Facial Recognition & Surveillance in India: Constitutional Issues, Privacy Rights and the Need for a Statutory Framework
Table of Contents
- Frequently Asked Questions
- Is facial recognition technology legal in India?
- Does the Constitution give Indians a right to privacy?
- Can police use facial recognition to investigate crimes?
- Does being in a public place mean a person has no privacy rights?
- Does the DPDP Act regulate police facial recognition?
- What constitutional rights can facial recognition affect?
- Why is facial recognition more intrusive than ordinary CCTV?
- What safeguards should police facial recognition have?
Introduction
Facial recognition technology (“FRT”) has moved rapidly from a futuristic concept to a practical policing and surveillance tool. Police authorities can potentially use facial recognition to identify persons from CCTV footage, compare images against databases, locate missing persons, investigate offences and monitor public spaces.
The legal question, however, is more complicated than whether the technology can assist law enforcement.
The central constitutional question is whether, when and under what safeguards the State may use facial recognition to identify or track individuals.
This question has acquired renewed significance in India in 2026 following legal challenges concerning alleged police surveillance and facial-recognition-enabled monitoring at public demonstrations, including proceedings before the Delhi High Court concerning surveillance at Jantar Mantar. The litigation has brought into sharp focus an unresolved issue: India does not presently have a dedicated, comprehensive statute specifically governing the use of facial recognition technology by police and other State authorities.
That does not mean that police use of technology operates in a complete legal vacuum. Constitutional rights, criminal procedure, evidence law, data-protection legislation, police rules, executive directions and judicial precedents may all be relevant. Indeed, the Delhi High Court was recently reported to have directed attention to the existing legal framework, including applicable statutory provisions and police standard operating procedures, rather than treating the issue as one that exists entirely outside law.
The real controversy, therefore, is narrower—and potentially more significant:
Can general laws and executive policies provide sufficient legal authority and safeguards for a technology capable of biometric identification and large-scale surveillance, or does constitutional legality require a specific statutory framework?
The answer will have major implications for privacy, dignity, equality, free speech, peaceful assembly, policing and the future of AI-driven law enforcement in India.
What Is Facial Recognition Technology?
Facial recognition technology is an AI-enabled system that analyses an image or video containing a human face and generates or compares biometric characteristics to determine whether the person corresponds to an existing image or database record.
In law enforcement, FRT can broadly be used in two ways.
1. Post-event facial recognition
Police may obtain CCTV footage or photographs after an incident and compare faces appearing in those images with an existing database.
For example, investigators may use facial recognition to generate possible matches from footage connected with a criminal investigation.
2. Live or real-time facial recognition
A more intrusive application involves cameras continuously scanning people in a particular location and automatically comparing their faces against a watchlist or database.
This distinction matters constitutionally.
A targeted search for a suspect following a specific offence is materially different from continuously scanning everyone present at a protest, railway station, public square or other public place.
The second model raises the possibility of population-scale identification and tracking.
Why Is Facial Recognition Legally Controversial in India?
The principal difficulty is that facial recognition combines several forms of State power:
- collection of images;
- creation or processing of biometric information;
- identification of individuals;
- database matching;
- surveillance of physical movements;
- potential profiling;
- retention of personal information;
- sharing of information between government databases; and
- potentially automated decision-making.
Each of these activities can implicate constitutional rights.
The Supreme Court’s landmark privacy jurisprudence provides the starting point.
Article 21 and the Constitutional Right to Privacy
In Justice K.S. Puttaswamy (Retd.) v. Union of India, the Supreme Court of India recognised privacy as a constitutionally protected fundamental right.
The judgment is particularly important for facial recognition because it expressly recognised the relationship between modern technology, data collection, surveillance and personal liberty.
The Court observed that technological development has created new instruments capable of invading privacy through “surveillance, profiling and data collection and processing.”
The constitutional position is not that the right to privacy is absolute.
The State can interfere with privacy in appropriate circumstances. But the interference must satisfy constitutional requirements.
Justice Chandrachud’s opinion in Puttaswamy identified three central requirements for restrictions on privacy:
- There must be a law authorising the intrusion;
- The law must pursue a legitimate State aim; and
- The measure must satisfy proportionality.
The judgment emphasised that the existence of law is an essential requirement under Article 21 and that the State’s objective must fall within constitutional limits of reasonableness and non-arbitrariness.
This framework creates the central constitutional problem for facial recognition.
If a police authority deploys facial recognition technology, the question is not merely whether identifying criminals is a legitimate governmental objective. It plainly can be.
The questions are:
Where is the legal authority?
What exactly does that law authorise?
What safeguards does it contain?
How long may the biometric information be retained?
Who may access it?
Can an individual challenge a false match?
What happens to people who are wrongly identified?
Can the system be used for general surveillance rather than a specific investigation?
What independent oversight exists?
These questions go directly to constitutional legality and proportionality.
Facial Recognition and Article 14: The Equality Problem
Facial recognition also raises concerns under Article 14 of the Constitution, which protects equality before the law and equal protection of the laws.
The technology is not necessarily neutral merely because a computer generates the result.
Facial recognition systems can produce false positives and false negatives. Accuracy may vary according to factors such as image quality, lighting, demographic characteristics and the dataset used to train or operate the system.
From a constitutional perspective, a false match can have serious consequences.
Imagine a system identifies an innocent individual as a suspect.
That person could potentially be:
- stopped or questioned;
- subjected to additional police scrutiny;
- associated with a criminal investigation;
- placed on a watchlist;
- denied a benefit or opportunity;
- investigated on the basis of an incorrect identification; or
- subjected to further surveillance.
The constitutional problem becomes more serious when an algorithmic output is treated as though it were conclusive evidence.
An algorithmic match should not automatically become a legal fact.
The existence of a facial-recognition “match” is fundamentally different from proof of identity beyond reasonable doubt.
Articles 19 and 21: Facial Recognition at Protests
The constitutional debate becomes particularly acute when facial recognition is deployed at demonstrations.
Articles 19(1)(a) and 19(1)(b) protect, respectively, freedom of speech and expression and the right to assemble peaceably and without arms, subject to constitutionally permissible restrictions.
A person may technically remain free to attend a protest while simultaneously being deterred from doing so because they know that police cameras may identify and record them.
This phenomenon is often described as a chilling effect.
The surveillance itself may therefore affect constitutional freedoms even if no protester is arrested.
That is why the distinction between ordinary photography and biometric identification is important.
A journalist, police officer or passer-by taking a photograph creates one kind of record.
A facial-recognition system capable of extracting a biometric representation, matching it against a database and potentially linking that identity with other information creates a substantially different surveillance capability.
The Jantar Mantar Surveillance Controversy
The constitutional debate became particularly visible in 2026 following proceedings before the Delhi High Court concerning alleged surveillance of protesters at Jantar Mantar.
A public interest petition filed by former JNU Students’ Union president Aishe Ghosh alleged continuous and intrusive surveillance of protesters, including photography, videography and monitoring. Reporting on the proceedings also referred to allegations concerning facial-recognition technology and AI-enabled surveillance.
The government disputed the characterisation of the activity as unlawful “snooping” and argued that videography at protests could be undertaken for maintaining law and order and public safety. During the proceedings, the government’s side also questioned the proposition that a person can claim privacy in a public place in the same manner as in a private setting.
That argument raises an important legal distinction.
Is there a right to privacy in a public place?
The fact that a person is visible in public does not automatically answer the constitutional question.
A person’s face may be visible to other people. But modern technology can transform an isolated observation into systematic identification, classification and tracking.
The legal issue is therefore not simply:
“Can the police see someone’s face?”
It is:
“Can the State systematically identify, record, analyse, retain and potentially track every person whose face happens to be visible in a public place?”
That is a significantly more serious constitutional question.
The Supreme Court’s privacy jurisprudence recognises that technological capabilities can fundamentally alter the nature and scale of surveillance.
As of late July 2026, reports indicated that the Delhi High Court did not finally determine the constitutional validity of the alleged surveillance in that proceeding. Instead, the Court reportedly advised that a broader petition addressing the legal framework and general guidelines could be considered.
Accordingly, the Jantar Mantar proceedings should not be described as having established a final judicial rule that police facial recognition is either constitutional or unconstitutional.
Does India Have a Facial Recognition Law?
Not a dedicated, comprehensive statute specifically regulating police facial recognition.
This distinction is important.
India has laws dealing with privacy, personal data, electronic records, criminal investigation and surveillance. Government agencies also operate technology systems pursuant to statutory powers, administrative rules, contracts, standard operating procedures and departmental arrangements.
But these instruments do not amount to a single, dedicated Facial Recognition and Biometric Surveillance Act laying down a comprehensive framework for police use of FRT.
This gap has been identified by researchers and civil society organisations for several years. The Centre for Internet and Society, for example, noted the absence of a coherent legal and regulatory framework governing government use of facial recognition technology.
The issue remains significant even after the enactment of the Digital Personal Data Protection Act, 2023.
The Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 (“DPDP Act”) is highly relevant to the discussion because facial images and associated digital information may constitute personal data.
However, the DPDP Act should not be treated as a complete substitute for a police facial-recognition statute.
One reason is the structure of the Act itself.
Section 17 contains significant exemptions. In particular, Section 17(1)(c) excludes specified provisions where personal data is processed in the interest of the prevention, detection, investigation or prosecution of an offence or contravention of law.
Section 17(2) also provides for broader exemptions relating to certain State instrumentalities in specified national-security, public-order and related circumstances.
This creates an important policy question:
If ordinary data-protection obligations do not comprehensively govern law-enforcement processing, what specialised safeguards regulate police biometric surveillance?
That question cannot simply be answered by pointing to the existence of a general data-protection statute.
The DPDP Act’s Phased Commencement Matters
Another important point is timing.
The Central Government notified the commencement framework for the DPDP Act in November 2025. Under that notification, several provisions—including the substantive provisions in Sections 3 to 17—were scheduled to commence 18 months after publication of the notification, while other provisions commenced earlier.
The Ministry of Electronics and Information Technology has also published the Digital Personal Data Protection Rules, 2025 and an enforcement timeline.
Consequently, any legal analysis of facial recognition in August 2026 must be careful not to describe the DPDP Act as though every substantive obligation were already fully operative.
More fundamentally, even once the DPDP framework is fully operational, data protection and biometric surveillance regulation are not necessarily the same thing.
A dedicated police surveillance framework could address matters that a general data-protection statute does not comprehensively resolve.
Why a Dedicated Facial Recognition Framework May Be Necessary
A specialised statutory framework could address questions that are currently difficult to answer uniformly.
1. Purpose limitation
Police should not be able to use facial recognition for unlimited purposes merely because the technology is technically capable of doing so.
A statute could specify permitted purposes, such as:
- identification of persons reasonably suspected of specified offences;
- identification of missing persons;
- identification of unidentified deceased persons;
- investigation of serious offences;
- narrowly defined public-security circumstances.
It could expressly prohibit certain uses, such as political profiling or indiscriminate identification of peaceful protesters.
2. Prior authorisation
The law could establish different authorisation requirements for different levels of surveillance.
For example:
Targeted post-event search: lower threshold.
Real-time facial recognition: higher threshold.
Mass identification at public assemblies: potentially the highest threshold or a prohibition except under narrowly defined circumstances.
Such distinctions would help align surveillance intensity with the seriousness of the State’s objective.
3. Retention limits
One of the most important questions is what happens after facial recognition has been used.
If a person is identified and found not to be connected with an investigation, should the biometric template be deleted immediately?
A statutory regime could require:
- fixed retention periods;
- automatic deletion;
- documented exceptions;
- audit trails;
- restrictions on secondary use; and
- penalties for unauthorised retention.
Without retention rules, temporary surveillance can become permanent population profiling.
4. Human Review of Algorithmic Matches
A facial-recognition match should ordinarily be treated as an investigative lead, not an automatic determination of guilt or identity.
Legislation could require independent human verification before consequential action is taken.
This would be particularly important where:
- the image quality is poor;
- the algorithm reports a low-confidence match;
- multiple possible matches exist;
- the person disputes the identification; or
- the result is being relied upon to justify arrest, search or further surveillance.
5. Accuracy and Independent Testing
A statutory framework could require police departments to publish or maintain information concerning:
- accuracy rates;
- false-positive rates;
- false-negative rates;
- testing methodology;
- demographic performance;
- database composition;
- software versioning; and
- independent audits.
This is especially important because an opaque algorithm makes it difficult for an affected person or court to understand how an identification was produced.
6. Notice and Transparency
The State may legitimately withhold some operational details where disclosure would compromise an investigation.
But complete secrecy creates its own constitutional problems.
A rights-based framework could require publication of:
- the existence of a facial-recognition programme;
- the legal authority for the programme;
- categories of data processed;
- retention periods;
- oversight mechanisms;
- authorised users;
- complaint procedures; and
- aggregate statistics concerning usage.
The public should not have to discover the existence of a biometric surveillance system only after it becomes controversial.
7. Independent Oversight
One of the strongest arguments for statutory regulation is the need to separate surveillance authorisation from unrestricted executive discretion.
Possible safeguards include:
- judicial authorisation for specified forms of surveillance;
- independent supervisory authorities;
- periodic audits;
- legislative reporting;
- internal compliance officers;
- mandatory records of searches;
- complaint mechanisms; and
- judicial review.
The Supreme Court’s earlier surveillance jurisprudence demonstrates the importance of procedural safeguards when intrusive State powers are exercised.
In People’s Union for Civil Liberties v. Union of India, the Supreme Court recognised telephone tapping as a serious invasion of privacy and imposed procedural safeguards designed to prevent arbitrary or indiscriminate interception.
Although telephone interception and facial recognition are technologically different, the broader constitutional principle is relevant: intrusive surveillance powers require safeguards against abuse.
Facial Recognition and the Evidentiary Question
Another under-discussed issue concerns the use of facial-recognition outputs in criminal proceedings.
Suppose a facial-recognition system reports an 85% or 90% similarity between a CCTV image and a person in a police database.
What exactly does that prove?
It does not necessarily establish:
- that the person was physically present at the relevant location;
- that the image was correctly captured;
- that the database image was accurate;
- that the algorithm operated correctly;
- that the algorithm was free from bias;
- or that the person committed the offence.
Facial recognition should therefore generally be distinguished from conventional identification evidence.
The Bharatiya Sakshya Adhiniyam, 2023 provides the contemporary statutory framework governing evidence, including electronic evidence, but the existence of an evidentiary framework does not by itself resolve whether the underlying surveillance or biometric collection was constitutionally authorised.
This produces two separate legal questions:
Was the data lawfully obtained?
and
What evidentiary weight should be given to the resulting identification?
The second question cannot cure the first.
National Automated Facial Recognition System and Broader Surveillance
India has also pursued national and state-level initiatives involving facial recognition and automated biometric identification.
The proposed or developing National Automated Facial Recognition System (“NAFRS”) has generated significant debate concerning centralised databases, police access, privacy, oversight and accountability. Academic and policy commentary has argued that the absence of a dedicated governing framework creates constitutional and institutional concerns, particularly when systems are used for large-scale identification.
The central legal concern is not technological sophistication.
It is institutional power.
A technology that permits the State to identify a person once is different from a technology that permits the State to identify and potentially track millions of people repeatedly.
Scale changes the constitutional analysis.
The Constitutional Test: Legality, Legitimate Aim and Proportionality
The most useful framework for analysing police facial recognition remains the constitutional privacy test emerging from Puttaswamy.
Step One: Legality
There must be a valid legal basis for the State’s interference with privacy.
A police department cannot necessarily create an entirely new category of intrusive biometric surveillance merely through an internal administrative instruction if the underlying power is not traceable to lawful authority.
This is particularly important where the surveillance involves systematic identification rather than ordinary observation.
Step Two: Legitimate State Aim
Law enforcement, crime prevention, public safety and national security can constitute legitimate State objectives.
The constitutional debate therefore should not be reduced to the proposition that “privacy always defeats policing.”
It does not.
The State has a legitimate responsibility to prevent crime and protect public safety.
The question is whether the specific surveillance measure is legally authorised and constitutionally justified.
Step Three: Necessity and Proportionality
Even a legitimate objective does not automatically justify every technological measure.
The State should be able to demonstrate:
- why facial recognition is necessary;
- why less intrusive measures would not adequately achieve the objective;
- why the geographic scope is appropriate;
- why the temporal duration is justified;
- why the database being searched is necessary;
- and what safeguards prevent misuse.
The Supreme Court has repeatedly treated proportionality as a structured constitutional inquiry rather than an unrestricted balancing exercise.
Facial Recognition and Mass Surveillance: Where Is the Line?
The most difficult cases are likely to involve indiscriminate surveillance.
Consider two scenarios.
Scenario A: Targeted investigation
Police investigating a serious offence obtain CCTV footage from a specific location and use facial recognition to generate possible leads.
There is a defined investigative purpose and a specific incident.
Scenario B: Generalised public surveillance
Police continuously scan every individual attending a peaceful political demonstration and compare the resulting biometric data against a broad database.
There is no particularised suspicion concerning each individual.
The second scenario presents substantially greater constitutional concerns because the surveillance is not simply investigative—it can become a mechanism for mapping political participation and association.
This is where Articles 14, 19 and 21 may intersect.
What Should a Future Facial Recognition Law Contain?
A comprehensive Indian facial-recognition statute should ideally establish a clear rights-based framework.
At a minimum, it should address:
- Definitions of facial recognition, biometric templates, live facial recognition and automated identification.
- Permitted purposes for police and State use.
- Prohibited uses, including impermissible political or discriminatory profiling.
- Authorisation requirements for targeted and mass surveillance.
- Judicial or independent oversight for high-risk deployments.
- Data minimisation and purpose limitation.
- Retention and deletion requirements.
- Accuracy and independent algorithmic testing.
- Human verification before consequential decisions.
- Audit logs and access controls.
- Vendor accountability where private companies supply surveillance technology.
- Cybersecurity requirements for biometric databases.
- Rules governing inter-agency database sharing.
- Transparency reports and public accountability.
- Remedies for wrongful identification.
- Compensation or other relief for unlawful processing.
- Penalties for misuse by public officials.
- Special safeguards for children and vulnerable persons.
- Rules governing surveillance at protests and other constitutionally protected assemblies.
- Independent periodic review of the necessity of the surveillance programme.
The Role of Courts
Until Parliament establishes a detailed statutory framework, courts are likely to remain central to determining the constitutional limits of facial recognition.
Judicial review can address questions such as:
- whether the State has legal authority;
- whether the surveillance is arbitrary;
- whether privacy has been disproportionately restricted;
- whether Article 19 rights are affected;
- whether safeguards are adequate;
- whether biometric data has been unlawfully retained;
- and whether affected individuals have an effective remedy.
But courts also face institutional limitations.
Constitutional litigation typically arises after a surveillance programme has already been designed and deployed.
A comprehensive statute can establish rules before surveillance begins.
That is one of the strongest arguments for legislative action.
Conclusion
Facial recognition technology presents a fundamental constitutional challenge because it changes the nature of State surveillance.
The issue is no longer simply whether a police officer may observe a person in a public place. Artificial intelligence can potentially convert an ordinary observation into persistent biometric identification, searchable records and large-scale tracking.
India’s constitutional framework already provides powerful principles against arbitrary State action. The Supreme Court’s privacy jurisprudence under Puttaswamy establishes that an intrusion into privacy must have a legal basis, pursue a legitimate State objective and satisfy proportionality.
The Digital Personal Data Protection Act, 2023 adds an important layer to India’s data-protection architecture, but its law-enforcement exemptions and phased commencement mean that it should not be mistaken for a comprehensive facial-recognition statute.
The 2026 controversy surrounding alleged facial-recognition and surveillance practices at Jantar Mantar illustrates why the issue can no longer be treated as merely technological or administrative. The Delhi High Court proceedings have brought questions of legal authority, police procedures, privacy, public-order powers and constitutional safeguards into the foreground, without yet producing a definitive judicial resolution of the broader issue.
The constitutional debate is therefore likely to continue.
The ultimate question is not whether India should use technology to fight crime.
It is whether technologically powerful surveillance should be governed by equally powerful legal safeguards.
A democratic State may have legitimate reasons to identify suspects, investigate crime and protect public safety. But the greater the State’s technological ability to observe and identify its citizens, the greater the need for legality, transparency, proportionality, accountability and effective remedies.
Facial recognition should not become a zone where technological capability outruns constitutional authority.
Frequently Asked Questions
Is facial recognition technology legal in India?
There is no single comprehensive Indian statute specifically regulating all police and State uses of facial recognition technology. However, that does not mean that facial recognition exists entirely outside the law. Constitutional rights, applicable statutes, criminal procedure, data-protection provisions, police rules and judicial precedents may govern particular deployments.
Does the Constitution give Indians a right to privacy?
Yes. The Supreme Court recognised privacy as a fundamental constitutional right in Justice K.S. Puttaswamy (Retd.) v. Union of India. Restrictions on privacy must satisfy constitutional requirements, including legality, legitimate State purpose and proportionality.
Can police use facial recognition to investigate crimes?
Law-enforcement agencies may use technological tools for legitimate investigative purposes, but the precise legal authority and constitutional validity of a particular facial-recognition deployment depend upon the circumstances, statutory powers, purpose, scope and safeguards involved.
Does being in a public place mean a person has no privacy rights?
No. The constitutional privacy inquiry cannot necessarily be reduced to whether a person is physically visible in public. Modern surveillance technology can transform ordinary observation into systematic biometric identification and tracking, raising additional constitutional questions.
Does the DPDP Act regulate police facial recognition?
The DPDP Act forms part of India’s data-protection framework, but it contains significant exemptions relevant to law enforcement, including processing connected with prevention, detection, investigation or prosecution of offences. It therefore cannot simply be treated as a comprehensive police facial-recognition statute.
What constitutional rights can facial recognition affect?
Depending on how it is deployed, facial recognition may implicate Article 14 (equality), Article 19 (freedom of speech and peaceful assembly) and Article 21 (life, personal liberty and privacy).
Why is facial recognition more intrusive than ordinary CCTV?
Ordinary CCTV may record an image. Facial recognition can automatically identify the individual appearing in that image and potentially connect that identity with databases, watchlists and other information. The capacity for systematic identification and aggregation creates a qualitatively different surveillance risk.
What safeguards should police facial recognition have?
A robust framework should address lawful authorisation, purpose limitation, necessity, proportionality, accuracy testing, human review, retention and deletion, independent oversight, audit trails, transparency, cybersecurity, database access and remedies for wrongful identification.

