Use of Aadhaar in employment records.

Use of Aadhaar in Employment Records

Introduction

Aadhaar is a 12-digit identification number issued by the Unique Identification Authority of India (UIDAI) under the Aadhaar Act, 2016. In employment relationships, employers may encounter Aadhaar in connection with employee identification, payroll, statutory benefits, provident fund records, attendance systems, tax-related documentation, and government welfare schemes.

However, the use of Aadhaar in employment records is subject to important constitutional and statutory limitations. An employer cannot simply assume that Aadhaar must be collected for every employment-related purpose. The purpose for which Aadhaar is collected, the legal authority for collection, the manner of authentication, and the handling of Aadhaar information are legally relevant.

1. Meaning of Aadhaar in Employment Records

Use of Aadhaar in employment records means maintaining or using an employee's Aadhaar number or Aadhaar-related information for legitimate employment or statutory purposes.

Possible contexts include:

  • employee identification;
  • payroll and salary administration;
  • provident fund records;
  • pension-related services;
  • government benefit schemes;
  • verification of identity;
  • statutory employment records;
  • employee onboarding;
  • attendance or access-control systems.

The legality of each use depends upon the applicable law and the particular purpose.

2. Constitutional Framework

The principal constitutional issue is Article 21, which protects the right to life and personal liberty and has been interpreted to include a right to privacy.

The Supreme Court's landmark judgment in K.S. Puttaswamy v. Union of India (2017) recognised privacy as a constitutionally protected right.

Privacy includes protection against inappropriate collection, storage and use of personal information.

Therefore, an employer's use of Aadhaar information must satisfy applicable legal requirements and cannot be treated as completely unrestricted merely because Aadhaar is an officially issued identity number.

3. Aadhaar Act, 2016

The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 provides the statutory framework governing Aadhaar.

The Act regulates matters such as:

  • Aadhaar enrolment;
  • authentication;
  • use of identity information;
  • protection of information;
  • disclosure;
  • penalties for unauthorised use.

The Aadhaar framework has also been affected by subsequent amendments and judicial decisions.

4. Aadhaar Is Not a Universal Employment Requirement

An important principle is that an employer should not automatically treat Aadhaar as mandatory for every employment-related activity.

The legality depends on the particular requirement.

For example, there is an important distinction between:

Aadhaar required by a valid statutory scheme

and

Aadhaar demanded by an employer merely as a matter of convenience.

An employer should therefore identify the legal basis for collecting and using Aadhaar.

5. Aadhaar and Employee Onboarding

During recruitment, an employer may need to establish the identity of an employee.

Other identity documents may potentially be available depending on the purpose.

Therefore, an employer should avoid treating Aadhaar as the only possible identity document unless a particular law or scheme specifically requires it.

This is especially relevant where refusal to provide Aadhaar could affect employment.

6. Aadhaar and Payroll

Aadhaar information may arise in payroll administration, but the employer should distinguish between:

  • information legally required for salary processing;
  • information required for a statutory benefit;
  • information collected merely for internal convenience.

Employers should collect only information that has a legitimate legal or operational purpose and should maintain appropriate security controls.

7. Aadhaar and EPF/PF Records

Aadhaar has significant relevance in the administration of provident-fund and social-security services.

Employees may be asked to link or authenticate their identity for particular statutory services.

However, the legal requirements applicable to EPFO processes should be distinguished from a general proposition that every employer has an unlimited right to retain Aadhaar information.

8. Aadhaar and Attendance Systems

Some employers may consider Aadhaar-based biometric attendance.

This creates additional privacy concerns because biometric information is highly sensitive personal information.

The employer must consider:

  • whether Aadhaar authentication is legally authorised;
  • whether another identification mechanism is available;
  • whether the collection is proportionate;
  • how biometric information is secured;
  • who can access it;
  • how long it is retained.

Using Aadhaar merely because it provides convenient employee identification does not by itself resolve these legal questions.

9. Aadhaar and Employee Privacy

Employment records can contain substantial personal information.

Aadhaar-related information can create risks including:

  • identity theft;
  • unauthorised disclosure;
  • impersonation;
  • misuse of authentication information;
  • excessive employee surveillance.

Therefore, organisations should establish appropriate access controls and information-security procedures.

10. Supreme Court's Aadhaar Judgment — K.S. Puttaswamy v. Union of India (2018)

This is the most important Aadhaar case.

