UIDAI issued the FAQs on the Aadhaar Data Vault (ADV)/Hardware Security Module (HSM)

Nov 16, 2025 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Industry Specific ComplianceThe Unique Identification Authority of India (UIDAI) on November 03, 2025, issued the FAQs on the Aadhaar Data Vault (ADV)/Hardware Security Module (HSM).

The following has been stated namely: -

• The FAQs explain that Aadhaar-related data includes the Aadhaar number along with demographic details and must be stored only in a secure Aadhaar Data Vault (ADV). The ADV is a dedicated, isolated, encrypted storage system meant to minimize the Aadhaar data footprint within an organisation. 

• A Hardware Security Module (HSM)—a tamper-resistant cryptographic device—is mandatory for generating, storing, and managing encryption keys as per FIPS 140-2 Level 3 standards. 

• All Reporting Entities that store Aadhaar numbers or e-KYC data shall implement ADV and replace Aadhaar numbers across their systems with reference keys, which cannot be simple hashes. 

• Only the ADV may store Aadhaar numbers; other systems may store only masked demographic data or UID tokens with safeguards. Reference keys enable internal processing without exposing Aadhaar numbers, and multiple keys may be issued for operational needs. 

• The FAQs also clarify storage rules, implementation responsibilities, and the requirement that Aadhaar data shall never be duplicated outside the ADV even in encrypted form.

Detailed notification is attached below.


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT