Home » Blog » The Right to Privacy in the Digital Age: Balancing Individual Rights and State Surveillance in India

The Right to Privacy in the Digital Age: Balancing Individual Rights and State Surveillance in India

Authored By: Aryaman Bandi

MS Ramaiah College of Law

1) Introduction

In an era where a citizen’s entire existence can be mapped through metadata, biometric logs, and digital footprints, the boundary between necessary governance and total surveillance has become very thin. When the Supreme Court of India delivered its unanimous judgment in Justice K.S. Puttaswamy v. Union of India (2017),1 it declared privacy a fundamental right intrinsic to life and personal liberty under Article 21. However, while the Court established that a person’s digital life is inviolable, it left open a critical legal battleground: the State’s broad authority to breach that privacy in the name of national security.

In the years following Puttaswamy, India’s legal landscape has struggled to operationalize this balance. Advanced state surveillance capabilities, ranging from facial recognition systems and digital communication intercepts to sweeping executive exemptions under the Digital Personal Data Protection (DPDP) Act, 2023,2 frequently test the proportionality standard established by the Supreme Court.

This article argues that India’s current statutory framework governing state surveillance, further compounded by the broad executive exemptions under the DPDP Act, 2023, fails the three-fold constitutional test of legality, necessity and proportionality laid down in Puttaswamy. If judges do not check government spying and laws do not limit government power, our right to privacy will exist only on paper, not in real life.

Roadmap

To substantiate this argument, this article proceeds in four main parts:

Part I traces the constitutional evolution of privacy law in India and establishes the legal contours and limitations of Article 21 after Puttaswamy.

Part II evaluates the current statutory and technical surveillance frameworks, analyzing state powers under the Indian Telegraph Act, the Information Technology Act and the broad exemptions under the DPDP Act, 2023.

Part III applies the judicial standard of proportionality to contemporary surveillance practices and highlights systemic gaps in independent oversight.

Part IV proposes actionable legislative reforms to balance state intelligence requirements with robust constitutional safeguards.

2) Main Body

I) Constitutional Genesis and the Post-Puttaswamy Standard

The constitutional status of privacy in India was historically unstable. The right to privacy is not directly mentioned in the Indian Constitution, but it has become a fundamental right through judicial interpretation. In M.P. Sharma v. Satish Chandra (1954)3 and Kharak Singh v. State of U.P. (1962),4 early Supreme Court benches refused to recognize privacy as a fundamental right, viewing the Constitution as silent on the matter. Over the following decades, this position slowly shifted, with courts recognizing facets of privacy within the broad ambit of personal liberty under Article 21.

However, procedural protections against state intrusion remained weak. The issue reached a turning point in PUCL (People’s Union for Civil Liberties) v. Union of India (1997),5 where the Supreme Court addressed unregulated telephone wiretapping by state agencies. Recognizing that telephonic conversations fall under Article 21 (Right to Life and Personal Liberty) and Article 19(1)(a) (Freedom of Speech and Expression), the Court acknowledged a severe “procedural vacuum”. To prevent state intrusion, the Court established administrative guidelines to govern wiretapping. Yet these safeguards relied primarily on internal executive review rather than independent judicial authorization, leaving state surveillance authority largely unchecked.

The landmark ruling in K.S. Puttaswamy v. Union of India (2017) marked a significant shift in Indian constitutional law by confirming privacy as a vital part of the right to life and personal liberty under Article 21.6 A nine-judge bench unanimously held that privacy is a fundamental right protected under Article 21, as well as Part III of the Constitution. The Court declared that privacy includes individual dignity, bodily autonomy and informational self-determination, affirming that an individual retains privacy rights even in public spaces and digital networks. The question that followed was whether India’s surveillance statutes could meet this standard.

II) Statutory Framework and Judicial Evolution

India’s operational surveillance architecture relies primarily on two statutory regimes: the Indian Telegraph Act, 18857 and the Information Technology Act, 2000.

Section 5(2) of the Indian Telegraph Act, 1885 empowers the Central or State Government to intercept telephonic communications upon the occurrence of a “public emergency” or in the interest of “public safety”. These thresholds can be invoked on grounds such as state security, public order or sovereignty. Rule 419A of the Indian Telegraph Rules, 19518 governs these interceptions. Under Rule 419A, interception orders can be issued only by the Union Home Secretary or a State Home Secretary, on grounds such as public safety, sovereignty or the security of the State.

Digital communications are governed by Section 69 of the Information Technology Act, 2000.9 Section 69 empowers the Central or State Government to issue directions for the interception, monitoring or decryption of any information stored or transmitted through any computer resource. In comparison to the Telegraph Act, Section 69 omits the prerequisites of “public emergency” or “public safety”, allowing surveillance for the broader purpose of investigating any offence. Under the IT Rules, 2009,10 approval authority remains centralized with executive officials. Furthermore, Section 69B of the Information Technology Act, 2000 empowers the Central Government to authorize government agencies to monitor and collect traffic data or information generated, transmitted, received or stored in any computer resource.

The enactment of the Digital Personal Data Protection (DPDP) Act, 2023 introduced significant data protection principles for private entities, yet it also created a substantial statutory loophole for state surveillance operations. Under Section 17(2)(a) of the DPDP Act,11 the Central Government has the power to exempt any state instrumentality from the provisions of the Act by executive notification. These exemptions can be granted in the interest of the sovereignty and integrity of India, the security of the State or public order. Consequently, state intelligence and law enforcement agencies may be exempted from core data governance mandates, including purpose limitation, data minimization and storage limitation. By shielding state instrumentalities from statutory accountability, Section 17(2)(a) severely undermines individual informational self-determination, a core component of Article 21 as established in Puttaswamy.

