INTRODUCTION
Artificial intelligence (AI) is increasingly being used in India in areas such as policing, healthcare, banking, education, employment, advertising and public administration. AI systems can collect, analyse and interpret large amounts of personal information within seconds. Facial-recognition systems can identify individuals, predictive tools can analyse behaviour, and automated systems can make decisions concerning a person's employment, credit, benefits or access to services.
These developments may improve efficiency and support innovation. However, they also create serious concerns about the right to privacy. AI often depends upon the collection and processing of personal data, including photographs, biometric information, location records, online activity, medical details and personal preferences. When such information is collected or used without adequate safeguards, it can affect a person's dignity, autonomy and freedom.
The Constitution of India does not expressly use the words "right to privacy". Nevertheless, the Supreme Court has recognized privacy as a fundamental right under Article 21, read with Articles 14 and 19. The decision in Justice K.S. Puttaswamy (Retd.) v Union of India established that privacy is an essential part of the right to life and personal liberty. The judgment recognized that privacy protects not only the physical home or body but also personal decisions, identity and control over personal information.
The use of AI therefore raises an important constitutional question: how can India benefit from artificial intelligence while ensuring that individuals are not subjected to unjustified surveillance, profiling or manipulation? This article explains the relationship between AI and privacy under Article 21, examines the legal framework, and argues that India requires stronger safeguards for AI systems that affect fundamental rights.
THE CONSTITUTIONAL BASIS OF PRIVACY
Before Puttaswamy, Indian privacy jurisprudence developed gradually through cases concerning personal liberty, dignity and unlawful State intrusion. In Kharak Singh v State of Uttar Pradesh, the Supreme Court considered the constitutional limits of police surveillance. Although the Court did not initially recognize a broad, independent right to privacy, later decisions gave greater importance to personal liberty and dignity.
In R. Rajagopal v State of Tamil Nadu, the Supreme Court recognized a person's right to be let alone and held that individuals have a right to protect the privacy of their personal life. Similarly, in People's Union for Civil Liberties v Union of India, the Court held that telephone tapping is a serious invasion of privacy and must be authorised and regulated by law.
The constitutional position was conclusively clarified by the nine-judge Bench in Puttaswamy. The Court held that privacy is protected as an intrinsic part of life and personal liberty under Article 21. It also observed that privacy has a relationship with dignity, autonomy, bodily integrity and decisional freedom.
The judgment identified different dimensions of privacy, including:
- Physical privacy, which protects the body and personal space.
- Decisional privacy, which protects personal choices and autonomy.
- Informational privacy, which protects a person's control over personal data.
The most relevant aspect for AI is informational privacy. AI systems can create detailed profiles of individuals by combining information collected from different sources. A person may provide data for one purpose, but AI may later use it for another purpose that the individual did not reasonably expect.
The Supreme Court also established that privacy is not an absolute right. A restriction on privacy must satisfy certain constitutional requirements. In general, the State must show:
- There is a valid law authorising the restriction.
- The restriction pursues a legitimate State aim.
- The restriction is necessary and proportionate.
- Adequate procedural safeguards exist against abuse.
These principles are essential when AI is used for surveillance, crime prevention or public administration.
HOW AI AFFECTS PRIVACY
Collection of personal data
AI systems require large datasets for training and operation. This data may include facial images, fingerprints, voice recordings, health information, financial records, browsing history and location details. The more information an AI system receives, the more accurately it may predict or classify individuals.
The problem is that people often do not understand what data is being collected or how it will be used. Online consent forms are frequently long and technical. In many situations, individuals have no genuine choice because refusing consent may prevent them from using an essential service.
This challenges the idea of informed consent. Consent is meaningful only when a person understands the purpose, extent and consequences of data processing. If an individual agrees to provide a photograph for identity verification, it does not automatically mean that the same photograph can be used for continuous facial recognition or predictive policing.
Facial recognition and mass surveillance
Facial-recognition technology is one of the clearest examples of AI's effect on privacy. It can identify or track individuals through CCTV cameras, public databases and digital platforms. Unlike traditional surveillance, AI can monitor large populations continuously and automatically.
