the previous hearings can be found here.

Senior Counsel Rakesh Dwivedi resumed his arguments for the Respondents. He began with referring to jurisprudence from the United States, the United Kingdom, South Africa and the European Union, to describe how privacy should be constructed in the Indian context. He argued that Indian jurisprudence is more in line with that of the United States, than the European Union. He stated that that former lays greater emphasis on the ‘reasonable expectation to privacy’. He then quoted a Harvard Law Review article, for the proposition that privacy should be tempered by considerations such as national security, efficiency, and entrepreneurship. He argued that that was especially true in the Indian context, where innovation and development should have more emphasis than privacy.

The counsel made reference to Justice Chandrachud’s opinion in Puttaswamy, and argued that social welfare could be a legitimate purpose for processing of data. Coming back to the construction of privacy, he argued that all Aadhaar data was in the public, relational sphere. He submitted that privacy is diluted in these realms, so there is a reduced expectation of privacy over data such as demographic data, and facial photographs. He reiterated that data with the Requesting Entities was dispersed, and therefore didn’t require the same level of protection as the CIDR.

Justice Chandrachud sought a clarification, if the submission was that core biometrics had a higher privacy interest, as opposed to demographic data, such as one’s address. He countered that the implication was not that the privacy interest in such data was gone. He gave the example of a woman and her address. He argued that she might give her address out for various purposes, but still had immense privacy interest in that information. The counsel responded that their argument was simply that privacy varies according to context.

The counsel argued that India had developed the appropriate tests in VG Row, much before any other jurisdiction. He reiterated the three-fold requirement of legality, necessity and proportionality. He noted that Indian jurisprudence generally did not adopt the due process standard. The counsel then addressed some of the cases that had been cited by the Petitioners, and attempted to distinguish them on facts.

Post lunch, the counsel resumed his submissions, with the issue of metadata collection. He attempted to distinguish the present case from Digital Rights Ireland, which had been cited by the Petitioners. The counsel argued that there were different types of metadata, and the data in question in those cases had been much more intrusive than what is collected by the Aadhaar authentication. He reiterated that the test is that of ‘appropriate safeguards’. He cited the case of Sundar Rajan v State of Tamil Nadu, which dealt with the Kundankulan nuclear power plant. He argued that the court had examined whether adequate safeguards had been in place, and had given due weight to economic benefits such as the increase in welfare, poverty alleviation etc. He argued that the Court in Sundar Rajan had held that apprehensions and fears could not be allowed to override the justification of the project. The counsel reiterated that the standard would be of ensuring adequate safeguards, and the risk would never be zero.

The counsel argued that the Aadhaar Act imposes a complete bar on sharing of the data, factors in consent, and the data with Requesting Entities was in any case disbursed and decentralized. He argued that the Petitioners had not suggested any way of improving the system, and only wanted it dismantled.

Justice Chandrachud asked what remedy was present in case of breaches. The counsel responded that the Information Technology Act would be applicable, which had penal provisions. Further, the route of contractual damages could be taken.

The counsel then described the EU Data Protection Directive, arguing that the purpose of the Directive was very different, with the aim being to ensure free flow of data. He argued that in contrast, Aadhaar didn’t allow any sharing of data. He argued that as a result, the absence of a regulation such as the Directive, or the General Data Protection Regulation would have no bearing on the matter at hand. He reiterated that the protections in the Aadhaar Act were sufficient, and even higher than those provided by the EU instruments. The counsel then went over the various provisions of the Directive and Regulation that govern the processing of sensitive information.

The counsel then resumed his submission with respect to metadata, as a response to the surveillance concerns raised by the Petitioners. He argued that the Petitioners had not appreciated the distinction between different types of metadata, such as system metadata, process metadata, business metadata etc. He argued that each had to be examined separately. He submitted that Aadhaar authentication only collected limited technical metadata.

The Chief Justice asked why the data had to be retained, and what sort of data was actually retained. The counsel drew the Court’s attention to an affidavit he had submitted, as well as the relevant circular which prescribes the metadata that is collected. He argued that it was all system related metadata, which allowed the UIDAI to exercise control over the Requesting Entities. He argued that information such as location data, the purpose for authentication, was not collected in the process.

The hearing will continue on April 25, 2018.

 

Advertisements

SC Constitution Bench on Aadhaar- Final Hearing (Day XXXI)

In October 2015, a 3-judge bench of the Supreme Court of India referred challenges to the Aadhaar program to a constitution bench. One of the primary concerns of this petition was to decide on the existence of a fundamental right to privacy, which has since been upheld. Other similar petitions, concerned with the legitimacy of Aadhaar had been tagged with this petition. While the existence of the fundamental right to privacy has been upheld, challenges against the Aadhaar programme and linking services to this programme were yet to be adjudicated upon.

An interim order was passed in December of 2017, a summary of the arguments can be found here and here.

