💥Join UPSC 2027,2028 Mentorship (August Batch) + XFactor Notes & Microthemes PDF

Digital India Initiatives

Saving faces: Use of facial recognition equipment at protest site is worrisome

Why in the News

The Delhi Police has told the Supreme Court that it deployed a facial recognition system at the site of the Cockroach Janta Party protests, along with a mobile surveillance van, a command and control vehicle, smart spectacles and drones. The disclosure came in the same proceeding. In that proceeding the force has continued to deny using excessive force or manhandling demonstrators, contrary to the protestors’ own testimonies. India is therefore normalising the technical ability to subject political gatherings to searchable biometric surveillance. Legislation and judicial oversight have not yet settled when the state may lawfully do so. The contest is between a policing capability that is already operational and a legal framework that names no threshold, no authorising authority and no retention rule for its use.

What is a facial recognition system?

  1. It converts a face into a searchable record: The system extracts measurable geometric features from a face image and stores them as a numeric template that can be matched against other templates.
  2. Two distinct operations, two different risk profiles: Verification matches one face against one claimed identity. Identification matches one face against an entire database, and only the second turns a crowd into a search.
  3. Real time capture removes the choice to participate anonymously: Cameras enabled with Artificial Intelligence (AI) scan faces as people move and run matches against a database without any interaction with the person scanned.

What surveillance equipment did the police say it had deployed?

  1. A facial recognition system with AI enabled cameras: These scanned faces in real time against a database. The demonstration was under way at the time.
  2. A mobile surveillance van: A vehicle mounted capture platform able to move with the crowd rather than covering a fixed field.
  3. A command and control vehicle: The on site node where feeds from the various capture devices were aggregated and acted on.
  4. Smart spectacles: Wearable devices used to identify individuals on the move, which extends identification beyond fixed and vehicle mounted cameras.
  5. Drones and videographers: Aerial and handheld recording covering the site from angles the ground cameras did not reach.
  6. Private contractors hold two of these systems: The van and the spectacles have been tied to private contractors on terms that have never been disclosed, so a commercial entity sits inside the capture chain on an unknown mandate.

What did the police not disclose?

  1. Whether every face in range was processed: The force has not addressed whether actual biometric processing occurred for every individual within the range of the cameras, which is the difference between targeted identification and mass capture.
  2. Where discarded images went: Images from checks that produced no match were open to copying in the interim, and the force has not said whether any copy survives.

Which laws currently govern facial recognition, and what do they leave open?

  1. No statute governs the technology: There is no law in force that regulates the use of facial recognition systems by the state, so deployment rests on executive decision alone.
  2. The data protection law is not yet operative on this point: The Digital Personal Data Protection Act, 2023, whose data processing obligations are not yet in force, still makes broad exemptions for state agencies.
  3. The existing police database is purpose limited: The Automated Facial Recognition System of the National Crime Records Bureau is meant for identifying criminals and unidentified bodies, not for scanning an assembly.
  4. The 2022 statute widened records, not subjects: The Criminal Procedure (Identification) Act, 2022 expanded the set of records the police may collect, but only from specified persons rather than from the public at large.
  5. The gap is the crowd: Every one of these instruments operates against identified groups of people, and none of them authorises indiscriminate capture of everyone present at a location.

Can mass biometric capture at a protest survive the proportionality test?

  1. The state carries the burden: Interference with the right to privacy must clear a well established proportionality test, and the burden of establishing each limb sits on the state.
  2. The first limb already fails on the facts: The existence of a legitimate objective is hard to establish for facial recognition used en masse, because the technology is indiscriminate at the point of capture and cannot be aimed at a suspect.
  3. A less restrictive alternative exists: Conventional policing achieves the same objective of maintaining order and identifying offenders without capturing the biometrics of every person present.
  4. Constitutional validity is not the only test: Even leaving aside the constitutionality of the police action, a capability deployed without a governing standard sets the precedent for the next deployment.

How does biometric surveillance affect the right to protest?

  1. The deterrent operates before any legal restriction: The chilling effect on potential participants curtails the right to protest without any order prohibiting the protest.
  2. Anonymity is part of the freedom: Assembly has historically carried the assurance that presence in a crowd is not the same as being recorded as an individual participant.
  3. The cost falls on people with the most to lose: Government employees, students facing institutional discipline and people in precarious work self select out once presence becomes a permanent identified record.
  4. The chill is unfalsifiable: Nobody counts the people who stayed home, so the harm never appears in the record a court would examine.

What remains unanswered before this use can be justified?

  1. The access controls: It is unknown which officers, agencies or contractor personnel could query the captured images and against which databases.
  2. The authorising legal provisions: The provisions relied on to authorise the major decisions, including the decision to scan an entire assembly, have not been identified.
  3. The false positive rate: The expected error rate of the system has not been stated, and a false match at a protest site produces detention of an innocent person on machine evidence.

Challenges to the regulation of facial recognition technology in India

  1. Deployment has run far ahead of legislation: State and city police forces have procured systems under general policing powers rather than under any enabling statute. Eg. Several State police departments and airports adopted facial recognition without a dedicated legal framework in place. Fix. Enact a facial recognition statute prescribing permitted purposes, a judicial or independent authorisation requirement, and a fixed retention period.
  2. The data protection statute exempts the principal user: Broad exemptions for state agencies mean the very actor conducting mass capture falls outside the consent and purpose limitation architecture. Eg. The Justice B N Srikrishna Committee had recommended narrow and specified exemptions rather than open ended ones on grounds of sovereignty and public order. Fix. Replace the blanket agency exemption with a case by case exemption that must be notified with reasons and laid before Parliament.
  3. Accuracy is unequal across populations: Error rates for facial recognition are consistently higher for darker skinned faces, women and younger subjects, so the burden of false matches is not evenly distributed. Eg. Independent testing of commercial systems has repeatedly found the highest error rates for darker skinned women. Fix. Mandate published accuracy testing disaggregated by skin tone, sex and age before any system is procured for policing use.
  4. Private contractors sit inside the state’s capture chain: Outsourcing capture hardware and processing places biometric data with entities that are not accountable through public law remedies. Eg. Police facial recognition deployments in several States run on vendor supplied platforms whose procurement contracts are not in the public domain. Fix. Require every surveillance procurement contract to be published with its data handling clauses, and make the contractor a joint respondent in any privacy proceeding.
  5. There is no oversight body with jurisdiction: No standing authority audits police biometric systems, so no institution can verify retention, deletion or match logs after the event. Eg. Agencies conducting interception under existing law are reviewed only by an internal executive review committee. Fix. Establish a statutory surveillance oversight commission with power to inspect match logs and order deletion.
  6. Function creep is the default trajectory: A database built for one purpose is progressively opened to others once the infrastructure exists. Eg. Facial recognition adopted for airport boarding convenience has been proposed for wider identity verification uses. Fix. Write a statutory bar on cross purpose querying, with each authorised purpose requiring a separate legislative amendment.

Conclusion

The disclosure establishes that the capability to convert a political gathering into a searchable biometric record is already deployed, contracted out in part, and operating without a statute that says when it may be used. The proportionality test, on the facts available, is not close: the technology captures indiscriminately, a less restrictive alternative exists, and the state has not identified the provision that authorised the decision. Until Parliament enacts a facial recognition law with a stated purpose, an authorising authority, a retention limit and published accuracy standards, each deployment simply widens the precedent for the next one.

“[2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023″


Join the Community

Free Daily News, Daily Prelims and Mains questions.