Yours in Law logo
YoursInLaw
Article

Data Protection and Digital Privacy: The Future of Personal Information Laws in India - Reinforcing Democracy or Orwellian?

Privacy and transparency are values that work together. Privacy protects people from the government and transparency makes sure that the government is accountable to the people. We need to make sure that our data protection laws do not allow the government to keep secrets and hide what they are doing.

Mohammad Amaan

25 August 2026

Introduction:

At the center of today’s data laws is a notable conflict between consent-based privacy laws and broad state exemptions. Modern democracies see the importance of giving individuals control over their personal information. However, this goal is often weakened by wide-ranging clauses that let government agencies ignore these protections. This contradiction creates a scenario where private companies face strict regulations through detailed consent processes, while the state has almost limitless access to the same data, making the legal system uneven and deeply flawed.

This situation prompts an important discussion about technological progress and the surveillance of citizens. Governments usually defend extensive data collection as necessary for efficient administration and digital updates. However, without strong safeguards, these actions could turn digital systems into tools for mass surveillance. To better understand this issue, we must outline a clear approach: first identifying the problem, then mapping existing laws, analyzing gaps, and finally proposing a solution focused on citizens.

The Legal Framework:

India’s data protection landscape has evolved through a complex decade-long journey, beginning with the rapid growth of the Aadhaar system in 2014. The backlash against this started with K.S. Puttaswamy v. Union of India1 ruling in 2017. The Supreme Court firmly established the right to privacy within Article 212 of the Constitution. This significant decision led to the formation of the Justice Srikrishna Committee in 2017-183, sparking a turbulent legislative process. Over the next few years, multiple versions of Data Protection and privacy Bills were proposed in 2018, 2019, and 2021, but these were all taken back. This extensive back-and-forth finally resulted in the passing of the Digital Personal Data Protection (DPDP) Act in 20234, followed by the release of the DPDP Rules in November 2025.

However, understanding the current legal situation requires knowing what is actually in effect versus what is still pending, something that greatly concerns digital media users, news organizations, and major tech platforms. The implementation of the DPDP Act is planned in three clearly defined phases, so the 2023 Act is not fully operational yet. The first phase included the creation of the Data Protection Board in November 2025, followed by the introduction of the Consent Manager framework in November 2026. Importantly, the government has stated that the complete range of obligations will only be outlined and put into effect by May 2027, leaving an extended transition period where compliance mechanisms and regulatory guidelines remain uncertain.

Gaps and Flashpoints in the act:

a) DPDP Act's Section 44(3) and Narrowing of RTI Act Exemptions

Section 44(3) of the Digital Personal Data Protection (DPDP) Act, 20235, systematically alters the operational mechanics of the Right to Information (RTI) Act, 20056, by amending Section 8(1)(j). Under the original RTI framework, Public Information Officers (PIOs) could disclose personal information if an overriding public interest justified it. Section 44(3) eliminates this "public interest override" entirely, replacing it with a broad, blanket bar against disclosing any "personal data"—defined expansively under Section 2(t) as any data capable of identifying an individual. By removing the balancing test previously performed by information authorities, the amendment enables state bodies to routinely reject RTI applications concerning public officials' assets, official conduct, and administrative irregularities simply by labeling the requested information as personal data.

In response, petitions filed before the Supreme Court of India in early 2026—including The Reporters' Collective Trust v. Union of India7, alongside filings by the National Campaign for People's Right to Information (NCPRI) and the Software Freedom Law Centre (SFLC)—have challenged the constitutional validity of Section 44(3). Petitioners contend that the law subverts the fundamental right to privacy recognized in K.S. Puttaswamy8, transforming a shield designed to protect citizens against state overreach into a mechanism that protects state functionaries from democratic oversight. Because the DPDP Act provides no statutory exemption for journalistic activities, investigative reporters seeking to expose corruption face immediate legal friction, as reporting on public figures can be treated as non-consensual processing of personal data.

b) Section 17 Exemptions and Asymmetric State Surveillance

Section 17 of the DPDP Act grants extensive exemptions to government agencies, permitting them to collect, process, and retain personal data without adhering to core obligations such as obtaining consent, issuing data processing notices, or complying with data minimization principles. While private entities and commercial platforms face stringent compliance requirements and financial penalties, government instruments are granted wide latitude under vague grounds like sovereignty, state security, and public order. This structural bifurcation creates a severe legal asymmetry: the state assumes sweeping authority to collect citizen data while exempting itself from the operational constraints imposed on non-state actors.

Digital rights commentators, including MediaNama founder Nikhil Pahwa, argue that Section 179, alongside rules such as Rule 23 of the DPDP Rules10, establishes state surveillance with limited judicial oversight. Under these provisions, the government can compel private intermediaries to surrender user data without notifying the affected individual, precluding any opportunity for prior judicial review or constitutional challenge. This framework institutionalizes a one-way transparency model where citizens remain continuously visible to executive agencies, creating a pervasive chilling effect on free speech, civil association, and journalistic source protection.

c) AI-Powered Surveillance at Protests and Constitutional Challenges.

The integration of artificial intelligence into public policing—demonstrated by the deployment of facial recognition technology (FRT) vehicles (such as "Ikshana"), AI smart glasses, and automated camera feeds at public demonstrations—marks a transition from traditional crowd management to active biometric profiling. During public assemblies at locations like Jantar Mantar, law enforcement agencies have utilized real-time facial recognition software and cataloged personal digital identifiers (such as social media handles) of attendees. Police authorities justify these measures under routine law-and-order maintenance, maintaining that biometric scanning helps identify individuals with criminal records.

This practice faces direct judicial scrutiny in the Delhi High Court through Aishe Ghosh v. Union of India11. The petitioner argues that subjecting peaceful demonstrators to mass biometric surveillance without explicit statutory backing violates the fundamental right to privacy established in K.S. Puttaswamy. The petition contends that the executive deployment of FRT fails the three-fold test of legality, legitimate state aim, and proportionality. In the absence of legislative protocols governing the collection, retention, and destruction of facial recognition data, indiscriminate biometric logging threatens to criminalize peaceful assembly under Article 19(1)(b).

d) MeitY’s 2026 IT Amendment Rules and the Deepfake Regulatory Lag.

On February 10, 2026, the Ministry of Electronics and Information Technology (MeitY) notified amendments to the Information Technology (Intermediary Guidelines and Digital Media Ethics Code)12 Rules to address the rise of AI-generated content and deepfakes. The 2026 Amendment provides a formal legal definition for "Synthetically Generated Information" (SGI) and establishes compliance mandates for digital platforms. Intermediaries are required to implement visible watermarking, embed tamper-evident provenance metadata, deploy automated filtering tools, and observe a strict 3-hour takedown window for deceptive synthetic media.

While these rules demonstrate an executive effort to counter digital impersonation and election-related misinformation, they also highlight how primary legislation lags behind technological shifts. Addressing complex generative AI harms through delegated executive rules rather than primary parliamentary enactments creates enforcement challenges and pushes platforms toward over-censorship to avoid intermediary liability. Furthermore, because the DPDP Act contains no explicit provisions regulating the unauthorized scraping of public personal data for AI model training, the current legal framework struggles to reconcile automated innovation with individual rights over identity and digital likeness.

Critical Analysis:

Part A: Panopticism, Surveillance, and the Chilling Effect

Panopticism, Surveillance, and Michel Foucault

A French philosopher and social theorist of considerable influence, Michel Foucault revolutionized the theory of power through his groundbreaking 1975 work Discipline and Punish: The Birth of the Prison13. Foucault challenged the concept of "sovereign power"—power based on violence—by focusing on "disciplinary power." Disciplinary power is exercised through surveillance and control of space, time, and human activity.

To elucidate his idea of "disciplinary power," Foucault used Jeremy Bentham’s model of Panopticon14, an architecture designed in the 18th century by Bentham, consisting of a central watchtower surrounded by individual cells. Most importantly, the blind windows of the tower make sure that the inmates can never ascertain whether they are under observation. Foucault explains that the main function of Panopticon is to cause a state of consciousness of permanent visibility that guarantees the proper functioning of power in the prisoner's mind. As the prisoner can possibly be seen at all times, there is no need for coercion and violence, as the prisoner himself becomes the jailer of himself by becoming the object of surveillance.

Application to Modern Digital Governance and Chilling Effects

Transposed to contemporary digital architecture, panopticism explains how CCTV deployment, state data trails, and pervasive metadata retention generate profound "chilling effects" on civic behavior. In the modern state, visibility is no longer constrained by brick-and-mortar watchtowers; it is distributed across data networks, biometric registries, and public surveillance apparatuses15.

Because16 citizens know their online queries, location logs, and physical communications are subject to retroactive state scrutiny, they proactively adjust their behavior to avoid suspicion. This produces self-censorship, where individuals voluntarily suppress political dissent, avoid reading controversial information, or refrain from peaceful assembly. The panoptic mechanism operates flawlessly here: the mere possibility of state observation—rather than actual, human surveillance in real time—transforms public behavior, eroding civil liberties without the state firing a single shot or issuing a formal ban.

Section B: Hegemony, Manufactured Common Sense, and Click-Through "Consent"

Antonio Gramsci and Ideological Hegemony

Italian Marxist theorist Antonio Gramsci developed the concept of hegemony in his Prison Notebooks (written between 1929 and 1935)17 to explain how ruling elites maintain political order. Gramsci posited that power is sustained through a dual apparatus: domination (direct physical coercion executed by the military, legal system, and police) and hegemony (cultural, moral, and intellectual leadership).

Hegemony is achieved when the dominant class successfully projects its own worldview onto the subordinate classes, transforming its specific economic and political interests into universal, undisputed "common sense" (senso comune). When power operates through common sense, citizens willingly accept the existing social order as natural, inevitable, and beneficial, rendering physical force largely redundant18.

Click-Through Consent as Substantive Coercion

In digital regulatory regimes, Gramscian hegemony manifests in the pervasive "click-through" agreement architecture—such as terms of service, privacy policies, and cookie banners. Tech platforms and digital states frame these mechanisms through the hegemony of market choice and user autonomy: data collection is presented as a neutral, "common sense" trade-off for accessing modern conveniences19.

However, while these agreements are formally voluntary (the user explicitly clicks "I Agree"), they are substantively coerced. In an era where digital access is a prerequisite for banking, employment, education, and public welfare, an individual possesses zero bargaining power. Refusing to consent results in functional exile from contemporary economic and civic life. The legal regime surrounding digital boilerplate contracts relies on the manufactured myth of informed consent, masking a deeply unequal structural power dynamic where users are compelled to surrender their personal data trails.

Section C: The Counter-Narrative: State Rationale, Efficiency, and Governance

Modern Administrative Rationale and Digital India20

To construct a rigorous critical analysis, critiquing state surveillance must be counterbalanced by examining the legitimate administrative justifications for digital legibility. Sovereign states frame large-scale digital identification and data integration systems—such as India's Digital India initiative and the Aadhaar framework—not through the lens of population control, but as transformative infrastructure for social and economic equity.

From this administrative standpoint, centralized data trails remove friction from state service delivery, enabling direct benefit transfers (DBT) that eliminate institutional corruption, middleman leakages, and ghost beneficiaries. By substituting bureaucratic discretion with algorithmic verification, the state purports to enforce administrative neutrality, ensuring welfare reaches vulnerable populations efficiently and transparently.

Economic Modernization and State Legibility

Beyond welfare distribution, data integration is positioned as a fundamental prerequisite for economic growth and national competitiveness under frameworks like "Ease of Doing Business." 21Digitizing financial transactions, tax compliance (e.g., GST platforms), and identity verification lowers transaction costs for commercial enterprises and accelerates fintech innovation.

Political theorist James C. Scott notes in Seeing Like22 a State that modern statecraft requires making society "legible"—simplifying complex social realities into standardized data points for effective planning. From the government’s perspective, surveillance infrastructure and data visibility are necessary tools to safeguard national security, streamline revenue collection, and manage public health emergencies. The central legal and philosophical tension, therefore, lies between the imperative to build an efficient, developmental state and the constitutional mandate to protect individual autonomy from overreach.

