Abstract
The widespread adoption of Facial Recognition Technology (FRT) across public infrastructure and law enforcement mechanisms has fundamentally reshaped urban governance, public administration, and crime prevention. However, the unregulated deployment of real-time passive facial tracking introduces existential challenges to fundamental human rights. This paper critically examines the intersection of automated biometric processing and constitutional guarantees under Part III of the Constitution of India. Grounded in the landmark jurisprudence of Justice K.S. Puttaswamy (Retd.) v. Union of India, it tests non-consensual FRT systems against the four-prong test of proportionality. Furthermore, it analyzes statutory lacunae within the Digital Personal Data Protection (DPDP) Act, 2023, particularly regarding sweeping state exemptions. Designed as a foundational inquiry for legal researchers and interns, the paper outlines actionable policy pathways to reconcile technological advancement with human dignity, democratic discourse, and civil liberties.
Introduction
Facial Recognition Technology (FRT) utilizes computer vision, biometric mapping, and machine learning algorithms to detect, analyze, and verify facial geometry from images or real-time video feeds. State agencies and commercial actors market FRT as an indispensable tool for identifying missing children, facilitating seamless airport transit (e.g., DigiYatra), managing crowd control, and tracking suspected criminals.
Unlike traditional biometrics—such as fingerprints or iris scans—that require active, consensual physical engagement, FRT operates passively, remotely, and continuously without the explicit knowledge or affirmative consent of the subject. In a constitutional democracy, mass passive surveillance presents a structural challenge to personal liberty. When individuals are perpetually subject to potential identification and tracking in public spaces, the boundary between state authority and personal autonomy dissolves. For legal scholars and law interns navigating modern jurisprudence, evaluating FRT requires moving beyond theoretical tech-ethics to examine how algorithmic processing impacts constitutional law, evidence, and public administration.
Theoretical Foundations: Biometric Data and Informational Privacy
To evaluate the legal implications of FRT, one must first recognize the nature of the data it extracts. An image of a face is not merely visual profile data; it is an aggregation of biological attributes. FRT algorithms extract geometric landmarks—such as nodal points, distance between the eyes, jawline contour, and nose depth—to generate a unique mathematical representation known as a “faceprint” or facial vector.
Informational privacy, as conceptualized in legal theory, grants individuals control over their personal narrative and sensitive digital footprints. Because a faceprint cannot be easily altered or masked without significant effort, its unauthorized collection undermines informational self-determination. Once a facial vector is stored in a centralized system, the subject loses control over where, when, and how their identity is cross-referenced across public and private databases.
Constitutional Jurisprudence: The Article 21 Nexus
The primary constitutional benchmark for testing state-sponsored surveillance in India is Article 21 of the Constitution, which guarantees the Right to Life and Personal Liberty.
A. The Puttaswamy Doctrine
In Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), a nine-judge bench of the Supreme Court held that the Right to Privacy is a fundamental right intrinsic to Article 21. The Supreme Court recognized three core dimensions of privacy:
- Bodily Privacy: Protection against unauthorized physical intrusions.
- Spatial Privacy: Protection against intrusive monitoring within private and public spaces.
- Informational Privacy: Authority over personal data processing.
B. The Four-Prong Test of Proportionality
To determine whether an executive or legislative measure restricting privacy is constitutionally valid, the Court established a four-fold test:
- Legality: The restrictive measure must be backed by a clear, formal parliamentary statute.
- Legitimate State Aim: The measure must pursue a valid public objective, such as national security or crime prevention.
- Proportionality and Necessity: The state must demonstrate that the chosen measure is strictly necessary and represents the least restrictive means available to achieve the target aim.
- Procedural Safeguards: The law must incorporate robust procedural checks, independent oversight, auditability, and data minimization mechanisms to prevent state abuse.
C. Testing FRT Against the Four-Prong Standard
When evaluated against the Puttaswamy criteria, current deployments of FRT in India exhibit constitutional vulnerabilities:
- Failure of Legality: The National Automated Facial Recognition System (NAFRS) and state-level systems (such as TSCOP in Telangana) operate primarily via executive notifications, tender documents, or administrative circulars rather than primary statutory enactments.
- Failure of Necessity and Proportionality: Continuous mass surveillance captures biometric details of thousands of innocent citizens to identify a small subset of suspects. Mass tracking fails the test of minimal intrusion.
- Lack of Independent Oversight: Most systems operate without judicial warrant requirements or independent statutory audit bodies.
A. The Chilling Effect on Article 19 Freedoms
Continuous facial scanning in public spaces impairs fundamental rights under Article 19(1)(a) (freedom of speech and expression) and Article 19(1)(b) (freedom to assemble peacefully). When citizens suspect that their presence at peaceful rallies, public protests, or political gatherings is logged by real-time facial analytics, they alter their behavior. This psychological deterrence—known as the chilling effect—causes citizens to self-censor and refrain from participating in political and civic life.
B. Algorithmic Bias and Article 14
Article 14 guarantees equality before the law and equal protection of the laws. Machine learning models depend on training datasets. Global studies, including benchmark testing by the National Institute of Standards and Technology (NIST), demonstrate that FRT algorithms exhibit higher error rates—specifically false positives and false negatives—when processing images of demographic minorities, women, and marginalized populations.
In criminal justice applications:
- False Positives: Lead to wrongful detentions, coercive police stops, and arbitrary arrests of innocent individuals based on flawed code.
- False Negatives: Cause failure to identify individuals, leading to procedural omissions.
Deploying biased algorithms without statutory error thresholds violates Article 14 by subjecting specific demographics to unequal legal risks and arbitrary police action.
Statutory Framework: Evaluating the DPDP Act, 2023
The enactment of the Digital Personal Data Protection (DPDP) Act, 2023, along with its operational rules, represents a key milestone in India’s data governance framework. Under the Act, biometric features—including facial images and mathematical templates—fall under the category of personal data.
A. Core Compliance Requirements for Fiduciaries
The DPDP framework sets out fundamental principles for Data Fiduciaries:
- Notice and Consent: Data Fiduciaries must provide clear, plain-language notices and obtain explicit consent before processing personal data.
- Purpose Limitation: Data collected for one specific purpose cannot be repurposed without fresh authorization.
- Rights of Data Principals: Individuals retain rights to access, correct, update, and request erasure of their personal data.
B. Critical Exemptions and State Exception Clauses
Despite these structured rules, the DPDP Act contains structural gaps regarding state-sponsored surveillance:
- Section 17 State Exemptions: The central government can exempt state agencies from core provisions of the Act in the interests of state security, sovereignty, public order, or prevention of offenses. This clause shields law enforcement FRT programs from consent, notice, and data minimization mandates.
- Absence of Specific Biometric Mass Surveillance Regulations: The DPDP Act uses a transactional data protection model. It lacks specific provisions governing real-time remote biometric surveillance, public space capture, or automated criminal profiling.
Consequently, while private corporations implementing FRT face regulatory scrutiny and penalties from the Data Protection Board, public sector agencies operate with broad exemptions that lack external checks and balances.
Case Studies and Judicial Challenges
A. The Telangana High Court Challenge (S.Q. Masood v. State of Telangana)
A central judicial challenge to FRT in India emerged in S.Q. Masood v. State of Telangana. The petitioner challenged the Telangana Police’s practice of stopping citizens in public, taking their photographs without consent, and cross-referencing them using the TSCOP mobile app. The petitioner argued that:
- The practice lacked primary statutory authorization, violating the Legality prong of Puttaswamy.
- Random public photo capture treats ordinary citizens as criminal suspects without reasonable suspicion, violating individual dignity and Article 21.
B. The Airport “DigiYatra” Consent Controversy
The introduction of facial recognition gates at Indian airports under the “DigiYatra” initiative raised practical questions regarding consent. While promoted as a voluntary system for seamless travel, reports highlighted instances of airport personnel capturing passenger biometrics without informed consent or enrolling passengers without clear disclosures. This demonstrates how operational realities can undermine statutory consent mechanisms when clear supervisory frameworks are absent.
Comparative Global Standards
| Jurisdictional Region | Governing Legal Instrument | Regulatory Stance on Real-Time FRT | Judicial / Statutory Safeguards |
| European Union | EU Artificial Intelligence Act & GDPR | Categorized as High-Risk / Generally Prohibited in Public Spaces | Requires prior judicial authorization; strict exceptions for specific serious crimes. |
| United States | Patchwork (State Laws & City Ordinances) | Varied; several cities (e.g., San Francisco) introduced total bans | Strict statutory moratoria on public sector facial surveillance in multiple jurisdictions. |
| India | DPDP Act, 2023 & Executive Orders | Broad state exemptions; no dedicated FRT statute | Operates primarily via executive orders; limited independent oversight. |
Practical Guide for Law Interns: How to Analyze FRT Matters
For legal researchers, interns, and young legal professionals evaluating FRT litigation or policy drafting, the following step-by-step framework provides a structured approach:
Step 1: Check Statutory Authority
└─ Is the deployment backed by a statute passed by Parliament/State Legislature?
If NO ──> Challenge on grounds of Legality under Puttaswamy (Art. 21).
Step 2: Evaluate Consent and Purpose Limitation
└─ Was explicit, informed consent collected from the subject?
If NO ──> Check applicability under the DPDP Act, 2023 / Section 17 Exemptions.
Step 3: Analyze Necessity & Minimal Intrusion
└─ Could law enforcement achieve the objective via less intrusive means?
If YES ──> Challenge on grounds of Proportionality.
Step 4: Audit for Bias and Due Process
└─ Has the algorithm undergone independent bias testing and public auditing?
If NO ──> Raise challenges under Article 14 (Arbitrary classification & Error risk).
9. Policy Recommendations
To reconcile law enforcement requirements with constitutional rights, India’s legal regime should incorporate the following reforms:
- Enactment of a Dedicated FRT Regulation Statute: Parliament should enact a specialized law governing biometric surveillance. The law must explicitly define permitted use cases, banned use cases (such as live mass identification without cause), and maximum retention limits for raw video feeds.
- Mandatory Judicial Warrants: Real-time facial scanning in public areas should require a prior judicial warrant issued by a magistrate upon a showing of probable cause.
- Independent Algorithmic Audits: Government agencies must mandate third-party technical audits and publish performance accuracy metrics across demographic groups prior to software deployment.
- Data Protection Impact Assessments (DPIAs): Public entities must conduct and publish DPIAs before initiating mass biometric collection programs.
- Right to Notice and Rectification: Citizens mistakenly flagged by FRT systems must be granted immediate access to audit logs, an administrative appeals process, and avenues to seek legal redress for wrongful detention.
Conclusion
Facial Recognition Technology presents a constitutional challenge: it offers administrative efficiency for state institutions while threatening informational privacy, civil liberties, and individual autonomy. The expansion of automated surveillance without explicit statutory backing risks weakening fundamental rights.

