Click the Play button to listen to article

A recent recurring theme in social media circles where users upload their photographs and ask AI systems to recreate those pictures in the 1980's style. While such pictures are entertaining, the underlying question that is only beginning to be addressed by Indian privacy law is rather difficult to answer. When a person uploads his photograph to an AI system, what exactly is he giving consent for? Of course, the natural answer to this question would be the photograph itself. But is it enough anymore?

AI system doesn't necessarily regard a photograph as a passive image. Instead, it becomes the subject for processing, modification, analysis and generation of information regarding the person who appears in the photograph. Thus, the problem is not limited to mere collection of a photograph, but what the AI system will do with it afterwards. The exact question here is whether the consent for processing a photograph for one specific purpose also covers any other inference, transformation, storage or subsequent use of this photograph by the AI system.

The question connects Article 21, the Supreme Court Jurisprudence regarding informational privacy, and the Digital Personal Data Protection Act, 2023 (DPDP Act). At the same time, it uncovers a new challenge which can be called inferential privacy.

The Photograph Is Not Just an Image

Traditionally, the privacy law has been built around information provided by the individual, information gathered, and the use being made of this information. When a user uploads an image to make an “80s version”, the image is the input. However, during the process, the system can analyse visual features, detect patterns, and create an output featuring features that have not been explicitly provided by the user.

The difference is critical. An individual may authorize the AI system to produce a certain style image. This does not mean that an individual consents to every other processing procedure performed to achieve this goal. The privacy issue becomes, therefore, not whether the individual willingly uploaded this image but it is whether the individual is aware of the nature and purpose of the processing that he or she has consented to?

It is critical because the informational content of an image is not confined to the individual who has uploaded it. An image may have other people's faces, one's house, school, workplace, car, landmarks, etc. The image that the user perceives as one picture could turn out to be a massive database of personal data after going through the machine process. It is the same image; however, its informational potential is different now.

What Exactly Did the User Consent To?

The doctrinal foundation of the issue is that of informed consent. The concept of consent itself would make no sense without an objective or purpose behind it. The DPDP Act offers valuable statutory guidance in this matter. Section 4 states that any personal data can be processed solely within the limits of the Act and for a lawful purpose. In cases where the processing of personal data is based on consent, there is statutory guidance about how that consent was acquired. Section 5 plays important role by providing that a Data Fiduciary must notify the Data Principal about their intent to process certain personal data for a certain purpose. This idea is further developed by the Digital Personal Data Protection Rules, 2025. Rule 3 stipulates that such a notification must stand alone and contain, using clear and understandable language, an itemised list of the data to be processed and its purpose or purposes.

This concept acquires its full value when applied to generative AI. If a person uploads a photograph to generate an 1980s style portrait, the intended purpose is obvious: to create the desired image. However, what if the photo was kept for other reasons? And what if the image is used to develop service or improve the model? And what if any other data is extracted from the image than what is needed to create the required output?

This is an issue of the scope of consent. This constitutional aspect makes the issue more relevant. As per the judgment delivered in Justice K.S. Puttaswamy (Retd.) v. Union of India, Supreme Court accepted that the right to privacy is a fundamental right enshrined under Article 21 and informational privacy is its important facet. Privacy is not just about secrecy; it has much more to do with autonomy and dignity and having control over personal information. The consent provided by an individual for disclosing his personal information for a certain purpose should not necessarily mean that he has authorised the use of his information for all technological purposes.

When AI Generates What Was Never There

That is when the issue becomes substantially more complex. Imagine the case of the photograph that causes the trend: a user uploads an old family photograph and asks the AI system to produce an “80s version” of the image. The final product may include changes to clothing, environment, lighting, facial features or other aspects. While some of them may be artistic decisions, others could be information created by the system that was not there in the original photo.

The privacy issue does not arise simply because of the accuracy of such information. The problem is that information generated about an identifiable individual by an AI system could be considered private even though it was never provided directly by that individual. The privacy issues cannot be confined only to the face. A photograph could contain personal information about the subject's surroundings, familial relations, education or occupation, geographic and socio-economic status. In accordance with technological capability and available data, AI systems could try to determine age, identity, emotional condition or other qualities of a person. Most of this information would not be provided by the individual.

The user who thinks she has just uploaded a picture of her childhood may actually have uploaded an informational document that includes her relatives, her school, home, locality, and environment. This makes for a crucial distinction between that which is visible, that which is extracted, that which is inferred, and that which is generated. Such distinctions should not, as a matter of law, necessarily be considered equivalent.

The original photograph is information that is consciously provided by the individual. The extracted information may include characteristics and patterns that are discovered through processing. Inference takes the process a step further; it is the conclusion that a system reaches based on the available information. And the generated information may be a representation or an attribute that did not exist in the source material. However, all four processes may raise the same fundamental question: Was the consent of the individual extended to such processing? It is the issue of inferential privacy. Traditional privacy protection concerns itself with the issue of: What information did the individual disclose? Inferential privacy adds to this question another: What information can a technological system derive or generate about the individual from what she disclosed?

That difference is of great legal significance, since while the individual can exert control over the first, he can exert only limited control over the second. The difference between the two cases is quite obvious. While the former case allows for full control over what is being entered into the system, the latter allows control over the informational opportunities which can be produced from the entry.

There is a challenge in relation to which simply stating that the individual consented to the processing of the photograph will not help. For instance, suppose the AI system can analyse the image and produce certain conclusions regarding the age and other attributes of the individual. Such a process may not have been requested by the individual in question. The same is true in regard to contextual information. The photograph may include other individuals who have not uploaded the photo themselves.

The privacy interest, however, goes beyond the uploader-platform relationship, and thus, demonstrates one of the major limitations of the current consent approach. It is possible to establish the photo provided by the user and the purpose indicated by the platform, but it remains questionable how to deal with information that became available solely due to the use of AI.

Neither the DPDP Act makes provisions for a distinct type of personal data, which could be referred to as “inferred” or “synthetic,” nor any specific framework for each inference made by the AI algorithms is developed under the current legislation. This absence of regulations cannot be interpreted as a conclusion about the fact that there should not be any protection for such information. Rather, this is a legal issue that needs to be addressed. If the information obtained using AI refers to an identifiable individual, then its inferred or generated nature should not mean that no further analysis is necessary.

The Way Forward: Consent Must Follow the Data

The solution cannot be to ban images produced by AI. Nor can every popular image trend be considered a privacy breach. We need to apply principles of privacy and data protection to AI systems. The consent to process the data for providing a certain service should be clearly distinguished from processing the data for another purpose. If consent is given to create an image, it does not mean consent is given to analyse this image in any way or use it for other purposes.

Second, notice has to be meaningful. The users should be able to understand what happens to their photograph, why it is processed, if it is stored and how it will be used aside from fulfilling the immediate request.

Third, if processing of the data produces information about an individual aside from the initial purpose of processing the data, there needs to be a clear legal basis of such processing and the explanation for that.

Fourthly, data minimization needs to be meaningful. It cannot be interpreted as processing as much personal data as possible just because it is possible with current technologies.

Fifthly, people need effective means by which they can exercise their rights regarding their personal data. Deletion and withdrawal provisions make very little sense if users cannot know what information was collected or in what way was it utilized.

Sixthly, more care needs to be exercised when it comes to images involving minors, intimate imagery or scenarios where the synthetic generation can pose increased risks to one's dignity, identity or reputation.

Lastly, accountability should be combined with technological opacity. A person cannot be realistically expected to figure out what the AI system does and how it operates internally.

Privacy risks do not necessarily come from surveillance or data breaches but can be generated even during everyday interactions where people knowingly provide information without realizing the variety of ways modern technologies can process the information.

Besides the Constitution of India, Puttaswamy's jurisprudence, DPDP Act and Rules, we need practical application of these principles to a technological world where data collection involves not only acquisition but also inference, manipulation and production. This implies that the law must stop at asking only “What did the individual share?” but also include the question: “What did the individual allow the system to do with that share?” and in more cases: “What information is allowed for the system to produce about the individual based on that sharing?” A photo could be uploaded in seconds. What could be produced from the information might last longer.

Author is an Assistant Professor at Bennett University, Greater Noida. Views are personal.

Tags: