Privacy Challenges in the Digital Era
Privacy Challenges in the Digital Era
Introduction
CHAPTER-I
Introduction
“It used to be expensive to make things public and cheap to make them private. Now
it’s expensive to make things private and cheap to make them public.”
– Clay Shirky on ‘Privacy in Digital Space’
1.1. INTRODUCTION:
“Privacy is the right to be free from covert observation and to select when, how, and to
whom one's information is disclosed”1. Privacy is a timeless concept that has evolved
over the years, shaping both advantages and challenges for individuals. Due to
enhancement in technology, its scope has increased and include categories such as
physical, informational, decisional and dispositional.2
The intensity and complexity of life, attendant upon advancing civilization have
rendered necessary some retreat from the world, the man, under the reefing influence
of culture, has become more sensitive to publicity, so that solitude and privacy have
become more essential to the individual; but modern enterprises and intention have,
through invasion upon his privacy, subjected him to mental pain and distress, for greater
that could be inflicted by mere bodily injury.6
1
Lindsey Norman, An Overview of the Changing Data Privacy Landscape in India 919 (2018).
2
Payal Thaorey, “Informational Privacy: Legal Introspection in India” II ILI Law Review 160 (Winter
2019).
3
Ralph TH Griffith,(1826-1906) Translated into English Verse ‘Ramayana’.
4
Kisari Mohan Ganguli (trans.), The Complete Mahabharata in English (1883-1896).
5
Medha Bisht, Kautilya’s Arthashastra (2019).
6
Samuel D. Warren & Louis D. Brandeis, “The right to privacy” 4 Harvard Law Review 193 (1890).
Page | 1
Introduction
The right to privacy is a fundamental human right that is essential for the
protection of human dignity and autonomy7. It is also necessary for the development of
a democratic society that respects the ‘rule of law’. However, in the digital era, the right
to privacy faces numerous emerging issues and challenges that threaten its protection.8
The digital era has led to the widespread ‘collection, processing, and storage of
personal information’9. The collection and use of personal information have made the
protection of the right to privacy a critical issue. The right to privacy has been
recognized as a fundamental right by various international and regional instruments,
such as the 'UDHR', the 'ICCPR', and the 'ECHR'.10 These instruments provide that
individuals have the right to privacy encompasses respect for an individual’s private
and family life, home, and communication.
Big data is another emerging issue and challenge to the right to privacy in the
digital era.13 Big data refers to the vast amount of data that is generated by individuals
and organizations through their online activities. Big data analytics enables
organizations to study and forecast individual behaviors and preferences. However, the
use of Big data analytics raises concerns about the ‘protection of personal information’
7
Office of the United Nations High Commissioner for Human Rights, “The right to privacy in the
Digital Age” (India), available at: [Link]
DigitalAge/ReportPrivacyinDigitalAge/[Link] (last visited on March. 28,
2021).
8
Heather Briston et al., Rights in the Digital Era (2015).
9
Christina Akrivopoulou & Athanasios Psygkas, “Personal Data Privacy And Protection In A
Surveillance Era: Technologies And Practices” (2011).
10
European Court of Human Rights, European Convention on Human Rights, (India), available at:
[Link] (last visited on April. 21, 2021).
11
Adi Kuntsman & Esperanza Miyake, Paradoxes of Digital Disengagement: In Search of the Opt-Out
Button (2020), (India), available at: [Link]
search-gateway (last visited on April. 28, 2021).
12
Ibid.
13
Supra note 4.
Page | 2
Introduction
The Internet of Things (IoT) is also an emerging issue and challenge to the right
to privacy in the digital era.14 The IoT refers to the interconnectedness of devices and
objects that are embedded with sensors and software. The use of IoT devices raises
concerns about the collection and use of personal information, as well as the ‘potential
for unauthorized access’ to personal information.15
Social media is another emerging issue and challenge to the right to privacy in
the digital era.16 Social media platforms allow individuals to share personal information
with a wide audience. The use of social media brings about concerns regarding the
safeguarding of personal information and the risk of unauthorized access to such data.
Biometric data is another emerging issue and challenge to the right to privacy
in the digital era.19 Biometric data refers to the use of biological characteristics, such as
fingerprints, facial recognition, and iris scans, to identify individuals. The use of
biometric data raises concerns about the safeguarding personal information and the
potential for misuse.
14
Office of the Victorian Information Commissioner, “Internet of Things and Privacy - Issues and
Challenges” (2021), (India), available at: [Link]
organisations/internet-of-things-and-privacy-issues-and-challenges/ (last visited on May. 05, 2021).
15
Ibid.
16
Jiahong Chen, Regulating Online Behavioural Advertising Through Data Issues and Challenges 2–8
(Edward Elger publishing Limited, U.K.,2021).
17
Ibid.
18
Ibid.
19
Office of the Victorian Information Commissioner, “Biometrics and Privacy” (2020), (India),
available at: [Link] (last
visited on May. 18, 2021).
20
Supra note 11.
Page | 3
Introduction
Artificial Intelligence (AI) is also an emerging issue and challenge to the right
to privacy in the digital era.21 AI refers to the use of machines and algorithms to analyze
and predict individual behavior and preferences. The use of AI raises concerns about
the protection of personal information and the potential for discrimination.
The emerging issues and challenges to the right to privacy in the digital era are
complex and require careful consideration of the rights and interests of individuals, as
well as the needs of society as a whole. It is essential to have a balanced approach that
takes into account the benefits and risks of digital technologies.
To protect the right to privacy in the digital era, various measures have been
proposed. One approach is the development of privacy-enhancing technologies that can
protect personal information while still allowing for the benefits of digital technologies.
Privacy-enhancing technologies include ‘encryption, data minimization, and
differential privacy’.
21
National Security Commission on Artificial Intelligence (NSCAI), “Interim Report” 12 (Nov. 2019),
(India), available at: [Link]
for-Congress_201911.pdf (last visited on May. 22, 2021).
22
Mohammad Hossein Ronaghi & Mohammad Mosakhani, “The Effects of Blockchain Technology
Adoption on Business Ethics and Social Sustainability: Evidence from the Middle East” Environment,
Development and Sustainability (2021), (India), available at: [Link]
articles/PMC8352148/ (last visited on June. 05, 2021).
23
Id.
24
General Data Protection Regulation, 2016/679, 2016 O.J. of E.U. (L 119) 1.
Page | 4
Introduction
Education and awareness-raising are also essential for the protection of the right
to privacy in the digital era. Individuals need to be aware of their rights and
responsibilities concerning the protection of their personal information. They also need
to understand the risks and benefits of digital technologies and how to protect their
personal information.
The right to privacy is a fundamental human right that is essential for the
‘protection of human dignity and autonomy’.26 However, in the digital era, the right to
privacy faces numerous emerging issues and challenges that threaten its protection.
Surveillance, Big data, the Internet of Things, social media, online behavioural
advertising, biometric data, cybersecurity, artificial intelligence, and blockchain are all
emerging issues and challenges to the right to privacy in the digital era.
In addition to the challenges and emerging issues discussed here, there are also
potential solutions that could help mitigate the threats to the right to privacy. For
example, privacy-by-design could be incorporated into the development of new
technologies to ensure that privacy considerations are integrated into their design from
the outset. Similarly, organizations could implement privacy Impact assessments to
identify and mitigate the privacy risks associated with their activities.
25
Id.
26
Supra Note 7.
27
Id.
Page | 5
Introduction
Therefore, the right to privacy in the digital era faces numerous emerging issues
and challenges, including surveillance, Big data, the Internet of Things, social media,
online behavioural advertising, biometric data, cybersecurity, artificial intelligence, and
blockchain. These challenges threaten the protection of the right to privacy, and a
balanced approach is needed to ensure that the benefits of digital technologies are
realized while still protecting this fundamental human right.
28
Office of the United Nations High Commissioner for Human Rights, The right to privacy in the
Digital Age, (India), available at: [Link]
DigitalAge/ReportPrivacyinDigitalAge/[Link].(last visited on June. 19, 2021)
29
“Surveillance is a Fact of Life, So Make Privacy a Human Right,” The Economist (Dec. 13, 2019),
(India), available at: [Link]
life-so-make-privacy-a-human-right (last visited on June. 25, 2021).
Page | 6
Introduction
of India.30 However, in the digital era, the right to privacy faces numerous challenges
and emerging issues that threaten its protection. This thesis will also explore the
challenges and emerging concerns related to facing the right to privacy, the legal
framework for the protection of privacy in India, and the measures that can be taken to
protect the right to privacy in the digital era.
The digital era has brought numerous challenges and emerging issues to the
protection of the right to privacy in India.31 One of the most significant challenges is
the widespread use of biometric data for identification purposes. 32 The Indian
government has implemented the Aadhaar scheme, 33 which requires individuals to
provide their biometric data in order to access government services. 34 However,
concerns have been raised about the security and privacy of this data.
Another challenge facing the right to privacy in India is the use of surveillance
technologies by the government. The government has implemented various
surveillance programs, such as the ‘Central Monitoring System’ and the ‘National
Intelligence Grid’, 35 which allow for the interception and monitoring of electronic
communications.36 However, the use of these technologies raises concerns about the
protection of privacy and civil liberties.
Social media and online platforms also pose a significant threat to the right to
privacy in India. The use of online platforms for sharing personal information has
become ubiquitous, and the potential for misuse of this information is high. 37 The
‘Cambridge Analytica scandal’, which involved the misuse of Facebook data for
30
Vikas Kumar, “right to privacy in Digital Era: A Study with Indian Context” Legal Service India
(Dec. 28, 2020), (India), available at: [Link]
[Link] (last visited on June. 30, 2021).
31
Ibid.
32
Supra note 26.
33
Ibid.
34
Supra note 26.
35
“No Blanket Permission to Any Agency for Surveillance under Netra, Natgrid: Centre to HC,”
Economic Times, (India), available at: [Link]
permission-to-any-agency-for-surveillance-under-netra-natgrid-centre-to-
hc/articleshow/[Link]?from=mdr (last visited on July. 18, 2021).
36
Id.
37
Rahul Kumar, “Jurisprudence of right to privacy in India” SSRN Electronic Journal (2020).
Page | 7
Introduction
political purposes, highlighted the risks associated with the use of social media.38
After the landmark ‘Mrs. Gandhi's case’40, the Indian Constitution underwent
changes, and the SC repeatedly stated that 'Article 21'41 is the core of fundamental rights
in India, encompassing multidimensional aspects. Two crucial terms, "Life" and
"Freedom,"42 have been interpreted definitively to give 'Article 21' an extended scope.
The right to privacy, not explicitly mentioned in the Constitution, came into existence
as a result of this expansion.
In the past, the law in India would only offer ‘protection against physical
harm’44. It became clear that not only physical safety but also the protection of the
ethereal self, emotions, and intellect were necessary as the custom-based decree
evolved to address the problems that the general public faced. To this day, the Right to
38
Michael D. Shear et al., “Cambridge Analytica Scandal: What You Need to Know,” The New York
Times, (India), available at: [Link]
[Link] (last visited on July. 20, 2021).
39
Justice KS Puttaswamy (Retd.) & Anr. V. Union of India & Ors. (2017) 10 SCC 1.
40
Maneka Gandhi v. Union of India, AIR 1978 SC 597.
41
The Constitution of India, art. 21
42
J.N. Pandey, Constitution of India 271-357 (Central Law Agency, 2020).
43
Rahul Kumar, “Jurisprudence of right to privacy In India”, SSRN Electronic Journal (2020).
44
Id.
Page | 8
Introduction
Life has expanded to include the ‘right to liberty’, the protection of widespread
collective wealth, and all types of property, both insignificant and unique.45
The Court has suggested the advantage of privacy from 'Article 21' by
unraveling it in similitude with ‘Article 12’ and ‘Article 17’46. The "privacy rights" are
required by each of these broad reports. The "Indian Constitution" does not list the right
to privacy as a fundamental Right.
The scope of this issue was first raised in ‘Kharak Singh’s Case’47, which was
concerned with the legality of precise directions that allowed surveillance of
respondents.
In the Maneka Gandhi49 case, A "Triple Test" was created for any legislation
that interfered with personal freedom. The legislation and process that permit
interfering with an individual's freedom and right of privacy should also be reasonable,
equitable, and correct—not specific, capricious, or onerous.50 The right to privacy is
now recognized as part of the 'Article 21' right to life and freedom. It is the right of
every citizen to protect his or her privacy about "family, marriage, reproduction,
45
Supra note 38.
46
The Constitution of India, art. 17.
47
1963 ALL. L. J. 711
48
The Constitution of India. art. 19 cl. 1(d).
49
Maneka Gandhi v. Union of India, AIR 1978 SC 597.
50
Aditya Verma, “right to privacy and RTI” (Central Information Commission, 2016), (India),
available at:
[Link]
Verma%20%20%281%29%20%281%[Link] (last visited on July. 25, 2021).
Page | 9
Introduction
parenthood, child behavior, and education, among other reasons." Anyone who
publishes anything about the aforementioned topics without the consent of the
individual in question runs the danger of suffering damage in real life.
In Kharak Singh's case51, the SC held right to privacy is part of the right to
protection of life and personal liberty guaranteed by 'Article 21'. The court equated the
right to privacy with the right to personal liberty. The right to privacy is ‘not an absolute
right’ and can be restricted if there is a compelling state interest, but such restrictions
must be proportionate and in accordance with the law.52
'The Bharatiya Nyaya Sanhita' also contains provisions that protect privacy,
such as ‘Section 78’, 55 which criminalizes the stalking of women. 'The Right to
Information Act, 2005'56, also contains provisions that protect privacy by exempting
51
Supra Note 46.