The final hearing commenced on January 17, 2017. Summaries of the arguments advanced in the previous hearings can be found here.

Senior Counsel Rakesh Dwivedi resumed his arguments on behalf of UIDAI and the state of Gujarat.

He discussed the nexus between s.7 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (Aadhaar Act / Act) and welfare of the society. Justice Chandrachud mentioned that as per the submissions, the absence of a robust method for identification of beneficiaries result in leakage of services which is appropriated by undeserved. He asked if Aadhaar would help in eliminating this issue to which Mr. Dwivedi answered in the affirmative.

Justice Chandrachud stated that the caveat pointed out by the petitioners is that there should be no exclusion on the grounds of not having an Aadhaar. Mr. Dwivedi responded that adequate measures are taken to ensure that no exclusion takes place on that ground. He further stated that Aadhaar brings the card holder face to face with the service provider since he has to go to him and give his biometrics. Justice Chandrachud responded that it is not the best model of governance and ideally the state must go to the individual. Mr. Dwivedi responded that such a model would depend on the capacity of the government.

Next, Mr. Dwivedi discussed about countries having economic and social rights and right to welfare as part of their respective constitutions also pointed out that welfare rights are a part of the Universal Declaration of Human Rights (UDHR). He reiterated that basic welfare requirements must be taken care of.

Mr. Dwivedi then referred to the Statement of Objects of the Protection of Human Rights Act, 1993 and pointed out that India is a signatory to it and many other international covenants as well. He further referred to various judgments of the Supreme Court on economic and social welfare, which culminated the framing of the Aadhaar Act.

Addressing the issue of balancing of rights, he referred to CJI’s judgment in Subramanian Swamy v. UoI, and pointed out how the right to freedom of speech was balanced against the right to reputation. He also referred to X v. Hospital Z, G. Sundarrajan v. UoI, Asha Ranjan v. State of Bihar, and Noise Pollution In Re v. UoI.

Mr. Dwivedi submitted that s.7 of the Act addresses the human rights of many people in the country and therefore the court should act as a sentinel and ensure that the right to privacy is balanced against all the other rights guaranteed under Ar. 21 that are covered by the Act. He reiterated that privacy is a small price that is to be paid for ensuring life and other rights under Ar.21. He further submitted that larger public interest is the determining factor when there is a conflict between rights. Justice Chandrachud however responded that it cannot be accepted as a ground for suppression of civil rights and Mr. Dwivedi responded that Aadhaar does not result in it.

The CJI asked if the argument was that whatever was done under the Act was to enhance the Ar.21 right of many, that being the legitimate state interest, accompanied by minimal intrusion, and Mr. Dwivedi responded in the affirmative.

Next, Mr. Dwivedi addressed the issue of reasonable expectation of privacy. He began with a discussion of the four kinds of information collected as part of the Aadhaar programme- a) demographics, b) optional demographics, c) biometrics, and d) core biometrics. He reiterated that these information are encrypted and stored in the CIDR and the authentication is performed either through YES or NO mode or E-KYC mode.

He submitted that the reasonable expectation of privacy would vary from one kind of information to another and that nobody can have it with respect to their demographic information and photo as it is publicly available.

The CJI mentioned that in case of every right, everyone has a reasonable expectation of exercising it. He further stated that in some instances the rights cannot be exercised in absoluteness and therefore whenever freedom is claimed it should be reasonable and that it applies to privacy as well.

Justice Sikri mentioned that the fact that the CIDR has all these information creates a fear of the data being utilized in a manner and for purposes unauthorized by the individual. Mr. Dwivedi responded that the UIDAI could only take note of general apprehensions and not subjective fears.

The hearing will continue on April 24, 2018.

SC Constitution Bench on Aadhaar- Final Hearing (Day XXX)

In October 2015, a 3-judge bench of the Supreme Court of India referred challenges to the Aadhaar program to a constitution bench. One of the primary concerns of this petition was to decide on the existence of a fundamental right to privacy, which has since been upheld. Other similar petitions, concerned with the legitimacy of Aadhaar had been tagged with this petition. While the existence of the fundamental right to privacy has been upheld, challenges against the Aadhaar programme and linking services to this programme were yet to be adjudicated upon.

An interim order was passed in December of 2017, a summary of the arguments can be found here and here.

The final hearing commenced on January 17, 2017. Summaries of the arguments advanced in the previous hearings can be found here.

Rakesh Dwivedi resumed his arguments for the Respondents. He began with the issue of  Section 7 and exclusion. The counsel responded to the argument about probabilistic systems by submitting that there are alternatives that are allowed by the Act. In the event of an authentication failure, the first alternative is to produce a proof of possession of Aadhaar. The second alternative is to provide enrollment ID, for people who haven’t yet received the Aadhaar. He submitted that the UIDAI had issued directions to this effect. A refusal to comply would be a breach under the Aadhaar Act.

