Rohan Yadav & Akshat Pundir are second year students at MNLU, Mumbai

Introduction: The Dual Mandate of AI-Driven Surveillance in India

The deployment of Artificial Intelligence in India’s public infrastructure is accelerating at an unprecedented rate, establishing a sophisticated surveillance ecosystem from the nationwide deployment of the ambitious Automated Facial Recognition System (AFRS) intended for all police forces to the rapid integration of facial recognition technology under the Smart City mission and at railway stations, This technological leap, however, presents a fundamental challenge to the core constitutional democracy: can the security imperative of the state be reconciled with the fundamental right to privacy? When we closely examine India’s current policy structure, we unravel a critical and ever-widening gap due to the excess powers granted to the state, insufficient oversight mechanisms, and a systemic lacuna in ensuring adequate safeguards to enable a modern surveillance system.

The Constitutional Bedrock: A High Bar for State Power

The foundation for the protection of privacy rights in India through constitutional safeguards is unambiguously high. In a landmark ruling by the Supreme Court in 2017, it was declared in K.S. Puttaswamy v. Union of India, that the right to privacy is an intrinsic and inalienable component of the right to life and personal liberty under Article 21, marking a paradigm shift  in India’s privacy jurisprudence by explicitly overruling earlier precedents of M.P. Sharma v. Satish Chandra (1954) and Kharak Singh v. State of U.P. (1962), which had denied recognition of privacy as a fundamental right. The Court’s unanimous verdict acknowledged that these earlier rulings incorrectly dismissed privacy as a Western construct, failing to appreciate its fundamental importance to individual dignity, autonomy, and liberty in a modern democratic society.

Consequent to the ruling,  the Court formulated a three-pronged test to ascertain circumstances where the State could encroach upon an individual’s private matters under this right:

1. The intrusion must come through a statute, which is reasonable, non-arbitrary, and specific.

2. The provision must provide a legitimate objective for the state, including public welfare, national security, or justifiable criminal deterrence.

3. The state must prove that the surveillance method it chooses is the least intrusive way to achieve a legitimate public safety goal. This ensures the government never uses a ‘sledgehammer’ of mass surveillance to address a minor regulatory ‘nut.’

As India deploys increasingly sophisticated surveillance systems, varying from facial recognition networks to centralized monitoring platforms, the recent DPDP Act has created paradoxes rather than solutions. While in theory, it mandates user consent for data processing; yet in practice, government agencies bypass these requirements through large security exemptions permitted under broadened interpretations Section 17. As a consequence,  laws authorize indefinite data retention for a 75-year period, facial matching without warrants, and surveillance deployments through executive orders rather than parliamentary legislation. Together, these statutory gaps actively undermine the constitutional safeguards embedded in Article 21, the right to privacy and personal liberty as illustrated by the above tests. Rather than merely ‘questioning’ these protections, India’s regulatory framework systematically erodes them through legislative design rather than accidental omission.

India’s Patchwork of Law: Exemptions and Arbitrary Retention

The use of biometrics and facial recognition technologies in India is currently based on a series of heterogeneous legislations, of which none specifically pertain to the real-time use of facial recognition at a mass scale.

The Digital Personal Data Protection Act, 2023 (DPDP Act), while designed to be the primary data protection statute, requiring explicit, informed consent for the processing of personal data, it contains a major limitation with respect to state surveillance. The Act grants the Central Government broad authority to exempt its own instrumentalities from almost any or all of the law’s provisions in the interest of state security or public order. These provisions create a critical inconsistency, that is while the Act mandates strict standards for consent and data protection for private sector data processing, government agencies are exempted from the same requirements, effectively negating the Act’s protective framework for state surveillance. Furthermore, when comparing the provisions of the DPDP Act to its global counterparts such as the GDPR, we see that while the latter provides explicit ‘special category’ protections for the handling of biometric data, the former incorporates weaker safeguards, by exempting government agencies in its entirety, leaving enforcement with minimal statutory and regulatory oversights.

The Criminal Procedure (Identification) Act, 2022 (CPIA), establishes a notable precedent by significantly augmenting state authority through the extensive expansion of biometric data collection to encompass palm prints, iris/retina scans, and physical/biological samples, beyond conventional capturing of fingerprints. It also broadly expands the scope of persons by allowing data collection from individuals arrested for not only major crimes, but also minor violations such as rash and negligent driving (carrying a maximum penalty of six months imprisonment), violating prohibitory orders under Section 163 of the BNSS (often deployed against peaceful protesters), or disobeying lawful authority under Section 188 of the BNSS (fined as little as ₹2,500).

What is more concerning is that the National Crime Records Bureau (NCRB) has been authorised by this act to retain any of this sensitive data in a central database for 75 years. Even in circumstances where individuals are eventually acquitted or released without trial, the law mandates retention of their data, with the exception of an explicit direction by the court to the contrary. The mandate for a 75-year retention period, entrenching as far as for acquitted or discharged individuals directly violates the proportionality standard for privacy established in the Puttuswamy judgement, where the Supreme Court  had established that surveillance must be the least intrusive means necessary; indefinite retention of biometric data for citizens found innocent of criminal charges fails this test.

Today, FRT deployment typically involves reliance on executive ordinances by the state rather than through a particular statute, a direct contravention of the ‘Legality’ requirement of the Puttaswamy test. While the Facial Recognition Technology (Regulation of Police Powers) Bill, 2023 (a private member’s bill) has been brought into debate to deal with this, it has yet to come into effect. Yet, it was a significant stepping stone calling for significant protections, such as required judicial approval (order from a magistrate) prior to FRT use during investigations and express prohibitions on employing FRT to profile someone on the basis of race, religion, or gender. Its non-enactment continues to perpetuate a regulatory void wherein facial recognition systems operate while being outside the ambit of constitutional constraints, leaving no protections against prospective discriminatory surveillance or profiling,  no accountability for police misuse, and no legal remedy for citizens subjected to invasive facial matching without judicial authorization.

The Ground Reality: Inaccuracy, Bias, and the Chilling Effect

There is no doubt that this regulatory gap poses substantial risks in India’s biggest cities. There are serious technological problems with these systems that make them hard to use.  Algorithmic prejudice is a big problem around the world. It means that facial recognition algorithms are less accurate at detecting women and persons with darker skin tonesReports say that the police’s FRT system in Delhi only got 2% of the missing youngsters right and had trouble telling boys and girls apart.  This indicates that a biased and redundant technology is being used to legitimise the huge growth of state authority, which puts innocent people, especially those in marginalised areas, at a higher risk of being wrongly identified and investigated, leading to the violation of constitutional protection against arbitrary detention and the constitutional presumption of innocence under Article 21, as citizens face investigation based on algorithmic error rather than evidence. Marginalized communities feel impacted by  the disproportionate impact, concerned by the breach of Article 14’s principles of equality of law and equal protection before laws. Inaccuracy renders all proportionality claims moot: if surveillance fails to accurately identify suspects, it cannot be justified as necessary.

Mass adoption of facial recognition surveillance is gradually leading to the alteration of relationship between citizens and the state in public spheres. These concerns crystalize in  recent instances such as those involving the Hyderabad police’s documented practice of forcing citizens to remove masks for unwarranted facial photography, as evidenced in the #BantheScan campaign by Amnesty International or the deployment of  CCTVs in Delhi to keep an eye on anti-CAA protesters. This targeted surveillance has a demonstrable “chilling effect.” on individuals’ fundamental freedoms of speech and peaceful assembly under Articles 19(1)(a) and 19(1)(c).

The reasonable expectation of anonymity in public life, which facilitates democratic participation, dissolves under such haphazard adoption of technology. As​‍​‌‍​‍‌​‍​‌‍​‍‌ a result, people absorb as a norm that any kind of public participation, for instance, being in citizens protests, speaking at public meetings, or even just walking through streets, will be followed by continuous facial tracking and recording in surveillance systems. If citizens are not able to conceal their identity, they logically limit their right to free expression which they have counted as a given in the Constitution and thus the public sphere, a space originally meant for democratic expression turns into a panopticon of state ​‍​‌‍​‍‌​‍​‌‍​‍‌surveillance.

