INTRODUCTION
The rapid expansion of the digital economy and the proliferation of internet-enabled technologies have fundamentally altered the landscape of human interaction, governance and civil liberties. In constitutional democracies, fundamental rights—particularly privacy and freedom of speech and expression—serve as safeguards against arbitrary state action and unjustified intrusion by public or private actors. Yet many constitutional frameworks were designed before smartphones, cloud computing, social media, facial recognition and artificial intelligence became part of everyday life. The result is a difficult legal question: how should rights developed in a largely physical world be protected when personal life, communication, identity and political participation increasingly take place online?
In India, this tension has become especially significant. The Supreme Court's recognition of privacy as a fundamental right in Justice K.S. Puttaswamy (Retd.) v. Union of India marked a major constitutional development.¹ At the same time, Parliament has created new statutory frameworks for digital data and online intermediaries. The Digital Personal Data Protection Act, 2023 (DPDP Act) seeks to regulate the processing of digital personal data, while the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (IT Rules) impose duties on intermediaries and digital platforms.² These measures respond to legitimate concerns about cybercrime, misinformation, online abuse and data misuse, but they also raise questions about the limits of governmental power and the responsibilities of private technology companies.
THE CONSTITUTIONAL EVOLUTION OF THE RIGHT TO PRIVACY
For decades, the Indian Constitution did not expressly mention a general right to privacy. Early decisions reflected uncertainty about whether privacy could be treated as a fundamental right. In M.P. Sharma v. Satish Chandra, the Supreme Court took a restrictive approach to privacy in the context of search and seizure.³ In Kharak Singh v. State of U.P., the Court considered police surveillance and domiciliary visits, and although the majority did not recognise a general constitutional right to privacy, it invalidated domiciliary visits at night.⁴ These cases reflected an older constitutional understanding in which personal liberty was frequently considered through the more visible categories of physical restraint and movement.
The constitutional position changed gradually as Article 21 was interpreted more broadly. The Court came to understand “life” and “personal liberty” as concepts connected with dignity, autonomy and the conditions necessary for meaningful existence. The decisive development came in Justice K.S. Puttaswamy (Retd.) v. Union of India. A nine-judge bench unanimously held that privacy is a constitutionally protected right arising from the guarantees of life, personal liberty and the broader structure of fundamental rights.⁵ Privacy was understood not simply as secrecy, but as an aspect of dignity and individual autonomy. The judgment recognised different dimensions of privacy, including bodily, spatial, decisional and informational privacy.
This is particularly important in the digital environment because personal information can reveal intimate details about an individual's identity, relationships, health, finances, movements, political interests and habits. A person's digital footprint can therefore become a detailed representation of the person themselves. The collection and processing of such information may affect autonomy even where the individual has not suffered a conventional physical invasion.
Puttaswamy also established that privacy is not absolute. Restrictions on the right must satisfy constitutional requirements commonly expressed through legality, legitimate state aim and proportionality.⁶ First, there must be a valid legal basis for the interference. Second, the interference must pursue a legitimate objective. Third, the measure must bear a rational relationship to that objective and must not impose a disproportionate burden on the individual.
The proportionality principle is especially important for surveillance technologies. Governments may legitimately need access to information to prevent terrorism, investigate serious offences, protect national security and deliver public services. However, the availability of powerful technology creates the possibility of collecting more information than is actually necessary. A constitutional system should therefore distinguish targeted and justified surveillance from indiscriminate data collection. Independent oversight, clear retention periods, purpose limitations and remedies for abuse are essential if surveillance powers are to remain compatible with fundamental rights.
FREEDOM OF SPEECH AND EXPRESSION ON DIGITAL PLATFORMS
Article 19(1)(a) of the Constitution guarantees citizens the right to freedom of speech and expression. The internet has transformed the practical meaning of this right because digital platforms allow individuals to publish opinions, receive information, organise communities and participate in public debate without relying exclusively on traditional media institutions.
The Supreme Court recognised the constitutional significance of internet-based expression in Anuradha Bhasin v. Union of India.⁷ The Court held that freedom of speech and expression through the medium of the internet is constitutionally protected, while also recognising that the right is subject to restrictions permitted by Article 19(2). This establishes an important principle: the fact that communication occurs online does not remove it from constitutional protection.
Nevertheless, online speech presents problems that are more complicated than traditional forms of publication. Content can be reproduced instantly, distributed across borders and amplified by algorithms. False information can spread rapidly, while harassment, threats and incitement can cause real-world harm. The state therefore has legitimate reasons to regulate certain forms of online conduct. The constitutional difficulty arises when regulation becomes so broad that lawful criticism, political disagreement or unpopular opinions are suppressed.
In Shreya Singhal v. Union of India, the Supreme Court struck down section 66A of the Information Technology Act, 2000 because the provision criminalised online communications using vague and overbroad expressions.⁸ The decision is significant because it demonstrates that technological regulation must still comply with constitutional standards of clarity and precision. A law cannot create an offence merely because speech is annoying, inconvenient or offensive in an undefined sense.
The IT Rules, 2021 represent a further development in the regulation of digital intermediaries. They impose due-diligence obligations on intermediaries and establish additional requirements for significant social media intermediaries.⁹ Some regulation is necessary to create accountability, particularly where platforms have become central to public communication. However, excessive takedown obligations, uncertain definitions or pressure to remove lawful content may encourage platforms to over-censor. This creates a chilling effect: users may avoid lawful expression because they fear that their content will be removed or that they may face legal consequences.