Justice Chandrachud asked if the Section 7 proviso would apply to someone who had not applied for Aadhaar. The counsel replied in the negative. The counsel continued, describing the Regulation. He submitted that for State and Central agencies that require Aadhaar for benefits, they are required to ensure enrollment, including the setting up of coordination centres. Further, in the context of PDS, he argued that Clause 5 of the relevant notification allowed any member of a household to claim the benefit. He concluded that there could be no question of denial, as a result of these measures.

Justice Chandrachud asked if the systems had been tested in remote areas, with limited connectivity, such as Ladakh. Section 7 is silent on alternatives in such cases. The counsel responded that certain exemptions had been notified in the regulations.

The counsel reiterated that the system should not be demolished, but improved so that it could work. He then submitted that even today, we live in a relational world. One cannot pick and choose how one relates to the world; or how one establishes identity. All institutions require some kind of identity, and have some conditions about it.  He argued that this wasn’t a question of dignity, because these are regulatory conditions. He stated that these are permissible, and the only standard is if a fundamental right is being violated.

The Bench noted that the counsel was trivializing the Petitoners’ argument. They noted that the central concern was that of centralization of the database and its misuse.  Justice Chandrachud further argued that the issue was why only one identity had been mandated, and why multiple identities could not be allowed.

The counsel responded that one must go by the rules of the institution they want to participate in. He provided the example of the Proximity Card of the Supreme Court. Justice Chandrachud asked if the form of identity should relate to the purpose of identification. The counsel agreed, stating that there should be a rational nexus. However, he argued that allowing different forms of identity to be submitted would lead to a slippery slope which would destroy the whole purpose of the system.

Justice Bhushan added that many of the other forms of identification don’t have pan-India operation. The counsel agreed, noting that they were also sectoral, without any portability. In comparison, he argued, Aadhaar is universal. Aadhaar is also unique on account of the use of biometrics. If you abandon biometrics, the unique nature is lost. He submitted that even Smart Cards use biometrics.

Justice Chandrachud reiterated the concern about aggregation and analysis of data. The counsel responded that all protections that were socially and legally possible were in place.

He continued, stating that the argument about biometrics providing knowledge about the person was incorrect. He argued that while DNA might contain such information, fingerprints don’t. Further, only one fingerprint would be present with the Requesting Entities. Justice Chandrachud clarified that the issue was not of the biometrics themselves, but their attachment and linking to everything else, which could become a source of information about the individual. The counsel responded that no single Requesting Entity would have access to all of that information. It would be delegated and segregated. Further, any collusion or aggregation would not possible. Any misuse would require corruption at an inconceivable scale. In addition, most of the authentication would be required very rarely – once a year, or once in a lifetime. For PDS, it would be once a month.

At this point Shyam Divan interjected, that Banks had been demanding Aadhaar every time a Fixed Deposit is opened. The counsel responded that for most people, that is also a rare occurrence. Further, that was an issue on the Bank’s side, and not mandated by the Act. He argued that that can be examined separately. If the law were to be changed, to mandate authentication for every transaction, that could be questioned and challenged.

The counsel then moved on to the issue of clashes between fundamental rights. He brought the bench’s attention to the Preamble to the Constitution. He argued that the Preamble states that certain values are to be ‘secured’ by the state, and certain are to be ‘promoted.’ He argued that this imposes an obligation on the state to provide the basic minimum (for instance, minimum wages) to people. He argued that there was therefore a hierarchy, and the right to life should triumph over the right to privacy. He argued that for the people to without the bare minimum, the Constitution would amount to a mere paper Constitution.

Justice Chandrachud noted that dignity was not a peripheral value in the Constitution, but the core foundation of all rights. The Constitution protects dignity in all its forms, and food security and privacy were both aspects of dignity. The counsel responded that when they were in conflict, the first must have primacy over the second. He noted the NALSA judgment, which according to him brought about a paradigm shift in our conception of dignity.

Justice Bhushan questioned if they had to be read in conflict, and could not be recognized together. The counsel responded that they were arguing for a balanced approach, and in this case, in the favour of the right to life.

Justice Chandrachud asked if this would require a proportionality test. He stated that the question was whether the incursion on privacy is so less, to justify the benefits that have been claimed. The counsel responded that in the case of a restriction on a right, the burden lies on the state. However, this was a case of an interplay between rights. Justice Chandrachud countered that the burden was still with the state. The counsel responded that they were only submitting that the parameters for scrutiny would be different. Further, that Article 21 supersedes the rights under Article 19 and 14. Life would come first, and the other rights wouldn’t mean anything without it.

The counsel then resumed arguing for the relevance of biometrics, noting that large parts of the population were illiterate. Their thumbprints were all they had had to use in the conduct of their lives.

The Chief Justice noted that the real problems were of surveillance, aggregation, privacy and exclusion, which have to be addressed. The counsel said that the subsidies were in furtherance of life, liberty and dignity.