52
Aditya Verma, right to privacy and RTI (Central Information Commission, 2016), (India), available
at: [Link]
20Verma%20%20%281%29%20%281%[Link] (last visited on July. 29, 2021).
[Link]
Verma%20%20%281%29%20%281%[Link].
53
The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal
Data or Information) Rules, 2011, Notification No. G.S.R. 313(E), 25 Mar. 2011..
54
The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, No.
18 of 2016 (India).
55
The Bharatiya Nyaya Sanhita 2023, Sec. 78.
56
Right to Information Act, Act No. 22 of 2005, (India).
Page | 10
Introduction
To protect the right to privacy in the digital era, various measures can be taken.
One approach is the development of privacy-enhancing technologies that can protect
personal information while still allowing for the benefits of digital technologies.
Privacy-enhancing technologies include encryption, data minimization, and differential
privacy.57
In the digital age, protecting the right to privacy also requires education and
awareness-raising. People must understand their rights and obligations with regard to
safeguarding their personal data. Along with learning how to safeguard their personal
data, they must also comprehend the advantages and disadvantages of digital
technologies.
In the digital age, privacy has become an increasingly important concern for
individuals around the world. As people rely more on technology for communication,
commerce, and social interaction, the potential for their personal data to be exploited
or misused by malicious Actors has grown significantly. In response, many countries
have implemented legal provisions designed to protect the privacy of their citizens in
the digital space.
One of the most important legal instruments as already mentioned above as far
57
"Privacy Enhancing Technologies (pets)" Wiley Online Library, (India), available at:
[Link] (last visited on August. 20, 2021).
58
General Data Protection Regulation, 2016/679, 2016 O.J. (L 119) 1.
Page | 11
Introduction
as this is concerned is the 'General Data Protection Regulation' (GDPR),59 which was
introduced by the European Union in 2018. The GDPR applies to all companies that
process the personal data of EU citizens, regardless of where those companies are
based. It sets out a number of important rights for individuals, including the right to
access and delete their personal data, the right to know how their data is being used,
and the right to object to the processing of their data in certain circumstances. The
GDPR also imposes significant penalties on companies that fail to comply with its
provisions, with fines of up to 4% of a company's global revenue.60
Many other countries have also implemented data protection laws that offer
similar protections to those found in the GDPR. For example, the 'California Consumer
Privacy Act' (CCPA)61 was introduced in 2020 and gives California residents the right
to know what personal information is being collected about them, the right to request
the deletion of their information, and the right to opt-out of the sale of their information.
The CCPA also includes penalties for companies that fail to comply with its provisions,
with “fines of up to ‘$7,500’ per violation”.62
In addition to data protection laws, as to this countries have also introduced laws
to protect the privacy of individuals in specific contexts, such as ‘communications and
online Activity’. For example, the ‘UK's Investigatory Powers Act’ restricts the
collection and retention of individuals online Activity and communication data by
public authorities, and requires them to obtain a warrant before accessing this
information. Similarly, the 'California Consumer Privacy Act' (ECPA)63 in the US sets
out rules governing the interception of electronic communications, including email and
phone calls.
59
Id.
60
Supra note 54.
61
California Civil Code, Secs. 1798.100–1798.199 (West 2021).
62
"California Consumer Privacy Act (CCPA) fines and consumer damages," Clarip, (India), (India),
available at: [Link]
Intentional%20violations%20of%20the%20California,violations%20is%20%242500%20per%20vi
olation (last visited on Aug. 25, 2021).
63
Electronic Communications Privacy Act of 1986, Pub. L. No. 99-508, 100 Stat. 1848 (codified as
amended at 18 U.S.C. Secs. 2510–2523).
Page | 12
Introduction
regulations aimed at limiting the use of personal data for advertising purposes and
giving individuals greater control over how their data is used in this context. For
example, the ePrivacy Regulation, which is currently being developed by the EU, would
require companies to obtain explicit consent from individuals before using their data
for online advertising, and would restrict the use of cookies and other tracking
technologies.64
The legal provisions around the globe available to protect privacy in the digital
space are varied but all aim to protect personal data from exploitation and misuse. Data
protection laws, specific context-based laws, and regulation of online advertising and
tracking are some of the measures that nations have adopted diverse strategies to
safeguard their citizens privacy. As technology continues to evolve, it is likely that these
legal provisions will also need to adapt to ensure that individuals privacy rights are
protected in the ever-changing digital landscape.
64
"EU's ePrivacy Regulation: 2022 Updates," [Link], (India), available at:
[Link] (last visited on Sep. 06, 2021).
65
"India has recognized the right to privacy as a fundamental right in 2017," The Indian Express (2020).
66
"India does not currently have a comprehensive data protection law," The Hindu (2019).
Page | 13
Introduction
in recent years. In this thesis, we will explore the emerging issues and challenges related
to the right to privacy in the digital era.
The term privacy can be defined as the “ability to control access to one's
personal information” 67 . However, as technology has advanced, this definition has
become increasingly complex. With the advent of social media, search engines, and
‘smart devices’, individuals now generate massive amounts of personal data on a daily
basis. This data is often collected, stored, and used by companies and governments for
various purposes, including targeted advertising, national security, and law
enforcement. The question of how to balance the benefits of technology with the need
to protect individual privacy rights lies at the heart of the issue.
A key concern regarding privacy in the digital age is the gathering and
utilization of personal information’. Companies such as Facebook and Google collect
vast amounts of personal data from their users, often without their explicit consent. This
data is then used to create targeted advertising campaigns, which can be highly effective
at influencing consumer behavior. However, this practice has raised concerns about the
use of personal data for commercial gain, as well as the potential for this data to be used
for more nefarious purposes, such as identity theft or cyber attacks.
67
Ibid.
68
Rajesh Sharma, “Cybersecurity in India: Problems and Perspectives,” in Tuhin Halder Chowdhury et
al. (eds.), Cybersecurity and Data Privacy: Concepts, Methodologies, Tools, and Applications 143–
168 (2020).
Page | 14
Introduction
personal data by governments for national security purposes has raised questions about
the balance between individual privacy rights and public safety. Finally, there are
ethical considerations related to the use of personal data for commercial gain, as well
as concerns about the potential for bias and discrimination in the use of this data.69
The ‘lack of transparency’ in the ‘collection and use of personal data’ is a major
concern for individuals. The terms of service and privacy policies of online services are
often written in complex legal jargon, making it difficult for users to understand what
they are agreeing to when they sign up for these services. Many individuals may not be
aware of the extent to which their personal data is being “collected, stored, and used by
these companies”. This lack of transparency can undermine trust in online services and
erode individuals' confidence in their ability to control their personal information. The
right to privacy is not absolute and must be balanced against other rights and interests.70
For example, in the case of national security, the need to protect citizens from harm
may justify the collection and use of personal data. However, this justification must be
carefully balanced against the right to privacy and other civil liberties. The need for
transparency and accountability is crucial to ensure that any infringement of privacy
rights is proportionate, necessary, and lawful.
One area of work is the development of policies and regulations that address the
challenges of privacy in the digital age. This might involve working with governments,
non-profits, or industry groups to draft new laws or guidelines that protect individual
privacy rights while still allowing for the benefits of digital technology71. This could
include advocating for clearer and more up-to-date privacy laws, encouraging
companies to adopt best practices for data collection and use, or pushing for greater
transparency in how personal data is collected and used.
69
N. Sharma, “right to privacy in Digital Age: An Indian Perspective” 7 International Journal of
Research & Analytical Reviews 146 (2020).
70
A. Singh, “Privacy Protection in Digital Age: A Critical Analysis of Indian Laws and Policies” 8
International Journal of Law 47, 59 (2021).
71
Ibid.
Page | 15
Introduction
or privacy-focused web browsers. It could also involve developing new ways to secure
personal data, such as using blockchain technology or other innovative solutions.
Technical work might involve collaborating with software developers, cybersecurity
experts, or other technical professionals.
The consequent area of work is education and advocacy around the issue of
privacy in the digital age. This might involve raising awareness among the public about
the risks and challenges of digital privacy, assisting individuals in comprehending their
rights and responsibilities in this area, or advocating for greater protections for privacy
rights. This could include developing educational materials, organizing workshops or
events, or partnering with other organizations to raise awareness72.
Another area of work is legal and ethical analysis of privacy issues in the digital
age. This might involve researching the legal and ethical implications of new
technologies or practices related to ‘data collection and use, analyzing court cases or
other legal decisions related to privacy’, or developing ethical guidelines for the
personal information. This work might be conducted by ‘legal scholars, ethicists, or
other researchers’.
The right to privacy in the digital era is a complex and multifaceted issue that
poses significant challenges to traditional notions of privacy. In this thesis, we will
72
"However, there are still deficiencies in the current legal and regulatory mechanisms for privacy
protection in the digital space in India." (Singh, 2021, p. 47).
73
Supra note 4
Page | 16
Introduction
explore the emerging issues and challenges related to this topic, including the collection
and use of personal data, cybersecurity, legal and ethical issues. By understanding these
challenges, we can work towards developing solutions that balance the benefits of
technology with the need to protect individual privacy rights.
74
Theresa Payton & Ted Claypoole, Privacy in the Age of Big data: Recognizing Threats, Defending
Your Rights, and Protecting Your Family (Rowman & Littlefield 2014).
75
Dan Jerker B. Svantesson & Roger Clarke, European Data Protection Law: Corporate Compliance
and Regulation (Kluwer Law International 2018).
76
ICO, “Your Data Matters” (2021), (India), available at: [Link] (last
visited on Sep. 20, 2021).
77
FTC, “Privacy and Security” (2021), (India), available at: [Link] (last
visited on Sep. 26, 2021).
Page | 17
Introduction
operational mechanisms, challenges, and the need for reforms to enhance their
efficiency, especially in the context of a globally interconnected digital economy.78.
This thesis will also investigate how these regulatory mechanisms are enforced, what
challenges they face, and what measures can be taken to strengthen them. Technologies
such as Big data analytics, Artificial Intelligence (AI), and ‘machine learning (ML)’
have revolutionized how personal data is collected, processed, and utilized. Although
these innovations provide many advantages, they also introduce risks that jeopardize
personal privacy. This thesis investigates the Impact of such technologies on privacy
protection and assesses whether existing legal mechanisms are equipped to manage
these risks while safeguarding fundamental rights.
This thesis aims to provide a comprehensive analysis of the legal provisions and
regulatory mechanisms that are available to protect privacy in the digital space. By
addressing these research questions, this thesis will contribute to a better understanding
of the challenges and opportunities that exist in safeguarding privacy in the digital era.
In the digital age, privacy rights have become a critical issue, with individuals
increasingly using digital technologies to communicate, conduct business, and engage
in social interactions. Governments and regulatory bodies around the world have put in
place legal and regulation, this thesis seeks to contribute to a better understanding of
the legal and regulatory frameworks in place to protect privacy rights in the digital age
and offer insights into how these frameworks can be improved to better safeguard
individuals' privacy rights in the digital speculator frameworks to protect individuals'
privacy rights in the digital space79. However, there are concerns that these frameworks
may not be sufficient to address the challenges posed by the rapidly evolving digital
landscape. Emerging risks such as deepfakes and cross-border data flows further
complicate privacy enforcement in the digital space. This thesis highlights these risks
and explores strategies to mitigate them through innovative regulatory solutions and
international collaboration. A comparative analysis of India’s privacy framework with
those of the United States and the European Union will help identify gaps and propose
78
DPA, “What is a Data Protection Authority?” (India), available at: [Link]
edpb/board/members_en (last visited on Oct. 03, 2021).
79
Peter Nemitz & Paul Burgess (eds.), The right to privacy in the Digital Age (Springer 2014).
Page | 18
Introduction
This thesis aims to explore the legal and regulatory mechanisms in place to
protect privacy rights in the digital space, with a particular focus on the digital context.
The thesis will address the research questions of what legal provisions are available to
protect privacy in digital space, and whether there are any regulatory mechanisms
available to address privacy violations in digital space80. The thesis will also assess the
current legal and regulatory mechanisms in place to protect privacy rights in the digital
space and identify any deficiencies in the Indian mechanisms. Additionally, the thesis
will undertake a comparative analysis with the Eurpean Union and United States legal
and regulatory mechanisms to evaluate the potential for improvement in the Indian
mechanisms. This thesis seeks to answer critical research questions, offering an in-
depth understanding of the challenges and opportunities related to privacy rights in the
digital age. It seeks to offer insights into how existing legal and regulatory frameworks
can be enhanced to better protect privacy while fostering technological progress. This
research posits that existing privacy laws, including the Digital Personal Data
Protection Act of 2023 in India, are inadequate in safeguarding individuals rights
against emerging technological advancements such as “Big data' analytics, artificial
intelligence, surveillance technologies, and transnational data exchanges”.
Consequently, there is a pressing need for more comprehensive and globally aligned
regulatory frameworks. Through an exploration of critical research questions, this study
aims to deliver an in-depth analysis of the issues and opportunities linked to privacy
rights in the digital age. It also seeks to recommend ways to strengthen current legal
and policy structures to enhance privacy protections while encouraging technological
innovation. The research will particularly focus on the impact of widespread
surveillance systems and their potential to encroach on individual privacy. Moreover,
it will evaluate the practicality of incorporating privacy-centric technologies into
surveillance practices to achieve a balance between ensuring security and safeguarding
personal freedoms.
Overall, this thesis aims to enhance the understanding of the legal and regulatory
frameworks in place to protect privacy rights in the digital age and offer insights into
80
Amitai Etzioni, The Limits of Privacy (Basic Books, New York, 1999).
