0% found this document useful (0 votes)
14 views45 pages

Privacy Challenges in the Digital Era

The document discusses the evolving concept of privacy in the digital era, highlighting its importance as a fundamental human right that faces numerous challenges such as surveillance, big data, and social media. It emphasizes the need for a balanced approach to protect individual privacy while embracing technological advancements. The document also outlines potential solutions, including privacy-enhancing technologies and regulatory measures, to safeguard personal information in the digital age.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
14 views45 pages

Privacy Challenges in the Digital Era

The document discusses the evolving concept of privacy in the digital era, highlighting its importance as a fundamental human right that faces numerous challenges such as surveillance, big data, and social media. It emphasizes the need for a balanced approach to protect individual privacy while embracing technological advancements. The document also outlines potential solutions, including privacy-enhancing technologies and regulatory measures, to safeguard personal information in the digital age.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Chapter-I

Introduction
CHAPTER-I
Introduction
“It used to be expensive to make things public and cheap to make them private. Now
it’s expensive to make things private and cheap to make them public.”
– Clay Shirky on ‘Privacy in Digital Space’

1.1. INTRODUCTION:

“Privacy is the right to be free from covert observation and to select when, how, and to
whom one's information is disclosed”1. Privacy is a timeless concept that has evolved
over the years, shaping both advantages and challenges for individuals. Due to
enhancement in technology, its scope has increased and include categories such as
physical, informational, decisional and dispositional.2

The concept of privacy is evident in numerous ancient texts of ‘Ramayana’3,


‘Mahabharata’4, ‘Grihya – Sutras’ and ‘Kautilya’‘s ‘Arthashastra- AVARANA’ was
used as a term which denotes existence of privacy- ‘Avarana’5 meant guard, shelter, or
shield. It also meant that women need to keep her face covered under the veil. The
concept of construction of houses originated from ancient ‘Hindu text’ i.e., ‘Grihya
Sutras’.

The intensity and complexity of life, attendant upon advancing civilization have
rendered necessary some retreat from the world, the man, under the reefing influence
of culture, has become more sensitive to publicity, so that solitude and privacy have
become more essential to the individual; but modern enterprises and intention have,
through invasion upon his privacy, subjected him to mental pain and distress, for greater
that could be inflicted by mere bodily injury.6

1
Lindsey Norman, An Overview of the Changing Data Privacy Landscape in India 919 (2018).
2
Payal Thaorey, “Informational Privacy: Legal Introspection in India” II ILI Law Review 160 (Winter
2019).
3
Ralph TH Griffith,(1826-1906) Translated into English Verse ‘Ramayana’.
4
Kisari Mohan Ganguli (trans.), The Complete Mahabharata in English (1883-1896).
5
Medha Bisht, Kautilya’s Arthashastra (2019).
6
Samuel D. Warren & Louis D. Brandeis, “The right to privacy” 4 Harvard Law Review 193 (1890).

Page | 1
Introduction

The right to privacy is a fundamental human right that is essential for the
protection of human dignity and autonomy7. It is also necessary for the development of
a democratic society that respects the ‘rule of law’. However, in the digital era, the right
to privacy faces numerous emerging issues and challenges that threaten its protection.8

The digital era has led to the widespread ‘collection, processing, and storage of
personal information’9. The collection and use of personal information have made the
protection of the right to privacy a critical issue. The right to privacy has been
recognized as a fundamental right by various international and regional instruments,
such as the 'UDHR', the 'ICCPR', and the 'ECHR'.10 These instruments provide that
individuals have the right to privacy encompasses respect for an individual’s private
and family life, home, and communication.

Surveillance is one of the most significant emerging issues and challenges to


the right to privacy in the digital era.11 Surveillance is the monitoring of an individual's
activities, behaviour, and communications. Surveillance can take place through various
means, such as ‘CCTV cameras, wiretapping, and internet surveillance’.12 The use of
surveillance technologies has increased significantly in recent years, and there are
concerns about the Impact of surveillance on individual privacy.

Big data is another emerging issue and challenge to the right to privacy in the
digital era.13 Big data refers to the vast amount of data that is generated by individuals
and organizations through their online activities. Big data analytics enables
organizations to study and forecast individual behaviors and preferences. However, the
use of Big data analytics raises concerns about the ‘protection of personal information’

7
Office of the United Nations High Commissioner for Human Rights, “The right to privacy in the
Digital Age” (India), available at: [Link]
DigitalAge/ReportPrivacyinDigitalAge/[Link] (last visited on March. 28,
2021).
8
Heather Briston et al., Rights in the Digital Era (2015).
9
Christina Akrivopoulou & Athanasios Psygkas, “Personal Data Privacy And Protection In A
Surveillance Era: Technologies And Practices” (2011).
10
European Court of Human Rights, European Convention on Human Rights, (India), available at:
[Link] (last visited on April. 21, 2021).
11
Adi Kuntsman & Esperanza Miyake, Paradoxes of Digital Disengagement: In Search of the Opt-Out
Button (2020), (India), available at: [Link]
search-gateway (last visited on April. 28, 2021).
12
Ibid.
13
Supra note 4.

Page | 2
Introduction

and the ‘potential for discrimination’.

The Internet of Things (IoT) is also an emerging issue and challenge to the right
to privacy in the digital era.14 The IoT refers to the interconnectedness of devices and
objects that are embedded with sensors and software. The use of IoT devices raises
concerns about the collection and use of personal information, as well as the ‘potential
for unauthorized access’ to personal information.15

Social media is another emerging issue and challenge to the right to privacy in
the digital era.16 Social media platforms allow individuals to share personal information
with a wide audience. The use of social media brings about concerns regarding the
safeguarding of personal information and the risk of unauthorized access to such data.

Online behavioral advertising is also an emerging issue and challenge to the


right to privacy in the digital era.17 Online behavioral advertising refers to the practice
of tracking an individual's online behavior to deliver targeted advertising. The use of
online behavioral advertising raises concerns about the protection of personal
information’ and the ‘potential for unauthorized access to personal information.18

Biometric data is another emerging issue and challenge to the right to privacy
in the digital era.19 Biometric data refers to the use of biological characteristics, such as
fingerprints, facial recognition, and iris scans, to identify individuals. The use of
biometric data raises concerns about the safeguarding personal information and the
potential for misuse.

Cybersecurity is also an emerging issue and challenge to the right to privacy in


20
the digital era. Cybersecurity involves protecting personal information from

14
Office of the Victorian Information Commissioner, “Internet of Things and Privacy - Issues and
Challenges” (2021), (India), available at: [Link]
organisations/internet-of-things-and-privacy-issues-and-challenges/ (last visited on May. 05, 2021).
15
Ibid.
16
Jiahong Chen, Regulating Online Behavioural Advertising Through Data Issues and Challenges 2–8
(Edward Elger publishing Limited, U.K.,2021).
17
Ibid.
18
Ibid.
19
Office of the Victorian Information Commissioner, “Biometrics and Privacy” (2020), (India),
available at: [Link] (last
visited on May. 18, 2021).
20
Supra note 11.

Page | 3
Introduction

unauthorized access, misuse, and disclosure. The use of cybersecurity measures is


essential for the ‘protection of personal information’ in the digital era.

Artificial Intelligence (AI) is also an emerging issue and challenge to the right
to privacy in the digital era.21 AI refers to the use of machines and algorithms to analyze
and predict individual behavior and preferences. The use of AI raises concerns about
the protection of personal information and the potential for discrimination.

Blockchain is another emerging issue and challenge to the right to privacy in


the digital era.22 Blockchain is a distributed ledger technology that is used to store and
share information securely”. The use of blockchain technology raises concerns about
the protection of personal information and the potential for ‘unauthorized access to
personal information’.23

The emerging issues and challenges to the right to privacy in the digital era are
complex and require careful consideration of the rights and interests of individuals, as
well as the needs of society as a whole. It is essential to have a balanced approach that
takes into account the benefits and risks of digital technologies.

To protect the right to privacy in the digital era, various measures have been
proposed. One approach is the development of privacy-enhancing technologies that can
protect personal information while still allowing for the benefits of digital technologies.
Privacy-enhancing technologies include ‘encryption, data minimization, and
differential privacy’.

Another approach is the development of privacy regulations and standards that


can ensure the Ensuring the ‘protection of personal information’ in the digital age is
crucial. The European Union's 'General Data Protection Regulation' (GDPR) 24 . An
example of a privacy regulation that provides individuals with control over their

21
National Security Commission on Artificial Intelligence (NSCAI), “Interim Report” 12 (Nov. 2019),
(India), available at: [Link]
for-Congress_201911.pdf (last visited on May. 22, 2021).
22
Mohammad Hossein Ronaghi & Mohammad Mosakhani, “The Effects of Blockchain Technology
Adoption on Business Ethics and Social Sustainability: Evidence from the Middle East” Environment,
Development and Sustainability (2021), (India), available at: [Link]
articles/PMC8352148/ (last visited on June. 05, 2021).
23
Id.
24
General Data Protection Regulation, 2016/679, 2016 O.J. of E.U. (L 119) 1.

Page | 4
Introduction

personal information and requires organizations to implement privacy safeguards.25

Education and awareness-raising are also essential for the protection of the right
to privacy in the digital era. Individuals need to be aware of their rights and
responsibilities concerning the protection of their personal information. They also need
to understand the risks and benefits of digital technologies and how to protect their
personal information.

The right to privacy is a fundamental human right that is essential for the
‘protection of human dignity and autonomy’.26 However, in the digital era, the right to
privacy faces numerous emerging issues and challenges that threaten its protection.
Surveillance, Big data, the Internet of Things, social media, online behavioural
advertising, biometric data, cybersecurity, artificial intelligence, and blockchain are all
emerging issues and challenges to the right to privacy in the digital era.

A balanced approach is necessary to ensure that the ‘benefits of digital


technologies’ are balanced with robust safeguards for privacy and security are realized
while still protecting the right to privacy. The protection of the right to privacy is
essential for the development of a democratic society that respects the rule of law and
human rights.27

It is important to acknowledge that the challenges facing the right to privacy in


the digital era are constantly evolving, and new issues may arise as technology
advances. Therefore, ongoing attention and proactive measures are needed to ensure
that the right to privacy is protected in the digital era.

In addition to the challenges and emerging issues discussed here, there are also
potential solutions that could help mitigate the threats to the right to privacy. For
example, privacy-by-design could be incorporated into the development of new
technologies to ensure that privacy considerations are integrated into their design from
the outset. Similarly, organizations could implement privacy Impact assessments to
identify and mitigate the privacy risks associated with their activities.

25
Id.
26
Supra Note 7.
27
Id.

Page | 5
Introduction

Another potential solution is the use of decentralized systems that allow


individuals to have greater control over their personal data. Blockchain technology, for
example, could provide a decentralized system for storing personal data that is both
secure and transparent. Such a system could provide individuals with greater control
over their personal data and reduce the risks associated with centralized storage.

It is also important to consider the role of governments in protecting the right to


privacy in the digital era. 28 Governments can play a vital role in regulating the
collection, use, and disclosure of personal information by private sector organizations.
They can also promote the development and adoption of privacy-enhancing
technologie’s and provide education and awareness-raising initiatives to help
individuals safeguard their personal information.

However, it is important to understand that government surveillance can also


pose a significant threat to the right to privacy.29 Therefore, governments must balance
their responsibility to protect national security with the protection of individual privacy
rights.

Therefore, the right to privacy in the digital era faces numerous emerging issues
and challenges, including surveillance, Big data, the Internet of Things, social media,
online behavioural advertising, biometric data, cybersecurity, artificial intelligence, and
blockchain. These challenges threaten the protection of the right to privacy, and a
balanced approach is needed to ensure that the benefits of digital technologies are
realized while still protecting this fundamental human right.

It is the responsibility of individuals, organizations, and governments to work


together to ensure that this fundamental human right is protected in the digital era.

The right to privacy is a fundamental right that is enshrined in the Constitution

28
Office of the United Nations High Commissioner for Human Rights, The right to privacy in the
Digital Age, (India), available at: [Link]
DigitalAge/ReportPrivacyinDigitalAge/[Link].(last visited on June. 19, 2021)
29
“Surveillance is a Fact of Life, So Make Privacy a Human Right,” The Economist (Dec. 13, 2019),
(India), available at: [Link]
life-so-make-privacy-a-human-right (last visited on June. 25, 2021).

Page | 6
Introduction

of India.30 However, in the digital era, the right to privacy faces numerous challenges
and emerging issues that threaten its protection. This thesis will also explore the
challenges and emerging concerns related to facing the right to privacy, the legal
framework for the protection of privacy in India, and the measures that can be taken to
protect the right to privacy in the digital era.

The digital era has brought numerous challenges and emerging issues to the
protection of the right to privacy in India.31 One of the most significant challenges is
the widespread use of biometric data for identification purposes. 32 The Indian
government has implemented the Aadhaar scheme, 33 which requires individuals to
provide their biometric data in order to access government services. 34 However,
concerns have been raised about the security and privacy of this data.

Another challenge facing the right to privacy in India is the use of surveillance
technologies by the government. The government has implemented various
surveillance programs, such as the ‘Central Monitoring System’ and the ‘National
Intelligence Grid’, 35 which allow for the interception and monitoring of electronic
communications.36 However, the use of these technologies raises concerns about the
protection of privacy and civil liberties.

Social media and online platforms also pose a significant threat to the right to
privacy in India. The use of online platforms for sharing personal information has
become ubiquitous, and the potential for misuse of this information is high. 37 The
‘Cambridge Analytica scandal’, which involved the misuse of Facebook data for

30
Vikas Kumar, “right to privacy in Digital Era: A Study with Indian Context” Legal Service India
(Dec. 28, 2020), (India), available at: [Link]
[Link] (last visited on June. 30, 2021).
31
Ibid.
32
Supra note 26.
33
Ibid.
34
Supra note 26.
35
“No Blanket Permission to Any Agency for Surveillance under Netra, Natgrid: Centre to HC,”
Economic Times, (India), available at: [Link]
permission-to-any-agency-for-surveillance-under-netra-natgrid-centre-to-
hc/articleshow/[Link]?from=mdr (last visited on July. 18, 2021).
36
Id.
37
Rahul Kumar, “Jurisprudence of right to privacy in India” SSRN Electronic Journal (2020).

Page | 7
Introduction

political purposes, highlighted the risks associated with the use of social media.38

The protection of privacy in India is governed by various legal frameworks. The


Constitution of India provides for the protection of the right to privacy as a fundamental
right. In 2017, the SC of India recognized the right to privacy as a fundamental right39.

After the landmark ‘Mrs. Gandhi's case’40, the Indian Constitution underwent
changes, and the SC repeatedly stated that 'Article 21'41 is the core of fundamental rights
in India, encompassing multidimensional aspects. Two crucial terms, "Life" and
"Freedom,"42 have been interpreted definitively to give 'Article 21' an extended scope.
The right to privacy, not explicitly mentioned in the Constitution, came into existence
as a result of this expansion.

Previously, Indian law only provided protection against physical threats.


However, as customary law evolved to address societal issues, it became clear that
protection was required not just for the physical self but also for the spiritual and
emotional selves. 43 As per the Indian Constitution, the Right to Life is one of the
fundamental rights, and "Article 21" is the cornerstone of this concept. It has broadened
its focus and given weight to two key terms, "life" and "freedom," which should be
interpreted very clearly. The right to privacy is one such right that emerged as a result
of 'Article 21' being expanded. The Supreme Court has distinguished many advantages
from ‘Article 21’, despite the fact that the Constitution expressly ‘does not grant any
benefit to privacy in that regard’.

In the past, the law in India would only offer ‘protection against physical
harm’44. It became clear that not only physical safety but also the protection of the
ethereal self, emotions, and intellect were necessary as the custom-based decree
evolved to address the problems that the general public faced. To this day, the Right to

38
Michael D. Shear et al., “Cambridge Analytica Scandal: What You Need to Know,” The New York
Times, (India), available at: [Link]
[Link] (last visited on July. 20, 2021).
39
Justice KS Puttaswamy (Retd.) & Anr. V. Union of India & Ors. (2017) 10 SCC 1.
40
Maneka Gandhi v. Union of India, AIR 1978 SC 597.
41
The Constitution of India, art. 21
42
J.N. Pandey, Constitution of India 271-357 (Central Law Agency, 2020).
43
Rahul Kumar, “Jurisprudence of right to privacy In India”, SSRN Electronic Journal (2020).
44
Id.

Page | 8
Introduction

Life has expanded to include the ‘right to liberty’, the protection of widespread
collective wealth, and all types of property, both insignificant and unique.45

The Court has suggested the advantage of privacy from 'Article 21' by
unraveling it in similitude with ‘Article 12’ and ‘Article 17’46. The "privacy rights" are
required by each of these broad reports. The "Indian Constitution" does not list the right
to privacy as a fundamental Right.

The scope of this issue was first raised in ‘Kharak Singh’s Case’47, which was
concerned with the legality of precise directions that allowed surveillance of
respondents.

With regards to surveillance, it has been held that observation, if meddlesome


and genuinely infringes on the protection of citizen, can encroach the opportunity of
development, ensured by ‘Articles 19(1)(d)’48 and ‘21’. Currently, talked about, 'Article
21' of the Indian Constitution specifies that “No person shall be deprived of his life or
personal liberty except according to procedure established by law”. The right to life
that is prized in "Article 21" has been liberally interpreted to encompass “more than
just surviving and living a life that is insignificant or animalistic. Accordingly, it en-
compasses all of the elements that contribute to a man's life being more "valuable, com-
plete, and worth living, and appropriate to security is one such right."

In the Maneka Gandhi49 case, A "Triple Test" was created for any legislation
that interfered with personal freedom. The legislation and process that permit
interfering with an individual's freedom and right of privacy should also be reasonable,
equitable, and correct—not specific, capricious, or onerous.50 The right to privacy is
now recognized as part of the 'Article 21' right to life and freedom. It is the right of
every citizen to protect his or her privacy about "family, marriage, reproduction,

45
Supra note 38.
46
The Constitution of India, art. 17.
47
1963 ALL. L. J. 711
48
The Constitution of India. art. 19 cl. 1(d).
49
Maneka Gandhi v. Union of India, AIR 1978 SC 597.
50
Aditya Verma, “right to privacy and RTI” (Central Information Commission, 2016), (India),
available at:
[Link]
Verma%20%20%281%29%20%281%[Link] (last visited on July. 25, 2021).

Page | 9
Introduction

parenthood, child behavior, and education, among other reasons." Anyone who
publishes anything about the aforementioned topics without the consent of the
individual in question runs the danger of suffering damage in real life.

The right to privacy is not specifically mentioned as a fundamental right in In-


dia's "Constitution." However, the Supreme Court has interpreted "Article 21" of the
Indian Constitution, which protects the Right to Life and personal liberty, to include
the right to privacy. The protection of one's spiritual and emotional self is linked to the
right to privacy, which is viewed as a multifaceted part of "Article 21."

In Kharak Singh's case51, the SC held right to privacy is part of the right to
protection of life and personal liberty guaranteed by 'Article 21'. The court equated the
right to privacy with the right to personal liberty. The right to privacy is ‘not an absolute
right’ and can be restricted if there is a compelling state interest, but such restrictions
must be proportionate and in accordance with the law.52

In addition to the Constitution, various laws have been enacted to protect


privacy in India. The “Information Technology (‘Reasonable Security Practices and
Procedures and Sensitive Personal Data or Information’) Rules”, 2011 53, provides for
the protection of sensitive personal data in the context of the use of ‘information
technology’. ‘The Aadhaar Act’, 201654, provides for the protection of biometric data
collected under the ‘Aadhaar scheme.’

'The Bharatiya Nyaya Sanhita' also contains provisions that protect privacy,
such as ‘Section 78’, 55 which criminalizes the stalking of women. 'The Right to
Information Act, 2005'56, also contains provisions that protect privacy by exempting

51
Supra Note 46.
52
Aditya Verma, right to privacy and RTI (Central Information Commission, 2016), (India), available
at: [Link]
20Verma%20%20%281%29%20%281%[Link] (last visited on July. 29, 2021).
[Link]
Verma%20%20%281%29%20%281%[Link].
53
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal
Data or Information) Rules, 2011, Notification No. G.S.R. 313(E), 25 Mar. 2011..
54
The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, No.
18 of 2016 (India).
55
The Bharatiya Nyaya Sanhita 2023, Sec. 78.
56
Right to Information Act, Act No. 22 of 2005, (India).

Page | 10
Introduction

certain types of information from disclosure.

To protect the right to privacy in the digital era, various measures can be taken.
One approach is the development of privacy-enhancing technologies that can protect
personal information while still allowing for the benefits of digital technologies.
Privacy-enhancing technologies include encryption, data minimization, and differential
privacy.57

Another approach is the development of privacy regulations and standards that


can ensure the protection of personal information in the digital era. The GDPR58 is an
example of a privacy regulation that provides individuals with control over their
personal information and requires organizations to implement privacy safeguards.

In the digital age, protecting the right to privacy also requires education and
awareness-raising. People must understand their rights and obligations with regard to
safeguarding their personal data. Along with learning how to safeguard their personal
data, they must also comprehend the advantages and disadvantages of digital
technologies.

In addition to these measures, there is also a need for ‘greater accountability’


and transparency in the use of personal information. Organizations that collect and use
personal information should be held accountable for their Actions, and individuals
should have the right to know how their personal information is being used.

In the digital age, privacy has become an increasingly important concern for
individuals around the world. As people rely more on technology for communication,
commerce, and social interaction, the potential for their personal data to be exploited
or misused by malicious Actors has grown significantly. In response, many countries
have implemented legal provisions designed to protect the privacy of their citizens in
the digital space.

One of the most important legal instruments as already mentioned above as far

57
"Privacy Enhancing Technologies (pets)" Wiley Online Library, (India), available at:
[Link] (last visited on August. 20, 2021).
58
General Data Protection Regulation, 2016/679, 2016 O.J. (L 119) 1.

Page | 11
Introduction

as this is concerned is the 'General Data Protection Regulation' (GDPR),59 which was
introduced by the European Union in 2018. The GDPR applies to all companies that
process the personal data of EU citizens, regardless of where those companies are
based. It sets out a number of important rights for individuals, including the right to
access and delete their personal data, the right to know how their data is being used,
and the right to object to the processing of their data in certain circumstances. The
GDPR also imposes significant penalties on companies that fail to comply with its
provisions, with fines of up to 4% of a company's global revenue.60

Many other countries have also implemented data protection laws that offer
similar protections to those found in the GDPR. For example, the 'California Consumer
Privacy Act' (CCPA)61 was introduced in 2020 and gives California residents the right
to know what personal information is being collected about them, the right to request
the deletion of their information, and the right to opt-out of the sale of their information.
The CCPA also includes penalties for companies that fail to comply with its provisions,
with “fines of up to ‘$7,500’ per violation”.62

In addition to data protection laws, as to this countries have also introduced laws
to protect the privacy of individuals in specific contexts, such as ‘communications and
online Activity’. For example, the ‘UK's Investigatory Powers Act’ restricts the
collection and retention of individuals online Activity and communication data by
public authorities, and requires them to obtain a warrant before accessing this
information. Similarly, the 'California Consumer Privacy Act' (ECPA)63 in the US sets
out rules governing the interception of electronic communications, including email and
phone calls.

Another important aspect of privacy protection in the digital space is the


regulation of online advertising and tracking. Many countries have introduced laws or

59
Id.
60
Supra note 54.
61
California Civil Code, Secs. 1798.100–1798.199 (West 2021).
62
"California Consumer Privacy Act (CCPA) fines and consumer damages," Clarip, (India), (India),
available at: [Link]
Intentional%20violations%20of%20the%20California,violations%20is%20%242500%20per%20vi
olation (last visited on Aug. 25, 2021).
63
Electronic Communications Privacy Act of 1986, Pub. L. No. 99-508, 100 Stat. 1848 (codified as
amended at 18 U.S.C. Secs. 2510–2523).

Page | 12
Introduction

regulations aimed at limiting the use of personal data for advertising purposes and
giving individuals greater control over how their data is used in this context. For
example, the ePrivacy Regulation, which is currently being developed by the EU, would
require companies to obtain explicit consent from individuals before using their data
for online advertising, and would restrict the use of cookies and other tracking
technologies.64

The legal provisions around the globe available to protect privacy in the digital
space are varied but all aim to protect personal data from exploitation and misuse. Data
protection laws, specific context-based laws, and regulation of online advertising and
tracking are some of the measures that nations have adopted diverse strategies to
safeguard their citizens privacy. As technology continues to evolve, it is likely that these
legal provisions will also need to adapt to ensure that individuals privacy rights are
protected in the ever-changing digital landscape.

In the digital era, where individuals personal information is easily accessible


and the boundaries of privacy are constantly shifting, the right to privacy has become
an increasingly pressing issue. With the rise of social media, smart devices, and other
technological advancements, individuals personal data is being collected and used in
ways that were once unimaginable. As a result, new challenges and issues have emerged
in the protection of privacy rights65. This thesis seeks to explore the emerging issues
and challenges related to the right to privacy in the digital era. Specifically, this thesis
will examine the ways in which personal data is collected, stored, and used by
companies and governments, the challenges of securing digital information, and the
legal and ethical issues surrounding privacy rights in the digital age. The digital age has
ushered in an unprecedented level of convenience and connectivity, bringing people
from all corners of the world closer together than ever before. However, this digital
revolution has also posed significant challenges to traditional notions of privacy. 66
personal data is now more accessible than ever, and the potential for abuse is alarmingly
high. As a result, the right to privacy has emerged the another most hotly debated topics

64
"EU's ePrivacy Regulation: 2022 Updates," [Link], (India), available at:
[Link] (last visited on Sep. 06, 2021).
65
"India has recognized the right to privacy as a fundamental right in 2017," The Indian Express (2020).
66
"India does not currently have a comprehensive data protection law," The Hindu (2019).

Page | 13
Introduction

in recent years. In this thesis, we will explore the emerging issues and challenges related
to the right to privacy in the digital era.

The term privacy can be defined as the “ability to control access to one's
personal information” 67 . However, as technology has advanced, this definition has
become increasingly complex. With the advent of social media, search engines, and
‘smart devices’, individuals now generate massive amounts of personal data on a daily
basis. This data is often collected, stored, and used by companies and governments for
various purposes, including targeted advertising, national security, and law
enforcement. The question of how to balance the benefits of technology with the need
to protect individual privacy rights lies at the heart of the issue.

A key concern regarding privacy in the digital age is the gathering and
utilization of personal information’. Companies such as Facebook and Google collect
vast amounts of personal data from their users, often without their explicit consent. This
data is then used to create targeted advertising campaigns, which can be highly effective
at influencing consumer behavior. However, this practice has raised concerns about the
use of personal data for commercial gain, as well as the potential for this data to be used
for more nefarious purposes, such as identity theft or cyber attacks.

Another challenge related to privacy in the digital era is the issue of


cybersecurity. As more and more data is stored digitally, the risk of cyber attacks and
data breaches increases. This not only puts individuals' personal information at risk but
also has broader implications for national security and the economy. The challenge of
securing ‘digital information’ is complex and requires a multifaceted approach that
involves both technical and policy-based solutions68.

The collection and personal information represent a significant challenge to


privacy in the digital era. in the debate over privacy in the digital age. Laws and
regulations related to privacy are often vague or outdated, and the interpretation of these
laws in the context of new technologies is often unclear. Additionally, the use of

67
Ibid.
68
Rajesh Sharma, “Cybersecurity in India: Problems and Perspectives,” in Tuhin Halder Chowdhury et
al. (eds.), Cybersecurity and Data Privacy: Concepts, Methodologies, Tools, and Applications 143–
168 (2020).

Page | 14
Introduction

personal data by governments for national security purposes has raised questions about
the balance between individual privacy rights and public safety. Finally, there are
ethical considerations related to the use of personal data for commercial gain, as well
as concerns about the potential for bias and discrimination in the use of this data.69

The ‘lack of transparency’ in the ‘collection and use of personal data’ is a major
concern for individuals. The terms of service and privacy policies of online services are
often written in complex legal jargon, making it difficult for users to understand what
they are agreeing to when they sign up for these services. Many individuals may not be
aware of the extent to which their personal data is being “collected, stored, and used by
these companies”. This lack of transparency can undermine trust in online services and
erode individuals' confidence in their ability to control their personal information. The
right to privacy is not absolute and must be balanced against other rights and interests.70
For example, in the case of national security, the need to protect citizens from harm
may justify the collection and use of personal data. However, this justification must be
carefully balanced against the right to privacy and other civil liberties. The need for
transparency and accountability is crucial to ensure that any infringement of privacy
rights is proportionate, necessary, and lawful.

One area of work is the development of policies and regulations that address the
challenges of privacy in the digital age. This might involve working with governments,
non-profits, or industry groups to draft new laws or guidelines that protect individual
privacy rights while still allowing for the benefits of digital technology71. This could
include advocating for clearer and more up-to-date privacy laws, encouraging
companies to adopt best practices for data collection and use, or pushing for greater
transparency in how personal data is collected and used.

Another area of work is the development of technical solutions to help protect


privacy in the digital era. This might involve creating new tools or systems that help
individuals control their personal data, such as secure messaging apps, encryption tools,

69
N. Sharma, “right to privacy in Digital Age: An Indian Perspective” 7 International Journal of
Research & Analytical Reviews 146 (2020).
70
A. Singh, “Privacy Protection in Digital Age: A Critical Analysis of Indian Laws and Policies” 8
International Journal of Law 47, 59 (2021).
71
Ibid.

Page | 15
Introduction

or privacy-focused web browsers. It could also involve developing new ways to secure
personal data, such as using blockchain technology or other innovative solutions.
Technical work might involve collaborating with software developers, cybersecurity
experts, or other technical professionals.

The consequent area of work is education and advocacy around the issue of
privacy in the digital age. This might involve raising awareness among the public about
the risks and challenges of digital privacy, assisting individuals in comprehending their
rights and responsibilities in this area, or advocating for greater protections for privacy
rights. This could include developing educational materials, organizing workshops or
events, or partnering with other organizations to raise awareness72.

Another area of work is legal and ethical analysis of privacy issues in the digital
age. This might involve researching the legal and ethical implications of new
technologies or practices related to ‘data collection and use, analyzing court cases or
other legal decisions related to privacy’, or developing ethical guidelines for the
personal information. This work might be conducted by ‘legal scholars, ethicists, or
other researchers’.

Finally, there is work to be done in developing business strategies that account


for ‘privacy concerns in the digital age’. This might involve working with companies
to develop privacy-focused business models or products, analyzing the risks and
opportunities associated with data collection and use, or consulting with companies on
how to comply with privacy regulations. This work might be conducted by management
‘consultants, marketing professionals, or other business experts’. Overall, there are
many different areas of work that relate to the right to privacy in the digital era. From
policy development to technical solutions, education and advocacy to legal and ethical
analysis, there is a wide range of potential work that can be done to address the
challenges and opportunities presented by the digital age73.

The right to privacy in the digital era is a complex and multifaceted issue that
poses significant challenges to traditional notions of privacy. In this thesis, we will

72
"However, there are still deficiencies in the current legal and regulatory mechanisms for privacy
protection in the digital space in India." (Singh, 2021, p. 47).
73
Supra note 4

Page | 16
Introduction

explore the emerging issues and challenges related to this topic, including the collection
and use of personal data, cybersecurity, legal and ethical issues. By understanding these
challenges, we can work towards developing solutions that balance the benefits of
technology with the need to protect individual privacy rights.

In today's digital age, privacy has become a fundamental right that is


increasingly vulnerable to violations. With the rise of the ‘internet, social media, and
other digital technologies, individuals are constantly generating and sharing personal
data online’. This raise concerns over how such information is collected, stored, and
used, and whether it is adequately protected from misuse or abuse. As a result, there
has been growing interest in understanding the legal provisions and regulatory
mechanisms that are available to safeguard privacy in the digital space74.

The question raised is critical as it requires a comprehensive understanding of


the existing legal framework governing privacy in the digital realm. It will examine
relevant national and international laws and regulations that address privacy in the
digital space, such as the 'General Data Protection Regulation' (GDPR) in the European
Union, the Privacy Act in the United States, and 'The Digital Personal Data Protection
Act, 2023' in India75. The thesis will examine the evolution of these laws over time and
their ‘impact on safeguarding privacy’ in the digital era.

These questions are essential as it requires an examination of the mechanisms


and processes that are available to deal with ‘privacy violations in the digital space’. In
addition to examining legal provisions, the study evaluates the role of regulatory
authorities, including the ‘Information Commissioner’s Office’ (ICO)76 in the UK, the
‘Federal Trade Commission (FTC)’77 in the US, and the ‘Data Protection Authority
(DPA)’ in India. These bodies are pivotal in addressing “privacy breaches, enforcing
compliance, and upholding individuals’ rights”. The research will analyze their

74
Theresa Payton & Ted Claypoole, Privacy in the Age of Big data: Recognizing Threats, Defending
Your Rights, and Protecting Your Family (Rowman & Littlefield 2014).
75
Dan Jerker B. Svantesson & Roger Clarke, European Data Protection Law: Corporate Compliance
and Regulation (Kluwer Law International 2018).
76
ICO, “Your Data Matters” (2021), (India), available at: [Link] (last
visited on Sep. 20, 2021).
77
FTC, “Privacy and Security” (2021), (India), available at: [Link] (last
visited on Sep. 26, 2021).

Page | 17
Introduction

operational mechanisms, challenges, and the need for reforms to enhance their
efficiency, especially in the context of a globally interconnected digital economy.78.
This thesis will also investigate how these regulatory mechanisms are enforced, what
challenges they face, and what measures can be taken to strengthen them. Technologies
such as Big data analytics, Artificial Intelligence (AI), and ‘machine learning (ML)’
have revolutionized how personal data is collected, processed, and utilized. Although
these innovations provide many advantages, they also introduce risks that jeopardize
personal privacy. This thesis investigates the Impact of such technologies on privacy
protection and assesses whether existing legal mechanisms are equipped to manage
these risks while safeguarding fundamental rights.

This thesis aims to provide a comprehensive analysis of the legal provisions and
regulatory mechanisms that are available to protect privacy in the digital space. By
addressing these research questions, this thesis will contribute to a better understanding
of the challenges and opportunities that exist in safeguarding privacy in the digital era.

In the digital age, privacy rights have become a critical issue, with individuals
increasingly using digital technologies to communicate, conduct business, and engage
in social interactions. Governments and regulatory bodies around the world have put in
place legal and regulation, this thesis seeks to contribute to a better understanding of
the legal and regulatory frameworks in place to protect privacy rights in the digital age
and offer insights into how these frameworks can be improved to better safeguard
individuals' privacy rights in the digital speculator frameworks to protect individuals'
privacy rights in the digital space79. However, there are concerns that these frameworks
may not be sufficient to address the challenges posed by the rapidly evolving digital
landscape. Emerging risks such as deepfakes and cross-border data flows further
complicate privacy enforcement in the digital space. This thesis highlights these risks
and explores strategies to mitigate them through innovative regulatory solutions and
international collaboration. A comparative analysis of India’s privacy framework with
those of the United States and the European Union will help identify gaps and propose

78
DPA, “What is a Data Protection Authority?” (India), available at: [Link]
edpb/board/members_en (last visited on Oct. 03, 2021).
79
Peter Nemitz & Paul Burgess (eds.), The right to privacy in the Digital Age (Springer 2014).

Page | 18
Introduction

actionable improvements to strengthen India’s approach.

This thesis aims to explore the legal and regulatory mechanisms in place to
protect privacy rights in the digital space, with a particular focus on the digital context.
The thesis will address the research questions of what legal provisions are available to
protect privacy in digital space, and whether there are any regulatory mechanisms
available to address privacy violations in digital space80. The thesis will also assess the
current legal and regulatory mechanisms in place to protect privacy rights in the digital
space and identify any deficiencies in the Indian mechanisms. Additionally, the thesis
will undertake a comparative analysis with the Eurpean Union and United States legal
and regulatory mechanisms to evaluate the potential for improvement in the Indian
mechanisms. This thesis seeks to answer critical research questions, offering an in-
depth understanding of the challenges and opportunities related to privacy rights in the
digital age. It seeks to offer insights into how existing legal and regulatory frameworks
can be enhanced to better protect privacy while fostering technological progress. This
research posits that existing privacy laws, including the Digital Personal Data
Protection Act of 2023 in India, are inadequate in safeguarding individuals rights
against emerging technological advancements such as “Big data' analytics, artificial
intelligence, surveillance technologies, and transnational data exchanges”.
Consequently, there is a pressing need for more comprehensive and globally aligned
regulatory frameworks. Through an exploration of critical research questions, this study
aims to deliver an in-depth analysis of the issues and opportunities linked to privacy
rights in the digital age. It also seeks to recommend ways to strengthen current legal
and policy structures to enhance privacy protections while encouraging technological
innovation. The research will particularly focus on the impact of widespread
surveillance systems and their potential to encroach on individual privacy. Moreover,
it will evaluate the practicality of incorporating privacy-centric technologies into
surveillance practices to achieve a balance between ensuring security and safeguarding
personal freedoms.

Overall, this thesis aims to enhance the understanding of the legal and regulatory
frameworks in place to protect privacy rights in the digital age and offer insights into

80
Amitai Etzioni, The Limits of Privacy (Basic Books, New York, 1999).

Page | 19
Introduction

how these frameworks can be improved to better ‘safeguard individuals privacy rights
in the digital space’.

The rapid evolution of digital technologies has brought significant challenges


to the concept of privacy, a cornerstone of individual autonomy and democratic
societies. This thesis explores how the notion of privacy has ‘developed in the digital
era and examines its implications for personal freedoms and governance’. The study
undertakes a critical examination of legal frameworks such as the European Union’s
General Data Protection Regulation81, India’s ‘Digital Personal Data Protection Act,
2023’82, and the US’ Privacy Act83. By analyzing these regulatory systems, the research
seeks to assess their adequacy in tackling the multifaceted issue.

IDENTIFICATION OF PROBLEM

The rapid advancement of information technologies and the proliferation of digital


spaces have significantly heightened concerns about the right to privacy. In an era
where personal data is continuously collected, processed, and shared, individuals face
unprecedented threats to their privacy.84 The right to privacy, fundamental for personal
autonomy and dignity, is increasingly vulnerable to misuse by both private entities and
governments. 85 Despite existing legal frameworks, numerous instances of data
breaches, unauthorized surveillance, and misuse of personal information highlight the
inadequacies of current protections.

The core issue is the serious threat to individual and informational privacy posed
by emerging digital technologies. 86 Although there is a wealth of literature on data
protection and privacy, most of it concentrates on particular topics, such the effects of
specific technology or the efficacy of particular legislation. In the Indian context, there
is a dearth of thorough analysis of the overall efficacy of the legal procedures in place

81
General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, Article 1, Official Journal
of the European Union (2016)
82
The Digital Personal Data Protection Act, 2023, No. 22, Acts of Parliament, 2023 (India).
83
Privacy Act, 1974, 5 U.S.C., (United States).
84
SLP (C) 804/2017
85
Pegasus spyware and related privacy concerns: "The use of spyware like Pegasus has raised
significant debates about digital privacy, building on earlier controversies involving programs like
CMA and PRISM."
86
United States Constitution, Amendment IV.

Page | 20
Introduction

to protect privacy against the emergence of digital technology 87 . This disparity


emphasizes the necessity of analyzing these processes holistically in order to spot flaws
and provide solid fixes.

LITERATURE REVIEW

These scholarly works collectively provide a rich foundation for understanding the
complexities of digital privacy. They highlight the interplay between technology, legal
frameworks, and ethical considerations, offering valuable insights into creating a
balanced and forward-thinking approach to privacy governance in the digital age. Each
contribution underscores the urgency of evolving privacy norms to keep pace with
technological advancements, ensuring that individual rights and societal progress
coexist harmoniously.

The researcher has consulted cyber law resources and books that tackle the risks
linked to with ‘internet usage’, noting that these risks vary depending on factors such
as “connectivity method, hardware type, security devices, and the nature of the user”
e.g., “educational institutions, government agencies, businesses, or private homes”88.

In this context, the evaluation of the literature in the following pages will look
at how different studies have approached the many facets of the subject of privacy
protection in India.

The landmark case ‘Justice K.S. Puttaswamy (Rtd.) and Anr. v. Union of India
& Ors’. 89 provided significant insights into the right to privacy in India. The SC
recognized ‘privacy as a fundamental right’ under 'Article 21' of the Indian
Constitution. The Court emphasized that an individual’s right to control their ‘personal
data and manage their personal and digital life’ is essential to their overall right to
privacy.

The ‘Report of the Committee of Experts 90 , chaired by Justice B.N.

87
Privacy rights rooted in religious texts: "Scholars have identified proto-privacy rights in texts such as
the Qur’an, sayings of Mohammad, and the Old Testament," see Privacy and Human Rights: An
International Survey of Privacy Laws and Developments 5 (2002).
88
Dr. Farooq Ahmad, Cyber Law in India 305 (New Era Law Publications, Delhi, 2nd edn.,2005).
89
AIR 2017 SC 4161
90
Government of India, “Report on the Data Protection Law” (2018)

Page | 21
Introduction

Srikrishna, highlighted key ‘data protection challenges’ in India and suggested


approaches to address these issues. The report also offered recommendations for the
central government, suggesting principles for a potential data protection framework in
India, along with a ‘draft data protection bill’.

‘Article 12’ of the UDHR of 1948 outlines privacy rights related to personal
space and communication, stating that no one should face arbitrary interference with
their “privacy, family, home, or correspondence, nor be subjected to attacks on their
honour or reputation”. It further guarantees legal protection against such
interferences91.

