The Position
On August 26, 2026, the Electronic Frontier Foundation published a formal policy position arguing that automated license plate reader (ALPR) networks cannot be reformed, only eliminated. Naming Flock Safety as the dominant vendor, EFF wrote that networked plate-reading is dangerous by design: "There is no configuration of an ALPR network that eliminates this risk, because the risk is the mass surveillance itself, not a misuse of it." The group pointed specifically to ICE, CBP, and DEA pulling data out of local police ALPR databases as proof that any local system, once built, becomes a federal one.
That is a serious argument, and it deserves a fair hearing before disagreement. ALPR and its cousin, facial recognition, genuinely do solve crimes and recover stolen vehicles — that's why police departments everywhere, including in India, keep building them. The problem EFF is describing is structural: a searchable, retroactive record of where every car (or face) has been is a different kind of power than a single traffic stop, and it doesn't stay contained to the purpose it was built for.
An Architecture India Already Has
India isn't watching this fight from the sidelines — it's running a parallel build-out, arguably with fewer checks than the one EFF is attacking. Delhi's Safe City Project is adding roughly 10,000 new facial-recognition-capable cameras to the roughly 25,000 already deployed citywide, feeding a combined network of close to 35,000 cameras into a ₹798-crore Integrated Command, Control, Communication and Computer Centre (C4I) built by the state's own Centre for Development of Advanced Computing. The C4I integrates automatic number plate recognition with e-Challan traffic records, and can match a face or plate against roughly a million records in 200 milliseconds — querying databases of some 350,000 known offenders and 300,000 unidentified-body records at once (State of Surveillance). This is precisely the fused, cross-referenced, agency-shared architecture EFF says cannot be reformed — built here as public infrastructure rather than a vendor contract.
A Traffic Law Doing Surveillance's Job
India's actual statutory hook for camera enforcement is narrow. Section 136A of the Motor Vehicles Act, added by the 2019 amendment, requires state governments to deploy "electronic monitoring and enforcement of road safety" — speed cameras, CCTV, speed guns — on highways and urban roads (Section 136A, Motor Vehicles Act, 1988). On September 2, 2024, the Supreme Court ordered states to implement it in cities with over a million residents, treating it as an overdue road-safety fix (LiveLaw). That is a defensible, narrowly-scoped mandate — catching speeders and red-light runners is a legitimate, proportionate use of cameras. But it says nothing about matching faces or plates against suspect databases, criminal records, or unidentified-persons lists. Delhi's C4I does all of that anyway, on a traffic-safety statute never written for it.
The Missing Statute
India's 2017 privacy ruling in Justice K.S. Puttaswamy v. Union of India set a test any state surveillance must clear: a valid law authorizing it, a legitimate aim, proportionality, and procedural safeguards. Legal analysis of India's facial-recognition rollout argues the whole framework fails at the first step — "there is no Act of parliament which allows the police, railways, or temple trusts to operate live facial recognition on the public"; deployments instead rest on executive orders and repurposed court directives, including a Delhi High Court order meant to help trace missing children (Bar and Bench). Where EFF is fighting an established industry over an existing law, India's version of the same architecture doesn't even have a law to fight over.
The Loophole in the New Privacy Law
India finally has a general data-protection statute — the Digital Personal Data Protection Act, 2023, with rules notified by MeitY on November 13, 2025 and full obligations phasing in through May 13, 2027 (SCC Online). But Section 17(2)(a) lets the central government exempt any government instrumentality from nearly the entire Act by notification alone, for reasons as broad as "security of the State" or "public order" — no court order, no sunset clause required (Digital Personal Data Protection Act, 2023). In practice, the one law positioned to regulate how police retain and cross-match ANPR and facial data is written to exclude exactly that use.
The Proportionate Answer
EFF's diagnosis — that the danger is the database's existence, not its misuse — is worth taking seriously even for readers skeptical of its prescription. But "eliminate it" doesn't fit India's situation any better than a blank check does. Section 136A-style traffic cameras have a real, legality-backed safety case. What doesn't have one is stretching that mandate into an identity-matching architecture with no statute of its own, no retention limits, and a privacy law engineered to look away. The fix isn't tearing down Delhi's C4I; it's giving the parts of it that go beyond traffic enforcement an actual Act of Parliament — purpose limits, audit trails, judicial reauthorization for database queries — and closing Section 17(2)(a) so India's first privacy law actually binds the agencies running the biggest surveillance network it protects.