💥Join UPSC 2027,2028 Mentorship (August Batch) + XFactor Notes & Microthemes PDF

Subject: Data Protection

  • Saving faces: Use of facial recognition equipment at protest site is worrisome

    Why in the News

    The Delhi Police has told the Supreme Court that it deployed a facial recognition system at the site of the Cockroach Janta Party protests, along with a mobile surveillance van, a command and control vehicle, smart spectacles and drones. The disclosure came in the same proceeding. In that proceeding the force has continued to deny using excessive force or manhandling demonstrators, contrary to the protestors’ own testimonies. India is therefore normalising the technical ability to subject political gatherings to searchable biometric surveillance. Legislation and judicial oversight have not yet settled when the state may lawfully do so. The contest is between a policing capability that is already operational and a legal framework that names no threshold, no authorising authority and no retention rule for its use.

    What is a facial recognition system?

    1. It converts a face into a searchable record: The system extracts measurable geometric features from a face image and stores them as a numeric template that can be matched against other templates.
    2. Two distinct operations, two different risk profiles: Verification matches one face against one claimed identity. Identification matches one face against an entire database, and only the second turns a crowd into a search.
    3. Real time capture removes the choice to participate anonymously: Cameras enabled with Artificial Intelligence (AI) scan faces as people move and run matches against a database without any interaction with the person scanned.

    What surveillance equipment did the police say it had deployed?

    1. A facial recognition system with AI enabled cameras: These scanned faces in real time against a database. The demonstration was under way at the time.
    2. A mobile surveillance van: A vehicle mounted capture platform able to move with the crowd rather than covering a fixed field.
    3. A command and control vehicle: The on site node where feeds from the various capture devices were aggregated and acted on.
    4. Smart spectacles: Wearable devices used to identify individuals on the move, which extends identification beyond fixed and vehicle mounted cameras.
    5. Drones and videographers: Aerial and handheld recording covering the site from angles the ground cameras did not reach.
    6. Private contractors hold two of these systems: The van and the spectacles have been tied to private contractors on terms that have never been disclosed, so a commercial entity sits inside the capture chain on an unknown mandate.

    What did the police not disclose?

    1. Whether every face in range was processed: The force has not addressed whether actual biometric processing occurred for every individual within the range of the cameras, which is the difference between targeted identification and mass capture.
    2. Where discarded images went: Images from checks that produced no match were open to copying in the interim, and the force has not said whether any copy survives.

    Which laws currently govern facial recognition, and what do they leave open?

    1. No statute governs the technology: There is no law in force that regulates the use of facial recognition systems by the state, so deployment rests on executive decision alone.
    2. The data protection law is not yet operative on this point: The Digital Personal Data Protection Act, 2023, whose data processing obligations are not yet in force, still makes broad exemptions for state agencies.
    3. The existing police database is purpose limited: The Automated Facial Recognition System of the National Crime Records Bureau is meant for identifying criminals and unidentified bodies, not for scanning an assembly.
    4. The 2022 statute widened records, not subjects: The Criminal Procedure (Identification) Act, 2022 expanded the set of records the police may collect, but only from specified persons rather than from the public at large.
    5. The gap is the crowd: Every one of these instruments operates against identified groups of people, and none of them authorises indiscriminate capture of everyone present at a location.

    Can mass biometric capture at a protest survive the proportionality test?

    1. The state carries the burden: Interference with the right to privacy must clear a well established proportionality test, and the burden of establishing each limb sits on the state.
    2. The first limb already fails on the facts: The existence of a legitimate objective is hard to establish for facial recognition used en masse, because the technology is indiscriminate at the point of capture and cannot be aimed at a suspect.
    3. A less restrictive alternative exists: Conventional policing achieves the same objective of maintaining order and identifying offenders without capturing the biometrics of every person present.
    4. Constitutional validity is not the only test: Even leaving aside the constitutionality of the police action, a capability deployed without a governing standard sets the precedent for the next deployment.

    How does biometric surveillance affect the right to protest?

    1. The deterrent operates before any legal restriction: The chilling effect on potential participants curtails the right to protest without any order prohibiting the protest.
    2. Anonymity is part of the freedom: Assembly has historically carried the assurance that presence in a crowd is not the same as being recorded as an individual participant.
    3. The cost falls on people with the most to lose: Government employees, students facing institutional discipline and people in precarious work self select out once presence becomes a permanent identified record.
    4. The chill is unfalsifiable: Nobody counts the people who stayed home, so the harm never appears in the record a court would examine.

    What remains unanswered before this use can be justified?

    1. The access controls: It is unknown which officers, agencies or contractor personnel could query the captured images and against which databases.
    2. The authorising legal provisions: The provisions relied on to authorise the major decisions, including the decision to scan an entire assembly, have not been identified.
    3. The false positive rate: The expected error rate of the system has not been stated, and a false match at a protest site produces detention of an innocent person on machine evidence.

    Challenges to the regulation of facial recognition technology in India

    1. Deployment has run far ahead of legislation: State and city police forces have procured systems under general policing powers rather than under any enabling statute. Eg. Several State police departments and airports adopted facial recognition without a dedicated legal framework in place. Fix. Enact a facial recognition statute prescribing permitted purposes, a judicial or independent authorisation requirement, and a fixed retention period.
    2. The data protection statute exempts the principal user: Broad exemptions for state agencies mean the very actor conducting mass capture falls outside the consent and purpose limitation architecture. Eg. The Justice B N Srikrishna Committee had recommended narrow and specified exemptions rather than open ended ones on grounds of sovereignty and public order. Fix. Replace the blanket agency exemption with a case by case exemption that must be notified with reasons and laid before Parliament.
    3. Accuracy is unequal across populations: Error rates for facial recognition are consistently higher for darker skinned faces, women and younger subjects, so the burden of false matches is not evenly distributed. Eg. Independent testing of commercial systems has repeatedly found the highest error rates for darker skinned women. Fix. Mandate published accuracy testing disaggregated by skin tone, sex and age before any system is procured for policing use.
    4. Private contractors sit inside the state’s capture chain: Outsourcing capture hardware and processing places biometric data with entities that are not accountable through public law remedies. Eg. Police facial recognition deployments in several States run on vendor supplied platforms whose procurement contracts are not in the public domain. Fix. Require every surveillance procurement contract to be published with its data handling clauses, and make the contractor a joint respondent in any privacy proceeding.
    5. There is no oversight body with jurisdiction: No standing authority audits police biometric systems, so no institution can verify retention, deletion or match logs after the event. Eg. Agencies conducting interception under existing law are reviewed only by an internal executive review committee. Fix. Establish a statutory surveillance oversight commission with power to inspect match logs and order deletion.
    6. Function creep is the default trajectory: A database built for one purpose is progressively opened to others once the infrastructure exists. Eg. Facial recognition adopted for airport boarding convenience has been proposed for wider identity verification uses. Fix. Write a statutory bar on cross purpose querying, with each authorised purpose requiring a separate legislative amendment.

    Conclusion

    The disclosure establishes that the capability to convert a political gathering into a searchable biometric record is already deployed, contracted out in part, and operating without a statute that says when it may be used. The proportionality test, on the facts available, is not close: the technology captures indiscriminately, a less restrictive alternative exists, and the state has not identified the provision that authorised the decision. Until Parliament enacts a facial recognition law with a stated purpose, an authorising authority, a retention limit and published accuracy standards, each deployment simply widens the precedent for the next one.

    “[2024, GS3, 10 marks] Describe the context and salient features of the Digital Personal Data Protection Act, 2023″

  • Data security has assumed significant importance in the digitized world due to rising cyber crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weakness sof the Report relating to protection of personal data in cyber space?

    The Justice B.N. Srikrishna Committee’s 2018 report – “A Free and Fair Digital Economy” – was India’s foundational attempt to translate the privacy jurisprudence of Puttaswamy (2017) into statutory architecture.

    The Rising Scale of Cybercrime in India

    Cybercrime cases rose from 10.29 lakh in 2022 to 28.15 lakh in 2025 (MHA, I4C).

