APAAR ID: One Nation, One Student ID – A Parent’s Complete Guide
APAAR ID:
One Nation, One Student ID
— A Parent’s Complete Guide
Every benefit. Every legal concern. Every unanswered question the government refuses to address directly — from the lens of privacy law, cybersecurity, and the Indian Contract Act.
The Government of India says APAAR ID is voluntary. Schools tell parents it is mandatory. The official reply from government authorities confirms “consent cannot be withdrawn.” Yet the consent form itself says it can be. This blog is not a scare piece. It is a structured, evidence-based analysis — benefits first — written so that every Indian parent can make a truly informed, free, and uncoerced decision about their child’s digital identity.
- What Is the APAAR ID? A Plain-Language Overview
- Part I — The Genuine Benefits
- Part II — Critical Technical Analysis of Government’s Security Claims
- Part III — Voluntary vs. Mandatory: The Central Contradiction
- Part IV — Legal Analysis: Contract Law, DPDP Act & Constitutional Rights
- Part V — Cybersecurity & AI/Deepfake Risks
- Part VI — Government’s Answers Examined (Q&A dated Jan 10, 2025)
- Part VII — Edge Cases Nobody Is Talking About
- Part VIII — What the Courts Have Said
- Part IX — Risk Matrix Summary
- Part X — What Should You Do as a Parent?
- Conclusion
What Is the APAAR ID?
The Automated Permanent Academic Account Registry (APAAR) is a unique 12-digit lifelong academic identification number assigned to every student enrolled in an Indian school or college. Conceptualised under the National Education Policy (NEP) 2020 and launched by the Ministry of Education in September 2023, it operates under the banner of “One Nation, One Student ID.”
The APAAR ID is structurally linked to two other government digital systems:
The APAAR ID is generated using the student’s Aadhaar number. For students under 18, parental Aadhaar and consent are required. This linkage is the root of most legal controversies.
Once generated, the APAAR ID is stored in and accessed through the student’s DigiLocker account. All academic documents — marksheets, degrees, certificates — are digitally stored here.
The APAAR ID is the primary key for the ABC system, which stores earned academic credits and allows credit transfer between institutions under NEP 2020’s flexible education framework.
The data collected under APAAR includes: name, date of birth, gender, photograph, contact details, Aadhaar number, authentication records, academic records, co-curricular achievements, attendance data, and any skill or sports certifications.
As of November 2025, over 33.85 crore students had created APAAR IDs across India. The Ministry of Education has set a target of 100% integration of all academic records by 2026–27.
The diagram below maps the full APAAR ecosystem — from the student at the centre to every system and third party their data flows through:
Figure 1 — APAAR Ecosystem: Data flows from student identity outward to 7 connected entities, including unregulated private recruitment agencies (bottom, red)
Part I — The Genuine Benefits
A fair and honest analysis must begin here. The APAAR ID, as a concept, addresses real, longstanding inefficiencies in India’s educational administration. These benefits are not trivial.
2.1 Administrative & Academic Benefits
One ID consolidates all achievements — degrees, mark sheets, co-curricular records, sports, skill certifications — eliminating the need to manage dozens of physical documents.
NEP 2020 allows students to exit and re-enter education at multiple points. APAAR enables smooth credit transfer without losing previously earned academic progress.
Linking to UDISE+ and scholarship databases means eligible students can be automatically identified and connected to government assistance without manual verification.
A continuous digital academic trail helps identify at-risk students early, enabling timely intervention by educational authorities to prevent school dropout.
Verifiable digital credentials reduce certificate fraud and fake degrees — a significant problem in Indian hiring and admissions. Employers can verify credentials instantly.
Digitised, verifiable academic records align with international credential verification systems, potentially easing study-abroad applications for Indian students.
2.2 Technological Infrastructure
The government has invested in meaningful technical safeguards for the DigiLocker platform that hosts APAAR data. According to the Ministry’s official response:
256-bit SSL encryption in transit and at rest · Federated Repository Architecture · Aadhaar-authenticated document access · ISO 27001-certified data centre · Mobile-based OTP authentication · Timed logout · Regular security audits · Data redundancy systems · User consent-based access model.
These are not insignificant. ISO 27001 certification requires rigorous information security management practices. The federated architecture means raw Aadhaar numbers are masked when data is shared with other government entities — an important design decision.
The APAAR vision is not inherently flawed. The goal of a paperless, portable, verifiable academic credential system is a genuinely good one. The problem lies entirely in implementation, consent architecture, data sharing scope, and legal safeguards — all of which are examined in the sections that follow.
Part II — Critical Technical Analysis of Government’s Security Claims
The official government response dated January 10, 2025 cited nine specific security controls implemented in DigiLocker as justification that the APAAR system is “built with the highest standards for privacy and data security.” As an ASCL Certified Cyber Crime Investigator, BSI Certified Lead Implementer (CLIP) of ISO 27701:2019 & GDPR, CQI/IRCA Certified ISO 27001:2022 Lead Auditor, TISAX Lead Auditor/Implementer (TÜV SÜD), and holder of a Diploma in Indian Cyber Law, with 11+ years of hands-on GRC and information security audit experience across India, Germany, and the USA, the author has examined each control individually — assessing not just whether the control exists, but whether it is adequate, scoped correctly, and sufficient justification for a parent to surrender their minor child’s biometric-linked identity data.
