UNESCO's Neurotechnology Recommendation Exposes Gaps in India's DPDP Act for Mental Privacy

On 11 November 2025, the 43rd session of UNESCO's General Conference in Samarkand adopted the first global-level Recommendation on the Ethics of Neurotechnology. Two days later, India's Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025, operationalising the Digital Personal Data Protection Act, 2023 after nearly two years. The temporal coincidence invites comparison, but the substance reveals a significant gap: while UNESCO now explicitly recognises neural data and data capable of inferring mental states as requiring heightened protection, India's data protection framework makes no such distinction and will not fully apply its substantive rules until mid-2027.

This article examines what UNESCO's recommendation means for India's legal landscape, the shortcomings of the DPDP Act in addressing neurotechnology, and how constitutional principles from Justice K.S. Puttaswamy (Retd.) v Union of India (2017) and Selvi v State of Karnataka (2010) may fill the void.

The UNESCO Recommendation: A Global Benchmark Without Teeth

UNESCO 's Recommendation is not a binding treaty. It asks Member States to give effect to its principles "in conformity with the constitutional practice and governing structures of each State." It serves as a benchmark rather than an enforceable obligation. Nevertheless, its explicit categorisation of neural data and mental-state inferences as sensitive personal data marks a watershed moment. For the first time, an international organisation has told states that data from EEG headsets, brain-computer interfaces, and consumer earbuds that can reveal what a person is thinking, feeling, or about to decide deserves special treatment.

The distinction is critical because neural data is not ordinary personal data. As the source material notes, "Ordinary personal data tells us something about a person; neural data tells us about the signals gathered by EEG headsets... which can permit inferences about what a person is thinking, feeling, or about to decide." The issue is not abstract. Mining and logistics firms already deploy EEG-based fatigue-monitoring headsets on drivers. In China, a primary school drew international attention in 2019 for putting brainwave-tracking headbands on students. EEG sensors are now built into commercially available headphones.

India's DPDP Act: A One-Size-Fits-All Approach

India's Digital Personal Data Protection Act, 2023 adopts a single category of 'personal data' and regulates its processing principally through consent and specified legitimate uses. It does not create a separate statutory category for neural or specially sensitive personal data, unlike many other jurisdictions that have separate regimes for health or biometric data. The Act applies the same baseline architecture of consent to buying groceries as to raw neural activity.

This is not a proof of negligence; the Act was drafted before consumer neurotechnology reached the mass market it occupies today. But the problem is that informed consent, the Act's central safeguard, is now being asked to address something it was not designed for. A user may meaningfully consent to a platform collecting a keystroke, but it is much harder to say that the same consent covers a device inferring her attention, mood, or susceptibility to a particular advertisement—especially where those inferences were neither technically possible nor contemplated when the consent was given.

The Act therefore needs to distinguish between collecting a neural signal and using that signal to infer a person's mental state. UNESCO's Recommendation makes the same point, calling for data-minimisation and purpose-limitation safeguards specific to inferences drawn from neural and neural-adjacent data. India's statute has no equivalent provision.

Cognitive Security: Beyond Unauthorised Access

Assume the consent problem is solved and a neurotechnology company holds neural data lawfully. Another question arises: does lawful possession entitle the company to infer anything it is technically capable of inferring? Neurotechnology creates a risk that conventional data-security rules do not fully capture. The danger may arise not from unauthorised access, but from authorised use.

Cybersecurity protects data from unauthorised access—encryption, access controls, breach response. Cognitive security is a different concern. It protects individuals from the misuse of information about their mental or cognitive state, even when that information was obtained lawfully. The concern is not unauthorised access, but what an organisation does with the information once it has legitimate access.

Consider a consumer in India using EEG-enabled earbuds. The device collects a raw neural signal, which may pass through a cloud system and a third-party AI system before being turned into a cognitive profile and shared with an advertiser or employer. At each stage, the company may show the transfer was authorised. That does not answer the harder question of responsibility when the problem is not a data breach but an inference made from lawfully obtained data. Indian law does not currently provide a clear framework for assigning responsibility in that situation.

Cross-Border Challenges and Jurisdictional Gaps

The problem becomes more acute when the companies involved are based outside India. The earbuds may be sold by a company with no Indian office, the cloud infrastructure located abroad, and the AI system generating the cognitive profile operated from a third country. Rule 15 of the DPDP Rules permits a Data Fiduciary to transfer personal data outside India, subject to conditions specified by the Central Government. But Rule 15 is not yet in force, and even when it takes effect, it does not specifically address the risks arising from neural-data inference.

This raises a practical question: who is responsible when the company, the servers, and the system making the inference are all outside India's jurisdiction? The answer should not depend on where the server is located. High-risk neurotechnology providers offering products to Indian consumers should therefore be required to maintain an accessible grievance mechanism in India. They should also disclose, in terms consumers can understand and act on, where inferences about them are generated and which entities are responsible.

Constitutional Foundations: Puttaswamy and Selvi

India need not necessarily wait for Parliament before its courts can address these questions. In Justice K.S. Puttaswamy (Retd.) v Union of India (2017), the Supreme Court recognised privacy, dignity, and autonomy within Article 21, including a person's decisional and informational autonomy. Selvi v State of Karnataka (2010) went further, holding that involuntary narco-analysis and similar techniques intrude on a form of privacy specific to the mind—protection against the forcible extraction of testimony from within a person's own consciousness.

Neither judgment recognises "cognitive liberty" as a standalone right, but they offer constitutional building blocks from which a right to mental privacy can be developed as neurotechnology cases reach the courts. Whether Selvi 's logic extends to non-invasive neural decoding in criminal investigation is a large question deserving its own treatment, but the foundation is there.

Four Changes to Bridge the Gap

The gap can be addressed through four changes to the existing framework. First, the DPDP framework should expressly recognise neural data and mental-state inferences as requiring heightened safeguards, in line with UNESCO's Recommendation. Second, the law should distinguish between consent to collect a neural signal and consent to derive further information from it. Third, Rule 15 should address cross-border accountability before it comes into force in 2027, including by requiring foreign neurotechnology providers serving Indian consumers to maintain an Indian grievance mechanism and provide information about how and where inferences are generated. Fourth, courts can develop the constitutional principles in Puttaswamy and Selvi as cases involving neurotechnology come before them.

Neural data can reveal information closely connected to a person's mental life, bringing questions of mental privacy and informational autonomy within the broader protections of Article 21. These developments need not wait for one another; statutory reform and constitutional development can proceed together.

Conclusion

UNESCO has told the world that neural data deserves to be treated as sensitive personal data. India's data-protection framework does not yet make a similar distinction, and its substantive Rules are not expected to apply until mid-2027. That leaves a significant gap between the protections being discussed internationally and those available under India's current framework. The challenge is not limited to preventing unauthorised access. For neurotechnology, the law must also address what happens when data is lawfully collected but is then used to draw sensitive conclusions about a person's mental or cognitive state. India still has time to address that gap before the existing framework begins to operate in full. The question is whether policymakers, courts, and regulators will act now or wait for the first neurotechnology scandal to force their hand.