When State Watches Protest: Constitutional Limits Of Facial Recognition Surveillance
Last month, as students gathered at Jantar Mantar demanding accountability for the NEET paper-leak scandal, a mobile command vehicle rolled in behind them, its telescopic mast fitted with cameras sweeping a 360-degree arc over the crowd. Photographs circulated of the vehicle, of AI-enabled smart spectacles worn by personnel, and of handheld scanners pointed at faces in the assembly. Within days, two separate constitutional challenges had been filed one by student activist Aishe Ghosh before the Delhi High Court, another by Rajya Sabha MP A.A. Rahim before the Supreme Court under Article 32 both asking essentially the same question: on what legal authority does the Indian state photograph, biometrically map, and retain the identities of citizens who have gathered to protest?
The honest answer, at present, is none. That gap not the technology itself is what makes this moment constitutionally significant.
A Vacuum Dressed As Policy
India has no statute that authorises, regulates, or limits the use of facial recognition technology (FRT) by police at public assemblies. The Criminal Procedure (Identification) Act, 2022, often invoked by law enforcement to justify biometric collection, is confined by its text to persons arrested, convicted, or otherwise brought within the criminal process it says nothing about capturing the faces of citizens exercising the fundamental right to assemble peaceably under Article 19(1)(b). The Digital Personal Data Protection Act, 2023, meanwhile, carves out broad exemptions for processing carried out by or on behalf of the State in the interests of sovereignty, security, and public order, and in any event remains substantially unenforced in the absence of an operational Data Protection Board. Neither statute was drafted with a scenario like Jantar Mantar in mind, and neither statute constrains it.
What existed at Jantar Mantar instead was executive practice: a facial recognition unit reportedly named “Ikshana,” AI-enabled smart glasses supplied by a private vendor, and integration with the Delhi Police's wider network of AI-linked CCTV cameras feeding into a centralised command centre a network whose scale was inaugurated with considerable fanfare by the Union Home Ministry earlier this year. The petitions note that Right to Information applications pursued through the Central Information Commission have struggled to establish even basic facts: what data is collected, how long it is retained, against which databases it is matched, and who authorised its deployment at a protest rather than at a crime scene. This is not incidental opacity. It is what a legal vacuum looks like in practice technology deployed at scale, answerable to no statute, and therefore, in constitutional terms, answerable to no one.
The Puttaswamy Test, Applied To A Crowd
The constitutional vocabulary for testing this practice already exists. K.S. Puttaswamy v. Union of India established that any State action infringing privacy must clear three hurdles: legality (a law must authorise it), legitimate aim (the law must serve a proper state purpose), and proportionality (the means must be necessary and the least restrictive available to achieve that purpose). FRT deployed against a protesting crowd fails at the first hurdle before the other two are even reached there is no law to test for proportionality, because there is no law at all.
But it is worth pressing further, because even a hypothetical statute authorising FRT at protests would face a proportionality problem of a distinctive kind. Ordinary surveillance jurisprudence in India has developed around targeted measures phone tapping under the Telegraph Act, for instance, requires an order directed at a specific person or line, reviewed by a competent authority. Facial recognition at a public assembly inverts that logic entirely. It does not target a suspect; it processes every face in a crowd of thousands indiscriminately, converting each into a biometric template capable of being matched, stored, and cross-referenced, regardless of whether that person has done anything to attract police attention beyond attending a protest. The proportionality inquiry cannot be conducted after the fact, individual by individual; it has to be built into the design of any permissible framework, through purpose limitation, strict retention caps, and prior judicial or independent authorisation before deployment none of which currently exist.
This indiscriminate character is also what gives the challenge its second constitutional dimension: the chilling effect on Article 19(1)(a) and 19(1)(b) rights. A citizen who knows that attending a protest means being biometrically logged into a police database, for an unknown duration, for unknown future use, faces a real disincentive to attend at all. Constitutional courts across jurisdictions have recognised that surveillance need not result in arrest or prosecution to cause injury; the awareness of being watched itself reshapes conduct, and speech chilled by surveillance is speech denied.
A Comparative Signal Worth Reading
India is not alone in confronting this question, and the comparative record is instructive rather than merely decorative. In R (Bridges) v. Chief Constable of South Wales Police, the England and Wales Court of Appeal held in 2020 that police use of live facial recognition technology, though not inherently unlawful, violated the right to privacy under the European Convention because the legal framework governing it left too much discretion to individual officers over who could be scanned and where the “who” and “where” questions were left effectively undefined, with no clear, publicly accessible policy constraining them. The court also found the force had failed in its duty to assess whether the technology's error rates disproportionately affected people by sex or race. The parallels to the Indian situation are not exact, but the structural lesson transfers cleanly: it is the absence of a clear, public, judicially reviewable framework not the existence of the technology as such that renders its use unlawful. A state cannot outsource the boundaries of a fundamental-rights-infringing power to unpublished internal standing orders.
What The Courts Are Now Being Asked To Decide
The Rahim petition asks the Supreme Court to restrain FRT deployment at peaceful assemblies until Parliament legislates. That framing is doing real constitutional work: it does not ask the Court to permanently outlaw the technology, but to insist that Article 21 guarantee of procedure established by law be honoured before the technology is used at all. This is the correct sequencing. Courts are generally reluctant, and rightly so, to design surveillance frameworks from the bench; that is a legislative task, requiring calibration of retention periods, oversight mechanisms, and accuracy standards that shift with the technology itself. But courts are well placed to declare that, in the interim, an executive practice with no statutory basis cannot continue merely because no one has yet stopped it.
If the Court engages with this case on its merits, it has the opportunity to do for algorithmic surveillance what Puttaswamy did for the right to privacy itself supply the missing doctrinal architecture before executive practice, entrenched through years of quiet deployment, becomes politically and administratively irreversible. The Jantar Mantar protests may have ended with the Education Minister's resignation. The constitutional question they raised has not ended with them, and how it is answered will shape what it means to assemble in public in India for a long time to come.
Author Anuradha Singh is an Assistant Professor at Bennett University, Greater Noida & Ayush Chaudhary is a 4th year Law student at ICFAI University Dehradun. Views are personal.