For years, chief ministers across several states have proudly claimed that they have blanketed their cities with CCTV cameras. The number of cameras installed has increasingly become a measure of administrative achievement, and political parties have even promised expanded CCTV coverage as part of their election manifestos. Yet, remarkably, very few questions have been asked about the implications of such widespread surveillance for the privacy of individuals in public spaces.
In marked contrast the mayor of Seattle in the United States refused to have CCTV switched on during the FIFA World Cup games and agreed only after major pressure was exerted. And she switched them off the day after the Games schedule ended in the city. Why? Because she said it violated the privacy of the city residents. And the city backed her!
But here in India the issue has rarely been privacy and over the years city roads, malls, and every outlet has been swamped with CCTV cameras. Because it was supposed to enhance security. And until recently nobody raised the issue. CCTV cameras for the country’s residents was a way of life.
A major test case is currently unfolding, arising from the July 2026 student protests at Jantar Mantar in Delhi over NEET exam paper leaks. During the agitation, police used a mobile command-and-control vehicle with cameras and facial recognition, and also collected protesters’ Instagram handles. Suddenly the privacy and rights issue started coming up. The agitation may have ended but the subsequent police action as indeed the facial recognition carried out to monitor the protest, has brought the issue of right to freedom up for discussion. People believe that the police had invaded the privacy of protestors and violated their right to freedom by surveilling them.
The Internet Freedom Foundation demanded deletion of the biometric data collected.
Student activist Aishe Ghosh petitioned the Delhi High Court, seeking a declaration that the mass surveillance was unconstitutional, destruction of collected personal data, and court-ordered guidelines governing use of surveillance technology, notably continuing the case even after the protests ended and the minister resigned.
Separately, a CPM MP has moved the Supreme Court, alleging Delhi Police deployed facial recognition, AI smart glasses, fingerprint tools and other biometric surveillance without statutory authority, violating Articles 14, 19 and 21 (equality, free speech/assembly, and privacy/liberty). The petition seeks a halt on FRT use at peaceful protests until a statutory framework exists, disclosure of the technologies and vendors used, deletion of biometric data of non-accused persons, and a grievance redressal mechanism.
The law effectively has started being applied about how much surveillance and where, is too much. Gradual examples were seen as over the last few months there have been instances where people have sought legal advice after a neighbour’s home security camera points at their home and in most cases the courts have stopped it.
What do an individual’s rights say on being surveilled by the government randomly?
A citizen’s rights against CCTV surveillance in India are grounded in the fundamental right to privacy under Article 21 of the Constitution, protections under the Information Technology Act, and rules from the Digital Personal Data Protection (DPDP) Act. These laws mean you have the right to be free from unwarranted monitoring in private spaces, the right to notice before being recorded, and legal recourse against the misuse of your video data.
India’s Digital Personal Data Protection Act, 2023 (DPDP Act) governs how “Data Fiduciaries” (organizations) process the “digital personal data” of “Data Principals” (individuals). Its core mechanics:
● Consent-based processing: private organisations must obtain free, informed, and unambiguous consent before processing personal data, covering things from purchase history to location data.
● Data Principal rights: the right to access a summary of personal data being processed, the right to correct or erase data by withdrawing consent, and the right to grievance redressal through the fiduciary or the Data Protection Board of India.
● CCTV/audio-visual identification is explicitly treated as personal data: audio-visual identification of individuals such as CCTV footage, webcam images, photos and videos, along with biometrics like fingerprints, iris scans, and face recognition, fall within its scope.
This applies to CCTV monitoring also since the act specifies the following:
● Commercial/institutional CCTV is covered: commercial CCTV that captures identifiable individuals falls under the Act, while purely domestic or personal use is exempt.
● AI-enabled CCTV: the government has confirmed AI-enabled CCTV cameras will be covered by the DPDP Rules, as part of a framework meant to address risks from expanded data collection including AI-enabled surveillance systems, alongside the DPDP Rules 2025 and the India AI Governance Guidelines, with the Data Protection Board overseeing compliance and enforcing penalties up to ₹250 crore.
● Underlying constitutional basis: the Supreme Court’s 2017 Puttaswamy judgment established the Right to Privacy as a Fundamental Right under Article 21, meaning any surveillance including CCTV must be justified by a legitimate purpose. The IT Act also plays a role — Section 66E penalizes unauthorized capturing/sharing of images, and Section 72A prevents disclosure of personal information without consent. Workplace/residential nuance: employee monitoring is legal for legitimate security purposes but “constant or intrusive monitoring” raises privacy concerns, and hidden/covert cameras without consent can run afoul of other criminal law provisions.
This is where most of the substantive criticism concentrates, as the Act is seen as strong on private-sector consent obligations but weak on constraining the state. In other words the government can modify it or tweak it if it wants while individuals will have to abide by it in letter and spirit.
● Section 17 exemptions: Section 17 allows the Central Government to exempt its own agencies from the law’s provisions on grounds like national security, sovereignty, and public order. Groups like the Internet Freedom Foundation and Editors Guild of India argue these exemptions are overly broad, unlike the GDPR’s strict proportionality tests for state exemptions, the DPDP Act lacks comparable legislative safeguards, raising concern about unmonitored state surveillance and impacts on press freedom.
● Scope of the exemption: critics note the law doesn’t just waive certain provisions for government agencies — Section 17(2) exempts them from the whole Act for those purposes, and Section 17(1)(c) already waives notice-and-consent requirements for processing tied to “prevention, detection, investigation or prosecution of any offence,” making 17(2) seen by some as redundant except to signal intent to fully exclude the state from oversight.
● No independent review mechanism: the surveillance regime remains concentrated in the executive, lacking specific articulation of circumstances/procedures for surveillance and any meaningful safeguard such as independent review of surveillance directions. Broad exemption language (“interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order or preventing incitement to any cognisable offence”) is criticized as vague and not meeting the proportionality standard set in Puttaswamy.
There is a counter-view to the argument that insists that the exemption isn’t a blank check. Section 17 creates a layered system of complete, partial, and conditional exemptions (10 distinct categories) rather than a single on/off switch, several of which only take effect once the Central Government issues a specific notification, and businesses/agencies claiming an exemption incorrectly still face liability before the Data Protection Board.
India has no law governing police use of facial recognition technology. This is the crux of nearly every criticism. FRT deployment by police rests not on specific statutory authorization but on general policing powers, the IT Act, and now the DPDP Act’s broad state exemptions discussed earlier, none of which were written with biometric surveillance of assemblies in
mind.
Facial recognition differs fundamentally from ordinary CCTV, it converts facial features into biometric templates that can be matched against databases, meaning participation in protests, rallies, or movements could be digitally catalogued and retained indefinitely, not just recorded.
A tech law expert argued accountability must run both ways, if FRT is used to track protesters, it should equally be used to identify police officers who acted without name badges, and that proportionality is required even where national security is invoked.
Even normally the issue of national security is used randomly by most governments when they do not want to explain their actions. It happens regularly in countries like the United States where national security reasons are given where the FBI seeks to overrule state laws.
The issue was discussed in the US as back as in 2007 in the Department of Homeland Security workshop to anticipate and work around the privacy and surveillance balance, probably anticipating that the technology would eventually reach a stage where rights and privacy may be violated. The rise of CCTV cameras was still in its infancy then.
In December of 2007, the Department of Homeland Security (DHS) Privacy Office convened a two-day public workshop to examine best practices for government use of video surveillance camera technology. The Workshop examined how technology, local and international communities, law enforcement, government agencies, and privacy advocates are shaping the use of CCTV and what safeguards should be in place as the use of CCTV expands.
The Workshop brought together leading academics, international government officials, researchers, law enforcement representatives, technologists, community leaders, and policy experts. These panelists identified a range of challenges facing local governments, communities, and law enforcement regarding privacy and use of CCTV.
The key topics discussed at the Workshop included:
• CCTV technology and its impact on privacy;
• International perspectives on the use of CCTV;
• Law enforcement use of CCTV;
• Community perspectives on use of CCTV;
• Legal and policy considerations regarding the use of CCTV;
• Best practices for the implementation and use of CCTV.
The policies put in place nearly 20 years ago are possibly why the issue of privacy to government surveillance is widely recognised in the country and the law is cautious about random surveillance of citizens since the law forbids it without a reason. India on the other hand has been oblivious to the other facet of CCTV cameras, surveillance and its effects.
Or rather, the people are oblivious since in every city around the country cameras stare down on people in every market, hospital, road and street. And no one believes it is something to object to or raise a question on. In fact a couple of years back the contest was between different states claiming to have the highest number of CCTV cameras. During elections it is almost always a major part of every party’s manifesto. One does not remember a single manifesto that promised to limit the use of CCTV to protect citizen privacy.
The use of facial recognition technology has expanded rapidly across policing, transport and public surveillance in India, despite the absence of a dedicated law regulating its use.
One of the largest proposed initiatives is the National Crime Records Bureau’s Automated Facial Recognition System, which aims to enable law enforcement agencies to match facial images against multiple databases, including CCTV footage, passport records, prison records and missing persons’ databases.
The technology has also been adopted at airports through the Ministry of Civil Aviation’s DigiYatra programme. First introduced at Hyderabad airport in 2018, it uses facial recognition to verify passengers at various checkpoints, reducing the need for repeated checking of boarding pass and identity verification.
Facial recognition is also being deployed under Safe City projects and the Smart Cities Mission. Several cities have integrated facial analytics with CCTV networks for crowd management, traffic monitoring and identifying repeat offenders. No questions were raised when all this was announced.
Several European countries have imposed strict limits on the use of facial recognition technology, citing concerns over privacy, civil liberties, discrimination and mass surveillance. The European Union (EU) has also introduced legal safeguards governing the use of biometric technologies.
European laws treat facial data as sensitive personal information. Policymakers argue that unrestricted facial recognition in public spaces could allow continuous monitoring of individuals, raising concerns about privacy and fundamental rights.
Concerns have also been raised over the accuracy of facial recognition systems. Studies have found that some systems are more likely to misidentify women and people from certain ethnic groups, increasing the risk of discrimination and wrongful identification.
In April 2019, a New York Times investigation revealed that Chinese authorities were using AI-enabled CCTV facial recognition systems to identify and track Uyghurs, the predominantly Muslim ethnic minority concentrated in Xinjiang. Leaked documents showed that surveillance camera networks were designed to distinguish Uyghur faces from non-Uyghur faces and generate “Uyghur alarms” when individuals were detected. The technology was reportedly integrated into police surveillance systems and used for ethnic profiling and population monitoring, raising global concerns about mass surveillance, discrimination, and human rights abuses.
Under the European Union’s Artificial Intelligence Act, the use of real-time facial recognition by law enforcement in public places is largely prohibited, except in limited circumstances such as locating missing persons, preventing an imminent terrorist threat or investigating certain serious crimes. Even then, its use requires judicial authorisation and other legal safeguards.
The EU also prohibits the creation of facial recognition databases through the indiscriminate collection of images from the internet or CCTV footage. In addition, the General Data Protection Regulation (GDPR) classifies biometric data as sensitive personal data and imposes strict conditions on its collection and processing.
Facial recognition technology has prompted concerns over privacy, surveillance, accuracy and accountability, particularly as artificial intelligence has made it possible to analyse large volumes of biometric data in real time.
Privacy advocates argue that people are often scanned without their knowledge or consent, while there is limited transparency about how facial data is collected, stored, shared or retained. Unlike passwords, facial data cannot be changed if compromised, making data breaches a long-term risk.
The intrusion of CCTV cameras have also been objected to by the educators. The Indian National Teachers’ Congress (INTEC) recently wrote to the chairperson of Jesus and Mary College, University of Delhi, seeking intervention over the installation of CCTV cameras inside classrooms. The teachers’ body said the move raises concerns related to academic freedom and classroom autonomy.
In its letter to the college administration, INTEC said that classrooms are spaces meant to encourage critical thinking, open discussion and a free exchange of ideas, and that continuous surveillance could alter this academic environment. The association stated that the presence of cameras inside classrooms may affect the trust-based interaction between teachers and students.
The teachers’ body said that constant recording of lectures and classroom discussions could lead to anxiety and self-censorship among faculty members and students. It added that such conditions may impact the overall teaching-learning process and the ability of educators to engage freely in academic discourse.
While acknowledging the importance of campus safety, INTEC stated that these should not interfere with the core academic functions of higher education institutions. It cautioned that installing surveillance systems inside classrooms could set a dangerous precedent for the autonomy of teachers.
The realisation that too much surveillance can be an invasion of an individual’s privacy is now slowly dawning and without doubt it has now become a new issue for debate. But has it really reached the common resident? That too is doubtful. We have a short memory span and once the furore over what happened in Jantar Mantar during the protest fades away, chances are so will the demand for privacy. However what is likely to affect a change is individual professions demanding some relaxation on surveillance. Or at least being given a caution as to where and when they will be monitored.
The man on the road is still and in all probability always will be, unaware of what the camera staring down at him means. If our faces are run through facial recognition at a mall via a camera, we will not be bothered. Awareness is the issue as is the fact that a common Indian citizen is unaware of what violates his right to freedom.
Technology to enhance protection is not objected to anywhere. The UK is covered with CCTV cameras and is possibly the most surveilled country in the world. India is getting close to it because the state says it is for our security. And the feeling of being safe is what every citizen wants. So chances are that the current furore over privacy will stay in individual professions and possibly some changes will emerge but for the general public on the road, the eye above will continue to monitor every move.






