Facial recognition at CJP protest raises questions over privacy, data protection
The deployment of the Ikshana facial recognition van at the Cockroach Janta Party protest in Jantar Mantar has triggered court challenges and fresh scrutiny. The dispute has sharpened concerns over privacy, biometric data use and the absence of a clear legal framework.

The presence of the AI-enabled facial recognition technology van Ikshana at Jantar Mantar during the recently concluded Cockroach Janta Party protests has raised serious questions about privacy violations, data protection and the responsibilities of the government. Petitions have also been filed in the Delhi High Court challenging the deployment of such technology against a citizens' protest led by students and young people, particularly amid fears of protesters being targeted and profiled, and the possible impact on their careers and studies.
The use of artificial intelligence (AI) and facial recognition technology by law enforcement agencies in India has grown significantly in recent years, particularly in the aftermath of the 26/11 Mumbai terror attacks. Police forces across several states have begun deploying facial recognition systems and drones to assist with surveillance and policing. However, these technologies have largely been introduced without any specific legislative framework governing their use, raising serious questions about privacy, accountability and the protection of personal data.
The absence of a dedicated legal framework has become particularly significant following the Supreme Court's landmark judgment in Justice K.S. Puttaswamy v. Union of India, which recognised the right to privacy as a fundamental right. In the wake of this judgment, the legality of surveillance systems such as the Central Monitoring System (CMS), NATGRID and NETRA has been challenged before the Delhi High Court on the ground that they infringe individual rights without any statutory basis.
The Union government has maintained that while the right to privacy is a "sacred fundamental right" and is respected by the State, privacy is not absolute. In submissions before the Delhi High Court in 2021, the Centre argued that the "veil of privacy" may be lifted where there is a legitimate state interest. According to the government, lawful interception, monitoring or decryption of messages or information stored in computer resources is carried out only by authorised agencies and only after obtaining approval from the competent authority in each case.
However, the hearing in the matter has remained pending since 2021 after the case was transferred to the Supreme Court at the Centre's request. There has been no effective hearing on the issue in either the High Court or the Supreme Court.
The debate becomes more complex in the context of facial recognition technology. Unlike ordinary video surveillance, facial recognition systems actively analyse faces, create biometric templates and compare them with existing databases to identify individuals. This involves the processing of highly sensitive personal data and raises concerns that extend beyond conventional CCTV monitoring.
According to Prashant Sugathan, Legal Director at the Software Freedom Law Center (SFLC), active facial recognition is fundamentally different from routine video recording by the police. He argues that the technology maps an individual's face against databases, creating a direct privacy concern. In his view, once facial data is mapped and linked to databases, it constitutes a definite violation of privacy. He also cautions that the widespread deployment of such technology effectively treats every individual as a suspect rather than limiting surveillance to persons under investigation.
India's legal position on personal data protection is currently in transition. The Digital Personal Data Protection Bill, 2022, released by the Ministry of Electronics and Information Technology (MeitY), proposed broad exemptions for processing personal data for purposes such as preventing, detecting or investigating the contravention of any law.
However, according to cyber law expert and Senior Advocate Pavan Duggal, the Digital Personal Data Protection Act does not automatically exempt the government from its obligations. The presumption is that government agencies are also covered unless they are specifically exempted.
According to Duggal, a crucial aspect of the current legal landscape is that, as matters stand, the Digital Personal Data Protection Act has not yet become operational. The Act is scheduled to come into effect on November 13, 2026, when the relevant notification takes effect.
"At present, neither the Data Protection Board nor the agencies responsible for implementing the law have been notified. Consequently, there is presently no operational statutory framework specifically regulating the collection, processing or storage of personal data under the Act," Duggal said.
This legal gap has significant implications for facial recognition technology. Since facial recognition relies entirely on the collection and processing of personal biometric data, there is currently no dedicated statutory regime governing its use. As a result, there is effectively no specific law regulating facial recognition technology in India at present.
Nevertheless, this does not mean that the State can exercise its surveillance powers without constitutional limits. Sugathan argues that even though the Digital Personal Data Protection Act has not yet been fully enforced, citizens continue to enjoy the fundamental right to privacy against the State under the Constitution.
While the absence of the Act may make it more difficult to enforce privacy rights against private corporations, constitutional protections remain available against government action. If authorities seek to restrict or interfere with these rights, proper legal procedures must be followed.
Duggal also said that once the Digital Personal Data Protection Act comes into force on November 13, 2026, government agencies processing personal data will become answerable under the new framework unless they are specifically exempted.
Until the necessary notifications are issued and the relevant authorities are established, questions will remain about how these obligations will be implemented in practice and the extent to which sovereign functions may continue to enjoy exemptions in the interest of national security or other legitimate state interests.
Individuals who believe their facial data has been collected or mapped without lawful authority have limited remedies at present. Sugathan suggests that affected persons may first write to the relevant police authorities requesting the deletion of any personal data being held.
However, he notes that the lack of transparency surrounding how facial recognition systems operate makes it difficult to determine whether data has in fact been collected or linked to databases. If authorities fail to respond satisfactorily, individuals may approach the High Court, alleging a violation of their fundamental right to privacy.
While such remedies exist, pursuing them remains a difficult and time-consuming process.
WHAT IS THE GLOBAL VIEW ON FACIAL RECOGNITION TECHNOLOGY?
The issue has also been the subject of heated debate across the globe.
In April this year, the High Court in the UK allowed the Metropolitan Police to use AI facial recognition tracking software in public spaces, as the policy restricted its use to tracking known criminals or missing persons.
The court noted that regulations and strict safeguards govern the use of AI facial recognition technology by the police. The images are compared with a database of wanted criminals or missing people, and if a face does not match anyone in the database, the system deletes the image immediately.
If the system finds a possible match, it alerts officers, who then double-check the hit before deciding whether to stop the individual, according to the policy safeguards.
In March, the Court of Justice of the European Union held that national police authorities do not have the power to collect biometric data such as fingerprints and photographs from suspects without first carrying out a case-by-case assessment under the 'strictly necessary' test.
While the case itself involved the collection of fingerprint data by French authorities, the court held that "the mere existence of one or more reasonable grounds for suspecting an offence does not suffice as a reason for the collection of biometric data".
"Every decision to gather identification data must therefore contain a clear statement of reasons, even if that statement is succinct, allowing the data subject to understand the reasons for the measure and to exercise his or her right to a remedy," the court said.
In the US, while there is no federal law expressly regulating the use of facial recognition technology, some states have passed legislation restricting mass biometric data collection through the technology.
The presence of the AI-enabled facial recognition technology van Ikshana at Jantar Mantar during the recently concluded Cockroach Janta Party protests has raised serious questions about privacy violations, data protection and the responsibilities of the government. Petitions have also been filed in the Delhi High Court challenging the deployment of such technology against a citizens' protest led by students and young people, particularly amid fears of protesters being targeted and profiled, and the possible impact on their careers and studies.
The use of artificial intelligence (AI) and facial recognition technology by law enforcement agencies in India has grown significantly in recent years, particularly in the aftermath of the 26/11 Mumbai terror attacks. Police forces across several states have begun deploying facial recognition systems and drones to assist with surveillance and policing. However, these technologies have largely been introduced without any specific legislative framework governing their use, raising serious questions about privacy, accountability and the protection of personal data.
The absence of a dedicated legal framework has become particularly significant following the Supreme Court's landmark judgment in Justice K.S. Puttaswamy v. Union of India, which recognised the right to privacy as a fundamental right. In the wake of this judgment, the legality of surveillance systems such as the Central Monitoring System (CMS), NATGRID and NETRA has been challenged before the Delhi High Court on the ground that they infringe individual rights without any statutory basis.
The Union government has maintained that while the right to privacy is a "sacred fundamental right" and is respected by the State, privacy is not absolute. In submissions before the Delhi High Court in 2021, the Centre argued that the "veil of privacy" may be lifted where there is a legitimate state interest. According to the government, lawful interception, monitoring or decryption of messages or information stored in computer resources is carried out only by authorised agencies and only after obtaining approval from the competent authority in each case.
However, the hearing in the matter has remained pending since 2021 after the case was transferred to the Supreme Court at the Centre's request. There has been no effective hearing on the issue in either the High Court or the Supreme Court.
The debate becomes more complex in the context of facial recognition technology. Unlike ordinary video surveillance, facial recognition systems actively analyse faces, create biometric templates and compare them with existing databases to identify individuals. This involves the processing of highly sensitive personal data and raises concerns that extend beyond conventional CCTV monitoring.
According to Prashant Sugathan, Legal Director at the Software Freedom Law Center (SFLC), active facial recognition is fundamentally different from routine video recording by the police. He argues that the technology maps an individual's face against databases, creating a direct privacy concern. In his view, once facial data is mapped and linked to databases, it constitutes a definite violation of privacy. He also cautions that the widespread deployment of such technology effectively treats every individual as a suspect rather than limiting surveillance to persons under investigation.
India's legal position on personal data protection is currently in transition. The Digital Personal Data Protection Bill, 2022, released by the Ministry of Electronics and Information Technology (MeitY), proposed broad exemptions for processing personal data for purposes such as preventing, detecting or investigating the contravention of any law.
However, according to cyber law expert and Senior Advocate Pavan Duggal, the Digital Personal Data Protection Act does not automatically exempt the government from its obligations. The presumption is that government agencies are also covered unless they are specifically exempted.
According to Duggal, a crucial aspect of the current legal landscape is that, as matters stand, the Digital Personal Data Protection Act has not yet become operational. The Act is scheduled to come into effect on November 13, 2026, when the relevant notification takes effect.
"At present, neither the Data Protection Board nor the agencies responsible for implementing the law have been notified. Consequently, there is presently no operational statutory framework specifically regulating the collection, processing or storage of personal data under the Act," Duggal said.
This legal gap has significant implications for facial recognition technology. Since facial recognition relies entirely on the collection and processing of personal biometric data, there is currently no dedicated statutory regime governing its use. As a result, there is effectively no specific law regulating facial recognition technology in India at present.
Nevertheless, this does not mean that the State can exercise its surveillance powers without constitutional limits. Sugathan argues that even though the Digital Personal Data Protection Act has not yet been fully enforced, citizens continue to enjoy the fundamental right to privacy against the State under the Constitution.
While the absence of the Act may make it more difficult to enforce privacy rights against private corporations, constitutional protections remain available against government action. If authorities seek to restrict or interfere with these rights, proper legal procedures must be followed.
Duggal also said that once the Digital Personal Data Protection Act comes into force on November 13, 2026, government agencies processing personal data will become answerable under the new framework unless they are specifically exempted.
Until the necessary notifications are issued and the relevant authorities are established, questions will remain about how these obligations will be implemented in practice and the extent to which sovereign functions may continue to enjoy exemptions in the interest of national security or other legitimate state interests.
Individuals who believe their facial data has been collected or mapped without lawful authority have limited remedies at present. Sugathan suggests that affected persons may first write to the relevant police authorities requesting the deletion of any personal data being held.
However, he notes that the lack of transparency surrounding how facial recognition systems operate makes it difficult to determine whether data has in fact been collected or linked to databases. If authorities fail to respond satisfactorily, individuals may approach the High Court, alleging a violation of their fundamental right to privacy.
While such remedies exist, pursuing them remains a difficult and time-consuming process.
WHAT IS THE GLOBAL VIEW ON FACIAL RECOGNITION TECHNOLOGY?
The issue has also been the subject of heated debate across the globe.
In April this year, the High Court in the UK allowed the Metropolitan Police to use AI facial recognition tracking software in public spaces, as the policy restricted its use to tracking known criminals or missing persons.
The court noted that regulations and strict safeguards govern the use of AI facial recognition technology by the police. The images are compared with a database of wanted criminals or missing people, and if a face does not match anyone in the database, the system deletes the image immediately.
If the system finds a possible match, it alerts officers, who then double-check the hit before deciding whether to stop the individual, according to the policy safeguards.
In March, the Court of Justice of the European Union held that national police authorities do not have the power to collect biometric data such as fingerprints and photographs from suspects without first carrying out a case-by-case assessment under the 'strictly necessary' test.
While the case itself involved the collection of fingerprint data by French authorities, the court held that "the mere existence of one or more reasonable grounds for suspecting an offence does not suffice as a reason for the collection of biometric data".
"Every decision to gather identification data must therefore contain a clear statement of reasons, even if that statement is succinct, allowing the data subject to understand the reasons for the measure and to exercise his or her right to a remedy," the court said.
In the US, while there is no federal law expressly regulating the use of facial recognition technology, some states have passed legislation restricting mass biometric data collection through the technology.
The presence of the AI-enabled facial recognition technology van Ikshana at Jantar Mantar during the recently concluded Cockroach Janta Party protests has raised serious questions about privacy violations, data protection and the responsibilities of the government. Petitions have also been filed in the Delhi High Court challenging the deployment of such technology against a citizens' protest led by students and young people, particularly amid fears of protesters being targeted and profiled, and the possible impact on their careers and studies.
The use of artificial intelligence (AI) and facial recognition technology by law enforcement agencies in India has grown significantly in recent years, particularly in the aftermath of the 26/11 Mumbai terror attacks. Police forces across several states have begun deploying facial recognition systems and drones to assist with surveillance and policing. However, these technologies have largely been introduced without any specific legislative framework governing their use, raising serious questions about privacy, accountability and the protection of personal data.
The absence of a dedicated legal framework has become particularly significant following the Supreme Court's landmark judgment in Justice K.S. Puttaswamy v. Union of India, which recognised the right to privacy as a fundamental right. In the wake of this judgment, the legality of surveillance systems such as the Central Monitoring System (CMS), NATGRID and NETRA has been challenged before the Delhi High Court on the ground that they infringe individual rights without any statutory basis.
The Union government has maintained that while the right to privacy is a "sacred fundamental right" and is respected by the State, privacy is not absolute. In submissions before the Delhi High Court in 2021, the Centre argued that the "veil of privacy" may be lifted where there is a legitimate state interest. According to the government, lawful interception, monitoring or decryption of messages or information stored in computer resources is carried out only by authorised agencies and only after obtaining approval from the competent authority in each case.
However, the hearing in the matter has remained pending since 2021 after the case was transferred to the Supreme Court at the Centre's request. There has been no effective hearing on the issue in either the High Court or the Supreme Court.
The debate becomes more complex in the context of facial recognition technology. Unlike ordinary video surveillance, facial recognition systems actively analyse faces, create biometric templates and compare them with existing databases to identify individuals. This involves the processing of highly sensitive personal data and raises concerns that extend beyond conventional CCTV monitoring.
According to Prashant Sugathan, Legal Director at the Software Freedom Law Center (SFLC), active facial recognition is fundamentally different from routine video recording by the police. He argues that the technology maps an individual's face against databases, creating a direct privacy concern. In his view, once facial data is mapped and linked to databases, it constitutes a definite violation of privacy. He also cautions that the widespread deployment of such technology effectively treats every individual as a suspect rather than limiting surveillance to persons under investigation.
India's legal position on personal data protection is currently in transition. The Digital Personal Data Protection Bill, 2022, released by the Ministry of Electronics and Information Technology (MeitY), proposed broad exemptions for processing personal data for purposes such as preventing, detecting or investigating the contravention of any law.
However, according to cyber law expert and Senior Advocate Pavan Duggal, the Digital Personal Data Protection Act does not automatically exempt the government from its obligations. The presumption is that government agencies are also covered unless they are specifically exempted.
According to Duggal, a crucial aspect of the current legal landscape is that, as matters stand, the Digital Personal Data Protection Act has not yet become operational. The Act is scheduled to come into effect on November 13, 2026, when the relevant notification takes effect.
"At present, neither the Data Protection Board nor the agencies responsible for implementing the law have been notified. Consequently, there is presently no operational statutory framework specifically regulating the collection, processing or storage of personal data under the Act," Duggal said.
This legal gap has significant implications for facial recognition technology. Since facial recognition relies entirely on the collection and processing of personal biometric data, there is currently no dedicated statutory regime governing its use. As a result, there is effectively no specific law regulating facial recognition technology in India at present.
Nevertheless, this does not mean that the State can exercise its surveillance powers without constitutional limits. Sugathan argues that even though the Digital Personal Data Protection Act has not yet been fully enforced, citizens continue to enjoy the fundamental right to privacy against the State under the Constitution.
While the absence of the Act may make it more difficult to enforce privacy rights against private corporations, constitutional protections remain available against government action. If authorities seek to restrict or interfere with these rights, proper legal procedures must be followed.
Duggal also said that once the Digital Personal Data Protection Act comes into force on November 13, 2026, government agencies processing personal data will become answerable under the new framework unless they are specifically exempted.
Until the necessary notifications are issued and the relevant authorities are established, questions will remain about how these obligations will be implemented in practice and the extent to which sovereign functions may continue to enjoy exemptions in the interest of national security or other legitimate state interests.
Individuals who believe their facial data has been collected or mapped without lawful authority have limited remedies at present. Sugathan suggests that affected persons may first write to the relevant police authorities requesting the deletion of any personal data being held.
However, he notes that the lack of transparency surrounding how facial recognition systems operate makes it difficult to determine whether data has in fact been collected or linked to databases. If authorities fail to respond satisfactorily, individuals may approach the High Court, alleging a violation of their fundamental right to privacy.
While such remedies exist, pursuing them remains a difficult and time-consuming process.
WHAT IS THE GLOBAL VIEW ON FACIAL RECOGNITION TECHNOLOGY?
The issue has also been the subject of heated debate across the globe.
In April this year, the High Court in the UK allowed the Metropolitan Police to use AI facial recognition tracking software in public spaces, as the policy restricted its use to tracking known criminals or missing persons.
The court noted that regulations and strict safeguards govern the use of AI facial recognition technology by the police. The images are compared with a database of wanted criminals or missing people, and if a face does not match anyone in the database, the system deletes the image immediately.
If the system finds a possible match, it alerts officers, who then double-check the hit before deciding whether to stop the individual, according to the policy safeguards.
In March, the Court of Justice of the European Union held that national police authorities do not have the power to collect biometric data such as fingerprints and photographs from suspects without first carrying out a case-by-case assessment under the 'strictly necessary' test.
While the case itself involved the collection of fingerprint data by French authorities, the court held that "the mere existence of one or more reasonable grounds for suspecting an offence does not suffice as a reason for the collection of biometric data".
"Every decision to gather identification data must therefore contain a clear statement of reasons, even if that statement is succinct, allowing the data subject to understand the reasons for the measure and to exercise his or her right to a remedy," the court said.
In the US, while there is no federal law expressly regulating the use of facial recognition technology, some states have passed legislation restricting mass biometric data collection through the technology.