Surveillance isn’t the only privacy concern

IIn August 2026, the Supreme Court heard a public interest litigation related to doxxing and deepfakes and asked Union ministries to take remedial action. Earlier in July, AA Rahim, a member of the Rajya Sabha, petitioned the Supreme Court against the Delhi Police’s use of facial recognition and biometric tracking during the Cockroach Janta Party (CJP) protests. And in May, the SC upheld the Election Commission’s (EC) Special Intensive Review of Electoral Rolls (SIR), although critics warned it could exclude large numbers of eligible voters.

While these stories may seem like three unrelated stories, read together, they form a pattern connecting the state, private firms, online networks, and citizens caught between them.

Three kinds of tracking

Facial recognition is the most obvious; The state watches people in public and tries to find out who they are. Mr. Rahim’s petition alleges that the Jantar Mantar police used facial recognition, artificial intelligence smart glasses, drones and a mobile command vehicle, and that the data was hosted by two private firms.

The CJP’s protests exposed the second layer. The women who participated were later targeted online: their personal information was made public with reported rape and death threats. Public identification as punishment is not new; in March 2020, the Uttar Pradesh administration placed hoardings in Lucknow with photographs and addresses of people protesting against the Citizenship Amendment Act. The Allahabad High Court ordered their removal, calling the display an “unwarranted invasion of privacy”. There is no need for hoarding today; a photo can be uploaded, identified, extended and linked to an address within hours.

SIR is a third kind of monitoring where identity checks decide who stays on the electoral roll. The Supreme Court ruled that the EC can examine citizenship for this limited purpose, even though it cannot decide on citizenship itself. However, the range is significant: Bihar’s SIR started with around 7.89 million voters and ended with a final roll of 7.42 million.

None of it falls evenly. For minorities, migrants, Dalits, Adivasis, women and the poor, surveillance determines whether they are counted, trusted or safe.

Indian jurisprudence on privacy has a strong foundation. In KS Puttaswamy Vs. Union of India (2017), a nine-judge Bench held privacy as a constitutionally protected right. However, Puttaswamy was decided in a case against the state and its test is built on state action. The Digital Privacy Act, 2023 allows the Union government to exempt any state instrumentality from the act by notification on grounds that include state security and public order. So consider Pegasus, a spyware made by an Israeli firm and allegedly used against journalists, activists and others. A court-appointed independent panel of experts reported malware in some of the phones it examined in 2022, but could not say for sure whether it was Pegasus; he also noted that the Union government was not cooperating. Later in 2025, the oversight committee said parts of the report would not be made public.

The result is therefore a legal environment in which the strongest constitutional protections may apply at one point in the chain, while the same person’s information passes through other hands outside of it. Who is then responsible when a protester is identified on camera, doxxed by anonymous accounts, and then threatened at home? What happens to privacy when electoral roll decisions determine whether someone can vote? What safeguards apply when data collected by the police is held by a private company? India does not have clear answers to these questions.

None of this is new. State interest in identifying individuals predates Aadhaar by more than 150 years. In 1858, William Herschel, a British judge, began taking handprints on contracts. This technique was later developed into the fingerprint classification system in Bengal. The technology has changed, but the impulse to make the population identifiable has not. It shows up in Aadhaar, Delhi cameras and SIR.

What’s different today is scale and speed. The state cameras, the private companies that operate them, the social media accounts that spread deepfakes, and the bureaucratic exercises that decide who counts for the role are not separate stories that happen to take place in the same summer. They are connected.

The current moment therefore calls for a different starting point: one that considers surveillance not as a discrete act by an identifiable actor against an identifiable person, but as a blanket act spread across states, companies, and foreign vendors all at once. Until India’s privacy debate catches up with this reality, any right it wins will always be a half-win, built to match threats the moment it’s written and out of date by the time it’s actually enforced.

Pankhuri Agarwal is a lecturer and Leverhulme Early Career Fellow at King’s Business School, King’s College London. Author of Fictions of Freedom: Migration, Modern Slavery and Bureaucracy in India (2026)

Published – 30 Sep 2026 0:50 AM IST