Examine how the 'bystander privacy' problem challenges the fiduciary-principal model of India's data protection law.
In this answer
The Digital Personal Data Protection (DPDP) Act, 2023 is built on a two-party architecture — a Data Fiduciary that processes data and a Data Principal who consents [1]. AI-enabled wearables such as camera-equipped smart glasses capture a third party, the bystander, who consents to nothing and is invisible to this design.
The fiduciary–principal architecture and its assumption
- Duties of notice, purpose limitation and consent are owed to an identified Data Principal who approaches the fiduciary, with penalties up to ₹250 crore for breach [1].
- The model assumes a voluntary, traceable transaction — a user signing up for a service.
Where the bystander falls outside the frame
- A person filmed on the street is neither principal nor fiduciary; no consent nexus exists, so the Act's core rights (access, correction, erasure) have no addressee.
- Processing by an individual for a purely personal or domestic purpose is exempted, insulating the wearer even as data flows to cloud-based AI [1].
- The bystander cannot exercise grievance redressal before the Data Protection Board because they cannot identify what was collected.
Technological aggravation
- Continuous capture plus facial recognition converts a passive device into a real-time identification tool, eroding anonymity in public spaces.
- A covert form factor with an optional recording indicator defeats the notice principle on which consent regimes rest.
- MeitY's India AI Governance Guidelines (2025) adopt a techno-legal, largely voluntary approach relying on existing laws, leaving this gap unaddressed [4].
Constitutional dimension
- K.S. Puttaswamy (2017) located informational privacy within Article 21, but statutory operationalisation stops at the consenting user [2].
- Covert filming disproportionately endangers women and marginalised groups, chilling free movement.
The bystander problem shows that consent-centric law protects transacting users, not incidental subjects. The eighteen-month phased compliance window under the DPDP Rules, 2025 offers space to mandate device-level notice, tamper-proof recording indicators, and manufacturer accountability [3]. Extending the fiduciary's duty of care to foreseeable third parties would align the statute with the constitutional promise of privacy for all.
Sources
- 1The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), India Codefiduciary–principal architecture, consent and notice duties, personal/domestic-purpose exemption, ₹250 crore penalty ceiling
- 2Justice K.S. Puttaswamy (Retd.) v. Union of India, Supreme Court of India, 24 August 2017privacy, including informational privacy, as a fundamental right under Article 21
- 3PIB, "Government notifies DPDP Rules, 2025" (November 2025)notification of the Rules and eighteen-month phased compliance period
- 4PIB, "MeitY Unveils India AI Governance Guidelines under IndiaAI Mission" (5 November 2025)techno-legal, voluntary-measures approach relying on existing laws for AI risks