0% found this document useful (0 votes)
3 views18 pages

Chapter2 Dissertation

This chapter discusses the constitutional foundations of privacy and proportionality in India, highlighting the recognition of informational privacy as a fundamental right under Article 21, affirmed by the Supreme Court in the Puttaswamy case. It traces the evolution of privacy rights in India, detailing the judicial journey towards acknowledging privacy as a fundamental right and the implications of the doctrine of proportionality on state actions affecting this right. The chapter emphasizes the need for a robust data protection regime and the constitutional obligations of the state as a Data Fiduciary in the context of emerging technological threats to privacy.

Uploaded by

uttamr.advocate
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views18 pages

Chapter2 Dissertation

This chapter discusses the constitutional foundations of privacy and proportionality in India, highlighting the recognition of informational privacy as a fundamental right under Article 21, affirmed by the Supreme Court in the Puttaswamy case. It traces the evolution of privacy rights in India, detailing the judicial journey towards acknowledging privacy as a fundamental right and the implications of the doctrine of proportionality on state actions affecting this right. The chapter emphasizes the need for a robust data protection regime and the constitutional obligations of the state as a Data Fiduciary in the context of emerging technological threats to privacy.

Uploaded by

uttamr.advocate
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

CHAPTER 2: THE CONSTITUTIONAL FOUNDATION — PRIVACY AND

PROPORTIONALITY

The constitutional analysis at the heart of this dissertation rests upon two related but analytically

distinct doctrinal foundations: first, the recognition of informational privacy as a fundamental

right under Article 21 of the Constitution of India, as affirmed by the nine-judge constitution

bench in Justice K.S. Puttaswamy (Retd.) v. Union of India (2017);1 and second, the doctrine of

proportionality as the operative standard by which the validity of State action affecting that right

is assessed. This chapter establishes both foundations with the precision that the subsequent

constitutional analysis demands. It traces the genealogy of the right to privacy under the Indian

Constitution from its contested pre-Puttaswamy history through to the contemporary framework;

it examines the specific content of informational privacy as a distinct and legally actionable facet

of the right; it unpacks the architecture of the four-pronged proportionality test that will be

applied in Chapter 3 to the exemptions in Section 17 of the Digital Personal Data Protection Act,

2023; and it maps the State's obligations as a Data Fiduciary onto the constitutional structure of

that test. The chapter concludes by establishing the technological substrate of the right — the

proposition that classical encryption is not merely a technical feature of the digital infrastructure

but the operational mechanism through which informational privacy is constitutionally

guaranteed — and that the displacement of that mechanism by quantum computing is therefore

not a technical concern but a constitutional one.

1
Samuel D. Warren & Louis D. Brandeis, 'The Right to Privacy' (1890) 4 Harv L Rev 193, 193.
2.1 The Genealogy of Privacy as a Fundamental Right in India
The idea that privacy constitutes an enforceable legal right has its intellectual origins in the

common law tradition of the nineteenth century. Warren and Brandeis, writing in the Harvard

Law Review in 1890, articulated the case for a legally cognisable right to privacy in response to

what they identified as the invasive potential of the press and photography: 'The press is

overstepping in every direction the obvious bounds of propriety and of decency. Gossip is no

longer the resource of the idle and of the vicious, but has become a trade, which is pursued with

industry as well as effrontery.'2 Their central argument was that the existing common law,

however developed for the protection of property and contract, was inadequate to protect 'the

right to be let alone'3 — a formulation that would, more than a century later, find its echo in

Indian constitutional adjudication. The normative ambition of the Warren-Brandeis article was

structural: to establish privacy as an independent legal right rather than a derivative protection

contingent upon property or confidence. 'The principle which protects personal writings and any

other productions of the intellect or of the emotions', they argued, 'is the right of privacy, and the

law has no new principle to formulate when it extends this protection to the personal appearance,

sayings, acts, and to personal relations, domestic or otherwise.'4

In the Indian constitutional context, the path to recognising privacy as a fundamental right was

neither linear nor uncontested. The Constitution of India does not expressly enumerate a right to

privacy in Part III. The earliest authoritative pronouncements of the Supreme Court were, if

anything, inhospitable to its recognition. In M.P. Sharma v. Satish Chandra (1954),5 an eight-

judge constitution bench considered whether the power of search and seizure violated any

2
ibid 195–196.
3
ibid 196.
4
Thomas M. Cooley, A Treatise on the Law of Torts (2nd edn, Callaghan 1888) 29.
5
Daniel J. Solove, 'The Limitations of Privacy Rights' (2023) 98 Notre Dame L Rev 975, 976.
fundamental right and held, in broad terms, that the framers of the Constitution had not

recognised a right to privacy analogous to the Fourth Amendment of the United States

Constitution. In Kharak Singh v. State of Uttar Pradesh (1963),6 a six-judge bench, confronted

with the constitutional validity of police surveillance regulations, held by majority that privacy

was not itself a fundamental right under Article 21, though the dissent of Justice Subba Rao —

observing that privacy is 'an essential ingredient of personal liberty' 7 — planted the seed of what

would become the settled constitutional position more than fifty years later.

The intervening decades saw a gradual judicial retreat from the austere position of M.P. Sharma

and Kharak Singh.8 In Govind v. State of Madhya Pradesh (1975),9 the Supreme Court

acknowledged that a right to privacy flows from Articles 19(a) and 21, though it characterised

the right as not yet fully developed and explicitly not absolute. In R. Rajagopalan v. State of

Tamil Nadu (1994),10 the Court held that the right to privacy means the right to be let alone and

that this right is implicit in Article 21, extending its scope to encompass a citizen's right to

safeguard the privacy of family, marriage, procreation, motherhood, childbearing, and education.

In People's Union for Civil Liberties v. Union of India (1997),11 the Court applied the principle

directly to surveillance, holding that telephone tapping constitutes a violation of Article 21's

guarantee of personal liberty and of Article 19(1)(a)'s guarantee of freedom of speech and

expression — thereby establishing the critical doctrinal link between privacy and communication

that would assume constitutional significance in the digital age.

6
ibid 984–985: rights 'put too much onus on individuals when many privacy problems are systematic.'
7
M.P. Sharma v. Satish Chandra AIR 1954 SC 300 (India).
8
Kharak Singh v. State of Uttar Pradesh AIR 1963 SC 1295 (India).
9
ibid (Subba Rao J, dissenting): 'It is true our Constitution does not expressly declare a right to privacy as a
fundamental right, but the said right is an essential ingredient of personal liberty.'
10
Govind v. State of Madhya Pradesh (1975) 3 SCR 946 (India), holding that the right to privacy flows from Arts.
19(a) and 21 but is not absolute.
11
R. Rajagopalan v. State of Tamil Nadu (1994) 6 SCC 632 (India), para 26.
The definitive resolution came in Puttaswamy (2017). A nine-judge constitution bench,

constituted specifically to resolve the competing earlier authorities, 12 held unanimously that the

right to privacy is a fundamental right protected as an intrinsic part of the right to life and

personal liberty under Article 21 and as part of the freedoms guaranteed by Part III of the

Constitution.13 The significance of this holding cannot be reduced to the resolution of a doctrinal

dispute. By grounding privacy in Article 21, the Court brought the entire constitutional apparatus

of fundamental rights protection — including the doctrine of proportionality, the requirement of

just, fair and reasonable procedure, and the availability of constitutional remedies under Article

32 — to bear upon every future case in which the State encroaches upon informational privacy.

The nine separate opinions authored by the bench, while unanimous on the conclusion, offer a

rich and analytically differentiated account of what privacy means, how it relates to human

dignity and autonomy, and what obligations it imposes upon the State. It is this differentiation —

and in particular the extended analysis in Justice Chandrachud's concurrence — that provides the

doctrinal architecture upon which this dissertation builds its central argument.

2.2 Informational Privacy as a Fundamental Right: The Expectation of Secrecy and the
Digital Subject
Privacy, as a fundamental right, is not monolithic. The Puttaswamy bench recognised multiple

distinct but overlapping dimensions of the right, each engaging different constitutional concerns

and attracting different analytical frameworks. Justice Chandrachud's opinion identified three

analytically separable aspects: the right not to be subject to physical intrusion or surveillance; the

right to make intimate personal decisions — what might be termed decisional autonomy; and

12
People's Union for Civil Liberties v. Union of India AIR 1997 SC 568 (India) (PUCL), holding that telephone
tapping is violative of Arts. 19(1)(a) and 21.
13
Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) 10 SCC 1 (hereafter Puttaswamy).
informational privacy — the right of the individual to exercise control over the collection,

retention, disclosure, and use of personal data.14 It is this third dimension — informational

privacy — that is the primary subject of this dissertation.

Justice Chandrachud's articulation of informational privacy is both precise and, for this

dissertation's purposes, prescient:

Informational privacy is a facet of the right to privacy. The dangers to privacy in


an age of information can originate not only from the state but from non-state
actors as well. We commend to the Union Government the need to set up a robust
regime for data protection. The creation of such a regime requires a careful and
sensitive balance between individual interests and legitimate concerns of the
state.15

The passage repays careful analysis. It identifies informational privacy as a distinct facet of the

right, not merely a subset or derivative of physical privacy. It acknowledges that the threats to

informational privacy in the digital age emanate from both the State and non-State actors — a

formulation that, as will be argued in Chapter 5, is directly relevant to the HNDL threat, where it

is foreign state adversaries and sophisticated non-State actors who harvest encrypted data.

Crucially, it identifies the creation of a robust data protection regime as a constitutional

imperative flowing from this recognition — an observation that anticipates the legislative history

that culminated in the DPDP Act 2023.

14
Puttaswamy (n 13) para 3 (per curiam): 'The right to privacy is protected as an intrinsic part of the right to life and
personal liberty under Article 21 and as a part of the freedoms guaranteed by Part III of the Constitution.'
15
The nine opinions are authored by: Khehar CJ; Chelameswar J; Bobde J; Rohinton Fali Nariman J; Abhay
Manohar Sapre J; D.Y. Chandrachud J; S.K. Kaul J; S.A. Nazeer J; and D.Y. Chandrachud J concurring in part. The
reference bench was constituted in response to a preliminary objection in Justice K.S. Puttaswamy v. Union of India
(the Aadhaar reference) that the earlier constitution bench decisions in M.P. Sharma and Kharak Singh had held
there was no fundamental right to privacy.
Justice Chandrachud further identified three components of informational privacy: 16 first, the

right of the individual to have control over personal data — encompassing consent to collection,

the right to access, the right to correction, and the right to erasure; second, the right against

surveillance and profiling by the State — the protection against the aggregation of personal data

in ways that enable the State to track, predict, or manipulate individual behaviour; and third, the

right to erasure or informational self-determination over the long term. Each of these components

is directly implicated by the quantum threat. The HNDL strategy, in particular, strikes at the

second component: it represents the ultimate form of retrospective State surveillance — the

capacity to decrypt and read, in their entirety, all past encrypted communications of a citizen,

with no contemporaneous knowledge or consent on the citizen's part.

Justice Kaul's concurrence adds a further dimension of particular relevance to this dissertation's

analysis of the State's obligations as a Data Fiduciary. Justice Kaul characterised the State's

relationship to personal data not merely as that of a potential violator of rights but as that of a

trustee or fiduciary — an entity that holds data on behalf of citizens and is accountable to them

for its proper use and protection:

The State must put in place a robust regime for data protection... [T]he right to
privacy... is a fundamental right which needs protection. Data as a commodity...
must be accompanied by accountability frameworks enforceable against both
State and private actors.17

16
Puttaswamy (n 13) para 169 (Chandrachud J): 'Privacy includes at its core the preservation of personal intimacies,
the sanctity of family life, marriage, procreation, the home and sexual orientation. Privacy also connotes a right to be
left alone.'
17
Puttaswamy (n 13) para 180 (Chandrachud J): 'Informational privacy is a facet of the right to privacy. The dangers
to privacy in an age of information can originate not only from the state but from non-state actors as well. We
commend to the Union Government the need to set up a robust regime for data protection. The creation of such a
regime requires a careful and sensitive balance between individual interests and legitimate concerns of the state.'
This fiduciary framing — adopted from Justice Kaul's concurrence and subsequently reflected in

the DPDP Act's classification of State instrumentalities as Data Fiduciaries 18 — carries

constitutional significance that extends beyond the statutory context. A fiduciary's obligation is

not merely reactive — to avoid misuse of the data entrusted to it — but prospective: to take

affirmative steps to protect that data against foreseeable risks. As Solove has argued, in the

context of systemic privacy problems, rights-based frameworks that focus on individual control

are insufficient precisely because many privacy harms are structural rather than transactional —

they arise from the systemic accumulation and vulnerability of data across entire populations. 19

The constitutional fiduciary obligation identified by Justice Kaul provides the normative

foundation for an argument that the State's duty under Puttaswamy is not discharged by

providing individual rights against misuse but requires systemic protective action — including,

on the argument advanced in this dissertation, the proactive adoption of cryptographic standards

adequate to protect data over its entire lifecycle.

The concept of the 'reasonable expectation of privacy' — first articulated in American

constitutional jurisprudence by Justice Harlan in Katz v. United States (1967)20 and subsequently

adopted in Indian jurisprudence through PUCL and Puttaswamy — assumes a particular

significance in the quantum-threat context. Under the Katz formulation, the test for whether the

right to privacy has been engaged has two limbs: whether the individual exhibited an actual,

subjective expectation of privacy; and whether that expectation is one that society is prepared to
18
Puttaswamy (n 13) para 185 (Chandrachud J), identifying three aspects of informational privacy: (i) right of the
individual to have control over data about oneself; (ii) right against surveillance and profiling by the State; (iii) right
to erasure and forgotten — anticipating by six years the framework of the DPDP Act 2023.
19
Puttaswamy (n 13) para 645 (Kaul J): 'The State must put in place a robust regime for data protection... [T]he right
to privacy... is a fundamental right which needs protection.'
20
Puttaswamy (n 13) para 310 (Chandrachud J), articulating the four-pronged test: '(i) The action must be sanctioned
by law; (ii) The proposed action must be necessary in a democratic society for a legitimate aim; (iii) The extent of
such interference must be proportionate to the need for such interference; (iv) There must be procedural guarantees
against abuse of such interference.'
recognise as objectively reasonable. When a citizen communicates through an encrypted channel

— WhatsApp, Signal, end-to-end encrypted email, or any platform using RSA or ECC-based key

exchange — that citizen exhibits an actual, subjective expectation of secrecy. The question that

the HNDL threat forces upon the constitutional framework is whether that expectation is

objectively reasonable when the State that has access to the encrypted traffic is also, or will

foreseeably be, capable of decrypting it retroactively. This dissertation's answer is that the

objective reasonableness of the citizen's expectation of secrecy is a function not only of the

current technical state of encryption but of the State's obligations to maintain the conditions

under which that encryption remains secure. A State that allows the technical foundations of

privacy to erode — through inaction in the face of foreseeable quantum decryption capabilities

— cannot simultaneously claim that a citizen's expectation of secrecy in encrypted

communications is unreasonable.

2.3 The Doctrine of Proportionality: From Om Kumar to Puttaswamy


The proportionality doctrine, as an operative standard of constitutional review, entered Indian

administrative and constitutional law in earnest through Om Kumar v. Union of India (2001).21

Prior to Om Kumar, the dominant standard of judicial review in administrative law was

Wednesbury unreasonableness — the inquiry into whether a decision was so unreasonable that

no reasonable authority could have made it. The Wednesbury standard is a threshold of extreme

irrationality: it does not require the court to examine whether the restriction on a right is the least

intrusive means available, or whether the benefits of the restriction are proportionate to its costs.

21
Puttaswamy (n 13) para 265 (Bobde J), describing the threefold test as requiring the restriction to be: (i) by law;
(ii) for a legitimate aim; and (iii) proportionate.
In Om Kumar, a two-judge bench of the Supreme Court drew a crucial distinction between this

standard and the proportionality inquiry:

When a fundamental right is involved the court is required to examine more than
the reasonableness of the restriction. The court must examine whether the means
adopted are proportionate to the objective sought to be achieved.22

This formulation signalled a fundamental shift in the intensity of constitutional review when

fundamental rights are at stake. Where the Wednesbury standard is deferential — asking only

whether the decision was within a broad range of rational responses — the proportionality

standard is exacting: it requires an analysis of whether the restriction is necessary, whether less

restrictive alternatives are available, and whether the costs to the right are commensurate with

the benefits of the State action. The move from Wednesbury to proportionality is, in doctrinal

terms, a move from process review to substantive review — from asking whether the State

thought about the right question to asking whether the State gave the right answer.

The doctrinal development gathered momentum in Modern Dental College and Research Centre

v. State of Madhya Pradesh (2016),23 in which a five-judge constitution bench expressly adopted

a structured, four-stage proportionality analysis drawn from comparative constitutional law —

drawing in particular on the jurisprudence of the Supreme Court of Canada under s 1 of the

Canadian Charter of Rights and Freedoms and the German Constitutional Court's

Verhältnismäßigkeit doctrine. The four stages as articulated in Modern Dental College are:

(i) a measure restricting a right must be designated for a proper purpose; (ii) the
measures undertaken to effectuate such a limitation must be rationally connected
22
Om Kumar v. Union of India (2001) 2 SCC 386 (India) (hereafter Om Kumar).
23
Om Kumar (n 22) para 27, distinguishing between Wednesbury unreasonableness (rationality review) and
proportionality, and holding that in matters touching fundamental rights, proportionality — rather than mere
rationality — is the operative standard: 'When a fundamental right is involved the court is required to examine more
than the reasonableness of the restriction.'
to the fulfilment of that purpose; (iii) the measures must be necessary in that there
are no alternative, less restrictive measures that could achieve the same purpose;
(iv) there needs to be a proper relation ('proportionality stricto sensu' or
'balancing') between the importance of achieving the aim and the social
importance of preventing the limitation on the constitutional right.24

This four-stage framework — proper purpose, rational connection, necessity, and balancing —

provides the analytical scaffolding for the constitutional critique developed in Chapter 3 of this

dissertation. When applied to Section 17 of the DPDP Act in the context of the HNDL threat,

each stage of the analysis yields a distinct constitutional objection. The proper purpose inquiry

exposes the absence of any defined, limited objective for the State's self-exemption from data

protection obligations. The rational connection inquiry reveals that blanket exemption of State

processing from security safeguard requirements has no rational connection to the achievement

of legitimate security objectives — a State genuinely concerned with security would, on the

contrary, strengthen rather than loosen the protective obligations around data it holds. The

necessity inquiry — the most powerful — establishes that the State, if it requires access to

specific data for specific security purposes, has less intrusive alternatives available through

targeted access mechanisms, rather than the wholesale exemption of State processing from

proportionate oversight. And the balancing inquiry, in the quantum-threat context, tips decisively

against the State: the cost of the exemption — the irreversible, retroactive exposure of every

citizen's encrypted data to quantum decryption — is catastrophically disproportionate to any

administrative convenience gained through broad statutory self-exemption.

24
Modern Dental College and Research Centre v. State of Madhya Pradesh (2016) 7 SCC 353 (India) (hereafter
Modern Dental College).
2.4 The Puttaswamy Proportionality Test: Architecture and Application
The Puttaswamy bench consolidated and refined the proportionality doctrine in the specific

context of the right to privacy. Justice Chandrachud's formulation — which is adopted as the

primary analytical framework for this dissertation — articulates the test in four prongs:

(i) The action must be sanctioned by law; (ii) The proposed action must be
necessary in a democratic society for a legitimate aim; (iii) The extent of such
interference must be proportionate to the need for such interference; (iv) There
must be procedural guarantees against abuse of such interference.25

The first prong — legality — requires that any encroachment upon the right to privacy must have

a legal basis that is accessible, foreseeable, and precise enough to allow the citizen to foresee the

consequences of the law. This is not merely a formal requirement: the European Court of Human

Rights, in its extensive jurisprudence on Article 8 of the European Convention on Human Rights

— the closest analogous provision to Article 21's privacy protection — has consistently held that

legal provisions authorising surveillance or data processing must indicate 'with sufficient clarity

the scope of discretion conferred on the competent authorities and the manner of its exercise' to

provide adequate protection against arbitrary interference. Applied to Section 17 of the DPDP

Act, the legality prong raises serious questions about the breadth of the exemption and the

absence of any statutory criteria delimiting when and how the exemption may be invoked.

The second prong — legitimate aim — is the least demanding in the Indian constitutional

context, since national security, public order, and prevention of offences are expressly

enumerated purposes in Article 19(2) and have been consistently recognised as legitimate

25
Modern Dental College (n 24) para 56, adopting the structured proportionality analysis: '(i) a measure restricting a
right must be designated for a proper purpose; (ii) the measures undertaken to effectuate such a limitation must be
rationally connected to the fulfilment of that purpose; (iii) the measures must be necessary in that there are no
alternative, less restrictive measures that could achieve the same purpose; (iv) there needs to be a proper relation
("proportionality stricto sensu" or "balancing") between the importance of achieving the aim and the social
importance of preventing the limitation on the constitutional right.'
objectives capable of supporting restrictions on fundamental rights. It would be unusual, and

likely incorrect, to argue that Section 17's exemptions lack a legitimate aim. This dissertation

does not press the argument at this stage of the test. The constitutional difficulty lies, rather, in

the third and fourth prongs.

The third prong — necessity, or the least-intrusive-means requirement — is the analytical core of

this dissertation's constitutional argument. The necessity inquiry requires the court to examine

whether the State's chosen instrument is the minimum restriction on the fundamental right that is

sufficient to achieve the legitimate aim. If less restrictive means are available that would achieve

the same objective, the chosen instrument fails the necessity test even if it would achieve the

objective more efficiently or conveniently. The significance of the quantum-threat context for

this prong is examined in Chapter 3, but the analytical structure may be stated here: if the State

can achieve legitimate national security and law enforcement objectives through targeted access

to specific data under judicial supervision, then the untargeted, uncircumscribed exemption of all

State processing from data protection obligations — leaving all State-held encrypted data

vulnerable to quantum decryption without any mandate to migrate to PQC — cannot satisfy the

necessity requirement.

The fourth prong — balancing or proportionality stricto sensu — requires that the importance of

the aim pursued must be weighed against the severity of the restriction imposed on the right. As

Justice Chandrachud observed in Puttaswamy: 'Proportionality is an essential facet of the

guarantee against arbitrary State action because it ensures that the nature and quality of the

encroachment on the right is not disproportionate to the purpose of the law.' 26 The quantum-

26
Puttaswamy (n 13) para 309 (Chandrachud J): 'Proportionality is an essential facet of the guarantee against
arbitrary State action because it ensures that the nature and quality of the encroachment on the right is not
disproportionate to the purpose of the law.'
threat context transforms this balancing inquiry into a matter of constitutional urgency: the cost

imposed on the right — the permanent, retroactive, and irreversible exposure of every citizen's

informational privacy to quantum decryption — is not a contingent or reversible harm. It is a

categorical and catastrophic deprivation of informational autonomy. The benefit on the other side

of the scale — the administrative convenience of blanket State self-exemption from data

protection obligations — cannot plausibly be characterised as commensurate with that cost.

The Puttaswamy proportionality framework was subsequently applied by the Supreme Court in

Anuradha Bhasin v. Union of India (2020)27 — the internet shutdown case arising from

restrictions imposed in Jammu and Kashmir — where the Court held that measures restricting

the exercise of fundamental rights in digital spaces must independently satisfy each prong of the

proportionality test and that the State cannot rely on blanket invocations of national security to

avoid proportionality scrutiny.28 The Court's insistence, in Anuradha Bhasin, that proportionality

review applies with full force to digital rights restrictions provides direct authority for the

proposition that Section 17's exemptions — which effectively remove proportionality constraints

from State processing of personal data in digital form — are themselves subject to the

proportionality test that they purport to displace.

The chilling effect doctrine — most directly applicable to Article 19(1)(a) — adds a further

dimension to the proportionality analysis. In Shreya Singhal (2015),29 the Supreme Court held

that overbroad restrictions on speech are unconstitutional not only because they prohibit

protected speech in particular cases but because they deter citizens from exercising their speech
27
Anuradha Bhasin v. Union of India (2020) 3 SCC 637 (India) (hereafter Anuradha Bhasin).
28
Anuradha Bhasin (n 27) para 27, holding: 'The doctrine of proportionality requires a restriction to be (i) suited to
achieve a legitimate aim; (ii) necessary, i.e. the least restrictive means available; and (iii) the benefits of the
restriction must outweigh its costs.' The Court further held that internet access is a medium for the exercise of rights
under Art. 19(1)(a) and Art. 19(1)(g), and that restrictions on internet access must be independently proportionate.
29
Shreya Singhal v. Union of India (2015) 5 SCC 1 (India) (hereafter Shreya Singhal).
rights at all, in anticipation of the possibility of State action against them. 30 The significance of

the chilling effect doctrine for the quantum-threat context is direct: where citizens cannot be

assured that their encrypted communications will remain private against future State decryption,

the rational response is to self-censor — to avoid communicating in ways that could, in a

foreseeable future, be read by the State. This anticipatory self-censorship is as much a

constitutional violation of Article 19(1)(a) as a contemporaneous prohibition on speech; indeed,

it is in some respects more damaging, because it operates invisibly and without any formal act of

State prohibition.

2.5 The State as Data Fiduciary and the Duty of Cryptographic Agility
The DPDP Act 2023 introduced the concept of the Data Fiduciary into Indian data protection

law.31 Under Section 2(i) of the Act, a Data Fiduciary is defined as any person who alone or in

conjunction with other persons determines the purpose and means of processing of personal

data.32 State instrumentalities — government ministries, statutory authorities, and agencies —

that collect and process personal data under statutory powers are, within this framework, Data

Fiduciaries. The Act imposes upon Data Fiduciaries the obligation, under Section 8(4), to

'protect personal data in its possession or under its control by taking reasonable security

safeguards to prevent personal data breach.'33 Section 17, however, exempts specified State

30
Shreya Singhal (n 29) para 19, striking down s 66A of the Information Technology Act 2000 on the ground that its
overbreadth created a chilling effect on constitutionally protected speech: 'Section 66A is cast so widely that
virtually any opinion on any subject would be covered by it, as every opinion would be provocative to some. The
chilling effect on free speech would be total.'
31
Digital Personal Data Protection Act 2023 (Act 22 of 2023) (hereafter 'DPDP Act'), preamble: 'An Act to provide
for the processing of digital personal data in a manner that recognises both the right of individuals to protect their
personal data and the need to process such personal data for lawful purposes...'
32
DPDP Act (n 31) s 2(i): 'Data Fiduciary means any person who alone or in conjunction with other persons
determines the purpose and means of processing of personal data.'
33
DPDP Act (n 31) s 8(4): 'Every Data Fiduciary shall protect personal data in its possession or under its control by
taking reasonable security safeguards to prevent personal data breach.'
processing from many of these obligations — including, critically, the obligation to implement

reasonable security safeguards — in the interests of national security, sovereignty, and the

prevention of offences.34

The relationship between the constitutional fiduciary obligation identified by Justice Kaul in

Puttaswamy35 and the statutory Data Fiduciary framework of the DPDP Act is not merely

analogical. Justice Kaul's formulation — that the State's relationship to personal data must be

governed by accountability frameworks enforceable through judicial review — provides the

constitutional foundation upon which the DPDP Act's fiduciary structure was built. It also

provides the constitutional standard against which Section 17's exemptions must be measured. A

fiduciary that exempts itself from its own accountability obligations, in circumstances where

those exemptions expose the data entrusted to it to a foreseeable and catastrophic risk, cannot be

said to be acting consistently with the constitutional duty of care from which the statutory

fiduciary obligation is derived.

This dissertation introduces the concept of cryptographic agility as a legal standard implied by

the 'reasonable security safeguards' requirement of Section 8(4) and, at the constitutional level,

by the positive obligation under Puttaswamy to protect informational privacy against foreseeable

threats. The CERT-In whitepaper provides the technical definition: crypto agility is 'the ability to

swiftly adapt cryptographic algorithms, parameters and protocols' and is described as 'vital for

long-term security, especially in a post-quantum world where even PQC schemes may eventually

34
DPDP Act (n 31) s 17(1): the Central Government may, by notification, exempt certain instrumentalities of the
State from all or some provisions of the Act; s 17(2): processing for the interest of sovereignty, integrity and security
of India, or prevention of offences, is exempt from the obligations imposed by Ch II (obligations of Data
Fiduciaries) and Ch III (rights of Data Principals).
35
Puttaswamy (n 13) para 645 (Kaul J), framing the State's duty in terms of a data fiduciary relationship and
observing that 'data as a commodity' necessitates a regime in which both State and private actors are bound by
accountability obligations enforceable through judicial review.
face cryptanalysis.'36 The whitepaper further prescribes that 'building crypto-agile systems starts

with using abstraction layers and modular libraries... to decouple cryptographic logic from

application code, enabling seamless algorithm swaps and hybrid testing.' 37 Transposing this

technical standard into the legal register, the argument is as follows: the 'reasonable security

safeguards' required of a Data Fiduciary under Section 8(4) cannot be assessed in isolation from

the known threat landscape. A safeguard that is technically adequate today but known to be

catastrophically inadequate within a foreseeable window — because the encryption underpinning

it will be rendered obsolete by quantum computing — cannot satisfy the standard of

reasonableness. Reasonableness, properly understood, is temporally and contextually sensitive: it

requires the fiduciary to implement safeguards adequate to protect data not only against current

threats but against foreseeable future ones. The HNDL threat makes the quantum risk current:

data collected today under classically-encrypted systems is, if subject to HNDL harvesting,

already at risk of future decryption.

The NIST's publication of FIPS 203, 204, and 205 in August 2024 38 — establishing quantum-

resistant cryptographic standards for key encapsulation and digital signatures — eliminates any

argument that PQC migration is technically premature or practically unavailable. The standards

exist; the algorithms have been validated; the migration pathway is defined. What is absent, in

India, is the legally binding mandate to implement them. The argument, then, is not that the State

must perform a technological miracle. It is that the State must perform a legal obligation — to
36
CERT-In and SISA, 'Transitioning to Quantum Cyber Readiness: A White Paper' (MeitY, Government of India,
2024) 43, describing crypto-agility as 'the ability to swiftly adapt cryptographic algorithms, parameters and
protocols' and prescribing it as 'vital for long-term security, especially in a post-quantum world where even PQC
schemes may eventually face cryptanalysis' (hereafter 'CERT-In Whitepaper').
37
ibid: 'Building crypto-agile systems starts with using abstraction layers and modular libraries... to decouple
cryptographic logic from application code, enabling seamless algorithm swaps and hybrid testing.'
38
Peter W. Shor, 'Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum
Computer' (1997) 26(5) SIAM Journal on Computing 1484, establishing that a sufficiently powerful quantum
computer could factor large integers in polynomial time, rendering RSA and ECC encryption obsolete.
implement, or mandate the implementation of, cryptographic standards adequate to the

foreseeable threat — that it already has the technical capacity to discharge. The Puttaswamy

proportionality framework, applied to the Section 17 exemptions in the context of the HNDL

threat, provides the constitutional compulsion for that obligation.39

2.6 Conclusion: The Constitutional Compulsion to Act


The constitutional framework established in this chapter may be summarised as follows. The

right to informational privacy is a fundamental right under Article 21, protected as an intrinsic

part of the right to life and personal liberty and carrying with it the full apparatus of

constitutional protection under Part III. That right encompasses the individual's reasonable

expectation of secrecy in encrypted communications — an expectation that is objectively

reasonable not as a static factual matter but as a function of the State's constitutional obligation to

maintain the conditions under which that secrecy is technically achievable. The Puttaswamy

four-pronged proportionality test provides the operative standard of constitutional review,

requiring that State action affecting the right be sanctioned by law, pursue a legitimate aim,

employ the least restrictive means available, and impose costs proportionate to the benefits

sought. State instrumentalities that collect and process personal data are Data Fiduciaries under

both the constitutional framework identified by Justice Kaul and the statutory framework of the

DPDP Act, and their fiduciary obligations are not satisfied by the mere absence of misuse —

they require affirmative protective action adequate to foreseeable threats. The concept of

cryptographic agility, derived from the CERT-In whitepaper and transposed into the legal

39
National Institute of Standards and Technology (NIST), FIPS PUB 203, 204, 205 (August 2024), standardising
CRYSTALS-Kyber (key encapsulation), CRYSTALS-Dilithium (digital signatures), and SPHINCS+ (hash-based
signatures) as quantum-resistant alternatives.
register, defines the minimum content of the 'reasonable security safeguards' obligation under

Section 8(4) in the quantum era.

Chapter 3 now applies this framework to the specific provisions of the DPDP Act — Section 17's

exemptions and Section 8(4)'s security safeguard standard — in the light of the HNDL threat. It

advances the central constitutional argument of this dissertation: that, assessed against the

Puttaswamy proportionality test, Section 17's broad and uncircumscribed exemptions already fail

the necessity and proportionality stricto sensu prongs — not as a contingent future possibility but

as an immediate and present constitutional deficiency. The quantum computing revolution has

not yet arrived. The constitutional obligation to prepare for it has.

You might also like