Page | 19
Introduction
how these frameworks can be improved to better ‘safeguard individuals privacy rights
in the digital space’.
IDENTIFICATION OF PROBLEM
The core issue is the serious threat to individual and informational privacy posed
by emerging digital technologies. 86 Although there is a wealth of literature on data
protection and privacy, most of it concentrates on particular topics, such the effects of
specific technology or the efficacy of particular legislation. In the Indian context, there
is a dearth of thorough analysis of the overall efficacy of the legal procedures in place
81
General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, Article 1, Official Journal
of the European Union (2016)
82
The Digital Personal Data Protection Act, 2023, No. 22, Acts of Parliament, 2023 (India).
83
Privacy Act, 1974, 5 U.S.C., (United States).
84
SLP (C) 804/2017
85
Pegasus spyware and related privacy concerns: "The use of spyware like Pegasus has raised
significant debates about digital privacy, building on earlier controversies involving programs like
CMA and PRISM."
86
United States Constitution, Amendment IV.
Page | 20
Introduction
LITERATURE REVIEW
These scholarly works collectively provide a rich foundation for understanding the
complexities of digital privacy. They highlight the interplay between technology, legal
frameworks, and ethical considerations, offering valuable insights into creating a
balanced and forward-thinking approach to privacy governance in the digital age. Each
contribution underscores the urgency of evolving privacy norms to keep pace with
technological advancements, ensuring that individual rights and societal progress
coexist harmoniously.
The researcher has consulted cyber law resources and books that tackle the risks
linked to with ‘internet usage’, noting that these risks vary depending on factors such
as “connectivity method, hardware type, security devices, and the nature of the user”
e.g., “educational institutions, government agencies, businesses, or private homes”88.
In this context, the evaluation of the literature in the following pages will look
at how different studies have approached the many facets of the subject of privacy
protection in India.
The landmark case ‘Justice K.S. Puttaswamy (Rtd.) and Anr. v. Union of India
& Ors’. 89 provided significant insights into the right to privacy in India. The SC
recognized ‘privacy as a fundamental right’ under 'Article 21' of the Indian
Constitution. The Court emphasized that an individual’s right to control their ‘personal
data and manage their personal and digital life’ is essential to their overall right to
privacy.
87
Privacy rights rooted in religious texts: "Scholars have identified proto-privacy rights in texts such as
the Qur’an, sayings of Mohammad, and the Old Testament," see Privacy and Human Rights: An
International Survey of Privacy Laws and Developments 5 (2002).
88
Dr. Farooq Ahmad, Cyber Law in India 305 (New Era Law Publications, Delhi, 2nd edn.,2005).
89
AIR 2017 SC 4161
90
Government of India, “Report on the Data Protection Law” (2018)
Page | 21
Introduction
‘Article 12’ of the UDHR of 1948 outlines privacy rights related to personal
space and communication, stating that no one should face arbitrary interference with
their “privacy, family, home, or correspondence, nor be subjected to attacks on their
honour or reputation”. It further guarantees legal protection against such
interferences91.
Issues related to internet privacy are also addressed in the 'United Kingdom’s
Data Protection Act of 1998', enacted on July 16, 1998, to implement the European
Union’s Data Protection Directive. This law has been pivotal in addressing privacy
matters in Great Britain92.
91
Universal Declaration of Human Rights adopted and proclaimed by General Assembly resolution
217A(III) of December 10, 1948.
92
Nandan Kamath (ed.), Law Relating to Computers, Internet and E-Commerce 380 (Universal Law
Publishing Co. Pvt. Ltd., Delhi, 2000).
93
General Data Protection Regulation, European Union (India), available at: [Link]
gdpr/ (last visited on Nov. 10, 2021).
94
R. Walters, Cybersecurity and Data laws of the Commomwealth: International Trade, investment and
arbitration (Springer Nature 2023)
Page | 22
Introduction
The book Cyber Security, Artificial Intelligence, Data Protection & the Law95
by Robert Walters and Marko Novak offers a comprehensive examination of the
evolving landscape of data protection law in the context of emerging technologies,
particularly ‘cyber security’ and Artificial Intelligence (AI). This work stands out for
its critical evaluations and guidance across various branches of ‘data protection law’,
making it a valuable resource for “legal scholars, practitioners, and policymakers
alike”.
95
Robert Walters and Marko Novak , Cyber Security, Artificial Intelligence, Data Protection & the Law
(Springer Nature 2021)
96
Julie M. Robillard et al., “Emerging Ethical and Privacy Concerns in AI Applications” 10(4)
Frontiers in Computational Neuroscience 1 (2019).
97
Michael Arnheim, The Handbook of Human Rights Law: An Accessible Approach to the Issues and
Principles (Kogan Page Ltd. 2004).
98
Mira Swaminathan and Arindrajit Basu, Surveillance and Data Protection: Threats to Privacy and
Digital Security, (2020-2021).
Page | 23
Introduction
report covers the Design and Impact of Surveillance technology, Domestic Laws and
International Standard.
99
Hyman Gross, Privacy: Its Legal Protection (Oceana Publications, N.Y., 1976).
100
Securing Rights: Legal Frameworks for Privacy and Data Protection in the Digital Era, (2023).
101
Constitutional Law in the Digital Age: Addressing Privacy and Cybersecurity Challenges, (2023).
102
Ethical Dilemmas and Privacy Issues in Emerging Technologies: A Review, (2023).
103
Digital Technologies: Tensions in Privacy and Data, (2023).
Page | 24
Introduction
privacy risks these practices pose to consumers. It categorizes privacy into information,
communication, and individual privacy, and discusses how each is affected by
corporate data strategies.
"A Key Review on Security and Privacy of Big data104: Issues, Challenges,
and Future Research Directions" (2023) - This review in the Signal, Image, and Video
Processing journal addresses the security and privacy issues associated with Big data.
It highlights the challenges in protecting data privacy in the context of large-scale data
analytics and suggests future research directions to enhance privacy-preserving
techniques.
104
A Key Review on Security and Privacy of Big data, (2023).
105
Bernadette Kamleitner & Vince Mitchell, “Your Data Is My Data: A Framework for Addressing
Interdependent Privacy Infringements” 38(1) Journal of Public Policy & Marketing 43 (2019).
106
Privacy-Preserving Collaborative Model Learning, (2023).
107
France Bélanger and Robert E. Crossler, “Privacy in the Digital Age: A Review of Information Privacy
Research in Information Systems”,35 MIS Quarterly,2011
Page | 25
Introduction
"Efficient and Secure Big data Storage System with Leakage Resilience in
Cloud Computing" (2023)109 - This article in Software Computing discusses a secure
system for Big data storage in the cloud, addressing potential data leakage and privacy
concerns.
"Privacy and Data Protection in the Era of Big data: Balancing Security
and Efficiency" (2023) 111 - This book discusses the balance between maintaining
privacy and achieving efficiency in Big data systems, with a focus on the legal and
ethical implications of data protection.