Justice Chandrachud asked for a clarification, whether the respondents were arguing for the tests under Puttuswamy to be abandoned. The counsel responded in the negative, and that Section 7 was not examined in Puttuswamy.

He then went on to quote from the Universal Declaration of Human Rights, and excerpts from Kesavanda Bharathi, the NALSA judgment, and German human rights jurisprudence.

The hearing will continue on April 19, 2018.

 

SC Constitution Bench on Aadhaar- Final Hearing (Day XXIX)

In October 2015, a 3-judge bench of the Supreme Court of India referred challenges to the Aadhaar program to a constitution bench. One of the primary concerns of this petition was to decide on the existence of a fundamental right to privacy, which has since been upheld. Other similar petitions, concerned with the legitimacy of Aadhaar had been tagged with this petition. While the existence of the fundamental right to privacy has been upheld, challenges against the Aadhaar programme and linking services to this programme were yet to be adjudicated upon.

An interim order was passed in December of 2017, a summary of the arguments can be found here and here.

The final hearing commenced on January 17, 2017. Summaries of the arguments advanced in the previous hearings can be found here.

Rakesh Dwivedi resumed his arguments for the Respondents. He began with stating that if there were problems with the system, they should be fixed, rather than the system being demolished completely. He argued that under Section 8 of the Act, the sharing and use of information was confined specifically to the authentication process. He further argued that the mandate of Section 29 states that core biometrics cannot be shared.

Justice Chandrachud asked how the UIDAI planned to control the Requesting Entities. The Counsel responded that control could be in terms of technical specifications of the devices, mandating approved software, mandating information systems audits etc.

In response to Justice Chandrachud’s query about the framing of Sections 8 and 29, the Counsel reiterated that the sharing of information would be limited to the process of authentication. Further, only non biometric information could be shared under Section 29.

Next, there was some disagreement between the counsel and Justice Chandrachud on the interpretation of Section 8. The Counsel stated that the Requesting Entity would not know the purpose for the authentication, but only that authentication had been done. Justice Chandrachud stated that that could be true for UIDAI, but it was uncertain if that would be true for Requesting Entities. According to him, the language of the Act didn’t conform to this design. Justice Sikri added that that would also render Section 8(3) redundant. The Counsel responded that the Bench could chose to read the Act in that way.

Justice Chandrachud then gave an example of an individual who goes to the hospital for certain services. The hospital sought authentication for him, 122 days out in 6 months. He noted that that would be potentially extremely valuable information for pharmaceutical companies, insurance providers etc. Until there was a data protection law, this could be a problem.

The counsel responded that no other jurisdiction has the sort of protections that the Aadhaar Act provides. Justice Chandrachud asked if the protection under the Act was all the data protection the citizens of India would ever need. He also gave the example of the European Union’s General Data Protection Regulation as an example of a comprehensive framework for data protection. The Counsel replied that the Aadhaar Act was sufficient, and in many ways superior. According to him, the GDPR has no penal provisions, and the States have to enact their own, which creates a patchwork. The Counsel argued that the Aadhaar framework has technological security, auditing, as well as penal provisions in place. He went on to say that there could never be 100% surety about anything. The standard to be sought was that of reasonable safeguards, and reasonable protection. He noted that none of the Petitioners had pointed out what more could be done.

Justice Chandrachud then noted that according to the Counsel’s reading, Sections 8(3) and 29(3) could be excised from the Act. The Counsel responded that nothing needed to be excised from the Act, only clarified. Further, there was no intent, purpose, or objective in the Act to allow aggregation of data, its analysis or transfer. In addition, any breach of the provisions would be punitive.

Justice Chandrachud observed that it is hard to predict commercial ingenuity, and it wouldn’t be possible to tell what use the Requesting Entities could make of the data with them. Justice Sikri interjected with the earlier hospital example, noting that the hospital would already have the data about medical treatments of the patients, and may not need Aadhaar to get that information. The main apprehension was one of misuse. The counsel agreed, questioning whether Aadhaar was adding to the problem, or making it worse in any way.

Justice Chandrachud noted that they must evaluate what safeguards can be introduced. He noted that data about individuals was now being used to influence electoral outcomes.

The counsel responded that Cambridge Analytica should not be brought into the discussion, because the nature of the data was different. Justice Chandrachud interjected, stating that that incident was symptomatic of the present times. The counsel responded arguing that the algorithms employed were different. There is a difference between matching algorithms (which Aadhaar uses) and sorting algorithms (which these companies use). He argued that there were many different types of algorithms, and the Petitioner’s had confused this distinction.  He concluded that the data could not be analyzed by the Respondents. If at all, they would have to go through proper procedure.

The counsel continued, stating that Smart Cards were entrenched technology and that the Smart Card lobby in the West didn’t want Aadhaar to succeed. He claimed that other countries like Singapore were looking to replicate our model.

