Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →

The Supreme Court Will Examine Police Facial Recognition. The DPDP Act Exempts the State — But Not the Vendors.

Supreme Court will examine police facial recognition at protests. DPDP Section 17 exempts the State — but the vendors holding the biometric data aren't.

D
DPDPBot Research Team
🕐 10 min read

#The Supreme Court Will Examine Police Facial Recognition. The DPDP Act Exempts the State — But Not the Vendors.

On 13 August, a three-judge Bench led by Chief Justice Surya Kant agreed to examine whether Delhi Police lawfully deployed facial recognition, drones and biometric capture against protesters at Jantar Mantar. The case matters far beyond protest policing, because it puts a question to the Court that the Digital Personal Data Protection Act, 2023 deliberately declined to answer: what happens to biometric data when the State collects it, and who is liable for the copy sitting on a private contractor's servers?

That second half is where Indian businesses should be paying attention. Section 17 of the DPDP Act can lift the law off the government. It does not lift the law off the companies that build, host and operate the surveillance stack.

#What the Supreme Court actually did on 13 August

The Bench of CJI Surya Kant, Justice Joymalya Bagchi and Justice V. Mohana agreed to hear a writ petition (Diary No. 45049/2026) filed by CPI(M) Rajya Sabha MP A.A. Rahim through Advocate-on-Record Subhash Chandran K.R., and tagged it with petitions already pending before the Court arising from the Cockroach Janata Party student protests.

Senior Advocate Dr. Menaka Guruswamy told the Court that facial recognition was being used by Delhi Police against protesters and that the resulting data is held by private companies. Her legality argument is narrow and, so far, unanswered: neither Delhi Police standing orders nor the Criminal Procedure (Identification) Act, 2022 authorise this. That 2022 statute reaches persons arrested, convicted or otherwise brought into the criminal process. It says nothing about scanning the face of someone standing in a lawful assembly.

The reliefs sought are unusually concrete for a surveillance petition. Beyond a declaration that indiscriminate biometric surveillance of peaceful assemblies is unconstitutional, the petition asks for disclosure of the technologies, databases and vendor arrangements used, a mechanism for affected individuals to access and delete their data, and a direction to the private respondents to permanently destroy the biometric information in their custody.

Named alongside the Union of India, Delhi Police and the National Crime Records Bureau are two private firms: Aditya Infotech Ltd. and Dimension NXG Pvt. Ltd.

A parallel petition by former JNU students' union president Aishe Ghosh was already before the Delhi High Court. On 27 July, Solicitor General Tushar Mehta argued that petition had become infructuous, submitting that video-recording a protest served a legitimate state interest and that the organisers were filming too. The Bench observed that the plea was confined to one protest, suggested a broader petition addressing the surveillance framework itself, and said: "Things have cooled down. Let them cool down further." The Supreme Court's decision three weeks later to take up exactly that broader question is the development worth marking.

#The stack: Ikshana, AjnaLens, Abhigyan

The petition describes a layered deployment rather than a single camera network. Live facial recognition ran through CCTV and drones. Real-time identification was carried out from a mobile command-and-control vehicle called Ikshana and through AjnaLens smart spectacles. Fingerprint matching was done in the field through a mobile application called Abhigyan.

Two details give the case its force. First, an RTI response from Delhi Police confirms that no privacy impact assessment was conducted before the facial recognition deployment. Second, separate RTI disclosures obtained by the Internet Freedom Foundation and cited in a Bar and Bench column published on 15 August show Delhi Police treating a facial similarity score above 80% as a "positive" identification — a threshold that, applied across a crowd of thousands, generates false matches by design.

The column, by Akshat Singh, makes the structural argument plainly: India's Automated Facial Recognition Systems "stumble right at the first hurdle because there is no Act of parliament which allows the police, railways, or temple trusts to operate live facial recognition on the public." What exists instead is a patchwork of executive orders, police manuals, and court directions repurposed from their original context — most notably Sadhan Haldar v. NCT of Delhi, a Delhi High Court direction concerned with tracing missing children, now serving as ambient legal cover for something far larger.

Under K.S. Puttaswamy v. Union of India (2017), state action invading privacy must clear four hurdles: a valid law, a legitimate aim, proportionality, and procedural safeguards. Where there is no statute at all, the analysis stops at the first.

#Why the DPDP Act gives protesters almost nothing here

This is the uncomfortable part for anyone who assumed the DPDP Act closed this gap. It did not, and the exemption is not accidental.

Section 17(1)(c) removes the Act's core obligations for processing carried out in the interests of prevention, detection, investigation or prosecution of offences. Section 17(2)(a) goes considerably further: it lets the Central Government exempt any "instrumentality of the State" from nearly the whole Act by notification, on grounds including sovereignty, security of the State, and public order.

There is no defined oversight agency attached to that power, no sunset clause, and no requirement of judicial authorisation. As a LiveLaw analysis published on 11 August by Dr. Anuradha Singh and Ayush Chaudhary put it, the Act's broad state exemptions combined with the absence of an operational Data Protection Board leave effectively no regulatory constraint on facial recognition deployment at protests.

That absence is not rhetorical. The Data Protection Board of India was legally established on 13 November 2025 under Section 18. Nine months later it still has no appointed Chairperson and no appointed Members; MeitY advertised one Chairperson and four Member posts in May and June 2026 and the selection process remains open. A data principal whose face was captured at Jantar Mantar has, on paper, a grievance route under the Act. In practice there is no one to hear it.

So the constitutional claim — Articles 19(1)(a), 19(1)(b) and 21, tested against Puttaswamy — is doing the real work in this litigation. The DPDP Act is not the shield. It is closer to being part of the problem.

#The vendors are not exempt, and that is the compliance story

Here is what Indian companies should take from this case.

Section 17(2)(a) exempts instrumentalities of the State. Aditya Infotech Ltd. and Dimension NXG Pvt. Ltd. are private companies. A private surveillance contractor is not an instrumentality of the State because it sells to one. When such a firm determines or shares in determining the purpose and means of processing personal data — and biometric templates are personal data — it is a data fiduciary under Section 2(i), carrying the full weight of the Act's obligations.

The petition is explicit that the two firms collected and processed biometric data "in violation of the Digital Personal Data Protection Act, 2023", and it asks the Court to order them to stop and to delete what they hold. Whatever the Court ultimately decides on the constitutional question, that framing should concentrate minds in every boardroom selling into government surveillance procurement.

Three exposures follow directly, and none of them wait for May 2027 to become commercially real:

Purpose limitation and data minimisation. Sections 4 through 6 tie processing to the specified lawful purpose for which consent was given, or to a legitimate use. A vendor retaining crowd biometrics after an engagement ends, or reusing them to tune a model, has no purpose to point to and no consent to rely on.

Storage limitation and erasure. Section 8(7) requires a data fiduciary to erase personal data once the specified purpose is no longer being served, unless retention is required by law. A contract with a police force is not a retention statute.

Security safeguards. Section 8(5) requires reasonable security safeguards, and Rule 7 of the DPDP Rules, 2025 sets the breach notification machinery. A vendor holding raw biometric templates of tens of thousands of identifiable people is holding the highest-severity dataset in Indian privacy law, with penalties reaching ₹250 crore for a security failure.

Volume, sensitivity and risk of harm are precisely the criteria the Government weighs under Section 10 when designating a Significant Data Fiduciary. A firm operating live biometric identification at civic scale sits squarely in that assessment, which would add Data Protection Impact Assessments, independent audits and a India-resident Data Protection Officer to the list. If you are mapping which of your processing activities carry that exposure, our resources library sets out the designation criteria and what changes once you are inside them.

#What the EU does, and the export gap it leaves

The comparison is unavoidable, and it is not flattering. Article 5(1)(h) of the EU AI Act prohibits real-time remote biometric identification in publicly accessible spaces for law enforcement, in force since 2 February 2025. Three narrow exceptions survive — targeted search for victims of trafficking, imminent terrorist threat, and location of suspects in serious crime — and each requires prior judicial or independent administrative authorisation, a fundamental rights impact assessment, and registration in an EU database. The European Court of Human Rights reached a similar place from the rights side in Glukhin v. Russia (2023), holding that live facial recognition used to identify a solo protester violated both privacy and freedom of expression.

India's DPDP Act runs the other way: a discretionary executive power to exempt the State entirely, exercised without judicial sign-off.

The gap between those two regimes has already become an export story. A cross-border investigation reported in July found that Barcelona-based Herta Security, which has received over €3.3 million in EU research grants since 2020, supplies facial recognition running on more than 4,000 cameras in India — railway stations, Delhi's largest prison complex, Ayodhya, and Ahmedabad's city-wide control room. Four EU AI law specialists consulted for the investigation concluded that at least two of those deployments, on Indian Railways' Eastern Region and the Ahmedabad city system, would be unlawful if operated on European soil. Herta has said EU funding did not finance or subsidise its commercial deployments in India.

For Indian buyers, the practical lesson is that "certified in Europe" tells you nothing about whether a deployment would be lawful in Europe. For Indian sellers, the reverse: a domestic reference deployment built on the assumption that the State's exemption travels down the supply chain is a reference you may not want to show a European customer, or an Indian court.

#What to do now if you touch biometric data

Facial recognition, fingerprint capture and voice matching are the most consequential categories the DPDP Act governs, and they are the least forgiving of the "we will fix it before May 2027" posture that MeitY has spent this month publicly refusing to indulge.

If your organisation deploys or supplies biometric systems, four things are worth doing before the next hearing in this matter:

  1. Establish your lawful basis in writing, per deployment. Not per product. A single contract clause asserting a government customer's authority is not a basis, and after this petition it is a documented risk.
  2. Run the impact assessment the police did not. The RTI admission that no privacy impact assessment preceded the Delhi deployment is the single most damaging fact in the case. Do not be the vendor whose file is equally empty.
  3. Set and enforce a deletion clock on biometric templates. Section 8(7) is not aspirational, and raw templates are the hardest data to justify keeping.
  4. Separate consented commercial processing from state-directed processing. Where you do rely on consent, it needs to be specific, informed, revocable, and auditable — which is what the consent manager framework taking effect from 13 November 2026 is built to evidence. Blending the two pools is how a lawful commercial dataset acquires an unlawful provenance.

The Supreme Court has not ruled yet. It has done something that in Indian constitutional litigation often matters as much: it has accepted that the question is worth answering, and consolidated it with the other protest-surveillance matters so that it will be answered once, at the level of the framework rather than a single afternoon at Jantar Mantar. Whatever the Bench concludes about Delhi Police, the companies that supplied the cameras, the spectacles and the command vehicle will be answering under a statute that offers them no exemption at all.


Need to know where biometric and other high-risk processing sits in your organisation before the Board is constituted? Start with our resources on Significant Data Fiduciary designation and data protection impact assessments, and see how a compliant consent manager integration evidences lawful basis ahead of the 13 November 2026 milestone.

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready — all in one platform.

Start free trial