Issues related to internet privacy are also addressed in the 'United Kingdom’s
Data Protection Act of 1998', enacted on July 16, 1998, to implement the European
Union’s Data Protection Directive. This law has been pivotal in addressing privacy
matters in Great Britain92.

In 2018, the European Union introduced the 'General Data Protection


Regulation'93 (GDPR), which reinforced key privacy principles, ensuring that privacy
rights are safeguarded through stringent data protection standards.

The book Cybersecurity and Data Laws of the Commonwealth94 by Robert


Walters provides a comprehensive comparison of data protection legislation in the UK
and other Commonwealth nations. It delves into the practical aspects of ‘inter-state data
agreements’, which are essential for facilitating secure data flows between nations.
Additionally, the book significantly contributes to the broader understanding and
analysis of ‘data protection laws’ across Commonwealth countries, supporting ongoing
research and dialogue in this evolving field.

91
Universal Declaration of Human Rights adopted and proclaimed by General Assembly resolution
217A(III) of December 10, 1948.
92
Nandan Kamath (ed.), Law Relating to Computers, Internet and E-Commerce 380 (Universal Law
Publishing Co. Pvt. Ltd., Delhi, 2000).
93
General Data Protection Regulation, European Union (India), available at: [Link]
gdpr/ (last visited on Nov. 10, 2021).
94
R. Walters, Cybersecurity and Data laws of the Commomwealth: International Trade, investment and
arbitration (Springer Nature 2023)

Page | 22
Introduction

The book Cyber Security, Artificial Intelligence, Data Protection & the Law95
by Robert Walters and Marko Novak offers a comprehensive examination of the
evolving landscape of data protection law in the context of emerging technologies,
particularly ‘cyber security’ and Artificial Intelligence (AI). This work stands out for
its critical evaluations and guidance across various branches of ‘data protection law’,
making it a valuable resource for “legal scholars, practitioners, and policymakers
alike”.

Julie M. Robillarda , Tanya L. Fenga , Arlo B. Sporna , Jen-Ai Laia , Cody


Loa , Monica Taa , Roland Nadler (2019)96 talks about, a different perspective on
objective to assess the “availability, readability, and privacy-related content” of the
privacy policies and terms of agreement of mental health apps available through
popular digital stores.

Michael Arnheim’s book “The Handbook of Human Rights Law: An


Accessible Approach to the Issues and Principles”, published by Kogan Page Ltd.
in London and Sterling, USA, in 2004 97 , focuses on the intersection of human
resources and the law within the framework of ‘European’ and ‘UK laws’. This study
discusses in detail both Article 10 of the ‘Human Rights Act’ of ‘1998’ and ‘Article 8’
of the “European Convention for the ‘Protection of Human Right’” and ‘Fundamental
Freedoms’, 1950. Both of these articles discuss the right to privacy as it relates to UK
law.

Mira Swaminathan and Arindrajit Basu, Surveillance and Data


Protection: Threats to Privacy and Digital Security, (2020-2021)98 The Centre for
Internet & Society is a study on surveillance and data protection as part of the Centre
for Internet & Society’s Report on digital civic space in India, the study examines the
effects of policy and legal frameworks on digital rights for Indian civil society. The

95
Robert Walters and Marko Novak , Cyber Security, Artificial Intelligence, Data Protection & the Law
(Springer Nature 2021)
96
Julie M. Robillard et al., “Emerging Ethical and Privacy Concerns in AI Applications” 10(4)
Frontiers in Computational Neuroscience 1 (2019).
97
Michael Arnheim, The Handbook of Human Rights Law: An Accessible Approach to the Issues and
Principles (Kogan Page Ltd. 2004).
98
Mira Swaminathan and Arindrajit Basu, Surveillance and Data Protection: Threats to Privacy and
Digital Security, (2020-2021).

Page | 23
Introduction

report covers the Design and Impact of Surveillance technology, Domestic Laws and
International Standard.

Hyman Gross’s book “Privacy its Legal Protection,” published in 197699. It


is impossible to secure the physical infiltration of private goods in private spaces, and
there are no effective restrictions to prevent their exposure or transmission. Protecting
privacy and ensuring that individuals live decent lives are the two goals of society.
These two interests must be balanced for society to operate effectively.

"Securing Rights: Legal Frameworks for Privacy and Data Protection in


the Digital Era" (2023)100: This paper, published in the Law Research Journal, offers
a deep dive into the legal frameworks surrounding privacy and data protection in the
digital age. It discusses international treaties, national legislation, and regulatory
challenges, making it a crucial read for understanding the legal complexities of privacy
in today's digital landscape.

"Constitutional Law in the Digital Age: Addressing Privacy and


Cybersecurity Challenges" (2023) 101 : This article explores the challenges
constitutional law faces in the digital age, particularly concerning privacy and
Cybersecurity. It emphasizes the need for robust data protection laws, surveillance
oversight, and international cooperation to safeguard privacy rights.

"Ethical Dilemmas and Privacy Issues in Emerging Technologies: A


Review" (2023)102 - This article, published in the Sensors journal, explores the ethical
and privacy challenges posed by emerging technologies like AI, IoT, and Big data. It
discusses how these technologies Impact privacy, emphasizing the need for robust
ethical standards and regulatory frameworks to protect personal data.

"Digital Technologies: Tensions in Privacy and Data" (2023)103 - Published


in the Journal of the Academy of Marketing Science, this paper examines the tensions
between firms' use of digital technologies for data sharing and monetization, and the

99
Hyman Gross, Privacy: Its Legal Protection (Oceana Publications, N.Y., 1976).
100
Securing Rights: Legal Frameworks for Privacy and Data Protection in the Digital Era, (2023).
101
Constitutional Law in the Digital Age: Addressing Privacy and Cybersecurity Challenges, (2023).
102
Ethical Dilemmas and Privacy Issues in Emerging Technologies: A Review, (2023).
103
Digital Technologies: Tensions in Privacy and Data, (2023).

Page | 24
Introduction

privacy risks these practices pose to consumers. It categorizes privacy into information,
communication, and individual privacy, and discusses how each is affected by
corporate data strategies.

"A Key Review on Security and Privacy of Big data104: Issues, Challenges,
and Future Research Directions" (2023) - This review in the Signal, Image, and Video
Processing journal addresses the security and privacy issues associated with Big data.
It highlights the challenges in protecting data privacy in the context of large-scale data
analytics and suggests future research directions to enhance privacy-preserving
techniques.

Bernadette Kamleitner and Vince Mitchell, Your Data Is My Data: A


Framework for Addressing Interdependent Privacy Infringements, Journal of
Public Policy & Marketing,. Bernadette Kamleitner and Vince Mitchell (2019)105
has talk about how everyone holding personal information about others. Each person’s
privacy critically depends on the interplay of multiple actors. In an age of technology
integration, this interdependence of data protection is becoming a major threat to
privacy. Current regulation focuses on the sharing of information between two parties
rather than multiactor situations.

"Privacy-Preserving Collaborative Model Learning106: The Case of Word


Vector Training" (2023) - Featured in IEEE Transactions on Knowledge and Data
Engineering, this paper presents approaches for privacy-preserving collaborative
learning, focusing on protecting sensitive data during the training of machine learning
models.

"Privacy in the Digital Age: A Review of Information Privacy Research in


Information Systems" 107 - This journal article from JSTOR offers a thorough
examination of privacy issues in the digital era, with a particular focus on information
systems. It explores the challenges that arise from the rapid advancement of digital

104
A Key Review on Security and Privacy of Big data, (2023).
105
Bernadette Kamleitner & Vince Mitchell, “Your Data Is My Data: A Framework for Addressing
Interdependent Privacy Infringements” 38(1) Journal of Public Policy & Marketing 43 (2019).
106
Privacy-Preserving Collaborative Model Learning, (2023).
107
France Bélanger and Robert E. Crossler, “Privacy in the Digital Age: A Review of Information Privacy
Research in Information Systems”,35 MIS Quarterly,2011

Page | 25
Introduction

technologies and their implications for privacy rights.

"Efficient Privacy Preservation of Big data for Accurate Data Mining"


(2023) 108 - Published in Information Sciences, this research explores algorithms
designed to ensure privacy while maintaining the accuracy of data mining in Big data
environments.

"Efficient and Secure Big data Storage System with Leakage Resilience in
Cloud Computing" (2023)109 - This article in Software Computing discusses a secure
system for Big data storage in the cloud, addressing potential data leakage and privacy
concerns.

Proceedings from the International Seminar on "right to privacy in Digital


Era – Challenges and Solutions" 110 - Organized by the Kerala Law Academy in
December 2022, this seminar brought together legal scholars and practitioners to
discuss the evolving challenges to privacy in the digital age. The proceedings cover a
range of topics, including the Impact of AI, data protection laws, and the tension
between national security and individual privacy rights.

"Privacy and Data Protection in the Era of Big data: Balancing Security
and Efficiency" (2023) 111 - This book discusses the balance between maintaining
privacy and achieving efficiency in Big data systems, with a focus on the legal and
ethical implications of data protection.

"Consumer Privacy in the Digital Economy: Legal and Technological


Challenges" (2023) 112- This book examines the challenges of protecting consumer
privacy in the digital economy, exploring both legal frameworks and technological
solutions to safeguard personal data.

“Privacy by Design: A Counterfactual Analysis of Google and Facebook

108
Efficient Privacy Preservation of Big Data for Accurate Data Mining, (2023).
109
Efficient and Secure Big Data Storage System with Leakage Resilience in Cloud Computing, (2023).
110
Proceedings from the International Seminar on "right to privacy in Digital Era – Challenges and
Solutions."
111
Privacy and Data Protection in the Era of Big Data: Balancing Security and Efficiency, (2023).
112
Consumer Privacy in the Digital Economy: Legal and Technological Challenges, (2023).

Page | 26
Introduction

Privacy Incidents” by Ira S. Rubinstein and Nathaniel Good113 critically examines


privacy lapses involving major technology companies through the lens of "Privacy by
Design." The authors analyze incidents involving Google and Facebook, emphasizing
that these breaches could have been mitigated or avoided if privacy principles had been
embedded from the inception of these technologies. Their work highlights the need for
anticipatory governance frameworks that integrate privacy safeguards proactively,
promoting user trust and accountability.