Justice Chandrachud noted that the issue was that there is a big world that interacts with Aadhaar. He said that the UIDAI might only be the least of their problems, since it is a government entity subject to a lot of scrutiny. The Counsel reiterated that only matching algorithms are used.

Coming back to the Act, the counsel submitted that Requesting Entities cannot be enrolled unless they establish the need for authentication.  Justice Chandrachud asked what the purpose behind opening Aadhaar to private players was. In response, the Counsel argued that the nature of the public-private divide was changing. Private companies have been entering fields that were historically the domain of the public sector. The companies are funded by money from Banks, where the people have made deposits. So, it was actually the public that is funding these players. He argued that private players that perform public functions should also be subject to constitutional norms, review and scrutiny. Currently, public companies are subject to many restrictions, such as standards of reasonableness, while no similar shackles apply to private companies. He concluded stating that that was a larger debate for another time. For now, all that was necessary to know is that private players are also regulated by the Act.

The counsel then moved on to responding to the Petitioner’s argument that the Aadhaar framework amounted to the numbering of human beings. Counsel argued that we have been numbering humans for a long time. He cited the PNR number for flights as an example. He also noted that the Supreme Court proximity cards were numbered.

Justice Chandrachud responded that Aadhaar was a unified identity, as opposed to multiple identifying numbers. The counsel responded that just because they were assigning numbers for a specific purpose, didn’t mean that they were numbering people. Further, they were not collecting information such as race, caste etc.

Justice Chandrachud then asked how the Aadhaar became a mandate, from a mere entitlement. The Counsel responded that the Aadhaar was an entitlement, and the UIDAI was mandate neutral. It is the government that notifies that certain linkages are mandatory. Each of these could be examined or challenged separately.

The counsel resumed his arguments after lunch by examining the scope of Section 57.  He argued that the objective of the section was not to expand, but to limit power. He submitted that if this limitation did not exist, anyone could become a Requesting Entity. The provision requires that there must be a law, or a prior contract.

Justice Chandrachud asked if once there was a prior contract under Section 57, if the UIDAI would be bound to offer authentication.  The Counsel responded that UIDAI could still refuse, and there was a requirement of necessity. Further, this embargo was applicable to anyone, which is why State Resident Data Hubs are no longer possible.

The Bench noted that nothing in the Act seems to give UIDAI this type of discretion, and questioned whether there were any guidelines for how the UIDAI would come to its decisions. The counsel responded that the power came from Section 57. He gave the example of the CBSE, noting that there had been many cases of fraud. The Board could apply to be a Requesting Entity for the purpose of conducting the exam. However, this would require the presence of a prior contract, and it cannot be an ex post facto exercise. He argued that this contract must also state that authentication must be in accordance with Sec. 8 and Part VI of the Aadhaar Act.

The counsel then went on to examine the Information Technology Act, arguing that all the provisions and safeguards under that Act and its Rules would also be applicable. For instance, the CIDR had been notified as a protected system under the Act.

The counsel then discussed the attributes and benefits of biometric data. He argued that Aadhaar brings service providers face to face with the beneficiaries. He noted that Aadhaar would not be a panacea for all problems, but the issue of fake identity documents would be solved.

He then responded to other arguments raised by the Petitioners. In response to the argument that there was no legal mandate to store information in the CIDR, he brought the Bench’s attention to Section 10 of the Act. On the argument of the use of foreign suppliers and licensors, the Counsel responded that the hardware all belonged to the UIDAI, and even technicians only had access when there was some troubleshooting required. In response to the system being probabilistic, he argued that there were appropriate fall back mechanisms under Section 7.

The hearing will continue on April 18, 2018.

 

SC Constitution Bench on Aadhaar- Final Hearing (Day XXVI)

In October 2015, a 3-judge bench of the Supreme Court of India referred challenges to the Aadhaar program to a constitution bench. One of the primary concerns of this petition was to decide on the existence of a fundamental right to privacy, which has since been upheld. Other similar petitions, concerned with the legitimacy of Aadhaar had been tagged with this petition. While the existence of the fundamental right to privacy has been upheld, challenges against the Aadhaar programme and linking services to this programme were yet to be adjudicated upon.

An interim order was passed in December of 2017, a summary of the arguments can be found here and here.

The final hearing commenced on January 17, 2017. Summaries of the arguments advanced in the previous hearings can be found here.

Advocate K. K. Venugopal resumed the arguments for the state. He submitted that s.59 of the Act provides for retrospective application. He referred to cases wherein actions were validated by a subsequent Act.

The AG then discussed the third version of the Aadhaar enrollment notification and highlighted that it is free and voluntary and provides for informed consent. Justice Chandrachud asked if the notifications that came out in 2009 and 2015, referred to in s.59 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (Aadhaar Act / Act), covers the entire universe of Aadhaar. He further pointed out that these notifications did not have any reference to biometrics and that it was only inserted in the third notification. He stated the argument is regarding the actions that took place before the issuance of the third notification.

