·The Hindu·15 marks·250–350 words

Examine how the 'bystander privacy' problem challenges the fiduciary-principal model of India's data protection law.

In this answer
  1. The fiduciary–principal architecture and its assumption
  2. Where the bystander falls outside the frame
  3. Technological aggravation
  4. Constitutional dimension

The Digital Personal Data Protection (DPDP) Act, 2023 is built on a two-party architecture — a Data Fiduciary that processes data and a Data Principal who consents [1]. AI-enabled wearables such as camera-equipped smart glasses capture a third party, the bystander, who consents to nothing and is invisible to this design.

The fiduciary–principal architecture and its assumption

  • Duties of notice, purpose limitation and consent are owed to an identified Data Principal who approaches the fiduciary, with penalties up to ₹250 crore for breach [1].
  • The model assumes a voluntary, traceable transaction — a user signing up for a service.

Where the bystander falls outside the frame

  • A person filmed on the street is neither principal nor fiduciary; no consent nexus exists, so the Act's core rights (access, correction, erasure) have no addressee.
  • Processing by an individual for a purely personal or domestic purpose is exempted, insulating the wearer even as data flows to cloud-based AI [1].
  • The bystander cannot exercise grievance redressal before the Data Protection Board because they cannot identify what was collected.

Technological aggravation

  • Continuous capture plus facial recognition converts a passive device into a real-time identification tool, eroding anonymity in public spaces.
  • A covert form factor with an optional recording indicator defeats the notice principle on which consent regimes rest.
  • MeitY's India AI Governance Guidelines (2025) adopt a techno-legal, largely voluntary approach relying on existing laws, leaving this gap unaddressed [4].

Constitutional dimension

  • K.S. Puttaswamy (2017) located informational privacy within Article 21, but statutory operationalisation stops at the consenting user [2].
  • Covert filming disproportionately endangers women and marginalised groups, chilling free movement.

The bystander problem shows that consent-centric law protects transacting users, not incidental subjects. The eighteen-month phased compliance window under the DPDP Rules, 2025 offers space to mandate device-level notice, tamper-proof recording indicators, and manufacturer accountability [3]. Extending the fiduciary's duty of care to foreseeable third parties would align the statute with the constitutional promise of privacy for all.

Sources

  1. 1The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), India Codefiduciary–principal architecture, consent and notice duties, personal/domestic-purpose exemption, ₹250 crore penalty ceiling
  2. 2Justice K.S. Puttaswamy (Retd.) v. Union of India, Supreme Court of India, 24 August 2017privacy, including informational privacy, as a fundamental right under Article 21
  3. 3PIB, "Government notifies DPDP Rules, 2025" (November 2025)notification of the Rules and eighteen-month phased compliance period
  4. 4PIB, "MeitY Unveils India AI Governance Guidelines under IndiaAI Mission" (5 November 2025)techno-legal, voluntary-measures approach relying on existing laws for AI risks

More from this note