108
Efficient Privacy Preservation of Big Data for Accurate Data Mining, (2023).
109
Efficient and Secure Big Data Storage System with Leakage Resilience in Cloud Computing, (2023).
110
Proceedings from the International Seminar on "right to privacy in Digital Era – Challenges and
Solutions."
111
Privacy and Data Protection in the Era of Big Data: Balancing Security and Efficiency, (2023).
112
Consumer Privacy in the Digital Economy: Legal and Technological Challenges, (2023).
Page | 26
Introduction
113
Id.
114
Ira S. Rubinstein & Nathaniel Good, “Privacy by Design: A Counter factual Analysis of Google and
Facebook Privacy Incidents”, 29 Berkeley Tech. L.J. 1333 (2014).
115
Margot E. Kaminski & Jennifer M. Urban, “Legal and Ethical Implications of Automated Decision-
Making Systems Powered by Artificial Intelligence”, 11 Colum. Sci. & Tech. L. Rev. 29 (2019).
116
Daniel J. Solove, “Privacy Self-Management and the Consent Dilemma”, 126 Harv. L. Rev. 1880
(2013).
Page | 27
Introduction
article argues that expecting individuals to manage their privacy effectively through
consent mechanisms is impractical due to the complexity of data practices and the
overwhelming nature of privacy policies. Solove advocates for systemic reforms that
reduce reliance on individual consent and instead enforce organizational accountability,
providing a pragmatic approach to privacy governance in an increasingly data-driven
world.
117
Ashwin Karale, “The Challenges of IoT: Addressing Security, Ethics, Privacy and Laws”, 58 Ind. J.
Info. Tech. 92 (2020).
118
Morgan Carter, “The Optimal Opt-In Option: Designing Effective User Consent Mechanisms”, 47
Geo. J. Int’l L. 853 (2016).
119
David Alpert, “Beyond Request-and-Respond: ProActive Frameworks for Privacy and Data Protec-
tion”, 25 Yale J.L. & Tech. 112 (2022).
Page | 28
Introduction
The primary objective of the study is to analyse the serious threat to the right to privacy
of individuals by the information technologies in the digital spaces. It also aims to check
the effectiveness of the present legal mechanism to deal with it. Main objectives of the
study are as follows:
1. To analyze the evolving concept of the right to privacy in the context of digital
technologies and its implications for individual autonomy and democratic societies.
5. To explore the need for globally harmonized regulations and propose strategies for
enhancing privacy protection in light of rapid technological advancements.
6. To investigate the role of public awareness in understanding data privacy risks and
empowering individuals to take control of their personal information.
Page | 29
Introduction
HYPOTHESIS
RESEARCH QUESTIONS
1. How has the concept of the right to privacy evolved in the context of the digital era,
and what are its implications for individual autonomy and democratic societies?
2. In what ways do technological advancements, such as Big data, artificial
intelligence, and machine learning, Impact the protection of privacy rights?
3. How effective are existing legal frameworks, including India’s Digital Personal
Data Protection Act of 2023 and the GDPR, in addressing privacy challenges in the
digital age?
4. What are the emerging privacy risks posed by innovations like deepfakes and cross-
border data flows, and how can they be effectively mitigated?
5. To what extent is there a need for globally harmonized regulations to protect privacy
in the digital era, and what strategies could be implemented to achieve this?
6. How does public awareness and understanding of data privacy risks influence
individuals’ ability to protect their personal information in the digital landscape?
This study seeks to deepen theoretical insights into privacy rights by examining them
through historical, legal, and technological lenses. By combining these perspectives,
the research aims to provide a holistic view of privacy protections and their evolution,
highlighting how these rights have been shaped by legal precedents, societal values,
and technological advancements. The study is intended as a resource for policymakers,
legal experts, and technology professionals, offering them a clearer understanding of
Page | 30
Introduction
RESEARCH METHODOLOGY
The methodology for this study follows a purely doctrinal methodology, which is
characterized by detailed ‘descriptive and analytical approaches’. This method involves
an in-depth examination of “legal principles, statutes, and precedents, relying heavily
on a thorough study of existing materials”. By focusing on established laws and
scholarly interpretations, the doctrinal approach aims to offer a structured analysis of
the research topic.
In this study, both primary and secondary sources form the foundation of
research. Primary sources include examination of laws such as India’s Digital Personal
Data Protection Act of 2023, the European Union’s ''General Data Protection
Regulation'' (GDPR), and other relevant legislative frameworks. It also includes
analysis of judicial decisions to understand the judicial interpretation of privacy in the
context of evolving digital technologies.
Page | 31
Introduction
to identify recurring patterns and themes in the legal frameworks and case law related
to privacy. Key themes include surveillance, data breaches, cross-border data flows,
and the challenges posed by AI and machine learning. This approach will help in
highlighting specific issues that need to be addressed to enhance privacy protections in
the digital era.
This research explores how privacy rights are changing in the digital age, focusing on
the serious risks that information technologies pose. Its scope includes an in-depth
investigation of the constitutional and legislative provisions that support privacy
protection, as well as a comprehensive assessment of the historical evolution of privacy
rights and a comparative comparison of national and worldwide viewpoints. Along with
examining how technology changes affect privacy rights, this research also examines
data protection laws now in place and suggests improvements to strengthen them.
Through evaluation and recommendation of strict measures, the research seeks to
effectively discourage violations of the right to privacy.
This study is important in several ways. First of all, it is a useful tool for
legislators and policymakers, providing information that helps them tailor legal
frameworks to the changing needs of the digital era. Moreover, it enriches ongoing legal
debate by adding to the conversation on privacy rights and the Impact of technology.
FRAMEWORK OF STUDY
The thesis unfolds across six interconnected chapters, meticulously designed to address
the multifaceted dimensions of the right to privacy in the digital era.
Chapter First begins with introductory remarks precisely introducing the topic, its
rationale, highlighting the framework of study, objectives of the study, hypothesis, and
the methodology adopted, identification of problem, review of literature including
research gap and outlining the brief remarks over the entire study. The inaugural chapter
sets the stage by delineating the primary objective of the study: the analysis of the
serious threat posed to individual privacy by information technologies in digital spaces.
Page | 32
Introduction
It aims to evaluate the efficacy of current legal mechanisms. This chapter outlines key
objectives, including the exploration of the historical development of the right to
privacy, examination at both international and national levels, and a spotlight on
constitutional and statutory provisions.
Building on the groundwork laid in Chapter One, the second chapter delves into the
development of privacy jurisprudence of the right to privacy. It spans ancient roots, the
Enlightenment era, and the contemporary challenges posed by the digital revolution.
This chapter forms a crucial backdrop for understanding the development of privacy
rights, leading to a comprehensive exploration of the Indian legal framework. It
highlight the view of jurists and their idea about the concept of privacy. It also zooms
in on the legal framework for privacy protection, examining significant privacy-related
cases in India and proposing measures to fortify India's right to privacy. This section
contributes valuable insights into the ongoing discourse surrounding privacy rights in
the realm of The Information Technology Act, 2000 and 'The Digital Personal Data
Protection Act, 2023'. The chapter also undertakes other ancillary legislation related to
protection and recognition of right to privacy.