Senior Counsel Rakesh Dwivedi responded the first two forms were hardly used as the government authorized only 1 crore enrollments prior the issuance of the third form.

The AG, next, mentioned that in 2014 when the CBI approached the Bombay High Court to obtain biometrics from the Central Identities Data Repository CIDR in connection with a rape case, the Unique Identification Authority of India (UIDAI) opposed it as it believed that it bound to not disclose it without the individual’s consent. Interestingly, Justice Chandrachud pointed out that the Magistrate of the lower court had passed an order to provide the CBI with the biometrics of all the residents of Goa, which was appealed by the UIDAI.

Next, referring to Justice Chandrachud’s judgment in Justice K. S. Puttuswamy & Anr. V. UoI & Ors., which talks about ‘reasonable expectation of privacy’, he reiterated that biometrics collected is only for the purpose of benefitting the individual and that the invasion of privacy as a result of it is minimal. He further stated that the Puttuswamy judgment restored privacy as a fundamental right but actions that took place prior to that should be neutralized. He further submitted that going by M. P. Sharma & Ors. Satish Chandra and Kharak Singh v. State of UP & Ors., the government acted in a bona fide manner and therefore its actions cannot be reversed but should be protected.

Justice Chandrachud said in Puttuswamy it was stated that the observation on privacy in M. P. Singh was not required and that with respect to Kharak Singh there is a clear inconsistency.

The CJI said the argument of the state should be that s.59 of the Act should be given a wider understanding and a purposive interpretation.

Additional Solicitor General Tushar Mehta commenced his arguments on behalf of the UIDAI. He stated he would address the following issues:

  1. Challenge to s.139AA of the Income Tax Act (IT Act) from the right to privacy perspective
  2. Challenge made to the argument of how Aadhaar helps in curbing the issue of money laundering
  3. Challenge to the linking of mobile numbers and bank accounts with Aadhaar number
  4. Scope of judicial review in the area of technology

Addressing the first issue, he stated his submissions would comprise of:

  1. Enforcement of the right to privacy
  2. How the tests laid down to determine legitimate invasion of privacy are dealt with in the Binoy Viswam v. UoI & Ors.
  3. How these tests are satisfied by 139AA of the IT Act

The ASG stated this court had previously dealt with the challenge to s.139AA and that all aspects expect the right to privacy were addressed. He pointed out that in Puttuswamy, the right to privacy was upheld as a fundamental right, linked to Ar.21 and therefore subject to the same limitations as the article. He referred to Justice Chandrachud’s judgment that laid down the three tests used to determine to permissible limitations on the right to privacy- existence of law, legitimate state interest, and proportionality. He submitted that there is an additional test of manifest arbitrariness derived from Shayara Bano.

He submitted that all the four tests were examined in the case of Binoy Viswam but in the context of Ar.19. He, next, stated that Justice Nariman, in Puttuswamy, put forth another test of larger public interest, having a lower threshold than legitimate state interest. The CJI however responded that satisfaction of legitimate state interest would be sufficient to indicate larger public interest.

Next, he referred to s.139A of the IT Act and highlighted that it required signature and left hand thump impression since 1989 to obtain a PAN. Justcie Sikri pointed out that the fingerprint was collected only from those people who could not sign. However the ASG responded the privacy of the small group of illiterate people is not of lesser importance. He further stated that the Parliament introduced s.139AA as an extension of s.139A in light of legitimate state interest and larger public interest. The bench however pointed out that the Aadhaar regime is different as previously there was no practice of collection of biometrics or authentication.

The ASG next discussed the issue of duplication of PAN and how it is misused for the purpose of money laundering, tax evasion, setting up of shell companies. He submitted the linking of Aadhaar with PAN would help in eliminating these problems by making PAN allocation more robust.

He further stated that uniqueness of PAN is important and that it can be verified with Aadhaar using biometrics and iris scans and claimed that it would be 100 percent accurate.

The ASG further stated that there is huge gap between the number of PAN holders and the tax base. He submitted that ours is a largely tax non-compliance economy as only 1.72 lakh people in the country are showing an income above 50 lakhs.

The hearing will continue on April 11, 2018.

SC Constitution Bench on Aadhaar- Final Hearing (Day XXV)

In October 2015, a 3-judge bench of the Supreme Court of India referred challenges to the Aadhaar program to a constitution bench. One of the primary concerns of this petition was to decide on the existence of a fundamental right to privacy, which has since been upheld. Other similar petitions, concerned with the legitimacy of Aadhaar had been tagged with this petition. While the existence of the fundamental right to privacy has been upheld, challenges against the Aadhaar programme and linking services to this programme were yet to be adjudicated upon.

An interim order was passed in December of 2017, a summary of the arguments can be found here and here.

The final hearing commenced on January 17, 2017. Summaries of the arguments advanced in the previous hearings can be found here.

