Supreme Court's Puttaswamy Doctrine Demands Sensitive Data Status for Neural Data, India's DPDPA Lags

A critical gap in India's data protection framework is coming under scrutiny as commercial neurotechnology devices—from meditation headbands to workplace fatigue monitors—enter the market without a legal regime that distinguishes neural signals from routine transactional data. Legal experts argue that the current silence in the Digital Personal Data Protection Act, 2023 (DPDPA) on brain-derived data leaves cognitive privacy exposed, despite robust constitutional foundations laid by the Supreme Court in K.S. Puttaswamy v. Union of India . The absence of a sensitive data category for neural information, they contend, is a structural mismatch between constitutional promise and statutory reality.

The Unique Nature of Neural Data

What makes brain data fundamentally different from other biometrics is its capacity to reveal not just identity but inner mental states. As one analysis notes, "A fingerprint or a facial scan identifies a person; neural signals can, with the right decoding model, reveal what a person is thinking, feeling, or about to do, often before the person is consciously aware of the inclination themselves." Researchers have shown that simple EEG patterns can be used to infer PIN numbers, political leanings, and emotional triggers. This goes beyond privacy—it touches the concept of cognitive liberty , the freedom to control one’s own mental processes without external interference.

Chile amended its Constitution in 2021 to explicitly protect neurorights, and UNESCO has moved toward a recommendation on the ethics of neurotechnology. India, however, has taken no such step at the statutory level, even as neurotechnology products are sold directly to consumers and deployed in workplaces and schools.

Constitutional Foundation: Puttaswamy's Mental Autonomy

The Supreme Court's landmark 2017 judgment in Puttaswamy recognized informational privacy as a facet of Article 21 of the Constitution, encompassing decisional and mental autonomy . The judgment's language on bodily and decisional privacy, experts argue, extends naturally to neural data. Unauthorized access to brain signals constitutes a graver constitutional injury than access to ordinary transactional data because "it reaches the seat of thought itself." The proportionality test laid down in Puttaswamy —requiring any state intrusion to be backed by law, pursue a legitimate aim, and be proportionate and necessary—would impose a very high bar on collection or compelled disclosure of brain data. A regime that treats neural signals no differently from a shopping cart history would struggle to survive that test.

The DPDPA's Troubling Silence

Despite this constitutional foundation, the enacted DPDPA abandoned the tiered approach of its predecessors. Earlier Bills (2018 and 2019) carried a distinct category of "sensitive personal data" covering health data, biometrics, genetic data, and sexual orientation, mirroring the European Union's General Data Protection Regulation (GDPR) Article 9 special categories. The final DPDPA replaced this with a single, uniform framework—except for a modestly heightened regime for children's data and data of persons with disabilities under guardianship.

As matters stand, neural data collected by a wellness app or neuromarketing firm is regulated exactly as a phone number or delivery address: through the same consent notice, same purpose-limitation clause, and same grievance-redressal mechanism. The older Information Technology (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011, which did carve out sensitive data categories, technically continue to operate for entities outside the DPDPA's eventual full commencement, but those rules were drafted before consumer neurotechnology existed and do not mention neural data at all.

"An employer could, in principle, justify continuous cognitive-state monitoring of employees under a 'legitimate use' exemption in Section 7 with far less friction than would be required to process, say, an employee's medical records under a health-data-specific standard." The Data Protection Board of India , tasked with enforcing the Act, is not yet functional, compounding the enforcement vacuum.

Practical Stakes: Workplaces, Classrooms, and Cross-Border Flows

The implications are not theoretical. Neurotechnology is entering Indian workplaces through fatigue-monitoring headsets for drivers and factory workers, into classrooms through attention-tracking tools marketed to schools, and into consumer wellness through meditation and sleep-tracking devices that log raw or processed EEG output on foreign servers. None of these deployments currently require explicit, purpose-specific, revocable consent of the kind that health data attracts in more mature regimes.

Cross-border transfer adds another layer of concern. Most consumer neurotechnology devices stream EEG data to servers outside India for model training. The DPDPA's cross-border transfer provisions under Section 16 leave this largely to government-notified restrictions rather than a data-type-specific bar, meaning neural data can leave Indian jurisdiction as freely as a search query unless the Central Government specifically blacklists a destination.

Children are especially vulnerable. Attention-monitoring products are being piloted in Indian schools. The DPDPA's heightened protection for children's data under Section 9 is triggered by the age of the data principal, not by the sensitivity of what is being measured. "A school could, in theory, satisfy its Section 9 obligations through parental consent alone while still permitting granular, continuous cognitive profiling of a child—a combination the Act's drafters plainly did not contemplate."

A Calibrated Way Forward

Legal commentators do not advocate reproducing the GDPR's model wholesale, with its own problems of rigidity. Instead, they call for a narrower, functional test: any data derived from direct neural measurement—EEG, functional near-infrared spectroscopy, or implanted electrode signals—should be treated as sensitive by default. This would trigger explicit consent requirements, tight purpose limitation to the stated therapeutic or research use, a prohibition on inferring unrelated traits from data collected for another purpose, and mandatory data protection impact assessments for any commercial neurotechnology deployment.

The Ministry of Electronics and Information Technology retains rule-making power under Section 40 of the DPDPA broad enough to introduce such a category through delegated legislation, without reopening the Act itself. The constitutional scaffolding is already in place; what is missing is statutory follow-through.

As neurotechnology moves from laboratory to living room, the cost of acting now is far lower than the cost of retrofitting protection after neural data breaches become common. India need not wait for a flagship judgment on neuro-privacy to act—the rule-making power exists, and the time to use it is before the technology outpaces the law.