For section 8 of the principal Act, the following section shall be substituted, namely:—
"8. (1) The Authority or any entity or group of entities specified by regulations may, subject to such conditions and on payment of such fees as may be specified by regulations, perform authentication.
(2) (a) In case a requesting entity seeks to perform Aadhaar authentication under this Act, it shall—
(i) send the Aadhaar number and demographic information or biometric information of an individual to the Central Identities Data Repository for authentication; and
(ii) receive a response from the Central Identities Data Repository confirming or rejecting the identity of the individual.
(b) In case an entity has been allowed under sub-section (1) to perform authentication, such entity shall—
(i) comply with such standards of privacy and security as may be specified by regulations; and
(ii) ensure that the information of an individual obtained during authentication is only used for the purposes authorised under this Act.
(3) No entity, other than those specified under sub-section (1), shall perform Aadhaar authentication."