Neuro-Privacy And Indian Constitution: Should Brain Data Be Treated As Sensitive Personal Data?

Namit Srivastava

30 Aug 2026 10:00 AM IST

  • Neuro-Privacy And Indian Constitution: Should Brain Data Be Treated As Sensitive Personal Data?
    Listen to this Article

    A commercially available headband can now record electroencephalographic (EEG) signals well enough to infer attention levels, emotional valence, and early markers of neurological conditions. Meditation applications sell such headbands in India today; neurotechnology firms are testing implantable and wearable brain-computer interfaces (BCIs) for both therapeutic and consumer use. What none of these products currently face, in India, is a data protection regime that treats the signal coming out of a human skull any differently from a shopping cart history. That gap deserves scrutiny.

    What makes neural data different

    Brain data is not merely another biometric. A fingerprint or a facial scan identifies a person; neural signals can, with the right decoding model, reveal what a person is thinking, feeling, or about to do, often before the person is consciously aware of the inclination themselves. Researchers have demonstrated that EEG patterns can betray PIN numbers, political leanings, and susceptibility to specific emotional triggers. Because the brain is the source of cognition rather than merely a record of it, neural data implicates not just privacy but something closer to what scholars call cognitive liberty: the freedom to control one's own mental processes without external inference or interference. Chile amended its Constitution in 2021 to recognise this distinction explicitly, adding neurorights protections against the misuse of brain data. UNESCO has since moved toward a recommendation on the ethics of neurotechnology. India has done neither.

    The constitutional foundation already exists

    This is not entirely uncharted territory for Indian constitutional law. In K.S. Puttaswamy v. Union of India, the Supreme Court located informational privacy within Article 21, holding that the right extends to control over personal information and, significantly, to decisional and mental autonomy. The judgment's language on bodily and decisional privacy sits comfortably with the idea that unauthorised access to a person's neural signals would be a graver constitutional injury than access to routine transactional data, because it reaches the seat of thought itself. The proportionality test laid down in Puttaswamy, and refined in later privacy litigation, requires that any state intrusion be backed by law, pursue a legitimate aim, and be proportionate and necessary. A regime permitting the collection or compelled disclosure of brain data without a heightened threshold would struggle to survive that test, particularly given how much more revealing such data is compared to the categories the Court had before it in 2017.

    The DPDPA's puzzling silence

    The difficulty is statutory rather than constitutional. The Digital Personal Data Protection Act, 2023 (DPDPA) departs from the approach of its own drafting history. Earlier iterations, including the 2018 and 2019 Bills that preceded it, carried a distinct category of “sensitive personal data” health data, biometric data, genetic data, sexual orientation, and the like attracting stricter consent and processing obligations, broadly mirroring the European Union's General Data Protection Regulation (GDPR) and its special categories under Article 9. The enacted DPDPA abandoned this tiered structure altogether. It defines “personal data” in Section 2(t) as any data about an individual identifiable by or in relation to such data, and applies a single, largely uniform consent-and-notice framework to all of it, with a modestly heightened regime reserved only for children's data and data of persons with disabilities under guardianship.

    This means that, as matters stand, neural data collected by a wellness app or a neuromarketing firm in India is regulated exactly as a phone number or a delivery address would be: through the same consent notice, the same purpose-limitation clause, and the same grievance-redressal mechanism, none of which is calibrated to the far greater sensitivity of the underlying information. The Information Technology (Reasonable Security Practices and Sensitive Personal Data or Information) Rules, 2011 which did carve out a “sensitive personal data or information” (SPDI) category covering health, biometric, and financial data technically continues to operate for entities outside the DPDPA's eventual full commencement, but even the SPDI Rules were drafted years before consumer neurotechnology existed and do not mention neural or brain-derived data at all.

    Why the gap matters in practice

    The practical stakes are not speculative. Neurotechnology is entering Indian workplaces through fatigue-monitoring headsets for drivers and factory workers, into classrooms through attention-tracking tools marketed to schools, and into consumer wellness through meditation and sleep-tracking devices that log raw or processed EEG output on foreign servers. None of these deployments currently require the explicit, purpose-specific, revocable consent that health data ordinarily attracts in more mature regimes, because the DPDPA does not distinguish neural data from any other category. An employer could, in principle, justify continuous cognitive-state monitoring of employees under a “legitimate use” exemption in Section 7 with far less friction than would be required to process, say, an employee's medical records under a health-data-specific standard. The Data Protection Board of India, tasked with adjudicating breaches and enforcing the Act, is itself not yet functional, compounding the enforcement vacuum with a definitional one.

    Cross-border transfer and children add urgency

    Two further features of the current landscape sharpen the concern. First, most consumer neurotechnology devices sold in India stream raw or lightly processed EEG output to servers outside the country for model training, and the DPDPA's cross-border transfer provisions under Section 16 leave this largely to government-notified restrictions rather than a data-type-specific bar meaning neural data can leave Indian jurisdiction as freely as a search query unless the Central Government specifically blacklists a destination. Second, attention-monitoring products are being piloted in Indian schools, squarely implicating the DPDPA's own heightened protection for children's data under Section 9. Yet that protection is triggered by the age of the data principal, not by the sensitivity of what is being measured so a school could, in theory, satisfy its Section 9 obligations through parental consent alone while still permitting granular, continuous cognitive profiling of a child, a combination the Act's drafters plainly did not contemplate when they wrote it.

    The case for a sensitive category, calibrated correctly

    None of this argues for reproducing the GDPR's model wholesale; that approach carries its own well-documented problems of rigidity and litigation over categorisation. It does argue for a narrower, functional test: data protection frameworks in India should treat any data derived from direct neural measurement EEG, functional near-infrared spectroscopy, or implanted electrode signals as sensitive by default, given its capacity to reveal involuntary mental states rather than voluntary disclosures. This would trigger explicit consent requirements, purpose limitation tightly drawn to the stated therapeutic or research use, a prohibition on inferring unrelated traits (emotional state, political inclination, health conditions) from data collected for another purpose, and mandatory data protection impact assessments for any commercial neurotechnology deployment. The Ministry of Electronics and Information Technology retains rule-making power under Section 40 of the DPDPA broad enough to introduce such a category through delegated legislation, without reopening the Act itself.

    Way forward

    The constitutional scaffolding for treating brain data as uniquely deserving of protection is already in place; Puttaswamy's recognition of mental and decisional autonomy as facets of Article 21 supplies the doctrinal basis. What is missing is statutory follow-through. As neurotechnology moves from laboratory to living room, the absence of a sensitive-data category for neural signals in the DPDPA is not a minor oversight but a structural mismatch between the constitutional value at stake and the ordinary-law protection on offer. India does not need to wait for a Puttaswamy style flagship judgment on neuro-privacy before acting; the rule-making power already exists, and the cost of using it now is far lower than the cost of retrofitting protection after neural data breaches becomes common enough to force the issue.

    Author is an Assistant Professor at CHRIST (Deemed to be University), Delhi NCR Campus. Views are personal.

    Next Story