

Facial recognition systems are increasingly used in public spaces in India, despite the absence of a comprehensive statutory framework governing their use.
Imagine the concourse at Howrah station in Kolkata during rush hour with approximately a million commuters each day, along with a hundred cameras quietly scanning every face against a watchlist that only a few officials have ever seen in full. Walk through the corridors at the Ram Mandir in Ayodhya and similar machines are identifying faces using police records as worshippers wait for darshan. Ahmedabad’s “safe city” control room does the same for the whole city. The majority of these systems do not announce their presence, let alone ask for consent.
Recent investigative reporting has revealed that much of the technology behind this surveillance comes from a Spanish company called Herta Security. Their facial recognition software reportedly runs on several thousand cameras across the country, which includes setups that would be illegal within the European Union, according to European legal scholars.
The problem here is that the very place that produces this software has curtailed real-time biometric identification of people in public spaces for law enforcement in February 2025, labelling it as an “unacceptable risk” under the EU’s Artificial Intelligence Act. What, according to Brussels, is too dangerous for its citizens, New Delhi markets it as “smart policing” and “passenger safety.”
India has turned out to be an attractive market due to the gap between theoretical protections which its laws offer and their practical enforcement. This is not only about a technology which is outpacing the law, but about a law which does not exist in the first place.
In 2017, a nine-judge bench of the Supreme Court in Justice KS Puttaswamy v. Union of India held that privacy is an essential part of Articles 14, 19, and 21. It laid down a four-pronged test governing State action that invades privacy:
Firstly, it must be legal, which means it must be based on a valid law and not some temporary order.
Second, the legislation must serve a legitimate state aim, such as national security, public morality, etc.
Third, there must be proportionality, which means that there should be a logical connection between the process and the aim.
Finally, as observed by Justice Sanjay Kaul, there must be procedural safeguards against misuse of the said legislation.
Courts have used this four-part test to evaluate everything from internet shutdowns to data-collection practices, especially in Anuradha Bhasin v. Union of India.
India’s Automated Facial Recognition Systems stumble right at the first hurdle because there is no Act of parliament which allows the police, railways, or temple trusts to operate live facial recognition on the public. Instead, there are scattered documents, state police manuals and court orders which are issued for entirely different purposes.
For example, a Delhi High Court direction in the case of Sadhan Haldar v. NCT of Delhi, intended to help trace missing children, has been serving as legal cover for a much broader surveillance program. Executive orders are not legislation and every official document is not a law. When the basis of “legality” of an Act or law is so thin, the other three parts of the test rarely get scrutinised.
Article 19(1) protects the freedom of speech and authorises citizens to assemble peacefully, but a citizen who knows her face is being recorded and later matched each time she crosses a railway platform or joins a protest will subconsciously weigh the risk of being there. This also impacts the freedom of journalists and protestors for whom Article 21’s promise of liberty acts as a source of motivation. The inherent drawback of this technology is that it shifts the burden of proof onto anyone whose face the algorithm marks.
The executive might argue that the current police powers and judicial directions from cases like Sadhan Haldar provide sufficient legal basis. However, these executive orders neither meet the legal standards set in the Puttaswamy judgment, nor do they satisfy the democratic principles that mandate the passage of any law passed by parliament.
Article 5(1)(h) of the EU AI Act prohibits real-time remote biometric identification in public spaces for law enforcement, with only three exceptions:
Searching for trafficking or abduction victims,
Preventing an imminent terrorist threat,
Locating a suspect in a serious crime,
It also requires prior approval from the judiciary, a fundamental rights impact assessment and registration in an EU-wide database.
The European Court of Human Rights issued a similar judgement in Glukhin v. Russia (2023) and observed that Moscow’s use of live facial recognition to track a peaceful protester violated his rights to private life and free expression. The Court called the technology “highly intrusive” and warned that its use against demonstrators risks the freedom that a democratic society aims to protect.
However, India’s Digital Personal Data Protection (DPDP) Act, 2023 takes the opposite approach. Section 17(2)(a) allows the Central government to exempt any “instrumentality of the State” from nearly the whole Act, including rules on purpose limitation and data minimisation. Vague reasons like “security of the State” or “maintenance of public order” are given, based only on an executive notification.
While Europe emphasises judicial oversight, India makes no mention of a defined agency or even a sunset clause. While the General Data Protection Regulation (GDPR) controls government data similar to the private sector, the DPDP Act lets the state set its own rules.
European companies continue to profit by selling technology that their regulators deem too risky to use at home. European lawmakers who finance the research for these tools have done little to limit their export to the Global South. In essence, Indian citizens often become the test subjects for products which are expelled from Europe.
None of this would have mattered this much if the technology worked perfectly, but it does not. Facial recognition systems are trained mostly on lighter-skinned faces and show higher error rates for darker skin tones and for women. This pattern has been documented by researchers at America’s National Institute of Standards and Technology and echoed in trials by London’s Metropolitan Police, whose system produced more false matches than correct ones during a well-known 2017 carnival deployment.
In a country where people have suffered discrimination based on caste, religion and unequal economic status for generations, an inaccurate biometric policy further disproportionately impacts communities that have long faced inequality.
Records obtained by the Internet Freedom Foundation under the Right to Information Act showed that the Delhi Police considers any facial similarity score above 80 per cent as a “positive” identification. Digital rights researchers have pointed out that this means the police are willing to accept a chance of error before labelling someone as a suspect.
The language used to market a facial recognition camera as a surveillance device instead markets it as a “passenger safety” measure, a “crowd management” tool, or a “safety” feature. This reframes a fundamental rights issue as a matter of civic convenience, which, in turn, means that a safety initiative is much harder to challenge in court or in public opinion than a surveillance program.
The most recent example is the Delhi High Court’s decision to hear a PIL on use of cameras by police personnel during the Jantar Mantar protests. It is a perfect representation of the violation of combinations of fundamental rights, including the right to protest under Article 19(1)(a) and (b), along with the inherent violation of the right to privacy.
None of this is irreparable, but fixing it requires active efforts by the legislature and the executive.
Primarily, parliament needs to stop any further rollout of Automated Facial Recognition Systems (AFRS) until it creates a dedicated law. This law should define allowable use cases, require independent approval before each use and impose penalties for misuse. Merely an executive notification cannot justify infringement of fundamental rights in a democratic country.
The blanket exemption for State agencies under Section 17(2)(a) of the DPDPA needs to be tightened to a real necessity and proportionality standard rather than a notification that the executive issues to itself.
No public use of biometric surveillance should proceed without a published Algorithmic Impact Assessment, similar to the environmental clearances required for major projects.
The law must include a sunset clause, which means that the imposition of surveillance orders should lapse automatically after a certain pre-decided time frame.
The courts have a deciding role that goes beyond reiterating Puttaswamy’s principles in general terms. Judges reviewing challenges to AFRS tenders and contracts should apply the four-part test with the same rigour they would apply to a wiretap order, as held in People’s Union for Civil Liberties vs Union of India & Ors. The judiciary should require the State to prove beforehand that ordinary, suspicion-based policing has genuinely failed before resorting to a biometric mechanism across an entire city or region.
If Europe believes that watching its own citizens in real time poses a threat to the free society, then India should not become the place where these rights are ignored based on discretion. The issue is not whether the government should use facial recognition technology, but whether it should do so without legislative approval and actual protections. Until parliament discusses these matters, India’s growing use of AFRS will remain uncomfortable within the constitutional framework outlined in the Puttaswamy judgment.
Akshat Singh is a recent law graduate from RMLNLU Lucknow.