Every fact web-verified against primary sources

The Lift Line

A law built on asking permission cannot protect the one person who was never going to be asked.

Why This Editorial Matters for Your Exam

This connects a live technology story to the constitutional right to privacy and to India’s principal data protection statute. It is examinable in GS2 as rights and legislation, and in GS3 as technology governance.

GS Paper 2: Fundamental Rights; Article 21; government policies and interventions; statutory and regulatory bodies.

GS Paper 3: Awareness in the fields of IT and emerging technology; challenges to internal security through communication networks.

Concept Meaning Why it is testable
Data Principal / Data Fiduciary The individual to whom personal data relates, and the person determining the purpose and means of processing The two roles around which the DPDP Act is built
Personal or domestic purpose exemption The Act does not apply to personal data processed by an individual for a purely personal or domestic purpose The provision that arguably leaves the wearer unregulated
Proportionality test (Puttaswamy) Legitimate aim, rational nexus, necessity, and balancing The constitutional standard for privacy intrusion

Background and Context

The Constitutional Foundation

Justice K. S. Puttaswamy (Retd.) v. Union of India (2017) was decided by a nine-judge bench, which held unanimously that the right to privacy is a fundamental right protected under Article 21 and as part of the freedoms in Part III. It recognised informational privacy as one dimension of the right and laid down a four-part proportionality test for any intrusion: a legitimate aim, a rational nexus between the measure and the aim, necessity in the sense that no less restrictive alternative exists, and a balancing of the intrusion against the benefit.

The Statute

Milestone Detail
Justice B. N. Srikrishna Committee Constituted 2017; reported 2018 with a draft Bill
Personal Data Protection Bill, 2019 Introduced, then withdrawn in August 2022
Digital Personal Data Protection Act, 2023 Enacted August 2023
DPDP Rules Notified 2025

The Act’s architecture:

Element Content
Data Principal The individual to whom the personal data relates
Data Fiduciary The person who alone or with others determines the purpose and means of processing
Significant Data Fiduciary A class notified on the basis of volume and sensitivity, carrying additional obligations including a Data Protection Officer and audits
Consent Manager A registered intermediary through which a principal may give, manage and withdraw consent
Data Protection Board of India The adjudicatory body for breaches
Penalties Up to ₹250 crore for specified breaches

Processing is lawful where it is for a lawful purpose and is based either on consent that is free, specific, informed, unconditional and unambiguous, or on certain legitimate uses. Critically, the Act does not apply to personal data processed by an individual for any personal or domestic purpose.

The Analysis

1. Consent presupposes a relationship, and ambient capture has none. The notice-and-consent sequence requires an identifiable fiduciary to approach an identifiable principal before processing begins. Wearable capture inverts every element: the fiduciary is not identifiable to the subject, the subject is not identified in advance, and processing begins the moment the person walks into frame. This is not a compliance failure. It is a design mismatch.

2. The exemption was written for a different world. The personal-or-domestic exemption exists so that ordinary private life is not converted into regulated data processing. That rationale is sound for a family photograph album. It sits uncomfortably with a networked camera worn continuously through public space, where the motive is personal and the effect is public. The wearer is personally motivated, and therefore arguably exempt, while being the proximate cause of the intrusion.

3. Processing, not capture, is where the harm scales. Being photographed in public is an old and largely tolerated condition. What is new is that footage can be run through face matching, gait recognition and location inference to produce identification and tracking. A thousand ordinary photographs are a nuisance; a thousand photographs plus a matching model is a surveillance system. Any regulation aimed at the camera rather than at the model is therefore aimed at the wrong stage.

4. Puttaswamy points the right way but was aimed elsewhere. The proportionality standard was articulated principally to discipline State intrusion. Horizontal application against private actors runs through statute, and the statute here is the DPDP Act, which is precisely the instrument the editorial says does not reach the case. The constitutional principle is available; the statutory vehicle is not.

5. The counter-argument is substantial and should not be dismissed. Photography in public has never required the consent of everyone in frame, and a rule that made it so would criminalise journalism, citizen evidence-gathering and ordinary life. Regulating a device category is overbroad, technologically brittle and largely unenforceable. The strength of this objection is exactly why the workable remedy targets biometric processing and notice through indicators, rather than the act of recording itself.

