Author: M.Radhi Rudra, School of Law, SRMIST, Chennai.
ABSTRACT:
Privacy has evolved from a traditional concept of personal space into a fundamental right concerning autonomy, dignity, and informational control in the digital era. This article examines the constitutional recognition of privacy in India, international protections, digital data challenges, legislative developments under the DPDP Act, and judicial approaches balancing privacy with technological advancement.
TO THE POINT:
Privacy is a complex concept that needs more recognition and consideration, especially with this evolving digital era. As technology evolved, communication and information sharing advanced, the protection of privacy has emerged as a significant legal and human rights concern of the twenty- first century.
The right to privacy has been recognized under international human rights law. It is established under Article 12 of Universal Declaration of Human Rights, 1948 and Article 17 of the International Covenant on Civil and Political Rights, 1966. As per these provisions, everyone has the right to privacy which highlights that no one should unfairly interfere with a person’s private life, family, home, or communications, or damage their honour and reputation. If this right is violated, the law should protect the person.
In the Indian perspective, the Constitution of India did not originally recognize the right to privacy as a fundamental right. Instead, the concept developed through a series of landmark judgments. While M.P. Sharma v. Satish Chandra (1954) and in Kharak Singh v. State of Uttar Pradesh (1963) did not recognise privacy as an independent right, later judgments such as Govind v. State of Madhya Pradesh (1975) and R. Rajagopal v. State of Tamil Nadu (1994) expanded its scope. Finally, Justice K.S. Puttaswamy v. Union of India (2017) recognised privacy as an intrinsic part of life and personal liberty under Article 21.
In the digital era, personal data drives government and commercial activities. While digital technologies have improved communication and access to services, they have also created concerns such as surveillance, data breaches, identity theft, and misuse of personal information. According to the Internet and Mobile Association of India (IAMAI), India has approximately 958 million active internet users, reflecting the rapid expansion of the digital ecosystem. This highlights the need to balance digital innovation with privacy protection.
LEGAL JARGON
• Privacy refers to personal aspects of an individual’s life free from the public disclosure.
• Right to Privacy is a constitutionally protected fundamental right under Article 21 that safeguards an individual’s autonomy, dignity and personal liberty.
• The Digital Personal Data Protection Act, 2023 is an act to provide for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes and for matters connected therewith or incidental thereto.
• Information Technology Act, 2000: was enacted to make electronic transactions legally valid and to support the growth of e-commerce and e-governance in India.
• Cybercrime: Cybercrime refers to criminal activities carried out using computers, networks, or digital devices. In India, it has evolved in various forms like otp scams, digital arrests, sextortion, and AI-driven fraud etc…
THE PROOF:
After a series of judgments, the Indian government amended the Information Technology Act, 2000, through the IT (Amendment) Act, 2008 which provides a legal framework for e-governance and cybercrime regulation. In August 2017, The Supreme Court of India declared the Right to privacy to be a fundamental right within the right to life provision. In this landmark judgment, a nine-judge bench urged the Government of India to put in place “a carefully structured regime” for the protection of personal data. To achieve this objective, India underwent several expert consultation and prepared rounds. It also introduced two earlier versions of the bill in Parliament in 2019 and 2022 as part of its efforts to create this regime. After years, Digital Personal Data Protection Act, 2023 was enacted. The DPDP Act establishedData Protection Board of India and provides lawful processing of personal data in a digital format, requiring that data be used only for the respective purpose. Once the purpose fulfilled, the data must be erased which means it should not be used for secondary purpose.
There has always been concern about Government surveillance. The Government of India considered a proposal requiring smartphone manufacturers to enable always-on satellite location tracking to help law enforcement with precise location data during investigations. Many companies such as Apple, Google, and Samsung opposed this proposal, arguing that continuous tracking would infringe users’ personal autonomy. The proposal sparked debate over national security versus privacy rights.
Furthermore, as per the Ministry of Home Affairs (MHA), cybercrime cases in India increased by 24% in 2025, reaching 28.15 lakh cases. Indians lost ₹22,495 crore to cyber fraud, with investment scams accounting for over 75% of the total financial losses, highlighting the growing sophistication of organized fraud. Despite the rise in cases, overall losses declined slightly from ₹22,845 crore in 2024 due to faster police intervention.
