Published On: August 22, 2026
Authored By: Solihah Rashid
Univeristy of Kashmir
1. Introduction
In the modern digital era, the rapid growth of information and communication technologies (ICTs) has fundamentally altered the model of human interaction, commercial transactions, and state governance. While this technological revolution has democratized access to services and administrative efficiency, it has simultaneously introduced an existential crisis for individual autonomy through extensive data collection and digital surveillance.[1] Governments and private entities now harvest, process, and monetise vast reserves of Personally Identifiable Information (PII) and sensitive metadata, often operating within regulatory vacuums or under outdated statutory frameworks.[2]
In India, the jurisprudential landscape underwent a framework shift with the unanimous declaration by a nine-judge bench of the Supreme Court that the Right to Privacy is a fundamental right under Article 21 of the Constitution.[3] Even so, a significant disconnect remains between constitutional doctrine and executive/legislative practice. Despite the constitutional principle established in Justice K.S. Puttaswamy (Retd.) v. Union of India, India’s legal structure governing data protection and state surveillance remains structurally weak.[4]
The statutory structure depends on legacy colonial laws, such as the Indian Telegraph Act, 1885, along with intermediate legislation like the Information Technology Act, 2000 (IT Act), and the newly passed Digital Personal Data Protection Act, 2023 (DPDP Act), which heavily favours executive discretion over individual rights.[5] This article critically analyses the current legal structure governing data privacy and state surveillance in India. It argues that the present system fails to fulfil the constitutional standard of proportionality, suffers from institutional deficits, and disproportionately privileges state security and corporate interests at the cost of citizen rights.
2. Concept of Data Privacy and Digital Surveillance
Understanding the interconnection between data privacy and digital surveillance requires clarifying their scope within modern legal theory. Data privacy refers to an individual’s dynamic capability to exercise control over their personal data, determining how, when, and to what degree information about them is collected, processed, and shared.[6] It covers informational self-determination, an intrinsic component of human dignity that protects against unjustified interference by state and non-state actors.[7]
Digital surveillance involves the systematic monitoring, collection, interception, and analysis of digital footprints, communications, metadata, and online behaviours.[8] While state surveillance can be a legitimate tool for protecting national security and combating complex criminal activity, unrestricted surveillance inherently erodes democratic freedoms.[9]
The concept of the “panoptic state” illustrates how continuous monitoring induces self-censorship, chills free expression under Article 19(1)(a), and restrains political dissent.[10] The basic challenge lies in establishing strict legal standards that prevent state surveillance from collapsing into arbitrary mass data collection.
3. Legal Framework Governing Data Privacy in India
3.1 Constitutional Protection
The constitutional basis of data privacy in India was affirmed in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017).[11] Overruling earlier decisions in M.P. Sharma v. Satish Chandra[12] and Kharak Singh v. State of U.P.,[13] the Supreme Court confirmed that privacy is a fundamental constitutional right derived from Article 21 (Right to Life and Personal Liberty) and integrated across Part III’s fundamental freedoms.
Importantly, the Court held that any state action restricting the right to privacy must satisfy a three-fold test: Legality, Necessity, and Proportionality.
Legality: The existence of a clear, well-defined law authorising the infringement.
Necessity/Legitimate State Aim: The measure must pursue a legitimate governmental objective.
Proportionality: The nature and extent of the interference must be proportional to the goal sought to be achieved, ensuring the least restrictive means are used and accompanied by adequate procedural safeguards against abuse.[14]
3.2 Statutory Framework and the DPDP Act, 2023
Formally, India’s statutory protection of personal data depends on Section 43A of the Information Technology Act, 2000, read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules).[15] This statutory framework suffered from significant weaknesses:
It applied only to corporate bodies, exempting government departments from liability for data breaches.
It covered a narrow set of “sensitive personal data” (such as passwords, financial data, and medical records), leaving general metadata unprotected.
Its enforcement mechanisms were weak, lacking dedicated regulatory oversight.[16]
To address these weaknesses, Parliament passed the Digital Personal Data Protection Act, 2023 (DPDP Act), following recommendations by the Justice B.N. Srikrishna Committee (2018).[17] While the DPDP Act introduces positive changes such as statutory duties for “Data Fiduciaries,” notice requirements, and substantial financial penalties for data security breaches, it retains structural flaws regarding state surveillance.[18]
In particular, Section 17 of the DPDP Act grants the Central Government broad powers to exempt any state instrumentality from the provisions of the Act on grounds such as “security of the State,” “public order,” and “prevention of offences.” This broad exemption creates a statutory gap that weakens the privacy protections established in Puttaswamy.[19]
Legal Framework / Statutory Basis & Era: Legacy Framework (2000–2011) — IT Act, 2000 (s 43A); SPDI Rules, 2011.
Primary Scope: Commercial entities; narrow “sensitive” data.
Primary Failure/Vulnerability: Fully exempted government entities; no independent data protection authority.
Legal Framework / Statutory Basis & Era: Current Regime — DPDP Act, 2023.
Primary Scope: Digital personal data processing.
Primary Failure/Vulnerability: Broad executive exemptions under Section 17; weak oversight independence.
4. Legal Framework on Digital Surveillance
Digital surveillance in India operates under a collection of pre-digital and early-internet statutes that centralise power within executive authorities.
4.1 The Indian Telegraph Act, 1885
Wiretapping and interception of telecommunications are governed by Section 5(2) of the Indian Telegraph Act, 1885.[20] Interception is permitted only during a public emergency or in the interest of public safety, on grounds such as state security, friendly relations with foreign states, or public order.
In People’s Union for Civil Liberties (PUCL) v. Union of India (1997), the Supreme Court recorded the lack of procedural safeguards in Section 5(2) and issued administrative guidelines to prevent arbitrary interception.[21] These guidelines were later codified as Rule 419A of the Indian Telegraph Rules, 1951. Under Rule 419A, interception orders must be authorised by the Union Home Secretary or State Home Secretary, subject to post-facto review by an executive Review Committee.[22]
4.2 Section 69 of the Information Technology Act, 2000
With the rise of digital networks, the state’s surveillance capabilities were extended under Section 69 of the IT Act, 2000, and the Information Technology Rules, 2009.[23] Section 69 widens executive power beyond the Telegraph Act by removing the conditions of “public emergency” or “public safety.” The state can authorise the interception, monitoring, or decryption of any digital information for the “investigation of any offence.”[24]
Both frameworks depend entirely on executive authorisation. The Home Secretary authorises interception, and a committee of fellow executive secretaries reviews the order. The absence of independent, prior judicial oversight creates a systemic conflict of interest, leaving executive surveillance decisions largely unchecked.[25]
5. Judicial Developments and Case Law
5.1 The Puttaswamy Ratio and the Four-Prong Proportionality Test
The foundational jurisprudence on Indian data privacy remains the 2017 Puttaswamy judgment. Beyond declaring privacy a fundamental right, Justice K.M. Joseph and Justice Sanjay Kishan Kaul highlighted that informational privacy safeguards individual freedom in an interconnected world.[26] The decision adopted a four-prong test of proportionality derived from comparative constitutional law:[27]
Legitimate Goal
Rational Connection
Necessity (Least Restrictive Means)
Proportionality Stricto Sensu
5.2 The Aadhaar Judgment: K.S. Puttaswamy (Aadhaar) v. Union of India (2018)
In the 2018 Aadhaar decision, a constitution bench examined the constitutionality of India’s targeted delivery of subsidies via biometric identification.[28] The majority upheld the Aadhaar Act, ruling that its statutory purpose satisfied the proportionality test by securing economic rights and food distribution under Article 21. However, the Court struck down specific provisions that encroached on individual privacy:
Key Provisions Struck Down by the Court:
Section 47: Struck down for prohibiting individuals from initiating prosecution for data misuse.
Section 57: Struck down to prevent private corporations from demanding Aadhaar data for commercial service provision.[29]
The dissenting opinion of Justice D.Y. Chandrachud raised structural concerns regarding biometric collection. He observed that centralising personal biometric and demographic data creates vulnerability to surveillance and state profiling, which can harm constitutional rights.[30]
6. Critical Issues and Structural Gaps
India’s growing surveillance ecosystem and data protection rules reveal deep structural weaknesses that risk facilitating executive overreach against fundamental rights. Section 17 of the Digital Personal Data Protection (DPDP) Act, 2023, grants broad exemptions to state instrumentalities, establishing a legal asymmetry that burdens the private sector while weakening executive accountability and violating the proportionality principles developed in Puttaswamy.[31][32] This issue is compounded by procedural gaps under Rule 419A of the Telegraph Rules and the 2009 Information Technology Rules, which confine surveillance authorisation and review to executive officials without independent judicial oversight.[33][35] Moreover, centralised systems such as the Central Monitoring System (CMS), NETRA, and NATGRID allow direct access to communications data without clear statutory governance or public reporting mechanisms, raising mass-surveillance concerns.[33][36] Finally, in the private sector, commercial data practices relying on dark patterns and unbalanced terms of service render user consent largely formalistic rather than meaningful, further exacerbating the imbalance of power between citizens and the state and corporations.[34]
7. Balancing Privacy and National Security: The Proportionality Framework
Balancing individual privacy with legitimate national security interests requires a structured proportionality model. National security is a valid state aim, but it cannot function as an unchecked justification for unrestricted executive action.[40][41][43]
To keep this balance consistent with constitutional standards, the surveillance framework should incorporate three basic elements:
Ex-Ante Judicial Authorisation
Targeted Surveillance over Mass Collection
Data Minimisation and Destruction Protocols
8. Comparative Legal Analysis
Examining international legal frameworks offers comparative perspectives for strengthening India’s statutory system.
8.1 European Union: The General Data Protection Regulation (GDPR)
The European Union’s GDPR (Regulation 2016/679) provides a comprehensive framework for informational self-determination.[44]
Key features include: Scope, Core Rights, Institutional Independence, and Surveillance Jurisprudence.
8.2 United States: Foreign Intelligence Surveillance Act (FISA) and ECPA
While the United States lacks a single federal data privacy law, its electronic surveillance framework contains judicial checks under the Foreign Intelligence Surveillance Act (FISA) and the Electronic Communications Privacy Act (ECPA).[48] The Foreign Intelligence Surveillance Court (FISC), though operating under specialised procedures, provides an independent judicial check on wiretapping applications, requiring demonstrated probable cause.[49]
8.3 Key Comparative Takeaways for India
Applicability to State — EU (GDPR): Full application; narrow exemptions. United States (ECPA/FISA): Statutory rules apply to state agencies. India (DPDP Act, 2023 & IT Act): Broad executive exemptions (s 17 DPDP Act). Proposed Indian Reforms: Restrict state exemptions; apply strict proportionality tests.
Oversight Mechanism — EU: Independent Data Protection Authorities. United States: Foreign Intelligence Surveillance Court (FISC). India: Executive Review Committees (Home Secretary). Proposed Indian Reforms: Introduce an independent Judicial Oversight Tribunal.
Surveillance Threshold — EU: Strictly targeted; mass retention prohibited. United States: Probable-cause warrants required. India: Broad “investigation of any offence” criteria. Proposed Indian Reforms: Narrow grounds exclusively to serious threats.
9. Conclusion
India’s constitutional jurisprudence recognises the Right to Privacy as a fundamental human right under Article 21. However, statutory implementation continues to fall behind these constitutional standards. Reliance on executive self-review, combined with the broad immunities and relief available under the Digital Personal Data Protection Act, 2023, leaves citizens vulnerable to arbitrary state surveillance and unregulated corporate data harvesting. To align the legal architecture with the principles established in Justice K.S. Puttaswamy, India requires legislative reform centred on transparency, clarity, accountability, and impartiality.
References
[1] Daniel J. Solove, Understanding Privacy (Harvard University Press 2008) 12–15.
[2] Graham Greenleaf, Asian Data Privacy Laws: Data Protection Regulation in the Region (Oxford University Press 2014) 45–48.
[3] Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) 10 SCC 1 [263].
[4] ibid [310].
[5] Information Technology Act 2000; Digital Personal Data Protection Act 2023.
[6] Alan F. Westin, Privacy and Freedom (Atheneum 1967).
[7] Puttaswamy (n 3) [118] (Chandrachud J).
[8] David Lyon, Surveillance Society: Monitoring Everyday Life (Open University Press 2001) 23–27.
[9] Anja Kovacs, ‘Surveillance Reform in India’ (Internet Democracy Project 2015) 8–12.
[10] Shoshana Zuboff, The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power (PublicAffairs 2019) 81–84.
[11] Puttaswamy (n 3).
[12] M.P. Sharma v. Satish Chandra AIR 1954 SC 300.
[13] Kharak Singh v. State of U.P. AIR 1963 SC 1295.
[14] Puttaswamy (n 3) [310] (Nariman J).
[15] Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (SPDI Rules).
[16] Apar Gupta, ‘Data Protection in India: The Current Framework and Missing Links’ (2019) 12 Journal of National Law University Delhi 45, 49.
[17] Ministry of Electronics and Information Technology, A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians (Report of the Committee of Experts on Data Protection, Chaired by Justice B.N. Srikrishna, 2018).
[18] Digital Personal Data Protection Act 2023, ss 4, 8, 33.
[19] ibid s 17.
[20] Indian Telegraph Act 1885, s 5(2).
[21] People’s Union for Civil Liberties (PUCL) v. Union of India (1997) 1 SCC 301 [28].
[22] Indian Telegraph Rules 1951, r 419A.
[23] Information Technology Act 2000, s 69; Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules 2009.
[24] Information Technology Act 2000, s 69(1).
[25] Chinmayi Arun, ‘Paper Rules, Digital Rights: Protection in the Surveillance State’ (2014) 29 India International Centre Quarterly 78, 82.
[26] Puttaswamy (n 3) [520] (Kaul J).
[27] ibid [325]; see also Modern Dental College & Research Centre v. State of M.P. (2016) 7 SCC 353.
[28] K.S. Puttaswamy (Aadhaar-5 J.) v. Union of India (2019) 1 SCC 1.
[29] ibid [512].
[30] ibid [1120] (Chandrachud J dissenting).
[31] Arushi & Sangwan, D. (2026). Constitutional Validity of AI-Based Surveillance in India: Privacy vs. National Security. International Insurance Law Review, 34(S1), 355–356.
[32] Gandhi, A. (2026). Digital Rights as Fundamental Rights: Privacy, AI and Article 21 in the Age of the Digital Personal Data Protection Act, 2023. Lex Scripta Magazine by Integrity Education India.
[33] Jain, A. (2020). The Development of Surveillance Technology in India. Verfassungsblog.
[34] Kumar Bisht, A., & Shanmuka Sreenivasulu, N. (2024). Information Privacy Rights in India: A Study of the Digital Personal Data Protection Act, 2023. Data Privacy – Techniques, Applications, and Standards.
[35] Mohanty, B. (2016). Inside the Machine: Constitutionality of India’s Surveillance Apparatus. Indian Journal of Law and Technology, 12, 1–30.
[36] Reddy, J. (2014). The Central Monitoring System and Privacy: Analysing What We Know So Far. Indian Journal of Law and Technology, 10, 1–25.
[37] ibid 112.
[38] Solove (n 1) 98.
[39] Digital Personal Data Protection Act 2023, s 6.
[40] Manohar Lal Sharma v. Union of India (2021) 8 SCC 421 [56].
[41] PUCL (n 21) [32].
[42] Tele2 Sverige AB v. Post- och telestyrelsen (2016) C-203/15 (CJEU).
[43] Srikrishna Committee Report (n 17) 74.
[44] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR) [2016] OJ L119/1.
[45] GDPR, arts 17, 20, 22.
[46] GDPR, arts 51, 83.
[47] Tele2 Sverige AB (n 42) [108].
[48] Foreign Intelligence Surveillance Act 1978 (50 U.S.C. § 1801 et seq.); Electronic Communications Privacy Act 1986 (18 U.S.C. § 2510 et seq.).
[49] Orin S. Kerr, ‘The Fourth Amendment and New Technologies: The Case for Caution’ (2009) 102 Michigan Law Review 801, 815.
Primary References & Bibliography
Statutes and Regulations
Constitution of India 1950.
Digital Personal Data Protection Act 2023 (India).
Foreign Intelligence Surveillance Act 1978 (United States).
Indian Telegraph Act 1885 and Indian Telegraph Rules 1951.
Information Technology Act 2000 (India).
Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules 2009 (India).
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (India).
Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR).
Judicial Decisions
Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) 10 SCC 1.
K.S. Puttaswamy (Aadhaar-5 J.) v. Union of India (2019) 1 SCC 1.
Kharak Singh v. State of U.P. AIR 1963 SC 1295.
M.P. Sharma v. Satish Chandra AIR 1954 SC 300.
Manohar Lal Sharma v. Union of India (2021) 8 SCC 421.
Modern Dental College & Research Centre v. State of M.P. (2016) 7 SCC 353.
People’s Union for Civil Liberties (PUCL) v. Union of India (1997) 1 SCC 301.
International Courts
Tele2 Sverige AB v. Post- och telestyrelsen (2016) C-203/15, Court of Justice of the European Union (CJEU).




