From Data Privacy To Mental Privacy: What UNESCO's Neurotechnology Recommendation Means For India

Sagnik Debnath

5 Sept 2026 8:00 PM IST

  • From Data Privacy To Mental Privacy: What UNESCOs Neurotechnology Recommendation Means For India
    Listen to this Article

    On 11 November 2025, The 43rd session of UNESCO's General Conference, which took place at Samarkand, adopted the Recommendation on the Ethics of Neurotechnology for the first time at the global level, thereby recognising neural data and data capable of enabling inferences about mental states and which requires heightened protection. Two days later, India's Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025, finally giving operative shape, after nearly two years, to the Digital Personal Data Protection Act, 2023.

    The coincidence invites comparison, but the comparison needs two qualifications. First, UNESCO's Recommendation is not a binding treaty: it asks Member States only to give effect to its principles “in conformity with the constitutional practice and governing structures of each State”–a benchmark, not an enforceable obligation. Second, India's Rules are themselves only partly in force. The provisions constituting the Data Protection Board took effect immediately on notification, but the Rules that would actually govern neural data in practice- consent notices, security safeguards, and cross-border transfer conditions among them -do not commence for another eighteen months, placing their effective date around mid-2027.

    For the first time, an international organisation told the states in explicit terms that neural data-and data from which mental state can be inferred should be treated as sensitive personal data. However, India's principal data-protection statute recognises no such category, and will not acquire one when its substantive provisions eventually switch on.

    Not all data about the body is data about the mind. Ordinary personal data tells us something about a person; neural data tells us about the signals gathered by EEG headsets, brain-computer interfaces, or sensors now built into consumer earbuds which can permit inferences about what a person is thinking, feeling, or about to decide. The distinction matters because it separates three acts, however, a single statute might otherwise treat identically: collecting a signal, decoding it, and inferring from it. The issue is not an abstract one. Mining and logistics firms already deploy EEG-based fatigue-monitoring headsets on drivers and operators, and UNESCO's own Recommendation names attention-tracking for air traffic controllers as a live example of workplace use. In china primary school drew international attention in 2019 for putting brainwave-tracking headbands on its students. EEG sensors are now used in commercially available headphones. What concerns these contexts is not who owns the data, but who has authority to access, infer, or act on what the nervous system reveals?

    The Digital Personal Data Protection Act, 2023 adopts a single category of 'personal data' and regulates its processing principally through consent and specified legitimate uses; it does not create a separate statutory category for neural or specially sensitive personal data. The DPDP bill creates one homogenous grouping for health/biometric data, without data protection rules with separate 'sensitive' or 'special' categories of data for health or biometrics. As it applies same baseline architecture of consent to buying stuff, so to raw neural activity.

    But this is not a proof of negligence, the Act was drafted before consumer neurotechnology reached the mass market it occupies today. The problem is that informed consent, the Act's central safeguard, is now being asked to address something it was not designed for. A user may be able to meaningfully consent to a platform collecting a keystroke. It is much harder to say that the same consent covers a device inferring her attention, mood, or susceptibility to a particular advertisement-especially where those inferences were neither technically possible nor contemplated when the consent was given.

    The Act therefore needs to distinguish between collecting a neural signal and using that signal to infer a person's mental state. UNESCO's Recommendation also makes the same point, calling for data-minimisation and purpose-limitation safeguards specific to inferences drawn from neural and neural-adjacent data. India's statute has no equivalent provision to update.

    Assume, for a moment, that the consent problem above is solved and a neurotechnology company holds neural data lawfully. Another question comes up, which ordinary data-security law is not built to answer: does lawful possession entitle the company to infer anything it is technically capable of inferring? Neurotechnology creates a risk that conventional data-security rules do not fully capture: the danger may arise not from unauthorised access, but from authorised use

    The answer is definitely no, and the reason requires distinguishing two ideas that has been equated under the single word “security.” Cybersecurity protects data from unauthorised access-encryption, access controls, breach response. Cognitive security is a different concern. It protects individuals from the misuse of information about their mental or cognitive state, even when that information was obtained lawfully. Therefore, the concern is not unauthorised access, but what an organisation does with the information once it has legitimate access to it.

    Take a consumer in India using EEG-enabled earbuds. The device collects a raw neural signal, which may then pass through a cloud system and a third-party AI system before being turned into a cognitive profile of that individual and shared with an advertiser or employer. At each stage, the company may be able to show that the transfer was authorised. That does not answer the harder question of responsibility when the problem is not a data breach but an inference made from data that was lawfully obtained. Indian law does not currently provide a clear framework for assigning responsibility in that situation.

    The problem becomes more difficult when the companies involved are based outside India. The earbuds may be sold by a company with no Indian office, the cloud infrastructure may be located abroad, and the AI system generating the cognitive profile may be operated from a third country. Rule 15 of the DPDP Rules permits a Data Fiduciary to transfer personal data outside India, subject to conditions specified by the Central Government. But Rule 15 is not yet in force, and even when it takes effect, it does not specifically address the risks arising from neural-data inference.

    This raises a practical question for Indian users: who is responsible when the company, the servers, and the system making the inference are all outside India's jurisdiction? The answer should not depend on where the server is located. High-risk neurotechnology providers offering products to Indian consumers should therefore be required to maintain an accessible grievance mechanism in India. They should also disclose, in terms that consumers can understand and act on, where inferences about them are generated and which entities are responsible for making them.

    India need not necessarily wait for Parliament before its courts can address these questions. Justice K.S. Puttaswamy (Retd.) v Union of India (2017) already recognised privacy, dignity, and autonomy within Article 21, including a person's decisional and informational autonomy. Selvi v State of Karnataka (2010) went further, holding that involuntary narco-analysis and similar techniques intrude on a form of privacy specific to the mind -protection against the forcible extraction of testimony from within a person's own consciousness.

    Neither judgments recognises “cognitive liberty” as a standalone right, and this piece does not claim otherwise. What they offer is a foundation: constitutional building blocks from which a right to mental privacy can be developed as neurotechnology cases reach the courts, without waiting for a textual amendment that may never come. Whether Selvi's logic extends to non-invasive neural decoding in criminal investigation is a large enough question to deserve its own treatment - a question for a separate piece.

    The gap can be addressed through four changes to the existing framework. First, the DPDP framework should expressly recognise neural data and mental-state inferences as requiring heightened safeguards, in line with the direction set by UNESCO's Recommendation. Second, the law should distinguish between consent to collect a neural signal and consent to derive further information from it. Third, Rule 15 should address cross-border accountability before it comes into force in 2027, including by requiring foreign neurotechnology providers serving Indian consumers to maintain an Indian grievance mechanism and provide information about how and where inferences are generated. Fourth, courts can develop the constitutional principles in Puttaswamy and Selvi as cases involving neurotechnology come before them. Neural data can reveal information closely connected to a person's mental life, bringing questions of mental privacy and informational autonomy within the broader protections of Article 21. These developments need not wait for one another; statutory reform and constitutional development can proceed together.

    Now looking back where we started, UNESCO has told the world that neural data deserves to be treated as sensitive personal data. India's data-protection framework does not yet make a similar distinction, and its substantive Rules are not expected to apply until mid-2027. That leaves a significant gap between the protections being discussed internationally and those available under India's current framework. The challenge is not limited to preventing unauthorised access. For neurotechnology, the law must also address what happens when data is lawfully collected but is then used to draw sensitive conclusions about a person's mental or cognitive state. India still has time to address that gap before the existing framework begins to operate in full.

    Views are personal.

    Next Story