My Aadhaar details were leaked/misused, what legal remedy do I have?
My Aadhaar number and biometric details appear to have been leaked or used without my authorisation for some transaction. I have been reading conflicting things online and I would like to understand what Indian law actually says about this, which Act and Section applies, what the realistic timelines and costs are, and what I should be doing right now to protect my position. If the matter can be resolved without litigation I would prefer that route, but I want to know what my rights are before I agree to anything or sign any document.
My Aadhaar details were leaked/misused, what legal remedy do I have? is governed in India primarily by Aadhaar Act, 2016 – Section 29, Aadhaar Act, 2016 – Section 37, Aadhaar Act, 2016 – Section 47 and Digital Personal Data Protection Act, 2023. The short answer is set out below, followed by the practical steps most people in this situation need to take. Read it alongside the specific provisions named, because the exact relief available to you turns on the facts you can prove on paper.
Section 29 of the Aadhaar Act restricts sharing of core biometric information, and Section 37 punishes unauthorised disclosure of identity information with imprisonment up to 3 years and/or fine up to Rs 10,000 (up to Rs 1 lakh for a company).
Section 47 of the Aadhaar Act requires that a complaint under the Act can be filed only by the UIDAI or a person authorised by it — so you should first lodge a complaint with UIDAI (via the helpline 1947 or the grievance portal) so they can pursue the criminal complaint on your behalf.
Separately, if a private company mishandled your Aadhaar-linked personal data, you can pursue a civil claim under Section 43A of the IT Act and, going forward, under the DPDP Act, 2023 for the fiduciary's failure to implement reasonable security safeguards.
Never share your Aadhaar number/OTP with unverified callers, and use UIDAI's 'lock biometric' feature via the mAadhaar app to prevent misuse of your biometric data for authentication until the matter is resolved.
You can also request a Virtual ID (VID) from UIDAI instead of sharing your actual Aadhaar number for everyday verification, which limits future exposure.
What to do next: 1) Lock your Aadhaar biometrics immediately via the mAadhaar app or UIDAI website; 2) Lodge a complaint with UIDAI through the 1947 helpline or grievance portal; 3) File a complaint at cybercrime.gov.in if fraud has resulted from the leak; 4) Use a Virtual ID (VID) for future verification instead of your Aadhaar number.
If the other side has already issued a notice, filed a case or set a deadline, treat the matter as time-sensitive — most remedies under Aadhaar Act, 2016 – Section 29 carry limitation periods, and a delay you cannot explain weakens an otherwise strong case. You can post the details on the MyVakeel forum for a practising advocate to review, or book a paid consultation with a Bar Council verified lawyer in this practice area.
Disclaimer: This information is for general awareness and does not constitute legal advice. Statutes and their interpretation change, and outcomes depend on the facts of your case. Please consult a qualified advocate before acting on it.