Conclusion:

1. Citizen-Centric Frameworks: Adapting GDPR’s Consent and Data Protection Architecture.

The way we think about data governance needs to change. We need to move from a system that is centered around the government to one that is centered around the individual. Now the idea of consent is not very meaningful because the government and big companies have a lot of power and can do what they want. To really protect people’s data, we need to follow the example of the European Union’s General Data Protection Regulation23. This means that people should have control over their data and be able to say what happens to it. They should be able to access their data correct it if it is wrong and delete it if they want to.

We also need an authority that is independent and can make sure that the rules are being followed. The current plan for the Digital Personal Data Protection Act is to give enforcement powers to a Data Protection Board. This board will not be independent and will be controlled by the government. We need to make sure that the regulatory body is independent and has the power to enforce the rules.

If we do not have an independent regulator then the idea of consent will not mean very much. Companies and the government will be able to do what they want with people’s data and people will not be protected.

2. Safeguarding Democratic Participation and Article 19 Guarantees.

We need to make sure that our data protection laws do not undermine the rights to speech and expression that are guaranteed in the Constitution. Now there is a problem with the way that privacy is being used to limit public accountability. For example, Section 44(3) of the Digital Personal Data Protection Act24 removed the " interest" test from the Right to Information Act. This means that the government can keep secrets and not tell people what they are doing even if it is in the interest.

Privacy and transparency are values that work together. Privacy protects people from the government and transparency makes sure that the government is accountable to the people. We need to make sure that our data protection laws do not allow the government to keep secrets and hide what they are doing.

We also need to be careful about surveillance. If the government is watching people all the time it can stop them from speaking out and exercising their rights. This is called the " effect". We need to make sure that our data protection laws protect journalists, researchers and whistleblowers and that people are able to speak out and express themselves without fear of being punished.

3. Rebalancing National Security and Fundamental Rights.

25National security is important. It should not be used as an excuse to take away people’s rights. The government has an interest in keeping people safe but this should not mean that they can do whatever they want. Now the law gives the government a lot of power to collect data and surveillance people without any real oversight.

We need to make sure that any time the government collects data or surveys people it is only done in a way that's necessary and proportionate to the threat. The government should have to get permission from a judge before they can collect data. They should have to tell people what they are doing. We also need to make sure that data is not kept for long. That it is deleted when it is no longer needed26.

If we can get the balance right between security and fundamental rights then we can make sure that the government is protecting people without taking away their rights. This is what a democratic republic is, about.

References:

Cases-

  • Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
  • Aishe Ghosh v. Union of India & Anr***.***, W.P.(C) No. 9639/2026 (Delhi High Court)
  • The Reporters' Collective & Nitin Sethi v. Union of India (W.P.(C) No. 177/2026, Supreme Court)

Legislations-

  • Article 21
  • Digital Personal Data Protection Act, 2023
  • Right to Information Act, 2005
  • Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026
  • Digital Personal Data Protection Rules, 2025
  • General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679)

Government Reports-

  • Srikrishna Committee Report
  • Khera, Reetika. (2019). Dissent on Aadhaar
  • Ministry of Electronics and Information Technology (MeitY), Government of India. Digital India: Power To Empower. Policy White Papers / Annual Reports.
  • DIGIPUB News India Foundation & Editors Guild of India Statements (Nov 2025)

Academic Sources-

  • Foucault, Michel. (1975). Discipline and Punish: The Birth of the Prison.
  • Bentham, Jeremy. (1791). Panopticon; or, The Inspection-House. London: T. Payne.
  • Richards, Neil M. (2013). "The Dangers of Surveillance." Harvard Law Review, 126(7), 1934–1965
  • Gramsci, Antonio. (1971). Selections from the Prison
  • Zuboff, Shoshana. (2019). The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power.

Footnotes

  1. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.

  2. The Constitution of India, 1950, Art. 21.

  3. Report of the Committee of Experts under the Chairmanship of Justice B.N. Srikrishna, A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians (2018).