1. Federated Repository Structure for Authentic Documents · 2. Standard Practices · 3. 256-Bit Secure Sockets Layer (SSL) Encryption · 4. Mobile Authentication based Sign Up · 5. Aadhaar Authentication based Issued Document Access · 6. ISO 27001 Certified Data Centre · 7. Data Redundancy · 8. Timed Log Out · 9. Security Audit · User Consent-Based System
Each control is evaluated below against the following professional framework: What does this control actually do? What are its documented limitations? Does it address the specific risks of APAAR — minor’s data, third-party sharing, Aadhaar linkage, and long-term retention?
Control 1 — Federated Repository Structure
What it does well: Reduces the “single point of catastrophic failure” risk. A breach at DigiLocker does not automatically expose all underlying source documents. Masking Aadhaar numbers in data-sharing events is a meaningful privacy design choice.
Critical gap: Federation does not apply to the downstream data-sharing chain. When APAAR data — including Name, DOB, Photograph, Address — is shared with recruitment agencies and external educational stakeholders, it leaves the federated architecture entirely and enters those entities’ own systems, which have no defined security baseline, no mandated certification, and no audit mechanism published under the APAAR framework. The federated architecture protects the vault, not what happens after the vault is opened.
Effective for the DigiLocker platform itself. Does not protect data once it exits the system. Given that sharing with recruitment agencies is explicitly mentioned in the consent form, this control provides no protection for that specific and concerning data flow.
Control 2 — “Standard Practices”
Professional assessment: In information security and GRC practice, a control that is not named, not measurable, not auditable, and not tied to a specific standard is not a control — it is an aspiration. ISO 27001, NIST CSF, SOC 2, PCI DSS, CIS Controls — these are “standard practices” that can be verified. “Standard practices” as a standalone claim is meaningless from a compliance standpoint.
Implication for consent decision: A parent being asked to share their child’s biometric-linked data on the basis of unnamed “standard practices” has been given no verifiable assurance whatsoever.
“Standard practices” is not a security control. It is circular language. No auditor, regulator, or court would accept this as evidence of due diligence. Its inclusion in an official government response to legitimate security concerns is, to put it plainly, not good enough.
Control 3 — 256-Bit SSL Encryption
What it does well: Protects data in transit from network-level interception — e.g., man-in-the-middle attacks on public Wi-Fi. AES-256 is currently considered computationally unbreakable with existing technology.
Critical limitations: (a) Encryption in transit ≠ encryption at rest. SSL/TLS protects the data channel, not the stored data. The government’s claim does not specify the encryption standard applied to data stored on DigiLocker servers — though a separate mention of “data at rest” encryption is implied.
(b) SSL/TLS does not protect against application-layer attacks — SQL injection, broken access control, insecure direct object references, and API vulnerabilities operate above the encryption layer. The OWASP Top 10 threats are entirely unaffected by SSL.
(c) SSL protects the pipe, not the endpoints. If a user’s device is compromised (malware, keylogger), or if the server-side application has vulnerabilities, AES-256 in transit provides no protection.
(d) “SSL” is technically outdated terminology. SSL 3.0 was deprecated in 2015 (RFC 7568). What is actually in use is TLS 1.2 or 1.3. Using “SSL” in an official 2025 government security claim suggests either outdated documentation or superficial security communication — neither is reassuring.
256-bit encryption in transit is a baseline hygiene control, not a differentiating security feature. Every Indian bank, e-commerce site, and government portal uses it. Presenting it as a reason a parent should feel confident sharing their child’s Aadhaar-linked biometric data overstates its significance significantly.
Control 4 — Mobile Authentication Based Sign Up
What it does well: Adds a second factor to the account creation process, reducing automated bulk account creation and basic identity fraud during sign-up.
Critical limitations:
(a) SMS OTP is the weakest form of 2FA. NIST Special Publication 800-63B (2017) explicitly deprecated SMS-based OTP as a primary authentication mechanism due to SIM-swap attacks, SS7 protocol vulnerabilities, and mobile number portability exploitation. India’s cybercrime landscape has a documented and growing problem with SIM-swap fraud.
(b) This control governs sign-up, not ongoing access. Once an account is created, the security of subsequent logins depends on the ongoing authentication mechanism, which is not separately described.
(c) A compromised SIM card = compromised DigiLocker account. For a system holding a child’s Aadhaar-linked identity, this is a material risk. SIM-swap attacks have been used to access government portals in India.
Mobile OTP is acceptable as one layer in a multi-factor stack but is not, by itself, a strong authentication mechanism for a system holding minors’ biometric-linked identity data. The absence of TOTP (Time-based OTP apps), hardware keys, or biometric authentication options for higher assurance levels is a notable gap.
