When Seeing Becomes Recording: Invisible Bystander And Limits Of Indian Privacy Law

Update: 2026-08-13 02:30 GMT
Click the Play button to listen to article

In July 2026, the Meta-AI powered Ray-Ban smart glasses became the center of conversation after two unconnected incidents captured public attention. At a trans rights march in Delhi, a content creator filmed a brief conversation with a protestor, without her knowledge. Days later, in a separate incident, photographs of a Delhi police officer wearing the same glasses while deployed at a public gathering started making rounds on social media. Both incidents exposed the same underlying anxiety - when a camera is built into an ordinary-looking pair of spectacles, how does the law protect those unaware around the wearer? While the Meta-AI Glasses have been hailed as a leap in AI technology, and as a marker of technological sophistication, it raises a range of multi-layered questions, cutting across the concepts of consent, surveillance, and most importantly, privacy.

Clicking photos or recording videos in public is an everyday act, thanks to smartphones. Recording on phones or cameras in public is overt and generally identifiable, if one has an objection, they may bring it up with the person recording. What makes these glasses different is not merely what they record, but how they do it. In the absence of any visible camera or a recording indicator, determining whether recording is taking place becomes exceedingly difficult, which, by extension means, that raising objections or even making inquiries is a far-fetched act. One could use the glasses to continuously record, analyse, process and transcribe people's activities, without them having any idea of being recorded. What makes these glasses a point of legal debate is their act of blurring the distinction between “seeing” and “documenting”. This article examines whether the Indian legal framework is equipped to address the unique privacy challenges posed by smart glasses and other wearable, seemingly ambient AI technologies.

The discontent with AI smart glasses is not that they enable people to see one another in public, but that they significantly alter the way information flows in everyday life. As Helen Nissenbaum argues, “privacy is not breached merely because information is observed in public spaces, it is compromised when information is collected, processed or shared in ways that are inconsistent with the norms of the context in which they were generated”. AI wearables breach this very contextual expectation by transforming ordinary, everyday interaction into continuous surveillance, often without the knowledge of those affected.

THE LIMITS OF EXISTING PRIVACY LAW

Broadly, Indian privacy law can be traced back to K.S. Puttaswamy v UOI, where a nine-judge bench of the Supreme Court held that the right to privacy is protected under Article 21. The judgment is highly celebrated for its recognition of the informational privacy and individual dignity as constitutional values. Although a significant step in development of Constitutional rights in India, it has to be acknowledged that this is a judicial decision, which, in simple terms, means that it primarily operates against the State and does not create any private law remedy whenever an individual records another.

Criminal law, on the other hand, provides selective remedies to a limited extent. Existing criminal law only recognises specific instances of invasion of privacy, such as voyeurism, stalking and the non-consensual recording of intimate images. Section 77 of the BNS protects women against observation or recording when engaged in private acts. Section 78 criminalises stalking, including repeated monitoring through electronic means. Section 66E of The Information Technology Act, similarly, penalises capturing, publishing or transmitting images of a person's “private area”, without consent in circumstances violating privacy. While these are important provisions, the threshold of violation they demand is higher than the one met by continuous recording using these glasses. This is a legal void that remains unaddressed. None of these sections address the more every day, ordinary situation in which any individual wearing smart glasses records strangers in public, gathering data and recording behaviour. This act, although unsettling, does not readily fit into any legal offence at present.

DATA PROTECTION AND THE INVISIBLE BYSTANDER

The paradox becomes apparent under the DPDP Act. The bystander, whose face and voice are captured, is undoubtedly subject to personal data. At first glance, it appears that the Digital Personal Data Protection Act, 2023 provides the most relevant framework for addressing this lacuna. The DPDP Act regulates collection and processing of personal data more broadly. The Act defines a data principal as the individual to whom the personal data relates and generally, under Section 4(1)(a), permits processing of that data only with that individual's consent. On paper, therefore, any bystander being recorded, whose face, voice or other information is captured through smart glasses would qualify as a data principal, whose consent is the basis of retention and processing of data.

The DPDP Act proceeds on the assumption that the individuals are aware that their personal data is being processed or collected, giving them a chance of consenting or refusing or subsequently exercising rights such as access, correction and deletion. AI glasses collapse this assumption. In the absence of any overt signal, the recording is so discreet that the bystanders may never realise that their personal data has been collected, let alone processed by AI systems. Therefore, unless verbally asked, the aspect of consent is conspicuously absent throughout.

The complexity is also in the manner in which such technology circumvents the Act. As a data fiduciary, Meta may owe obligations under the Act, but the problem still remains - the bystander would have no practical way of knowing that their data has entered the Meta systems, let alone exercising their rights of access, correction or erasure. The person whose privacy has been violated or whose data has been recorded, is not the person who interacted with the platform in the first place despite which their data might be processed and used without them ever knowing and stepping up for objection or enforcing their rights.

This is the central problem posed by AI-enabled wearables. Indian privacy law contemplates three actors - the state, whose powers are hedged by the Constitution, the data fiduciary, whose processing is regulated by the DPDP Act and the victim of a recognised criminal offence. The ordinary bystander falls into none of these categories. They are neither the state, nor the fiduciary, nor the user or the victim of a statutorily recognised privacy offence. As a result, the individual whose privacy interests are most directly affected, occupies the least visible position within the existing legal framework. This lacuna is not unique to India.

EVIDENCE WITHOUT CONSENT

The lack of consent also permeates the boundaries of the Evidence framework. Indian courts do not recoginse the “fruit of a poisonous tree” doctrine, which simply means, that the evidentiary value of electronic records obtained through scrupulous, non-consensual means is admissible, subject to the court's discretion. While Puttaswamy elevated the right to privacy to the stature of fundamental rights, Indian evidence law has remained untouched. The fact that legally unconsented recordings remain valid and admissible, is incentive enough for the usage of such ambient technology, which very conveniently falls within the contours of procedural law, while Constitutional law simultaneously seeks to prohibit such misuse.

WHEN “NO CAMERAS ALLOWED” IS NO LONGER ENOUGH

The implications of the use these wearables are not just limited to their interaction with the black letter of law but transgresses into the very infrastructure of the legal system – the Courts, which are sensitive institutions that strictly prohibit the use of cameras or recording of proceedings on devices within their premises to maintain the integrity of judicial proceedings. Smart glasses, by virtue of their inconspicuous design, have the potential to breach this boundary, allowing recordings to be made despite institutional restrictions. The relevance of such mandates stem from their robust enforceability, but as recording devices become harder to detect, the practical effectiveness of these restrictions is likely to diminish.

EMERGING REGULATORY RESPONSES

The problem is acute and spreads across jurisdictions. Although many countries have now begun recognising the issue, the response in terms of solid legislation has been weak. Meta has attempted to address these concerns by incorporating a visible LED recording indicator and publishing user guidelines that place the onus on the user and are just recommendations to use the device as “responsible citizens” and not use them for “unlawful purposes”. Whether this small, covert LED serves as enough notice, remains contested. The Irish Data Protection Commission has in fact called upon Meta to clarify whether these tiny LED lights are enough to serve as notice to people being recorded. These developments suggest that there is a consensus that AI enabled wearables present novel risks that have hitherto not been posed by conventional cameras. What remains absent, however, is an overarching regulatory framework capable of addressing these risks efficiently.

RETHINKING REGULATION

In the Indian context, perhaps the first, and most important step would be the recognition of AI wearables as a distinct regulatory category is imperative. Their ability for continuous and inconspicuous recording along with real-time AI processing sets them apart from conventional cameras and justifies bringing in new regulations. Parliament may consider introducing a separate regulatory framework for such wearable recording devices. Such a framework could (i) require a visible, intelligible tamper-proof recording indicator whenever recording is active, similar to the proposal presently under consideration in Pennsylvania; (ii) empower regulators to prohibit the use of such devices in designated sensitive spaces, including courtrooms, hospitals, schools and examination centres, akin to restrictions adopted by the New York court system; and (iii) prescribe technology-specific obligations governing recording, retention and AI processing of footage, drawing inspiration from the legislative frameworks developed by several U.S. states for police body-worn cameras. These measures would regulate the distinctive risks posed by wearable surveillance without unnecessarily restricting ordinary photography or personal use.

It is well settled that Puttaswamy recognized informational privacy as an integral part of dignity and personal liberty, yet, as this article argued, the existing framework has been weak and reactive in addressing identifiable harms after they occur and has often not addressed the infrastructure that makes such harms possible in the first place. If the constitutional promise of privacy is to remain relevant in the era of ambient AI technology, law must step up beyond protecting only those who know that their data has been collected and begin safeguarding those who may never realise that they have become part of someone else's digital memory. The bystander should no longer remain the forgotten subject of India's privacy framework.

Author Advait Mishra is an Advocate based in Chhattisgarh & Avilokita Kesharwani is a 2nd Year LLB Hons student at National Law School of India University, Bangalore. Views are personal.

Tags:    

Similar News