III) Critical Evaluation and Proportionality Deficit

The structural vulnerability at the heart of India’s surveillance regime is its reliance on administrative self-review. Under Rule 419A of the Telegraph Rules and the 2009 IT Rules, executive officers issue interception orders, which are then reviewed by a committee composed entirely of senior bureaucrats, typically the Cabinet Secretary, the Law Secretary and the Telecommunications Secretary.

This model violates the fundamental principle of nemo judex in causa sua (no one should be a judge in their own cause). An executive branch tasked with law enforcement and national security cannot impartially adjudicate whether its own intelligence-gathering measures meet constitutional standards. By lacking independent judicial warrants prior to interception, a safeguard present in democratic jurisdictions such as the UK and the US, India’s framework reduces oversight to an internal administrative routine.

This lack of statutory oversight is intensified by the State’s rapid deployment of advanced, non-statutory surveillance technologies. Law enforcement agencies increasingly use Automated Facial Recognition Systems (AFRS), predictive policing algorithms and wide-scale metadata harvesting without any parliamentary legislation governing their use. Operating without statutory backing, these deployments violate the first criterion of Puttaswamy, the requirement of legality, which mandates that any state interference with privacy must be grounded in clear, accessible and specific law.

The deployment of pervasive technical surveillance also has a severe chilling effect on fundamental freedoms. When citizens know that their movements, associations and digital footprints are subject to unmonitored state logging, self-censorship inevitably follows.

IV) Legislative Reforms and Path Forward

To reconcile India’s surveillance practices with the Puttaswamy proportionality framework, statutory reform must begin by eliminating administrative self-authorization. Section 5(2) of the Indian Telegraph Act12 and Section 69 of the IT Act13 must be amended to mandate prior judicial authorization for all targeted surveillance orders. Except in narrowly defined, time-sensitive emergencies, which should require ex post judicial ratification within 24 hours, interception orders should be issued only by a designated judicial officer or a specialized judicial warrant tribunal, and only upon a showing of probable cause and necessity.

Realigning the DPDP Act with Article 21 demands a significant narrowing of the Section 17 exemptions. Rather than granting blanket immunity to state instrumentalities, Section 17 must be amended to replace open-ended executive discretion with strict, defined legal standards. Exemptions granted to state intelligence and law enforcement agencies should be applied only on a case-by-case basis, and only when strictly necessary for specific national security or criminal investigation needs.

Moreover, even when valid exemptions are granted, state entities must remain bound by baseline data protection principles, including purpose limitation, data minimization and strict storage limitation periods.

3) Conclusion

The constitutional right to privacy established in Puttaswamy represents a landmark victory for individual autonomy in India’s legal landscape. However, a constitutional guarantee is only as robust as the statutory mechanisms that enforce it. As state surveillance transitions from traditional wiretaps to advanced digital tracking, automated biometrics and broad statutory data exemptions, the gap between constitutional theory and executive practice threatens to erode Article 21 rights. Balancing individual liberty with national security does not require sacrificing democratic accountability. By replacing administrative self-scrutiny with prior judicial authorization, establishing independent oversight and narrowing statutory exemptions under data protection law, India can build a surveillance framework that serves state security without compromising constitutional principles. Reforming these mechanisms will ensure that the right to privacy remains an active, enforceable shield against executive overreach in the digital age.

Bibliography

Table of Cases

  1. Kharak Singh v State of U.P., (1964) 1 SCR 332
  2. M.P. Sharma v Satish Chandra, AIR 1954 SC 300; (1954) 1 SCR 107
  3. People’s Union for Civil Liberties (PUCL) v Union of India, (1997) 3 SCC 301

Table of Legislation

  1. Digital Personal Data Protection Act, 2023, s 17(2)(a)
  2. Indian Telegraph Act 1885, s 5(2)
  3. Indian Telegraph Rules 1951, r 419A
  4. Information Technology Act 2000, s 69
  5. Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules 2009, r 3

Secondary Sources

  1. Centre for Law & Policy Research, “Justice K.S. Puttaswamy vs. Union of India”, CLPR Translaw (accessed 23 August 2026)
  2. Ekta Yadav and Prof Gaurav Khanna, “The Evolution of Right to Privacy: From K.S. Puttaswamy to Aadhaar”, IJFMR (accessed 23 August 2026)

Footnote(S):

1 Centre for Law & Policy Research “Justice K.S. Puttaswamy vs. Union Of India” https://translaw.clpr.org.in/case-law/justice-k-s-puttaswamy-anr-vs-union-of-india-ors-privacy/ 23th August 2026

2 Digital Personal Data Protection Act, 2023

3 M.P. Sharma v Satish Chandra, AIR 1954 SC 300; (1954) 1 SCR 107

4 Kharak Singh v State of U.P., (1964) 1 SCR 332

5 People’s Union for Civil Liberties (PUCL) v Union of India, (1997) 3 SCC 301

6 Ekta Yadav , Prof Gaurav Khanna The Evolution of Right to Privacy: From K.S. Puttaswamy to Aadhaar , IJFMR https://www.ijfmr.com/papers/2025/6/59991.pdf 23rd August 2026

7 Indian Telegraph Act 1885, s 25

8 Indian Telegraph Rules 1951, r 419A

9 Information Technology Act 2000, s 69

10 Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules 2009, r 3

11 Digital Personal Data Protection Act 2023, s 17(2)(a)

12 Indian Telegraph Act 1885, s 5(2)

13 Information Technology Act 2000, s 69

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top