Control 5 — Aadhaar Authentication Based Issued Document Access
What it does well: Aadhaar authentication (eKYC) is a robust identity verification mechanism. Requiring it for sensitive document access raises the bar significantly above simple password-based access. Legitimate and meaningful control.
Critical concerns — and this is a significant one:
(a) It creates a paradox of mandatory Aadhaar dependency. APAAR requires Aadhaar to create. Aadhaar authentication is required to access. This means a child who does not have Aadhaar (or whose Aadhaar is not linked) cannot access their own academic records — despite the Supreme Court’s clear position that Aadhaar cannot be made mandatory for education access.
(b) Aadhaar authentication itself has documented failure modes. Fingerprint authentication failure rates — particularly for manual labourers, elderly individuals, and children — have been widely reported. OTP-based Aadhaar auth reverts to the SMS vulnerabilities discussed above.
(c) The biometric data risk is amplified, not reduced. This control confirms that the system is biometrically tethered. Any compromise of the Aadhaar biometric database has direct consequences for every APAAR holder.
Aadhaar authentication is a meaningful security control, but its use here reinforces the constitutional concern: APAAR effectively mandates Aadhaar for education in substance, even if not in name. From a pure security standpoint, this control is solid. From a rights and inclusion standpoint, it is deeply problematic.
Control 6 — ISO 27001 Certified Data Centre
What it does well: ISO 27001 is a substantive, auditable, internationally recognised standard. Certification requires third-party audit by an accredited body and periodic surveillance audits. It is the most credible control in this list.
Critical limitations that are often misunderstood:
(a) ISO 27001 certifies a management system, not specific technical controls. An organisation can be ISO 27001 certified while still having unpatched servers, weak passwords, or poor access controls — as long as there is a documented process for managing these. Certification does not guarantee the absence of vulnerabilities.
(b) Scope limitation is everything. ISO 27001 certificates have a defined scope. The certificate covers the certified entity’s defined scope — which may not include every system, every process, or every third party involved in APAAR data processing. The certification of the DigiLocker data centre does not extend to UDISE+, ABC, affiliated educational institutions, or recruitment agencies.
(c) Certification status can change. ISO 27001 certificates are valid for three years with annual surveillance audits. There is no public dashboard showing the current, active certification status of the APAAR ecosystem.
(d) The government says “data centre” — not “DigiLocker platform.” This is a subtle but important distinction. The hosting infrastructure may be certified; the application layer (the DigiLocker web and mobile app) may not be within that certification scope.
ISO 27001 certification of the data centre is the strongest single control in this list. However, presenting it as comprehensive security assurance for the entire APAAR ecosystem — including downstream data-sharing partners — is misleading. It covers one node in a multi-node system.
Control 7 — Data Redundancy
What it does well: Ensures data availability and business continuity. Protects against hardware failure, natural disaster, or localised outage.
Critical observation — and this is the most ironic control on the list:
Data redundancy is directly adverse to privacy. The more copies of data exist, the larger the attack surface, and the harder it is to achieve genuine data deletion or withdrawal of consent. When a parent withdraws consent — exercising their DPDP Act right — data redundancy means there are potentially multiple backup copies, replicas, and snapshots of the child’s data across the infrastructure. Ensuring complete deletion across all redundant copies is technically complex and rarely achieved without explicit, auditable deletion procedures.
This control is presented as a security benefit. From a data privacy and right-to-erasure perspective, it is actually a complicating factor.
Data redundancy protects against data loss — which serves the government’s interest in retaining records. It does not protect the individual’s privacy. In fact, it works against the right to erasure. Presenting redundancy as a reason to trust the system with your child’s data conflates institutional data preservation interests with individual privacy interests.
Control 8 — Timed Log Out
What it does well: Protects against session hijacking on shared or public devices. Basic but useful for use cases like a school lab or shared family computer.
Critical assessment:
This is a session management control — among the most basic security hygiene measures in web application security. It is on the OWASP checklist for any authenticated web application. Its inclusion as one of nine primary security justifications for a national system holding minors’ biometric-linked data suggests either that the full security posture is being cherry-picked for public communication, or that the security architecture is not as deep as claimed.
A timed log-out does not address: data breach at the database level, API vulnerabilities, third-party data misuse, insider threats, or any of the risks that actually matter at the scale and sensitivity of APAAR.
Timed logout is a feature every internet banking portal has had since 2005. Its inclusion in a list of security justifications for sharing a child’s Aadhaar-linked biometric identity is, with respect, insufficient. This control does not address any of the material risks of the APAAR system.
Control 9 — Security Audit & User Consent-Based System
What it does well: Regular security audits are essential for identifying and remediating vulnerabilities. This is a meaningful control if conducted rigorously and by qualified independent auditors.
Critical gaps:
(a) No public audit reports are available. Transparency is central to accountability. The government has not published any APAAR-specific security audit findings, penetration test summaries, or remediation records. “We conduct audits” is not the same as “our audits found X and we fixed Y.”
