apaar-id
| |

APAAR ID: One Nation, One Student ID – A Parent’s Complete Guide

CYBER COPS INDIA  ·  cybercops.in  ·  DIGITAL RIGHTS & CYBER LAW RESEARCH
INVESTIGATIVE ANALYSIS

APAAR ID:
One Nation, One Student ID
— A Parent’s Complete Guide

Every benefit. Every legal concern. Every unanswered question the government refuses to address directly — from the lens of privacy law, cybersecurity, and the Indian Contract Act.

PUBLISHED: April 24, 2026  ·  UPDATED: April 24, 2026  ·  READ TIME: ~18 minutes  ·  CATEGORY: Data Privacy / Cyber Law
NR
Neelabh Rai — ASCL Certified Cyber Crime Investigator (CCCI)  ·  BSI Certified Lead Implementer — ISO 27701:2019 & GDPR  ·  ISO 42001:2023 Lead Implementer  ·  ISO 27001:2022 Lead Auditor (CQI/IRCA)  ·  ISO 22301 Lead Auditor (IRCA)  ·  TISAX Lead Auditor/Implementer (TÜV SÜD)  ·  Diploma in Indian Cyber Law (Govt. Law College, Mumbai)  ·  B.Tech — Information Technology (AKGEC, UPTU)  ·  11+ Years in GRC
Founder, CYBER COPS India  ·  Fellow, IETE  ·  EC Member, IETE Noida  ·  cybercops.in  ·  neelabhrai.com

The Government of India says APAAR ID is voluntary. Schools tell parents it is mandatory. The official reply from government authorities confirms “consent cannot be withdrawn.” Yet the consent form itself says it can be. This blog is not a scare piece. It is a structured, evidence-based analysis — benefits first — written so that every Indian parent can make a truly informed, free, and uncoerced decision about their child’s digital identity.

SECTION 01

What Is the APAAR ID?

The Automated Permanent Academic Account Registry (APAAR) is a unique 12-digit lifelong academic identification number assigned to every student enrolled in an Indian school or college. Conceptualised under the National Education Policy (NEP) 2020 and launched by the Ministry of Education in September 2023, it operates under the banner of “One Nation, One Student ID.”

The APAAR ID is structurally linked to two other government digital systems:

🆔
Aadhaar

The APAAR ID is generated using the student’s Aadhaar number. For students under 18, parental Aadhaar and consent are required. This linkage is the root of most legal controversies.

📁
DigiLocker

Once generated, the APAAR ID is stored in and accessed through the student’s DigiLocker account. All academic documents — marksheets, degrees, certificates — are digitally stored here.

🏦
Academic Bank of Credits (ABC)

The APAAR ID is the primary key for the ABC system, which stores earned academic credits and allows credit transfer between institutions under NEP 2020’s flexible education framework.

The data collected under APAAR includes: name, date of birth, gender, photograph, contact details, Aadhaar number, authentication records, academic records, co-curricular achievements, attendance data, and any skill or sports certifications.

📊 Scale of Deployment

As of November 2025, over 33.85 crore students had created APAAR IDs across India. The Ministry of Education has set a target of 100% integration of all academic records by 2026–27.

The diagram below maps the full APAAR ecosystem — from the student at the centre to every system and third party their data flows through:

APAAR Ecosystem Map Structural mind map showing APAAR ID at the centre connected to Aadhaar/UIDAI, DigiLocker, ABC, UDISE+, Educational Institutions, Scholarship Bodies, and Recruitment Agencies APAAR ID 12-digit lifelong student identity Ministry of Education NEP 2020 · Policy owner Aadhaar / UIDAI Mandatory for ID creation DigiLocker ISO 27001 · Document storage UDISE+ Database Student enrolment records Academic Bank (ABC) Credits · Transcripts Educational Institutions Schools · Colleges Universities Scholarship Bodies Govt. benefits · Awards Recruitment Agencies ⚠ Private entities · No defined oversight Govt / regulated entity High-risk data flow Institutional access

Figure 1 — APAAR Ecosystem: Data flows from student identity outward to 7 connected entities, including unregulated private recruitment agencies (bottom, red)


SECTION 02

Part I — The Genuine Benefits

A fair and honest analysis must begin here. The APAAR ID, as a concept, addresses real, longstanding inefficiencies in India’s educational administration. These benefits are not trivial.

2.1 Administrative & Academic Benefits

📋
Unified Academic Portfolio

One ID consolidates all achievements — degrees, mark sheets, co-curricular records, sports, skill certifications — eliminating the need to manage dozens of physical documents.

🔄
Seamless Institutional Transfers

NEP 2020 allows students to exit and re-enter education at multiple points. APAAR enables smooth credit transfer without losing previously earned academic progress.

🎓
Scholarships & Benefits Access

Linking to UDISE+ and scholarship databases means eligible students can be automatically identified and connected to government assistance without manual verification.

📉
Reduced Dropout Risk

A continuous digital academic trail helps identify at-risk students early, enabling timely intervention by educational authorities to prevent school dropout.

🔒
Anti-Fraud Mechanism

Verifiable digital credentials reduce certificate fraud and fake degrees — a significant problem in Indian hiring and admissions. Employers can verify credentials instantly.

🌍
Global Credential Recognition

Digitised, verifiable academic records align with international credential verification systems, potentially easing study-abroad applications for Indian students.

2.2 Technological Infrastructure

The government has invested in meaningful technical safeguards for the DigiLocker platform that hosts APAAR data. According to the Ministry’s official response:

✅ Stated Security Measures (DigiLocker)

256-bit SSL encryption in transit and at rest · Federated Repository Architecture · Aadhaar-authenticated document access · ISO 27001-certified data centre · Mobile-based OTP authentication · Timed logout · Regular security audits · Data redundancy systems · User consent-based access model.

These are not insignificant. ISO 27001 certification requires rigorous information security management practices. The federated architecture means raw Aadhaar numbers are masked when data is shared with other government entities — an important design decision.

