Two courts are asking the same question the Indian state has not answered yet: what happens
to a citizen’s face once it has been recorded at a protest? The Delhi High Court will hear a
matter regarding this question on August 25. The Supreme Court on August 13 tagged a
petition filed by Rajya Sabha MP A.A. Rahim, and directed that the collected biometric data
be preserved and kept out of the public domain.
However, both courts have not yet answered the real question: not whether the data was
collected, but whether the state has any responsibility to delete it.
A month has passed since the Education Minister Dharmendra Pradhan resigned and the
protesters went home. But the data recorded at Jantar Mantar has no legal deadline for
deletion. July 20 was when AI surveillance was most heavily deployed: AI-powered cameras
and facial recognition vans through which the Delhi Police systematically recorded faces,
clothing, and movements.
The protest achieved its aim but nothing in Indian law requires that this data now be deleted.
Legal Vacuum
India has no dedicated framework governing facial recognition technology and AI
surveillance. The Digital Personal Data Protection Act, 2023, provides wide-ranging
exemptions to government agencies. According to Section 17(1)(c), if the data is processed
for the “prevention,” “detection,” “investigation,” or “prosecution” of any offence, then
Chapter II won’t apply. Interestingly, Chapter II contains Section 8, which governs deletion
of data. Section 17(2)(a) provides the Central Government with another exemption – it may,
by notification, disapply this Act to any state agency on the basis of “sovereignty and
integrity of India,” “security of the State,” or “maintenance of public order.” The Delhi Police
order of June 9, 2022, authorised FRT to identify “suspected individuals or known
criminals.” This language perfectly fits in Section 17(1)(c), without requiring any
notification.
The question remains if the aim is fulfilled, will the data be deleted? Section 8(7) provides
that once the purpose for which data was collected no longer exists, it becomes the duty of
the Data Fiduciary (the entity that determines why and how data is collected) to delete the
data. But Section 17(1) extinguishes that duty if it is for crime prevention, and Section
17(2)(a) provides an even bigger route. Either way, the law is completely silent on how long
protest-surveillance footage can be kept.
The problem deepens when data is moved outside. On August 13, Senior Advocate Menaka
Guruswamy told the Supreme Court that the facial-mapping system and surveillance van
collected biometric data without consent and this data is now hosted by two private
companies. This can be done only if there exists a valid contract between a Data Fiduciary
and a Data Processor as provided by the DPDP Act. Whether this contract exists is not
disclosed yet.
The Criminal Procedure Identification Act, 2022, provides a 75-year retention period for
biometric data, with no automatic deletion mechanism. An individual must apply for erasure
themselves. The DPDP Rules have a one-year retention period, but this doesn’t apply
uniformly. For protest-related surveillance, there are no fixed guidelines.
The petition filed by Jawaharlal Nehru University’s former Student Union President Aishe
Ghosh calls the surveillance “arbitrary and opaque” since it has no independent oversight.
The Delhi Police has admitted that no privacy impact assessment was done before procuring
FRT, and no legal opinion was sought. It also refused to reveal the information regarding
databases linked to the system. A police force that sought no legal opinion before deploying
the system is unlikely to seek one for deletion.
Constitutional Argument
The protest is over, with demands met. No criminal action was taken against the majority of
protesters. What aim does indefinite retention of data now serve? When the protest is over,
how is retaining the facial data of protesters proportionate? Is there no less restrictive means,
such as deleting the data of the protesters?
The Delhi Police claims that surveillance helped identify 2,873 individuals with prior cases
involving murder, rape, and child abuse who visited the protest site. This may justify
screening a crowd for known offenders in real time but retaining data of everyone else
permanently is not justified.
In the KS Puttaswamy judgment, the Supreme Court held that the right to privacy is a
fundamental right under Article 21 of the Constitution and any state intrusion on it must
satisfy the principles of legality, proportionality, and necessity. The PIL filed by Ghosh says
the surveillance fails the triple test. The surveillance created a profound chilling effect. The
students covered their faces in the protest. Many feared that the footage could reach their
college or government jobs. The police threatened to send the photos to parents and
institutions.