(b) Frequency and scope are undefined. Annual? Quarterly? Does the scope include third-party integrations, UDISE+ APIs, or the ABC platform? Unknown.
(c) Who conducts the audit? CERT-In empanelled auditor? Internal team? Independent Big-4 firm? The credibility of an audit is entirely dependent on the independence and competence of the auditor.
User Consent-Based System — The deepest irony:
This is listed as a security control. But the entire premise of this blog — validated by the Orissa High Court — is that the consent mechanism itself is defective: no opt-out option, contradictory government statements on withdrawal rights, and coercion at school level. Describing a flawed consent architecture as a “security control” reveals a fundamental misunderstanding of what consent means in a data protection context.
Without published audit findings, “security audit” is an unverifiable claim. And presenting a consent mechanism that the Orissa High Court found to be defectively drafted as a “security control” is, at best, a category error.
Overall Technical Assessment
The nine controls, evaluated holistically, present the following picture:
| Control | Type | Adequacy for APAAR’s Risk Profile | Rating |
|---|---|---|---|
| Federated Repository | Architecture | Good design for core platform; no coverage of downstream sharing | PARTIAL |
| Standard Practices | Unspecified | Non-verifiable, non-auditable — not a control | INADEQUATE |
| 256-bit SSL | Encryption (Transit) | Industry baseline; does not address application-layer attacks | BASELINE |
| Mobile OTP Sign-Up | Authentication | Weak 2FA; SMS OTP deprecated by NIST; SIM-swap risk | WEAK |
| Aadhaar Auth for Access | Authentication | Strong control; creates Aadhaar lock-in; constitutional concern | CONDITIONAL |
| ISO 27001 Data Centre | Compliance / ISMS | Meaningful; scope limited to data centre, not full ecosystem | PARTIAL |
| Data Redundancy | Availability | Availability control, not privacy control; complicates erasure | MISREPRESENTED |
| Timed Log Out | Session Management | Basic hygiene; irrelevant to material risks of APAAR | INSUFFICIENT |
| Security Audit | Assurance | Valid if public, independent, and scoped; none of this confirmed | UNVERIFIABLE |
| Consent-Based System | Governance | The consent mechanism is itself judicially challenged as defective | CONTRADICTED |
Of the nine controls cited, one is strong (ISO 27001 — with caveats), two are partial (Federated Architecture, Aadhaar Authentication), two are baseline industry hygiene (SSL, Mobile OTP), one is technically misrepresented as a privacy control (Data Redundancy), one is unverifiable (Security Audit), one is legally non-existent (Standard Practices), one is irrelevant to material risks (Timed Logout), and one is itself the subject of a High Court order for defective design (Consent System).
The complete absence of any controls governing: third-party data processor obligations, data retention limits, cross-entity breach notification, recruitment agency data handling standards, deletion procedures, or children’s data-specific safeguards — means the government’s security claim, taken as a whole, does not constitute adequate justification for a parent to share their minor child’s Aadhaar-linked biometric identity data with a system that distributes that data to unregulated third parties.
This is not a judgement that the system is insecure. It is a professional assessment that the security claims made are insufficient, incomplete, and in some cases misleading as a basis for an informed consent decision.
The scorecard below visualises the adequacy rating of each control at a glance:
Figure 2 — Security Controls Scorecard: Bar length represents adequacy for APAAR’s risk profile. 7 of 9 controls fall below the adequate threshold for a system holding minors’ biometric-linked identity data.
Part III — Voluntary vs. Mandatory: The Central Contradiction
This is the question that prompted this entire blog. The government’s position and the ground reality are in direct, documented conflict.
3.1 The Official Position
“Creating an APAAR ID is optional, but the Department of School Education encourages every student to obtain their unique ID to consolidate all achievements and learnings in one place.”
— Official response to author’s queries, January 10, 2025
3.2 The Ground Reality
Schools across multiple states have been directing parents to sign consent forms as a compulsory activity, failing to communicate that refusal is an option. The Central Board of Secondary Education (CBSE) has reportedly pushed for 100% APAAR enrolment — a quantitative target that structurally creates institutional pressure to coerce consent.
When a government ministry sets a target of 100% enrolment, it creates an implicit mandate. Schools and teachers face administrative accountability for “gaps” in enrolment. This top-down pressure inevitably filters down to parents as coercion, regardless of what the official policy document says.
3.3 The Consent Form’s Design Flaw
The official APAAR consent form — used in schools nationwide — contained a fundamental design flaw that the Orissa High Court later flagged explicitly (see Section 7). The form provided no option to refuse consent. Parents were presented with a form to sign, with no checkbox or field to indicate disagreement.
“If it is intended to be a voluntary act, appropriate provisions clearly specifying such fact ought to have been incorporated in the form by providing option to the parents to refuse to submit their consent or to opt out of it entirely.”
