Why in the News
Meta’s smart glasses, which can discreetly record video and audio of anyone around the wearer, have renewed concerns over surveillance and consent, and over how far the Digital Personal Data Protection Act, 2023 actually protects a bystander who never agreed to be recorded. The Supreme Court’s nine-judge Bench in Justice K.S. Puttaswamy v. Union of India (2017) held privacy to be a fundamental right intrinsic to Article 21, developing a three-part legality-necessity-proportionality test for any restriction on it. Wearable recording devices normalised for everyday use test that framework in a setting the 2017 judgment did not anticipate: a bystander with no relationship to the device’s owner, and no practical way to know they are being recorded.
Why do smart glasses expose a specific gap in India’s privacy framework?
- The Digital Personal Data Protection Act, 2023 is built around consent, which a bystander cannot give: The Act’s core protection mechanism requires a data principal’s consent before personal data is processed, a structure that assumes a data subject who is a party to the transaction, not a bystander recorded without their knowledge by someone else’s device.
- No dedicated framework for covert or discreet recording devices: Existing privacy protections address data processing by an identifiable data fiduciary, typically a company or platform, not the diffuse, device-level recording enabled by consumer wearables carried by private individuals.
- Enforcement depends on the bystander detecting the recording: Because smart glasses are designed to record discreetly, a bystander has no practical way to exercise any of the rights the 2023 Act grants a data principal, since exercising those rights first requires knowing that one’s data was processed at all.
- Cybercrime figures already show a rising surveillance-adjacent harm pattern: National Crime Records Bureau data has recorded a rising trend in cybercrime cases involving unauthorised recording and image-based harassment, a pattern smart-glasses-style wearables are positioned to accelerate.
Conclusion
Smart glasses expose a structural gap between a consent-based data protection framework and a recording technology that operates on people who never consented to anything. Closing that gap requires provisions specific to covert or ambient recording devices, rather than relying on the same consent architecture built for data fiduciaries processing information from their own users.
What is the Right to Privacy, and what does it protect?
- About: The Right to Privacy is a fundamental right, read into Article 21’s guarantee of life and personal liberty, protecting an individual’s control over personal information, bodily integrity, and personal decisions from unjustified interference by the State.
- Rationale: The right exists because personal autonomy, from choice of partner to control over one’s own data trail, is treated as intrinsic to human dignity rather than a privilege the State may withdraw.
- Named typology: The Supreme Court in Puttaswamy (2017) recognised several strands within the right: informational privacy over personal data, decisional autonomy over intimate personal choices, bodily integrity against intrusive procedures, and digital privacy against online surveillance.
- Proportionality test for restrictions: Any state action restricting privacy must meet a three-part test: legality (backed by law), a legitimate aim, and proportionality between the means used and the aim pursued.
- Institutional gap in independent oversight: Agencies such as the Intelligence Bureau, the Research and Analysis Wing, and the National Investigation Agency operate without a dedicated, independent body reviewing their surveillance activity for privacy compliance.
- Colonial-era laws still authorise interception: Provisions in the Telegraph Act continue to authorise phone tapping under standards that predate the Puttaswamy proportionality test, creating a mismatch between old authorisation powers and the newer constitutional standard.
- Corporate data harvesting outside individual awareness: Technology platforms collect and monetise personal data at a scale most users do not track or understand, a form of privacy erosion the Digital Personal Data Protection Act, 2023 only partially addresses through its consent and purpose-limitation provisions.
- Low digital literacy limits the exercise of privacy rights: Citizens frequently do not know what data they have given consent to share, or how to invoke the correction and erasure rights the 2023 Act grants them.
Challenges in protecting the right to privacy
- Mass surveillance without independent judicial oversight: Interception and surveillance decisions in India are authorised through executive processes rather than prior judicial warrant. Eg. Allegations around the use of Pegasus spyware against journalists and activists in 2021 raised exactly this oversight gap. Fix. Introduce a judicial or quasi-judicial warrant requirement before any interception order takes effect, replacing the current executive-only authorisation.
- National-security exemptions in the 2023 Act draw criticism: The Digital Personal Data Protection Act, 2023 permits government agencies to be exempted from several of its obligations on national security and public-order grounds. Eg. Government bodies notified under the Act’s exemption provisions are not bound by the same data-minimisation and purpose-limitation duties private data fiduciaries face. Fix. Require any national-security exemption to be time-bound and reviewed periodically by an independent oversight body rather than granted as a standing exemption.
- Corporate surveillance through data-driven advertising: Large technology platforms build detailed behavioural profiles from data users hand over without meaningfully understanding the trade-off. Eg. Targeted political and commercial advertising built on granular user profiling has drawn regulatory scrutiny in multiple jurisdictions. Fix. Mandate clear, layered consent disclosures under the 2023 Act’s rules that separate necessary data use from optional profiling-based use.
- Health data retention concerns from pandemic-era tools: Contact-tracing and health applications built during the COVID-19 pandemic raised unresolved questions about how long the government retains the health data those apps collected. Eg. Aarogya Setu’s data retention and sharing practices drew sustained criticism from privacy researchers. Fix. Set a statutory data-retention ceiling for any health-emergency application, with automatic deletion once the stated public-health purpose ends.
- No dedicated authority solely focused on privacy enforcement: The Data Protection Board established under the 2023 Act adjudicates complaints but does not function as a proactive privacy regulator auditing surveillance practices across government and industry. Fix. Expand the Data Protection Board’s mandate to include periodic, unprompted audits of large-scale surveillance and data-processing systems, government and private alike.
Back2Basics: Digital Personal Data Protection Act, 2023
- India’s first standalone law on personal data processing, built around consent as the primary legal basis for processing, with defined exceptions for legitimate uses such as employment and government functions.
- Creates the Data Protection Board of India as the adjudicatory body for data-protection complaints and penalties.
- Grants data principals rights to access, correct, and erase their personal data, and imposes purpose-limitation and data-minimisation duties on data fiduciaries.
- Permits the government to exempt specified agencies from several of the Act’s obligations on national security and public-order grounds, a provision that has drawn criticism for its breadth.
Matching Previous Year Question
“[2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023”
