The Eye of the State: Navigating the Intersection of Facial Recognition Technology and Article 21 of the Indian Constitution
- Admin

- Jun 8
- 8 min read
By- Vatsala Pandey & Abhishek Yadav
~ Article 21[1] safeguards the citizen from the chains of the State; facial recognition forms those chains out of unseen code.
Abstract
This article explores the rising tension between the state’s implementation of Facial Recognition Technology (FRT) for ‘predictive policing’ and the fundamental Right to Life and Personal Liberty guaranteed under Article 21[2] of the Indian Constitution. While the executive branch validates mass surveillance as a means for public safety and administrative efficiency, this article argues that the persistent, non-consensual tracking of bio-metrics poses a real threat to individual dignity and the right to be left alone.
By implementing the landmark ‘Triple Test’ (Legality, Necessity, and Proportionality) recognized in the case of K.S. Puttaswamy v. Union of India (2018)[3]The study surveys how current FRT deployments, often operating through executive overreach rather than legislative mandate, fail to meet constitutional benchmarks. The discussion additionally examines the ‘chilling effect’ of surveillance on civil liberties and the essential risks of algorithmic bias, which can lead to the unlawful instigation of sidelined communities.
The silent increase of Facial Recognition Technology (FRT) across Indian cities, from airports to protest sites symbols a standard shift in the relationship between the citizen and the State. Under the canopy of Article 21[4] of the Indian Constitution, the ‘Right to Life’ has advanced from mere physical existence into a sophisticated assurance of individual dignity and private autonomy. However, when a camera captures a face, changes it into a measured code, and cross-references it against an illicit database without the individual’s knowledge, the ‘Right to be Let Alone’ is analytically pulled apart.
Introduction:
India's first comprehensive privacy law, the Digital Personal Data Protection Act, 2023[5]It was just passed but has not gone into effect as of mid-2025. Once it is in effect, it will control the “processing of digital personal data,” which includes digitally stored bio-metrics and photos. With rare exceptions, consent and purpose notice are necessary for data processing. In contrast to previous bills, the Digital Personal Data Protection Act provides baseline protection for all personal data and does not distinguish between “sensitive” and non-sensitive data. Particularly, it exempts specific state uses, such as processing for public order, security, sovereignty, etc., through notification. This means that if they can justify it as security or crime prevention, government agencies (like the police) may contend that DPDP.[6] does not apply to Facial Recognition Technology (FRT). The Act also envisages a Data Protection Board to handle complaints and impose penalties, and it enshrines modern rights (data access, correction, erasure) once it becomes effective. However, until and unless enforcement rules and the Board are set up, DPDP’s actual impact on law enforcement practices remains uncertain.
The Sensitive Personal Data or Information (SPDI) Rules OF 2011[7] and the Information Technology Act of 2000[8]India’s primary privacy protections were restricted before DPDP. Biometric data is included in the category of ‘Sensitive Personal Data or Information (SPDI),’ which was recognized by the IT (Information Technology) Act (as amended) and its 2011[9] regulations. SPDI processing entities, such as private businesses that gather fingerprints, are essential to acquire consent and use ‘reasonable security practices.’ A limited criminal penalty for wrongful disclosure (Section 72A)[10] and civil liability (Section 43A) may result from a breach of fiduciary duty. These regulations, though, have not been broadly imposed in the context of surveillance and primarily apply to private actors. They do not precisely limit how the government uses FRT (Facial Recognition Technology).
Other frameworks: India has other applicable laws and guidelines. The Aadhaar Act (2016)[11] permits biometric-based identity (iris/thumbprints) for safety benefits, but bars the government from revealing data, except in limited ways. (It does not directly regulate Facial Recognition Technology by police.) Some state governments have considered their peculiar policies: for example, Kerala passed a state-level privacy bill, and local bodies have ‘privacy policies’ for municipal data. At present, though, there is no dedicated Indian law on facial recognition itself; use of FRT (Facial Recognition Technology) by authorities falls between general privacy rules and sectoral rules.
Analysis: Facial recognition inherently implicates privacy because it links a person’s biometric data (their image) to identity, location, and other personal details. Under the K.S. Puttaswamy case[12]Any capture and use of a person’s face by the state must satisfy the privacy test: a lawful basis, a legitimate aim, and proportionality. At present, India’s laws do not openly authorize the random use of facial recognition technology in public. If police set up a “live facial recognition” scanner (for example, on CCTV or a mobile app) to scan crowds, this intrudes upon an individual’s informational privacy. The state’s interest (crime control, public safety) is important, but courts will ask: Is this narrowly tailored? Could the same objective be achieved with less intrusion? For example, if FRT is used only to search for a specific fugitive, that is more justifiable than indiscriminate scanning of all citizens’ faces.
The DPDP Act’s[13] The permission regime sheds light on the expected standards; usually, processing needs free and well-versed consent. But the Act’s own exemptions swallow that rule in imperative cases; any use by “instrumentality of the State” notified under national security or public order is exempt. Hence, unless the government voluntarily makes its Facial Recognition Technology programs, which are subject to DPDP[14] principles, there is no automatic requirement for consent or notice when police scan faces. In practice, this means a citizen’s photo taken by police may not trigger Digital Personal Data Protection claims of unlawful processing, because law enforcement could claim immunity. This leaves room for broad surveillance. The lack of an explicit statutory hook is a legal loophole: neither the Constitution nor DPDP.[15] gives clear ‘permission’ for specific Facial Recognition deployments, but neither absolutely forbids them either.
The rules of proportionality: For instance, Facial Recognition Technology must be for a ‘legitimate purpose critical to the Data Fiduciary’s function,’ and data collected should be discarded when that purpose ends. Under the Digital Personal Data Protection[16], if consent is the basis for processing, a citizen should be able to withdraw consent. However, police data collection is rarely labeled ‘consensual’; it is typically asserted as duty-bound. Still, ethical norms suggest that even the police should define clear purpose-limits (e.g. identifying specific suspects) and avoid keeping biographic data longer than needed.
Suggestively, the use of Facial Recognition Technology by authorities can simply overrun. If cameras scan the faces of bystanders, or if banks/government link identities to crowds, the natural “expectation of privacy” in public spaces diminishes. Yet even in public, anonymity has value in a free society. The Supreme Court has hinted that anonymity is part of free speech and dissent. The judgment of the K.S.Puttaswamy case[17] warned that “each citizen has a right to go about in public spaces without intimate surveillance.” When FRT is combined with CCTVs, that warning takes on new force. Technology now makes it feasible to identify anyone on public streets at any moment. This potential for mass identification was not imagined when Article 21[18] was drafted, but courts may well hold that relentless face-scanning chills privacy.
Ethical issues: The recognized biases of Facial Recognition Technology compound the legal problems. Studies (and common experience) show FRT is less correct for women and darker-skinned individuals. The diverse society in India creates a mess, excessively affecting minorities (like low-caste Dalits, native Adivasis, or Muslims), who are especially troublesome. These worries are backed by data: biometric algorithms skilled on lighter-skinned datasets commonly misfire in India. The absence of a data protection law was noted in the same breath as this bias problem. Without any firm auditing or legal remedy, a person wrongly “flagged” by Facial Recognition Technology might face detention or police scrutiny with no quick way to contest it.
Wrongness, Marginalized Groups & Incorrect Positives:
Once the Facial Recognition Technology software is inaccurate, the “misapplication” shifts from deliberate surveillance to official negligence, where defective data results in a direct threat to personal liberty. The Delhi Police followed the “2% Accuracy” metric, where RTIs[19] filed regarding the Delhi Police’s facial recognition system exposed an astounding flaw. When the software was originally cleared by the Delhi High Court in 2018, it was firmly intended for a noble purpose: finding missing children. Though subsequent disclosures exposed that the software’s actual accuracy rate in distinguishing between faces was terribly low, failing to properly differentiate between young boys and girls, and apparently functioning at a general accuracy rate of just 2% in certain technical assessments.
Another ethical problem is consent and transparency:
When banks or companies install Facial Recognition Technology (for entry or login), they usually ask for consent. But when the state uses FRT, there is no opt-in mechanism. Numerous Indians have never been well-versed that their faces might be used in state databases. As one digital rights lawyer noted, “most people are not even aware that they are being shrivelled” by these systems. This lack of transparency violates best practices. The Digital Personal Data Protection Act’s[20] The notice-and-consent rule was designed precisely to give people a choice.
“We must ask ourselves: when a software malfunction in a facial match can incorrectly strip a person of their freedom, are we upholding the rule of law, or are we outsourcing Article 21[21] to an un-elected algorithm?” as it was held in the case of K.S. Puttaswamy v. Union of India[22]that privacy is not a threat, but an important assurance of human dignity and personal liberty under Article 21[23] of the Constitution. By creating That any state contravention on privacy must be tested against the harsh standard of a “fair, just, and reasonable” procedure, the Apex Court drew a clear line against arbitrary state action.
Worldwide, the trend is to require warrants or judicial oversight for intrusive tech. India currently has no law requiring a court order for a Facial Recognition Technology search. If a citizen protests during a random face scan, police typically have no obligation to justify their actions. This runs counter to jurisprudence, which usually imposes at least some checks on police powers. In practice, then, the legal position is unsettled: rights exist on paper, but enforcement may be delayed.
The Legal Remedy Against Data Misuse:
A Devoted Legislative Framework- Instead of depending on broad, general data protection rules, India requires unambiguous legislation that regulates biometric surveillance. The law must clearly dictate which state performers can use Facial Recognition Technology. It must mandate judicial warrants for targeted facial tracking, moving away from one-sided executive authorization.
Harsh Observance to the Proportionality Test- The state must show that using Facial Recognition Technology is the complete minimum essential measure to attain a specific goal (example: finding a missing child vs. scanning a whole political rally). Large, untargeted scanning of nonviolent public gatherings should be lawfully barred as a disproportionate measure.
Conclusion
Facial recognition technology offers influential tools for identification and security, but in India, it poses grave privacy and moral challenges. The Apex Court’s decision in the K.S.Puttaswamy[24] The case makes clear that Indians have a fundamental right to informational privacy, and any surveillance regime must be legal, essential, and balanced. The new DPDP Act[25]Once entirely in force, it will introduce consent and data-protection principles even for biometric processing. Though it has many exemptions for government activity leave uncertainty. As per the facts, India is swiftly deploying Facial Recognition Technology without clear rules. Millions of faces are being scanned even as only a segment of people understand their rights. Lawfully, they may initiate requiring procedural safeguards, for instance, limiting Facial Recognition Technology to defined crimes, assigning advance notice, or ensuring mechanisms to contest misidentification. Moreover, transparency and accountability must progress, and the public should know when and why their faces are being scanned, and data should not be retained longer than necessary. As the technology spreads, Indian policymakers and judges will have to resolve its benefits with constitutional rights. In India, an equilibrium must be struck- preserving legitimate law implementation capabilities while upholding the individual’s dignity and privacy. Attaining that balance will require healthy legal standards (likely rooted in DPDP.[26] and Article 21[27] of the Constitution) and public oversight. Only then can India deploy facial recognition “the right way” if at all, without eroding the privacy rights that its courts have sworn to protect.
[1] The Constitution of India, art 21
[2] Ibid.
[3] AIR 2018 SC (SUPP) 1841,
[4] Ibid.
[5] Digital Personal Data Protection Act, 2023 (Act 22 of 2023).
[6] Ibid.
[7] G.S.R. 313(E)
[8]Information Technology Act, 2000 (Act 21 of 2000)
[9] Ibid.
[10]Information Technology Act, 2000 (Act 21 of 2000, ss. 72A, 43A.
[11]The Aadhaar Act, 2016 (Act 18 of 2016)
[12]Supra note 3 at 1.
[13]Supra note 5 at 2.
[14]Supra note 5 at 2.
[15]Supra note 5 at 2.
[16]Supra note 5 at 2.
[17]Supra note 3 at 1.
[18]Supra note 1 at 1.
[19] Rights to Information Act, 2005 (Act 22 of 2005)
[20]Supra note 5 at 2.
[21]Supra note 1 at 1.
[22]Supra note 3 at 1.
[23]Supra note 1 at 1.
[24]Supra note 3 at 1.
[25]Supra note 5 at 2.
[26]Supra note 5 at 2.
[27]Supra note 1 at 1.




Comments