

ON MARCH 28, 2026, the Union government announced that the Centre for Development of Telematics (‘C-DOT’) would deploy facial recognition and other policing technologies for Delhi Police. The system would support crowd monitoring and identity verification during deployments for maintaining law-and-order; photographs would be matched against available databases to identify suspects, missing persons and repeat offenders. The announcement says what the systems can do, but not who may place a person on a watchlist, what matching threshold applies, how a false match may be challenged, or which law authorises each use. A press release may announce capacity; it cannot supply the authority or safeguards required for coercive use, which must remain subject to rigorous constitutional oversight.
The constitutional problem is deeper than data collection, storage or use per se. A photograph becomes a query; the query produces a candidate; the candidate so produced can shape law enforcement action against actual people. A combination of databases can reveal facts no source itself discloses, while an algorithm can turn those inferences into suspicion at a very large scale. Moreover, surveillance is largely treated as a relation of power, and aggregation and secondary use as distinct privacy harms. The injury lies in the State’s new capacity to classify and act.
India’s emerging regulatory architecture risks treating procurement, general policing duties, soft AI policy and statutory exemptions as though, together, they supplied legal authority. That is a category error. An exemption is a negative rule: it disapplies specified duties under a particular enactment. Authorisation is positive: it identifies who may exercise an intrusive power, against whom, for what purpose, on what conditions and subject to what remedy. Where State action intrudes upon rights, competence cannot be inferred merely from the absence of a prohibition.
Data and State-generated suspicion
A model does not decide whom the police photograph, where cameras are placed or whose name enters a watchlist. Historical enforcement patterns provide the raw material needed to understand the implications and why it requires significant attention. Jai Vipra’s study of Delhi policing argues that spatial over-policing makes Muslim communities likely to be disproportionately exposed to facial recognition; it does not establish intentional targeting, and its CCTV data were preliminary and incomplete. A very familiar problem of neutral systems reproducing structured inequality. The point is structural: vendor accuracy cannot cure unequal deployment or watchlist design. Technical performance also varies with image quality, demographic group and the threshold selected. This is a distributive harm, where rule-of-law requires Article 14 to scrutinise the watchlist, camera geography, decision of deployment, and deployment map.
The second is a democratic harm. Persistent identification at a protest burdens speech and association even if nobody is arrested. This is not an assertion to be proved. An arrest, search or any action is not required to disrupt free expression or association of people if they are being watched and identified. The idea of a big brother watching by itself induces conformity and fear, without requiring a replication of Orwellian settings. The judicial understanding has been quite clear on this. The constitutional injury need not await arrest or search: knowledge of persistent identification can itself chill participation. In the Pegasus proceedings, the Supreme Court recognised that fear of surveillance may induce self-censorship; the European Court of Human Rights similarly held that facial recognition used to identify and arrest a peaceful protester could chill expression and assembly. A system procured to identify fugitives cannot silently become an instrument for mapping dissent.
The third harm is procedural. Automated classification can harden a probabilistic association into official suspicion without showing the person the data, inference or threshold that produced it. Scholarship on the ‘scored society’ identifies the core demands of procedural fairness: systems must be testable, adverse classifications explainable and errors contestable. A nominal human in the loop is no safeguard if the officer cannot understand the output, obtain corroboration or disagree with it.
The July 2026 CJP protests at Jantar Mantar exposed this problem in practice. Delhi Police told the Supreme Court that facial recognition had identified 2,873 people with criminal records, while maintaining that action required field verification. On September 4, however, an Indian Express investigation reported that at least 25 people on that list were in jail when the system purportedly placed them at the protest. The concern is not simply technical error: provisional matches had entered an official account of the assembly before verification was complete. An assurance that officers will check later cannot substitute for a demonstrable verification procedure. Even accurate identification leaves a separate question: what authorises treating a person’s past record and presence at a protest as grounds for further State action?
The lifecycle problem: powers at collection, silence after it
The Telecommunications Act 2023 and the 2024 interception rules require senior authorisation, recorded reasons, specificity, limited duration, consideration of less intrusive means, records, destruction and executive review. Section 69 of the Information Technology Act, and the 2009 Rules adopt a comparable structure. These restraints are important however they principally govern interception, monitoring or decryption. They do not supply a generally applicable, use-specific framework for what follows acquisition: database fusion, model training, watchlist construction, threshold selection, inference or coercive reliance.
These gaps are compounded by institutional design. Officials who seek, authorise and review interception remain within the executive chain. Review of an interception order does not necessarily examine procurement of a general-purpose system or later repurposing of the data. Across these regimes, there is no generally applicable statutory requirement for a public inventory of high-risk State systems, independent technical audit, aggregate reporting or notice after secrecy is no longer necessary.
Section 4 of the Criminal Procedure (Identification) Act, directs the National Crime Records Bureau to collect, store, process, share and disseminate specified measurements, with records retained for seventy-five years subject to the statutory deletion rule. The Inter-Operable Criminal Justice System integrates police, court, prison, forensic and prosecution databases and expressly enables data analytics and AI/ML tools. This architecture makes it possible for a measurement collected for one statutory purpose to become an input into a qualitatively different system of automated association. As Vidushi Marda argues, limitations at the data, model and application stages must be confronted before deployment, not relegated to retrospective ethics.
Government policy now recognises several of these risks. The 2025 India AI Governance Guidelines recommend risk classification, human oversight, audit trails, transparency and grievance mechanisms, while the 2026 techno-legal white paper treats governance across the AI lifecycle. But these instruments are predominantly principles, recommendations and voluntary measures. They do not themselves confer statutory power, create enforceable disclosure duties or supply a cause of action. Chinmayi Arun’s description of Indian surveillance safeguards as ‘paper-thin’, and Vrinda Bhandari and Karan Lahiri’s account of the surveillance state after Puttaswamy, remain criticisms of our legal architecture and not objections that a better ethics checklist can answer.
Exemption is not authorisation
The Digital Personal Data Protection Act, is relevant but incomplete. ‘Person’ includes the State, while ‘processing’ includes automated operations, alignment and combination. Once the core provisions commence, the Act will impose duties that may constrain governmental processing. Yet section 17(1)(c) disapplies most duties and Data Principal rights where processing is necessary for the prevention, detection, investigation or prosecution of offences; section 17(2)(a) permits notified State instrumentalities to be exempted on sovereignty, security and public-order grounds. At the time of writing, sections 4 and 17 remain scheduled to commence on May 13, 2027.
Comparison sharpens rather than solves the problem. Article 2(3) of the EU AI Act excludes systems used exclusively for military, defence or national-security purposes. For law-enforcement use of real-time remote biometric identification in public spaces, however, Article 5 uses a different regulatory grammar: exhaustive purposes, strict necessity, temporal, geographical and personal limits, prior judicial or binding independent administrative authorisation, and an urgent-use route subject to prompt approval. Its high-risk regime adds risk management, logging, human oversight and fundamental-rights assessment, while the Law Enforcement Directive supplies independent supervision and remedies. These institutions cannot simply be transplanted into India; they demonstrate what authorisation looks like: purpose-specific, ex ante and auditable.
Ram Jawaya Kapur (1955) establishes that executive power is not confined to implementing enacted legislation. But it equally recognises that the executive cannot act contrary to the Constitution or law, or encroach upon legal rights. For Delhi Police, the strongest candidate is section 60(b) of the Delhi Police Act,, which requires officers to obtain intelligence concerning cognisable offences and take lawful preventive steps. That general duty may support ordinary investigation; it does not, without more, prescribe who may enter a biometric watchlist, what matching threshold applies or whether an entire assembly may be remotely identified.
In Bishambhar Dayal Chandra Mohan v. (1982), the Supreme Court held that the executive ‘cannot interfere with the rights of others unless they can point to some specific rule of law which authorizes their acts’. That requirement cannot be satisfied by section 4’s definition of a ‘lawful purpose’ as one not expressly forbidden by law. The provision answers when processing is barred by the DPDP regime; it does not specify who may place an entire protest under biometric identification, populate a watchlist, or convert a probabilistic match into restraint. A procurement contract, memorandum of understanding or general duty to prevent crime does no better. The State cannot bootstrap coercive authority from a statutory silence it helped create.
