💥Mains Ready By December. Smash Mains & Smash PYQ Admissions Open

Subject: Data Protection

  • Inside India’s problem with reporting child sexual abuse material

    Why in the News

    The National Human Rights Commission (NHRC) has issued notices to two Union ministries and the Delhi Police over paid Instagram advertisements. The advertisements allegedly used search terms such as “rape video” and “child video” to direct users to Telegram channels offering child sexual abuse material (CSAM). The Commission has directed that an Action Taken Report reach it within two weeks. The advertisements had passed the review systems of Meta, which owns Instagram, and remained available until the company’s attention was drawn to them. Two questions follow from that failure: whether the statutory duty to report the offence was complied with, and whether a platform whose artificial intelligence systems actively shape content can still claim the legal protections available to intermediaries.

    What is a CyberTipline report?

    1. An alert raised by the platform: A CyberTipline report is generated when a technology platform detects suspected child sexual abuse material and refers it for law enforcement follow up.
    2. It locates the material, not its source: A report often identifies where the material was found, not where it originated, and establishing origin requires a separate investigation.
    3. How it reaches an Indian investigator: Reports are processed by the National Crime Records Bureau (NCRB) and the Indian Cybercrime Coordination Centre (I4C), and are then routed and assigned to the relevant State and district authorities.

    What has the Commission asked of the platform?

    1. Whether the offences were reported at all: Meta has been asked whether the alleged offences were reported, and, if they were not, to identify those responsible for ensuring compliance.
    2. The duty lies on any person: Section 19 of the Protection of Children from Sexual Offences (POCSO) Act, 2012 requires any person who apprehends that an offence under the Act is likely to be committed, or who knows one has been committed, to report it to the Special Juvenile Police Unit or the local police.
    3. Internal processes do not discharge it: The Commission’s stated position is that the obligation cannot be substituted by internal correspondence, grievance redressal or regulatory engagement.

    Is a platform that shapes content still an intermediary?

    1. The systems do more than host: A supplementary representation before the Commission argued that Meta’s artificial intelligence assisted tools generate captions, recommend posting schedules, optimise engagement and assist monetisation.
    2. The classification question has been referred: The Ministry of Information and Broadcasting has been asked to examine whether such functions remain consistent with intermediary status, or whether they resemble the role of a publisher of online curated content under the Information Technology Rules, 2021.
    3. The stake in the answer: Intermediary status carries protection from liability for content that others post. A publisher of curated content carries responsibility for what it puts out.

    How many reports arrive, and how many become cases?

    1. The volume: India received around 1.9 million CyberTipline reports in 2025.
    2. The conversion is small: Only a fraction of those reports translate into police action.
    3. Verification precedes registration: Authorities conduct a preliminary verification before a first information report is registered, and not every report progresses beyond that stage.

    Where does a report stall before an FIR?

    1. Report quality varies: The reports vary significantly in quality and completeness, so many cannot carry a preliminary verification at all.
    2. A prima facie test on the material: Investigators assess whether the flagged material prima facie depicts child sexual abuse material. Once jurisdiction is identified and the material verified, the case is forwarded to the local police station or cyber police unit.
    3. Age is the recurring obstacle: Verifying the age of the victim is among the more recurring difficulties, since poor image quality, blurred visuals or uncertainty about age obstruct that finding.
    4. Attribution comes last: Only once a first information report is registered do investigators begin identifying the individual behind the account.

    What decides the outcome in court?

    1. A designated forum: Cases are generally tried before the special courts designated under the POCSO Act.
    2. Convictions turn on digital evidence: Defence arguments frequently focus on whether the accused was actually the person using the device, the SIM card or the internet connection linked to the offence.
    3. An unidentified offender ends the case: Where investigators cannot identify the person responsible, police may file a closure report.

    Challenges to CSAM detection and prosecution in India

    1. Encryption removes the point of detection: Offenders increasingly use encrypted platforms, where the service provider cannot scan content and therefore generates no report at all. Eg. End to end encrypted messaging leaves no server side copy for a platform to match against a database of known material.
      The Fix: Require significant platforms to report metadata level signals, such as advertising keywords and channel invitation links, where the content itself is not visible to them.
    2. Synthetic material defeats hash matching: Detection relies on matching a file against databases of known material, and newly generated images produce no match. Eg. Images of children produced by generative models carry no prior hash record.
      The Fix: Extend detection to classifier based models and recognise synthetic child sexual abuse material explicitly as an offence in the governing statute.
    3. The reporting duty has no platform specific machinery: Section 19 places the duty on any person, and prescribes no route by which a foreign incorporated platform files with an Indian police unit. Eg. Reports currently arrive through the CyberTipline chain rather than as a statutory filing by the company.
      The Fix: Prescribe a designated reporting channel and a fixed filing deadline for significant social media intermediaries under the Information Technology Rules.
    4. Judicial expansion has outpaced investigative capacity: The offence has been widened by the courts, and district cyber units have not grown to match it. Eg. In Just Rights for Children Alliance v. S. Harish (2024) the Supreme Court held that storing and viewing child sexual abuse material is itself an offence under Section 15 of the POCSO Act.
      The Fix: Fund district cyber forensic units and a national facility for medical and forensic age estimation, so verification is not left to the investigating officer’s judgement.

    Conclusion

    Detection is not the constraint in this system. The constraint sits between an automated alert and a chargeable case, where verification, jurisdiction and identification each remove a share of what was reported, and a closure report is the default outcome when identification fails. A platform whose systems recommend, caption and monetise what appears on it is not simply carrying what other people post, and the protection designed for a passive carrier does not obviously fit it. How the Ministry of Information and Broadcasting answers that classification question is the thing to watch.

    Back2Basics: National Human Rights Commission

    1. A statutory body: The NHRC was constituted under the Protection of Human Rights Act, 1993, and is not a constitutional body.
    2. Composition: It has a Chairperson and members, with the chairpersons of specified national commissions, including the National Commission for Protection of Child Rights, as ex officio members.
    3. Powers: It inquires suo motu or on a petition into a violation of human rights or negligence in preventing one, and holds the powers of a civil court for that inquiry.
    4. Limits: Its findings are recommendatory, and it can require the concerned government to report the action taken on them.

    Matching Previous Year Question

    “[2017] In India, it is legally mandatory for which of the following to report on cyber security incidents? 1. Service providers 2. Data Centres 3. Body corporate Select the correct answer using the code given below: (a) 1 only (b) 1 and 2 only (c) 3 only (d) 1, 2 and 3 ANSWER: (d)”

  • Focus on the children, not the platform

    Focus on the children, not the platform

    Why in the News

    Meta has settled a $171 billion case with several United States States over allegations about the effect of its apps on children’s mental health. The settlement requires daily usage limits and “nighttime blocks” for teenagers. It requires “enhanced age assurance measures” (checks intended to establish a user’s age before access is granted) to keep children off the apps. It also requires the depersonalisation of feeds, so a child is served random content rather than content matched to that child’s interests. The outcome is being read as a step towards holding platforms accountable. That framing places the platform at the centre of the problem rather than the child, and the two framings do not produce the same policy.

    Why does a platform centric approach to child safety misfire?

    1. The measures are difficult to enforce: An age gate assumes a child will not defeat it, while children are sophisticated and motivated users of technology who find ways around such checks.
    2. It ignores what children need to be safe online: Poorly designed recommendation systems expose children to harmful content, and stripping personalisation replaces that risk with irrelevant or inappropriate material. It also makes it harder for educational and support services to reach the children who need them.
    3. Online spaces are the only support some children have: Children experiencing neglect or abuse, LGBTQIA+ children and socially isolated children use platforms to find information, companionship or help. A child’s participation is not confined to one service, so a platform that becomes too restrictive simply loses them to platforms with weaker protections.
    4. The offline environment is what pushes children online: In India screens fill a vacuum rather than displacing abundant offline opportunities, because many children have no access to safe public spaces or affordable recreational facilities.

    What would a child centred approach ask for instead?

    1. Equip the child, as is done in the physical world: Children are taught what not to share, how to respond to unsolicited contact, how to recognise manipulation, when to block or report someone, and when to seek help.
    2. Treat digital literacy as the instrument, not the afterthought: Digital literacy and sensitisation are what change a child’s behaviour at the moment a technical control fails, and they receive far less policy attention than platform obligations.
    3. Address the whole ecology of childhood: Responsibility sits across platforms, parents, schools, communities, public spaces and children themselves, so a measure aimed at one of the six leaves the other five untouched.

    Why does the harder answer receive less policy attention?

    1. A platform obligation is visible and countable: A regulator can order a control, verify that it shipped, and record compliance, none of which a curriculum or a public playground delivers on the same timescale.
    2. India’s move so far is a recommendation, not a mandate: The 2026 Economic Survey called for a digital wellness curriculum in schools, and whether it is implemented widely and appropriately is untested.
    3. The effective lever sits outside the regulator’s reach: Digital literacy runs through school systems and recreational space runs through municipalities, while enforcement powers sit with technology and data protection regulators.
    4. The argument does not absolve platforms: Platform responsibility survives intact, and the contest is over which lever produces a safer child rather than over whether platforms owe anything at all.

    Conclusion

    Child online safety is presently measured by the number of controls a service ships. The better measure is what a child is able to do when a control fails, and the settlement model produces no information about that at all. The capability side of the problem belongs to schools, parents and municipalities. The enforcement side belongs to a technology regulator, and nobody owns the gap between the two.

    Child Online Safety in India

    1. What the field covers: The rules governing children’s access to online services, the data those services may collect about a child, and the content they may direct at one.
    2. How India regulates it: Through due diligence obligations on intermediaries under technology law and consent rules under data protection law, rather than through a single children’s online safety statute.
    3. Who counts as a child: Indian data protection law treats every person below 18 as a child, a higher threshold than the 13 year line used in United States children’s privacy law.

    Laws and Rules Governing Child Online Safety

    1. Information Technology Act, 2000, amended in 2008: The parent statute for offences committed through a computer resource, carrying Section 66D on cheating by impersonation and Section 69 on interception.
    2. Section 67B separately punishes publishing or transmitting material depicting children in sexually explicit acts.
    3. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, amended in 2023: Impose due diligence, grievance redressal and content takedown obligations on intermediaries.
    4. Digital Personal Data Protection Act, 2023, with the Digital Personal Data Protection Rules, 2025: Govern consent, data fiduciary duties, breach notification and the Data Protection Board of India.
    5. Section 9 requires verifiable parental consent before a child’s personal data is processed, and bars tracking, behavioural monitoring and advertising targeted at children.
    6. Protection of Children from Sexual Offences Act, 2012: Defines and punishes sexual offences against persons below 18, covers offences committed using electronic material, and makes reporting mandatory.

    [2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023.

  • US settlement with Meta is a start. India must protect itself

    US settlement with Meta is a start. India must protect itself

    Why in the News

    Meta has agreed to pay up to $17.1 billion to resolve child harm claims brought by a bipartisan coalition of attorneys general across the United States, its territories and the District of Columbia.

    What does the settlement require Meta to do?

    1. The scale and the date: The agreement was reached on 26 August and ranks among the largest consumer protection settlements in internet history.
    2. Default time limits and night restrictions: Users under 18 get default limits on time spent and restrictions on night time use.
    3. Limits on notifications during school hours: The company must curb notifications sent to minors while school is in session.
    4. Age assurance: The settlement requires enhanced measures to establish whether a user is a minor before the account is treated as an adult account.
    5. Independent compliance oversight: Compliance with the safeguards is monitored by an independent party rather than reported by the company itself.

    Why does the penalty carry little punitive weight?

    1. The sum is small against the revenue base: The company generated $201 billion in revenue in 2025, and the settlement is payable over 10 years.
    2. The market read it as a cost, not a shock: The stock rose 5 per cent after the settlement was announced.
    3. The reforms are the substance, not the money: The mandated safety changes go to how Facebook and Instagram are allowed to operate for minors, and they are overdue rather than novel.

    Why has India’s own debate produced no comparable outcome?

    1. The cycle is episodic and self closing: A tragedy occurs, outrage follows, a platform issues a statement, a parliamentary question may be asked, and silence returns.
    2. The harm is not less serious here: The absence of Indian legal action reflects the absence of a process capable of compelling answers, not a smaller problem.
    3. Regulatory attention has been lighter than in the West: Global platforms have operated in India with weaker oversight and lower public awareness than they face in other large markets.

    What did the American case produce that India lacks?

    1. Court compelled discovery: The litigation forced the company to produce internal research, design documents and executive communications about child safety, under oath, in public and subject to cross examination.
    2. The questions India cannot currently ask: What internal research shows about the mental health impact on Indian teenage girls, how the recommendation engine behaves in Hindi, Tamil and Bengali for a fourteen year old at 11 pm, and how many Indian children under 13 are active on platforms that legally prohibit their membership.
    3. The unmeasured scale of abuse material: The scale of child sexual abuse material affecting Indian users and the manner of its reporting are not on any public record. Eg. In the United States alone, 7.5 million such materials were under internal review.
    4. Whether the same design was applied here: If the addictive design features at issue in the American cases were applied to Indian users, those users have been exposed to the same harm with none of the protection.

    What legal tools does India already hold?

    1. The statutory base already exists: The Consumer Protection Act, 2019, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Protection of Children from Sexual Offences (POCSO) Act, 2012, the Juvenile Justice (Care and Protection of Children) Act, 2015 and the Constitution together cover the conduct alleged.
    2. A regulator level inquiry: The National Commission for Protection of Child Rights (NCPCR), the statutory body for child rights, can open a formal inquiry compelling platforms to produce India specific safety research, algorithm documentation, data on underage users and internal harm research.
    3. Direct recourse for families: Affected families can approach consumer forums and High Courts directly, without waiting for a regulator to act first.
    4. Coordinated State litigation: State governments can file consumer protection and child safety suits in Indian courts, and a single State moving first can trigger a wider set of filings.
    5. The policy standard is already stated: The Safe, Trusted and Accountable framework developed in 2021 was built so that platforms operating at scale bear legal responsibility for the consequences of their design choices.

    Why is new legislation still needed?

    1. Existing law compels disclosure only case by case: Each of the routes above produces documents inside one proceeding, so nothing survives the case that produced it.
    2. A statutory right to algorithmic disclosure: Parliament can create an obligation on platforms to reveal their content moderation policies, recommendation engine parameters and child safety research for Indian users.
    3. A standing recipient rather than a court: The disclosure would run to a designated Indian authority, which turns a litigated exception into a continuing duty.

    Challenges to compelling platform disclosure in India

    1. No child rights regulator holds standing discovery power: A statutory commission can summon information, and it cannot compel sworn production of internal research open to cross examination. Eg. Platform responses to Indian regulators are routinely filed as written submissions rather than as evidence tested in a hearing.
      The Fix: Give the child rights commission discovery powers with a stated penalty for non production, on the model available to a commission of inquiry.
    2. Consumer forums cannot read algorithmic evidence: A district or State consumer commission has no technical assessor able to interpret recommendation engine documentation. Eg. Consumer adjudication in India is built around defective goods and deficient services, not around product design telemetry.
      The Fix: Attach a standing panel of technical assessors to the National Consumer Disputes Redressal Commission for platform cases.
    3. The evidence sits outside Indian process: Internal research and design documents are held on servers abroad and reached through mutual legal assistance. Eg. Mutual legal assistance requests to the United States for platform records routinely take more than a year to return.
      The Fix: Write a production obligation for India specific safety research into intermediary due diligence, so the duty attaches to operating in India rather than to where a server sits.
    4. Safe harbour blunts liability for design: Section 79 of the Information Technology Act, 2000 shields intermediaries for third party content, and design and ranking choices are argued into that shelter. Eg. Platforms have defended recommendation ranking as an automated function rather than as an editorial act.
      The Fix: Separate design and ranking decisions from hosting in the due diligence rules, so safe harbour covers content and not product architecture.

    Conclusion

    Platform accountability in India has been argued at the level of statements and outrage, never at the level of evidence. The material that would establish whether Indian children were exposed to the same design choices sits with the platforms, and no Indian process currently compels its production. Legislation would convert that into a standing duty, and litigation would produce it once. The marker to watch is whether any Indian regulator or State government files an action carrying discovery powers, rather than another request for information.

    Online child safety in India

    1. What the domain covers: It governs how platforms design products for users below 18, across age of access, consent, exposure to content and collection of data.
    2. The regulatory age is higher than the platform age: Indian data protection law treats anyone below 18 as a child, while platforms set their own account creation floor at 13.
    3. States have moved before the Centre: Karnataka announced plans to bar social media for those under 16, and Andhra Pradesh announced restrictions for those under 13.
    4. The evidence base cited officially: Research highlighted in the Economic Survey 2025-26 records that adolescents lack the neurological brakes needed to resist addictive features such as infinite scroll.

    Laws and Rules Governing Online Child Safety

    1. Digital Personal Data Protection Act, 2023: It treats any individual below 18 as a child, requires verifiable parental consent before processing a child’s data, and prohibits behavioural tracking and targeted advertising directed at children.
    2. The Data Protection Board of India adjudicates breaches and imposes penalties under the Act, with appeals lying to the Telecom Disputes Settlement and Appellate Tribunal.
    3. Information Technology Act, 2000: Section 67B criminalises publishing or transmitting material depicting children in sexually explicit acts, and extends to browsing and downloading such material.
    4. Indian Penal Code and Bharatiya Nyaya Sanhita provisions on obscenity: They cover sale and circulation of obscene material to a person under 20, and operate alongside the specialised child protection statutes.

    Key Facts about Online Child Safety

    1. Australia set a minimum age of 16 for social media accounts through the Online Safety Amendment (Social Media Minimum Age) Act 2024, enforced from December 2025.
    2. Indonesia became the first Southeast Asian country to enforce a ban for under 16s, in March 2026.
    3. Gaming disorder is classified as a health condition in the World Health Organization’s International Classification of Diseases, Eleventh Revision (ICD-11).
    4. Kerala runs Digital De-Addiction centres, known as D-DAD centres, for children showing signs of compulsive device use.

    Challenges in Online Child Safety

    1. Age verification is easily circumvented: A minimum age holds only where the platform can establish age, and self declared dates of birth cannot be checked. Eg. Children open accounts on platforms barring under 13s using a false year of birth or an adult family member’s account.
      The Fix: Move to privacy preserving age estimation processed on the device, rather than to identity document uploads.
    2. Verification itself creates a new privacy risk: Establishing age through selfies, identity documents or bank details assembles a fresh database of minors’ sensitive data. Eg. Document based age checks require a child to hand a platform the exact identifiers the law is trying to keep from it.
      The Fix: Require age signals to be discarded once the check is complete, with a bar on retaining the underlying document.
    3. A ban pushes use underground: Restriction moves minors to less regulated services and to tools that hide their location. Eg. Teenagers migrate to smaller platforms or route access through virtual private networks.
      The Fix: Replace a binary ban with a graduated model, strict restriction under 13, supervised access from 13 to 15, and full access at 16.
    4. Restriction removes support networks for some children: Online communities are the only peer support available to some minors, and a blanket bar cuts that too. Eg. LGBTQ+, neurodivergent and disabled children frequently depend on such communities.
      The Fix: Exempt verified support, counselling and helpline services from minor account restrictions.

    [2025, GS2, 15 marks] The National Commission for Protection of Child Rights has to address the challenges faced by children in the digital era. Examine the existing policies and suggest measures the Commission can initiate to tackle the issue.”

  • Police camera ‘caught’ murder, rape accused at Jantar Mantar protest

    Police camera ‘caught’ murder, rape accused at Jantar Mantar protest

    Why in the News

    The Delhi Police has told the Supreme Court that its Facial Recognition System (FRS) spotted 2,873 people with criminal antecedents at the main protest site at Jantar Mantar between 20 and 26 July. The submission follows a Supreme Court order quashing every First Information Report (FIR) arising from the exam leak student protests.

    What is the Delhi Police’s Facial Recognition System?

    1. What the software does: It places boxes around faces detected in a camera feed and compares them against images held in police databases.
    2. The threshold for a positive match: A match is treated as positive at an accuracy rate of 80 per cent, a figure the force disclosed in a 2022 reply under the Right to Information (RTI) Act, 2005.
    3. What it searches against: Of the 2,873 flags, 2,402 were attributed to Crime Kundli, the force’s own biometric database, and 471 to criminal records.
    4. What the output is not: A match is not by itself proof of identity, and performance varies with the algorithm, camera angle, lighting, image quality, masks and the database being searched.

    What does the offence-wise breakdown in the affidavit show?

    1. The residual category is the largest by far: 1,884 of the 2,873, close to two thirds, sit under other Indian Penal Code, Bharatiya Nyaya Sanhita and special law entries rather than under any named serious offence.
    2. The legal status of those flagged is unstated: The affidavit does not specify whether the people identified were accused, convicts, or merely named in criminal cases.
    3. The database is claimed to hold only serious offenders: The affidavit states that the face and other material of only those accused facing serious offences are in the police record, and not those facing petty offences such as traffic violations.
    4. The geographic concentration: The North district recorded the highest count at 285, followed by Outer at 257, North West at 256, North East at 174, East at 173 and South West at 166. Railways, Crime Branch, IGI Airport, Metro and the Special Cell were among the other units listed.

    What did the record check of 205 flagged individuals find?

    1. The sample examined: The 205 comprised 101 murder accused, 61 rape accused, 6 accused under the Protection of Children from Sexual Offences (POCSO) Act, 2012, and 37 of the 62 listed under attempt to murder.
    2. The finding: At least 25 of them were lodged in the Tihar, Mandoli or Rohini prison complexes at the time the system flagged them, according to police, jail and court records.
    3. The composition of the 25: 17 were accused in murder cases, 4 in rape cases of which 3 were under the POCSO Act, and 4 in attempt to murder cases.
    4. The dates of the flags: Three of the 25 were identified on 24 July, 21 on 25 July and one on 26 July, the final day of the protest.

    Why does the police assurance not settle the question?

    1. Verification is the only safeguard on record: The stated position is that action follows only after field verification establishes that the person was in fact present at the site, and no verification standard, timeline or reporting duty accompanies that assurance.
    2. Verification is still pending at scale: The force has stated that further verification of the identified individuals is pending, which leaves 2,873 names on a list that a court has already permitted the government to act on.
    3. The accuracy threshold is an internal setting, not a legal standard: An 80 per cent match is a configuration choice inside the software, and no statute, rule or judicial direction fixes what confidence level may be relied on before a person is named.
    4. The error is not random noise: People held in custody were placed at a protest site by the system, which points to database and matching failure rather than to a borderline image.

    Challenges to facial recognition in policing

    1. No statutory basis governs deployment: India has no law authorising or limiting police use of facial recognition, so procurement, matching thresholds and retention are set administratively. Eg. The Delhi Police’s 80 per cent threshold became public only through a Right to Information reply, not through a published rule.
      The Fix: Require prior legislative authorisation and a published operating standard for any biometric identification system before it is deployed in a public space.
    2. Accuracy falls sharply for some groups: Error rates in facial recognition are higher for darker skin tones, women and younger faces, so the burden of a false match is not evenly spread. Eg. The United States National Institute of Standards and Technology’s evaluation of commercial algorithms recorded higher false positive rates across demographic groups.
      The Fix: Mandate a published demographic error audit of the deployed algorithm before each operational use, with results filed with the sanctioning authority.
    3. The system was built for one purpose and used for another: A database assembled to trace missing persons or match crime scene images becomes a crowd screening tool without any fresh authorisation. Eg. The Delhi Police’s facial recognition capability was originally acquired for tracing missing children.
      The Fix: Attach a statutory purpose limitation to each biometric database, so any new use requires a separate written sanction that is placed on record.
    4. Surveillance at a protest changes who turns up: Recording and matching faces at an assembly deters lawful participation independently of any action that follows. Eg. Cameras mounted on police vans at the Jantar Mantar site were visible to those attending.
      The Fix: Bar identification of participants at a lawful assembly except on a written order naming a specific cognisable offence under investigation.
    5. There is no route to contest a match: A person flagged by the system is not told, so the error surfaces only if a journalist or a court checks the records. Eg. The 25 custodial mismatches came to light through a newspaper’s record check, not through any internal review.
      The Fix: Require written notice to every individual against whom a biometric match is acted on, with a stated procedure to seek correction of the underlying record.

    Conclusion

    A facial match is being treated as a sufficient basis to proceed against a named list, while the force’s own position is that a match establishes nothing on its own. Both cannot hold at once. Nothing on record fixes what field verification must consist of, who performs it, or who checks that it happened. The point to watch is whether the Court requires the verification outcome for each flagged individual to be filed before any action follows.

    [2024] Under which of the following Articles of the Constitution of India, has the Supreme Court of India placed the Right to Privacy?

    (a) Article 15

    (b) Article 16

    (c) Article 19

    (d) Article 21

  • In India, a hard limit for X’s transparency pledge

    In India, a hard limit for X’s transparency pledge

    Why in the News

    X has pledged to publicly disclose government censorship and content-removal requests, while MeitY has warned that such disclosures may violate India’s Section 69A blocking framework.

    What is the Section 69A blocking framework?

    1. Statutory basis: Section 69A of the Information Technology Act, 2000 empowers the Union government to direct an intermediary to block public access to online content on specified grounds.
    2. The operative rules: The Information Technology (Blocking) Rules, 2009 are the framework under which a blocking direction is issued and acted on.
    3. Rule 16 mandates secrecy: It requires strict confidentiality over all blocking requests and the actions taken on them.
    4. Non-compliance is a criminal offence: An intermediary that fails to comply attracts imprisonment up to seven years.

    What exactly does the pledge collide with?

    1. The pledge names three disclosures: X proposes to publish that an order exists, which body issued it, and on what basis it was issued.
    2. Rule 16 forbids each of the three: The confidentiality mandate covers the existence of a request, its author and its stated grounds alike.
    3. Secrecy is what enables an unreasoned block: Confidentiality lets the executive block content without a reasoned public order and without notifying the person whose content is blocked.
    4. The liability lands on individuals: X’s Indian entity carries resident compliance and grievance officers, so criminal consequences attach to identifiable people inside the country.

    Does the announced mechanism do what was claimed?

    1. The release paired two separate things: X open-sourced its “Phoenix” recommendation code alongside a pilot feature called “Under the Hood”.
    2. Under the Hood shows platform labels, not state orders: It gives selected users visibility labels on their own accounts, such as spam flags and reach restrictions.
    3. A blocking order runs on a separate track: A Section 69A order operates outside that feature entirely.
    4. The user still sees only the old notice: The withheld content carries a “withheld in India” label naming neither the order nor the agency.

    Why does Section 69A no longer describe the whole takedown picture?

    1. Order volumes have roughly quadrupled: Section 69A orders rose from about 6,000 a year through 2023 to about 24,300 in 2025.
    2. A second route now carries a growing share: Since a 2023 MeitY memorandum, ministries, States and police issue orders under Section 79(3)(b) of the same Act.
    3. The Sahyog portal is the channel: Those orders are routed through the Ministry of Home Affairs portal, which X calls a censorship portal.
    4. An unreasoned order leaves nothing to publish: Where an order arrives without a stated basis, X has little to surface even if it intended to.

    What does X’s own compliance record show about the pledge?

    1. The stated identity is free speech absolutism: X brands itself in those terms.
    2. Actual compliance runs between 83 and 99 per cent: That is the share of demands the platform acts on.
    3. One order covered 2,355 accounts: In July 2025 X said the government ordered that many accounts blocked, including Reuters, within an hour.
    4. Objection was followed by compliance: X objected loudly and then complied, restoring the Reuters account only after a public outcry.

    Where does the litigation now stand?

    1. The Karnataka High Court dismissed the challenge: In September 2025 it rejected X’s petition against the Sahyog portal and called the portal “an instrument of public good”.
    2. Parallel proceedings ran in Bombay: X’s appeal and its Bombay petitions were consolidated.
    3. The Supreme Court stayed all four in July 2026: No court has ruled on the merits of the disclosure question.

    Challenges to the Section 69A blocking framework

    1. Blocking orders are never published: The framework produces no public record of what was blocked or why, so its use cannot be reviewed by anyone outside the executive. Eg. Directions issued during the farmers’ protest in 2021 covering over a thousand accounts were never published in any form.
      The Fix: Publish a redacted version of every blocking direction carrying the ground invoked, withholding only operational detail.
    2. The person whose content is blocked is rarely heard: The 2009 Rules provide for notice to the originator where identifiable, and in practice the intermediary alone appears before the committee. Eg. In Shreya Singhal v. Union of India (2015) the Supreme Court upheld Section 69A partly on the strength of that hearing, which originators seldom receive.
      The Fix: Make service of notice on an identifiable account holder a condition of validity of a blocking direction.
    3. Emergency powers bypass the review committee: An interim block can be ordered by the Secretary, Information Technology, before the committee that is meant to examine it has met. Eg. The 2020 ban on 59 Chinese applications was issued as an interim emergency measure under this framework.
      The Fix: Cap an emergency block at 48 hours unless the committee ratifies it within that period.
    4. Section 79(3)(b) carries none of the 69A safeguards: Safe harbour is lost on a government notification alone, with no committee, no periodic review and no defined issuing authority. Eg. Thousands of police units and State departments can issue takedown notices through a single portal.
      The Fix: Extend the 2009 Rules’ committee examination and periodic review to every order issued under Section 79(3)(b).
    5. Enforcement is aimed at individuals rather than the company: Criminal liability on a resident grievance officer converts a corporate regulatory dispute into personal jeopardy for an employee. Eg. The resident officer requirements of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 were challenged on exactly this ground.
      The Fix: Confine non-compliance penalties to corporate monetary fines, and reserve imprisonment for wilful obstruction established in court.

