·The Hindu·15 marks·250–350 words

Wearable AI devices like smart glasses expose a structural gap in India's data protection framework. Discuss with reference to the DPDP Act, 2023.

In this answer
  1. The Act's two-party architecture
  2. Where wearables break the model
  3. Compounding risk: identification

In K.S. Puttaswamy (2017) the Supreme Court read informational privacy into Article 21 [3], and the Digital Personal Data Protection Act, 2023 operationalised it [1]. Yet camera-and-microphone smart glasses record people who never entered any consent transaction, revealing a design gap rather than a mere enforcement failure.

The Act's two-party architecture

  • The DPDP Act is built on the Data Fiduciary–Data Principal relationship: consent is sought from the person whose data is being collected as a user [1].
  • Obligations — notice, purpose limitation, erasure, breach reporting — all flow from that bilateral link, backed by penalties up to ₹250 crore [1].
  • The Act applies to digital personal data collected online or digitised offline [2], but presumes an identifiable fiduciary processing data of a consenting principal.

Where wearables break the model

  • A glasses wearer captures bystanders — passers-by, patients, employees — who are neither users nor parties to any notice; the "third party in the frame" is unaddressed [1].
  • The personal/domestic use exemption shields individual recording, while the manufacturer's duties run only to its own customer, leaving a liability vacuum [2].
  • Notice, the hinge of consent, fails technologically: a recording-indicator LED is a voluntary design choice, not a statutory mandate.

Compounding risk: identification

  • Pairing wearable cameras with facial recognition converts anonymity in public into instant identification; India still lacks a dedicated FRT statute, NITI Aayog's Responsible AI framework being advisory only [4].
  • Harms fall unevenly on women, minors and marginalised groups, where covert filming enables stalking and doxxing.

The gap is structural: a consent architecture designed for platforms cannot govern devices that collect data ambiently. India should mandate tamper-proof recording indicators as a device certification condition, extend duties to hardware manufacturers, and regulate biometric identification separately — as the EU AI Act does by restricting real-time remote biometric identification in public spaces [5]. Anchoring such rules in Puttaswamy's proportionality test would let innovation proceed without hollowing out Article 21.

Sources

  1. 1The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), MeitYData Fiduciary–Data Principal architecture, consent and notice obligations, ₹250 crore penalty ceiling
  2. 2PRS Legislative Research — Summary, The Digital Personal Data Protection Bill, 2023scope of application and personal/domestic-use exemption
  3. 3Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), Supreme Court of Indiaprivacy as a fundamental right under Article 21
  4. 4NITI Aayog, *Responsible AI for All* — discussion paper on Facial Recognition TechnologyFRT governed by advisory principles, no dedicated statute
  5. 5Council of the EU — Artificial Intelligence Actrestrictions on real-time remote biometric identification in public spaces

More from this note