DATA PROTECTION AND THE DIGITAL PERSONAL DATA PROTECTION ACT
The protection of informational privacy requires more than constitutional recognition. It also requires legislation capable of regulating the everyday collection and use of personal information by governments and businesses. The DPDP Act, 2023 was enacted to provide a framework for processing digital personal data while recognising both individual interests and lawful data use.¹⁰
However, the effectiveness of a data protection regime depends on the strength of its safeguards. One important concern concerns exemptions under section 17. The Act permits specified processing activities to fall outside significant parts of its protective framework, including processing connected with the prevention, detection, investigation or prosecution of offences. It also allows exemptions for certain State instrumentalities where notified in specified national-interest circumstances.¹¹ Such exceptions may be justified where secrecy or rapid access to information is necessary, but they must not become a route through which constitutional privacy protections are effectively bypassed.
The Act is also being implemented in stages rather than through a single commencement date. The Government's 13 November 2025 notification placed several substantive provisions, including sections 3 to 17, on an eighteen-month commencement timetable.¹² This means that legal analysis should distinguish between enacted provisions and provisions that have not yet become operational. The Digital Personal Data Protection Rules, 2025 were notified in November 2025 and provide the detailed implementation framework, with some rules taking effect later.¹³
The statutory framework should also be assessed in light of the growing importance of artificial intelligence. AI systems depend heavily on data, and automated systems may make or influence decisions affecting employment, credit, education, policing and access to services. Where the underlying data is inaccurate or biased, automated processing can reproduce or magnify discrimination. Individuals may also find it difficult to understand why an algorithm produced a particular result. Transparency, accountability and human review are therefore essential components of rights-respecting technological governance.
SURVEILLANCE, ARTIFICIAL INTELLIGENCE AND EMERGING CONSTITUTIONAL RISKS
Modern technology has expanded the state's ability to monitor communications, analyse large datasets and identify individuals through biometric systems. These tools can support legitimate objectives such as crime prevention and national security, but their constitutional risks are substantial. The availability of sophisticated surveillance can create a concentration of power if monitoring operates without adequate legal and institutional controls.
AI also creates challenges for freedom of expression. Generative AI can produce synthetic images, audio and text at scale, making it harder for citizens to distinguish genuine information from manipulated material. The Government has consequently considered further regulation of synthetically generated information through proposed amendments to the IT Rules.¹⁴ Such regulation may be justified to reduce serious harms, but it should be carefully drafted so that measures against deceptive content do not become tools for suppressing satire, criticism, journalism or political speech.
CONCLUSION AND WAY FORWARD
The digital age has transformed the relationship between citizens, the state and technology companies. Privacy and freedom of expression remain fundamental rights, but protecting them now requires legal rules capable of responding to data-driven technologies, algorithmic decision-making and digital communication.
First, judicial oversight should be strengthened in areas involving significant interference with privacy, including surveillance, interception and large-scale data access. Executive authorities should not be the only institutions capable of determining whether intrusive measures are justified.
Second, statutory exemptions should be narrowly framed and accompanied by procedural safeguards. National security and crime prevention are legitimate objectives, but constitutional rights should not disappear merely because personal data is processed by a public authority.
Third, platform regulation should emphasise due process. Users should receive clear notice when content is restricted, meaningful reasons for decisions and accessible mechanisms for review. This can reduce both under-enforcement of genuine harms and over-removal of lawful speech.
Fourth, AI regulation should incorporate transparency, accountability and human oversight. Individuals affected by consequential automated decisions should, where appropriate, have a meaningful opportunity to understand and challenge those decisions.
Finally, digital rights require more than legislation. Courts, regulators, technology companies and citizens must develop a culture of constitutional responsibility. The central question should not be whether technology can perform a particular task, but whether its use is consistent with dignity, liberty, equality and the rule of law.
India's constitutional framework is capable of adapting to technological change because fundamental rights are not limited to the circumstances that existed when the Constitution was drafted. The task is to ensure that innovation strengthens human freedom rather than weakening it. A successful digital constitutional order must therefore combine technological progress with legality, proportionality, accountability and effective remedies.
FOOTNOTES
1. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
2. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021; Digital Personal Data Protection Act, 2023.
3. M.P. Sharma v. Satish Chandra, AIR 1954 SC 300.
4. Kharak Singh v. State of U.P., AIR 1963 SC 1295.
5. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
6. Ibid., paras 260–265.
7. Anuradha Bhasin v. Union of India, (2020) 3 SCC 637.
8. Shreya Singhal v. Union of India, (2015) 5 SCC 1.
9. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, as amended.
10. Digital Personal Data Protection Act, 2023, Act No. 22 of 2023.
11. Digital Personal Data Protection Act, 2023, s 17.
12. Ministry of Electronics and Information Technology, Notification G.S.R. 843(E), 13 November 2025.
13. Digital Personal Data Protection Rules, 2025, Ministry of Electronics and Information Technology, notified 14 November 2025.
14. Ministry of Electronics and Information Technology, Draft Amendments to the IT Rules, 2021 relating to synthetically generated information, 22 October 2025.