In 2021, Air India disclosed a cyberattack that compromised the personal data of approximately 4.5 million customers worldwide. The leaked information included passenger names, passport details, ticket information, and credit card data (excluding CVV/CVC numbers). The incident highlighted the vulnerability of digital databases and the necessity of robust data protection measures.
CASE LAWS
1. Khushbu W/o. Iddrish Khan v. State of Maharashtra
Criminal Writ Petition No. 128 of 2026, Bombay High Court (Nagpur Bench), decided on 3 July 2026.
Facts:
A road accident case was registered at Khapa Police Station against an unknown driver for bailable offences under the BNS and the Maharashtra Motor Vehicles Rules. Although petitioner No. 2 (husband) was not named as an accused, the police repeatedly visited the petitioners’ residence during the investigation. The petitioners alleged that the police entered their house without a warrant or notice, questioned petitioner No. 1 (wife) in the absence of a lady police constable, entered her bedroom, and seized her mobile phone without ollowing procedural safeguards under the BNSS. Aggrieved by the alleged illegal search, seizure, and harassment, the petitioners filed the present writ petition.
Held:
The Court held that Section 185 of the BNSS is mandatory and that a mobile phone is a repository of a person’s private life. Any search and seizure conducted without following the safeguards prescribed under Sections 185 and 105 of the BNSS amounts to a violation of the right to privacy guaranteed under Article 21 of the Constitution. Accordingly, the Court declared the search illegal, directed the return of the mobile phone, and awarded ₹10,000 compensation to the petitioner for the violation of her constitutional rights.
2. WhatsApp LLC v. Competition Commission of India & Ors.
Competition App. (AT) No. 1 of 2025
Facts:
WhatsApp introduced its 2021 Privacy Policy, which expanded the sharing of user data with Meta companies. The Competition Commission of India (CCI) initiated a suo motu investigation, alleging that WhatsApp, being a dominant player in the messaging market, imposed unfair and coercive data-sharing conditions on users in violation of Section 4 of the Competition Act, 2002. After investigation, the CCI held WhatsApp and Meta liable, imposed a penalty of ₹213.14 crore on Meta, and directed WhatsApp to stop sharing user data with Meta for advertising purposes for five years, while also requiring greater transparency and user choice regarding data sharing. WhatsApp and Meta challenged the order before the NCLAT.
Held:
The NCLAT held that the CCI had the jurisdiction to examine WhatsApp’s conduct under the Competition Act and refused to stay the CCI’s transparency and user-choice directions. However, as an interim measure, the five-year ban on sharing user data with Meta for ads, citing possible disruption to WhatsApp’s business model. The Tribunal also stayed recovery of the remaining penalty, subject to WhatsApp depositing 50% of the total penalty, and directed that the appeals be heard expeditiously.
CONCLUSION:
The rapid growth of digital technologies has made privacy protection a critical legal necessity. While laws such as the Digital Personal Data Protection Act, 2023 strengthen data protection, continuous efforts are required to balance innovation, security, and individual rights. Effective enforcement and judicial oversight remain essential to safeguard privacy in the digital age.
FAQ’s
1. Name the major privacy issues due to digitalization?
Large Scale collection of personal data’s by apps and companies increase surveillance, data breaches, identity theft, and financial fraud.
2. How can privacy protection be improved in the digital age?
Ans: Strong laws improve the data protection with better enforcement, awareness, transparent data collection practicesand cyber security measures. Additionally, individuals must be aware of the use personal data and demand privacy safeguards.
REFERENCE
1. India now has 958 million active internet users; 57% of these are from rural areas – The Hindu
2. Right to Privacy, Evolution, Significance, Challenges
3. https://lawbhoomi.com/right-to-privacy-in-the-digital-age/
4. Right to privacy and data protection
5. Right to Privacy: Court in Review – Supreme CourtObserver
8. Air India cyber-attack: Data of millions of customers compromised
9.https://fpf.org/blog/the-digital-personal-data-protection-act-of-india-explained/
10. Whatsapp Llc vs Competition Commission Of India on 23 January, 2025
11. https://www.insightsonindia.com/2026/02/21/cybercrime-in-india/
13. https://www.lawweb.in/2026/07/bombay-hc-entry-into-residential.html