    Conclusion

    A platform cannot publish what a statute makes an offence to publish, whatever it announces. The pledge and the confidentiality mandate are not two competing policies. They are a company’s stated practice set against a criminal provision, and only a court can move one of them. What remains unresolved is whether transparency about a restriction on speech is itself part of the speech that is being restricted, since no Indian judgment has answered that question. The marker to watch is the disposal of the consolidated challenge now before the Supreme Court.

    Laws and Rules Governing Online Content Regulation in India

    1. Information Technology Act, 2000: The parent statute governing electronic records, cyber offences and the obligations of intermediaries.
    2. Section 69A grounds: Blocking is permitted on grounds of sovereignty and integrity of India, defence, security of the State, friendly relations with foreign States, public order, and preventing incitement to a cognisable offence relating to these.
    3. Section 79 safe harbour: An intermediary is not liable for third party content it hosts, provided it observes due diligence, and it loses that protection where it fails to act on a government notification.
    4. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021: Impose due diligence on intermediaries, require significant platforms to appoint a resident grievance officer, and fix timelines to acknowledge and resolve complaints. Amended in 2023.
    5. Digital Personal Data Protection Act, 2023: Governs the processing of digital personal data and establishes the Data Protection Board of India to adjudicate breaches.
    6. Telecommunications Act, 2023: Provides for interception and for suspension of telecommunication services on grounds of public emergency and public safety.
    7. Bharatiya Nyaya Sanhita, 2023: Criminalises circulation of false information likely to cause public disorder and speech promoting enmity between groups.
    8. Cable Television Networks (Regulation) Act, 1995: Regulates television content through a Programme Code barring material that threatens communal harmony or national security.

    [2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023.

  • How social media hooks children — Meta’s $17-billion settlement over addictive design

    Why in the News

    Meta, the owner of Facebook and Instagram, has agreed to pay up to $17.1 billion in penalties to 47 US states, Washington DC and other territories, and to make binding changes to its products, over claims that it endangered children through addictive design and violated child privacy norms. The settlement follows a March jury verdict in KGM v. Meta et al, where a Los Angeles jury held Meta and Google liable for $6 million in damages after finding that platform features contributed to a young user’s mental health harm. Indian regulators are studying the settlement as a possible template even as the Centre weighs age-based restrictions, usage limits and stronger parental consent requirements for children’s access to social media, discussions that remain at an early stage.

    What has Meta agreed to change, and why does the design focus matter?

    1. A default two-hour daily cap across both apps: Meta will impose a combined two-hour daily limit on Facebook and Instagram for under-18 users, cumulative across multiple accounts, changeable only by a verified parent, with direct messaging excluded.
    2. Time-boxed access at night and during school hours: Teen users will be blocked from most parts of the platforms between midnight and 6 am, with most push notifications disabled between 10 pm and 7 am and muted between 8 am and 3 pm on school weekdays.
    3. Engagement features are curbed by default: The settlement provides a non-personalised feed option, hides like and reaction counts by default, restricts cosmetic-procedure filters, and requires usage prompts after every 15 minutes of continuous scrolling.
    4. Compliance is externally audited: Meta must hire an independent auditor to assess compliance with the safeguards for five years, addressing an issue exposed at the KGM trial, where only 1.1 percent of teen users had activated an existing optional daily-use limit.

    Why do experts see the design-focused approach as more significant than the payout?

    1. The settlement forces architectural change, not just policy change: A US legal academic notes this is the first US instance of a major platform being forced to change the “architecture of its product” rather than only its stated policies, arguing the design changes matter more than the settlement figure.
    2. Default settings determine real-world reach: A researcher at Common Sense Media expects the universal, default time and night-mode limits to have real effect, while the optional recommendation and engagement changes will reach fewer teens because a parent must actively enable them.
    3. Compliance is not the same as harm reduction: A policy scholar cautions that measuring compliance with a feature checklist is different from measuring actual outcomes, and argues independent researchers need real data access on sleep, wellbeing and compulsive-use patterns to know if the changes work.
    4. Recommendation algorithms remain the open question: Critics note the changes do not fully address the recommendation systems that encourage continued scrolling, with one researcher’s biggest unresolved question being how removing algorithmic recommendations changes what teens are shown and re-engage with.

    What evidence links social media design to youth mental health harm?

    1. Large-scale studies link engagement to anxiety and depression: A 2024 meta-analysis of 143 studies involving over one million adolescents found greater social media engagement associated with higher levels of anxiety and depression.
    2. Specific design features have identifiable mechanisms of harm: A Johns Hopkins researcher identifies appearance-based social comparison, visible like counts and overnight notifications as features with clear mechanisms of psychological impact.
    3. Reducing use shows measurable benefit: A 2025 randomised controlled trial of 220 young people found that cutting smartphone-based social media use to about one hour a day for three weeks reduced depression, anxiety and fear of missing out, and improved sleep; a 2026 trial found a similar reduction in loneliness after cutting use by about 78 minutes a day.
    4. Academic performance is also affected: A 2025 systematic review of 34 studies found off-task social media and smartphone use generally associated with lower academic achievement among children and adolescents.

    What does the settlement leave unresolved, and what does it mean for India?

    1. A financial incentive, not a mandate, for industry-wide adoption: About 30 percent of the $17 billion payout is contingent on YouTube and TikTok adopting comparable safeguards and matching payments, with stricter limits following only if Snap, TikTok and YouTube all comply.
    2. No admission of wrongdoing or binding precedent: The consent judgment explicitly states the settlement does not establish a standard of care or serve as precedent in any non-participating US state or international jurisdiction, including India.
    3. A legal question on platform liability remains open in the US: A Stanford law professor notes Meta’s attempt to invoke Section 230 immunity against design-based claims could still reach the US Supreme Court, since the settlement does not resolve roughly 2,900 other pending cases.
    4. India’s own discussions remain preliminary: The Centre is weighing age-based restrictions, usage-hour limits and stronger parental consent requirements for children’s social media access, but these discussions are still at an early stage, with the US settlement offered as a possible design-regulation template.

    Back2Basics

    1. Section 230: A provision of the US Communications Decency Act, 1996, that shields online platforms from liability for content posted by users, now being tested against claims that target a platform’s product design rather than the content it hosts.
    2. Digital Personal Data Protection Act, 2023: India’s framework law on personal data processing, which includes provisions requiring verifiable parental consent before processing a child’s personal data.
    3. Multidistrict litigation: A US federal court procedure that consolidates similar lawsuits filed in different districts, such as the roughly 2,900 other cases against social media platforms, for coordinated pre-trial proceedings.

    (GS3-22, 2024, 10 marks, Microtheme: Data Protection) “Describe the context and salient features of the Digital Personal Data Protection Act, 2023”

  • Smart glasses highlight gaps in privacy laws

    Why in the News

    Meta’s smart glasses, which can discreetly record video and audio of anyone around the wearer, have renewed concerns over surveillance and consent, and over how far the Digital Personal Data Protection Act, 2023 actually protects a bystander who never agreed to be recorded. The Supreme Court’s nine-judge Bench in Justice K.S. Puttaswamy v. Union of India (2017) held privacy to be a fundamental right intrinsic to Article 21, developing a three-part legality-necessity-proportionality test for any restriction on it. Wearable recording devices normalised for everyday use test that framework in a setting the 2017 judgment did not anticipate: a bystander with no relationship to the device’s owner, and no practical way to know they are being recorded.