— Orissa High Court, WPC No. 8285 of 2025 (Rohit Anand Das v. State of Odisha)3.4 The Free-and-Fair-Consent Test
| Principle of Valid Consent | APAAR Implementation Status |
|---|---|
| Freely given — No coercion or undue influence | FAILED — Schools presenting it as mandatory; 100% enrolment targets create institutional pressure |
| Specific — Consent for defined purposes | PARTIAL — Form mentions “educational activities” but shares with “recruitment agencies” — a non-educational purpose |
| Informed — Full knowledge of consequences | FAILED — Most parents not informed of data sharing scope, third-party access, or long-term implications |
| Unambiguous — Clear affirmative action | FAILED — No opt-out option on original form; Orissa HC directed this to be rectified |
| Withdrawable — Right to withdraw at any time | CONTRADICTED — Govt. response says “consent cannot be withdrawn” but form says it can; DPDP Act mandates withdrawal rights |
Part IV — Legal Analysis
Three distinct bodies of law converge on the APAAR ID — Indian Contract Law, the DPDP Act 2023, and Constitutional rights established through the Puttaswamy judgments. The mind map below shows how each framework applies:
Figure 3 — Legal Framework Mind Map: Three independent bodies of law each independently challenge APAAR’s consent architecture
4.1 The Indian Contract Act, 1872
Consent, in law, is not simply a signature on a form. The Indian Contract Act defines and constrains what constitutes valid consent — and APAAR’s consent architecture fails on multiple counts.
4.2 Digital Personal Data Protection Act, 2023
The DPDP Act 2023, now partially in force, establishes India’s modern data protection framework. Several of its provisions are directly relevant to APAAR.
The consent form acknowledges: “any personal data already been processed shall remain unaffected on such withdrawal.” This is legally defensible for processing that occurred while consent was valid. However, it means that once your child’s photograph, Aadhaar-linked identity, and academic records have been shared with third parties including recruitment agencies — that data cannot be recalled. The right to withdraw consent does not undo past processing. This makes the initial consent decision of extraordinary, permanent consequence.
4.3 Constitutional Rights — K.S. Puttaswamy Judgment
“Coercion disguised as choice is not consent. The government’s claim that APAAR is ‘voluntary’ is misleading.”
— Indian Express, April 2025The Supreme Court’s landmark 2017 judgment in K.S. Puttaswamy v. Union of India established privacy as a fundamental right under Article 21 of the Constitution. The 2019 Aadhaar judgment further held that Aadhaar cannot be made mandatory for access to basic education.
Since APAAR requires Aadhaar linkage as a prerequisite, and schools are effectively making APAAR mandatory, the implementation arguably violates both the constitutional privacy framework and the explicit direction of the Supreme Court on Aadhaar-education linkage.
Part V — Cybersecurity & AI/Deepfake Risks
This section addresses risks that are not hypothetical. They are documented, increasing, and particularly acute when the victim is a minor whose data is collected, stored, and shared before they are old enough to consent themselves.
5.1 The Data That Is Being Collected
The consent form is explicit. Personal Identifiable Information (PII) being collected includes:
Name · Address · Age · Date of Birth · Gender · Photograph — and this may be shared with: UDISE+ database · Scholarship management bodies · Academic record keepers · Other educational institutions · Recruitment Agencies.
5.2 Deepfake Risk — The Most Underestimated Threat
The diagram below shows how a single data breach — at any node in the APAAR ecosystem — cascades through successive harm stages, with the minor child as the ultimate victim at every path:
Figure 4 — Risk Cascade: Multiple breach pathways converge on the child. The irreversibility of the harm is the critical concern, not just its probability.
The photograph of a minor, linked to verified identity data (name, DOB, Aadhaar), creates a uniquely dangerous dataset in the current AI landscape.
Unlike deepfakes created from casual social media images, a photograph linked to verified government identity can be used to create highly credible, legally difficult-to-challenge synthetic media of a minor.
A photo taken when the child is 8 years old may be used for harm when they are 18. The data, once in a system, persists. The child’s future — employment, relationships, safety — can be affected by data given years earlier without their knowledge.
DOB + Name + Address + Photo + Aadhaar number is the complete dataset needed for identity theft, SIM swap fraud, financial fraud, and targeted social engineering attacks.
Sharing child data with “recruitment agencies” — private entities with no defined regulatory oversight under APAAR — creates an uncontrolled data exit point. One breach at a small recruitment agency cascades to millions of children.
5.3 The Centralised Database Risk
Centralised databases are high-value targets. The larger and more complete the database, the more attractive it is to state-sponsored threat actors, ransomware groups, and data brokers. A database of 33+ crore students — each with verified biometric-linked identity — is among the most valuable data assets imaginable from an adversarial standpoint.
While DigiLocker holds ISO 27001 certification, the APAAR system involves multiple downstream data processors — UDISE+, ABC, educational institutions, scholarship bodies, and recruitment agencies. ISO 27001 certification of the core platform does not extend to every entity in the data-sharing chain. Each node is a potential breach point.
