·The Hindu·15 marks·250–350 words

Right to Privacy is a fundamental right, but technology often outpaces law. Critically analyse in the context of AI-enabled surveillance devices.

In this answer
  1. Where the legal framework holds firm
  2. Where technology outpaces the law

In Justice K.S. Puttaswamy (2017), a nine-judge Bench unanimously held privacy to be a fundamental right under Article 21 [2]. Yet AI-enabled wearables — smart glasses combining cameras, microphones and facial recognition — reveal that while the constitutional promise is settled, statutory design trails technological capability.

Where the legal framework holds firm

  • Constitutional anchor: Puttaswamy laid down a proportionality test — legality, legitimate aim, necessity — applicable to any privacy intrusion, including surveillance [2].
  • Statutory architecture: the DPDP Act, 2023 imposes notice, purpose limitation and consent obligations on data fiduciaries, with penalties up to ₹250 crore [1][5].
  • Policy response: MeitY's India AI Governance Guidelines (November 2025) create an AI Governance Group, Technology & Policy Expert Committee and AI Safety Institute, applying transparency and accountability principles across sectors [3].

Where technology outpaces the law

  • The bystander gap: the DPDP Act rests on a two-party fiduciary–principal model; a person incidentally recorded in public is party to no consent relationship, and thus largely outside its protection [1][5].
  • No device-design mandate: nothing compels a visible recording indicator, defeating the "notice" principle that consent regimes presume.
  • Regulatory vacuum on facial recognition: India lacks a dedicated statute for FRT, even as real-time identification of strangers becomes technically feasible.
  • Soft law limits: the AI Guidelines are largely voluntary and recommendatory, not enforceable obligations [3].
  • Comparative lag: the EU AI Act expressly prohibits real-time remote biometric identification in public spaces, barring narrow exceptions [4].

Thus the deficit is not of rights but of enforceable design and third-party safeguards. Extending DPDP obligations to device manufacturers, mandating tamper-proof recording indicators, and framing FRT rules consistent with the proportionality test would let regulation move with innovation rather than behind it — realising Article 21's guarantee that anonymity in public spaces is not surrendered by default.

Sources

  1. 1The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYfiduciary–principal consent architecture, penalty ceiling, absence of bystander coverage
  2. 2Justice K.S. Puttaswamy (Retd.) v. Union of India, WP(C) 494/2012, Supreme Court of India, 24 Aug 2017privacy as a fundamental right under Article 21; proportionality test
  3. 3India AI Governance Guidelines, MeitY (PIB, November 2025)AI Governance Group, AI Safety Institute, voluntary/techno-legal approach
  4. 4EU AI Act: first regulation on artificial intelligence, European Parliamentprohibition on real-time remote biometric identification in public spaces
  5. 5Summary: The Digital Personal Data Protection Bill, 2023, PRS Legislative Researchobligations of data fiduciaries and rights of data principals

More from this note