India biometric surveillance

India's Facial Recognition Sweep at Jantar Mantar Exposes a Six-Year-Old Regulatory Vacuum

Delhi Police flagged ~400 people via live FRT at the NEET-UG protest site under rules that don't exist, and the DPDP Act's law-enforcement carve-out won't fill the gap.

Facial Recognition at Jantar Mantar: By the Numbers People of Internet Research · India ~400 People flagged Identified via live FRS against cr… 80% Match threshold used Similarity score Delhi Police trea… 1,100+ Riot identifications, 2020 People identified via FRT after th… 9 Years since privacy ruling Since Puttaswamy (2017) required a… peopleofinternet.com
Facial Recognition at Jantar Mantar: B… People of Internet Research · India ~400 People flagged 80% Match threshold used 1,100+ Riot identifications,… 9 Years since privacy ruling peopleofinternet.com

Key Takeaways

A Protest, Two Vans, and No Statute

Between July 20 and 24, 2026, Delhi Police stationed two "Ikshana" surveillance vehicles — 360-degree camera rigs originally built for the 2023 G20 summit — outside Kerala House, a few hundred metres from the Jantar Mantar protest site where students were demonstrating over alleged irregularities in the NEET-UG 2026 medical entrance exam. One van streamed live CCTV to a command centre; the other ran that feed through facial recognition software (FRS) and automatic number-plate recognition, checking faces against police databases of wanted persons and habitual offenders. Police say the system flagged roughly 400 people with alleged criminal records in and around the protest site during those five days.

Police describe this as ordinary investigative work: cross-referencing faces against a criminal database isn't fundamentally different from a constable checking IDs. That framing has some force — a protest of this scale genuinely draws pickpockets and opportunists, and past communal violence in Delhi has shown that identifying instigators after the fact matters to public order. But applying that logic to a live, continuous dragnet feed running over a peaceful political assembly is a different order of intrusion than post-hoc identification of people already suspected of a specific offence — and that gap is what the objections are actually about.

The Part That Should Concern Regulators More Than the Cameras

The substantive problem isn't that FRT exists — it's that nothing governs how Delhi Police uses it. The Internet Freedom Foundation, citing RTI replies obtained after a second appeal to the Central Information Commission, says Delhi Police could point to no rule authorising the deployment, had conducted no privacy impact assessment, and treats a bare 80% facial-similarity score as a "positive match" sufficient to flag someone for further scrutiny. On July 24, IFF sent a legal representation to the Delhi Police Commissioner demanding an immediate halt to live facial recognition of participants in peaceful assemblies absent specific statutory authorisation.

This is not a new complaint. After the February 2020 northeast Delhi riots, then-Home Minister Amit Shah told Parliament that facial recognition had helped identify more than 1,100 people — using a system that, by IFF's account at the time, was running at roughly 1% accuracy the prior year and had failed basic tests like distinguishing children by sex. Six years and one G20-grade hardware upgrade later, the technology has plainly improved; the legal architecture around it has not moved at all.

The Case Now in Front of the Delhi High Court

Former JNUSU president Aishe Ghosh has filed a public interest litigation asking the Delhi High Court to require a legal framework — including data-protection safeguards — before facial recognition is trained continuously on protesters. Her counsel, Senior Advocate Nandita Rao, invoked the Supreme Court's nine-judge privacy ruling in Justice K.S. Puttaswamy v. Union of India (24 August 2017), which held that any state intrusion on privacy — including in public spaces — must clear a three-part test: a specific enabling law, a legitimate state aim, and proportionality between the means used and that aim. Solicitor General Tushar Mehta countered for the government that videographing a public protest is a routine law-and-order measure, and that claiming privacy in a public assembly is "ironical." The bench reserved its view on the competing submissions and listed the matter for July 27, 2026.

Mehta's videography argument isn't wrong on its own terms — recording a public protest for order-maintenance is well-established practice that courts have generally accepted. The leap the government has to defend is from recording to automated, real-time biometric matching against a criminal database — a categorically different exercise of state power. It doesn't just document the protest; it algorithmically sorts every attendee's face against watch-lists in real time, using a match threshold set low enough to guarantee a meaningful false-positive rate at protest scale.

Why the DPDP Act Doesn't Save the Situation

India's Digital Personal Data Protection Act, 2023 is often cited as the eventual answer to gaps like this one. It isn't. Section 17 lets the central government exempt any notified state agency from the Act's core obligations — consent, purpose limitation, data-principal rights — for processing tied to "sovereignty and integrity of India, security of the State... [or] public order," and separately exempts processing for "prevention, detection, investigation or prosecution of any offence" outright. Unlike comparable regimes such as the UK's Investigatory Powers Act, which requires ministerial sign-off plus independent judicial-commissioner review before intrusive surveillance is authorised, Section 17 specifies no procedure and no independent oversight body an agency must clear before invoking the exemption. NITI Aayog's own 2021 "Responsible AI for All" paper had recommended that law enforcement not be blanket-exempted from data protection oversight; Parliament's final text did not adopt that recommendation.

The Proportionate Fix Isn't "No Cameras"

None of this is an argument against surveillance technology as a policing tool. Number-plate recognition at a border checkpoint, or facial matching against a specific wanted-persons alert list used narrowly and audited after the fact, is defensible law enforcement. What's indefensible is deploying continuous, dragnet FRT over a specific, identified political assembly, with a low match threshold, no statute, no privacy impact assessment, and no stated data-retention limit — and then defending it after the fact as a generic, content-neutral law-and-order tool. A workable middle path already exists in draft form: a dedicated facial recognition technology statute that fixes accuracy and match thresholds, mandates pre-deployment privacy impact assessments, requires independent or judicial sign-off for protest-adjacent use, and sets hard retention limits on captured biometric data. Until India passes something like it, every deployment — however well-intentioned the individual officers running it — is discretionary state power operating on a chilling effect it has no license to impose.

Sources & Citations

  1. Delhi High Court PIL hearing (LiveLaw)
  2. K.S. Puttaswamy v. Union of India, Supreme Court judgment (Indian Kanoon)
  3. Digital Personal Data Protection Act, 2023 (PRS Legislative Research)
  4. Delhi Police FRS deployment details (Tribune India)
  5. ~400 people flagged (The Logical Indian)
  6. 2020 Delhi riots FRT precedent (TechCrunch)