5.4 What Happens When Data Escapes the System?
There is no published breach notification protocol specific to APAAR that parents have been informed of. Under the DPDP Act, a Data Fiduciary is required to notify the Data Protection Board and affected individuals of personal data breaches. However:
→ The DPDP Rules specify notification to the DPB, but the threshold and timeline for notifying individual Data Principals (parents and children) remains an open regulatory question.
→ There is no mechanism by which a parent can discover whether their child’s APAAR data has been accessed, shared, or compromised.
→ The internet freedom advocacy group Internet Freedom Foundation (IFF) has specifically raised alarms about the absence of a clear oversight mechanism.
Part VI — Government’s Answers Examined
The official government response dated January 10, 2025 was provided in reply to questions raised in January 2025. Let us analyse each point with professional scrutiny.
Part VII — Edge Cases Nobody Is Talking About
These are real-world scenarios raised in the original set of questions to the government. They expose systemic gaps in the APAAR framework’s design.
Case A: Death of a Parent & Remarriage
Consider: A child loses one parent. The surviving parent later remarries. In an inter-caste or inter-religion marriage, the child may acquire a new surname. The questions this raises:
1. Who bears the cost and effort of updating the APAAR ID — the APAAR team, the school, or the parent?
2. What is the official process for name change on the APAAR ID after a court-recognised surname change?
3. If the deceased parent’s name is embedded in the ID-generation record, how is the father/mother name field updated?
4. Is there a defined SLA (Service Level Agreement) for such updates? What happens to the child’s academic continuity during the update process?
5. No official answer has been provided to any of these questions.
Case B: Single Parents & Non-Traditional Guardianship
The consent form is titled “Consent by Father/Mother/Legal Guardian.” What happens in cases of:
Is one parent’s consent sufficient? What if both parents are required by the system architecture but only one is alive or available?
Children under state care, NGO custody, or with court-appointed guardians — what documentation is required, and who verifies guardian authority?
If parents are separated and one parent consents to APAAR without the other’s knowledge, is this valid? Can the non-consenting parent challenge it?
Case C: The Consenting Parent’s Own Privacy
To generate an APAAR ID for a minor, the parent must provide their own Aadhaar for authentication. This means the APAAR system also processes and authenticates the parent’s biometric identity. The consent form does not explicitly address what happens to the parent’s Aadhaar authentication data after the verification event.
Under DPDP Act, the parent is also a Data Principal. The processing of their Aadhaar authentication record requires lawful basis. The consent form for the child’s APAAR ID does not constitute valid consent for processing the parent’s personal data. This is a gap in the consent architecture that deserves regulatory attention.
Part VIII — What the Courts Have Said
This ruling validates every concern raised in this blog about the original consent form design. It establishes a judicial precedent that parents have a right to a genuine, meaningful opt-out — not merely a theoretical withdrawal right after the fact. This judgment should be cited by any parent or advocate challenging school-level coercion.
Part IX — Risk Matrix Summary
| Risk Domain | Risk Description | Likelihood | Impact | Rating |
|---|---|---|---|---|
| Consent Coercion | Schools treating voluntary APAAR as mandatory; parents uninformed of opt-out rights | High | High | CRITICAL |
| Data Breach — Central DB | Centralised Aadhaar-linked database of 33+ crore students as high-value target | Medium | Catastrophic | CRITICAL |
| Deepfake / AI Misuse | Verified photo + identity data enabling credible synthetic media targeting minors | Medium | Severe | CRITICAL |
| Recruitment Agency Data Misuse | PII shared with private entities; no defined limitation on further processing | Medium | High | HIGH |
| Identity Theft | Complete PII dataset (DOB + address + photo + Aadhaar linkage) enabling fraud | Medium | High | HIGH |
| Third-Party Chain Breach | Data shared downstream to entities outside DigiLocker’s ISO 27001 coverage | High | High | HIGH |
| DPDP Act Non-Compliance | Withdrawal right denial; children’s data processing without adequate safeguards | High | Medium | HIGH |
| Surveillance Creep | Academic + behavioural data accumulation enabling student profiling over lifetime | Low-Medium | High | MEDIUM |
| Name/Status Change Failure | No defined process for post-remarriage, death, or legal name changes | Medium | Medium | MEDIUM |
| Digital Divide Exclusion | Rural/marginalised students disadvantaged if APAAR becomes de facto mandatory | High | Medium | MEDIUM |
Part X — What Should You Do as a Parent?
This blog does not advocate blanket refusal of APAAR. It advocates informed, free, and genuinely voluntary consent — which is your legal right.
If You Choose to Consent:
1. Read the consent form in full. Ask the school to explain every clause.
2. Ask specifically: Which third-party entities will receive my child’s data? What are their data retention policies?
3. Keep a copy of the signed consent form for your records.
4. Note the date of consent. Under DPDP Act, you may withdraw consent later — despite what the government’s Jan 10 response says.