  4. The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023).

  5. Section 2(t) (Definition of Personal Data), Section 17 (Exemptions for State Instrumentalities), and Section 44(3) (Amendment to the Right to Information Act, 2005).

  6. Right to Information Act, 2005: Section 8(1)(j)

  7. The Reporters' Collective Trust & Anr. v. Union of India, W.P.(C) No. 211/2026 (Supreme Court of India) (Challenging Section 44(3) of the DPDP Act regarding its impact on RTI disclosures and investigative journalism).

  8. K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 (Landmark Constitution Bench judgment establishing the fundamental right to privacy under Article 21 and the triple test of legality, necessity, and proportionality)

  9. Nikhil Pahwa / MediaNama Commentary: Technical analysis on DPDP Section 17 government exemptions, Rule 23 opacity, and state surveillance risks.

  10. Digital Personal Data Protection Rules, 2025: Rule 23 (Government access powers and data retention provisions).

  11. Aishe Ghosh v. Union of India & Anr***.***, W.P.(C) No. 9639/2026 (Delhi High Court) (Challenging the deployment of facial recognition technology and AI surveillance at public protest sites).

  12. Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026: Notified by MeitY on February 10, 2026 (Introducing provisions on Synthetically Generated Information, metadata provenance, and takedown timelines).

  13. Foucault, Michel. (1975). Discipline and Punish: The Birth of the Prison. Translated by Alan Sheridan. New York: Vintage Books. (Essential text for the Panopticon and internalizing surveillance).

  14. Bentham, Jeremy. (1791). Panopticon; or, The Inspection-House. London: T. Payne. (The original architectural concept).

  15. Richards, Neil M. (2013). "The Dangers of Surveillance." Harvard Law Review, 126(7), 1934–1965. (Definitive legal text on how state surveillance produces chilling effects on thought and speech).

  16. Solove, Daniel J. (2007). "'I've Got Nothing to Hide' and Other Misunderstandings of Privacy." San Diego Law Review, 44, 745. (Key text debunking state arguments against the need for privacy).

  17. Gramsci, Antonio. (1971). Selections from the Prison Notebooks. Edited and translated by Quintin Hoare and Geoffrey Nowell Smith. International Publishers. (Foundation for ideological hegemony and "common sense").

  18. Zuboff, Shoshana. (2019). The Age of Surveillance Capitalism: The Fight for a Human Future at the New Frontier of Power. PublicAffairs. (Synthesizes consent architecture, data extraction, and structural power).

  19. Radin, Margaret Jane. (2013). Boilerplate: The Fine Print, Vanishing Rights, and the Rule of Law. Princeton University Press. (Critical legal study of modern digital terms of service).

  20. Ministry of Electronics and Information Technology (MeitY), Government of India. Digital India: Power To Empower. Policy White Papers / Annual Reports.

  21. Khera, Reetika. (2019). Dissent on Aadhaar: Big Data Meets Big Brother. Orient Blackswan. (Focuses specifically on the Indian context, balancing state claims of welfare efficiency against biometric exclusion).

  22. Scott, James C. (1998). Seeing Like a State: How Certain Schemes to Improve the Human Condition Have Failed. Yale University Press. (Essential political theory on "state legibility")

  23. General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) (Benchmark model for citizen-centric consent architecture and independent Data Protection Authorities)

  24. Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) (Specifically Sections 17 [State Exemptions], 36 [Government Requisition of Data], and 44(3) [Amendment to Section 8(1)(j) of RTI Act])

  25. Central Public Information Officer, Supreme Court of India v. Subhash Chandra Aggarwal, (2019) 11 SCC 641 (Key judgment settling the balance between the Right to Information under Article 19(1)(a) and the right to privacy under Section 8(1)(j) of the RTI Act).

  26. The Reporters' Collective & Nitin Sethi v. Union of India (W.P.(C) No. 177/2026, Supreme Court) (Writ petition challenging Section 44(3) of the DPDP Act, 2023, regarding the blanket exemption diluting public-interest RTI disclosures).