From Targeted Interception to India’s Digital Panopticon

Authored by Lemuela Mary J, a 5th-year law student at Saveetha School of Law, Saveetha Institute of Medical and Technical Sciences.
india-mass-surveillance-aadhaar

Abstract

This presentation analyses how the apparatus of surveillance in India has inexorably switched its surveillance schemes to a structure of mass digital surveillance as an all-encompassing structural paradigm; it also looks at how the largest democracy in the world has ironically adopted authoritarian technological paradigms and, at the same time, incorporated privacy as a constitutional prerogative.

Constitutional Promise, Administrative Reality

As we are aware, there are always good and bad things about any new establishment. Although the case of K.S. Puttaswamy in 2017 recognised privacy as a basic right inherent in Article 21 of the Constitution, there has been a disturbing inconsistency between the constitutional rhetoric and administrative reality since then, as mass surveillance infrastructure continues to grow. The surveillance machinery in India has grown exponentially without much public discussion or parliamentary review of its use, resulting in what scholars deem the shaping of surveillance democracy, that is, democratic institutions coexisting with intrusive surveillance machinery to the discomfort of many. However, the discovery of the Pegasus spyware in 2021 revealed the malicious intent of NSO Group in its malware, as journalists, activists, and politicians became victims. Those numbers appeared on a leaked list of potential targets. However, the Supreme Court’s technical committee (Justice R.V. Raveendran) examined 29 phones, found malware in five and could not conclusively attribute it to Pegasus while noting the Union Government’s non-cooperation. This was not interception, but invasive, zero-click hacking, where the distinction between targeted and mass is greyed out.

Comparative Accountability

As can be seen comparatively, democracies that have mastered the fine art of surveillance have put in place strong accountability systems. The Federal Constitutional Court of Germany invalidated data retention laws on account of breaching privacy rights, and the Investigatory Powers Act 2016 of Britain, which caused controversy, nevertheless put a carve-out in the establishment of the Investigatory Powers Commissioner, who has a judicial background and can authorise the issuance of surveillance warrants. On the other hand, the surveillance structure of India works on the law vacuum, wherein the 19th-century Indian Telegraph Act (1885) and the Information Technology Act (2000) hastily amended regulations regulate the digital surveillance of the 21st century. This lack of an extensive data protection law until 2023, with the Digital Personal Data Protection Act, which in turn was also criticised due to its exemption of government agencies from major provisions, has allowed surveillance to flourish unrestrained. China’s Personal Information Protection Law (PIPL), which is not a component of its social credit infrastructure, is a data protection law that is structurally modelled after the GDPR. Not through PIPL, but rather through real-name registration under the Cybersecurity Law and the assistance requirements placed on private operators by the Data Security Law and Article 7 of the National Intelligence Law, mass surveillance related to apps like WeChat takes place. However, the fact that PIPL was written to avoid interfering with monitoring is more important for this argument than the fact that it permits it. Considering Aadhaar-linked systems, India is aware of China’s size, but it lacks the EU’s accountability framework. China here functions not merely as a passing contrast but as a structural precedent for the central claim about Section 17.

Mass Surveillance and the Proportionality Deficit

The Central Monitoring System in India and NATGRID, which compiles information in 21 different categories, such as income tax documents, bank information, and railway tickets, create panoptic profiles of citizens that go way beyond the needs of counterterrorism. The argument that these systems have blocked serious urban terror attacks since 2014, though it may be true in itself, cannot in itself justify mass surveillance, unless it can be shown that less intrusive options would be ineffective, an element of the proportionality test habitually disregarded.