💡 The Author’s Position on Benefits

The APAAR vision is not inherently flawed. The goal of a paperless, portable, verifiable academic credential system is a genuinely good one. The problem lies entirely in implementation, consent architecture, data sharing scope, and legal safeguards — all of which are examined in the sections that follow.


SECTION 03

Part II — Critical Technical Analysis of Government’s Security Claims

The official government response dated January 10, 2025 cited nine specific security controls implemented in DigiLocker as justification that the APAAR system is “built with the highest standards for privacy and data security.” As an ASCL Certified Cyber Crime Investigator, BSI Certified Lead Implementer (CLIP) of ISO 27701:2019 & GDPR, CQI/IRCA Certified ISO 27001:2022 Lead Auditor, TISAX Lead Auditor/Implementer (TÜV SÜD), and holder of a Diploma in Indian Cyber Law, with 11+ years of hands-on GRC and information security audit experience across India, Germany, and the USA, the author has examined each control individually — assessing not just whether the control exists, but whether it is adequate, scoped correctly, and sufficient justification for a parent to surrender their minor child’s biometric-linked identity data.

📋 The Nine Controls Claimed by the Government

1. Federated Repository Structure for Authentic Documents  ·  2. Standard Practices  ·  3. 256-Bit Secure Sockets Layer (SSL) Encryption  ·  4. Mobile Authentication based Sign Up  ·  5. Aadhaar Authentication based Issued Document Access  ·  6. ISO 27001 Certified Data Centre  ·  7. Data Redundancy  ·  8. Timed Log Out  ·  9. Security Audit  ·  User Consent-Based System

Each control is evaluated below against the following professional framework: What does this control actually do? What are its documented limitations? Does it address the specific risks of APAAR — minor’s data, third-party sharing, Aadhaar linkage, and long-term retention?

Control 1 — Federated Repository Structure

GOVERNMENT CLAIM
“Federated Repository Structure for Authentic Documents”
What it means: Rather than a single monolithic database holding all data, the federated model distributes records — DigiLocker stores references and links to documents held at source repositories (e.g., CBSE, universities, Aadhaar). Raw Aadhaar numbers are reportedly masked when shared with other government entities.

What it does well: Reduces the “single point of catastrophic failure” risk. A breach at DigiLocker does not automatically expose all underlying source documents. Masking Aadhaar numbers in data-sharing events is a meaningful privacy design choice.

Critical gap: Federation does not apply to the downstream data-sharing chain. When APAAR data — including Name, DOB, Photograph, Address — is shared with recruitment agencies and external educational stakeholders, it leaves the federated architecture entirely and enters those entities’ own systems, which have no defined security baseline, no mandated certification, and no audit mechanism published under the APAAR framework. The federated architecture protects the vault, not what happens after the vault is opened.
⚠️ Verdict: PARTIALLY ADEQUATE — Scoped Too Narrowly

Effective for the DigiLocker platform itself. Does not protect data once it exits the system. Given that sharing with recruitment agencies is explicitly mentioned in the consent form, this control provides no protection for that specific and concerning data flow.

Control 2 — “Standard Practices”

GOVERNMENT CLAIM
“Standard Practices”
What it means: This is the least specific control in the entire list. “Standard practices” is not a named framework, not a certifiable standard, not a verifiable control. It is a phrase.

Professional assessment: In information security and GRC practice, a control that is not named, not measurable, not auditable, and not tied to a specific standard is not a control — it is an aspiration. ISO 27001, NIST CSF, SOC 2, PCI DSS, CIS Controls — these are “standard practices” that can be verified. “Standard practices” as a standalone claim is meaningless from a compliance standpoint.

Implication for consent decision: A parent being asked to share their child’s biometric-linked data on the basis of unnamed “standard practices” has been given no verifiable assurance whatsoever.
🔴 Verdict: INADEQUATE — Unverifiable, Non-Specific

“Standard practices” is not a security control. It is circular language. No auditor, regulator, or court would accept this as evidence of due diligence. Its inclusion in an official government response to legitimate security concerns is, to put it plainly, not good enough.

Control 3 — 256-Bit SSL Encryption

GOVERNMENT CLAIM
“256 Bit Secure Sockets Layer (SSL) Encryption”
What it means: Data transmitted between a user’s browser/device and the DigiLocker servers is encrypted using AES-256 within a TLS (Transport Layer Security) session. This is the same encryption used by banks and most major web services.

What it does well: Protects data in transit from network-level interception — e.g., man-in-the-middle attacks on public Wi-Fi. AES-256 is currently considered computationally unbreakable with existing technology.

Critical limitations: (a) Encryption in transit ≠ encryption at rest. SSL/TLS protects the data channel, not the stored data. The government’s claim does not specify the encryption standard applied to data stored on DigiLocker servers — though a separate mention of “data at rest” encryption is implied.
(b) SSL/TLS does not protect against application-layer attacks — SQL injection, broken access control, insecure direct object references, and API vulnerabilities operate above the encryption layer. The OWASP Top 10 threats are entirely unaffected by SSL.
(c) SSL protects the pipe, not the endpoints. If a user’s device is compromised (malware, keylogger), or if the server-side application has vulnerabilities, AES-256 in transit provides no protection.
(d) “SSL” is technically outdated terminology. SSL 3.0 was deprecated in 2015 (RFC 7568). What is actually in use is TLS 1.2 or 1.3. Using “SSL” in an official 2025 government security claim suggests either outdated documentation or superficial security communication — neither is reassuring.
⚠️ Verdict: BASELINE — Necessary but Far from Sufficient

256-bit encryption in transit is a baseline hygiene control, not a differentiating security feature. Every Indian bank, e-commerce site, and government portal uses it. Presenting it as a reason a parent should feel confident sharing their child’s Aadhaar-linked biometric data overstates its significance significantly.

Control 4 — Mobile Authentication Based Sign Up

GOVERNMENT CLAIM
“Mobile Authentication based Sign Up”
What it means: Account creation on DigiLocker requires mobile OTP (One-Time Password) verification — a form of SMS-based two-factor authentication (2FA) for the registration process.

What it does well: Adds a second factor to the account creation process, reducing automated bulk account creation and basic identity fraud during sign-up.

Critical limitations:
(a) SMS OTP is the weakest form of 2FA. NIST Special Publication 800-63B (2017) explicitly deprecated SMS-based OTP as a primary authentication mechanism due to SIM-swap attacks, SS7 protocol vulnerabilities, and mobile number portability exploitation. India’s cybercrime landscape has a documented and growing problem with SIM-swap fraud.
(b) This control governs sign-up, not ongoing access. Once an account is created, the security of subsequent logins depends on the ongoing authentication mechanism, which is not separately described.
(c) A compromised SIM card = compromised DigiLocker account. For a system holding a child’s Aadhaar-linked identity, this is a material risk. SIM-swap attacks have been used to access government portals in India.
⚠️ Verdict: BASELINE WITH KNOWN VULNERABILITIES

Mobile OTP is acceptable as one layer in a multi-factor stack but is not, by itself, a strong authentication mechanism for a system holding minors’ biometric-linked identity data. The absence of TOTP (Time-based OTP apps), hardware keys, or biometric authentication options for higher assurance levels is a notable gap.

Control 5 — Aadhaar Authentication Based Issued Document Access

GOVERNMENT CLAIM
“Aadhaar Authentication based Issued Document Access”
What it means: To access certain sensitive documents (including APAAR-linked records), Aadhaar-based biometric or OTP authentication is required. This ensures that document access is tied to verified identity.

What it does well: Aadhaar authentication (eKYC) is a robust identity verification mechanism. Requiring it for sensitive document access raises the bar significantly above simple password-based access. Legitimate and meaningful control.

Critical concerns — and this is a significant one:
(a) It creates a paradox of mandatory Aadhaar dependency. APAAR requires Aadhaar to create. Aadhaar authentication is required to access. This means a child who does not have Aadhaar (or whose Aadhaar is not linked) cannot access their own academic records — despite the Supreme Court’s clear position that Aadhaar cannot be made mandatory for education access.
(b) Aadhaar authentication itself has documented failure modes. Fingerprint authentication failure rates — particularly for manual labourers, elderly individuals, and children — have been widely reported. OTP-based Aadhaar auth reverts to the SMS vulnerabilities discussed above.
(c) The biometric data risk is amplified, not reduced. This control confirms that the system is biometrically tethered. Any compromise of the Aadhaar biometric database has direct consequences for every APAAR holder.
⚠️ Verdict: STRONG CONTROL, BUT CREATES AADHAAR LOCK-IN

Aadhaar authentication is a meaningful security control, but its use here reinforces the constitutional concern: APAAR effectively mandates Aadhaar for education in substance, even if not in name. From a pure security standpoint, this control is solid. From a rights and inclusion standpoint, it is deeply problematic.

Control 6 — ISO 27001 Certified Data Centre

GOVERNMENT CLAIM
“ISO 27001 certified Data Centre”
What it means: The data centre hosting DigiLocker infrastructure holds ISO 27001 certification — the international standard for Information Security Management Systems (ISMS). This requires documented risk management, access controls, incident response procedures, business continuity planning, and regular audits.

What it does well: ISO 27001 is a substantive, auditable, internationally recognised standard. Certification requires third-party audit by an accredited body and periodic surveillance audits. It is the most credible control in this list.

Critical limitations that are often misunderstood:
(a) ISO 27001 certifies a management system, not specific technical controls. An organisation can be ISO 27001 certified while still having unpatched servers, weak passwords, or poor access controls — as long as there is a documented process for managing these. Certification does not guarantee the absence of vulnerabilities.
(b) Scope limitation is everything. ISO 27001 certificates have a defined scope. The certificate covers the certified entity’s defined scope — which may not include every system, every process, or every third party involved in APAAR data processing. The certification of the DigiLocker data centre does not extend to UDISE+, ABC, affiliated educational institutions, or recruitment agencies.
(c) Certification status can change. ISO 27001 certificates are valid for three years with annual surveillance audits. There is no public dashboard showing the current, active certification status of the APAAR ecosystem.
(d) The government says “data centre” — not “DigiLocker platform.” This is a subtle but important distinction. The hosting infrastructure may be certified; the application layer (the DigiLocker web and mobile app) may not be within that certification scope.
⚠️ Verdict: MEANINGFUL BUT SCOPE-LIMITED AND OFTEN MISREPRESENTED

ISO 27001 certification of the data centre is the strongest single control in this list. However, presenting it as comprehensive security assurance for the entire APAAR ecosystem — including downstream data-sharing partners — is misleading. It covers one node in a multi-node system.

Control 7 — Data Redundancy

GOVERNMENT CLAIM
“Data Redundancy”
What it means: Data is replicated across multiple servers or data centres. If one fails, data remains accessible from backup copies.

What it does well: Ensures data availability and business continuity. Protects against hardware failure, natural disaster, or localised outage.

Critical observation — and this is the most ironic control on the list:
Data redundancy is directly adverse to privacy. The more copies of data exist, the larger the attack surface, and the harder it is to achieve genuine data deletion or withdrawal of consent. When a parent withdraws consent — exercising their DPDP Act right — data redundancy means there are potentially multiple backup copies, replicas, and snapshots of the child’s data across the infrastructure. Ensuring complete deletion across all redundant copies is technically complex and rarely achieved without explicit, auditable deletion procedures.

This control is presented as a security benefit. From a data privacy and right-to-erasure perspective, it is actually a complicating factor.
🔴 Verdict: AVAILABILITY CONTROL PRESENTED AS PRIVACY CONTROL — MISLEADING

Data redundancy protects against data loss — which serves the government’s interest in retaining records. It does not protect the individual’s privacy. In fact, it works against the right to erasure. Presenting redundancy as a reason to trust the system with your child’s data conflates institutional data preservation interests with individual privacy interests.