Data and Institutions Vault

Prelims-grade facts:

  • Justice K. S. Puttaswamy v. Union of India (2017): nine-judge bench; privacy a fundamental right under Article 21; four-part proportionality test.
  • Digital Personal Data Protection Act, 2023, enacted August 2023; DPDP Rules notified 2025.
  • Preceded by the Justice B. N. Srikrishna Committee (constituted 2017, reported 2018) and the Personal Data Protection Bill, 2019, withdrawn in August 2022.
  • Key roles: Data Principal, Data Fiduciary, Significant Data Fiduciary, Consent Manager.
  • Adjudicatory body: Data Protection Board of India. Maximum penalty: ₹250 crore.
  • The Act does not apply to personal data processed by an individual for a purely personal or domestic purpose.

⚠️ Watch the trap: The DPDP Act, 2023 applies to digital personal data, and to non-digital data only once digitised. It is not a general privacy statute: it does not cover anonymised data, and it contains wide exemptions for State instrumentalities. Do not describe it as India’s equivalent of a comprehensive right-to-privacy law.

The Debate

FOR (the law leaves a real gap): The protective mechanism is consent, and the bystander is definitionally outside any consent relationship. The personal-or-domestic exemption removes the wearer from the Act’s reach entirely. Downstream AI processing converts casual footage into an identification capability that no existing provision addresses.

AGAINST (existing law suffices and device regulation is overbroad): Public photography has never required universal consent. Voyeurism, stalking and harassment are already offences. State surveillance is governed by Puttaswamy proportionality. Regulating an object rather than a use is unenforceable, technologically obsolete on arrival, and chills legitimate recording.

Balanced verdict: The gap is real but it is narrower than a device ban would assume. The intrusion that genuinely lacks a remedy is biometric identification of non-consenting bystanders, not recording as such. Regulation should therefore attach to processing: mandatory and non-defeatable recording indicators to restore notice, a prohibition on real-time biometric identification of bystanders outside narrowly defined and supervised circumstances, and an express clarification that the personal-or-domestic exemption does not extend to continuous capture in public space or to biometric processing of the resulting footage.

How to Think About This

When a technology appears to defeat a legal framework, resist the instinct to regulate the object. Instead, decompose the activity into stages and ask at which stage the harm actually arises, and which stage is practically regulable.

Here the stages are capture, storage, processing and use. Capture is impossible to police and largely lawful. Use is where the damage lands but is detected only after the fact. Processing is the stage that is both harmful and regulable, because it requires models, infrastructure and identifiable operators. Locating the intervention at the regulable stage nearest the harm is the general principle, and it applies well beyond privacy law.

Diagram-in-Words

Capture Ambient, continuous Storage Device and cloud Biometric processing Face match, gait, location Use Tracking, profiling Consent fails here No notice possible Regulate here Harmful and regulable Personal-or-domestic exemption removes the wearer from the Act entirely Capture is unpoliceable; use is detected too late; processing needs models and operators that can be identified, licensed and held to account
Consent breaks at the first stage and the harm lands at the last, but the only stage with identifiable operators to regulate is the third.

Takeaway Box

Lift line: A law built on asking permission cannot protect the one person who was never going to be asked.

Prelims hooks: Puttaswamy (2017), nine-judge bench, privacy under Article 21, four-part proportionality test; DPDP Act 2023 enacted August 2023, Rules notified 2025; Srikrishna Committee 2017-18; PDP Bill 2019 withdrawn August 2022; Data Protection Board of India; penalties up to ₹250 crore; personal-or-domestic purpose exemption.

Ethics and interview angle: Does a person walking through a public street retain any reasonable expectation of privacy once every passer-by may be wearing a camera capable of identifying them?

PYQ linkage: Connects to past UPSC Mains questions on the right to privacy after Puttaswamy and on the governance of emerging technologies.

Probable question: “India’s data protection law regulates relationships, while modern surveillance technology operates without them.” Critically examine with reference to ambient wearable devices.

Source: Smart Glasses and the Bystander the Privacy Law Forgot — Ujiyari.com | Free UPSC & State PCS Editorial Analysis