UPSC CSE 2026 Essay Paper Discussion

Privacy as a Moral Claim, Not Only a Right: Consent, Coercion and Mandatory Digital ID (UPSC Ethics — GS IV)

Privacy is a moral interest before it is a legal right, and the interest it protects is the capacity to act without being watched. The central harm of a mandatory digital identity is not exposure but exclusion — a biometric failure denying rations to the person least able to appeal.

Privacy as a Moral Claim, Not Only a Right: Consent, Coercion and Mandatory Digital ID (UPSC Ethics — GS IV)

Privacy arguments in India almost always begin with a case and a proportionality test. That is the legal question, and it is downstream of a moral one: why does being observed matter at all to a person who has broken no law?

The answer is not embarrassment. What observation reaches is the capacity to form intentions, change one’s mind, hold an unpopular view before it is ready to be defended, and associate with people whose company would be held against you. Those are conditions of agency, not preferences about comfort, and the right recognised in 2017 protects an interest older than itself.

The Goods Privacy Protects

The classical formulations — Warren and Brandeis on “the right to be let alone” in 1890, Alan Westin in 1967 on privacy as control over information about oneself — treat privacy as a boundary. What matters is the list of things the boundary protects.

Autonomy. A person deciding under observation is partly deciding how the decision will look; removing the audience is what makes a choice his own.

Dignity. Being reduced to a profile — a risk score, a probability of default — is a distinct injury from having a secret exposed, because it substitutes a model for a person and then acts on the model.

Association and dissent. Trade unions, minority faiths, whistleblowers and opposition organisers need to meet before they are strong enough to be visible. Privacy is a precondition of political life, not a retreat from it.

Bodily and mental integrity. Data about the body and the brain is not merely about you but is you — the problem taken up in neuroethics and cognitive liberty.

Contextual Integrity: Why “Already Public” Is Not an Answer

Helen Nissenbaum’s contextual integrity is the most useful tool here. Information flows are governed by norms attached to the context in which they occur, and a violation is a breach of those norms rather than the disclosure of a secret.

So “the information was already available” answers nothing. Your address is known to your neighbours, your landlord and the post office; that does not make it appropriate for an insurer to buy it. A doctor knowing your medical history is the norm of the clinical context, and the same fact reaching an employer is a violation though no new information was created. The wrong lies in the onward flow.

It also explains why aggregation is a harm in itself: innocuous facts — where you were, what you bought, who you called — combine into something none of them contained. Genomic databases show this sharpest, since a sample given for research carries information about relatives who consented to nothing, as precision medicine and Genome India sets out.

Table of the four prongs of the proportionality test — legality, legitimate aim, necessity and procedural safeguards — with what each asks and where Indian systems commonly fail
The four prongs, and the one Indian systems fail most often
Four cards distinguishing identification, authentication and authorisation, and defining function creep as a separate wrong
Three words routinely collapsed into one, and the wrong that follows

“Nothing to Hide” and the Three Replies

The commonest objection is that an honest person loses nothing by being seen. It has three answers, working at different levels.

Privacy protects against error, not only exposure. Most privacy harm comes from data being wrong, stale or misread — a name matched to the wrong record, a flag that follows a person through every later transaction. Someone with nothing to hide still has much to lose from a mistake he cannot see or correct.

The harm is aggregation. Each fact volunteered is defensible on its own. The composite is not a fact at all but an inference, and inferences about a person’s beliefs, health and associations are drawn without being disclosed to him.

The burden falls unequally. The claim is made by people whose lives are conventional and whose data is unlikely to be scrutinised. For a minority member, a labour organiser, a journalist’s source or a person of the wrong caste in the wrong village, being legible to the state is not neutral. A principle that protects only the unremarkable is not a principle.

Chilling Effects: Harm Without Enforcement

Bentham’s panopticon works because the inmate cannot tell when he is watched and behaves as though he always is. That is how surveillance harms even where no action follows: people stop searching for certain things, stop attending certain meetings, and self-censor in ways that leave no record and no complaint.

The harm is therefore invisible to the usual audit: a programme can show no misuse, no leaks and no wrongful arrests while having narrowed what citizens are willing to do. Traceability requirements and the compliance duties under the IT intermediary guidelines and digital media ethics code raise exactly this problem — the effect on speech is real and never appears as an enforcement statistic.

Consent at Scale Is Mostly Fiction

Consent does real moral work when it is informed, voluntary and revocable. At the scale of digital services and welfare delivery, it is usually none of these, for four separable reasons.

Monopoly. Where a service has no substitute — a payments rail, an admissions portal, a single land-records system — refusal is not available, and a choice with one branch is not a choice.

The price of refusal is an entitlement. A customer who declines terms loses a product. A ration cardholder who declines loses food. These are not the same transaction, and treating both as consent obscures the difference.

Unreadable notice. Nobody reads a privacy policy of several thousand words listing fifteen third-party recipients. Consent obtained that way is a signature, not an agreement.

The subject is a beneficiary, not a customer. Someone applying for a pension has no bargaining power, no exit and often no literacy in the medium. Consent architecture designed for commerce, transplanted into welfare, launders coercion as agreement.

Mandatory Digital Identity: Three Words Kept Apart

Most confused argument about digital ID comes from collapsing three distinct operations.

Identification answers “who is this person?” and requires a search across a population. Authentication answers “is this the person who holds this entitlement?” and requires only a comparison against one record. Authorisation answers “may this person receive this benefit?” — a question of eligibility, not identity.

The distinction matters because systems built for the second are routinely used for the first, and because failures of authentication get treated as failures of authorisation. A person whose fingerprint does not read has not become ineligible; he has failed a technical step. The two are conflated whenever the machine’s answer is treated as final.

Function creep is a separate wrong. An identifier introduced for one purpose and later required for others has changed character even if no rule was broken: the population consented, at best, to the original purpose. The pattern to watch is “voluntary but effectively compulsory” — formally optional, while every route to a service runs through it. Judge such a scheme by its practical effect, not its label, because the effect is what the person at the counter meets.

Exclusion Error as the Central Moral Harm

Targeting systems make two errors: including someone undeserving, and excluding someone deserving. Almost all political attention goes to the first; almost all the moral weight belongs to the second.

A wrongly included beneficiary costs the exchequer a small sum. A wrongly excluded one loses food, medicine or a pension, and is by definition least able to appeal — no documents, no travel money, no phone that receives the grievance message. Field studies of biometric authentication in the public distribution system have documented failures concentrated among manual labourers whose fingerprints are worn and among the elderly, so the error is not randomly distributed but falls on the poorest.

An administrator who treats a 2% authentication failure rate as excellent performance has made a moral choice and not merely a technical assessment. The question is what happens to the 2%, and whether anyone is accountable for finding out.

Puttaswamy, DPDP and What Is Not Covered

In Justice K. S. Puttaswamy v. Union of India (2017) a nine-judge bench held unanimously that privacy is a fundamental right intrinsic to Article 21 and the freedoms in Part III. Its operative contribution is the proportionality test: an intrusion requires a law, a legitimate state aim, a necessary connection between means and aim with no less intrusive alternative, and procedural safeguards against abuse.

In the 2018 Aadhaar judgment the Court upheld the architecture while striking down the provision that let private bodies require authentication, narrowing the national-security disclosure clause, and holding that nobody should be denied a benefit for want of Aadhaar. That last direction is a proportionality holding stated as an operating instruction.

The Digital Personal Data Protection Act, 2023 builds on notice and consent, with a category of “legitimate uses” needing no consent — including the State’s provision of a subsidy, benefit, service or licence. It lets the Central Government exempt instrumentalities of the State from most of the Act, removed the public-interest override the Right to Information Act carried for personal information, and leaves enforcement to a Board appointed by the executive. Its practical effect is examined in the DPDP Act and data protection.

What no statute covers is surveillance itself. Interception rests on executive authorisation under the telecommunications and information technology statutes, reviewed by a committee of officials, with no judicial warrant and no parliamentary oversight; facial recognition, camera networks and predictive policing operate without dedicated legislation. Where the law is silent the question becomes an ethical one for whoever deploys the system.

The Administrator’s Duties, Stated as Engineering

Data minimisation, purpose limitation and privacy by design are usually presented as compliance requirements. They are moral principles in technical dress, and they reduce to five questions any officer running a database should be able to answer.

Who can query this, and on what authority? Role-based access, not a shared password, and not “the whole office”.

Is every query logged, and does anyone read the log? An audit trail nobody reviews is a record of misuse, not a control on it.

What is collected that is not needed? Every extra field is a liability with no offsetting benefit; the burden of justification belongs on collection, not deletion.

What happens when the system says no? There must be an offline or manual route, staffed and known to the front line, or the failure mode is denial.

Where does a wrongly excluded person go, and by when? A grievance channel without a deadline and a named officer is decoration — the point developed in accountability and responsibility.

Underlying all five is the choice of default. A system built on the presumption that claimants are probably fraudulent produces exclusion and calls it integrity; one built on the presumption of eligibility produces leakage and calls it service. Both are moral positions, and only one is usually stated.

The Honest Difficulties

Privacy conflicts with goods that are genuinely important. Targeted welfare needs to know who is poor. Epidemic control needs contact data. Criminal investigation needs communication records. An absolutist framing that treats every intrusion as a violation cannot be operated by anyone with a job, and stating the right as though it settles cases misdescribes it.

Deduplication has real benefits. Unique identification has removed duplicate and ghost entries from welfare rolls, and pretending otherwise concedes the argument to people who then ignore the costs. The honest position is that both the savings and the exclusions are real and that they fall on different people.

The test is justification, not prohibition. An intrusion is acceptable when it rests on a law, serves a legitimate aim, is the least intrusive available means, and is appealable by the person affected. Most Indian systems satisfy the first three in some form and fail the fourth almost entirely, which is why appeal — not consent — is the reform that would do the most work. If consent cannot be meaningful for a welfare beneficiary, loading the architecture onto consent shifts responsibility to the person with the least power.

FAQ

What does it mean to call privacy a moral claim rather than only a right? That the interest privacy protects — autonomy, dignity, the capacity to associate and dissent — exists whether or not a court has recognised it. The legal right supplies a remedy; it does not create the interest.

What is contextual integrity? Helen Nissenbaum’s idea that information flows carry norms from the context in which they occur, so a violation is an inappropriate onward flow rather than the disclosure of a secret.

What are the replies to the “nothing to hide” argument? That privacy protects against error and misuse as much as exposure; that the harm is aggregation rather than any single fact; and that the burden falls unequally on the vulnerable and the dissenting rather than on the conventional.

What is the difference between identification and authentication? Identification asks who a person is and requires a search across a population. Authentication asks only whether this person matches one record. Systems built for the second are routinely used for the first.

What is the proportionality test from Puttaswamy? An intrusion on privacy requires a law, a legitimate state aim, a necessary connection between means and aim with no less intrusive alternative, and procedural safeguards against abuse.

Why is exclusion error the central ethical problem in digital ID? Because a wrongly included beneficiary costs money while a wrongly excluded one loses food or medicine, and is by definition least able to appeal. The error also falls disproportionately on manual labourers and the elderly.

Practice Questions

Prelims MCQs

  1. Contextual integrity holds that a privacy violation consists in: (a) Disclosure of a secret (b) An information flow breaching the norms of the context in which it was shared (c) Collection without written consent (d) Storage outside national borders — Answer: (b) which is why “already public” is not a defence.
  2. In Justice K. S. Puttaswamy v. Union of India (2017), privacy was held to be: (a) A statutory right under the IT Act (b) A fundamental right intrinsic to Article 21 and Part III (c) A directive principle (d) A common-law right — Answer: (b) by a unanimous nine-judge bench.
  3. Which is not one of the prongs of the proportionality test? (a) Legality (b) Legitimate state aim (c) Least intrusive means (d) Prior consent of the data subject — Answer: (d) the fourth prong is procedural safeguards against abuse, not consent.
  4. Authentication, as distinct from identification, answers the question: (a) Who is this person, searched across a population (b) Whether this person matches one particular record (c) Whether this person is eligible for a benefit (d) Where this person resides — Answer: (b) eligibility is a separate question of authorisation.
  5. “Function creep” refers to: (a) Degradation of biometric accuracy (b) Use of an identifier for purposes beyond the one it was introduced for (c) Growth of storage capacity (d) Delay in grievance redressal — Answer: (b) a wrong distinct from any breach of the original purpose.

Mains Practice Questions

  1. “Privacy is a moral interest before it is a legal right.” Examine the goods it protects. (150 words)
  2. Evaluate the “nothing to hide” argument and the standard replies to it. (150 words)
  3. Why is consent an inadequate ethical foundation for data collection in welfare delivery? Suggest what should replace or supplement it. (250 words)
  4. “Exclusion error, not exposure, is the central moral harm of mandatory digital identity.” Critically examine. (250 words)
  5. An administrator runs a large citizen database. What duties follow from data minimisation, purpose limitation and privacy by design? (250 words)

Tell Google you want more of this.

Add Anantam IAS as a preferred source

One tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.

Share this

PDF

Abhishek Sharma Sir

Written by

Abhishek Sharma Sir

Faculty — Ethics & Essay · Anantam IAS

Abhishek Sharma teaches Ethics & Essay at Anantam IAS. He builds a usable ethics vocabulary — thinkers, case studies, terminology — and runs structured essay workshops that move students from clichéd openings to arguments that actually score.

Specialises in · Ethics, integrity and aptitude (GS-IV); Mains essay paper Experience · 10+ years Visit website ↗

GS IV is marked on structure, not on sincerity.

Ethics answers and case studies evaluated in writing by faculty — where the framework went missing, and where the conclusion dodged the decision.