Control 8 — Timed Log Out

GOVERNMENT CLAIM
“Timed Log Out”
What it means: The DigiLocker session automatically expires after a period of inactivity, requiring re-authentication.

What it does well: Protects against session hijacking on shared or public devices. Basic but useful for use cases like a school lab or shared family computer.

Critical assessment:
This is a session management control — among the most basic security hygiene measures in web application security. It is on the OWASP checklist for any authenticated web application. Its inclusion as one of nine primary security justifications for a national system holding minors’ biometric-linked data suggests either that the full security posture is being cherry-picked for public communication, or that the security architecture is not as deep as claimed.

A timed log-out does not address: data breach at the database level, API vulnerabilities, third-party data misuse, insider threats, or any of the risks that actually matter at the scale and sensitivity of APAAR.
🔴 Verdict: BASIC HYGIENE — DOES NOT MEANINGFULLY INFORM CONSENT DECISION

Timed logout is a feature every internet banking portal has had since 2005. Its inclusion in a list of security justifications for sharing a child’s Aadhaar-linked biometric identity is, with respect, insufficient. This control does not address any of the material risks of the APAAR system.

Control 9 — Security Audit & User Consent-Based System

GOVERNMENT CLAIM
“Security Audit” and “User Consent-Based System”
Security Audit — What it means: The DigiLocker platform undergoes periodic security audits, which may include vulnerability assessments, penetration testing, or compliance audits.

What it does well: Regular security audits are essential for identifying and remediating vulnerabilities. This is a meaningful control if conducted rigorously and by qualified independent auditors.

Critical gaps:
(a) No public audit reports are available. Transparency is central to accountability. The government has not published any APAAR-specific security audit findings, penetration test summaries, or remediation records. “We conduct audits” is not the same as “our audits found X and we fixed Y.”
(b) Frequency and scope are undefined. Annual? Quarterly? Does the scope include third-party integrations, UDISE+ APIs, or the ABC platform? Unknown.
(c) Who conducts the audit? CERT-In empanelled auditor? Internal team? Independent Big-4 firm? The credibility of an audit is entirely dependent on the independence and competence of the auditor.

User Consent-Based System — The deepest irony:
This is listed as a security control. But the entire premise of this blog — validated by the Orissa High Court — is that the consent mechanism itself is defective: no opt-out option, contradictory government statements on withdrawal rights, and coercion at school level. Describing a flawed consent architecture as a “security control” reveals a fundamental misunderstanding of what consent means in a data protection context.
🔴 Verdict: SECURITY AUDIT — UNVERIFIABLE WITHOUT PUBLIC DISCLOSURE; CONSENT SYSTEM — ITSELF THE SUBJECT OF JUDICIAL CHALLENGE

Without published audit findings, “security audit” is an unverifiable claim. And presenting a consent mechanism that the Orissa High Court found to be defectively drafted as a “security control” is, at best, a category error.

Overall Technical Assessment

The nine controls, evaluated holistically, present the following picture:

Control Type Adequacy for APAAR’s Risk Profile Rating
Federated Repository Architecture Good design for core platform; no coverage of downstream sharing PARTIAL
Standard Practices Unspecified Non-verifiable, non-auditable — not a control INADEQUATE
256-bit SSL Encryption (Transit) Industry baseline; does not address application-layer attacks BASELINE
Mobile OTP Sign-Up Authentication Weak 2FA; SMS OTP deprecated by NIST; SIM-swap risk WEAK
Aadhaar Auth for Access Authentication Strong control; creates Aadhaar lock-in; constitutional concern CONDITIONAL
ISO 27001 Data Centre Compliance / ISMS Meaningful; scope limited to data centre, not full ecosystem PARTIAL
Data Redundancy Availability Availability control, not privacy control; complicates erasure MISREPRESENTED
Timed Log Out Session Management Basic hygiene; irrelevant to material risks of APAAR INSUFFICIENT
Security Audit Assurance Valid if public, independent, and scoped; none of this confirmed UNVERIFIABLE
Consent-Based System Governance The consent mechanism is itself judicially challenged as defective CONTRADICTED
⚖️ The Author’s Professional Verdict on Government’s Security Claims

Of the nine controls cited, one is strong (ISO 27001 — with caveats), two are partial (Federated Architecture, Aadhaar Authentication), two are baseline industry hygiene (SSL, Mobile OTP), one is technically misrepresented as a privacy control (Data Redundancy), one is unverifiable (Security Audit), one is legally non-existent (Standard Practices), one is irrelevant to material risks (Timed Logout), and one is itself the subject of a High Court order for defective design (Consent System).

The complete absence of any controls governing: third-party data processor obligations, data retention limits, cross-entity breach notification, recruitment agency data handling standards, deletion procedures, or children’s data-specific safeguards — means the government’s security claim, taken as a whole, does not constitute adequate justification for a parent to share their minor child’s Aadhaar-linked biometric identity data with a system that distributes that data to unregulated third parties.

This is not a judgement that the system is insecure. It is a professional assessment that the security claims made are insufficient, incomplete, and in some cases misleading as a basis for an informed consent decision.

The scorecard below visualises the adequacy rating of each control at a glance:

Security Controls Scorecard Horizontal bar scorecard rating each of the 9 government security controls for APAAR from Inadequate to Strong CONTROL ADEQUACY FOR APAAR’s RISK PROFILE VERDICT INADEQUATE PARTIAL ADEQUATE STRONG Federated Repository PARTIAL Standard Practices INADEQUATE 256-bit SSL Encryption BASELINE Mobile OTP Sign-Up WEAK Aadhaar Authentication CONDITIONAL ISO 27001 Data Centre PARTIAL Data Redundancy MISREPRESENTED Timed Log Out INSUFFICIENT

Figure 2 — Security Controls Scorecard: Bar length represents adequacy for APAAR’s risk profile. 7 of 9 controls fall below the adequate threshold for a system holding minors’ biometric-linked identity data.


