2026-05-25
Added · Updated
These regulations establish a comprehensive, mandatory framework for controlling and securing access to the National Data Warehouse by requiring integrated Customer Due Diligence, multi-modal biometric verification, and strict purpose-bound data minimization. All requesting entities must execute a formal Services Agreement, adhere to specific technical and security baselines, and maintain immutable audit logs for every transaction to ensure full traceability and accountability. The Authority retains exclusive control over data, mandates immediate breach reporting within 12 hours, and prohibits the unauthorized storage, aggregation, or monetization of sensitive identity attributes.