A Constitution Bench examined the constitutional validity of the Aadhaar framework.

The Court upheld the Aadhaar scheme in substantial part but imposed important limitations on its use.

Principle

The Court emphasised the importance of:

  • privacy;
  • informational autonomy;
  • proportionality;
  • statutory authority;
  • protection against unnecessary collection and use of personal information.

Employment relevance

The decision demonstrates that Aadhaar use must be connected to a legally permissible purpose and cannot simply be expanded into an unrestricted identification mechanism.

11. K.S. Puttaswamy v. Union of India — Privacy Judgment, 2017

Before deciding the Aadhaar challenge, a nine-judge Constitution Bench recognised privacy as a fundamental right.

Principle

Privacy forms part of the constitutional protection of life and personal liberty under Article 21.

The judgment recognised different dimensions of privacy, including informational privacy.

Employment relevance

Employee Aadhaar information is personal information. Employers therefore need to consider privacy and lawful processing when collecting or retaining such information.

12. Binoy Viswam v. Union of India, 2017

The Supreme Court considered the government's requirement relating to Aadhaar and PAN.

The Court examined the statutory authority and constitutional issues surrounding the linking requirement.

Principle

Aadhaar-related requirements must operate within the legal framework established by legislation and constitutional protections.

Employment relevance

An employer cannot automatically transform every government Aadhaar requirement into a general employment requirement without examining the underlying statutory basis.

13. Justice K.S. Puttaswamy (Retd.) v. Union of India, 2018 — Section 57

The Supreme Court specifically examined the breadth of the Aadhaar Act's provisions concerning authentication and use by private entities.

The Court restricted the ability of private entities to demand Aadhaar authentication merely on the basis of contractual arrangements.

Principle

Private entities cannot claim an unrestricted power to use Aadhaar authentication simply because an individual agrees to it.

Employment relevance

This is particularly important for private employers. An employer should have an appropriate legal basis before requiring Aadhaar authentication from employees.

14. Aadhaar Act and Section 57

The original Aadhaar framework had permitted authentication in certain private-sector contexts.

The Supreme Court's 2018 decision invalidated the broad private-use provision contained in Section 57 to the extent challenged.

Subsequent legislative changes also altered the statutory framework.

Therefore, employers should not rely on old assumptions that "consent alone makes Aadhaar use lawful."

The precise statutory basis must be examined.

15. Lokniti Foundation v. Union of India

Aadhaar-related litigation has also addressed questions concerning authentication, privacy and the legal framework surrounding Aadhaar.

The broader judicial approach demonstrates that Aadhaar information requires safeguards because of the possibility of identity-related misuse.

Employment relevance

Corporate HR departments should treat Aadhaar information as sensitive employee information and restrict unnecessary access.

16. UIDAI v. CBI, 2014

The Supreme Court dealt with access to Aadhaar-related information in the context of investigative requirements.

The Court emphasised the statutory safeguards applicable to Aadhaar information.

Principle

Access to Aadhaar-related information cannot be treated as completely unrestricted.

Employment relevance

Employers should similarly avoid treating employee Aadhaar information as ordinary HR data that can freely be disclosed internally or externally.

17. K.S. Puttaswamy v. Union of India — Proportionality

The Aadhaar litigation is particularly important because of the constitutional principle of proportionality.

Government or institutional use of personal information should have an appropriate connection with a legitimate objective.

In an employment context, this raises questions such as:

  1. Why is Aadhaar being collected?
  2. Is there legal authority?
  3. Is Aadhaar actually necessary?
  4. Is another identification method sufficient?
  5. Who will have access?
  6. How will the information be protected?
  7. How long will it be retained?

18. Aadhaar Data Security

A corporate employer holding Aadhaar information should implement appropriate safeguards.

These may include:

  • restricted HR access;
  • encryption/security controls;
  • secure databases;
  • access logging;
  • limited retention;
  • employee awareness;
  • prohibition on unauthorised disclosure;
  • secure destruction where retention is no longer required.

The risk is particularly significant because Aadhaar numbers are permanent identifiers.

19. Aadhaar and Data Protection

The legal environment has also evolved through India's broader data-protection framework, including the Digital Personal Data Protection Act, 2023.

Employers processing digital personal data must consider the applicable obligations concerning:

  • lawful processing;
  • notice;
  • security safeguards;
  • data handling;
  • rights of individuals;
  • obligations of data fiduciaries.