SECTION 04

Part III — Voluntary vs. Mandatory: The Central Contradiction

This is the question that prompted this entire blog. The government’s position and the ground reality are in direct, documented conflict.

3.1 The Official Position

✅ Government of India — Official Stance

“Creating an APAAR ID is optional, but the Department of School Education encourages every student to obtain their unique ID to consolidate all achievements and learnings in one place.”

— Official response to author’s queries, January 10, 2025

3.2 The Ground Reality

Schools across multiple states have been directing parents to sign consent forms as a compulsory activity, failing to communicate that refusal is an option. The Central Board of Secondary Education (CBSE) has reportedly pushed for 100% APAAR enrolment — a quantitative target that structurally creates institutional pressure to coerce consent.

⚠️ Critical Contradiction

When a government ministry sets a target of 100% enrolment, it creates an implicit mandate. Schools and teachers face administrative accountability for “gaps” in enrolment. This top-down pressure inevitably filters down to parents as coercion, regardless of what the official policy document says.

3.3 The Consent Form’s Design Flaw

The official APAAR consent form — used in schools nationwide — contained a fundamental design flaw that the Orissa High Court later flagged explicitly (see Section 7). The form provided no option to refuse consent. Parents were presented with a form to sign, with no checkbox or field to indicate disagreement.

“If it is intended to be a voluntary act, appropriate provisions clearly specifying such fact ought to have been incorporated in the form by providing option to the parents to refuse to submit their consent or to opt out of it entirely.”

— Orissa High Court, WPC No. 8285 of 2025 (Rohit Anand Das v. State of Odisha)

3.4 The Free-and-Fair-Consent Test

Principle of Valid Consent APAAR Implementation Status
Freely given — No coercion or undue influence FAILED — Schools presenting it as mandatory; 100% enrolment targets create institutional pressure
Specific — Consent for defined purposes PARTIAL — Form mentions “educational activities” but shares with “recruitment agencies” — a non-educational purpose
Informed — Full knowledge of consequences FAILED — Most parents not informed of data sharing scope, third-party access, or long-term implications
Unambiguous — Clear affirmative action FAILED — No opt-out option on original form; Orissa HC directed this to be rectified
Withdrawable — Right to withdraw at any time CONTRADICTED — Govt. response says “consent cannot be withdrawn” but form says it can; DPDP Act mandates withdrawal rights


SECTION 06

Part V — Cybersecurity & AI/Deepfake Risks

This section addresses risks that are not hypothetical. They are documented, increasing, and particularly acute when the victim is a minor whose data is collected, stored, and shared before they are old enough to consent themselves.

5.1 The Data That Is Being Collected

The consent form is explicit. Personal Identifiable Information (PII) being collected includes:

⚠️ PII Collected Under APAAR (Per Consent Form)

Name · Address · Age · Date of Birth · Gender · Photograph — and this may be shared with: UDISE+ database · Scholarship management bodies · Academic record keepers · Other educational institutions · Recruitment Agencies.

5.2 Deepfake Risk — The Most Underestimated Threat

The diagram below shows how a single data breach — at any node in the APAAR ecosystem — cascades through successive harm stages, with the minor child as the ultimate victim at every path:

APAAR Data Breach Risk Cascade Flowchart showing how a data breach at any APAAR node cascades through identity theft, SIM-swap, deepfake creation, and financial fraud to harm the minor child Data Breach at Any Node DigiLocker · UDISE+ · Recruitment Agency · ABC Full PII Exposed Name+DOB+Address+Photo Aadhaar Linkage Exposed Biometric ID compromised Photo + Identity Verified image+metadata Identity Theft Fake accounts · Loan fraud SIM Swap Attack Hijack OTP → DigiLocker access AI Deepfake Creation Verified photo → synthetic media THE CHILD — Ultimate Victim Reputational · Financial · Safety · Future harm Data given before child could consent ⚠ Harm may materialise years after consent was given — long after any withdrawal right can matter

Figure 4 — Risk Cascade: Multiple breach pathways converge on the child. The irreversibility of the harm is the critical concern, not just its probability.

The photograph of a minor, linked to verified identity data (name, DOB, Aadhaar), creates a uniquely dangerous dataset in the current AI landscape.

🤖
Identity-Grounded Deepfakes

Unlike deepfakes created from casual social media images, a photograph linked to verified government identity can be used to create highly credible, legally difficult-to-challenge synthetic media of a minor.

📅
Time-Delayed Harm

A photo taken when the child is 8 years old may be used for harm when they are 18. The data, once in a system, persists. The child’s future — employment, relationships, safety — can be affected by data given years earlier without their knowledge.

🔗
Data Aggregation Attack

DOB + Name + Address + Photo + Aadhaar number is the complete dataset needed for identity theft, SIM swap fraud, financial fraud, and targeted social engineering attacks.

🏢
Recruitment Agency Risk

Sharing child data with “recruitment agencies” — private entities with no defined regulatory oversight under APAAR — creates an uncontrolled data exit point. One breach at a small recruitment agency cascades to millions of children.

5.3 The Centralised Database Risk

Centralised databases are high-value targets. The larger and more complete the database, the more attractive it is to state-sponsored threat actors, ransomware groups, and data brokers. A database of 33+ crore students — each with verified biometric-linked identity — is among the most valuable data assets imaginable from an adversarial standpoint.

🔴 Security Architecture Concern

While DigiLocker holds ISO 27001 certification, the APAAR system involves multiple downstream data processors — UDISE+, ABC, educational institutions, scholarship bodies, and recruitment agencies. ISO 27001 certification of the core platform does not extend to every entity in the data-sharing chain. Each node is a potential breach point.