This chapter also discusses the role of the judiciary in protecting such rights.
Privacy protection in India is rooted in the constitutional framework, which guarantees
fundamental rights to its citizens. While the right to privacy is not explicitly mentioned
in the Constitution of India, it has been recognized and protected through judicial
interpretation
The third chapter navigates the intricate landscape of technological advancement and
its Impact on the right to privacy. It critically analyzes problematic definitions of
"privacy," explores the architecture of the Internet of Things, and delves into marketing
privacy concerns. Additionally, it probes the psychological components of privacy and
examines the intersection of justice with privacy dimensions. It summarizes the current
status and theoretical roots of the two most distinct "branches" of privacy law—
autonomy (both physical and decisional) and informational privacy. This Part also
Page | 33
Introduction
Chapter four: Comparative Analysis of Right to Digital Privacy in India with USA
and European Union.
The fourth chapter adopts a comparative lens, juxtaposing the right to digital privacy in
India USA and the European Union. It evaluates legal frameworks, cultural
perspectives, technological advancements, and emerging challenges. The chapter
concludes with insights on global privacy standards and cross-border data flows,
offering recommendations for safeguarding digital privacy in an interconnected world.
Understanding their differing approaches not only provides insights into their domestic
policies but also contributes to a broader understanding of the global discourse
surrounding digital privacy.
The fifth chapter scrutinizes 'The Digital Personal Data Protection Act, 2023', tracing
the evolution of personal data protection laws in India, constitutional provisions, and
the landscape of data protection under various statutes. It analyzes key features of the
Act, provides suggestions for lawmakers, and critically evaluates the implications of
the new Data Protection Act in 2023.
The sixth chapter deals with the conclusion and suggestion of the thesis.
Page | 34
Introduction
The relationship between AI and privacy becomes even more intricate when one
considers its application in surveillance. Modern surveillance systems, bolstered by AI
technologies such as facial recognition, behavior prediction, and automated decision-
making tools, have enabled entities to monitor individuals with unprecedented
precision and scale. While these capabilities can enhance security and streamline
processes, they also pose significant threats to civil liberties and individual
autonomy 121 . For example, AI-driven surveillance systems can lead to mass data
collection and profiling, raising concerns about misuse, discrimination, and the erosion
of fundamental rights122. The lack of transparency in how AI models make decisions
further exacerbates these concerns, as individuals often have limited visibility into the
mechanisms that influence critical outcomes, such as credit approvals, job recruitment,
or even criminal justice proceedings.
120
M. Schwartz & D.J. Solove, Information Privacy Law, 7th ed. (Aspen Publishing,2023).
121
Daniel J. Solove, “Privacy Self-Management and the Consent Dilemma” 126 Harvard Law Review
1880 (2013).
122
Ibid.
Page | 35
Introduction
The digital era has also seen the proliferation of The Internet of Things (IoT),
further compounding privacy concerns. IoT devices, ranging from smart home
assistants to wearable fitness trackers, collect and exchange vast amounts of data,
including location information, biometric data, and behavioral patterns. These
interconnected ecosystems often create vulnerabilities that can be exploited by
malicious actors, leading to security breaches and unauthorized access to personal
information123. The constant tracking and monitoring capabilities of IoT devices raise
questions about the extent to which individuals' lives are being observed and recorded,
often without their explicit consent or understanding. To safeguard privacy in this
context, robust legal frameworks are imperative. Such frameworks should mandate
clear user consent for data collection, establish stringent standards for data security, and
promote the adoption of privacy-enhancing technologies like encryption and data
anonymization.
123
Orin S. Kerr, “The 'Fourth Amendment' and New Technologies: Constitutional Myths and the Case
for Caution” 102 Michigan Law Review 801 (2004).
124
Graham Greenleaf, “Global Data Privacy Laws 2022: 144 National Laws & 20 Bills” 172 Privacy
Laws & Business International Report 1 (2022).
Page | 36
Introduction
125
Neil M. Richards, “The Dangers of Surveillance” 126 Harvard Law Review 1934 (2013).
Page | 37
Introduction
The Internet of Things (IoT)126 has transformed the way we interact with everyday
objects, from smart home devices to wearable fitness trackers. IoT devices collect and
exchange data, often including personal information, to provide enhanced functionality
and convenience. However, the widespread adoption of IoT raises significant privacy
challenges. IoT devices capture vast amounts of sensitive data, such as location
information, biometric data, and personal habits. The constant monitoring and tracking
capabilities of IoT devices can result in unprecedented intrusion into individuals'
private lives. Moreover, the interconnected nature of IoT ecosystems increases the
vulnerability of personal data to security breaches and unauthorized access. Addressing
privacy challenges in the IoT era requires implementing robust security measures,
ensuring user consent and control over data collection and sharing, and promoting
transparency regarding data practices. Privacy-enhancing technologies, such as
encryption and data anonymization, can also be pivotal in alleviating ‘privacy risks
associated with IoT’.
126
Office of the Victorian Information Commissioner, “Internet of Things and Privacy - Issues and
Challenges” (2021), (India), available at: [Link]
organisations/internet-of-things-and-privacy-issues-and-challenges/ (last visited on Oct. 10, 2021).
127
Adi Kuntsman & Esperanza Miyake, Paradoxes of Digital Disengagement: In Search of the Opt-
Out Button (2021), (India), available at: [Link]
refreqid=search-gateway (last visited on Oct. 25, 2021).
Page | 38
Introduction
collection and retention, judicial review, and independent oversight bodies, can help
ensure accountability and safeguard privacy rights in the face of surveillance 128
activities.
The digital era presents unique privacy challenges due to the rapid advancement
of technology and the extensive collection and processing of personal data. Addressing
these challenges requires a multifaceted approach that encompasses legal frameworks,
technological innovations, and societal awareness. Protecting privacy in the digital era
entails incorporating privacy-by-design principles into the development of
technologies, ensuring individuals' informed consent and control over their data, and
fostering transparency and accountability in data practices. Moreover, ongoing
dialogue between policymakers, technology developers, and privacy advocates is
crucial to navigate the evolving landscape of privacy challenges and strike an
appropriate balance between innovation and privacy protection. By proactively
addressing emerging privacy challenges, India can establish a robust legal framework
and technological infrastructure that promotes privacy protection and fosters trust in the
digital ecosystem. To curb this issue not only the legislature helped but the judiciary
also played an important role. There were several times when the SC passes several
judgments favoring the privacy in digital space.129
The rise of the internet and the digital revolution in the late 2oth century introduced
unparalleled challenges to privacy. The internet provided new avenues for
“communication, information sharing, and commerce”, but it also raised concerns
about the erosion of personal privacy.130
Online platforms, social media, and search engines collect vast amounts of
personal data, leading to the loss of anonymity and potential invasions of privacy.