The precise obligations depend on the nature and circumstances of the processing and the applicable commencement of statutory provisions.

20. Aadhaar and Employee Consent

Consent can be relevant, but it should not automatically be treated as a complete answer.

For example, an employee may technically agree to provide Aadhaar information because refusing could affect the employment relationship.

Therefore, the legal basis for processing should be examined separately from the employee's apparent agreement.

This is particularly important in employment because the employer and employee may not have equal bargaining power.

21. Aadhaar and Contractual Employment

Employers sometimes insert clauses requiring employees to provide Aadhaar information.

Such clauses should be examined in light of:

  • applicable legislation;
  • the actual purpose;
  • necessity;
  • privacy obligations;
  • security requirements.

A contractual clause cannot automatically override statutory privacy protections.

22. Aadhaar and Third-Party HR Vendors

Modern companies frequently outsource HR functions to:

  • payroll providers;
  • HR software companies;
  • background-verification agencies;
  • attendance providers;
  • benefits administrators.

If Aadhaar information is shared with such vendors, the employer should ensure that appropriate contractual and security safeguards are in place.

The organisation should know:

  • what information is shared;
  • why it is shared;
  • who can access it;
  • how it is protected;
  • when it will be deleted or returned.

23. Aadhaar and Employee Background Verification

Aadhaar may sometimes be used as one element of identity verification.

However, identity verification should not become an excuse for collecting unnecessary personal information.

Employers should distinguish between:

identity verification

and

unlimited access to an employee's identity information.

24. Important Compliance Principles for Employers

An employer using Aadhaar information should consider the following:

1. Purpose limitation

Collect Aadhaar-related information for a specific legitimate purpose.

2. Legal basis

Identify the law or lawful basis permitting the processing.

3. Data minimisation

Do not collect more information than necessary.

4. Security

Use appropriate technical and organisational safeguards.

5. Access control

Limit access to authorised personnel.

6. Retention

Do not retain information indefinitely without a legitimate reason.

7. Transparency

Employees should understand why their Aadhaar information is being collected and how it will be used.

8. No unauthorised disclosure

Aadhaar information should not be casually circulated through email, messaging applications or unsecured spreadsheets.

25. Example

Suppose ABC Ltd. asks every employee to send a scanned copy of their Aadhaar card to the HR WhatsApp group.

This raises several concerns:

  • Why is Aadhaar required?
  • Is it legally necessary?
  • Is WhatsApp an appropriate channel?
  • Who can access the document?
  • Will the document remain permanently in the group?
  • Is masking/redaction appropriate?
  • Is another identity document sufficient?

A more privacy-conscious approach would be to establish the legal purpose, use an authorised secure HR system, restrict access and collect only what is actually required.

26. Difference Between Aadhaar Authentication and Aadhaar Storage

These concepts should not be confused.

Aadhaar AuthenticationAadhaar Storage
Verification of identity through an authorised mechanismMaintaining Aadhaar information in organisational records
May occur for a particular transactionMay involve continuing retention
Purpose-specificCreates continuing data-security obligations
Authentication does not automatically mean unlimited retentionRetention requires a legitimate reason

27. Six Key Legal Principles

The jurisprudence surrounding Aadhaar and privacy establishes several important principles:

  1. Privacy is a fundamental right.
  2. Personal information deserves legal protection.
  3. Aadhaar use must have an appropriate legal basis.
  4. Private entities do not possess unlimited authority to demand Aadhaar.
  5. Purpose and proportionality matter.
  6. Security and confidentiality of identity information are essential.

Conclusion

The use of Aadhaar in employment records lies at the intersection of employment law, constitutional privacy, data protection and Aadhaar legislation.

Employers may need Aadhaar-related information for certain lawful statutory or employment purposes, but Aadhaar should not automatically be treated as a compulsory document for every HR activity. The legality of its collection depends upon the purpose, statutory authority, necessity, manner of processing, security safeguards and applicable data-protection requirements.

The Supreme Court's decisions in Puttaswamy, Binoy Viswam, UIDAI v. CBI and related Aadhaar cases establish that identity information cannot be treated as ordinary data free from constitutional and statutory safeguards.

For corporate HR departments, the practical rule is therefore: identify the lawful purpose, collect only what is necessary, protect the information, restrict access, and avoid treating Aadhaar as universally mandatory without a specific legal basis.

LEAVE A COMMENT