5.4 What Happens When Data Escapes the System?

There is no published breach notification protocol specific to APAAR that parents have been informed of. Under the DPDP Act, a Data Fiduciary is required to notify the Data Protection Board and affected individuals of personal data breaches. However:

→ The DPDP Rules specify notification to the DPB, but the threshold and timeline for notifying individual Data Principals (parents and children) remains an open regulatory question.
→ There is no mechanism by which a parent can discover whether their child’s APAAR data has been accessed, shared, or compromised.
→ The internet freedom advocacy group Internet Freedom Foundation (IFF) has specifically raised alarms about the absence of a clear oversight mechanism.


SECTION 07

Part VI — Government’s Answers Examined

The official government response dated January 10, 2025 was provided in reply to questions raised in January 2025. Let us analyse each point with professional scrutiny.

The government says APAAR is “optional.” Schools are saying it is mandatory. How do we reconcile this?
The government’s answer sidesteps this entirely by simply reiterating that it is “optional.” It does not address how the 100% CBSE enrolment target creates institutional pressure, nor does it address school-level coercion. The answer is technically accurate, practically unhelpful.
The government says “consent cannot be withdrawn.” The consent form says it can. Which is correct?
The government’s position is legally incorrect under the DPDP Act 2023, which expressly grants the right to withdraw consent. The consent form is closer to the legal truth but muddies it by adding that “data already processed shall remain unaffected.” The government’s response appears to conflate withdrawal of consent with reversal of processed data — these are two different concepts.
The government points to ISO 27001 certification, 256-bit SSL, and DigiLocker security. Is this sufficient reassurance?
These are legitimate and important security measures for the DigiLocker platform itself. However, the concern is not about the security of the storage platform — it is about data shared downstream with third parties including educational institutions and recruitment agencies. ISO 27001 certification of DigiLocker does not govern how recruitment agencies or UDISE+ handle the data once received. This is a category error in the government’s answer.
The government says “The consent given right now is only for creation of APAAR ID.” Is this accurate?
This is demonstrably inaccurate. The consent form itself states that PII “may be made available to entities engaged in various educational activities such as UDISE+ database, scholarships, maintenance academic records, other stakeholders like Educational Institutions and recruitment agencies.” The consent scope is far broader than mere ID creation.

SECTION 08

Part VII — Edge Cases Nobody Is Talking About

These are real-world scenarios raised in the original set of questions to the government. They expose systemic gaps in the APAAR framework’s design.

Case A: Death of a Parent & Remarriage

Consider: A child loses one parent. The surviving parent later remarries. In an inter-caste or inter-religion marriage, the child may acquire a new surname. The questions this raises:

⚠️ Unresolved Scenarios

1. Who bears the cost and effort of updating the APAAR ID — the APAAR team, the school, or the parent?
2. What is the official process for name change on the APAAR ID after a court-recognised surname change?
3. If the deceased parent’s name is embedded in the ID-generation record, how is the father/mother name field updated?
4. Is there a defined SLA (Service Level Agreement) for such updates? What happens to the child’s academic continuity during the update process?
5. No official answer has been provided to any of these questions.

Case B: Single Parents & Non-Traditional Guardianship

The consent form is titled “Consent by Father/Mother/Legal Guardian.” What happens in cases of:

👤
Single-parent household

Is one parent’s consent sufficient? What if both parents are required by the system architecture but only one is alive or available?

🏛️
Court-appointed guardians

Children under state care, NGO custody, or with court-appointed guardians — what documentation is required, and who verifies guardian authority?

🔄
Custody disputes

If parents are separated and one parent consents to APAAR without the other’s knowledge, is this valid? Can the non-consenting parent challenge it?

Case C: The Consenting Parent’s Own Privacy

To generate an APAAR ID for a minor, the parent must provide their own Aadhaar for authentication. This means the APAAR system also processes and authenticates the parent’s biometric identity. The consent form does not explicitly address what happens to the parent’s Aadhaar authentication data after the verification event.

🔴 Unaddressed Privacy Point

Under DPDP Act, the parent is also a Data Principal. The processing of their Aadhaar authentication record requires lawful basis. The consent form for the child’s APAAR ID does not constitute valid consent for processing the parent’s personal data. This is a gap in the consent architecture that deserves regulatory attention.


SECTION 09

Part VIII — What the Courts Have Said

2017 — SUPREME COURT
K.S. Puttaswamy v. Union of India — Privacy declared a fundamental right under Article 21. Any state action involving personal data must adhere to legality, necessity, and proportionality. This is the constitutional baseline against which APAAR is measured.
2019 — SUPREME COURT
K.S. Puttaswamy v. Union of India (Aadhaar judgment) — Aadhaar cannot be made mandatory for access to basic education. Since APAAR requires Aadhaar linkage, any effective mandate of APAAR for school access arguably conflicts with this direction.
DECEMBER 2025 — ORISSA HIGH COURT
Rohit Anand Das v. State of Odisha (WPC No. 8285/2025) — Landmark. Court held that a consent form for a purportedly voluntary scheme must include an explicit opt-out or refusal option. Directed the government to amend the APAAR consent form accordingly. Court held: the option to withdraw consent later does NOT substitute the right to refuse consent at the outset.
✅ Significance of the Orissa HC Judgment

This ruling validates every concern raised in this blog about the original consent form design. It establishes a judicial precedent that parents have a right to a genuine, meaningful opt-out — not merely a theoretical withdrawal right after the fact. This judgment should be cited by any parent or advocate challenging school-level coercion.


SECTION 10

Part IX — Risk Matrix Summary

Risk Domain Risk Description Likelihood Impact Rating
Consent Coercion Schools treating voluntary APAAR as mandatory; parents uninformed of opt-out rights High High CRITICAL
Data Breach — Central DB Centralised Aadhaar-linked database of 33+ crore students as high-value target Medium Catastrophic CRITICAL
Deepfake / AI Misuse Verified photo + identity data enabling credible synthetic media targeting minors Medium Severe CRITICAL
Recruitment Agency Data Misuse PII shared with private entities; no defined limitation on further processing Medium High HIGH
Identity Theft Complete PII dataset (DOB + address + photo + Aadhaar linkage) enabling fraud Medium High HIGH
Third-Party Chain Breach Data shared downstream to entities outside DigiLocker’s ISO 27001 coverage High High HIGH
DPDP Act Non-Compliance Withdrawal right denial; children’s data processing without adequate safeguards High Medium HIGH
Surveillance Creep Academic + behavioural data accumulation enabling student profiling over lifetime Low-Medium High MEDIUM
Name/Status Change Failure No defined process for post-remarriage, death, or legal name changes Medium Medium MEDIUM
Digital Divide Exclusion Rural/marginalised students disadvantaged if APAAR becomes de facto mandatory High Medium MEDIUM

SECTION 11

Part X — What Should You Do as a Parent?

This blog does not advocate blanket refusal of APAAR. It advocates informed, free, and genuinely voluntary consent — which is your legal right.

If You Choose to Consent:

✅ Steps to Take Before Signing

1. Read the consent form in full. Ask the school to explain every clause.
2. Ask specifically: Which third-party entities will receive my child’s data? What are their data retention policies?
3. Keep a copy of the signed consent form for your records.
4. Note the date of consent. Under DPDP Act, you may withdraw consent later — despite what the government’s Jan 10 response says.
5. Monitor your child’s DigiLocker account periodically for unauthorised access or unexpected documents.

If You Choose to Refuse or Defer:

📋 Your Legal Position

1. APAAR is officially voluntary. You have the right to refuse.
2. Cite the Orissa High Court judgment (WPC No. 8285/2025) if the school insists it is mandatory.
3. Cite K.S. Puttaswamy (2019): Aadhaar cannot be mandatory for basic education access.
4. Submit a written refusal to the school Principal, keep a copy. This creates a documentary trail.
5. Your child cannot legally be denied admission, grades, scholarships, or educational benefits solely on the basis of not having an APAAR ID (voluntary scheme).
6. If a school denies any service or benefit, this is actionable — file a complaint with the State Education Department and the school’s governing board.

The CBSE “REFUSED” Protocol — What CBSE Itself Has Officially Established

This is the most important practical development in the APAAR story — and one that most parents and schools are entirely unaware of. CBSE has, through its own official circulars, created a documented, codified mechanism to handle parental refusal. Your memory is correct — and the documentation is on CBSE’s own domain.

🔴 The Critical Sequence of CBSE Circulars on APAAR

January 24, 2025 — CBSE issued its first implementation circular positioning APAAR as the primary identifier for Class X and XII board exam registrations (List of Candidates / LOC). Reference: Circular_Implementation_APAAR_ID_24012025. This circular effectively linked board exam eligibility to APAAR — creating the very institutional pressure this blog has documented.

August 27, 2025 — CBSE’s LOC circular (Ref: CBSE/LOC/X-XII/2025-2026) explicitly stated that schools would only be able to fill the LOC for candidates who had their APAAR IDs — with validation at submission. This was the high-water mark of institutional coercion: no APAAR = no board exam registration.

September 9–11, 2025 — Under documented pressure from schools, parents, and advocacy groups including the Internet Freedom Foundation (IFF), CBSE reversed course. Circular Ref: CBSE/Co-Ord/APAAR ID/2025-2026 introduced partial relaxation with two formal codes schools must use in the LOC.

CBSE CIRCULAR — CBSE/Co-Ord/APAAR ID/2025-2026 — DATED SEPTEMBER 9, 2025
“In case of APAAR IDs not being generated owing to lack of consent of parents, a copy of the denial of consent by parents be maintained by the schools and entry against APAAR be made as ‘REFUSED’ in the LOC.

In case of APAAR IDs not being generated owing to other reasons, entry against APAAR be made as ‘NOGEN’.”

This is a landmark development that deserves to be understood clearly by every parent. Let us unpack exactly what it means — and what it does not mean.

What “REFUSED” Means for Your Child — The Good News

✅ What the CBSE REFUSED Protocol Establishes

1. Parental refusal is formally recognised by CBSE itself. A school that tells you APAAR is mandatory is contradicting CBSE’s own circular — there is now a designated system code (“REFUSED”) that only exists because refusal is a legitimate, documented outcome.

2. Your child’s board exam registration cannot be blocked solely due to APAAR refusal. The LOC will be submitted with “REFUSED” — the child remains eligible for examination registration.

3. The school must retain your written denial of consent as a documentary record. This means your written refusal is a formal document in the school’s records — not an informal verbal communication that can be ignored.

4. This applies to Class IX, X, XI, and XII registrations under the 2025-26 cycle, with the expectation of full APAAR coverage by 2026-27.

What “REFUSED” Does Not Mean — The Critical Caveat

⚠️ Limitations the CBSE Circular Does Not Address

1. This is explicitly a temporary relaxation, not a permanent guarantee. CBSE’s circular states these relaxations apply only for the current academic cycle. The board has simultaneously reiterated that “schools must continue working toward full APAAR coverage.” The institutional pressure to achieve 100% has not been withdrawn — it has only been deferred.

2. No “no-adverse-consequence” guarantee has been issued. The circular establishes the procedural code but does not guarantee that a child marked “REFUSED” will face no disadvantage in future scholarship matching, academic transfers, or higher education access where APAAR may be required.

3. The “NOGEN” code conflates two entirely different situations — parents who cannot generate an ID due to technical issues (Aadhaar mismatch, documentation gap) and parents who choose not to consent. Combining these into one category obscures the true scale of parental refusal from aggregate reporting, making it harder to assess how many parents are actually exercising their rights.

4. The overseas school exemption (CBSE schools outside India are exempt from APAAR due to local regulations) creates an ironic two-tier system: Indian students abroad are not subject to this scheme, but students within India — whose data is arguably more sensitive in the domestic context — have no equivalent exemption.

“CBSE’s new circular acknowledges the reality that parental consent can be refused. But with no clear opt-out guarantees and no privacy safeguards, it remains a partial fix.”

— Internet Freedom Foundation (IFF), September 2025

The Three-Document Arsenal — What Every Refusing Parent Should Carry

If you are refusing APAAR consent and your school pushes back, the following three official documents — all sourced directly from government or judicial authorities — together constitute an unassailable legal position:

Document Authority What It Establishes Source
CBSE Circular
CBSE/Co-Ord/APAAR ID/2025-2026
CBSE (Central Board of Secondary Education) Formal “REFUSED” code for parental non-consent in LOC. School must accept written refusal and cannot block exam registration. Official PDF ↗
Orissa HC Judgment
WPC No. 8285/2025
Orissa High Court Consent form must include opt-out option. Right to refuse consent at outset cannot be substituted by a post-hoc withdrawal clause. Rohit Anand Das v. State of Odisha, December 2025
K.S. Puttaswamy v. Union of India (2019) Supreme Court of India Aadhaar cannot be made mandatory for access to basic education. APAAR’s Aadhaar prerequisite cannot be an indirect mandate for education access. 2019 (1) SCC 1
✅ The Practical Step: Written Refusal Template

When submitting your refusal, a brief written note to the school Principal should state:

“I, [Parent Name], parent/guardian of [Child Name] (Class __, Roll No. __), hereby decline to provide consent for generation of an APAAR ID for my child. This decision is exercised in accordance with the voluntary nature of the APAAR scheme as confirmed by the Department of School Education, and consistent with the CBSE circular CBSE/Co-Ord/APAAR ID/2025-2026, which provides for a ‘REFUSED’ entry in the List of Candidates for students whose parents do not consent. I request that a copy of this refusal be retained in the school’s records as required by the said circular.”

Keep a signed and dated copy for yourself. Request an acknowledgement from the school.

The Question You Were Asked: What If Your Child Is the Only One Without an APAAR ID?

This is a legitimate social-pressure concern. Here is the honest answer: in a system where 33+ crore students are enrolled, there may be practical disadvantages in the future if certain academic processes become APAAR-dependent. This is the nature of network-effect digital systems. However:

⚖️ The Author’s Assessment

The risk of social or administrative pressure is real. The risk of data harm from a system with inadequate safeguards is also real. Consent obtained under fear of exclusion is not free consent — under Indian Contract Act Section 15. Until the government: (a) publishes a clear data retention and deletion policy; (b) defines and limits the scope of third-party sharing; (c) ensures the DPDP Act’s children’s data provisions are fully operationalised for APAAR; and (d) provides a legally clear withdrawal mechanism — a cautious, informed parent has every legal and ethical right to withhold consent.


CONCLUSION

The Informed Choice Is the Only Choice That Counts

The APAAR ID is a well-intentioned policy instrument in service of a genuinely transformative educational vision. A paperless, portable, verifiable academic credential system is the right direction for a digital India.

But good intentions do not override legal rights. A voluntary scheme that functions as a de facto mandatory one is not voluntary. A consent form with no opt-out option does not produce legal consent. A government response that contradicts the statutory right to withdraw consent is simply incorrect in law.

There are signs of institutional acknowledgement. CBSE’s September 2025 circular introducing the “REFUSED” code in the List of Candidates is a meaningful concession — it is the first time a central educational authority has formally codified the right of parents to say no, embedded it in the examination registration system, and required schools to retain documentary evidence of that refusal. That is progress, and it deserves recognition.

But it is partial progress. The Orissa High Court has spoken on the consent form. The K.S. Puttaswamy judgment has spoken on Aadhaar and education. The DPDP Act has spoken on children’s data and withdrawal rights. What remains is for the Ministry of Education to align its full implementation — its consent architecture, its data-sharing scope, its third-party oversight, and its official communications — with the law.

Until that alignment is complete, every Indian parent deserves to know: you have a right to say no, CBSE has formally acknowledged that right, and no court in India will tell you otherwise.

✍️ About the Author

Neelabh Rai is an ASCL Certified Cyber Crime Investigator (CCCI) and seasoned GRC professional with 11+ years of deep-rooted experience in information security audits, cybercrime investigation, and regulatory compliance. He has led 150+ internal audits across enabling and delivery functions and has driven successful ISO implementations and certifications across India, Germany, and the USA — including for German automobile companies, healthcare sector clients, and financial institutions.

Certifications & Qualifications: ASCL Certified Cyber Crime Investigator (CCCI) · BSI Certified Lead Implementer (CLIP) — ISO 27701:2019 & GDPR · CQI/IRCA Certified ISO 27001:2022 Lead Auditor · ISO 42001:2023 Lead Implementer (AI Risk Management) · IRCA Certified ISO 22301:2012 Business Continuity Lead Auditor · TISAX Lead Auditor/Implementer (TÜV SÜD certified) · Diploma in Indian Cyber Law, Government Law College Mumbai · B.Tech — Information Technology, AKGEC Ghaziabad (UPTU).

Recognition & Research: Fellow of IETE (Institution of Electronics and Telecommunication Engineers) and current Executive Committee Member, IETE Noida Chapter. International award recipient — Cyber Security Ace from the International Cyber Threat Task Force (ICTTF) for outstanding contributions to SCADA security. Author of published and indexed research papers on typosquatting, cyber terrorism, and digital forensics, cited by the University of Leicester (UK) and Calgary Law Enforcement (Canada). Invited speaker at international conferences in Singapore, Kerala, and Kanpur.

CYBER COPS India: Founder of cybercops.in — an independent platform dedicated to helping Indian digital citizens stay safer online through research, legal analysis, and cybersecurity awareness. This blog is an extension of that mission.

This blog represents the author’s independent analysis in a personal capacity. It is not legal advice and does not represent the views of any employer or affiliated organisation. Parents with specific legal concerns should consult a qualified cyber law or constitutional law advocate. The queries to the government cited herein were submitted on January 4, 2025, and the official response was received on January 10, 2025.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.