Attorney General K. K. Venugopal resumed his arguments for the state. He continued to refer to judgments that upheld the collection of biometric information. He discussed the decision of the US Court of Appeals, which dealt with DNA and forensic identification of prisoners. The CJI pointed out that the case only dealt with a narrow group of offenders and therefore might not be applicable to the context of Aadhaar. The AG responded that the reasoning of the court is relevant as it upheld the legislation on the grounds that it cannot be struck down on the basis of mere possibility of misuse in the future and that if the provision is later amended it will be dealt with in the future.

Justice Chandrachud responded the issue here is not that of misuse but of the use of law as s.2(g) of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (Aadhaar Act / Act) can expand the scope of ‘biometric information’. He further mentioned such power vested in an administrative authority might not meet the proportionality requirement. The AG responded it is an issue of excessive delegation and that he would address it.

He next referred to a Fordham Law Journal article on automated finger imaging and the right to privacy explaining how the former does not result in a violation of the latter. Referring to the article, he stated finger imaging is 99.9 percent accurate.

He submitted biometrics is a tool for very accurate conclusion as it prevents fraud and other violations such as tax evasion, money laundering. However Justice Sikri replied fraud is not because of multiple identities. The AG responded if there is Aadhaar, there would be no question of multiple identities. Justice Chandrachud pointed out Aadhaar would not prevent a person from setting up multiple layers of commercial entities controlled by the same individual and therefore would not contribute towards preventing bank frauds.

Justice Chandrachud further stated that even if Aadhaar satisfies the legitimacy of interests, the crux of the issue deals with proportionality. He asked how far could the state cast the net. He pointed out that under s.7 of the Act, the state can rely on legitimate state interest i.e. ensuring that the benefits go to the deserving people but the issue is with respect to those areas which are unrelated to the areas stipulated under s.7.

The AG responded that the government has to compare to 1.2 billion names to avoid de duplication and identify the right person. He asked how far does the casting of the net to areas other than the ones mentioned in S.7 of the Act result in a violation of the right to privacy.

Justice Sikri stated the requirement to tabulate each and every activity involving money, irrespective of whether it’s linked to s.7, through authentication might not satisfy the requirement of proportionality. He cited the example of linking mobile number with Aadhaar and said one can say it’s related to money laundering but considering everyone to be a possible violator is violation of proportionality.

The AG responded that terrorists communicate to each other secretly through cell phones and pointed out the example of internet shut down in Kashmir. However Justice Chandrachud responded that the political wisdom of the action is not questioned but he pointed out that terrorists do not apply for mobile number and therefore it is not necessary to ask everyone to disclose their Aadhaar number to obtain a mobile number.

The AG responded the question is to what extent is the right to privacy invaded. He reiterated it is as minimal as possible and further submitted that as far as demographics are concerned, all of it is available in the public domain and therefore there is no invasion of privacy other than the bare minimal amount. He also stated that this helps in serving large public interest.

The AG then asked if a claim of right to privacy can be raised for the purpose of denying rights covered under s.7 of the Act and pointed out that earlier there were large number of fake cards. Justice Chandrachud stated s.7 is not based on an ‘US v. Them’ argument. He pointed out Ar.21 has two elements- a) economic and b) privacy.

The AG responded both the rights are traceable to the same article and therefore the issue is how to reconcile between them. He referred to a case wherein the court upheld the right to information over the right to privacy. However Justice Sikri pointed out that in the case the court only had to deal with balancing of two rights of the same person.

The AG responded that only the bare minimal amount of information required to satisfy the identity of the individual is collected. He further stated that where Aadhaar is required for ensuring that the vast majority of population have the basic right to life such as shelter, food, there is full justification for the encroachment on the right to privacy, provided it is minimal.

Justice Chandrachud suggested the better argument for the state would be to acknowledge that there is an invasion but that it is proportional to the need. He also said in order to decide if the invasion is minimal or not other factors such as informed consent, purpose for which biometrics is obtained, safeguards that are in place to ensure that it is not leaked out for other purposes should be considered. Justice Bhushan interjected that minimal invasion is purely subjective. The AG responded the bench should look at the information collected from an objective perspective keeping in mind the larger interest of the country.

Justice Chandrachud said proportionality laid down in Justice K. S. Puttuswamy And Anr. V. UoI was in broad terms and therefore it is to be determined how to use it in the case of Aadhaar. He asked if it would mean utilization of data only for the purpose for which it was collected. The AG responded not one extra element of information is collected from the individual than is required for the purpose and further submitted that s.29(1)(a), s.29(1)(b) of the Act stipulate purpose limitation.

Next, Justice Chandrachud mentioned there was no safeguard before the Act came into being and that s.59 of the Act does not provide for retrospective application. Senior Counsel Rakesh Dwivedi submitted that a concept study was performed in rural areas before Aadhaar was decided upon and that Information Technology Act in 2009 empowered the use of Aadhaar for e-commerce.