Global Lessons: Proportionality and Strong Oversight

India should take notes from states, such as the member nations of the EU, the US and the UK, that have incorporated rights-based frameworks for surveillance and the use of AI, so as to take effective measures against breaches of privacy through surveillance technology.

By adopting a dual approach, the EU handles biometric data with utmost caution.  The GDPR (General Data Protection Regulation) categorizes biometric data used for unique identification as a Special Category of personal data, typically forbidding its processing without a clear legal basis. In addition to the GDPR, the EU AI (Regulation) Act implements a classification framework, identifying facial recognition technology (FRT) as “High-Risk” and has explicitly forbidden certain practices involving this technology, including collection and management of real-time remote biometric identification in public spaces for law enforcement, except under narrowly defined exceptions, such as for targeted searches for victims of trafficking or missing persons; prevention of imminent threats to life or physical safety, including terrorist attacks; or identification of suspects for serious crimes carrying maximum custodial sentences of at least four years under national law. Even in these cases, deployment requires prior judicial or independent administrative authorization, completion of an assessment on the impact on fundamental rights, and places strict limitations on their temporal, geographic, and personal scope.

Unlike the European Union’s centralized regulatory approach, the United States lacks a comprehensive federal legislation governing the use of biometric surveillance. Instead, state-based regulatory fragmentation characterizes the American landscape. For instance, Illinois enacted the Biometric Information Privacy Act (BIPA) in 2008, mandating private businesses to seek express and written consent before collecting any form of biometric data and grants a private right of action, enabling individuals to litigate against businesses for infringement, as illustrated in the precedents of Rogers v. BNSF Railway (2022), the first suit under BIPA, which tried to jury verdict, awarding $228 million in damages (imposing a penalty of $5,000 per violation × 45,600 instances of unconsensual storage of fingerprint scans of drivers) and Patel v. Facebook (2020), which resulted in a $550 million settlement when Facebook’s “Tag Suggestion” facial recognition feature collected user facial data without consent, establishing a strong, enforceable deterrence. Moreover, municipal districts such as Portland and San Francisco have implemented extensive prohibitions on the official utilization of facial recognition technology, wherein Portland’s prohibitions extend to both city government and private entities in places of public accommodation, including restaurants, retail stores, hotels, and entertainment venues, whereas, San Francisco’s prohibitions apply to city agencies and public sector deployment only.

These examples highlight the urgent need for India to move beyond broad legislation and establish technology-specific regulations, supported by independent oversight and direct accountability mechanisms.

Conclusion – The Path to Reform: A Call for Proportionality

The unregulated proliferation of mass face recognition technology systems, intensified by the exemptions in the DPDP Act and the overly expansive retention provisions of the CPIA, presents a substantial threat to constitutionally safeguarded privacy rights.

A specific statute regulating the adoption of FRT, based on the suggestions of the 2023 bill, is required to clearly delineate boundaries, forbid capricious application, and override the extensive authorities conferred by existing statutes, eventually meeting the threshold set by the Puttuswamy test.

Adoption of compulsory judicial oversight by utilization of FRT in law enforcement must necessitate a mandatory, precise, and specified magistrate’s order for each occurrence, guaranteeing that its application is essential and commensurate with the offence.

Under such new laws, there should be provisions for the public to access annual reports detailing the results of impartial third-party evaluations of all face recognition technology systems to assess algorithmic bias and fairness. To ensure algorithmic accountability, public officials and enforcement agencies like the police force should be subject to public audits to prove they are following non-discrimination regulations.

The arbitrary 75-year data retention period of the CPIA should be substituted with a stringent data minimization principle.  Biometric data must be destroyed immediately upon the conclusion of an investigation or the acquittal/discharge of the individual, consistent with the proportionality demanded by Article 21.  

India is at a pivotal crossroads.  The decisions taken today with respect to AI surveillance and its regulation will dictate whether technology functions as a tool for improved public safety, while being bound by the framework of constitutional democracy, or transforms into a key for widespread, unregulated control.  Legislative reform is essential; it is a fundamental obligation to safeguard the promise of liberty articulated in Article 21 in the digital era.

Share this post