Facial recognition at CJP protest raises questions over privacy, data protection
The presence of the AI-enabled facial recognition technology van Ikshana at Jantar Mantar during the recently concluded Cockroach Janta Party protests has raised serious questions
The presence of the AI-enabled facial recognition technology van Ikshana at Jantar Mantar during the recently concluded Cockroach Janta Party protests has raised serious questions about privacy violations, data protection and the responsibilities of the government. Petitions have also been filed in the Delhi High Court challenging the deployment of such technology against a citizens' protest led by students and young people, particularly amid fears of protesters being targeted and profiled, and the possible impact on their careers and studies. Read Full Story The use of artificial intelligence (AI) and facial recognition technology by law enforcement agencies in India has grown significantly in recent years, particularly in the aftermath of the 26/11 Mumbai terror attacks. Police forces across several states have begun deploying facial recognition systems and drones to assist with surveillance and policing. However, these technologies have largely been introduced without any specific legislative framework governing their use, raising serious questions about privacy, accountability and the protection of personal data. The absence of a dedicated legal framework has become particularly significant following the Supreme Court's landmark judgment in Justice K.S. Puttaswamy v. Union of India, which recognised the right to privacy as a fundamental right. In the wake of this judgment, the legality of surveillance systems such as the Central Monitoring System (CMS), NATGRID and NETRA has been challenged before the Delhi High Court on the ground that they infringe individual rights without any statutory basis. The Union government has maintained that while the right to privacy is a "sacred fundamental right" and is respected by the State, privacy is not absolute. In submissions before the Delhi High Court in 2021, the Centre argued that the "veil of privacy" may be lifted where there is a legitimate state interest. According to the government, lawful interception, monitoring or decryption of messages or information stored in computer resources is carried out only by authorised agencies and only after obtaining approval from the competent authority in each case.
However, the hearing in the matter has remained pending since 2021 after the case was transferred to the Supreme Court at the Centre's request. There has been no effective hearing on the issue in either the High Court or the Supreme Court. The debate becomes more complex in the context of facial recognition technology. Unlike ordinary video surveillance, facial recognition systems actively analyse faces, create biometric templates and compare them with existing databases to identify individuals. This involves the processing of highly sensitive personal data and raises concerns that extend beyond conventional CCTV monitoring. According to Prashant Sugathan, Legal Director at the Software Freedom Law Center (SFLC), active facial recognition is fundamentally different from routine video recording by the police. He argues that the technology maps an individual's face against databases, creating a direct privacy concern. In his view, once facial data is mapped and linked to databases, it constitutes a definite violation of privacy. He also cautions that the widespread deployment of such technology effectively treats every individual as a suspect rather than limiting surveillance to persons under investigation. India's legal position on personal data protection is currently in transition. The Digital Personal Data Protection Bill, 2022, released by the Ministry of Electronics and Information Technology (MeitY), proposed broad exemptions for processing personal data for purposes such as preventing, detecting or investigating the contravention of any law. However, according to cyber law expert and Senior Advocate Pavan Duggal, the Digital Personal Data Protection Act does not automatically exempt the government from its obligations. The presumption is that government agencies are also covered unless they are specifically exempted. According to Duggal, a crucial aspect of the current legal landscape is that, as matters stand, the Digital Personal Data Protection Act has not yet become operational. The Act is scheduled to come into effect on November 13, 2026, when the relevant notification takes effect. "At present, neither the Data Protection Board nor the agencies responsible for implementing the law have been notified.