    Why do smart glasses expose a specific gap in India’s privacy framework?

    1. The Digital Personal Data Protection Act, 2023 is built around consent, which a bystander cannot give: The Act’s core protection mechanism requires a data principal’s consent before personal data is processed, a structure that assumes a data subject who is a party to the transaction, not a bystander recorded without their knowledge by someone else’s device.
    2. No dedicated framework for covert or discreet recording devices: Existing privacy protections address data processing by an identifiable data fiduciary, typically a company or platform, not the diffuse, device-level recording enabled by consumer wearables carried by private individuals.
    3. Enforcement depends on the bystander detecting the recording: Because smart glasses are designed to record discreetly, a bystander has no practical way to exercise any of the rights the 2023 Act grants a data principal, since exercising those rights first requires knowing that one’s data was processed at all.
    4. Cybercrime figures already show a rising surveillance-adjacent harm pattern: National Crime Records Bureau data has recorded a rising trend in cybercrime cases involving unauthorised recording and image-based harassment, a pattern smart-glasses-style wearables are positioned to accelerate.

    Conclusion

    Smart glasses expose a structural gap between a consent-based data protection framework and a recording technology that operates on people who never consented to anything. Closing that gap requires provisions specific to covert or ambient recording devices, rather than relying on the same consent architecture built for data fiduciaries processing information from their own users.

    What is the Right to Privacy, and what does it protect?

    1. About: The Right to Privacy is a fundamental right, read into Article 21’s guarantee of life and personal liberty, protecting an individual’s control over personal information, bodily integrity, and personal decisions from unjustified interference by the State.
    2. Rationale: The right exists because personal autonomy, from choice of partner to control over one’s own data trail, is treated as intrinsic to human dignity rather than a privilege the State may withdraw.
    3. Named typology: The Supreme Court in Puttaswamy (2017) recognised several strands within the right: informational privacy over personal data, decisional autonomy over intimate personal choices, bodily integrity against intrusive procedures, and digital privacy against online surveillance.
    4. Proportionality test for restrictions: Any state action restricting privacy must meet a three-part test: legality (backed by law), a legitimate aim, and proportionality between the means used and the aim pursued.
    5. Institutional gap in independent oversight: Agencies such as the Intelligence Bureau, the Research and Analysis Wing, and the National Investigation Agency operate without a dedicated, independent body reviewing their surveillance activity for privacy compliance.
    6. Colonial-era laws still authorise interception: Provisions in the Telegraph Act continue to authorise phone tapping under standards that predate the Puttaswamy proportionality test, creating a mismatch between old authorisation powers and the newer constitutional standard.
    7. Corporate data harvesting outside individual awareness: Technology platforms collect and monetise personal data at a scale most users do not track or understand, a form of privacy erosion the Digital Personal Data Protection Act, 2023 only partially addresses through its consent and purpose-limitation provisions.
    8. Low digital literacy limits the exercise of privacy rights: Citizens frequently do not know what data they have given consent to share, or how to invoke the correction and erasure rights the 2023 Act grants them.

    Challenges in protecting the right to privacy

    1. Mass surveillance without independent judicial oversight: Interception and surveillance decisions in India are authorised through executive processes rather than prior judicial warrant. Eg. Allegations around the use of Pegasus spyware against journalists and activists in 2021 raised exactly this oversight gap. Fix. Introduce a judicial or quasi-judicial warrant requirement before any interception order takes effect, replacing the current executive-only authorisation.
    2. National-security exemptions in the 2023 Act draw criticism: The Digital Personal Data Protection Act, 2023 permits government agencies to be exempted from several of its obligations on national security and public-order grounds. Eg. Government bodies notified under the Act’s exemption provisions are not bound by the same data-minimisation and purpose-limitation duties private data fiduciaries face. Fix. Require any national-security exemption to be time-bound and reviewed periodically by an independent oversight body rather than granted as a standing exemption.
    3. Corporate surveillance through data-driven advertising: Large technology platforms build detailed behavioural profiles from data users hand over without meaningfully understanding the trade-off. Eg. Targeted political and commercial advertising built on granular user profiling has drawn regulatory scrutiny in multiple jurisdictions. Fix. Mandate clear, layered consent disclosures under the 2023 Act’s rules that separate necessary data use from optional profiling-based use.
    4. Health data retention concerns from pandemic-era tools: Contact-tracing and health applications built during the COVID-19 pandemic raised unresolved questions about how long the government retains the health data those apps collected. Eg. Aarogya Setu’s data retention and sharing practices drew sustained criticism from privacy researchers. Fix. Set a statutory data-retention ceiling for any health-emergency application, with automatic deletion once the stated public-health purpose ends.
    5. No dedicated authority solely focused on privacy enforcement: The Data Protection Board established under the 2023 Act adjudicates complaints but does not function as a proactive privacy regulator auditing surveillance practices across government and industry. Fix. Expand the Data Protection Board’s mandate to include periodic, unprompted audits of large-scale surveillance and data-processing systems, government and private alike.

    Back2Basics: Digital Personal Data Protection Act, 2023

    1. India’s first standalone law on personal data processing, built around consent as the primary legal basis for processing, with defined exceptions for legitimate uses such as employment and government functions.
    2. Creates the Data Protection Board of India as the adjudicatory body for data-protection complaints and penalties.
    3. Grants data principals rights to access, correct, and erase their personal data, and imposes purpose-limitation and data-minimisation duties on data fiduciaries.
    4. Permits the government to exempt specified agencies from several of the Act’s obligations on national security and public-order grounds, a provision that has drawn criticism for its breadth.

    Matching Previous Year Question

    “[2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023”

  • What has fuelled the backlash against Flock cameras in the U.S.?

    Why in the News

    A backlash has grown in the United States against Flock Safety, a company supplying Automated License Plate Reader (ALPR) cameras, after reports that local police departments used the company’s camera network for purposes beyond its stated public-safety mandate, including tracking individuals without a warrant. Flock’s cameras were adopted by thousands of US municipalities on the promise of solving vehicle-related crime through license-plate matching. Evidence that police departments used the same network for broader surveillance, including in ways that reached beyond a single jurisdiction’s own authority, has turned a crime-fighting tool into a symbol of unchecked surveillance expansion.

    Why has Flock Safety specifically drawn this backlash?

    1. Scale of camera deployment across US municipalities: Flock Safety’s automated license-plate-reader cameras are installed across thousands of towns and cities in the United States, giving the company’s network a national footprint that few individual police departments could have built on their own.
    2. Cross-jurisdiction data sharing without matching oversight: Police departments using Flock’s network can search license-plate data captured by cameras in other jurisdictions, a capability that expands what a single local force can track well beyond its own legal boundary, without matching cross-jurisdiction oversight.
    3. Reported misuse beyond stated crime-fighting purpose: Instances have emerged of the camera network being used to track individuals in contexts such as reproductive-healthcare-related travel and immigration enforcement, uses that go well beyond the vehicle-theft and hit-and-run cases the system was marketed to solve.
    4. Absence of a federal framework governing ALPR use: The United States has no single federal law governing how automated license-plate-reader data can be collected, retained, or shared, leaving oversight to a patchwork of local ordinances and police department policy.