    Indians lost approximately

    Cybercrime complaints have grown by over 623% between 2021 and 2024 on the NCRP portal.

    77% of fraud losses stem from investment scams; digital arrests (9%) and sextortion (4%) are the fastest-growing categories (I4C, 2025).

    I4C has frozen 24.67 lakh mule accounts and blocked 9.42 lakh SIM cards linked to cyber fraud

    Key Recommendations of the Srikrishna Committee Report

    Citizen reframed as data principal; entity as data fiduciary with trust obligations.

    Enshrined principles of consent, purpose limitation, data minimisation, and storage limitation.

    Heightened protection for sensitive personal data – health, biometric, financial, religious, genetic

    Created an independent Data Protection Authority (DPA) with adjudicatory powers.

    Mandated data localisation for critical and sensitive personal data within India.

    Recognised new-age rights – confirmation, correction, portability, right to be forgotten.

    Special safeguards for children’s data, including parental consent and a ban on profiling.

    Cross-border transfer permitted only via adequacy mechanisms or contractual safeguards.

    Strengths of the Report

    Constitutional anchoring in Puttaswamy – privacy treated as a fundamental right, not a regulatory courtesy.

    Fiduciary framing imposes a trust-based duty on data handlers, drawing from common law traditions.

    GDPR-aligned principles of purpose limitation and accountability bring India to global standards.

    Independent regulator (DPA) institutionalises enforcement beyond executive discretion.

    Empowerment of citizens through actionable rights – correction, portability, erasure.

    Sectoral sensitivity through layered protection for health, financial, biometric, and children’s data.

    Digital sovereignty advanced through data localisation provisions for critical data.

    Balanced approach – does not stifle innovation; permits research, journalism, and reasonable business processing.

    Weaknesses of the Report

    Broad State exemptions – surveillance under Section 35 permits processing in the interest of national security, public order, etc., without prior judicial oversight.

    Weak independence of the DPA – appointment process dominated by the executive raises capture concerns.

    Ambiguity on “critical” personal data – left to executive notification, creating regulatory uncertainty.

    Data localisation costs disproportionately affect MSMEs, startups, and global service providers.

    No clear remedy framework for data breaches – compensation provisions remain vague and non-deterrent.

    Inadequate provisions on non-personal data – a critical gap addressed only later by the Kris Gopalakrishnan Committee.

    No special framework for emerging threats – AI profiling, deepfakes, biometric coercion are underaddressed.

    Limited attention to journalistic and whistleblower data, raising press-freedom concerns.

    Way Forward

    Operationalise the Digital Personal Data Protection Act, 2023, with timely framing of subordinate rules.

    Establish the Data Protection Board of India (DPBI) as a genuinely independent authority, on the lines of TRAI or SEBI.

    Bring State surveillance under judicial pre-authorisation, in line with the Puttaswamy proportionality test.

    Strengthen CERT-In, I4C, and NCIIPC capacities with sustained funding and inter-agency coordination.

    Mandate algorithmic transparency and AI-impact assessments for high-risk processing.

    Operationalise the Cyber Fraud Mitigation Centre (CFMC) to scale real-time fraud interception.

    Launch a national digital literacy mission focusing on Tier-2/3 cities, senior citizens, and first-time users.

    Promote international cooperation through Budapest Convention engagement and bilateral data-sharing protocols.

    “Data is the new oil.” Thus, protection of personal data is no longer a technological concern but a constitutional one.

    2019 – What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India.

    (10)

    The CyberDome Project is a high-tech PPP initiative of Kerala Police, established as a “Centre of Excellence” to combat emerging cyber threats through collaborative research and development.

    Rising Internet Crimes in India

    Cybersecurity incidents rose from 10.29 lakh in 2022 to 22.68 lakh in 2024 (120% increase in two years)

    Massive Financial Toll- over as per NCRP.

    Significant rise in AI-driven phishing and “Digital Arrest” scams

    Enforcement agencies have blocked over 9.42 lakh SIM cards and 2.63 lakh IMEIs linked to fraudulent activities by early 2025.