This creates the possibility of mass surveillance. A person may be tracked while travelling, attending a protest, visiting a hospital or meeting another individual. Even if the person has not committed an offence, the system may record and store information about their movements.
Such surveillance can affect Article 21 because privacy includes the right to live without constant observation. It may also affect Article 19(1)(a), which protects freedom of speech and expression, and Article 19(1)(b), which protects peaceful assembly. If people believe that their faces and movements are being recorded, they may avoid expressing unpopular opinions or participating in lawful demonstrations.
The constitutional concern becomes more serious when facial-recognition systems are used without a clear law, defined purpose, independent oversight or limits on data retention. The mere existence of advanced technology cannot justify its unrestricted use. Under Puttaswamy, the State must demonstrate that the system is necessary and proportionate to a legitimate objective.
Profiling and automated decision-making
AI can classify individuals according to their behavior, income, health, education, credit history or perceived risk. This is known as profiling. Profiling may be used by banks to evaluate loan applications, employers to select candidates, insurers to calculate premiums, or law-enforcement agencies to identify persons considered likely to commit an offence.
Although profiling may appear objective, AI systems can reproduce discrimination present in the data used to train them. If historical data contains social or institutional bias, the AI system may produce biased results. For example, a predictive-policing system trained on records of excessive policing in a particular community may wrongly identify that community as more dangerous.
This creates concerns under Article 14, which guarantees equality before the law, as well as Article 21. A person may suffer serious consequences without knowing how the decision was made. An automated system may deny a loan, reject employment or increase surveillance, while its decision remains difficult to challenge.
The right to privacy is therefore linked to transparency and autonomy. Individuals should not be reduced to data profiles over which they have no control. Where an AI decision significantly affects a person's rights or livelihood, there should be a right to receive reasons, seek human review and challenge inaccurate information.
Re-identification and data aggregation
AI can combine different datasets to reveal information about individuals. Data that appears anonymous may become identifiable when combined with location records, photographs, social-media activity or transaction histories. This is known as re-identification.
For example, a dataset may remove names but retain age, location and travel details. When AI compares those details with publicly available information, it may be possible to identify the person. Consequently, anonymization alone cannot always guarantee privacy.
Data aggregation also creates the danger of function creep. Information collected for one purpose may gradually be used for another. A system initially designed to improve traffic management may later be used for policing, immigration control or political monitoring. Without strict purpose limitation, individuals lose control over their personal data.
LEGAL AND POLICY FRAMEWORK
India's principal data-protection legislation is the Digital Personal Data
Protection Act, 2023. The Act regulates the processing of digital personal data and recognizes the relationship between data fiduciaries and data principals. It contains provisions concerning consent, notice, security safeguards and certain rights of individuals, including access to information, correction and erasure in specified circumstances.
The Act is an important step because it recognizes that personal data should not be processed without lawful authority. It also imposes duties upon organisations that determine the purpose and means of processing personal data.
However, the Act has limitations in relation to AI. It does not create a detailed and comprehensive framework for algorithmic accountability. It does not expressly provide a broad right to explanation whenever an automated system makes a decision. It also does not sufficiently address algorithmic bias, model transparency, independent algorithmic audits or the special risks associated with facial recognition.
Another concern relates to exemptions available to the State. If government agencies receive wide exemptions for reasons such as national security, public order or prevention of offences, citizens may have limited ability to know how their data is being processed. National security is an important constitutional objective, but it cannot automatically remove the requirement of legality, necessity and proportionality.
The use of AI by State authorities must therefore be tested against the principles developed in Puttaswamy. A surveillance programme should have a clear legal basis, a defined purpose, limited scope, safeguards against misuse, independent supervision and an effective remedy for unlawful action.
CRITICAL LEGAL ANALYSIS
AI is not unconstitutional merely because it processes personal data. The Constitution permits reasonable restrictions on rights when they are supported by law and justified by a legitimate public purpose. AI may help detect financial fraud, assist disaster management, improve healthcare and strengthen criminal investigations.
The constitutional problem arises when AI is used secretly, excessively or without accountability. The following concerns require particular attention.
First, legality is essential. A general executive order or internal departmental practice should not be sufficient to authorise intrusive surveillance of citizens. Parliament must establish clear legal limits for high-risk AI systems.
Second, proportionality must be applied seriously. The State should prove that the AI system is suitable for achieving its purpose and that no less intrusive alternative is available. Collecting data about the entire population merely because it may be useful in future is unlikely to satisfy this standard.
Third, accuracy is crucial. Incorrect data or faulty AI predictions can cause wrongful arrest, denial of welfare, reputational harm or exclusion from employment. Individuals must be able to correct inaccurate information and challenge decisions based on it.
Fourth, human oversight is necessary. AI should assist decision-making, but it should not replace legal responsibility. A police officer, government official or private organisation should remain accountable for a decision merely because it was generated by software.
Finally, privacy protection must include effective remedies. Citizens should be able to complain to an independent authority, approach constitutional courts and seek compensation or deletion of unlawfully processed data.
THE WAY FORWARD
India should adopt a rights-based approach to AI regulation. The following measures can strengthen Article 21 protections:
- High-risk AI systems should be subject to mandatory privacy and humanrights impact assessments.
- Facial-recognition systems should be regulated by specific legislation rather than general administrative powers.
- Data collection should follow purpose limitation and data minimisation principles.
- Individuals should receive clear information about automated processing affecting them.
- Important decisions should be subject to human review and reasoned appeal.
- Independent audits should examine algorithmic bias, accuracy and security.
- Sensitive data should not be retained indefinitely.
- Government surveillance programmes should have judicial or independent authorisation and periodic review.
- Strong penalties should apply to misuse, unauthorised disclosure and negligent security practices.
- Police, judges, regulators and public officials should receive training in AI, data protection and constitutional rights.
Courts will also play an important role. Judicial review should examine not only whether an AI system has been authorised but also whether it operates fairly and proportionately. Courts should be willing to require disclosure of sufficient information to allow affected persons to challenge the use of AI, while protecting legitimate trade secrets and national-security information.
CONCLUSION
The use of AI has both positive and negative effects on the right to privacy under Article 21. AI can improve public services, assist investigations and promote efficiency. At the same time, it can enable mass surveillance, intrusive profiling, discrimination, re-identification and invisible control over personal decisions.
The judgment in Justice K.S. Puttaswamy (Retd.) v Union of India provides a strong constitutional foundation for responding to these challenges. Its emphasis on dignity, autonomy, informational privacy, legality and proportionality should guide every public and private deployment of AI.
The Digital Personal Data Protection Act, 2023 is a significant beginning, but it does not fully address the special risks posed by artificial intelligence. India requires stronger rules on automated decision-making, facial recognition, algorithmic bias, transparency, human oversight and independent accountability.
Ultimately, technological progress cannot be measured only by the speed or intelligence of machines. It must also be measured by whether technology respects human dignity. AI should serve the individual, not turn the individual into an object of continuous observation and prediction. The future of Article 21 will depend on ensuring that innovation remains consistent with constitutional morality, personal liberty and the right to live with dignity.
REFERENCES
Legislation
- Constitution of India, arts 14, 19 and 21.
- Digital Personal Data Protection Act, 2023.
- Information Technology Act, 2000.
Cases
- Justice K.S. Puttaswamy (Retd.) v Union of India, (2017) 10 SCC 1.
- Kharak Singh v State of Uttar Pradesh, AIR 1963 SC 1295.
- R. Rajagopal v State of Tamil Nadu, (1994) 6 SCC 632.
- People's Union for Civil Liberties v Union of India, (1997) 1 SCC 301.
- Anuradha Bhasin v Union of India, (2020) 3 SCC 637.
Reports and Policy Materials
- Justice A.P. Shah Committee, Report of the Group of Experts on Privacy (2012).
- Srikrishna Committee, A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians (2018).
- NITI Aayog, National Strategy for Artificial Intelligence (2018).
- Ministry of Electronics and Information Technology, policy materials on responsible and ethical AI.
- United Nations, Universal Declaration of Human Rights, art. 12.
- International Covenant on Civil and Political Rights, art. 17.