5. Monitor your child’s DigiLocker account periodically for unauthorised access or unexpected documents.
If You Choose to Refuse or Defer:
1. APAAR is officially voluntary. You have the right to refuse.
2. Cite the Orissa High Court judgment (WPC No. 8285/2025) if the school insists it is mandatory.
3. Cite K.S. Puttaswamy (2019): Aadhaar cannot be mandatory for basic education access.
4. Submit a written refusal to the school Principal, keep a copy. This creates a documentary trail.
5. Your child cannot legally be denied admission, grades, scholarships, or educational benefits solely on the basis of not having an APAAR ID (voluntary scheme).
6. If a school denies any service or benefit, this is actionable — file a complaint with the State Education Department and the school’s governing board.
The CBSE “REFUSED” Protocol — What CBSE Itself Has Officially Established
This is the most important practical development in the APAAR story — and one that most parents and schools are entirely unaware of. CBSE has, through its own official circulars, created a documented, codified mechanism to handle parental refusal. Your memory is correct — and the documentation is on CBSE’s own domain.
January 24, 2025 — CBSE issued its first implementation circular positioning APAAR as the primary identifier for Class X and XII board exam registrations (List of Candidates / LOC). Reference: Circular_Implementation_APAAR_ID_24012025. This circular effectively linked board exam eligibility to APAAR — creating the very institutional pressure this blog has documented.
August 27, 2025 — CBSE’s LOC circular (Ref: CBSE/LOC/X-XII/2025-2026) explicitly stated that schools would only be able to fill the LOC for candidates who had their APAAR IDs — with validation at submission. This was the high-water mark of institutional coercion: no APAAR = no board exam registration.
September 9–11, 2025 — Under documented pressure from schools, parents, and advocacy groups including the Internet Freedom Foundation (IFF), CBSE reversed course. Circular Ref: CBSE/Co-Ord/APAAR ID/2025-2026 introduced partial relaxation with two formal codes schools must use in the LOC.
In case of APAAR IDs not being generated owing to other reasons, entry against APAAR be made as ‘NOGEN’.”
Earlier implementation circular: cbse.gov.in — Circular_Implementation_APAAR_ID_24012025.pdf
LOC circular (Aug 27): cbse.gov.in — LOC_2526_27082025.pdf
This is a landmark development that deserves to be understood clearly by every parent. Let us unpack exactly what it means — and what it does not mean.
What “REFUSED” Means for Your Child — The Good News
1. Parental refusal is formally recognised by CBSE itself. A school that tells you APAAR is mandatory is contradicting CBSE’s own circular — there is now a designated system code (“REFUSED”) that only exists because refusal is a legitimate, documented outcome.
2. Your child’s board exam registration cannot be blocked solely due to APAAR refusal. The LOC will be submitted with “REFUSED” — the child remains eligible for examination registration.
3. The school must retain your written denial of consent as a documentary record. This means your written refusal is a formal document in the school’s records — not an informal verbal communication that can be ignored.
4. This applies to Class IX, X, XI, and XII registrations under the 2025-26 cycle, with the expectation of full APAAR coverage by 2026-27.
What “REFUSED” Does Not Mean — The Critical Caveat
1. This is explicitly a temporary relaxation, not a permanent guarantee. CBSE’s circular states these relaxations apply only for the current academic cycle. The board has simultaneously reiterated that “schools must continue working toward full APAAR coverage.” The institutional pressure to achieve 100% has not been withdrawn — it has only been deferred.
2. No “no-adverse-consequence” guarantee has been issued. The circular establishes the procedural code but does not guarantee that a child marked “REFUSED” will face no disadvantage in future scholarship matching, academic transfers, or higher education access where APAAR may be required.
3. The “NOGEN” code conflates two entirely different situations — parents who cannot generate an ID due to technical issues (Aadhaar mismatch, documentation gap) and parents who choose not to consent. Combining these into one category obscures the true scale of parental refusal from aggregate reporting, making it harder to assess how many parents are actually exercising their rights.
4. The overseas school exemption (CBSE schools outside India are exempt from APAAR due to local regulations) creates an ironic two-tier system: Indian students abroad are not subject to this scheme, but students within India — whose data is arguably more sensitive in the domestic context — have no equivalent exemption.
“CBSE’s new circular acknowledges the reality that parental consent can be refused. But with no clear opt-out guarantees and no privacy safeguards, it remains a partial fix.”
— Internet Freedom Foundation (IFF), September 2025The Three-Document Arsenal — What Every Refusing Parent Should Carry
If you are refusing APAAR consent and your school pushes back, the following three official documents — all sourced directly from government or judicial authorities — together constitute an unassailable legal position:
| Document | Authority | What It Establishes | Source |
|---|---|---|---|
| CBSE Circular CBSE/Co-Ord/APAAR ID/2025-2026 |
CBSE (Central Board of Secondary Education) | Formal “REFUSED” code for parental non-consent in LOC. School must accept written refusal and cannot block exam registration. | Official PDF ↗ |
| Orissa HC Judgment WPC No. 8285/2025 |
Orissa High Court | Consent form must include opt-out option. Right to refuse consent at outset cannot be substituted by a post-hoc withdrawal clause. | Rohit Anand Das v. State of Odisha, December 2025 |
| K.S. Puttaswamy v. Union of India (2019) | Supreme Court of India | Aadhaar cannot be made mandatory for access to basic education. APAAR’s Aadhaar prerequisite cannot be an indirect mandate for education access. | 2019 (1) SCC 1 |
When submitting your refusal, a brief written note to the school Principal should state:
“I, [Parent Name], parent/guardian of [Child Name] (Class __, Roll No. __), hereby decline to provide consent for generation of an APAAR ID for my child. This decision is exercised in accordance with the voluntary nature of the APAAR scheme as confirmed by the Department of School Education, and consistent with the CBSE circular CBSE/Co-Ord/APAAR ID/2025-2026, which provides for a ‘REFUSED’ entry in the List of Candidates for students whose parents do not consent. I request that a copy of this refusal be retained in the school’s records as required by the said circular.”
