Facial Recognition Technology and the Right to Privacy: A Legal Analysis in India

Author: Rupam Shivani
College: Indore Institute of Law

LinkedIn Profile: https://www.linkedin.com/in/rupam-shivani-33079825b?utm_source=share_via&utm_content=profile&utm_medium=member_ios


Abstract:

One of the most important advancements in contemporary surveillance and identification systems is facial recognition technology. Law enforcement, security, banking, transportation, and public administration have all benefited greatly from its capacity to identify people by their face features. However, because face information is strongly linked to an individual’s identity and can be obtained without meaningful participation or awareness, the technology raises serious constitutional issues.

The constitutional debate surrounding new surveillance technologies changed when Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) acknowledged privacy as a fundamental right. Privacy is linked to autonomy, dignity, and control over personal data; it is not just the right to confidentiality. Therefore, the constitutional requirements of legality, legitimate State purpose, need, and proportionality must be met when State authorities use FRT.

Practical issues such erroneous identification, face data retention, unauthorised access, lack of transparency, function creep, and insufficient accountability must also be addressed by Indian law. Although a more comprehensive framework for protecting digital personal data is provided by the Digital Personal Data Protection Act, 2023, the increasing use of biometric surveillance highlights the necessity for precise operational safeguards pertaining to facial recognition.

This essay evaluates the connection between FRT and the constitutional right to privacy, looks at important Indian court rulings, and talks about the precautions that must be taken to make sure that advancements in technology do not compromise basic rights.

To the Point:

Face Recognition Technology (FRT) is an artificial intelligence-based technology that uses face feature analysis from photos, CCTV footage, mobile devices, and other digital systems to identify or validate a person. Law enforcement, banking, airport security, attendance systems, identification, and public monitoring are all using it more and more. The extensive use of FRT raises severe issues about the basic right to privacy guarantyd by Article 21 of the Indian Constitution, even while it can enhance security and aid in investigations.

In Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), the Supreme Court identified privacy as a basic right and ruled that any State action that impacts private must adhere to constitutional criteria. Because a person’s face serves as a permanent biometric identity, facial recognition raises special difficulties. A compromised face is more difficult to alter than a password.

Therefore, the legal difficulty is striking a balance between legitimate state objectives like public safety, crime prevention, and national security and individual privacy, personal liberty, and data protection. This balancing is made more challenging by India’s lack of a comprehensive, FRT-specific legislative framework. This article looks at the necessity for safeguards against misuse, pertinent legal ideas, significant court rulings, and the constitutional implications of face recognition.

Use of Legal Jargon:

The following legal ideas are pertinent to the control and application of facial recognition technology:

Right to Privacy: Article 21 and other constitutional freedoms recognise privacy as a basic right. Bodily privacy, informational privacy, liberty in making decisions, and defence against unjustified state interference are all included.

Biometric Data: Since facial photos and templates can be used to uniquely identify a person, they may be considered biometric or sensitive personal information.

An individual’s control over information about their identity, personal life, and actions is safeguarded by informational privacy. When facial data is gathered or handled without sufficient safeguards, FRT may violate this right.

Surveillance: The term “surveillance” describes the methodical observation of people. Because people can be identified without intentionally revealing their identify, facial recognition technology has the potential to increase the scope of monitoring.

Consent: A key component of data protection is consent. Legal and equitable concerns are raised by the gathering and use of facial data without meaningful consent.

Proportionality: A privacy constraint must be appropriate, necessary, and proportionate to its justifiable goal.

Data minimisation: Information should only be gathered and kept if it is required for a particular legal reason. Large-scale facial databases increase the possibility of security lapses and abuse.

Limitation on Purpose: Information about a person’s face that is gathered for a valid reason shouldn’t be automatically utilisedfor unrelated purposes.

The Proof:

Facial recognition technology raises a number of practical and legal issues.

Gathering of Facial Data: To identify people, FRT systems need facial pictures or templates. People may be scanned without actively taking part in the identifying process when cameras are placed in public areas.

Mass Surveillance: Authorities may be able to identify a lot of people in public areas thanks to the technology. In contrast to conventional identifying techniques, facial recognition can function remotely and continuously.

Accuracy and False Matches: False positives or false negatives can be generated by facial recognition algorithms. An innocent individual could be mistakenly recognised as a suspect due to a false match. When technological outcomes impact police investigations or other state actions, this raises grave issues.
Lack of Transparency: People might not be aware of when face recognition technology is being used, what data is being gathered, how long it is kept, or with whom it is shared. It is challenging to effectively use privacy rights when there is a lack of transparency.
Data Security: Biometric data in facial databases can make them attractive targets for attackers. The impacted person cannot easily replace their face in the same way that they can with a password if their facial information is stolen.

Information gathered for one reason may later be used for another, a phenomenon known as function creep. For instance, a system that was first implemented for security might eventually be utilised for more extensive monitoring.

Discrimination & Bias: Depending on how the system is built and trained, facial recognition may or may not be effective. Errors that impact specific groups can raise issues of equity and nondiscrimination.

Impact on Freedom: Freedom of association, mobility, and expression may be impacted by persistent identification. If people think they are being watched, they might steer clear of legitimate protests, gatherings, or other events.

Judicial and Constitutional Scrutiny: Privacy, dignity, liberty, and proportionality must be taken into consideration when determining whether intrusive surveillance is constitutionally permissible. The simple fact that technology serves a public purpose does not inevitably make it legal.

Case Laws:

1. Union of India v. Justice K.S. Puttaswamy (Retd.) (2017)

The right to privacy was unanimously acknowledged by the Supreme Court as a fundamental constitutional right. The ruling linked privacy to individual autonomy, liberty, and dignity.

The choice is especially crucial for facial recognition since biometric identification entails gathering and analysing data that can be used to identify specific people. Therefore, any State use of FRT that significantly interferes with privacy must meet constitutional requirements.

The ruling also made clear how crucial proportionality is when restricting basic rights. The interference must have a proper legal basis and be justified in terms of the constitution; merely having a legitimate governmental purpose is insufficient.

2. Union of India v. K.S. Puttaswamy (Aadhaar) (2018)

The Aadhaar ruling looked at the connection between privacy and biometric identification. The Supreme Court restricted the usage of the Aadhaar architecture while upholding other of its features.

The ruling showed that the gathering and application of biometric data necessitates close constitutional examination. It also reaffirmed the idea that the state must weigh individual privacy against welfare and identification goals.

Since both Aadhaar and FRT employ biometric data for identification, the logic is applicable to facial recognition.

3. Union of India v. People’s Union for Civil Liberties (1997)

The Supreme Court acknowledged in the telephone-tapping case that an individual’s right to privacy may be impacted by surveillance and interception. In order to avoid arbitrary meddling, the Court established procedural protections.

The case’s concepts apply to contemporary surveillance technologies even though it dealt with telephone eavesdropping rather than facial recognition. Instead of using unchecked presidential discretion, government surveillance must adhere to legal and procedural safeguards.

4. Union of India v. Maneka Gandhi (1978)

The Supreme Court concluded that the process impacting personal liberty must be fair, just, and reasonable, broadening the interpretation of Article 21.

Because technology surveillance may have an impact on individual liberty and autonomy, the principle is pertinent to FRT. Therefore, any intrusive use of technology by public authority must adhere to the fairness and reasonableness requirements of the constitution.

5. Union of India v. Anuradha Bhasin (2020)

The Supreme Court stressed that limitations on fundamental freedoms cannot be applied arbitrarily and must meet constitutional requirements.

The ruling upholds the more general rule that state actions pertaining to technology and individual liberties must continue to be subject to proportionality, legality, and judicial review.

