The Constitutional Challenges of Facial Recognition in India

thelawmonitor
5 Min Read
The Constitutional Challenges of Facial Recognition in India

The deployment of facial recognition systems in India is expanding rapidly, particularly in public spaces, yet there is a significant absence of a comprehensive legal framework to regulate their use. Imagine the bustling Howrah Station in Kolkata, where about a million commuters pass daily under the watchful lens of numerous cameras. These devices silently compare everyone’s face against a confidential watchlist, known only to a select few officials. Similar situations unfold in the corridors of the Ram Mandir in Ayodhya, where worshippers are identified using police databases, and across Ahmedabad, where the city’s “safe city” control room employs comparable technology. These systems often operate without proper notification or consent from the public.

Investigative reports have revealed that much of this surveillance technology is provided by Herta Security, a Spanish company. Their facial recognition software reportedly powers thousands of cameras across India, in ways that would be illegal within the European Union, as noted by European legal scholars. While the EU has classified real-time biometric identification in public spaces as an “unacceptable risk” under its Artificial Intelligence Act set to be enforced in 2025, India promotes its use under the banner of “smart policing” and “passenger safety.”

India’s attractiveness as a market stems from the disparity between theoretical legal protections and their practical enforcement. The issue is not just about a technology that outpaces existing laws, but about the absence of a law altogether. The Supreme Court of India, in its landmark ruling in Justice KS Puttaswamy v. Union of India, established privacy as intrinsic to Articles 14, 19, and 21 of the Constitution, outlining a four-pronged test for any State action that infringes on privacy.

This test demands that such action be lawful, serve a legitimate state aim, maintain proportionality, and include procedural safeguards. However, India’s Automated Facial Recognition Systems (AFRS) fail at the first hurdle because there is no parliamentary Act that permits their operation by police, railways, or temple trusts. Instead, fragmented documents, police manuals, and unrelated court orders, such as the Delhi High Court’s direction in Sadhan Haldar v. NCT of Delhi, are inappropriately used as legal justification for broader surveillance programs.

Impact on Fundamental Rights

Article 19(1) guarantees the freedom of speech and peaceful assembly, but the awareness of being constantly monitored can deter individuals from exercising these rights. This also affects journalists and protestors who rely on Article 21’s assurance of liberty. Moreover, the technology’s inherent flaw is the shift of the burden of proof onto those marked by the system.

Although the executive may argue that existing police powers and judicial directions provide sufficient legal basis, these do not meet the standards set by the Puttaswamy judgment, nor do they fulfill democratic principles requiring parliamentary legislation.

The EU AI Act, specifically Article 5(1)(h), prohibits real-time biometric identification in public spaces except under stringent conditions, requiring judicial approval and fundamental rights assessments. Similarly, the European Court of Human Rights in Glukhin v. Russia deemed Moscow’s use of live facial recognition to track a protester as a violation of rights to privacy and free expression.

Conversely, India’s Digital Personal Data Protection (DPDP) Act, 2023, under Section 17(2)(a), offers broad exemptions for State agencies, without the judicial oversight emphasized in Europe. This results in Indian citizens being test subjects for technology deemed too risky for use in Europe.

Addressing the Challenges

To rectify these issues, legislative and executive action is essential. Parliament should halt the further implementation of AFRS until a dedicated law is established, outlining permissible use cases, requiring independent approvals, and imposing penalties for misuse. A mere executive notification cannot justify a breach of fundamental rights.

The blanket exemptions under Section 17(2)(a) of the DPDP Act must be tightened, and no public deployment of biometric surveillance should occur without a published Algorithmic Impact Assessment. A sunset clause should be included to ensure surveillance orders expire after a predetermined period.

Courts must rigorously apply the four-part test from Puttaswamy in reviewing AFRS-related cases, ensuring that biometric mechanisms are a last resort. Until these matters are addressed by parliament, India’s use of AFRS remains uneasy within its constitutional framework.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *