Abstract
This article examines the expanding use of biometric surveillance, particularly facial recognition technology, against protesters in India, and its uneasy fit within the constitutional privacy framework established in Justice K.S. Puttaswamy (Retd.) v. Union of India. Using the Delhi Police’s deployment of facial recognition at the 2026 Cockroach Janta Party protests as a case study, it argues that such deployments fail even the threshold requirement of legality under the Puttaswamy test, let alone necessity and proportionality. The article situates this failure within a broader pattern, tracing how surveillance infrastructure built for welfare delivery and crime detection has been repurposed to target dissent, from the 2019-20 anti-CAA protests to present-day financial crackdowns on protest funding. Drawing on comparative jurisprudence, including R (Bridges) v. Chief Constable of South Wales Police, Digital Rights Ireland, Carpenter v. United States, and the EU AI Act, it proposes that India needs targeted legislation grounded in the Puttaswamy test itself, rather than a new constitutional doctrine, to close the widening gap between the right to privacy and its practice.
On July 20, 2026, thousands of young people marched toward Parliament in New Delhi to protest a paper leak in the NEET examination, organizing under the banner of the Cockroach Janta Party. They were subject, instead, to baton charges and tear gas. Parked near the protest site was a police vehicle equipped with cameras that were actively running facial recognition on the crowd, a system built to flag individuals with criminal records, as the Delhi Police later told the Supreme Court. Counsel for the petitioners made a simple observation in reply: it is not possible to scan a single face in a crowd and match it against a database without the system observing everyone in that crowd in order to find the one person it seeks. This was not an isolated incident.
It is the culmination of a surveillance system that India has spent more than a decade building. This system was originally built for welfare delivery but has been increasingly repurposed, often in secrecy, to track people who disagree with the government.
The Doctrinal Foundation, and Its Erosion
In Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), a nine-judge bench of the Supreme Court did what two earlier benches had declined to do in M.P. Sharma (1954) and Kharak Singh (1964): it held that privacy is a fundamental right protected under Articles 14, 19, and 21 of the Constitution, and that it forms part of human dignity and autonomy. The judgment did not stop at declaring the right; it built a test for when the state may lawfully intrude on it. There must be a law authorizing the intrusion; that law must serve a legitimate state purpose; and the means used must be suitable and go no further than necessary to achieve that purpose.
In the Aadhaar judgment (Puttaswamy II, 2018), the Court applied the same test to the biometric identity project and, for the most part, upheld it, concluding that Aadhaar was a consensual data-sharing system with statutory backing under the Aadhaar Act, 2016, aimed at welfare delivery. Justice D.Y. Chandrachud dissented forcefully, and subsequent litigation has chipped away at parts of the scheme, but the core principle has held: collecting biometric data is not inherently unconstitutional if it satisfies the three-part test. Eight years on, it is worth asking whether the state’s use of the technology at protests would pass that test at all.
Delhi Police has effectively answered that question itself in the CJP protest litigation before the Supreme Court. The force has admitted it never conducted a privacy impact assessment before deploying facial recognition at the protest, and never publicly announced that it would use the technology. The faces matched against its database are run under a colonial-era statute, the Identification of Prisoners Act, 1920, superseded only in 2022 by the Criminal Procedure (Identification) Act, which was designed to standardise the collection of convict and arrestee records, not to enable real-time biometric surveillance of peaceful gatherings. No law authorises this deployment at Jantar Mantar, which makes it hard to satisfy even the first limb of the Puttaswamy test: legality. Necessity and proportionality fare worse still. As the Internet Freedom Foundation has documented, Delhi Police treats an 80 percent facial-similarity score as a positive match, a threshold being used to generate suspects out of a crowd that has, by all accounts, remained peaceful and shown no connection to any offence.
Dissent as the Target
This is not an isolated pattern. During the 2019-20 protests against the Citizenship (Amendment) Act, an automated facial recognition system that Delhi Police had originally procured from a startup to trace missing children was activated for crowd control within days of the Act’s passage, and was later used, according to police records, to identify “habitual protesters.” Dozens of anti-CAA activists, many of them women, including several students from JNU and Jamia, were charged under the Unlawful Activities (Prevention) Act (UAPA) after the February 2020 Delhi riots, on the theory that raising funds and organising logistics and food distribution for the protests amounted to a “larger conspiracy.” These individual cases remain under appeal. The overall pattern, however, is clear: tools built by law enforcement to trace money and identity were turned toward tracing protest, and became grounds for prosecution.
This is what privacy is meant to protect: not merely secrecy, but the freedom to organise, assemble, and disagree with the state without that participation becoming a UAPA charge. When a person’s biometric identity, financial records, and location data sit in separate departmental silos that the state can link at will, there is no real zone of autonomy left for them to make choices in. This forms precisely the digital panapticon theory extensively talked about in Indian legal scholarship, an idea fundamental to post-modern approaches to the State.
What Other Courts Have Done With the Same Problem
This is not an exclusive issue faced by India and there is a viable alternative between unrestricted surveillance and banning the technology altogether, as suggested by comparative jurisprudence.
The United Kingdom’s first judicial ruling on live facial recognition, R (Bridges) v. Chief Constable of South Wales Police (2020), did not consider the technology to be per se illegal. In that case, the Court of Appeal concluded that South Wales Police’s use of the system infringed on Article 8 of the European Convention on Human Rights (ECHR) due to the excessive discretion they have in deciding who to watchlist and the lack of clarity on where the system was to be deployed, and because the force’s data protection impact assessment had not taken into account those aspects. The call was not to prohibit the technology, but to establish an explicit and well-defined legal framework, which is lacking from Indian police.
In Digital Rights Ireland (2014) the Court of Justice of the European Union (CJEU) took a more extreme stance, finding that the Data Retention Directive of the EU was disproportionate to its security objectives, even if it provided the security benefits. The Court determined that the possibility of mass retention gives the impression to people that their private life is monitored at all times. The harm of the Constitution, in other words, was not only the potential for misuse but the abatement of free speech itself.
In Carpenter v. United States (2018), the US Supreme Court came to a similar conclusion about cell-site location data derived from the typical use of a cell phone, ruling that such data is still protected by the Fourth Amendment if it affords the government “near-perfect surveillance” of the person’s movements. Assumptions of privacy in small portions of shared information are no match for technologies which are designed to track everyone, all the time.
The EU’s AI Act, which will enter into force in 2025, is the most direct answer to India’s current situation: It explicitly prohibits the use of real-time remote facial recognition by law enforcement in the public space, with narrow exceptions (finding abducted children, preventing an imminent terrorist attack), which must be specifically authorised by a judge or prosecutor. This is in contrast to India, where a private member’s bill to control the deployment of facial recognition by police, which was introduced in the Rajya Sabha in 2023, has languished for years, and the technology has been deployed more prolifically on the ground.
What Should Change
All of this demands no new constitutional doctrine. It demands the use of the one it has in India. The Parliament should pass a separate legislation for biometric surveillance at public gatherings that is grounded on the Puttaswamy test itself: a public and open criterion for who is put on a watchlist; an impact assessment prior to deployment and a default prohibition on retention of biometric data of people who do not appear on the watchlist. Financial and banking measures to be implemented against protest funders (FCRA proceedings, investigations under PMLA, freezing of accounts etc.) should also be subject to a proportionality test so that logistical support of protest (without the element of violence or unlawful purpose) should not be classified as unlawful. But the seriousness of a challenge such as the CJP protest litigation is not just the harm which follows from that scanning of the crowd, but the harm being done by the scanning itself, as Digital Rights Ireland pointed out.
Puttaswamy’s question for the state was a challenging one for the court on the extent of intrusion into private life. What is left is to ensure that police, ministries and investigative agencies also comply with that standard, rather than thinking that they are beyond the technology that they are supposed to be regulating.


Leave a Reply