This is not just a domestic constitutional issue. India is a signatory to the International
Covenant on Civil and Political Rights. Article 17 provides that there cannot be arbitrary
interference with anyone’s privacy. The UN Special Rapporteur specifically called for
deletion of biometric surveillance data as soon as the purpose is fulfilled. India’s failure to
implement any of these mechanisms places it in direct tension with these obligations.
Moreover, Article 19(1) provides the right to peaceful assembly. A restriction on assembly
must also pass tests of legality, necessity, proportionality, and procedural safeguard.
Indefinitely retaining biometric data from a concluded protest, without criminal proceedings,
fails, at minimum, the necessity and proportionality prongs; there is no necessity when the
protest has ended, and blanket retention is disproportionate to the aim of maintaining public
order.
There is also a preventive-detention dimension that makes it more than an abstract privacy
concern. Section 170 of the Bharatiya Nagarik Suraksha Sanhita, 2023, allows police to arrest
a person without warrant if it appears that the person “designs to commit a cognisable
offence.” The data collected today can be used in the future to arrest a student based on an
algorithm’s prediction. Article 5(1)(d) of the EU AI Act bans such profiling. India is building
technology that the EU has described as very dangerous.
Precedent: When Data Is Never Deleted
The starkest illustration is not Jantar Mantar; it is Chand Bagh. Two men, Ali and
Mohammad, were arrested in 2020 Delhi riot cases on the basis of FRT matching, with no
test identification parade conducted. They spent, respectively, four and a half years and two
years in pre-trial incarceration.
The Delhi Police has acknowledged using FRT in 750 out of 758 Delhi riots cases. The
Home Minister, Amit Shah, told the Rajya Sabha that 1,922 people were identified through
FRT. An 80% similarity score was accepted as positive by the Delhi Police, yet four in five
cases ended in acquittal or discharge. In 2018, the Delhi Police’s FRT accuracy was 2%,
which was decreased to 1% in 2019.
The 2020 protest data was never deleted; years later, people were arrested based on that data.
In 2026, the same infrastructure was used at Jantar Mantar. The question is not whether it will
be misused; the question is whether anyone will stop it.
The risk is not equally borne by everyone. According to a 2021 study by the Vidhi Centre for
Legal Policy, FRT will inevitably affect Muslims disproportionately, especially in over-
policed areas like Old Delhi and Nizamuddin. Research by Jai Vipra of Cornell University
finds that Muslim-majority areas have higher CCTV concentration. Dalits, Adivasis, and poor
communities are overrepresented in police databases.
The Delhi High Court in Jorawar Singh Mundy v. Union of India recognised a right to be
forgotten, a principle that says if the legitimate purpose is fulfilled then the information
should be removed from the public domain. If this principle can be applied to court records,
then it should be applied to biometric surveillance data collected from peaceful protesters
once the protest has concluded and no criminal proceedings are initiated. The answers are
clear: no legitimate aim remains, retention is disproportionate, and less restrictive means
exist. The Constitution demands deletion, but the law is silent. That gap is the problem.
Restricted in Europe, Screening in India
India has more than 4,000 cameras powered by Spanish company Herta Security. Article 5 of
the EU AI Act tightly restricts, with narrow exceptions, real-time FRT in public spaces for
law enforcement. The EU provided €3.3 million in research funding to Herta to develop this
technology. Italian MEP Brando Benifei has criticised the EU for making a profit abroad
from tools that it has deemed too dangerous for European citizens. Apar Gupta of the Internet
Freedom Foundation says that India is one of the leading adopters of FRT without any
safeguards. The same technology deemed too dangerous for European citizens is deployed
against Indian ones, and the data it collects is stored forever.
What George Orwell imagined in 1984 as authoritarian terror, India is building as
administrative infrastructure. The difference is that Big Brother was openly totalitarian.
India’s surveillance is disguised as law and order, women’s safety, and public security.
This is an infrastructure with no law to govern it, no oversight to review it, and no
mechanism to make it forget. Whatever the Delhi High Court and the Supreme Court order in
the coming weeks, it cannot replace a statutory deletion requirement Parliament has never
enacted. The government that heard the students must now answer: the protest has ended;
will it delete their faces now?