Puttaswamy completes the point. Intrusion must have a basis in law, pursue a legitimate aim, satisfy necessity and proportionality, and carry safeguards against abuse. Read with Maneka Gandhi (1978), the inquiry cannot stop at lawful collection: it must follow data through matching, inference and coercive use. Any procedure affecting liberty must be fair and non-arbitrary under Articles 21 and 14, while restrictions on speech, association and assembly must independently satisfy Article 19.
A constitutional floor should translate this nexus into use-specific safeguards. Objective and reviewable watchlist criteria, deployment-specific validation, subgroup testing and recorded reasons before consequential action would translate Article 14’s prohibitions of indirect discrimination and arbitrariness into evidence a court can test. Article 19 supports narrower limits of person, place, purpose and time when journalism, association or protest is monitored. Article 21 supports a legal basis, necessity, retention and deletion limits, audit logs, notice when secrecy is no longer justified, and an effective route to reasons, correction and remedy. These safeguards create the record needed to adjudicate legality, rational connection, necessity and non-arbitrariness.
National security associated secrecy is a valid argument only with calibrated procedure and cannot extinguish review. In the Pegasus proceedings, the Supreme Court rejected a ‘free pass’ based on a bare invocation of national security. In Madhyamam Broadcasting (2023), it rejected reflexive reliance on sealed material and required procedures capable of protecting sensitive information without disabling fair adjudication. Public rules can disclose permitted uses, oversight and retention, while genuinely operational material may be protected through redaction, a summary, public-interest-immunity procedures or, where necessary, a court-appointed amicus.
The case for a constitutional floor
The remedial gap is functional rather than total. Statutes regulate particular acts of interception or collection, but no generally applicable, use-specific framework governs the downstream AI lifecycle that produces and operationalises suspicion. PUCL (1996) is the closest analogue: against an existing statutory interception power, the Court imposed requirements of authorisation, necessity, specificity, duration, records and review until rules were framed. Yet it expressly declined to create prior judicial scrutiny without statutory support. PUCL establishes the power to constitutionalise procedure, while warning that independent ex ante approval for high-risk AI requires a separate justification.
Vishaka (1997) supplies the temporal form to the argument: rights-derived guidelines that are binding until legislation occupies the field. DK Basu (1997) supplies the method. The Court did not rewrite the law of arrest; it made coercive power auditable through identification, an arrest memo, notice, records, and medical examination. An AI analogue is a record of the watchlist source, query, model and list version, threshold, result, human reasons and downstream action. Prakash Singh (2006) supports independent structure, but its directions followed extensive commission reports and expert convergence; the Court sought further study where that material was absent. The proper course is therefore an expert-assisted constitutional minimum, not judicial improvisation.
Ashwini Kumar Upadhyay (2026) sets the boundary. Courts may fill interstitial gaps to enforce fundamental rights, but cannot create a detailed and enduring policy scheme; Vishaka cannot be invoked where legislation already occupies the field. The claimed vacuum must therefore be defined narrowly: not policing or data processing as a whole, but the absence of use-specific conditions governing the conversion of automated inference into coercive State action. Any intervention should be temporary, evidence-based and confined to rights-intrusive uses such as remote biometric identification in public space, protest or location monitoring, cross-database profiling and automated outputs that materially affect liberty.
Within that narrow field, interim directions should require: first, identification of the legal source and authorised purpose; secondly, before high-risk deployment, a recorded fundamental-rights and proportionality assessment addressing less intrusive alternatives, watchlist criteria and deployment-specific validation; thirdly, tamper-evident audit logs, retention limits, corroboration and recorded human reasons before an output materially affects liberty; and fourthly, an effective avenue for correction and judicial challenge. For the most intrusive uses, the Court could require approval by a functionally independent authority, with a narrow emergency route and prompt review, but it must explain why later proportionality doctrine and the technology’s scale justify this step despite PUCL.
This basic rule-of-law based idea does provide us with a minimum benchmark, and may yield proper legislation with equivalent or hopefully stronger safeguards. Until then, judicial abstention cannot be viewed as neutrality as it leaves the executive to define, deploy and review its own power with new capabilities. The Court is not required to decide policy, rather it must establish that technological capacity or statutory exemption cannot be treated as constitutional permission for surveillance. The emergence of new technology always brings with it new and novel ways of coercion and control, therefore it is essential that safeguards should develop and be applied at the same pace, especially if the use poses a direct harm to the rights of the people at large.