
India AI Surveillance: Constitutional Privacy Rights Tested
Summary
- India extensively uses AI surveillance, including facial recognition in projects like Safe City and NATGRID, but lacks specific laws regulating police use of this technology.
- The 2017 Puttaswamy judgment established privacy as a fundamental right, requiring proportionality for any state infringement.
- The Digital Personal Data Protection Act, notified in November 2025, includes broad exceptions for state data processing under national security, limiting its protective scope.
- The Pegasus spyware case exemplifies how national security justifications can classify information and complicate accountability for state surveillance.
- Constitutional challenges based on the Puttaswamy judgment remain the primary legal recourse against potential privacy infringements by state AI surveillance, given current regulatory gaps.
The Expanding Reach of AI Surveillance in India
Constitutional challenges, primarily rooted in the `Puttaswamy judgment`, remain the most potent legal recourse against potential privacy infringements by state AI surveillance, given current regulatory gaps.
Across India's urban landscape, state-sponsored artificial intelligence (AI) surveillance systems are increasingly prevalent, utilizing CCTV cameras equipped with facial recognition technology in public spaces such as airports and shopping malls. These systems are designed to identify individuals and monitor their movements in the physical world. While such technology can serve beneficial purposes, like tracking missing persons or apprehending criminals, its widespread deployment raises significant questions about individual privacy.
Notable government initiatives underscore this trend. The Safe City Project, for instance, integrates CCTV networks with facial recognition and behavioral analytics across various cities, ostensibly for the security of women and children. Similarly, the National Intelligence Grid (NATGRID), a comprehensive database allowing security agencies access to information from banks, telecommunication providers, and immigration systems, was further enhanced in December 2025 with additional AI and facial recognition capabilities. These developments highlight a growing reliance on advanced surveillance tools.
However, the application of these technologies extends beyond conventional security concerns. Recent incidents, such as the police deployment of facial recognition vans to photograph and identify participants during student protests against examination leaks, illustrate the broader potential for their use. This particular event also brought to light a critical legal void: India currently lacks specific legislation governing the use of facial recognition technology by its police forces.
Constitutional Safeguards and Their Limits
The foundational legal framework for privacy in India was significantly strengthened by the landmark 2017 Supreme Court decision in `Justice K.S. Puttaswamy vs. Union of India`. A nine-judge bench unanimously declared the right to privacy a fundamental right, not merely a state-granted privilege, embedding it within Articles 14, 19, and 21 of the Constitution. This ruling established that any infringement upon this fundamental right must adhere to a principle of proportionality, meaning intrusions must be limited and not excessive to be considered justified.
Despite this constitutional safeguard, the state frequently invokes "national security" as a broad justification for surveillance activities, making it challenging to assess the legitimacy of such interventions. While the `Puttaswamy judgment AI surveillance` framework mandates a proportionality test, the practical application often faces hurdles when state actions are cloaked under the umbrella of national security. This creates a tension between the individual's fundamental right to privacy and the state's asserted need for extensive surveillance.
A Regulatory Vacuum Amidst Broad State Powers
The absence of a dedicated `facial recognition technology India law` for police operations represents a significant legal lacuna. While Parliament attempted to address data protection concerns with the `Digital Personal Data Protection Act`, which was notified in November 2025, this legislation does not fully close the gap concerning state surveillance. Instead, the Act includes sweeping `Digital Personal Data Protection Act state exceptions`, allowing the state to process personal data broadly under the guise of national security, thereby potentially undermining its protective intent.
The implications of such broad exceptions are evident in cases like the `Pegasus spyware` controversy. Despite allegations from media and activists regarding the targeting of individuals with military-grade spyware, the results of a government-appointed technical committee remain classified as sensitive information due to national security considerations. An earlier court hearing even saw the bench comment that there was nothing inherently wrong with a country utilizing spyware, further highlighting the challenges in holding state surveillance accountable when national security is invoked.
Implications for Fundamental Rights and Legal Recourse
The confluence of widespread `India AI surveillance constitutional privacy` concerns, the absence of specific regulatory frameworks for technologies like facial recognition, and the broad state exceptions within new data protection laws creates a precarious environment for fundamental rights. The very infrastructure designed for security, such as the `India Safe City Project privacy` measures or `NATGRID AI surveillance India` capabilities, can readily be repurposed against groups like protesters, striking workers, or journalists, as demonstrated by past and ongoing events.
Given this landscape, legal professionals and compliance officers in India must recognize the substantial legal vacuum surrounding state-led AI surveillance, particularly regarding facial recognition. Understanding that constitutional challenges, primarily rooted in the `Puttaswamy judgment`, remain the most potent legal recourse against potential privacy infringements is crucial. The expansive `Digital Personal Data Protection Act state exceptions` mean that individuals and organizations must often look to the higher constitutional principles to safeguard privacy against state overreach, especially when `AI surveillance national security India` justifications are invoked.
Practical Implications
Lawyers and compliance officers in India should be aware of the significant legal vacuum concerning state-led AI surveillance, especially facial recognition, and understand that constitutional challenges based on the Puttaswamy judgment remain the primary legal recourse against potential privacy infringements, given the broad state exceptions in the new Digital Personal Data Protection Act.
Source
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Wansom is AI and can make mistakes.
