Why in news?
Facial recognition at protests, doxxing and deepfakes, and the SIR of electoral rolls reveal gaps in India’s privacy law.
UPSC Relevance
Prelims: Right to privacy (K.S. Puttaswamy case), Digital Personal Data Protection Act 2023, 326, history of fingerprinting.
Mains GS-II: Fundamental rights and their evolving scope; judiciary; Election Commission; e-governance and accountability; government policies.
Mains GS-III: Role of media and social networking sites in internal security challenges; cyber security; awareness in IT and AI.
GS-IV : Ethics of surveillance, dignity and autonomy.
Three kinds of watching
| Kind of watching | What happens | Examples from the news |
| 1. State surveillance in public | The state watches people in public spaces and uses technology to establish who they are. | Rahim’s petition alleges that police used facial recognition, AI-enabled smart glasses, drones and a mobile command vehicle at Jantar Mantar, and that the data was hosted by two private firms. |
| 2. Online identification by networks (doxxing) | Private individuals and anonymous accounts identify people and publish their personal details to shame or threaten them. | Women who took part in the CJP protests were targeted online; their personal details were published along with rape and death threats. Earlier, in March 2020, the UP administration put up hoardings in Lucknow with photographs and addresses of anti-CAA protesters; the Allahabad High Court ordered their removal, calling it an “unwarranted interference in privacy”. |
| 3. Bureaucratic identity checks | Identity checks decide who stays on the electoral roll and therefore who can vote. | The SIR: the Court held that the EC may examine citizenship for this limited purpose but cannot decide citizenship itself. Bihar’s SIR began with about 7.89 crore electors and ended with a final roll of 7.42 crore. |
- The author argues that these are not three unrelated stories. Read together, they form a pattern connecting the state, private firms, online networks and the citizens caught among them.
- Surveillance must be treated not as a discrete act by one identifiable actor against one identifiable person, but as a diffuse act spread across states, companies and foreign vendors at once.
- Legal gaps: India has no clear legal answers to who is responsible when a protester is identified by a camera, doxxed by anonymous accounts and then threatened at home.
Why the new pattern is a concern
- Chilling effect on free speech: If protesters know they can be identified, doxxed and threatened, many will stay away. This weakens Article 19(1)(a) and 19(1)(b) (speech and peaceful assembly).
- Gendered harm: Women protesters faced rape and death threats after their details were published. Online abuse pushes women out of public and political life.
- Blurred accountability: Police data hosted by private firms, spread by anonymous accounts and processed by foreign software leaves no single actor answerable.
- Accuracy and bias: Facial recognition systems have higher error rates for women and darker-skinned people, which can lead to wrongful identification.
- Function creep: Data collected for one purpose (such as crowd control or voter verification) may be used for other purposes without consent.
- Exclusion from democracy: In the SIR, an identity-verification exercise decides whether a person can vote. Errors can remove genuine voters, especially the poor, migrants and women whose documents are weaker.
- The Pegasus episode : shows how difficult it is to fix accountability when surveillance involves foreign vendors and secret state action.
- In Manohar Lal Sharma v. Union of India (2021), the Supreme Court refused to let the state get a “free pass” by merely invoking national security and appointed an independent expert committee.
- In 2022, the Justice R.V. Raveendran committee reported malware in some of the phones it examined, but could not say for sure whether it was Pegasus. It also noted that the Union government had not cooperated.
- Later, in 2025, the Supreme Court indicated that parts of the report would not be made public.
India’s privacy jurisprudence
- Early phase: In M.P. Sharma (1954) and Kharak Singh (1962), the Supreme Court held that privacy was not a fundamental right, though Kharak Singh struck down domiciliary night visits by police. Gobind (1975) and R. Rajagopal (1994) later recognised privacy in a limited form.
- Telephone tapping: In PUCL v. Union of India (1997), the Court held tapping to be a serious invasion of privacy and laid down procedural safeguards, including review committees.
- K.S. Puttaswamy v. Union of India (2017): A nine-judge Bench unanimously held privacy to be a constitutionally protected right, intrinsic to Article 21 and to the freedoms in Part III. It overruled M.P. Sharma and Kharak Singh to that extent. It recognised informational privacy, bodily autonomy and decisional autonomy.
- Aadhaar judgment (Puttaswamy II, 2018): A five-judge Bench upheld Aadhaar for welfare delivery but struck down Section 57, which allowed private companies to use Aadhaar for authentication.
- Limitation noted by the author: Puttaswamy was decided in a case against the state, and its test is framed around state action. It does not easily address harm done by private firms or anonymous online actors.
The Puttaswamy test for restricting privacy
| Requirement | Meaning |
| Legality | There must be a law authorising the restriction. |
| Legitimate aim | The law must pursue a legitimate state aim, such as national security or prevention of crime. |
| Proportionality | The means used must be suitable, necessary and the least restrictive option, and must balance the right against the aim. |
| Procedural safeguards | There must be safeguards against abuse of power (added by Justice S.K. Kaul and applied in the Aadhaar case). |
The legal gaps
- The Digital Personal Data Protection Act, 2023 – The Union government can exempt any state instrumentality by notification on grounds including the security of the state, sovereignty, and public order.
- Interception and monitoring: Section 69 of the IT Act, 2000 and Section 20 of the Telecommunications Act, 2023 (which replaced the Indian Telegraph Act, 1885) allow lawful interception on grounds such as sovereignty, security and public order.
