The proposed regulations will supersede the Aadhaar (Authentication) Regulations, 2016 uidai.gov.in/images/regulat…
Context : This is the regulation relating to Authentication coming after #Aadhaar Amendments and the Aadhaar Good Governance Rules 2020
TLDR - This regulations is around authentication framework, including offline verification appointment of requesting entities and AUA/ASA, Obligations of Offline Verification Seeking Entities (OVSE), eKYC guidelines, regulations around logs, audit, transaction data
On definitions - ANCS - #Aadhaar Number Capture Service is a new tech getting a mention. There are very references technical details of this service, which will run by @UIDAI. At the outset, does seem like OAuth endpoint being run.
Regulations without sufficient details is bad
Offline verification gets regulatory recognition.
4 types of offline verification. They are allowing paper copy to be collected, which is deeply problematic.
But regulations now seek redaction / black out of first 8 digits. Will we see this in reality? Take your guess
Authentication types - such careful wording to allow facial authentication, without explicitly mentioning that in regulations.
#CoWIN is the first large scale app to perform facial authentication.
#OVSE must tell the Aadhaar holder - the nature of information received during auth / verification, its use - in local language *AND* must provide alternate viable means of identification, and cannot deny / refuse any service.
Upon withdrawing consent, Aadhaar data shall be deleted by the requesting entity in a verifiable manner and an acknowledgement of the same to be shared with resident.
Capturing biometrics. It is to be noted that @AyushmanNHA is capturing facial data for #CoWIN facial authentication pilot - without the processes and specification laid down by the authority in public domain.
Side stepping a bit on facial authentication guidelines by volunteers. Yeah, you will not see any reference to UIDAI, but this is how all #Aadhaar tech was built.
Coming back - "In all modes, Aadhaar number is mandatory and is submitted along with input parameters" - is such a disregard to #VID. But this is where we see - #ANCS Token eventually replacing, but there are no technical details of the same available, while the regulation has it
Notification about authentication / verification to Aadhaar holder, including the case of offline verification, where OVSE should notify about verification. through email and/or SMS on mobile number and/or paper based
acknowledgement. Basically, get a slip when you share #Aadhaar
Chapter III is about licensing of service providers. Basically, any private entity fulfilling the criteria (regulated financial sector entities / telcos) + OTHERS(!) are eligible. Chapter also deals with responsibilities of ASAs
#OVSE - This is pratically every amar-akbar-antony entity in India that demands #Aadhaar.
1 (b) makes no sense, after allowing to collect paper copies of Aadhaar at the top.
Log maintainence -- While @UIDAI itself will keep logs only for 6 months, per SC judgement, @UIDAI is now regulating that private entities / AUAs will have to keep them for 2 + 5 = 7 years! #SaveOurPrivacy
ASA too will have to maintain logs for 2 + 5 = 7 years.
Missed a key point on consent. Unless explicitly opted-out, you have presumed to have consented to modified purpose!!!
What the above means - Unless one explicitly opts-out of anything @AyushmanNHA brings - one is deemed to have consented for any purpose they modify - after one gave #Aadhaar for vaccination.
This has grave implications on health ID + tracking.
That's a wrap on the draft. There are few provisions "on paper" which tries to gives better rights to holders (Like OVSE notification) - but sweepingly bad provisions undermine everything else.
#ANCS - There is very little technical detail on this OAuth(?) like implementation. "Please note that your Aadhaar number will be captured by the UIDAI’s ANCS (Aadhaar Number Capture Service) on their website" -- tells another search result.
Need more technical documentation
• • •
Missing some Tweet in this thread? You can try to
force a refresh
Request for Proposal (RFP) for selection of a CONSULTING FIRM to operate Program Management Unit(PMU) in @MtcChennai opens today. Lets look the scope of privatization of #MTC Is this what for Dr Alby John IAS was appointed as MD? 🧵
#SaveMTC #SaveChernnai #ChennaiCityPartnership
A. Support #ChennaiCityPartnership
i) Management of Public Transport Service Contract
A PTSC without autonomy to set fares (revenue mobilisation) - will result in increased privatisation of services - as the target will be meet KPIs
ii) Management of GCC procurement and management.
Right - A private consultant will manage the private operator run GCC.
There is a lot of confusion on this #UPI charges and its being made to spread multiple 'fake news' in a area where there is clarity. This directly stems from fact - who is allowed to price on what?
NPCI will charges #MDR for transactions above ₹2000 - when the payment mode by user is a wallet.
Note - this is not the same as using PhonePe / GPay.
It is applicable only when you use Wallet - PhonePe / PayTM are popular wallets still exist.
It is not applicable when you use UPI via banks.
2. Who is making this announcement?
NPCI.
3. Can NPCI make this announcement?
All Payment operators are at liberty to price payment products - except ATM interchange - which @RBI actively regulates.
#UPI#AppUpdate PhonePe UPI, Payment, Recharge play.google.com/store/apps/det… Get. Set. Gold! <br><br>You can now accumulate Gold at regular intervals by setting up a Gold SIP on PhonePe! <br><br> P.S: Without worry about market risks and fluc...
#UPI#AppUpdate Truecaller: Caller ID & Block play.google.com/store/apps/det… We keep updating our App to make it better. <br>This version brings:<br>- Our redesigned profile will show you the number of spam calls, messages and unknown numbers ...
Vaccination data is shared equally between UNDP, BMGF, eGov - That all 3 is funded by @BillGates is connecting thread. #CoWIN#VaccinationCertificate#HealthData loot. -- Also #Modi photo to appease the political head of state to keep the loot silent.