    What does this suggest for India’s own camera-based surveillance rollout?

    1. India is expanding AI-linked camera surveillance in parallel: Indian cities have been expanding networks of AI-enabled cameras for traffic and law-enforcement purposes, a rollout that mirrors the scale-up Flock’s network underwent in the United States before the current backlash.
    2. India’s privacy law does not yet address law-enforcement camera data specifically: The Digital Personal Data Protection Act, 2023 governs personal data processing generally but does not set out a dedicated framework for retention limits, access logging, or cross-agency sharing of camera surveillance data collected for law enforcement.
    3. The US backlash offers a design lesson before scale, not after: The concern in the United States surfaced only after the network had scaled to thousands of jurisdictions with data-sharing already built into the product, a sequencing that leaves oversight design catching up to deployment rather than preceding it.

    Conclusion

    The backlash against Flock Safety’s cameras in the United States is a warning about what happens when a surveillance network scales faster than the oversight framework governing its use. India’s own camera-based surveillance expansion is at an earlier stage, leaving room to build retention, access, and sharing safeguards into the framework before, rather than after, the network reaches a comparable scale.

    Back2Basics: Automated License Plate Reader (ALPR)

    1. A camera system that automatically captures and reads vehicle license plates, converting the image into searchable text data matched against watchlists or databases.
    2. Originally marketed for narrow uses such as locating stolen vehicles or vehicles linked to an active crime.
    3. Data captured by one camera can be pooled into a shared network, allowing a search across cameras operated by multiple, unconnected police jurisdictions.
    4. Raises retention and access-control questions distinct from a single fixed CCTV camera, because the data is structured, searchable, and easily aggregated across locations.

    Matching Previous Year Question

    “[2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023”

  • Saving faces: Use of facial recognition equipment at protest site is worrisome

    Why in the News

    The Delhi Police has told the Supreme Court that it deployed a facial recognition system at the site of the Cockroach Janta Party protests, along with a mobile surveillance van, a command and control vehicle, smart spectacles and drones. The disclosure came in the same proceeding. In that proceeding the force has continued to deny using excessive force or manhandling demonstrators, contrary to the protestors’ own testimonies. India is therefore normalising the technical ability to subject political gatherings to searchable biometric surveillance. Legislation and judicial oversight have not yet settled when the state may lawfully do so. The contest is between a policing capability that is already operational and a legal framework that names no threshold, no authorising authority and no retention rule for its use.

    What is a facial recognition system?

    1. It converts a face into a searchable record: The system extracts measurable geometric features from a face image and stores them as a numeric template that can be matched against other templates.
    2. Two distinct operations, two different risk profiles: Verification matches one face against one claimed identity. Identification matches one face against an entire database, and only the second turns a crowd into a search.
    3. Real time capture removes the choice to participate anonymously: Cameras enabled with Artificial Intelligence (AI) scan faces as people move and run matches against a database without any interaction with the person scanned.

    What surveillance equipment did the police say it had deployed?

    1. A facial recognition system with AI enabled cameras: These scanned faces in real time against a database. The demonstration was under way at the time.
    2. A mobile surveillance van: A vehicle mounted capture platform able to move with the crowd rather than covering a fixed field.
    3. A command and control vehicle: The on site node where feeds from the various capture devices were aggregated and acted on.
    4. Smart spectacles: Wearable devices used to identify individuals on the move, which extends identification beyond fixed and vehicle mounted cameras.
    5. Drones and videographers: Aerial and handheld recording covering the site from angles the ground cameras did not reach.
    6. Private contractors hold two of these systems: The van and the spectacles have been tied to private contractors on terms that have never been disclosed, so a commercial entity sits inside the capture chain on an unknown mandate.

    What did the police not disclose?

    1. Whether every face in range was processed: The force has not addressed whether actual biometric processing occurred for every individual within the range of the cameras, which is the difference between targeted identification and mass capture.
    2. Where discarded images went: Images from checks that produced no match were open to copying in the interim, and the force has not said whether any copy survives.

    Which laws currently govern facial recognition, and what do they leave open?

    1. No statute governs the technology: There is no law in force that regulates the use of facial recognition systems by the state, so deployment rests on executive decision alone.
    2. The data protection law is not yet operative on this point: The Digital Personal Data Protection Act, 2023, whose data processing obligations are not yet in force, still makes broad exemptions for state agencies.
    3. The existing police database is purpose limited: The Automated Facial Recognition System of the National Crime Records Bureau is meant for identifying criminals and unidentified bodies, not for scanning an assembly.
    4. The 2022 statute widened records, not subjects: The Criminal Procedure (Identification) Act, 2022 expanded the set of records the police may collect, but only from specified persons rather than from the public at large.
    5. The gap is the crowd: Every one of these instruments operates against identified groups of people, and none of them authorises indiscriminate capture of everyone present at a location.

    Can mass biometric capture at a protest survive the proportionality test?

    1. The state carries the burden: Interference with the right to privacy must clear a well established proportionality test, and the burden of establishing each limb sits on the state.
    2. The first limb already fails on the facts: The existence of a legitimate objective is hard to establish for facial recognition used en masse, because the technology is indiscriminate at the point of capture and cannot be aimed at a suspect.
    3. A less restrictive alternative exists: Conventional policing achieves the same objective of maintaining order and identifying offenders without capturing the biometrics of every person present.
    4. Constitutional validity is not the only test: Even leaving aside the constitutionality of the police action, a capability deployed without a governing standard sets the precedent for the next deployment.

    How does biometric surveillance affect the right to protest?

    1. The deterrent operates before any legal restriction: The chilling effect on potential participants curtails the right to protest without any order prohibiting the protest.
    2. Anonymity is part of the freedom: Assembly has historically carried the assurance that presence in a crowd is not the same as being recorded as an individual participant.
    3. The cost falls on people with the most to lose: Government employees, students facing institutional discipline and people in precarious work self select out once presence becomes a permanent identified record.
    4. The chill is unfalsifiable: Nobody counts the people who stayed home, so the harm never appears in the record a court would examine.

    What remains unanswered before this use can be justified?

    1. The access controls: It is unknown which officers, agencies or contractor personnel could query the captured images and against which databases.
    2. The authorising legal provisions: The provisions relied on to authorise the major decisions, including the decision to scan an entire assembly, have not been identified.
    3. The false positive rate: The expected error rate of the system has not been stated, and a false match at a protest site produces detention of an innocent person on machine evidence.

