Right to Privacy is a fundamental right, but technology often outpaces law. Critically analyse in the context of AI-enabled surveillance devices.
In Justice K.S. Puttaswamy (2017), a nine-judge Bench unanimously held privacy to be a fundamental right under Article 21 [2]. Yet AI-enabled wearables — smart glasses combining cameras, microphones and facial recognition — reveal that while the constitutional promise is settled, statutory design trails technological capability.
Where the legal framework holds firm
- Constitutional anchor: Puttaswamy laid down a proportionality test — legality, legitimate aim, necessity — applicable to any privacy intrusion, including surveillance [2].
- Statutory architecture: the DPDP Act, 2023 imposes notice, purpose limitation and consent obligations on data fiduciaries, with penalties up to ₹250 crore [1][5].
- Policy response: MeitY's India AI Governance Guidelines (November 2025) create an AI Governance Group, Technology & Policy Expert Committee and AI Safety Institute, applying transparency and accountability principles across sectors [3].
Where technology outpaces the law
- The bystander gap: the DPDP Act rests on a two-party fiduciary–principal model; a person incidentally recorded in public is party to no consent relationship, and thus largely outside its protection [1][5].
- No device-design mandate: nothing compels a visible recording indicator, defeating the "notice" principle that consent regimes presume.
- Regulatory vacuum on facial recognition: India lacks a dedicated statute for FRT, even as real-time identification of strangers becomes technically feasible.
- Soft law limits: the AI Guidelines are largely voluntary and recommendatory, not enforceable obligations [3].
- Comparative lag: the EU AI Act expressly prohibits real-time remote biometric identification in public spaces, barring narrow exceptions [4].
Thus the deficit is not of rights but of enforceable design and third-party safeguards. Extending DPDP obligations to device manufacturers, mandating tamper-proof recording indicators, and framing FRT rules consistent with the proportionality test would let regulation move with innovation rather than behind it — realising Article 21's guarantee that anonymity in public spaces is not surrendered by default.
Sources
- 1The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYfiduciary–principal consent architecture, penalty ceiling, absence of bystander coverage
- 2Justice K.S. Puttaswamy (Retd.) v. Union of India, WP(C) 494/2012, Supreme Court of India, 24 Aug 2017privacy as a fundamental right under Article 21; proportionality test
- 3India AI Governance Guidelines, MeitY (PIB, November 2025)AI Governance Group, AI Safety Institute, voluntary/techno-legal approach
- 4EU AI Act: first regulation on artificial intelligence, European Parliamentprohibition on real-time remote biometric identification in public spaces
- 5Summary: The Digital Personal Data Protection Bill, 2023, PRS Legislative Researchobligations of data fiduciaries and rights of data principals