    Over 86% of households are now connected to the internet – High vulnerability

    13.7% of global incidents target India (Cyfirma report)

    Importance of CyberDome in Controlling Internet Crimes

    Shift from “reactive investigation” approach to “proactive defense” model

    Public-Private Collaboration bridges the talent gap by involving over 2,500 volunteers, including ethical hackers and IT experts

    Real-Time Threat Intelligence using AI and machine learning. In 2024, it successfully thwarted a major DDoS attack on an Indian financial institution.

    Combatting Online Exploitation through initiatives like “Hac’KP 2025” and the “KID GLOVE” program (international recognition from INTERPOL)

    In September 2024, it launched a Security Operation Centre (SOC) to monitor police networks and prevent sensitive data breaches.

    Specialized Cyber-Wings- It operates niche units like the “Ransomware School” and a Malware Analysis Lab, creating Standard Operating Procedures (SOPs).

    Academic Synergy- Collaborations with institutions like NIT Calicut (2024 MoU)

    Financial Fraud Mitigation detected vulnerabilities in 4 out of 10 banking apps tested (CAG report)

    Officers and volunteers act as “Online Police Patrols,” monitoring social media for extremist propaganda, radicalization efforts, and the spread of fake news.

    The CyberDome Project has transformed the Kerala Police into a tech-forward force, achieving a 25% increase in case resolution between 2022 and 2024.

  • Describe the context and salient features of the Digital Personal Data Protection Act, 2023

    The DPDP Act, 2023 aims to transform India from a “privacy-neutral” state to a “privacy-centric” digital democracy. It provides the legal backbone for India’s $1 trillion digital economy aspirations.

    Context of the Act

    Committee Recommendations (Justice B.N. Srikrishna Committee) emphasizing “Data Sovereignty” and the “Fiduciary” relationship.

    Digital economy- With over 900 million internet users, the rapid expansion of digital payments (UPI) and digital public infrastructure (Aadhar, CoWIN) required robust safeguards.

    Inadequacy of IT Act, 2000- The previous framework (Section 43A) was narrow, outdated, and lacked the “teeth” to penalize global tech giants for data breaches.

    To remain a global outsourcing hub, India needed a law compatible with Global Norms. Eg- EU’s GDPR.

    Data Breaches highlighted the vulnerability of citizens’ personal data. Eg- CoWIN data leak

    The rise of AI-driven behavioral profiling and “dark patterns” in e-commerce necessitated “Purpose Limitation.”

    Data has become the “new oil” in modern warfare, with data localization as a vital component of national security.

    Salient Features of the Act

    The Act is built on the philosophy of “Rightful Processing”

    Tripartite Stakeholder Model- Identifies the Data Principal (individual), Data Fiduciary (entity deciding data use), and Data Processor (entity handling data).

    Consent-First Approach- Processing is only lawful with “free, specific, informed, unconditional, and unambiguous” consent via a clear notice.

    Rights of Data Principals- Grants the right to Access (summary of data), Correction, Erasure, and Nomination (bequeathing digital data after death).

    Significant Data Fiduciaries (SDFs)- Entities handling high-volume or sensitive data (e.g., Social Media) must appoint a Data Protection Officer (DPO) and conduct annual audits.

    Protection of Minors- Mandates verifiable parental consent for children (under 18) and strictly prohibits tracking or targeted advertising directed at them.

    Data Protection Board of India (DPBI)- A digital-first regulatory body empowered to investigate breaches and impose fines.

    Negative List for Cross-Border Flow- Permits data transfer to most countries unless specifically restricted by a government “Blocklist.”

    Stringent Financial Penalties- Forgoes criminal jail terms in favor of massive civil penalties-up to for failure to prevent a data breach.

    Challenges That Remain

    Surveillance concerns- Section 17 allows the state to bypass most provisions for “security of the state” and “public order”.

    Diligence vs. Innovation- high cost of implementing “Privacy by Design” and maintaining audit trails for MSMEs and startups.

    One-size-fits-all approach- Unlike GDPR, the Indian law does not distinguish between general data and “Sensitive” data.

    The Act is a right step toward Digital Sovereignty. It must move beyond mere legal text to create a “Privacy Culture” for meaningful exercise of digital autonomy.