Aadhaar and the Fiction of Voluntariness

The integration of the Aadhaar biometric database with welfare and, eventually, monitoring programs raises additional privacy concerns. In Justice K.S. Puttaswamy (Retd) and Anr. vs Union of India and Ors. on 24 August, 2017, the Supreme Court upheld linking for PAN/income tax and subsidies under Section 7 while simultaneously striking down mandatory Aadhaar linking for bank accounts and mobile SIM cards, as well as Section 57 (private-entity use). Despite this, the court affirmed the constitutionality of Aadhaar by characterising its use as voluntary. Therefore, the Court rejected most of the requirements that are frequently used as proof of rising compulsion. However, the Telecom Act 2023’s biometric verification requirement creates archives of millions of people’s private physical identifiers, creating new worries about the state’s expanding surveillance capabilities. Jump to the next decade: the 2023 Digital Personal Data Protection Act (DPDPA), billed as the Indian GDPR analogue; however, by some accounts, it gives the government broad exemptions in surveillance. The 2025 DPDP Rules also expand to allow state agencies the ability to request data outside of a judicial process that may contribute to metadata surveillance. In 2025, crowds at the Republic Day were observed in Delhi with AI-enhanced CCTV cameras using facial recognition (FRT) to track millions of people, which sounded an alarm because of false positives against minorities SFLC roundup. For instance, consider the Project SHIELD (2025) of Odisha, where AI cameras will give a hotspot an offender score. The most widely cited empirical study, Buolamwini and Gebru’s Gender Shades audit of commercial systems, found that overall accuracy ranged from 87.9 to 93.7%, with lighter-skinned faces recognised 11.8 to 19.2 percentage points more accurately than darker-skinned faces and error rates for darker-skinned women reaching 20.8 to 34.7%. These findings have greatly impacted discussions over the fairness of facial recognition technology used in public-sector contexts, despite the fact that they came from a worldwide benchmark rather than an India-specific dataset. However, jail records in India have long demonstrated that undertrial inmates are disproportionately members of historically marginalised populations. When considered collectively, these worries imply that the use of facial recognition systems with demographic disparities in law enforcement could perpetuate current trends of disproportionate surveillance and false identification if they are not supported by strong safeguards, independent auditing, and accountability mechanisms.

In India, the surveillance machinery, once in place, is irreversible. Regime change offers no respite; the apparatus persists and can be weaponised by corrupt officials, who may auction dissidents’ locations on the dark web, enabling identity theft and physical harm.

Pegasus: A Target List and an Inconclusive Inquiry

The definition of Justice Surya Kant, when hearing Pegasus, that there is nothing wrong with having spyware, is technically correct, but it skips an important question: with whom is it used, and by what means of authorisation? Such judicial shares in executive claims of national security, which have been echoed, in other words, are fundamentally dangerous to revive authoritarian surveillance in the disguise of democracy. There exist latent dangers that instantiate what Snowden refers to as “turnkey tyranny” infrastructures of oppression waiting merely upon political determination to take effect. The society, which partakes in the sacrifice of liberty to security, stands a chance of losing both. The gaps in the research in this study appear to be that there is a lack of empirical studies concerning behavioral changes due to surveillance, the aspect of algorithmic bias is not explored, the accuracy and constitutional considerations have not been discussed, the practice of surveillance capitalism has not been analysed, the concept of collaboration between the Five Eyes is unexplored, identity verification without data disclosure ( Zero-Knowledge Proof system) has not been studied, the court is technical literacy in adjudicating surveillance and the inclusion of informing targets after investigations in Post-Surveillance.

Conclusion: Toward Accountable Surveillance

In the rush of this, the law needs to give tech power its leash so that it can be held accountable and secure. It is time to have ironclad firewalls in India: encrypted silos, citizen vetoes, penalties of treason for abuse. Otherwise, mass surveillance is not a protective shield, but rather a sword in the hands of evil. The transition to mass surveillance in India, which ensures the security of the country, threatens to create a dystopian society in which authority and technology are more important than rights. India can increase responsibility so that its digital future empowers citizens rather than enslaving them. And will we not recover our virtual sovereignty?

Leave a Reply

Your email address will not be published. Required fields are marked *

GET IN TOUCH

Collaborate with us for Research and Policy Innovation

We welcome collaborations, research partnerships, and inquiries related to cyber law, governance, and digital policy. Whether you are an academic, policymaker, or institution, we’d be delighted to explore how CRGCL can work with you on impactful research and outreach initiatives.

Why Collaborate with CRGCL:
Reach Out to Our Research Team