 

Constitutional Issues Relating to Facial Recognition

Article 21 and Privacy:

Life and individual freedom are safeguarded by Article 21. Following Puttaswamy, privacy is a crucial element of Article 21. By enabling people to be recognised, followed, or classified based on their physical attributes, facial recognition technology may have an impact on privacy.

Equality and Article 14

Equal protection under the law and equality before the law are guarantyd under Article 14. There may be concerns about equity and arbitrary state action if a FRT system yields outcomes that are disproportionately incorrect for specific groups of people.

Freedom and Article 19

Article 19 liberties may be indirectly impacted by facial recognition. If people are afraid of being recognised and observed, they can be reluctant to take part in legal demonstrations, gatherings, or groups. A thorough constitutional analysis is necessary to address such a chilling impact.

Autonomy and Dignity

Individual autonomy and human dignity are directly related to privacy. A person should have a fair amount of control over how their personal information is gathered and used. This control could be compromised by uncontrolled face surveillance.

Regulation is necessary.

For the employment of facial recognition technology, India needs a transparent and unambiguous framework. A framework like this ought to comprise:

Clear Legal Authority: FRT should only be used by government organisations in accordance with a well-defined legal framework.
Limitation on Purpose: Only specific, legal purposes should be used for the collection and processing of facial data.
Data Minimisation: Only the information required to accomplish the legal goal should be gathered by authorities.
Restricted Retention: It is not advisable to keep facial data on file forever. There should be explicit guidelines for deletion and retention durations.

Independent Oversight: The deployment of high-risk facial recognition systems should be observed by an impartial body.
Accuracy Requirements: Standards for assessing and verifying FRT systems’ accuracy should be established by authorities.
Human Review: An automatic facial recognition match shouldn’t be the only reason for an arrest, prosecution, or other unfavourable state action.
Transparency: Subject to reasonable security considerations, people should be given the proper information regarding the use and intent of facial recognition.
Security Measures: Robust organisational and technical defences should shield facial databases from hackers and unlawful access.
Effective Remedies: People who are illegally watched or mistakenly identified have to have easy access to legal recourse.

Challenges:

The sophistication of facial recognition has increased due to the quick development of artificial intelligence. But technological capacity has advanced more quickly than the particular laws controlling its application.

The main concern is not whether facial recognition technology is beneficial, but rather when its application is constitutionally permissible. While crime prevention and security are valid state goals, they cannot always take precedence over fundamental rights.

A democratic legal system must guarantee that surveillance is still required, appropriate, and responsible. A serious imbalance between the state and the individual might result from a lack of transparency. As a result, robust institutional and legal protections ought to accompany technical advancement.

Conclusion:

Although facial recognition technology has many advantages for law enforcement, security, and identification, its intrusive potential raises fundamental constitutional concerns. Ordinary public areas can become settings where people can be continuously identified and possibly tracked thanks to the technology.

The constitutional basis for analysing such surveillance is provided by Justice K.S. Puttaswamy (Retd.) v. Union of India, which acknowledged privacy as a fundamental right. In addition to secrecy, privacy safeguards one’s liberty, dignity, and control over personal data. As a result, the requirements of legality, legitimate aim, need, and proportionality must all be met when using facial recognition.

Strong regulations pertaining to consent where necessary, data minimisation, purpose limitation, retention, accuracy, transparency, independent oversight, and efficient remedies should be implemented in India.

FAQs:

1.Facial recognition technology: what is it?
An artificial intelligence-based system called facial recognition technology uses facial features to identify or confirm a person.

2.Does the right to privacy relate to facial recognition?
Indeed. An individual’s identity can be established or revealed using facial templates and photographs. Therefore, the fundamental right to privacy may be violated by the use of such information, especially by state officials.

3.What is the most significant privacy case decided by the Supreme Court?
In the historic ruling Justice K.S. Puttaswamy (Retd.) v. Union of India (2017), the Supreme Court acknowledged privacy as a fundamental right.