's Neurotechnology Recommendation Exposes Gaps in India's DPDP Act for
On , the 43rd session of 's General Conference in Samarkand adopted the first global-level Recommendation on the Ethics of Neurotechnology. Two days later, India's notified the , operationalising the after nearly two years. The temporal coincidence invites comparison, but the substance reveals a significant gap: while now explicitly recognises and data capable of inferring mental states as requiring heightened protection, India's data protection framework makes no such distinction and will not fully apply its substantive rules until .
This article examines what 's recommendation means for India's legal landscape, the shortcomings of the DPDP Act in addressing neurotechnology, and how constitutional principles from Justice K.S. Puttaswamy (Retd.) v Union of India () and Selvi v State of Karnataka () may fill the void.
The Recommendation: A Global Benchmark Without Teeth
's Recommendation is not a binding treaty. It asks Member States to give effect to its principles
"in conformity with the constitutional practice and governing structures of each State."
It serves as a benchmark rather than an enforceable obligation. Nevertheless, its explicit categorisation of
and
as
marks a watershed moment. For the first time, an international organisation has told states that data from EEG headsets, brain-computer interfaces, and consumer earbuds that can reveal what a person is thinking, feeling, or about to decide deserves special treatment.
The distinction is critical because
is not ordinary personal data. As the source material notes,
"Ordinary personal data tells us something about a person;
tells us about the signals gathered by EEG headsets... which can permit inferences about what a person is thinking, feeling, or about to decide."
The issue is not abstract. Mining and logistics firms already deploy EEG-based fatigue-monitoring headsets on drivers. In China, a primary school drew international attention in 2019 for putting brainwave-tracking headbands on students. EEG sensors are now built into commercially available headphones.
India's DPDP Act: A One-Size-Fits-All Approach
India's adopts a single category of 'personal data' and regulates its processing principally through consent and specified legitimate uses. It does not create a separate statutory category for neural or specially , unlike many other jurisdictions that have separate regimes for health or biometric data. The Act applies the same baseline architecture of consent to buying groceries as to raw neural activity.
This is not a proof of negligence; the Act was drafted before consumer neurotechnology reached the mass market it occupies today. But the problem is that , the Act's central safeguard, is now being asked to address something it was not designed for. A user may meaningfully consent to a platform collecting a keystroke, but it is much harder to say that the same consent covers a device inferring her attention, mood, or susceptibility to a particular advertisement—especially where those inferences were neither technically possible nor contemplated when the consent was given.
The Act therefore needs to distinguish between collecting a neural signal and using that signal to infer a person's mental state. 's Recommendation makes the same point, calling for and safeguards specific to inferences drawn from neural and neural-adjacent data. India's statute has no equivalent provision.
: Beyond Unauthorised Access
Assume the consent problem is solved and a neurotechnology company holds lawfully. Another question arises: does lawful possession entitle the company to infer anything it is technically capable of inferring? Neurotechnology creates a risk that conventional data-security rules do not fully capture. The danger may arise not from unauthorised access, but from authorised use.
Cybersecurity protects data from unauthorised access—encryption, access controls, breach response. is a different concern. It protects individuals from the misuse of information about their mental or cognitive state, even when that information was obtained lawfully. The concern is not unauthorised access, but what an organisation does with the information once it has legitimate access.
Consider a consumer in India using EEG-enabled earbuds. The device collects a raw neural signal, which may pass through a cloud system and a third-party AI system before being turned into a cognitive profile and shared with an advertiser or employer. At each stage, the company may show the transfer was authorised. That does not answer the harder question of responsibility when the problem is not a data breach but an inference made from lawfully obtained data. Indian law does not currently provide a clear framework for assigning responsibility in that situation.
Cross-Border Challenges and Jurisdictional Gaps
The problem becomes more acute when the companies involved are based outside India. The earbuds may be sold by a company with no Indian office, the cloud infrastructure located abroad, and the AI system generating the cognitive profile operated from a third country. permits a to transfer personal data outside India, subject to conditions specified by the . But Rule 15 is not yet in force, and even when it takes effect, it does not specifically address the risks arising from neural-data inference.
This raises a practical question: who is responsible when the company, the servers, and the system making the inference are all outside India's jurisdiction? The answer should not depend on where the server is located. High-risk neurotechnology providers offering products to Indian consumers should therefore be required to maintain an accessible in India. They should also disclose, in terms consumers can understand and act on, where inferences about them are generated and which entities are responsible.
Constitutional Foundations: Puttaswamy and Selvi
India need not necessarily wait for Parliament before its courts can address these questions. In Justice K.S. Puttaswamy (Retd.) v Union of India (), the recognised within , including a person's . Selvi v State of Karnataka () went further, holding that involuntary narco-analysis and similar techniques intrude on a form of privacy specific to the mind—protection against the forcible extraction of testimony from within a person's own consciousness.
Neither judgment recognises "" as a standalone right, but they offer constitutional building blocks from which a right to can be developed as neurotechnology cases reach the courts. Whether Selvi 's logic extends to non-invasive neural decoding in criminal investigation is a large question deserving its own treatment, but the foundation is there.
Four Changes to Bridge the Gap
The gap can be addressed through four changes to the existing framework. First, the DPDP framework should expressly recognise and as requiring heightened safeguards, in line with 's Recommendation. Second, the law should distinguish between consent to collect a neural signal and consent to derive further information from it. Third, Rule 15 should address before it comes into force in , including by requiring foreign neurotechnology providers serving Indian consumers to maintain an Indian and provide information about how and where inferences are generated. Fourth, courts can develop the constitutional principles in Puttaswamy and Selvi as cases involving neurotechnology come before them.
can reveal information closely connected to a person's mental life, bringing questions of and informational autonomy within the broader protections of . These developments need not wait for one another; statutory reform and constitutional development can proceed together.
Conclusion
has told the world that deserves to be treated as . India's data-protection framework does not yet make a similar distinction, and its substantive Rules are not expected to apply until . That leaves a significant gap between the protections being discussed internationally and those available under India's current framework. The challenge is not limited to preventing unauthorised access. For neurotechnology, the law must also address what happens when data is lawfully collected but is then used to draw sensitive conclusions about a person's mental or cognitive state. India still has time to address that gap before the existing framework begins to operate in full. The question is whether policymakers, courts, and regulators will act now or wait for the first neurotechnology scandal to force their hand.