Digi Yatra cannot insist on Aadhaar as proof of identity, says Kerala HC
360° Perspective Analysis
Deep-dive into Geography, Polity, Economy, History, Environment & Social dimensions — AI-powered, on-demand
Context
The Kerala High Court has directed that the portal, a biometric boarding system at Indian airports, cannot mandate the use of details as the sole proof of identity. The court, hearing a Public Interest Litigation (PIL), instructed the (AAI) to consider alternative identification documents for registration, emphasizing concerns over the collection and storage of sensitive personal data under the .
UPSC Perspectives
Polity
This case sits at the intersection of technological governance and fundamental rights, specifically the right to privacy as guaranteed under of the Indian Constitution, established in the landmark (2017). The court's observation that cannot insist on reinforces the Supreme Court's earlier ruling that authentication is only mandatory for welfare schemes utilizing the , and private or voluntary services cannot compel its use. The insistence on alternative ID proofs reflects the legal principle of proportionality, ensuring that state actions do not unnecessarily infringe upon citizen privacy when less intrusive means (other IDs) are available. For UPSC Mains, analyze this as a tension between the state's drive for digital public infrastructure (DPI) efficiency and the necessity of robust data protection frameworks.
Governance
The initiative is a prime example of e-governance aiming to streamline citizen services through facial recognition technology (FRT). However, its implementation has raised concerns about data localization, informed consent, and purpose limitation—core tenets of the (DPDP Act). The PIL highlights the gap between the rollout of digital services and the operationalization of regulatory bodies like the . The court's intervention underscores the need for privacy by design in government applications, where data minimization is prioritized. Candidates should evaluate how the DPDP Act aims to balance the facilitation of ease of living (seamless travel) with the mandate of securing sensitive personal data (biometrics) against unauthorized processing or breaches.
Internal Security
The widespread collection and storage of biometric data by entities associated with the presents significant cybersecurity challenges. Facial recognition data is highly sensitive and irrevocable; unlike a password, biometrics cannot be changed if compromised. Centralized databases or decentralized nodes storing this data become high-value targets for cyberattacks, raising concerns about mass surveillance and identity theft. The claims to use decentralized storage on passengers' devices, but the overarching architecture must be scrutinized against the standards set by and the DPDP Act. From a security perspective, over-reliance on a single identifier like creates a single point of failure; thus, the High Court's push for diversified identity verification enhances the resilience of the security ecosystem.