The hearing will continue on April 10, 2018.

SC Constitution Bench on Aadhaar- Final Hearing (Day XXIV)

In October 2015, a 3-judge bench of the Supreme Court of India referred challenges to the Aadhaar program to a constitution bench. One of the primary concerns of this petition was to decide on the existence of a fundamental right to privacy, which has since been upheld. Other similar petitions, concerned with the legitimacy of Aadhaar had been tagged with this petition. While the existence of the fundamental right to privacy has been upheld, challenges against the Aadhaar programme and linking services to this programme were yet to be adjudicated upon.

An interim order was passed in December of 2017, a summary of the arguments can be found here and here.

The final hearing commenced on January 17, 2017. Summaries of the arguments advanced in the previous hearings can be found here.

Attorney General K. K. Venugopal resumed his arguments for the state. He stated that the policy decisions of the government cannot be the subject matter of any judicial review and that the three organs of the state should mutually respect each other. He further stated that judicial review of every administrative decision will hinder development and that the duty of the court is to expound the language of the act and not decide the fairness of a particular policy.

Justice Sikri pointed out that the petitioners’ are challenging the state’s submission that Aadhaar results in only minimal invasion of privacy and therefore their challenge is based on the principle of proportionality. Mr. Venugopal replied that Aadhaar has a legitimate state interest. However Justice Sikri stated that the bench is not concerned with the policy decision but the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (Aadhaar Act / Act) and the Regulations.

Justice Sikri further asked, if Mr. Venugopal is arguing that the Aadhaar system is almost impeccable and the court should not comment what is correct and what is not since the government has already performed extensive research with the help of experts. Mr. Venugopal replied in the affirmative and stated that the entire challenge is based whether the Aadhaar is safe and secure and that it already proved by them.

Next, he discussed the sixteen digit virtual ID. Justice Chandrachud asked if every Aadhaar holder gets one. Mr. Venugopal replied that it is up to the individual to generate one for himself through the UIDAI website. Justice Chandrachud asked if the entire population has the knowledge on how to do it to which Mr. Venugopal replied that it is only an additional measure. Justice Chandrachud suggested that there should be a provision that would enable everyone to have a virtual ID. However Mr. Venugopal stated out that if everyone is provided with one unique virtual ID just like an Aadhaar number, then it would be permanent and pointed out that now it is an ID that can be regenerated each time.

Justice Chandrachud confirmed if the idea behind the virtual ID is to mask the Aadhaar number so that one who is conscious about their privacy will have the option of providing a virtual ID in place of the Aadhaar number and prevent the latter from being in the public domain and AG answered in the affirmative.

Next, Justice Chandrachud stated that the fact that a legislation has adopted a legislative policy might indicate legitimate state interest but the mere fact that it is a policy decision is not sufficient to satisfy the proportionality test. Mr. Venugopal responded that the Aadhaar satisfies the test of proportionality since all possible alternatives were considered before it was adopted and reiterated that the court should not become an approval authority.

Next, Justice Chandrachud raised concerns with the power granted to the registration authority to determine what constitutes biological attributes and how it is to be collected. He said that because of the open-ended nature of biological attributes, in the future, the registration authority can even include DNA under it. He asked if power of this nature would satisfy the test of proportionality. Mr. Venugopal replied that as per s.55 of the Act Parliament would have the overseeing authority. However Justice Chandrachud pointed out that the regulations do not need the approval of the Parliament before it is implemented and that as per s.55 the regulation would be cancelled only if the Parliament disapproves it. Therefore the regulation takes effect as soon it is passed and its effect is not deferred till it is approved by the Parliament. He said this is an issue of excessive delegation. Mr. Venugopal replied that he would address this issue later.

Mr. Venugopal then referred to cases in which the collection of biometric information was decided to be reasonable and submitted that state may have vital interest in the collection of biometric information. Justice Chandrachud pointed out that in the cases referred, the biometrics were collected for a specific purpose such as in the interest of safety, ensuring protection against crime and stated that universal application of fingerprints irrespective of purpose is a violation of the proportionality principle. Mr. Venugopal replied that purposes enumerated under s.7 of the Act as well as other purposes such as prevention of money laundering, terrorism, black money are specific and legitimate state interests.

He then submitted that fingerprints are increasingly being used for non-criminal purposes and is not an unwarranted invasion of privacy.

Next, he submitted that fingerprints cannot be used for surveillance and that it only serves as a means for identification. He further stated that neither the current government nor the previous governments have used it for surveillance in the last seven years.

Next, he compared Aadhaar to SSN. Justice Chandrachud pointed out that SSN is equivalent to PAN card and not Aadhaar as it does not collect biometrics but contains only the name and SSN number. Senior Counsel Shyam Divan pointed out that SSN does not have authentication unlike Aadhaar. However Mr. Venugopal submitted that SSN collects more information than Aadhaar.

The hearing will continue on April 5, 2018.