    Challenges to the regulation of facial recognition technology in India

    1. Deployment has run far ahead of legislation: State and city police forces have procured systems under general policing powers rather than under any enabling statute. Eg. Several State police departments and airports adopted facial recognition without a dedicated legal framework in place. Fix. Enact a facial recognition statute prescribing permitted purposes, a judicial or independent authorisation requirement, and a fixed retention period.
    2. The data protection statute exempts the principal user: Broad exemptions for state agencies mean the very actor conducting mass capture falls outside the consent and purpose limitation architecture. Eg. The Justice B N Srikrishna Committee had recommended narrow and specified exemptions rather than open ended ones on grounds of sovereignty and public order. Fix. Replace the blanket agency exemption with a case by case exemption that must be notified with reasons and laid before Parliament.
    3. Accuracy is unequal across populations: Error rates for facial recognition are consistently higher for darker skinned faces, women and younger subjects, so the burden of false matches is not evenly distributed. Eg. Independent testing of commercial systems has repeatedly found the highest error rates for darker skinned women. Fix. Mandate published accuracy testing disaggregated by skin tone, sex and age before any system is procured for policing use.
    4. Private contractors sit inside the state’s capture chain: Outsourcing capture hardware and processing places biometric data with entities that are not accountable through public law remedies. Eg. Police facial recognition deployments in several States run on vendor supplied platforms whose procurement contracts are not in the public domain. Fix. Require every surveillance procurement contract to be published with its data handling clauses, and make the contractor a joint respondent in any privacy proceeding.
    5. There is no oversight body with jurisdiction: No standing authority audits police biometric systems, so no institution can verify retention, deletion or match logs after the event. Eg. Agencies conducting interception under existing law are reviewed only by an internal executive review committee. Fix. Establish a statutory surveillance oversight commission with power to inspect match logs and order deletion.
    6. Function creep is the default trajectory: A database built for one purpose is progressively opened to others once the infrastructure exists. Eg. Facial recognition adopted for airport boarding convenience has been proposed for wider identity verification uses. Fix. Write a statutory bar on cross purpose querying, with each authorised purpose requiring a separate legislative amendment.

    Conclusion

    The disclosure establishes that the capability to convert a political gathering into a searchable biometric record is already deployed, contracted out in part, and operating without a statute that says when it may be used. The proportionality test, on the facts available, is not close: the technology captures indiscriminately, a less restrictive alternative exists, and the state has not identified the provision that authorised the decision. Until Parliament enacts a facial recognition law with a stated purpose, an authorising authority, a retention limit and published accuracy standards, each deployment simply widens the precedent for the next one.

    “[2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023″

  • Data security has assumed significant importance in the digitized world due to rising cyber crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weakness sof the Report relating to protection of personal data in cyber space?

    The Justice B.N. Srikrishna Committee’s 2018 report – “A Free and Fair Digital Economy” – was India’s foundational attempt to translate the privacy jurisprudence of Puttaswamy (2017) into statutory architecture.

    The Rising Scale of Cybercrime in India

    Cybercrime cases rose from 10.29 lakh in 2022 to 28.15 lakh in 2025 (MHA, I4C).

    Indians lost approximately

    Cybercrime complaints have grown by over 623% between 2021 and 2024 on the NCRP portal.

    77% of fraud losses stem from investment scams; digital arrests (9%) and sextortion (4%) are the fastest-growing categories (I4C, 2025).

    I4C has frozen 24.67 lakh mule accounts and blocked 9.42 lakh SIM cards linked to cyber fraud

    Key Recommendations of the Srikrishna Committee Report

    Citizen reframed as data principal; entity as data fiduciary with trust obligations.

    Enshrined principles of consent, purpose limitation, data minimisation, and storage limitation.

    Heightened protection for sensitive personal data – health, biometric, financial, religious, genetic

    Created an independent Data Protection Authority (DPA) with adjudicatory powers.

    Mandated data localisation for critical and sensitive personal data within India.

    Recognised new-age rights – confirmation, correction, portability, right to be forgotten.

    Special safeguards for children’s data, including parental consent and a ban on profiling.

    Cross-border transfer permitted only via adequacy mechanisms or contractual safeguards.

    Strengths of the Report

    Constitutional anchoring in Puttaswamy – privacy treated as a fundamental right, not a regulatory courtesy.

    Fiduciary framing imposes a trust-based duty on data handlers, drawing from common law traditions.

    GDPR-aligned principles of purpose limitation and accountability bring India to global standards.

    Independent regulator (DPA) institutionalises enforcement beyond executive discretion.

    Empowerment of citizens through actionable rights – correction, portability, erasure.

    Sectoral sensitivity through layered protection for health, financial, biometric, and children’s data.

    Digital sovereignty advanced through data localisation provisions for critical data.

    Balanced approach – does not stifle innovation; permits research, journalism, and reasonable business processing.

    Weaknesses of the Report

    Broad State exemptions – surveillance under Section 35 permits processing in the interest of national security, public order, etc., without prior judicial oversight.

    Weak independence of the DPA – appointment process dominated by the executive raises capture concerns.

    Ambiguity on “critical” personal data – left to executive notification, creating regulatory uncertainty.

    Data localisation costs disproportionately affect MSMEs, startups, and global service providers.

    No clear remedy framework for data breaches – compensation provisions remain vague and non-deterrent.

    Inadequate provisions on non-personal data – a critical gap addressed only later by the Kris Gopalakrishnan Committee.

    No special framework for emerging threats – AI profiling, deepfakes, biometric coercion are underaddressed.

    Limited attention to journalistic and whistleblower data, raising press-freedom concerns.

    Way Forward

    Operationalise the Digital Personal Data Protection Act, 2023, with timely framing of subordinate rules.

    Establish the Data Protection Board of India (DPBI) as a genuinely independent authority, on the lines of TRAI or SEBI.

    Bring State surveillance under judicial pre-authorisation, in line with the Puttaswamy proportionality test.

    Strengthen CERT-In, I4C, and NCIIPC capacities with sustained funding and inter-agency coordination.

    Mandate algorithmic transparency and AI-impact assessments for high-risk processing.

    Operationalise the Cyber Fraud Mitigation Centre (CFMC) to scale real-time fraud interception.

    Launch a national digital literacy mission focusing on Tier-2/3 cities, senior citizens, and first-time users.

    Promote international cooperation through Budapest Convention engagement and bilateral data-sharing protocols.

    “Data is the new oil.” Thus, protection of personal data is no longer a technological concern but a constitutional one.

    2019 – What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India.

    (10)

    The CyberDome Project is a high-tech PPP initiative of Kerala Police, established as a “Centre of Excellence” to combat emerging cyber threats through collaborative research and development.

    Rising Internet Crimes in India

    Cybersecurity incidents rose from 10.29 lakh in 2022 to 22.68 lakh in 2024 (120% increase in two years)

    Massive Financial Toll- over as per NCRP.

    Significant rise in AI-driven phishing and “Digital Arrest” scams

    Enforcement agencies have blocked over 9.42 lakh SIM cards and 2.63 lakh IMEIs linked to fraudulent activities by early 2025.

    Over 86% of households are now connected to the internet – High vulnerability

    13.7% of global incidents target India (Cyfirma report)

    Importance of CyberDome in Controlling Internet Crimes

    Shift from “reactive investigation” approach to “proactive defense” model

    Public-Private Collaboration bridges the talent gap by involving over 2,500 volunteers, including ethical hackers and IT experts

    Real-Time Threat Intelligence using AI and machine learning. In 2024, it successfully thwarted a major DDoS attack on an Indian financial institution.

    Combatting Online Exploitation through initiatives like “Hac’KP 2025” and the “KID GLOVE” program (international recognition from INTERPOL)

    In September 2024, it launched a Security Operation Centre (SOC) to monitor police networks and prevent sensitive data breaches.

    Specialized Cyber-Wings- It operates niche units like the “Ransomware School” and a Malware Analysis Lab, creating Standard Operating Procedures (SOPs).

    Academic Synergy- Collaborations with institutions like NIT Calicut (2024 MoU)

    Financial Fraud Mitigation detected vulnerabilities in 4 out of 10 banking apps tested (CAG report)

    Officers and volunteers act as “Online Police Patrols,” monitoring social media for extremist propaganda, radicalization efforts, and the spread of fake news.

    The CyberDome Project has transformed the Kerala Police into a tech-forward force, achieving a 25% increase in case resolution between 2022 and 2024.