Frederik Zuiderveen Borgesius, Jonathan Gray, and Mireille van Eechoud,


in their work “Open Data, Privacy, and Fair Information Principles: Towards a
Balancing Framework, explore the complex relationship between open data
initiatives and privacy protections”114. Their study underscores the tension between
public transparency and individual privacy, advocating for a framework that adheres to
Fair Information Practices (FIPs). The authors propose balanced approaches to ensure
that open data policies do not inadvertently compromise personal information,
providing practical solutions for harmonizing innovation and privacy in governance and
business applications.

In The Right to Contest AI, Margot E. Kaminski and Jennifer M. Urban


investigate the “legal and ethical implications of automated decision-making
systems powered by artificial intelligence” 115 . They discuss the regulatory
mechanisms available under frameworks like Europe’s GDPR, which grants
individuals the right to challenge unfair AI-based decisions. The authors stress the need
for more stringent oversight and transparent systems to address biases and inequalities
inherent in many AI technologies. Their work is pivotal in shaping discussions about
accountability and fairness in the rapidly evolving AI landscape.

Daniel J. Solove, in his work “Privacy Self-Management and the Consent


Dilemma, addresses the limitations of consent-based privacy frameworks”116- The

113
Id.
114
Ira S. Rubinstein & Nathaniel Good, “Privacy by Design: A Counter factual Analysis of Google and
Facebook Privacy Incidents”, 29 Berkeley Tech. L.J. 1333 (2014).
115
Margot E. Kaminski & Jennifer M. Urban, “Legal and Ethical Implications of Automated Decision-
Making Systems Powered by Artificial Intelligence”, 11 Colum. Sci. & Tech. L. Rev. 29 (2019).
116
Daniel J. Solove, “Privacy Self-Management and the Consent Dilemma”, 126 Harv. L. Rev. 1880
(2013).

Page | 27
Introduction

article argues that expecting individuals to manage their privacy effectively through
consent mechanisms is impractical due to the complexity of data practices and the
overwhelming nature of privacy policies. Solove advocates for systemic reforms that
reduce reliance on individual consent and instead enforce organizational accountability,
providing a pragmatic approach to privacy governance in an increasingly data-driven
world.

Ashwin Karale’s- “The Challenges of IoT: Addressing Security, Ethics,


Privacy, and Laws delves into the multifaceted implications of the Internet of
Things” 117 . Karale draws attention to the ethical conundrums and security flaws
brought about by the interconnection of gadgets that gather and exchange enormous
volumes of data. The report urges the creation of a thorough regulatory framework to
address these issues and guarantee that IoT technologies are created and implemented
with user privacy, data security, and ethical concerns as top priorities.

Morgan Carter’s-The Optimal Opt-In Option focuses on improving user


agency in data privacy through the design of more effective opt-in mechanisms118.
Carter critiques the default settings often used by companies to obscure user consent,
arguing that they exploit psychological inertia. The paper explores behavioral
tendencies affecting user decisions and proposes strategies to enhance meaningful
engagement with opt-in processes. This research provides actionable insights for
regulators and organizations to design user-centric privacy policies that align with
ethical data handling practices.

David Alpert’s- “Beyond Request-and-Respond critiques the traditional


reactive approach to privacy and data requests, arguing for more proactive and
preventive frameworks.”119 The article explores innovative methods to streamline data
protection while maintaining organizational efficiency. Alpert proposes practical
models that integrate automation and transparency to foster greater accountability and

117
Ashwin Karale, “The Challenges of IoT: Addressing Security, Ethics, Privacy and Laws”, 58 Ind. J.
Info. Tech. 92 (2020).
118
Morgan Carter, “The Optimal Opt-In Option: Designing Effective User Consent Mechanisms”, 47
Geo. J. Int’l L. 853 (2016).
119
David Alpert, “Beyond Request-and-Respond: ProActive Frameworks for Privacy and Data Protec-
tion”, 25 Yale J.L. & Tech. 112 (2022).

Page | 28
Introduction

trust, marking a significant step forward in addressing contemporary privacy concerns.

It is a crucial addition to the literature on data protection. Through its critical


evaluations, global perspectives, exploration of the interplay between technology and
law, and practical guidance, the book significantly contributes to the on-going discourse
surrounding data protection law. It serves as a vital resource for those seeking to
understand and respond to the challenges posed by the rapid advancements in cyber
security and artificial intelligence, ultimately advocating for more robust and adaptive
legal frameworks to protect individual privacy in the digital age.

OBJECTIVE OF RESEARCH STUDY

The primary objective of the study is to analyse the serious threat to the right to privacy
of individuals by the information technologies in the digital spaces. It also aims to check
the effectiveness of the present legal mechanism to deal with it. Main objectives of the
study are as follows:

1. To analyze the evolving concept of the right to privacy in the context of digital
technologies and its implications for individual autonomy and democratic societies.

2. To examine the Impact of technological advancements, such as Big data, artificial


intelligence, and machine learning, on the protection and infringement of privacy
rights.

3. To assess the effectiveness of existing legal frameworks, including India’s 'Digital


'Personal Data Protection Act' of 2023' and the GDPR, in safeguarding privacy
rights in the digital era.

4. To identify the emerging challenges posed by digital innovations, such as deepfakes


and cross-border data flows, in protecting individual privacy.

5. To explore the need for globally harmonized regulations and propose strategies for
enhancing privacy protection in light of rapid technological advancements.

6. To investigate the role of public awareness in understanding data privacy risks and
empowering individuals to take control of their personal information.

Page | 29
Introduction

HYPOTHESIS

While digital technologies offer significant advancements and opportunities, they


simultaneously pose substantial threats to individual privacy, which existing legal
frameworks struggle to address. This research hypothesizes that current privacy laws,
including India’s Digital Personal Data Protection Act of 2023, are insufficient to
protect individuals’ rights in the face of evolving technological challenges like Big data,
artificial intelligence, surveillance tools and cross-border data flows, necessitating the
development of more robust, globally harmonized regulations.

RESEARCH QUESTIONS

1. How has the concept of the right to privacy evolved in the context of the digital era,
and what are its implications for individual autonomy and democratic societies?
2. In what ways do technological advancements, such as Big data, artificial
intelligence, and machine learning, Impact the protection of privacy rights?
3. How effective are existing legal frameworks, including India’s Digital Personal
Data Protection Act of 2023 and the GDPR, in addressing privacy challenges in the
digital age?
4. What are the emerging privacy risks posed by innovations like deepfakes and cross-
border data flows, and how can they be effectively mitigated?
5. To what extent is there a need for globally harmonized regulations to protect privacy
in the digital era, and what strategies could be implemented to achieve this?
6. How does public awareness and understanding of data privacy risks influence
individuals’ ability to protect their personal information in the digital landscape?

SIGNIFICANCE OF RESEARCH STUDY

This study seeks to deepen theoretical insights into privacy rights by examining them
through historical, legal, and technological lenses. By combining these perspectives,
the research aims to provide a holistic view of privacy protections and their evolution,
highlighting how these rights have been shaped by legal precedents, societal values,
and technological advancements. The study is intended as a resource for policymakers,
legal experts, and technology professionals, offering them a clearer understanding of

Page | 30
Introduction

existing privacy challenges and gaps in current data protection frameworks.

Moreover, the study will provide practical recommendations for strengthening


data protection laws, which could serve as a foundation for formulating more effective
privacy policies. These findings are positioned to contribute to the development of
comprehensive privacy measures that prioritize safeguarding personal information in
increasingly digital environments. Given the rapid rise of digital technologies and the
inadequacies in existing privacy laws to fully address modern data risks, this research
is particularly relevant. It addresses urgent privacy concerns by highlighting areas
where legislation may fall short, potentially influencing policy changes that better
protect individuals' privacy rights in an evolving digital landscape.

RESEARCH METHODOLOGY

The methodology for this study follows a purely doctrinal methodology, which is
characterized by detailed ‘descriptive and analytical approaches’. This method involves
an in-depth examination of “legal principles, statutes, and precedents, relying heavily
on a thorough study of existing materials”. By focusing on established laws and
scholarly interpretations, the doctrinal approach aims to offer a structured analysis of
the research topic.

In this study, both primary and secondary sources form the foundation of
research. Primary sources include examination of laws such as India’s Digital Personal
Data Protection Act of 2023, the European Union’s ''General Data Protection
Regulation'' (GDPR), and other relevant legislative frameworks. It also includes
analysis of judicial decisions to understand the judicial interpretation of privacy in the
context of evolving digital technologies.

Secondary sources consist of Scholarly articles, books, articles, and online


resources on information and technology laws, as well as relevant publications like
magazines and newspapers. Through examining these materials, the doctrinal research
approach allows for an informed understanding of legal issues, contributing to both
theoretical knowledge and practical insights. This methodology is especially valuable
in fields where the interpretation and application of existing laws are pivotal to
addressing contemporary legal questions. The research will employ thematic analysis

Page | 31
Introduction

to identify recurring patterns and themes in the legal frameworks and case law related
to privacy. Key themes include surveillance, data breaches, cross-border data flows,
and the challenges posed by AI and machine learning. This approach will help in
highlighting specific issues that need to be addressed to enhance privacy protections in
the digital era.

SCOPE OF THE STUDY

This research explores how privacy rights are changing in the digital age, focusing on
the serious risks that information technologies pose. Its scope includes an in-depth
investigation of the constitutional and legislative provisions that support privacy
protection, as well as a comprehensive assessment of the historical evolution of privacy
rights and a comparative comparison of national and worldwide viewpoints. Along with
examining how technology changes affect privacy rights, this research also examines
data protection laws now in place and suggests improvements to strengthen them.
Through evaluation and recommendation of strict measures, the research seeks to
effectively discourage violations of the right to privacy.

This study is important in several ways. First of all, it is a useful tool for
legislators and policymakers, providing information that helps them tailor legal
frameworks to the changing needs of the digital era. Moreover, it enriches ongoing legal
debate by adding to the conversation on privacy rights and the Impact of technology.

FRAMEWORK OF STUDY

The thesis unfolds across six interconnected chapters, meticulously designed to address
the multifaceted dimensions of the right to privacy in the digital era.

Chapter One: Introduction

Chapter First begins with introductory remarks precisely introducing the topic, its
rationale, highlighting the framework of study, objectives of the study, hypothesis, and
the methodology adopted, identification of problem, review of literature including
research gap and outlining the brief remarks over the entire study. The inaugural chapter
sets the stage by delineating the primary objective of the study: the analysis of the
serious threat posed to individual privacy by information technologies in digital spaces.

Page | 32
Introduction

It aims to evaluate the efficacy of current legal mechanisms. This chapter outlines key
objectives, including the exploration of the historical development of the right to
privacy, examination at both international and national levels, and a spotlight on
constitutional and statutory provisions.

Chapter Two: Development of ‘Privacy’ Jurisprudence

Building on the groundwork laid in Chapter One, the second chapter delves into the
development of privacy jurisprudence of the right to privacy. It spans ancient roots, the
Enlightenment era, and the contemporary challenges posed by the digital revolution.
This chapter forms a crucial backdrop for understanding the development of privacy
rights, leading to a comprehensive exploration of the Indian legal framework. It
highlight the view of jurists and their idea about the concept of privacy. It also zooms
in on the legal framework for privacy protection, examining significant privacy-related
cases in India and proposing measures to fortify India's right to privacy. This section
contributes valuable insights into the ongoing discourse surrounding privacy rights in
the realm of The Information Technology Act, 2000 and 'The Digital Personal Data
Protection Act, 2023'. The chapter also undertakes other ancillary legislation related to
protection and recognition of right to privacy.

This chapter also discusses the role of the judiciary in protecting such rights.
Privacy protection in India is rooted in the constitutional framework, which guarantees
fundamental rights to its citizens. While the right to privacy is not explicitly mentioned
in the Constitution of India, it has been recognized and protected through judicial
interpretation

Chapter Three: Technological Advancement & Its Effect on right to privacy

The third chapter navigates the intricate landscape of technological advancement and
its Impact on the right to privacy. It critically analyzes problematic definitions of
"privacy," explores the architecture of the Internet of Things, and delves into marketing
privacy concerns. Additionally, it probes the psychological components of privacy and
examines the intersection of justice with privacy dimensions. It summarizes the current
status and theoretical roots of the two most distinct "branches" of privacy law—
autonomy (both physical and decisional) and informational privacy. This Part also

Page | 33
Introduction

outlines the technology and developments of the digital age.

Chapter four: Comparative Analysis of Right to Digital Privacy in India with USA
and European Union.

The fourth chapter adopts a comparative lens, juxtaposing the right to digital privacy in
India USA and the European Union. It evaluates legal frameworks, cultural
perspectives, technological advancements, and emerging challenges. The chapter
concludes with insights on global privacy standards and cross-border data flows,
offering recommendations for safeguarding digital privacy in an interconnected world.
Understanding their differing approaches not only provides insights into their domestic
policies but also contributes to a broader understanding of the global discourse
surrounding digital privacy.

Chapter Five: Analysis of Digital Personal Data Protection Act, 2023.

The fifth chapter scrutinizes 'The Digital Personal Data Protection Act, 2023', tracing
the evolution of personal data protection laws in India, constitutional provisions, and
the landscape of data protection under various statutes. It analyzes key features of the
Act, provides suggestions for lawmakers, and critically evaluates the implications of
the new Data Protection Act in 2023.

This structured flow of chapters ensures a seamless progression through historical


contexts, legal frameworks, technological dimensions, and comparative analyses,
culminating in a comprehensive exploration of the right to privacy in the digital age.

Chapter six: Conclusion and Suggestion

The sixth chapter deals with the conclusion and suggestion of the thesis.

arising from rapid technological developments.

1.2. Challenges In digital space

Artificial Intelligence (AI) and Privacy

Artificial Intelligence (AI) has redefined the landscape of technological


advancement, becoming a transformative force across industries such as healthcare,

Page | 34
Introduction

finance, transportation, and even space exploration. AI systems, powered by


sophisticated machine learning algorithms, have demonstrated their ability to process
colossal volumes of data, make precise predictions, and automate decision-making
processes that were once deemed impossible. However, this remarkable progress comes
with significant concerns, particularly in the realms of privacy and surveillance120. The
inherent dependence of AI on vast datasets, which often include sensitive personal
information, has introduced complex challenges that extend beyond conventional
privacy issues. In many instances, the data collected and utilized by AI systems is not
only used to improve algorithmic accuracy but also has the potential to expose intricate
details of individuals' private lives.

The relationship between AI and privacy becomes even more intricate when one
considers its application in surveillance. Modern surveillance systems, bolstered by AI
technologies such as facial recognition, behavior prediction, and automated decision-
making tools, have enabled entities to monitor individuals with unprecedented
precision and scale. While these capabilities can enhance security and streamline
processes, they also pose significant threats to civil liberties and individual
autonomy 121 . For example, AI-driven surveillance systems can lead to mass data
collection and profiling, raising concerns about misuse, discrimination, and the erosion
of fundamental rights122. The lack of transparency in how AI models make decisions
further exacerbates these concerns, as individuals often have limited visibility into the
mechanisms that influence critical outcomes, such as credit approvals, job recruitment,
or even criminal justice proceedings.

In addressing these challenges, it is crucial to adopt a multifaceted approach


that integrates privacy-by-design principles and emphasizes transparency in AI
development. Privacy-by-design entails embedding data protection mechanisms into
the architecture of AI systems from their inception. This includes implementing data
minimization practices, anonymizing sensitive information, and ensuring that users
retain control over how their data is collected, stored, and utilized. Furthermore,

120
M. Schwartz & D.J. Solove, Information Privacy Law, 7th ed. (Aspen Publishing,2023).
121
Daniel J. Solove, “Privacy Self-Management and the Consent Dilemma” 126 Harvard Law Review
1880 (2013).
122
Ibid.

Page | 35
Introduction

fostering explainability in AI algorithms is essential to building trust; individuals and


oversight bodies must be able to understand the rationale behind AI-driven decisions to
ensure accountability and fairness.

The digital era has also seen the proliferation of The Internet of Things (IoT),
further compounding privacy concerns. IoT devices, ranging from smart home
assistants to wearable fitness trackers, collect and exchange vast amounts of data,
including location information, biometric data, and behavioral patterns. These
interconnected ecosystems often create vulnerabilities that can be exploited by
malicious actors, leading to security breaches and unauthorized access to personal
information123. The constant tracking and monitoring capabilities of IoT devices raise
questions about the extent to which individuals' lives are being observed and recorded,
often without their explicit consent or understanding. To safeguard privacy in this
context, robust legal frameworks are imperative. Such frameworks should mandate
clear user consent for data collection, establish stringent standards for data security, and
promote the adoption of privacy-enhancing technologies like encryption and data
anonymization.

In the realm of surveillance, the implications of AI-powered technologies


extend into governance and law enforcement, where tools such as predictive policing
and social credit systems have gained traction. While these systems promise enhanced
efficiency and crime prevention, they often operate with limited oversight, raising
ethical and legal dilemmas. For instance, predictive algorithms may unintentionally
reinforce existing biases, disproportionately targeting certain demographics or
communities. Similarly, social credit systems, which rank individuals based on their
behavior or compliance with societal norms, risk creating a surveillance state where
privacy and individual freedoms are significantly curtailed. The unchecked deployment
of such systems can lead to a chilling effect on free expression and an erosion of trust
in public institutions124.

123
Orin S. Kerr, “The 'Fourth Amendment' and New Technologies: Constitutional Myths and the Case
for Caution” 102 Michigan Law Review 801 (2004).
124
Graham Greenleaf, “Global Data Privacy Laws 2022: 144 National Laws & 20 Bills” 172 Privacy
Laws & Business International Report 1 (2022).

Page | 36
Introduction

Beyond terrestrial applications, AI's Impact on privacy and surveillance extends


into deep space exploration and research. Space agencies and private enterprises
increasingly leverage AI for tasks such as satellite data analysis, interplanetary mission
planning, and even extraterrestrial life detection. These systems process enormous
volumes of data, some of which may have implications for global security or involve
sensitive geopolitical information. For instance, AI-enabled satellites used for Earth
observation can collect high-resolution imagery, providing insights into human
activities, infrastructure, and environmental changes. While this information can be
invaluable for disaster management and scientific research, it also raises questions
about its potential misuse in espionage or unauthorized surveillance.

To navigate the delicate balance between AI-driven innovation and privacy


protection, international collaboration is paramount. ‘Governments, technology
developers, and privacy advocates must work together to establish ethical guidelines,
standardize best practices, and promote the responsible use of AI technologies’.
Additionally, fostering public awareness and education on privacy rights and AI's
implications is essential to empower individuals to make informed choices about their
data125.

The rapid advancement of AI, IoT, and surveillance technologies presents a


unique paradox: While these innovations hold the promise of transforming industries
and enhancing lives, they also pose unprecedented ‘challenges to privacy and civil
liberties’. Addressing these challenges requires a holistic approach that incorporates
“legal, ethical, and technological solutions”. By prioritizing “privacy protection,
fostering transparency, and ensuring accountability”, societies can harness the full
potential of AI and related technologies while safeguarding the fundamental rights and
‘freedoms of individuals’. Proactive efforts to address emerging privacy challenges will
be instrumental in building a digital ecosystem that is not only innovative but also
respectful of ‘human dignity and autonomy’.

125
Neil M. Richards, “The Dangers of Surveillance” 126 Harvard Law Review 1934 (2013).

Page | 37
Introduction

[Link] of Things (IoT) and Privacy

The Internet of Things (IoT)126 has transformed the way we interact with everyday
objects, from smart home devices to wearable fitness trackers. IoT devices collect and
exchange data, often including personal information, to provide enhanced functionality
and convenience. However, the widespread adoption of IoT raises significant privacy
challenges. IoT devices capture vast amounts of sensitive data, such as location
information, biometric data, and personal habits. The constant monitoring and tracking
capabilities of IoT devices can result in unprecedented intrusion into individuals'
private lives. Moreover, the interconnected nature of IoT ecosystems increases the
vulnerability of personal data to security breaches and unauthorized access. Addressing
privacy challenges in the IoT era requires implementing robust security measures,
ensuring user consent and control over data collection and sharing, and promoting
transparency regarding data practices. Privacy-enhancing technologies, such as
encryption and data anonymization, can also be pivotal in alleviating ‘privacy risks
associated with IoT’.

In the digital era, surveillance practices have become increasingly pervasive,


both by governments and private entities. Surveillance technologies, such as “CCTV
cameras, facial recognition systems, and data monitoring tools, raise significant
concerns about privacy and civil liberties” 127 . Mass surveillance programs and the
‘indiscriminate collection and analysis of personal data’ can infringe upon individuals'
right to privacy and erode trust in institutions. Moreover, the lack of encryption and
data anonymization in surveillance practices, raises questions about the appropriate
balance between security measures and privacy rights.

To address surveillance challenges, it is essential to establish robust legal


frameworks that strike a balance between ‘legitimate security concerns and privacy
protection’. Transparency and oversight mechanisms, such as clear guidelines for data

126
Office of the Victorian Information Commissioner, “Internet of Things and Privacy - Issues and
Challenges” (2021), (India), available at: [Link]
organisations/internet-of-things-and-privacy-issues-and-challenges/ (last visited on Oct. 10, 2021).
127
Adi Kuntsman & Esperanza Miyake, Paradoxes of Digital Disengagement: In Search of the Opt-
Out Button (2021), (India), available at: [Link]
refreqid=search-gateway (last visited on Oct. 25, 2021).

Page | 38
Introduction

collection and retention, judicial review, and independent oversight bodies, can help
ensure accountability and safeguard privacy rights in the face of surveillance 128
activities.

The digital era presents unique privacy challenges due to the rapid advancement
of technology and the extensive collection and processing of personal data. Addressing
these challenges requires a multifaceted approach that encompasses legal frameworks,
technological innovations, and societal awareness. Protecting privacy in the digital era
entails incorporating privacy-by-design principles into the development of
technologies, ensuring individuals' informed consent and control over their data, and
fostering transparency and accountability in data practices. Moreover, ongoing
dialogue between policymakers, technology developers, and privacy advocates is
crucial to navigate the evolving landscape of privacy challenges and strike an
appropriate balance between innovation and privacy protection. By proactively
addressing emerging privacy challenges, India can establish a robust legal framework
and technological infrastructure that promotes privacy protection and fosters trust in the
digital ecosystem. To curb this issue not only the legislature helped but the judiciary
also played an important role. There were several times when the SC passes several
judgments favoring the privacy in digital space.129

[Link] Internet and the Erosion of Anonymity

The rise of the internet and the digital revolution in the late 2oth century introduced
unparalleled challenges to privacy. The internet provided new avenues for
“communication, information sharing, and commerce”, but it also raised concerns
about the erosion of personal privacy.130

Online platforms, social media, and search engines collect vast amounts of
personal data, leading to the loss of anonymity and potential invasions of privacy.

128
Privacy and Civil Liberties Oversight Board (PCLOB), Report on Surveillance Programs (2014,
United States).
129
Justice K.S. Puttaswamy (Retd.) & Anr. v. Union of India & Ors., (2017) 10 SCC 1.
130
Office of the United Nations High Commissioner for Human Rights, "The right to privacy in the
Digital Age," (India), available at: [Link]
DigitalAge/ReportPrivacyinDigitalAge/[Link] (last visited on Oct. 30,
2021).

Page | 39
Introduction

Individuals personal information’, ‘browsing habits’, and ‘online interactions’ became


valuable commodities for advertisers and data brokers.131

The erosion of anonymity online has sparked debates about the extent to which
individuals can maintain privacy in the digital age. The challenges posed by the internet
have prompted the development of privacy regulations and the need for “individuals,
governments, and technology companies” to find a balance between the benefits of
connectivity and the protection of personal information.

Data Collection and Privacy Concerns

The digital age has also witnessed a proliferation of data collection practices,
132
often conducted without individuals' full awareness or consent. Companies,
governments, and other entities collect, analyze, and utilize vast amounts of personal
data, raising significant privacy concerns.

The collection of personal data, such as location information, browsing history,


and online interactions, enables targeted advertising, personalized services, and data-
driven decision-making. 133 However, it also raises questions about consent, data
security, and the potential for abuse or misuse of personal information.

The growing recognition of these privacy concerns has led to the development
of data protection laws and regulations worldwide. For example, the European Union's
'General Data Protection Regulation' (GDPR) 134 introduced comprehensive privacy
regulations to protect individuals' rights and provide greater control over their personal
data.

1.5. Surveillance Technologies and National Security


The digital age has witnessed the rapid development and deployment of surveillance
135
technologies, often driven by national security concerns. Governments, law

131
Social Media Privacy, Electronic Privacy Information Center, [Link]
privacy/social-media-privacy/.(last visited on Nov. 02, 2021).
132
Id.
133
Id.
134
General Data Protection Regulation, Apr. 27, 2016, O.J. (L 119) 1.
135
Office of the United Nations High Commissioner for Human Rights, "The right to privacy in the
Digital Age," (India), available at: [Link]
DigitalAge/ReportPrivacyinDigitalAge/[Link] (last visited on Nov 05, 2021)

Page | 40
Introduction

enforcement agencies, and intelligence organizations employ advanced surveillance


tools to monitor communications, track individuals' movements, and gather
intelligence.

The increased surveillance capabilities have raised concerns about the balance
between security interests and individual privacy. Debates surrounding the legality and
proportionality of surveillance practices have been at the forefront of privacy
discussions. Court cases and legislative efforts aim to establish safeguards and
oversight mechanisms to protect privacy rights while addressing national security
concerns.

The digital revolution has transformed the privacy landscape, introducing


complex challenges in the protection of personal information, anonymity, and the
balance between security and privacy. As technology continues to advance, it is crucial
to adapt privacy frameworks and regulations to ensure that individuals' fundamental
rights are safeguarded in the digital age.

1.5.1. Privacy and Genetic Information

Advances in genetics and genomics have presented new challenges to privacy rights.
The ability to sequence and analyze an individual's genetic code has revolutionized
medical research, personalized medicine, and forensic investigations. However, it also
raises concerns about the privacy and security of genetic information.136

Genetic data contains highly personal and sensitive information that can reveal
an individual's predisposition to certain diseases, ancestry, and even familial
relationships. The potential for unauthorized access, data breaches, and misuse of
genetic information poses significant privacy risks.

Efforts to protect genetic privacy include regulations and ethical guidelines that
govern the collection, storage, and sharing of genetic data. Striking the right balance
between advancing scientific knowledge and safeguarding individuals' genetic privacy
remains an ongoing challenge.

136
Id

Page | 41
Introduction

The case of “Justice K.S. Puttaswamy and Anr. v. Union of India” 137 ,
Identified as the 'Aadhaar case', by the SC. The case challenged the constitutionality
of the Aadhaar project, a “unique identification system” that collected biometric and
demographic data of the residents. The SC reiterated that the right to privacy is a
fundamental right and emphasized the need to ensure the collection of biometric data
is conducted in a manner that upholds an individual's privacy and dignity. This
judgment further solidified the constitutional protection of privacy rights and
emphasized the importance of balancing technological advancements with individual
privacy.

The SC, in its judgment, recognized the right to privacy as a fundamental right
protected under 'Article 21' of the Indian Constitution. It affirmed that privacy is an
essential aspect of human dignity and individual autonomy. The judgment emphasized
the need for robust data protection measures and imposed restrictions on the use of
Aadhaar data, emphasizing the importance of informed consent and purpose limitation.

The case of 'R. Rajagopal v. State of Tamil Nadu' (1994)138, Under "Article
19(1)(a)" of the Constitution, the SC ruled that the right to privacy is an ‘essential
component of the right to freedom of speech and expression’139. The SC decided that it
would be an infringement of privacy if “someone's personal information was published
without their permission”. The ruling established a precedent for privacy protection
within the context of ‘freedom of speech and expression’ and acknowledged the
‘individual's right’ to manage the distribution of their personal information.

In this case, 'Selvi and Ors. v. State of Karnataka (2010)'140, The admissibility
of evidence gathered via techniques like narco-analysis and other types of involuntary
testing was investigated by the Supreme Court. The Court ruled that subjecting
individuals to such tests without their consent violated their right to privacy and
‘dignity’, enshrined under ''Articles 20(3)''141 and 21142 of the Constitution. This ruling

137
(2017) 10 SCC 1.
138
1995 AIR 264
139
The Constitution of India, art. 19 cl. 1(a).
140
(2010) 7 SCC 263.
141
The Constitution of India. art. 20 cl. 3.
142
The Constitution of India. art. 21.

Page | 42
Introduction

highlighted how crucial it is to uphold a ‘person's autonomy and protect their right to
privacy’, especially when conducting ‘criminal investigations’.

‘Vishakha and Ors. v. State of Rajasthan and Ors.’ (1997)143:

The SC tackled the problem of sexual harassment in the workplace in this historic de-
cision, acknowledging the necessity of rules to stop and deal with it. The Court stressed
that eliminating sexual harassment is crucial to guaranteeing the exercise of the funda-
mental right to work with dignity guaranteed by "Article 21" of the Constitution. This
case was crucial in establishing the legal framework that addresses sexual harassment
in the workplace and recognizes the value of a respectful and safe workplace.

‘Shreya Singhal v. Union of India (2015)’144:

The constitutionality of Section 66A of the IT Act, which made some forms of online
expression illegal, was at the center of this dispute. Citing a violation of the right to
freedom of speech and expression guaranteed by "Article 19(1)(a)" of the Constitution,
the Supreme Court ruled that Section 66A was unconstitutional 145 . The ruling
underlined the need of preserving online free speech while acknowledging the necessity
of striking a balance with justifiable worries about morality and public order. This
decision had significant implications for upholding the right to privacy in the digital
age and ensuring the protection of free expression online.

1.6. Impact of Landmark Judgments on Privacy Protection

The landmark judgments discussed above have had a significant Impact on privacy
protection in India. They have helped shape the legal framework and provided guidance
on the interpretation and application of privacy laws. The Impact of these judgments
can be observed in the following ways:

‘Affirmation of privacy’ as a basic right: The recognition of ‘privacy as a


fundamental right’ in the 'Aadhaar case' has established a strong foundation for privacy
protection. It ensures that “privacy is considered a core aspect of human dignity and

143
(1997) 6 SCC 241.
144
AIR 2015 SC 1523.
145
The Constitution of India. art. 19 cl. 1(a).

Page | 43
Introduction

individual autonomy”.

Emphasis on data protection principles: The judgments have emphasized the


importance of data protection principles, such as informed consent, purpose limitation,
and transparency. They have highlighted the need for organizations to respect
individuals' rights over their personal data and to adopt privacy-by-design approaches.

Strengthening of data protection laws: The judgments have influenced the drafting
and formulation of data protection laws in India, such as the 'Personal Data Protection
Act' (PDPB). They have prompted policymakers to incorporate key privacy principles
and provisions into the legislation to ensure stronger privacy safeguards.

Empowering individuals: The judgments have empowered individuals by reaffirming


their rights to privacy and control over their personal data. They have encouraged
individuals to assert their privacy rights and seek redress in cases of privacy violations.

Increased scrutiny of technology companies: The judgments have drawn attention to


the data practices of technology companies and raised awareness about the need for
transparency and accountability. They have prompted greater scrutiny of data handling
practices and led to increased demands for stronger data protection regulations.

Overall, these rulings have been crucial in shaping the understanding and
implementation of privacy protection in India. They have contributed to the
development of a robust legal framework and fostered a greater awareness of privacy
rights among individuals and organizations.

Page | 44

You might also like