Constitutional void in India's facial recognition policy violates Puttaswamy privacy test: Supreme Court

India's rapidly expanding use of facial recognition technology by law enforcement and government agencies exists in a legal vacuum, directly contravening the four-pronged privacy test laid down by the Supreme Court in the landmark Justice K.S. Puttaswamy v. Union of India case. The policy, deployed for everything from crime prevention to welfare distribution, lacks a foundational statute, making it constitutionally suspect under Articles 14, 19, and 21. Legal experts now question whether any such surveillance system can survive judicial scrutiny absent a dedicated law that satisfies the Court's requirements of legality, legitimate aim, proportionality, and procedural safeguards.

The Puttaswamy Framework: A Four-Pronged Shield

In 2017, a nine-judge bench of the Supreme Court unanimously declared the right to privacy a constitutionally protected fundamental right, intrinsic to the freedoms guaranteed under Articles 14, 19, and 21. This judgment did not simply recognize the right; it established a rigorous evaluative standard for any state action that intrudes upon it. The Court mandated that any such action must pass a four-part test.

Firstly, the intrusion must have " legality ," meaning it must be authorized by a " valid law " and not by executive order, policy circular, or temporary administrative measure. As the Court observed, "it must be based on a valid law and not some temporary order." This emphasizes the supremacy of legislation enacted by Parliament or state legislatures, ensuring democratic deliberation and public accountability.

Secondly, the legislation must serve a "legitimate state aim," such as national security, public order, or public morality. This prong requires the state to articulate a compelling purpose that justifies the privacy invasion.

Thirdly, the principle of "proportionality" demands a logical connection between the means employed and the aim sought. The intrusion must be the least restrictive alternative available, and its benefits must outweigh the harm to individual rights.

Finally, as Justice Sanjay Kaul specifically highlighted in his concurring opinion, there must be robust " procedural safeguards against misuse of the said legislation." These include oversight mechanisms, data retention limits, transparency requirements, and independent redressal avenues.

Facial Recognition: A Policy Without a Law

India's facial recognition ecosystem operates through a patchwork of state-level pilot projects, central government initiatives like the National Automated Facial Recognition System (NAFRS), and use by agencies such as the Delhi Police and the National Crime Records Bureau. Critically, no single act of Parliament authorizes the wholesale deployment of this technology for surveillance. Instead, its legal basis derives from older statutes like the Code of Criminal Procedure, 1973, or the Information Technology Act, 2000—neither of which explicitly contemplates or regulates automated facial recognition at scale.

Legal scholars argue that such reliance on general provisions fails the first prong of the Puttaswamy test. The absence of a "valid law" specifically addressing the collection, storage, and use of biometric facial data means any state action under the policy is, by definition, illegal. Even administrative guidelines or executive orders cannot substitute for a parliamentary statute, as the Court made clear.

Applying the Test: Where the Policy Fails

When the four-pronged test is applied to the existing facial recognition policy, it becomes evident that the policy is constitutionally unsustainable on multiple fronts.

Legality: As noted, there is no specific law. The use of facial recognition by police forces often relies on internal departmental orders or memoranda of understanding with private vendors. This direct reliance on non-legislative instruments violates the Puttaswamy requirement that any privacy-intruding state action must be grounded in a law passed by the legislature.

Legitimate State Aim: While crime prevention and public safety are undoubtedly legitimate aims, the problem lies in the scope of data collection. Facial recognition systems often capture data of innocent citizens in public spaces without suspicion or consent. The aim may be legitimate, but the blanket application sweeps in an entire population, potentially violating the spirit of the requirement.

Proportionality: This is where the policy most clearly falters. The Puttaswamy test demands a "logical connection" between the process (mass surveillance) and the aim (crime fighting). Scholars argue that the indiscriminate capture and retention of facial data is not proportionate to any specific threat. Moreover, the lack of accountability metrics makes it impossible to verify whether the system actually reduces crime without disproportionately harming privacy.

Procedural Safeguards: Justice Sanjay Kaul's emphasis on safeguards is particularly relevant. Current deployments lack independent oversight, data breach protocols, or clear rules on data retention and deletion. There is no statutory mechanism for a citizen to know if their biometric data is in a database, correct errors, or challenge surveillance. Without these safeguards, misuse is not just possible—it is almost inevitable.

Judicial Precedent Reinforces the Void

The Supreme Court has already applied the Puttaswamy test to other digital rights issues. In Anuradha Bhasin v. Union of India , the Court examined the legality of internet shutdowns in Jammu and Kashmir. It held that any executive action restricting internet access must satisfy the test of legality and proportionality. The Court noted that even under Article 19, the primary test for any restriction is whether it is imposed by law and is proportionate. Extending this logic, the same standard applies with even greater force to continuous surveillance like facial recognition, which collects biometric data—a deeply sensitive category under the emerging data protection framework.

The use of the Puttaswamy test in the Anuradha Bhasin case underscores its applicability to modern technological state actions. If internet shutdowns require a specific legal basis, then a nationwide facial recognition system—which is more invasive and permanent—certainly demands one.

Implications for Legal Practice and Policy

For legal professionals, this analysis signals that any challenge to facial recognition projects on constitutional grounds has a strong foundation. Petitions can argue that the absence of a dedicated law violates the first prong of Puttaswamy , and that the system's operation without built-in proportionality and safeguards violates the remaining prongs. Courts may be compelled to issue moratoriums on further deployment until the state enacts a compliant statute.

From a policy perspective, the government must move beyond executive fliers and pilot projects. A comprehensive surveillance law—likely within the framework of a data protection act—must address: the specific purposes for which facial recognition can be used; limitations on data collection, storage, and sharing; independent oversight; transparency obligations; and redressal for affected individuals. Until such a law is enacted, the entire policy framework rests on constitutionally shaky ground.

Conclusion: A Call for Legislative Action

The constitutional void surrounding India's facial recognition policy is not merely an oversight—it is a direct challenge to the right to privacy as interpreted by the nine-judge bench. The Puttaswamy framework was designed precisely to prevent executive overreach in the name of security. Without a valid law, the state's use of this powerful technology amounts to an unconstitutional invasion. As the Supreme Court has repeatedly warned, the freedoms enshrined in Part III of the Constitution cannot be overridden by administrative convenience. The onus now lies on Parliament to legislate, and on the courts to enforce the constitutional limits until they do.