- Biometric data of suspects: The Criminal Procedure (Identification) Act, 2022 allows police to take measurements, including biometrics, of convicts, arrested persons and others. Records can be kept by the NCRB for 75 years.
- Facial recognition: Police in several states use facial recognition systems, and the NCRB has been developing a National Automated Facial Recognition System. There is no specific law governing their use, accuracy or data retention.
- Doxxing and deepfakes: India has no specific offence of doxxing. Victims rely on general provisions such as Section 66E of the IT Act (violation of privacy), the BNS provisions on stalking, criminal intimidation and defamation, and the IT Rules, 2021, which require platforms to remove non-consensual intimate or morphed images within 24 hours of a complaint. Amendments have been made to require labelling of synthetically generated (AI) content.
- Electoral rolls: The EC’s power flows from Article 324 (superintendence, direction and control of elections). Article 326 provides adult suffrage for citizens aged 18 and above. Under the Representation of the People Act, 1950, a non-citizen cannot be registered, and Section 21(3) allows a special revision. In Lal Babu Hussein (1995), the Court held that names cannot be deleted without due process.
- RTI amendment – Amends Section 8(1)(j) of the RTI Act, 2005, widening the exemption for personal information.
The author’s concern is that the broad exemption for state agencies means the law that is meant to protect citizens’ data may not apply to the very bodies that collect the most sensitive data.
Security vs Privacy: the balance
| Basis | Case for surveillance tools | Case for strong privacy safeguards |
| Public order | Helps manage large crowds, identify violent offenders and prevent terror attacks. | Mass surveillance of peaceful protesters goes beyond what is necessary and fails the proportionality test. |
| Efficiency | Technology speeds up investigation and finding missing children (for example, Delhi Police’s use of facial recognition to trace missing children). | Speed without rules multiplies harm, as data spreads within hours. |
| Clean electoral rolls | Removing dead, duplicate and ineligible names protects the integrity of elections. | The burden of proof on citizens may exclude genuine voters; a vote once lost in an election cannot be restored. |
| Accountability | The state is answerable through courts and Parliament. | Secrecy, national security exemptions and private contractors weaken real accountability, as the Pegasus case showed. |
Way Ahead
- A law on surveillance: Enact a clear law governing facial recognition and other surveillance tools, with rules on purpose, accuracy, retention, independent authorisation and oversight, in line with the Puttaswamy test.
- Narrow the DPDP exemptions: State exemptions under Section 17 should be specific, time-bound and subject to review, and the Data Protection Board should be made more independent.
- Cover the whole data chain: Private companies that host police data should carry clear duties, audit obligations and liability.
- Address doxxing and deepfakes: Create a specific offence of doxxing, enforce quick takedowns, and require platforms to label AI-generated content and trace malicious accounts.
- Safeguards in electoral revisions: Ensure notice, a fair hearing, easy documentation and a presumption in favour of those already on the rolls.
- Learn from global practice: The EU’s GDPR covers both public and private actors, and the EU AI Act largely bans real-time remote biometric identification in public spaces, with narrow exceptions.
- Digital literacy and support: Help citizens, especially women, protect their data and seek remedies quickly.
Privacy in India today is not threatened by one watcher but by many working together. Puttaswamy gave India a strong foundation, but a framework focused only on state action cannot protect citizens in this web. Privacy law must follow the data wherever it travels, so that dignity and liberty are protected at every point in the chain.
Practice Questions
Q1. Consider the following statements regarding the right to privacy in India:
1. In the K.S. Puttaswamy case (2017), a nine-judge Bench held the right to privacy to be intrinsic to Article 21 and the freedoms in Part III.
2. The Digital Personal Data Protection Act, 2023 allows the Union government to exempt any instrumentality of the state from its provisions on the ground of public order.
3. The Supreme Court has held that the fundamental rights under Articles 19 and 21 can never be enforced against private persons.
How many of the statements given above are correct?
(a) Only one
(b) Only two
(c) All three
(d) None
Answer: (b). Statements 1 and 2 are correct. Statement 3 is incorrect, as in Kaushal Kishor v. State of UP (2023) the majority held that Articles 19 and 21 can be enforced even against non-state actors.
Q2. Consider the following statements:
Statement-I: The world’s first Fingerprint Bureau was set up in Calcutta in 1897.
Statement-II: A fingerprint classification system was developed in Bengal with contributions from Indian police officers Azizul Haque and Hem Chandra Bose.
Which one of the following is correct in respect of the above statements?
(a) Both Statement-I and Statement-II are correct and Statement-II explains Statement-I
(b) Both Statement-I and Statement-II are correct but Statement-II does not explain Statement-I
(c) Statement-I is correct but Statement-II is incorrect
(d) Statement-I is incorrect but Statement-II is correct
Answer: (a). The classification system developed in Bengal made it possible to organise fingerprint records, which led to the setting up of the Calcutta Fingerprint Bureau in 1897.
Mains Practice Question
“The Puttaswamy judgment gave India a strong foundation for privacy, but threats to privacy today come as much from private and online actors as from the state.” Discuss the gaps in India’s privacy framework and suggest measures to address them. (250 words, 15 marks)
Tell Google you want more of this.
Add Anantam IAS as a preferred sourceOne tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.