Keep a signed and dated copy for yourself. Request an acknowledgement from the school.
The Question You Were Asked: What If Your Child Is the Only One Without an APAAR ID?
This is a legitimate social-pressure concern. Here is the honest answer: in a system where 33+ crore students are enrolled, there may be practical disadvantages in the future if certain academic processes become APAAR-dependent. This is the nature of network-effect digital systems. However:
The risk of social or administrative pressure is real. The risk of data harm from a system with inadequate safeguards is also real. Consent obtained under fear of exclusion is not free consent — under Indian Contract Act Section 15. Until the government: (a) publishes a clear data retention and deletion policy; (b) defines and limits the scope of third-party sharing; (c) ensures the DPDP Act’s children’s data provisions are fully operationalised for APAAR; and (d) provides a legally clear withdrawal mechanism — a cautious, informed parent has every legal and ethical right to withhold consent.
The Informed Choice Is the Only Choice That Counts
The APAAR ID is a well-intentioned policy instrument in service of a genuinely transformative educational vision. A paperless, portable, verifiable academic credential system is the right direction for a digital India.
But good intentions do not override legal rights. A voluntary scheme that functions as a de facto mandatory one is not voluntary. A consent form with no opt-out option does not produce legal consent. A government response that contradicts the statutory right to withdraw consent is simply incorrect in law.
There are signs of institutional acknowledgement. CBSE’s September 2025 circular introducing the “REFUSED” code in the List of Candidates is a meaningful concession — it is the first time a central educational authority has formally codified the right of parents to say no, embedded it in the examination registration system, and required schools to retain documentary evidence of that refusal. That is progress, and it deserves recognition.
But it is partial progress. The Orissa High Court has spoken on the consent form. The K.S. Puttaswamy judgment has spoken on Aadhaar and education. The DPDP Act has spoken on children’s data and withdrawal rights. What remains is for the Ministry of Education to align its full implementation — its consent architecture, its data-sharing scope, its third-party oversight, and its official communications — with the law.
Until that alignment is complete, every Indian parent deserves to know: you have a right to say no, CBSE has formally acknowledged that right, and no court in India will tell you otherwise.
Neelabh Rai is an ASCL Certified Cyber Crime Investigator (CCCI) and seasoned GRC professional with 11+ years of deep-rooted experience in information security audits, cybercrime investigation, and regulatory compliance. He has led 150+ internal audits across enabling and delivery functions and has driven successful ISO implementations and certifications across India, Germany, and the USA — including for German automobile companies, healthcare sector clients, and financial institutions.
Certifications & Qualifications: ASCL Certified Cyber Crime Investigator (CCCI) · BSI Certified Lead Implementer (CLIP) — ISO 27701:2019 & GDPR · CQI/IRCA Certified ISO 27001:2022 Lead Auditor · ISO 42001:2023 Lead Implementer (AI Risk Management) · IRCA Certified ISO 22301:2012 Business Continuity Lead Auditor · TISAX Lead Auditor/Implementer (TÜV SÜD certified) · Diploma in Indian Cyber Law, Government Law College Mumbai · B.Tech — Information Technology, AKGEC Ghaziabad (UPTU).
Recognition & Research: Fellow of IETE (Institution of Electronics and Telecommunication Engineers) and current Executive Committee Member, IETE Noida Chapter. International award recipient — Cyber Security Ace from the International Cyber Threat Task Force (ICTTF) for outstanding contributions to SCADA security. Author of published and indexed research papers on typosquatting, cyber terrorism, and digital forensics, cited by the University of Leicester (UK) and Calgary Law Enforcement (Canada). Invited speaker at international conferences in Singapore, Kerala, and Kanpur.
CYBER COPS India: Founder of cybercops.in — an independent platform dedicated to helping Indian digital citizens stay safer online through research, legal analysis, and cybersecurity awareness. This blog is an extension of that mission.
This blog represents the author’s independent analysis in a personal capacity. It is not legal advice and does not represent the views of any employer or affiliated organisation. Parents with specific legal concerns should consult a qualified cyber law or constitutional law advocate. The queries to the government cited herein were submitted on January 4, 2025, and the official response was received on January 10, 2025.