128
Privacy and Civil Liberties Oversight Board (PCLOB), Report on Surveillance Programs (2014,
United States).
129
Justice K.S. Puttaswamy (Retd.) & Anr. v. Union of India & Ors., (2017) 10 SCC 1.
130
Office of the United Nations High Commissioner for Human Rights, "The right to privacy in the
Digital Age," (India), available at: [Link]
DigitalAge/ReportPrivacyinDigitalAge/[Link] (last visited on Oct. 30,
2021).
Page | 39
Introduction
The erosion of anonymity online has sparked debates about the extent to which
individuals can maintain privacy in the digital age. The challenges posed by the internet
have prompted the development of privacy regulations and the need for “individuals,
governments, and technology companies” to find a balance between the benefits of
connectivity and the protection of personal information.
The digital age has also witnessed a proliferation of data collection practices,
132
often conducted without individuals' full awareness or consent. Companies,
governments, and other entities collect, analyze, and utilize vast amounts of personal
data, raising significant privacy concerns.
The growing recognition of these privacy concerns has led to the development
of data protection laws and regulations worldwide. For example, the European Union's
'General Data Protection Regulation' (GDPR) 134 introduced comprehensive privacy
regulations to protect individuals' rights and provide greater control over their personal
data.
131
Social Media Privacy, Electronic Privacy Information Center, [Link]
privacy/social-media-privacy/.(last visited on Nov. 02, 2021).
132
Id.
133
Id.
134
General Data Protection Regulation, Apr. 27, 2016, O.J. (L 119) 1.
135
Office of the United Nations High Commissioner for Human Rights, "The right to privacy in the
Digital Age," (India), available at: [Link]
DigitalAge/ReportPrivacyinDigitalAge/[Link] (last visited on Nov 05, 2021)
Page | 40
Introduction
The increased surveillance capabilities have raised concerns about the balance
between security interests and individual privacy. Debates surrounding the legality and
proportionality of surveillance practices have been at the forefront of privacy
discussions. Court cases and legislative efforts aim to establish safeguards and
oversight mechanisms to protect privacy rights while addressing national security
concerns.
Advances in genetics and genomics have presented new challenges to privacy rights.
The ability to sequence and analyze an individual's genetic code has revolutionized
medical research, personalized medicine, and forensic investigations. However, it also
raises concerns about the privacy and security of genetic information.136
Genetic data contains highly personal and sensitive information that can reveal
an individual's predisposition to certain diseases, ancestry, and even familial
relationships. The potential for unauthorized access, data breaches, and misuse of
genetic information poses significant privacy risks.
Efforts to protect genetic privacy include regulations and ethical guidelines that
govern the collection, storage, and sharing of genetic data. Striking the right balance
between advancing scientific knowledge and safeguarding individuals' genetic privacy
remains an ongoing challenge.
136
Id
Page | 41
Introduction
The case of “Justice K.S. Puttaswamy and Anr. v. Union of India” 137 ,
Identified as the 'Aadhaar case', by the SC. The case challenged the constitutionality
of the Aadhaar project, a “unique identification system” that collected biometric and
demographic data of the residents. The SC reiterated that the right to privacy is a
fundamental right and emphasized the need to ensure the collection of biometric data
is conducted in a manner that upholds an individual's privacy and dignity. This
judgment further solidified the constitutional protection of privacy rights and
emphasized the importance of balancing technological advancements with individual
privacy.
The SC, in its judgment, recognized the right to privacy as a fundamental right
protected under 'Article 21' of the Indian Constitution. It affirmed that privacy is an
essential aspect of human dignity and individual autonomy. The judgment emphasized
the need for robust data protection measures and imposed restrictions on the use of
Aadhaar data, emphasizing the importance of informed consent and purpose limitation.
The case of 'R. Rajagopal v. State of Tamil Nadu' (1994)138, Under "Article
19(1)(a)" of the Constitution, the SC ruled that the right to privacy is an ‘essential
component of the right to freedom of speech and expression’139. The SC decided that it
would be an infringement of privacy if “someone's personal information was published
without their permission”. The ruling established a precedent for privacy protection
within the context of ‘freedom of speech and expression’ and acknowledged the
‘individual's right’ to manage the distribution of their personal information.
In this case, 'Selvi and Ors. v. State of Karnataka (2010)'140, The admissibility
of evidence gathered via techniques like narco-analysis and other types of involuntary
testing was investigated by the Supreme Court. The Court ruled that subjecting
individuals to such tests without their consent violated their right to privacy and
‘dignity’, enshrined under ''Articles 20(3)''141 and 21142 of the Constitution. This ruling
137
(2017) 10 SCC 1.
138
1995 AIR 264
139
The Constitution of India, art. 19 cl. 1(a).
140
(2010) 7 SCC 263.
141
The Constitution of India. art. 20 cl. 3.
142
The Constitution of India. art. 21.
Page | 42
Introduction
highlighted how crucial it is to uphold a ‘person's autonomy and protect their right to
privacy’, especially when conducting ‘criminal investigations’.
The SC tackled the problem of sexual harassment in the workplace in this historic de-
cision, acknowledging the necessity of rules to stop and deal with it. The Court stressed
that eliminating sexual harassment is crucial to guaranteeing the exercise of the funda-
mental right to work with dignity guaranteed by "Article 21" of the Constitution. This
case was crucial in establishing the legal framework that addresses sexual harassment
in the workplace and recognizes the value of a respectful and safe workplace.
The constitutionality of Section 66A of the IT Act, which made some forms of online
expression illegal, was at the center of this dispute. Citing a violation of the right to
freedom of speech and expression guaranteed by "Article 19(1)(a)" of the Constitution,
the Supreme Court ruled that Section 66A was unconstitutional 145 . The ruling
underlined the need of preserving online free speech while acknowledging the necessity
of striking a balance with justifiable worries about morality and public order. This
decision had significant implications for upholding the right to privacy in the digital
age and ensuring the protection of free expression online.
The landmark judgments discussed above have had a significant Impact on privacy
protection in India. They have helped shape the legal framework and provided guidance
on the interpretation and application of privacy laws. The Impact of these judgments
can be observed in the following ways:
143
(1997) 6 SCC 241.
144
AIR 2015 SC 1523.
145
The Constitution of India. art. 19 cl. 1(a).
Page | 43
Introduction
individual autonomy”.
Strengthening of data protection laws: The judgments have influenced the drafting
and formulation of data protection laws in India, such as the 'Personal Data Protection
Act' (PDPB). They have prompted policymakers to incorporate key privacy principles
and provisions into the legislation to ensure stronger privacy safeguards.
Overall, these rulings have been crucial in shaping the understanding and
implementation of privacy protection in India. They have contributed to the
development of a robust legal framework and fostered a greater awareness of privacy
rights among individuals and organizations.
Page | 44