Click the Play button to listen to article

On August 4, 2026, the Supreme Court issued a sweeping thirteen-point directive to combat “digital arrest” scams, a fraud that has cost Indian citizens over ₹52,976 crore in six years. The order is a welcome intervention against a specific criminal menace. But it also throws into relief a quieter, more structural problem the Court has been sitting on since October 2022: what happens when the police, not a con artist, are the ones asking for access to your phone?

That question is the subject of Foundation for Media Professionals v. Union of India, a writ petition still pending before a Bench headed by the Chief Justice. Filed after journalist's laptops and phones were seized en masse during the NewsClick raids, the petition asks for something India's criminal procedure has never provided: guidelines on when and how digital devices may be searched, seized, and mined for evidence. Four years, several hearings, and one CBI Manual assurance later, the case remains undecided. In the interim, trial courts and High Courts have been left to improvise a doctrine that Parliament never wrote and the Supreme Court has not yet settled.

A Search Regime Built for Almirahs, Not Smartphones

Sections 185 and 186 of the Bharatiya Nagarik Suraksha Sanhita (successors to Sections 93 and 165 CrPC) authorise police to search premises and seize “documents” or “things” believed relevant to an investigation. This framework was designed for a world of almirahs, ledgers, and letters discrete physical objects with natural boundaries. A locked cupboard yields the specific file the police are looking for; the search ends there.

A smartphone has no such boundary. It is, in the Karnataka High Court's own description in Virendra Khanna v. State of Karnataka (2021), a repository of “entire personal life” banking credentials, medical records, privileged legal communications, location history stretching back years, and increasingly, biometric and health data synced from wearables. When BNSS Section 185 is stretched to authorise seizure of a phone, the accompanying search is not of a document but of a universe. Nothing in the statute tells an investigating officer where that universe ends. Nothing requires them to specify, in advance, what category of data they are looking for, or to return or purge what proves irrelevant. The search is general by default precisely the kind of search Article 21's privacy jurisprudence, since Puttaswamy, was meant to discipline through the tests of legality, necessity, and proportionality.

Virendra Khanna remains the most cited authority on point, and it addressed a narrower question: whether compelling an accused to disclose a passcode violates the privilege against self-incrimination under Article 20(3). The Court held it does not, reasoning that a password is analogous to a physical key rather than testimonial content the incriminating material is the data, not the act of unlocking. That reasoning has been extensively debated elsewhere, including on the fit between the Kathi Kalu Oghad testimonial-physical divide and a code that exists only in the accused's memory. But the self-incrimination question, however contested, is only one slice of the larger problem. Even where compulsion is constitutionally permissible, the scope of what may then be searched, copied, and retained remains entirely unregulated. India's digital evidence law has been arguing over the front door while leaving the entire house unmapped.

What “Reasonable Suspicion” Cannot Do Alone

BNSS Section 185 permits a search where the officer has “reasonable ground for believing” the device contains something relevant to the offence under investigation. In physical searches, that offence-specific belief naturally cabins the search: if the suspicion concerns a stolen consignment, the search is for the consignment, not for the household's private correspondence. Digital searches break that logic. There is no way to search a phone for one category of relevant material a threatening message, a bank transfer without the search apparatus passing through, indexing, and often mirroring everything else on the device. Forensic tools used by Indian police (Cellebrite and its domestic equivalents) do not selectively extract; they image the entire device, creating a permanent, portable copy of a person's digital life that persists in the police record indefinitely, searchable well after the original investigation closes.

This is not a hypothetical concern. Once a full forensic image exists, its subsequent use is governed by nothing more specific than departmental practice. There are no statutory minimisation requirement compelling investigators to disregard material outside the scope of the offence under investigation; no mandatory purge once a case concludes in acquittal; no independent audit of who accesses the image and for what purpose. The chain-of-custody rigour Indian courts have developed for narcotics seizures under the NDPS Act sampling protocols, forensic lab accreditation, documented custody logs have no analogue for digital evidence outside that one statute. BNSS Section 105's mandatory seizure videography documents the moment of seizure; it says nothing about what happens to the mirrored data afterward.

What a Digital Search Doctrine Would Require

Comparative jurisprudence offers a workable template, not because foreign law binds Indian courts, but because other apex courts confronted an identical structural problem and produced reasoned solutions. The U.S. Supreme Court's unanimous ruling in Riley v. California (2014) held that the search-incident-to-arrest exception, developed for physical objects on an arrestee's person, cannot be mechanically extended to smartphones, given the “immense storage capacity” that makes a phone qualitatively different from a wallet or cigarette packet. A warrant, the Court held, is presumptively required, and even then, must be tethered to the specific offence under investigation the logic later extended to historical location data in Carpenter v. United States (2018), now itself being tested again this year in Chatrie v. United States over geofence warrants. The United Kingdom's Police and Criminal Evidence Act codes of practice similarly require that digital examinations be conducted under a documented protocol specifying search terms, date ranges, and data categories in advance, with material outside that scope quarantined rather than freely browsed.

An Indian digital search doctrine, whether legislated by Parliament or laid down by the Supreme Court in the pending FMP proceedings, would need at minimum four elements. First, prior judicial authorisation for any forensic examination of a seized device, rather than the current model where a magistrate's role is confined to authorising the initial seizure. Second, particularity: the authorising order must specify the offence, the categories of data reasonably connected to it, and where feasible, a date range, so that the search is not a general rummage through an entire digital life. Third, a mandatory minimisation and segregation protocol, of the kind FMP itself proposed, under which material outside the authorised scope is quarantined from investigators and not used to build unrelated cases the “plain view” doctrine that operates for physical searches has no coherent digital equivalent yet. Fourth, a statutory retention and deletion timeline, tied to the disposal of the underlying case, so that forensic images do not persist as permanent, searchable dossiers on citizens who are acquitted or never charged.

The Cost of Continued Silence

The Supreme Court's own language in the FMP hearings has repeatedly acknowledged the stakes Justice Kaul's observation that “the entire digital footprint is on that one device” captured precisely why physical-search analogies fail. Yet acknowledgment without adjudication has produced four years of regulatory vacuum, filled unevenly by High Court decisions like Virendra Khanna that address compulsion but not scope, and by the Union's informal assurance that the 2020 CBI Manual will apply pending formal guidelines a manual that binds only Union agencies, has no statutory force, and is invisible to the state police forces who conduct the overwhelming majority of digital seizures in India.

The August 2026 directive on digital arrest scams shows the Court is capable of decisive, detailed intervention when the harm is legible and urgent. The harm from an unregulated digital search power is less visible, distributed across thousands of ordinary seizures rather than concentrated in dramatic fraud, but it is no less structural. Until the Court decides FMP, or Parliament legislates ahead of it, the answer to whether police can demand your phone password will keep depending on which High Court you happen to be in, and the answer to what they can then do with everything on it will depend on nothing at all.

Author is a 4th year Law student at CHRIST (Deemed to be University), Delhi NCR. Views are personal.

Tags: