LAW AND TECHNOLOGY
MODULE 5 NOTES
Privacy, Law and Technology
5.1 Origin and Development of Law of Privacy
5.2 Concept and Nature and Law of Privacy
5.3 The Digital Personal Data Protection Act, 2019
1. Concept and Meaning of Privacy
1. Definition:
o Privacy refers to an individual's right to be let alone, to control access to their personal information, and to
make autonomous decisions without unwarranted interference by the State or others.
2. Essence:
o It embodies personal liberty, dignity, and informational control — the ability to decide what to share,
with whom, and for what purpose.
3. In the digital age:
o Privacy extends to data protection, cyber surveillance, social media usage, online banking, and digital
footprints.
o Cybercrimes such as identity theft, phishing, unauthorized data access, hacking, and online stalking are
direct violations of privacy rights.
2. Historical Origin of Privacy Law (Global Perspective)
1. Early Roots:
o The concept of privacy evolved from common law principles of trespass, defamation, and confidentiality.
o Initially, it was seen as a property right, later evolving into a human right.
2. Key Milestone – 1890:
o The concept was first explicitly recognized as a legal right in the United States through a landmark
publication.
3. Landmark World Case:
Case 1 – Warren and Brandeis Case (1890)
Citation: Samuel D. Warren and Louis D. Brandeis, “The Right to Privacy”, Harvard Law Review, Vol. IV, No. 5
(Dec. 15, 1890)
(i) Background:
• In late 19th-century America, the press had begun invading private lives through photographs and gossip columns.
• Warren and Brandeis, disturbed by the press intrusion into personal affairs, argued for a distinct right to privacy.
(ii) Issues:
• Can individuals claim legal protection for personal privacy separate from traditional torts like defamation or
trespass?
(iii) Related Laws:
• There was no explicit privacy law; only property-based torts like trespass and defamation were available.
(iv) Arguments Advanced:
• The authors argued that technological innovations (like photography and newspapers) required new legal
recognition of privacy.
• Proposed a new common law right: “the right to be let alone.”
(v) Judgement / Contribution:
• Although not a judicial decision, the article influenced U.S. courts profoundly.
• It formed the foundation for the modern Right to Privacy in U.S. jurisprudence and inspired future rulings.
(vi) Ratio Decidendi:
• Privacy is an independent, fundamental right rooted in human dignity, distinct from property or reputation.
(vii) Obiter Dicta:
• Society must balance freedom of the press with individuals’ right to privacy.
(viii) Critical Analysis:
• Warren & Brandeis’ conception of privacy was visionary—it foresaw modern data privacy challenges in an era
before the Internet.
• It laid the intellectual groundwork for later U.S. decisions such as Griswold v. Connecticut (1965) and Roe v.
Wade (1973).
(ix) Conclusion:
• The Warren-Brandeis article marks the birth of privacy as a legal right — later expanded globally as part of the
right to life, liberty, and dignity.
4. Development of Privacy in India
Pre-Constitutional Era:
• India, under colonial rule, did not have a codified privacy right.
• The concept evolved post-independence through judicial interpretation of Article 21 (Right to Life and Personal
Liberty).
5. Early Indian Cases on Privacy
Case 1 – M.P. Sharma v. Satish Chandra (1954)
Citation: AIR 1954 SC 300
Coram: Eight-Judge Bench of the Supreme Court of India
(i) Background:
• Concerned with searches and seizures conducted during investigations into company affairs under the Companies
Act.
• Petitioners claimed that such searches violated their right to privacy under Article 20(3) (self-incrimination) and
Article 21.
(ii) Issues:
• Does the Constitution of India recognize a fundamental right to privacy?
(iii) Related Laws:
• Article 20(3) – Protection against self-incrimination.
• Article 21 – Protection of life and personal liberty.
• Search and Seizure provisions under CrPC.
(iv) Arguments Advanced:
• Petitioners argued that broad search powers infringed upon their personal liberty and privacy.
• The State argued that no such fundamental right was recognized.
(v) Judgement:
• The Court held that the Constitution does not explicitly recognize the right to privacy.
• Therefore, search and seizure under law could not be struck down on that ground.
(vi) Ratio Decidendi:
• No constitutional guarantee of privacy exists under Article 21.
(vii) Obiter Dicta:
• The framers of the Constitution did not intend to incorporate a separate right to privacy.
(viii) Critical Analysis:
• The judgment reflected a colonial-era view prioritizing state interests over personal liberty.
• However, it was rendered before the doctrine of “expansive interpretation of Article 21” was established.
(ix) Conclusion:
• Privacy was not yet recognized as a fundamental right in India at this stage.
6. Progressive Development in India
Case 2 – Kharak Singh v. State of Uttar Pradesh (1962)
Citation: AIR 1963 SC 1295
(i) Background:
• Police surveillance under the U.P. Police Regulations allowed domiciliary visits at night for suspects.
• The petitioner argued this violated his privacy and liberty.
(ii) Issues:
• Does unauthorized surveillance violate Article 21 (Right to Life and Personal Liberty)?
(iii) Related Laws:
• Article 19(1)(d) – Freedom of movement.
• Article 21 – Right to life and liberty.
(iv) Arguments Advanced:
• Surveillance amounts to invasion of privacy and dignity.
• State contended that such surveillance was necessary for public safety.
(v) Judgement:
• The majority upheld police surveillance but struck down domiciliary visits as unconstitutional.
• Subba Rao, J. (Dissent): Recognized Right to Privacy as implicit in Article 21.
(vi) Ratio Decidendi:
• Privacy, though not expressly mentioned, is an essential ingredient of personal liberty.
(vii) Obiter Dicta:
• “The right to privacy is an integral part of personal liberty” — (Justice Subba Rao’s dissent became a foundation
for future rulings).
(viii) Critical Analysis:
• The dissenting opinion became jurisprudentially significant, influencing future recognition of privacy as a
fundamental right.
(ix) Conclusion:
• Kharak Singh was a turning point — from denial (M.P. Sharma) to recognition of privacy as implicit in liberty.
7. Recognition of Privacy as a Fundamental Right
Case 3 – Justice K.S. Puttaswamy (Retd.) v. Union of India (2017)
Citation: (2017) 10 SCC 1 (Nine-Judge Bench)
(i) Background:
• Challenge to the constitutional validity of the Aadhaar project (biometric ID system).
• Petitioners claimed it violated the Right to Privacy.
(ii) Issues:
• Whether the Right to Privacy is a fundamental right under the Constitution?
• Whether earlier rulings (M.P. Sharma and Kharak Singh) denying such a right were correct?
(iii) Related Laws:
• Article 14 – Right to equality.
• Article 19 – Freedoms.
• Article 21 – Right to life and personal liberty.
• Information Technology Act, 2000 – Section 43A & 72A (data protection & confidentiality).
(iv) Arguments Advanced:
• Petitioners: Privacy is intrinsic to life and liberty; essential for dignity and autonomy.
• State: Right to privacy is not expressly enumerated and can be restricted for public interest.
(v) Judgement:
• Unanimous (9–0): Privacy is a fundamental right protected under Articles 14, 19, and 21.
• Overruled M.P. Sharma (1954) and Kharak Singh (majority) (1962).
(vi) Ratio Decidendi:
• Right to Privacy is inherent in the right to life and personal liberty and forms part of the constitutional
guarantees of dignity, autonomy, and freedom.
(vii) Obiter Dicta:
• Privacy includes:
o Bodily privacy (e.g., medical decisions).
o Decisional autonomy (e.g., marriage, sexuality, procreation).
o Informational privacy (e.g., data protection, digital surveillance).
(viii) Critical Analysis:
• The judgment integrated global human rights jurisprudence (e.g., Griswold v. Connecticut, Roe v. Wade, R v.
Dyment).
• It established a constitutional benchmark for data protection and cyber privacy.
• However, the absence of a dedicated Data Protection Law was highlighted as a lacuna.
(ix) Conclusion:
• Puttaswamy transformed the Indian legal landscape — establishing privacy as a fundamental,
multidimensional, and enforceable right.
• It forms the constitutional foundation for protecting citizens in cyberspace.
8. Privacy in the Context of Cyber Crimes
1. Cyber Privacy Violations include:
o Unauthorized access (hacking, phishing).
o Identity theft and data breaches.
o Online harassment, doxxing, cyberstalking, and revenge pornography.
2. Relevant Indian Laws:
o Information Technology Act, 2000:
▪ Section 43A: Compensation for failure to protect data.
▪ Section 66C: Identity theft.
▪ Section 66E: Violation of privacy through electronic transmission.
▪ Section 72 & 72A: Breach of confidentiality and disclosure of information.
o Indian Penal Code (Bharatiya Nyaya Sanhita, 2023):
▪ Sections on criminal intimidation, defamation, and voyeurism.
o Constitutional Backing: Article 21 (Right to Privacy).
3. Judicial Relevance Post-Puttaswamy:
o The decision strengthens constitutional challenges against mass surveillance, data leaks, and
unauthorized profiling.
9. Critical Analysis
1. Evolutionary Nature:
o Privacy evolved from an undefined concept to a fundamental right through judicial interpretation.
2. Digital Imperative:
o The recognition of privacy as informational control aligns with the digital age, where personal data is the
“new oil.”
3. Global Convergence:
o India’s position now aligns with global standards such as the EU General Data Protection Regulation
(GDPR).
4. Remaining Gaps:
o Absence of comprehensive Data Protection Law (Digital Personal Data Protection Act, 2023 is a
beginning).
o Balancing privacy with national security and cyber surveillance remains a challenge.
10. Conclusion
• The Right to Privacy has evolved from a moral claim to a constitutional and human right.
• The journey from Warren & Brandeis (1890) → M.P. Sharma (1954) → Kharak Singh (1962) →
Puttaswamy (2017) demonstrates a shift from state-centric to individual-centric jurisprudence.
• In the era of cybercrime, AI, and data analytics, privacy safeguards are indispensable to protect human dignity
and liberty in cyberspace.
“Privacy is not a privilege—it is the constitutional oxygen that sustains human dignity in a digital world.”
1. Meaning and Concept of Privacy
1. Definition:
o Privacy means the right of an individual to be left alone — to live life free from unwanted interference by
others, including the State, media, or private entities.
2. Etymology:
o Derived from the Latin word “Privatus” meaning “separated from the rest” or “withdrawn from public life.”
3. Basic Essence:
o It is the autonomy of the individual — the freedom to make personal choices, control personal information,
and maintain one’s dignity and individuality.
4. Philosophical Foundation:
o Privacy is deeply linked to human dignity, liberty, and individuality, which are intrinsic to democratic
societies.
o It protects both the “freedom to be” (personal autonomy) and the “freedom from” (interference).
5. Nature of Privacy in the Modern Era:
o In the digital age, privacy extends beyond the physical realm (home, body) to the virtual sphere — emails,
biometrics, data, social media, and online communication.
6. Scholarly Definition (Warren & Brandeis, 1890):
o “Privacy is the right to be let alone.”
o It represents the earliest legal articulation of privacy as a distinct legal right.
7. Contemporary Understanding (Post-Puttaswamy, 2017):
o Privacy encompasses:
▪ Bodily privacy – control over one’s body.
▪ Decisional privacy – autonomy in personal life choices.
▪ Informational privacy – control over personal data and communications.
2. Nature and Characteristics of the Right to Privacy
1. (i) Fundamental and Inherent Right:
o Privacy is inherent in human existence, not granted by the State.
o The Supreme Court of India in Justice K.S. Puttaswamy v. Union of India (2017) affirmed privacy as a
fundamental right under Articles 14, 19, and 21.
2. (ii) Negative and Positive Aspect:
o Negative aspect: Protection against unwarranted interference by State or others.
o Positive aspect: Imposes an obligation on the State to safeguard individuals’ privacy (e.g., through data
protection laws).
3. (iii) Dynamic and Contextual Nature:
o The scope of privacy evolves with technological, social, and cultural changes.
o It adapts to new contexts such as AI, social media, surveillance, and genetic data.
4. (iv) Relative, Not Absolute:
o Privacy is not absolute; it can be reasonably restricted for legitimate purposes like:
▪ National security
▪ Public order
▪ Prevention of crime
▪ Protection of others’ rights
5. (v) Interconnected with Other Rights:
o Privacy is intertwined with:
▪ Right to life and liberty (Art. 21)
▪ Freedom of speech and expression (Art. 19(1)(a))
▪ Freedom of movement (Art. 19(1)(d))
▪ Right to dignity (Preamble + Art. 21)
6. (vi) Multi-Dimensional Character:
Privacy has several dimensions:
o Physical Privacy: Protection from physical intrusions (home, body searches).
o Informational Privacy: Protection of data and communication from misuse.
o Decisional Privacy: Freedom in personal choices (marriage, reproduction, gender identity).
o Proprietary Privacy: Protection of confidential business or personal information.
o Spiritual/Mental Privacy: Freedom of thought, conscience, and belief.
7. (vii) Balancing Test:
o Privacy must be balanced with competing interests.
o Puttaswamy (2017) laid down a three-fold test:
▪ Legality: Any invasion must have a legal basis.
▪ Necessity: Must serve a legitimate state aim.
▪ Proportionality: Action must be the least intrusive means available.
3. Evolution and Development of Privacy Law
1. Ancient and Pre-Modern Roots:
o Ancient Indian texts like Manusmriti and Arthashastra recognized personal sanctity (e.g., prohibitions on
intruding into private dwellings).
2. 19th Century:
o The modern legal recognition of privacy emerged through Warren and Brandeis (1890) in the USA — the
foundational scholarly work.
3. 20th Century Developments (Globally):
o Universal Declaration of Human Rights (UDHR, 1948):
▪ Article 12 – “No one shall be subjected to arbitrary interference with his privacy, family, home, or
correspondence.”
o International Covenant on Civil and Political Rights (ICCPR, 1966):
▪ Article 17 – Similar protection against arbitrary interference.
4. Development in India (Case Law Timeline):
o M.P. Sharma v. Satish Chandra (1954) – No fundamental right to privacy recognized.
o Kharak Singh v. State of U.P. (1962) – Dissenting view (Justice Subba Rao) recognized privacy as part of
personal liberty.
o Govind v. State of Madhya Pradesh (1975) – Privacy recognized but subject to restrictions.
o R. Rajagopal v. State of Tamil Nadu (1994) – Media cannot publish private information without consent.
o Justice K.S. Puttaswamy v. Union of India (2017) – Privacy declared as a fundamental right.
4. Privacy in the Digital and Cyber Context
1. Digital Transformation:
o With social media, online transactions, and digital surveillance, privacy now includes data protection and
cybersecurity.
2. Cyber Privacy Violations Include:
o Hacking (Sec. 66 IT Act)
o Identity Theft (Sec. 66C IT Act)
o Violation of Privacy through electronic means (Sec. 66E IT Act)
o Breach of confidentiality (Sec. 72, 72A IT Act)
o Cyberstalking (Sec. 354D IPC / BNS)
o Revenge pornography & unauthorized publication of images.
3. Information Technology (Amendment) Act, 2008:
o Introduced Section 43A — liability of body corporates for failure to protect data.
o Section 66E – Punishes capturing or transmitting private images without consent.
4. Digital Personal Data Protection Act (DPDPA), 2023:
o India’s first comprehensive data privacy law.
o Regulates collection, storage, and use of personal data.
o Establishes the Data Protection Board of India.
o Defines rights of individuals: Right to access, correction, and erasure of data.
5. Cyber Jurisprudence on Privacy:
o Recognizes that informational privacy (control over personal data) is central to autonomy.
o Courts apply the proportionality test for data surveillance or interception cases.
5. Constitutional Foundation of Privacy in India
1. Article 21:
o “No person shall be deprived of his life or personal liberty except according to procedure established by
law.”
o The Supreme Court interpreted “life” to mean more than animal existence, encompassing dignity and
privacy.
2. Articles 14 & 19:
o Article 14 (Equality before law) and Article 19 (freedom of expression, movement, association) form a
“golden triangle” with Article 21 — ensuring privacy as part of liberty and equality.
3. Judicial Recognition:
o In Puttaswamy (2017), the Court held that privacy is an intrinsic part of the right to life and liberty,
forming a natural, inalienable, and fundamental human right.
4. Scope of Privacy under Article 21:
o Protects:
▪ Home and family life
▪ Communications and correspondence
▪ Reputation and dignity
▪ Personal data and bodily autonomy
▪ Sexual orientation and identity
6. Statutory Recognition of Privacy in India
1. Information Technology Act, 2000 (as amended in 2008):
o Sections 43A, 66C, 66E, 72, and 72A directly address digital privacy violations.
2. Indian Penal Code / Bharatiya Nyaya Sanhita, 2023:
o Protects privacy through provisions on defamation, criminal intimidation, voyeurism, and stalking.
3. Digital Personal Data Protection Act, 2023:
o Comprehensive framework for data collection, storage, and transfer.
4. Indian Telegraph Act, 1885:
o Section 5(2) allows lawful interception but subject to procedural safeguards (privacy limitations).
5. Aadhaar Act, 2016:
o Regulates use of biometric data for identification, emphasizing informed consent.
7. Important Dimensions of the Law of Privacy
Dimension Description Example / Legal Basis
Physical Privacy Protection from physical intrusion or Kharak Singh v. State of U.P.
surveillance.
Informational Privacy Control over personal and digital data. Puttaswamy v. Union of India (2017)
Decisional Privacy Freedom to make intimate personal Navtej Singh Johar v. Union of India (2018)
decisions.
Reputational Privacy Protection against defamation and R. Rajagopal v. State of Tamil Nadu (1994)
character attacks.
Communicational Secrecy of communications (calls, emails, PUCL v. Union of India (Telephone Tapping
Privacy chats). Case, 1997)
8. Relationship Between Privacy and Cyber Crimes
1. Cybercrimes directly violate informational privacy by unauthorized data access, surveillance, or disclosure.
2. Data breaches and identity theft can lead to psychological, financial, and reputational harm.
3. Privacy laws act as preventive mechanisms by penalizing unauthorized access and misuse.
4. Law enforcement must balance investigation needs with individual privacy under judicial oversight.
9. Challenges in Enforcing Privacy
1. Lack of awareness about digital rights.
2. Overbroad surveillance powers of the State.
3. Weak data protection mechanisms and enforcement.
4. Balancing freedom of press and public interest.
5. Cross-border data transfer and jurisdictional hurdles.
10. Conclusion
• The concept of privacy has evolved from a moral claim to a fundamental constitutional and human right.
• The nature of privacy is multidimensional — encompassing physical, decisional, and informational aspects.
• In the cyber era, privacy is central to digital freedom and personal dignity.
• India’s recognition of privacy under Article 21 and the enactment of the Digital Personal Data Protection Act,
2023 signify a shift towards a data-responsible democracy.
“Privacy today is not just the right to be let alone — it is the right to control one’s digital self.”
Comparison Table: Traditional Privacy vs Digital Privacy
Aspect / Traditional Privacy Digital Privacy (Cyber Age) Examples / Relevant Laws &
Dimension Cases
Physical - Concerned with physical - Extends to digital Cases: - Kharak Singh v. State of
Privacy space, home, and body. - surveillance, CCTV U.P. (AIR 1963 SC 1295) –
Protection from physical monitoring, biometric data Police surveillance struck down. -
intrusion, surveillance, or collection, and geo-tracking. - Govind v. State of M.P. (1975) –
unauthorized entry by State Protects individuals from Surveillance permissible only
or individuals. invasive technologies. under lawful procedure.
Laws: - Article 21, Constitution
of India - IT Act, 2000 – Sec. 66E
(violation of privacy via
electronic means) - Digital
Personal Data Protection Act,
2023 (DPDPA)
Decisional - Autonomy over personal - Includes online autonomy – Cases: - Justice K.S. Puttaswamy
Privacy and family decisions (e.g., right to make decisions about v. Union of India (2017) –
marriage, procreation, data consent, social media Privacy as part of liberty and
religion). - Right to make usage, and digital identity. - dignity. - Navtej Singh Johar v.
intimate personal choices Also includes choices about Union of India (2018) – Sexual
without interference. AI profiling and digital orientation as an expression of
footprints. privacy. - Suchita Srivastava v.
Chandigarh Administration
(2009) – Reproductive autonomy
upheld.
Laws: - Articles 19 & 21,
Constitution of India - DPDPA,
2023 – Consent-based data
processing.
Informational - Concerned with - Involves control over digital Cases: - People’s Union for Civil
Privacy protection of personal data, social media Liberties (PUCL) v. Union of
correspondence, letters, and information, biometric India (1997) – Telephone tapping
communications. - details, emails, cloud storage, violates privacy unless under due
Freedom from arbitrary and financial records. - Focus process. - Puttaswamy v. Union
search and seizure of on data protection, consent, of India (2017) – Recognized
personal information. and encryption. informational privacy as core of
human dignity.
Laws: - Information Technology
Act, 2000: Sec. 43A (data
protection), 66C (identity theft),
72 (breach of confidentiality). -
DPDPA, 2023 – Rights to access,
correct, and erase personal data. -
Article 12, UDHR (1948); Article
17, ICCPR (1966).
- Protects secrecy of postal - Extends to emails, chats, Cases: - PUCL v. Union of India
Communicational communication, telegraphs, social media messages, and (1997) – Telephone tapping
Privacy and private cloud communications. - requires judicial oversight. -
correspondence. Protection against Anuradha Bhasin v. Union of
unauthorized interception, India (2020) – Internet access
hacking, or surveillance. linked with freedom of speech.
Laws: - Indian Telegraph Act,
1885, Sec. 5(2). - IT Act, 2000 –
Sec. 69 (interception). - DPDPA,
2023 – Digital communication
protection.
Reputational - Protection from - Protection from cyber Cases: - R. Rajagopal v. State of
Privacy defamation and intrusion defamation, revenge Tamil Nadu (1994) – Media
into private life through pornography, doxxing, cannot publish private
newspapers, gossip, or online character information without consent. -
photography. assassination, and deepfakes. Swami Ramdev v. Facebook Inc.
(2019) – Global injunction
against defamatory content
online.
Laws: - IPC / BNS, 2023 –
Defamation provisions. -IT Act,
2000 – Sec. 67, 67A (obscenity,
privacy violations). - DPDPA,
2023.
Key Takeaways
1. Traditional Privacy focused on physical and moral aspects — home, body, family, reputation.
2. Digital Privacy emphasizes data protection, informational control, and online autonomy in cyberspace.
3. The Right to Privacy today is both:
o A Constitutional Right (Article 21 of the Indian Constitution), and
o A Statutory Right (through the Information Technology Act, 2000 and the Digital Personal Data Protection
Act, 2023).
4. The nature of privacy has evolved from “right to be let alone” to “right to control one’s personal and digital
identity.”
Illustrative Summary
Traditional Privacy Digital Privacy
Protection of physical space, home, and body Protection of digital identity, data, and online
activity
Threats from physical surveillance or media intrusion Threats from hacking, data leaks, online profiling
Safeguarded under common law and early constitutional Governed by constitutional rights + IT & Data
jurisprudence Protection laws
Passive right – “to be let alone” Active right – “to control and manage personal
data”
In essence:
Traditional privacy protected personal space.
Digital privacy protects personal data.
Together, they form the modern constitutional and human right to privacy in the information age.
EVOLUTION OF PRIVACY: FROM WARREN & BRANDEIS (1890) → PUTTASWAMY (2017)
(Global & Indian Timeline – Legal and Constitutional Development of the Right to Privacy)
GLOBAL DEVELOPMENT TIMELINE
Year Event / Case / Instrument Jurisdiction Significance / Contribution
1890 Warren & Brandeis, “The Right USA First scholarly articulation of privacy as a legal right —
to Privacy” (Harvard Law “Right to be let alone.” Laid the foundation for privacy
Review, USA) law globally.
1948 Universal Declaration of United Declared protection from arbitrary interference with
Human Rights (UDHR), Article Nations privacy, family, home, or correspondence — recognized
12 privacy as a human right.
1966 International Covenant on Civil United Obligated States to protect individuals from unlawful
and Political Rights (ICCPR), Nations interference with privacy — gave privacy binding
Article 17 international legal force.
1965 Griswold v. Connecticut, 381 USA U.S. Supreme Court recognized privacy as a
U.S. 479 constitutional right under the “penumbra” of the Bill of
Rights — particularly in marital relations.
1973 Roe v. Wade, 410 U.S. 113 USA Extended the right to privacy to decisional autonomy
— reproductive choices and bodily integrity.
1981 OECD Privacy Guidelines OECD Created international principles on data protection —
Countries the basis for modern data privacy regulations.
1995 EU Data Protection Directive European Introduced comprehensive data protection norms —
(Directive 95/46/EC) Union precursor to the GDPR.
2016– EU General Data Protection European Established global benchmark for informational
2018 Regulation (GDPR) Union privacy, consent, and data control.
🇮INDIAN DEVELOPMENT TIMELINE
Year Case / Event / Law Significance / Legal Principle Established
1954 M.P. Sharma v. Satish Chandra, Supreme Court (8-Judge Bench) held that Right to Privacy is not a
AIR 1954 SC 300 Fundamental Right under the Indian Constitution.
1962 Kharak Singh v. State of U.P., Majority rejected privacy as a right, but Justice Subba Rao’s dissent
AIR 1963 SC 1295 recognized privacy as integral to personal liberty under Article 21.
1975 Govind v. State of Madhya Recognized privacy as implicit in Article 21 but subject to reasonable
Pradesh, AIR 1975 SC 1378 restrictions for state security and public interest.
1994 R. Rajagopal v. State of Tamil Affirmed privacy as the “right to be let alone” and held that publication
Nadu, (1994) 6 SCC 632 of private life without consent violates privacy.
1997 PUCL v. Union of India, (1997) 1 Declared telephone tapping violates privacy unless conducted under law
SCC 301 and procedural safeguards.
2009 Suchita Srivastava v. Recognized reproductive autonomy and bodily integrity as part of
Chandigarh Administration, privacy under Article 21.
(2009) 9 SCC 1
2012 Aadhaar Project Controversy Raised issues of biometric data collection and informational privacy.
begins
2017 Justice K.S. Puttaswamy (Retd.) Landmark Judgment: Unanimously declared Right to Privacy as a
v. Union of India, (2017) 10 SCC Fundamental Right under Articles 14, 19, and 21. Overruled M.P.
1 (9-Judge Bench) Sharma and Kharak Singh. Identified privacy as multi-dimensional —
bodily, decisional, and informational.
2023 Digital Personal Data Protection India’s first comprehensive data protection legislation giving statutory
Act (DPDPA), 2023 effect to informational privacy.
Key Takeaways for Lecture / Discussion
1. Global Influence: India’s privacy jurisprudence aligns with international human rights norms (UDHR & ICCPR).
2. Judicial Evolution: From denial (1954) → recognition (1975–1994) → constitutional affirmation (2017).
3. Modern Transition: From protecting physical and moral space to protecting digital data and autonomy.
4. Contemporary Relevance: The Digital Personal Data Protection Act, 2023 operationalizes informational
privacy recognized in Puttaswamy.
A small correction first: there is no “Digital Personal Data Protection Act, 2019” as such. What existed in 2019 was
the Personal Data Protection Bill, 2019 (PDP Bill 2019) which was proposed, not enacted. That Bill was later
withdrawn. What is enacted is the Digital Personal Data Protection Act, 2023 (DPDP Act / DPDPA-2023).
1. Why was a Personal Data Protection law proposed (2019 Bill) / Enacted (2023 Act) — Background &
Rationale
A. Background & Need
1. Supreme Court’s Puttaswamy Judgment (2017)
o The Supreme Court held that Right to Privacy is a fundamental right under the Indian Constitution (Articles
14, 19, 21).
o It also flagged that existing laws (e.g. IT Act, SPDI Rules) were inadequate to protect digital privacy.
2. Patchwork / Gaps in existing framework
o Under the Information Technology Act, 2000 and the SPDI Rules (Sensitive Personal Data or Information
Rules) there were limited protections for certain data categories (e.g. health, financial), and no overarching,
sector-agnostic data protection law.
o No mechanism to enforce rights like access, correction, erasure, data portability, or remedy for misuse.
3. Rise of digital economy & data-driven services
o Explosion of data collection by tech firms, social media platforms, e-commerce, AI / profiling.
o Frequent data breaches, misuse, surveillance, and cross-border flows of personal data.
4. Global trend & comparative regimes
o Many countries adopted GDPR (EU), CCPA (California), and similar statutory frameworks. India needed its
own comprehensive legislation to protect citizens’ data and regulate fiduciaries.
5. Parliamentary process & stakeholder demand
o In December 2019, the PDP Bill was introduced (by Ministry of Electronics & IT). (Wikipedia)
o It proposed a Data Protection Authority, consent regime, obligations on data fiduciaries, and rights of data
principals. (PRS Legislative Research)
o The Bill faced criticism over government exemptions, access for state agencies, etc., and was withdrawn in
2022. (Wikipedia)
B. Enactment of the DPDP Act, 2023
1. Replacement / successor law
o With PDP Bill withdrawn, the government introduced the Digital Personal Data Protection Bill, 2023,
which was passed by Parliament and received Presidential assent on 11 August 2023 to become the Digital
Personal Data Protection Act, 2023. (MeitY)
o It represents India’s first comprehensive cross-sectoral data protection law. (Future of Privacy Forum)
2. By whom / authority
o Enacted by Parliament of India. The Bill was introduced in Lok Sabha by Ashwini Vaishnaw, the Minister
of Electronics & IT. (Wikipedia)
o After passage in both Houses and President’s assent, it became law. (MeitY)
2. Objectives and Usefulness of DPDP Act / Data Protection Regime
Objectives / Purpose
• To recognize and protect the right of individuals (data principals) to control their digital personal data.
• To balance that right with the legitimate need to process such data for lawful purposes (business, governance,
public interest) so as not to obstruct growth of digital economy.
• To establish obligations on data fiduciaries (entities that decide how and why data is processed) and rights of
data principals.
• To institute a Data Protection Board of India as adjudicatory mechanism and oversight.
• To impose penalties and enforcement mechanisms to deter misuse and ensure compliance.
• To provide legal certainty to stakeholders (business, government, citizens) on data flows, cross-border transfers,
exemptions, etc.
Why Useful / Benefits
• Empowers individuals with control over their personal data: rights of access, correction, erasure, objection,
grievance redressal.
• Encourages trust in digital services (e-commerce, fintech, health tech) by ensuring data protection norms.
• Helps in preventing data misuse, identity theft, profiling without consent, surveillance abuse.
• Aligns India with global data protection standards, making cross-border data flows more manageable.
• Provides legal recourse for violations and misuses, thus acting as a deterrent.
• Promotes accountability in data processing and institutional oversight.
4. Examples & Illustrative Applications of Key Provisions
• Suppose Company A wants to collect your biometric face data for a service: They must obtain verifiable consent
(Sec. 4), inform you the purpose, who they share with, and allow withdrawal (Sec. 5).
• A Significant Data Fiduciary (e.g., a large social media platform) must do periodic audits, appoint a data
protection officer, and maintain local grievance redressal.
• If there is a data breach, the fiduciary must notify the Board (Sec. 28) and affected principals, mitigate the
impact, and maintain breach logs.
• A data principal may request correction or erasure (Sec. 12), and if fiduciary refuses, complain via fiduciary’s
redressal mechanism (Sec. 13) or escalate to the Board (Chapter V).
• For cross-border transfer from India to another country, fiduciary must ensure that the receiving country ensures
adequate data protection or follow conditions notified by government (Sec. 16).
• The Board (Sec. 21, 22) can impose penalties, direct deletion or restriction of processing, and order
compensation.
• Section 37 allows blocking access to data or services if a fiduciary persists in non-compliance or in public
interest.
• The Telecom Disputes Settlement & Appellate Tribunal (TDSAT) acts as appellate authority over Board
decisions (Sec. 22).
5. Critical Commentary / Issues & Challenges
• Limited scope: Act applies only to digital personal data; offline-only data not covered unless digitized. (Future
of Privacy Forum)
• No special category data: Unlike GDPR, DPDP Act does not distinguish “sensitive personal data” – all personal
data treated under same regime (though government may classify). (Future of Privacy Forum)
• Government exemptions: Broad exemptions for state agencies (national security, public order) may dilute
privacy protections. (MeitY)
• Timeline / commencement uncertainty: The Act is passed, but many provisions will come into force via
notifications and rules. (Latham & Watkins)
• Enforcement capacity: The Data Protection Board must be staffed, resource-equipped, and independent to be
effective.
• Balancing innovation vs regulation: Need to ensure that overly rigid regulation does not stifle legitimate data-
driven activity.
• Cross-border transfer constraints: For global companies, restrictions on data movement might pose operational
challenges.
• Consent fatigue & clarity: Verifiable consent must be meaningful; must avoid “clickwrap without
understanding.”
• Overlap with other laws: E.g. IT Act, sectoral laws (health, finance) — potential conflicts need harmonization.
Section-wise Summary Table: DPDP Act, 2023
Section Title / Theme Summary / Key Provisions Illustrative Example /
No. Notes
1 Short title, Gives the name: Digital Personal Data E.g., Sections on cross-
commencement Protection Act, 2023. Declares that different border transfer might start
provisions may commence on different dates by later than sections on
notification of the Central Government. consent.
2 Definitions Defines important terms: Data Principal, Data E.g., Data Fiduciary =
Fiduciary, Consent Manager, automated, Board, entity deciding “why and
child, processing, etc. how” data is processed.
3 Processing digital Any processing must be for a “lawful purpose” A company collecting only
personal data for lawful and adhere to principles (purpose limitation, data email and name (not
purpose; limitations minimization, accuracy, storage limitation, unnecessary sensitive data)
security, accountability). for newsletter.
4 Consent of Data Principal Requires verifiable consent from the principal Before collecting health
before processing, specifying purpose, data, a hospital asks explicit
categories, recipients. yes/no consent with details.
5 Withdrawal of Consent Principal can withdraw consent anytime; A user opts out: the service
fiduciary must cease processing and erase unless must delete her data (unless
legally required to retain. needed for legal
compliance).
6 Transparency, notices, Fiduciary must provide a clear notice (privacy On signup page, a “Privacy
etc. policy) with purposes, categories of data, third Notice” link with simple
parties, how to withdraw, and principal’s rights. language and options.
7 Retention and Erasure of Data should not be retained longer than After user unsubscribes,
Data necessary; fiduciary must erase or anonymize remove her records within
data when purpose ends or consent withdrawn. set time.
8 Security safeguards and Fiduciary must implement “reasonable security Encryption, access controls;
data breach practices” and notify Board and principals of if breach occurs, send
breaches. breach notice.
9 Risk mitigation, DPIA, Under certain conditions, fiduciary must carry Before deploying a facial
etc. out a Data Protection Impact Assessment recognition feature, do a
(DPIA) and take steps to reduce risk. DPIA.
10 Processing children’s data Stricter rules for data of children <18; must A gaming app must get
obtain verifiable parental consent; certain parental consent before
processing prohibited (targeted advertising) collecting child data.
unless exceptions.
11 Additional obligations of Entities with large data operations have added A major social media
Significant Data duties: audits, appoint Data Protection Officers, platform is “Significant” and
Fiduciary local grievance mechanism, periodic reporting. must publish audit reports.
12 Record-keeping Fiduciaries must maintain records of processing, Keep logs of processing
obligations security measures, DPIAs, etc. activity and security
reviews.
13 Grievance Redressal by Fiduciary must set up internal grievance A user complains;
fiduciary mechanism (at least two tiers) to address fiduciary’s grievance cell
complaints from principals. must respond within
timelines.
14 Rights of Data Principal: Principal can request the data being processed, A user requests a copy of
Access purpose, third parties, etc. her personal data held by the
service.
15 Right to Correction & Principal may ask to correct inaccurate data or Correct one’s address or
Erasure erase data, subject to legal retention obligations. delete profile.
16 Processing of personal Cross-border transfers allowed only subject to An Indian service storing
data outside India conditions / safeguards notified by government; data on a foreign server
fiduciary must ensure adequate protection must meet rules before
abroad. transfer.
17 Exemptions Government agencies may be exempt (for public Intelligence agency
order, sovereignty, security) via notification; processing data under
limited oversight. security exemption.
18 Establishment of Data Creates the Data Protection Board of India as the Complaints about data
Protection Board adjudicatory body for complaints and breach are adjudicated by
enforcement. this Board.
19 Composition of Board How Chairperson and members are appointed, Board must have experts in
qualifications, eligibility. data protection, law, tech.
20 Disqualifications, term, Conditions for disqualification, terms of service, A Board member cannot be
salary salaries, allowances for Board members. in conflict of interest.
21 Procedure & powers of The Board can investigate, adjudicate, issue Board calls documents,
Board orders, directions, impose penalties. holds hearings, etc.
22 Appeal to Appellate Decisions of the Board may be appealed to the If Board’s decision
Tribunal Telecom Disputes Settlement & Appellate unsatisfactory, approach
Tribunal (TDSAT). TDSAT.
23 Penalties & Penalties for breaches / non-compliance; Board Fine for delay in erasure,
Compensation can order compensation to affected persons. compensation to victim.
24 Limitation on penal Time limits / limitation periods for initiating Claim must be filed within
proceedings penal actions under the Act. specified period.
25 Protection for action Fiduciary or officers acting in good faith under If a fiduciary acts per rules
taken in good faith the Act are protected from legal liability. honestly, protection applies
if later challenged.
26 Offences by fiduciary or Defines offences (e.g., contravention of Fiduciary allowed agent to
agent obligations) and liability of fiduciary or its misuse; both may be liable.
agents.
27 Adjudication of breach Board’s power to adjudicate breaches, hold Board holds show cause
hearings, impose orders/penalties. notice, hears parties.
28 Reporting of personal Fiduciary must report to Board about data Within 72 hours of
data breach to Board breaches within prescribed time. detection, send report.
29 Emergency disclosures / Fiduciary may disclose data without consent in In a medical emergency,
legitimate disclosures emergencies or if required by law (e.g. for share health data with
investigation). hospital.
30 Audit by Board Board may direct audit of fiduciary’s Board orders audit of a
compliance; fiduciary must provide documents. social media platform.
31 Power of Board to require Board can demand anonymized aggregate data Board requests anonymized
non-personal for public interest or regulatory functions. usage stats from an app.
(anonymized) data
32 Power to block or disable Board may order blocking or disabling access to Block a site or data
access to data non-compliant data or services. repository violating rules.
33 Power to require identity Board may require identity of originator (in To trace a harasser, Board
of originator of data misuse cases) from fiduciary / intermediaries. asks the service to disclose
originator.
34 Interim orders & Board can issue temporary orders / injunctions to Board orders freezing of
injunctive relief prevent harm during investigation. data pending decision.
35 Power to restrict or Board may restrict or prohibit processing that Ban a feature suspected of
prohibit processing violates Act or public interest. unfair profiling.
36 Powers of investigation Board has powers like summons, inspect, call for Board summons logs of data
documents/records, examine witnesses. access.
37 Powers to block data / Authority (Board or government) may block Block misuse content or
services in public interest services or data sets crucial to public interest. service endangering public.
38 Powers to issue directions Board may issue directions/guidelines to ensure Board issues standard
/ guidelines compliance (standards, best practices). encryption guidelines.
39 Protection for action in Board members or its officers acting in good If Board enforcement
good faith (Board) faith are protected from personal liability. decisions are made honestly,
protection applies.
40 Offences & penalties by Additional definitions of offence types, Higher penalties for
fiduciaries or agents aggravating factors, multiple liabilities. repeated violations.
(continued)
41 Power to compound The Board may compound specific offences Fiduciary pays a penalty and
offences (settlements) based on conditions. avoids further proceedings.
42 Admissibility of Evidence collected under Act is admissible; Logs certified under rules
evidence, presumptions Board may draw presumptions in some cases. may be presumed valid.
43 Power to make rules Central Government may notify rules for Rules will clarify timelines,
implementation of Act’s provisions. forms, security standards.
44 Repeals & savings Repeals or modifies conflicting earlier laws; Old SPDI rules remain until
“savings” for prior actions and liabilities. replaced; ongoing
proceedings preserved.
Since the Digital Personal Data Protection Act, 2023 (DPDPA) is new and not yet fully enforced, no direct judicial
decisions have yet been pronounced under this Act.
However, the jurisprudence that forms its constitutional and interpretative foundation arises from landmark
privacy and data protection cases — both before and leading to the DPDPA, 2023.
Important Case Laws Related to the Digital Personal Data Protection Act, 2023
Justice K.S. Puttaswamy (Retd.) v. Union of India (2017)
Citation: (2017) 10 SCC 1 (Nine-Judge Bench, Supreme Court of India)
Coram: CJI J.S. Khehar, Dr. D.Y. Chandrachud, R.F. Nariman, Sanjay Kishan Kaul, et al.
Background:
• The case arose from the challenge to the Aadhaar Scheme — a government initiative to collect biometric and
demographic data of citizens for welfare delivery.
• Petitioners argued that Aadhaar violated the fundamental right to privacy.
Issues:
1. Is the Right to Privacy a fundamental right under the Constitution of India?
2. What is the scope and nature of this right in the context of the digital age?
3. Does the Aadhaar scheme violate privacy principles under Article 21?
Related Laws:
• Articles 14, 19, and 21 of the Constitution
• Information Technology Act, 2000
• Data protection principles drawn from Warren & Brandeis (1890) and R. Rajagopal v. State of Tamil Nadu (1994)
Arguments Advanced:
• Petitioners: Privacy is intrinsic to life and liberty; Aadhaar’s biometric collection is excessive and lacks
safeguards.
• State: There is no express right to privacy in the Constitution; Aadhaar is for welfare efficiency, not surveillance.
Judgment:
• The Supreme Court unanimously held (9–0) that Right to Privacy is a Fundamental Right protected under
Articles 14, 19, and 21.
• Overruled earlier cases — M.P. Sharma (1954) and Kharak Singh (1962).
Ratio Decidendi:
• Privacy is an intrinsic part of personal liberty and human dignity.
• It includes informational privacy, bodily autonomy, and decisional autonomy.
• The State must ensure data protection and accountability mechanisms when collecting or processing data.
Obiter Dicta:
• The Court emphasized the need for a comprehensive data protection legislation to safeguard informational
privacy in the digital era.
Critical Analysis:
• This judgment was the constitutional foundation for the DPDP Act, 2023.
• It recognized privacy not just as freedom from intrusion, but as positive control over personal information.
• The judgment also influenced legislative drafting of Sections 3–10 (lawful processing, consent, and data fiduciary
obligations).
Conclusion:
• Puttaswamy directly led to the creation of India’s Data Protection Regime, culminating in the Digital Personal
Data Protection Act, 2023.
Justice K.S. Puttaswamy (Aadhaar) v. Union of India (2018)
Citation: (2019) 1 SCC 1
Coram: CJI Dipak Misra, A.K. Sikri, A.M. Khanwilkar, D.Y. Chandrachud (dissent), Ashok Bhushan
Background:
• The follow-up case examined the constitutional validity of the Aadhaar Act, 2016, after Puttaswamy (2017) had
recognized privacy as a fundamental right.
Issues:
1. Does the Aadhaar system violate informational privacy and the right to dignity?
2. Are the provisions enabling data collection, retention, and sharing constitutional?
Related Laws:
• Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016
• Articles 14, 19, and 21
Arguments Advanced:
• Petitioners: The Aadhaar database creates a surveillance architecture and risks profiling.
• Respondents: Aadhaar is essential for welfare delivery, and data protection safeguards exist.
Judgment:
• The Court upheld Aadhaar’s constitutionality but struck down several provisions:
o Section 33(2) (national security access) and Section 57 (use by private entities) were invalidated.
o Emphasized data minimization and proportionality.
Ratio Decidendi:
• Privacy can be restricted only when the test of legality, necessity, and proportionality is satisfied.
• State surveillance and data collection must have lawful backing and safeguards.
Obiter Dicta:
• Directed the government to bring a dedicated Data Protection Law.
• Recommended creating a Data Protection Authority to enforce citizens’ informational rights.
Critical Analysis:
• Introduced the “Threefold Test” that became the guiding principle for Section 3 (lawful purpose) and Section 17
(exemptions) of the DPDP Act, 2023.
• Also influenced the drafting of provisions on purpose limitation, data retention, and lawful processing.
Conclusion:
• Aadhaar (2018) reinforced Puttaswamy (2017) and laid the constitutional benchmarks for lawful data
processing now enshrined in the DPDP Act.
R. Rajagopal v. State of Tamil Nadu (1994)
Citation: (1994) 6 SCC 632
Coram: Justice B.P. Jeevan Reddy and Justice S.C. Sen
Background:
• Concerned the publication of an autobiography of a death-row convict ("Auto Shankar") by a magazine
(Nakkheeran), which revealed private facts without consent.
Issues:
• Does the freedom of the press under Article 19(1)(a) override an individual’s right to privacy under Article 21?
Related Laws:
• Article 19(1)(a) – Freedom of speech
• Article 21 – Right to life and liberty
Arguments Advanced:
• Petitioners (Journalists): The right to publish true facts derived from public records.
• Respondents: Publishing private information violates privacy and dignity.
Judgment:
• Recognized the “Right to be let alone” as part of the right to privacy under Article 21.
• Publication of private facts without consent violates privacy, except when part of public records.
Ratio Decidendi:
• The right to privacy restrains unauthorized publication about private life without consent, unless it serves
public interest.
Obiter Dicta:
• Public officials may have limited privacy concerning their official conduct.
Critical Analysis:
• This case was India’s first judicial recognition of privacy before Puttaswamy.
• It inspired later inclusion of informational control and consent principles in the DPDP Act.
Conclusion:
• R. Rajagopal laid the common law foundation for informational privacy that the DPDP Act later codified
through Sections 4, 5, and 6 (Consent, Notice, and Transparency).
People’s Union for Civil Liberties (PUCL) v. Union of India (1997)
Citation: (1997) 1 SCC 301
Background:
• Concerned the telephone tapping orders issued under Section 5(2) of the Indian Telegraph Act, 1885.
• Petitioners challenged the surveillance as a violation of privacy.
Issues:
• Does telephone tapping violate the right to privacy under Article 21?
• What are the procedural safeguards for lawful surveillance?
Related Laws:
• Indian Telegraph Act, 1885 – Section 5(2)
• Article 21 – Right to Life and Personal Liberty
Arguments Advanced:
• Petitioners: Unrestricted tapping violates privacy and liberty.
• State: Surveillance is needed for national security; judicial scrutiny unnecessary.
Judgment:
• The Court held that telephone tapping is an invasion of privacy.
• Laid down detailed procedural safeguards to prevent misuse.
Ratio Decidendi:
• Privacy of communication is integral to Article 21.
• Surveillance must satisfy the tests of necessity and proportionality.
Obiter Dicta:
• Suggested periodic review of interception orders and accountability mechanisms.
Critical Analysis:
• This case directly influenced Section 17 (Exemptions) and Section 29 (Emergency disclosures) of the DPDP
Act.
• It laid down balance between security needs and privacy rights.
Conclusion:
• PUCL became the jurisprudential model for lawful data surveillance provisions under the DPDP Act.
Gobind v. State of Madhya Pradesh (1975)
Citation: (1975) 2 SCC 148
Background:
• Challenge to police surveillance regulations under the M.P. Police Act.
• Petitioner argued that domiciliary visits and secret watch violated privacy.
Issues:
• Does surveillance by the State violate Article 21?
• Is privacy protected under Indian Constitution?
Related Laws:
• Article 19(1)(d), Article 21
• Police Regulations (M.P.)
Judgment:
• Recognized privacy as a penumbral right under Article 21.
• However, allowed reasonable restrictions for public safety.
Ratio Decidendi:
• Privacy is an essential ingredient of liberty but subject to compelling public interest.
Critical Analysis:
• The first Indian case to implicitly recognize privacy.
• It influenced DPDP’s structure: data protection rights balanced with State exemptions (Section 17).
Anuradha Bhasin v. Union of India (2020)
Citation: (2020) 3 SCC 637
Background:
• Concerned the internet shutdown in Jammu & Kashmir after Article 370 abrogation.
• Raised issues of online access, speech, and informational rights.
Issues:
• Is internet access part of the freedom of speech and right to privacy?
• Can the State impose indefinite shutdowns?
Judgment:
• The Court held freedom of internet access is part of Article 19(1)(a) and Article 21.
• Any restriction must be necessary, proportionate, and time-bound.
Relevance to DPDP Act:
• Reinforces digital privacy and informational autonomy in cyberspace.
• Influences interpretation of Sections 3–5 (lawful processing and consent) and Section 37 (blocking in public
interest).
Internet and Mobile Association of India v. Reserve Bank of India (2020)
Citation: (2020) 10 SCC 274
Background:
• RBI prohibited banks from dealing with cryptocurrency exchanges.
• Petitioners argued it violated informational and financial privacy.
Issues:
• Whether RBI’s circular violated freedom to carry trade and informational privacy.
Judgment:
• Court struck down RBI’s circular as disproportionate under the test of reasonableness.
• Affirmed that informational autonomy in digital financial transactions is protected.
Relevance to DPDP Act:
• Emphasizes proportionality and due process in regulating digital activities — key to enforcement and
restrictions under DPDP’s Sections 17 & 37.
Shreya Singhal v. Union of India (2015)
Case Name & Citation
• Shreya Singhal v. Union of India
• AIR 2015 SC 1523; Writ Petition (Criminal) No. 167 of 2012
• Decided on 24 March 2015
Coram / Bench
• Justices R.F. Nariman and Jasti Chelameswar
• Opinion delivered by Justice R.F. Nariman
Brief Background
• Section 66A of the Information Technology Act, 2000 (as amended) criminalized sending “offensive,”
“menacing,” or “annoying” content over computers / communication devices.
• The provision was widely criticized for its vague language and potential for misuse.
• Several instances of arrests under Section 66A for social media posts (political commentary, satire, jokes) had
sparked public debate and litigation.
• Petitions were filed in the Supreme Court challenging the constitutional validity of Section 66A, and also
questioning Sections 69A and 79 of the IT Act, 2000, plus Section 118(d) of the Kerala Police Act (so far as it
borrowed 66A)
Facts of the Case
• The petitioners contended that because Section 66A’s terms (“grossly offensive,” “menacing,” “annoyance,” etc.)
were undefined and overbroad, individuals could be punished for innocuous speech.
• The State (Union of India) defended 66A as necessary to curb misuse of digital platforms (harassment, threats,
defamation, etc.) and maintain public order in cyberspace.
• The petitions argued that 66A violated Article 19(1)(a) (free speech) and did not meet the test of permissible
restrictions under Article 19(2). They also raised concerns under Article 21 (due process, dignity), and equality
(Article 14)
• For Sections 69A and 79: the challenge was whether the blocking powers and intermediary liability regime could
be abused or unconstitutional if not properly constrained.
Issues (Questions before the Court)
1. Whether Section 66A of the IT Act is violative of Article 19(1)(a) of the Constitution (i.e. free speech) because it
fails the test of “reasonable restriction” under Article 19(2).
2. Whether Sections 69A (blocking of public access to information) and Section 79 (intermediary liability) are
constitutionally valid or need to be read down.
3. Whether Section 118(d) of the Kerala Police Act (to the extent it adopts 66A) should be struck down.
Related Laws / Constitutional Provisions
• Article 19(1)(a) – Freedom of speech and expression
• Article 19(2) – Reasonable restrictions (for public order, decency, etc.)
• Article 14 – Equality / arbitrariness doctrine
• Article 21 – Protection of life and personal liberty
• IT Act, 2000 – Sections 66A, 69A, 79
• Rules under IT Act (Intermediary Guidelines)
• Kerala Police Act, Section 118(d) (as applied)
Arguments Advanced
Petitioners’ Arguments
• Section 66A’s terms are vague, subjective, overbroad, leading to arbitrary enforcement and “chilling effect” on
speech.
• It does not confine itself to serious harms or incitement to violence or public disorder; punishes “annoyance,”
“inconvenience,” which may cover innocuous speech.
• It cannot be saved as a “reasonable restriction” under Article 19(2).
• To the extent Kerala Police Act references 66A, that too must fall.
• Sections 69A and 79 must be read in a manner consistent with constitutional guarantees (i.e. procedural
safeguards, due process).
• The Court should ensure that intermediaries are not overburdened by open-ended takedown obligations without
judicial oversight.
Respondents’ Arguments (Union of India)
• The legislature intended flexibility to deal with evolving misuse in cyberspace; rigid definitions may limit
efficacy.
• Section 66A is necessary for maintaining public order, protecting citizens from harassment, defamation, threats.
• The mere possibility of misuse is not ground to strike down a law.
• For Sections 69A and 79: these provisions are essential for blocking harmful content and placing obligations on
intermediaries so they assist in regulation and accountability.
Judgment (Held by the Court)
• The Supreme Court struck down Section 66A entirely as unconstitutional.
• The Court read down Section 79 and associated rules so that intermediary liability will be triggered only on
receipt of judicial or governmental orders, not mere “actual knowledge” of illegal content.
• Section 69A was held constitutionally valid with procedural safeguards (hearing, central review, reasoned orders)
and thus not struck down.
• Section 118(d) of Kerala Police Act, insofar as it mirrors 66A, was struck down.
Ratio Decidendi (Core Legal Principles)
1. Vagueness & Overbreadth Doctrine: Laws must be clear and narrow — Section 66A’s vague terms like
“annoyance,” “offensive,” “insult” fail this requirement and allow arbitrary enforcement.
2. Chilling Effect: A law that deters lawful speech due to fear of punishment is unconstitutional.
3. Reasonable Restriction Test: A restriction on free speech must satisfy:
o Legality (valid, clear law),
o Legitimate Aim (public order, etc.),
o Proportionality / Narrow Tailoring (least restrictive means).
4. Intermediary Liability: The safe-harbour shield (Section 79) must be conditioned on due diligence and
compliance with judicial orders — intermediaries cannot be held liable just on “actual knowledge” absent court
orders.
5. Severability: If part of a statute is unconstitutional and cannot be saved by reading it narrowly, that part must be
struck down, not the entire Act.
Obiter Dicta / Additional Observations
• The Court underlined the distinct nature of internet speech: internet has near-zero cost, instant global reach, and
is different from traditional media.
• Emphasized that public order restrictions must relate to incitement, not mere discussion or advocacy.
• Noted that the legislature must in future regulate speech in digital realm with precision, clarity, procedural
safeguards.
• Recognized that protected speech includes political, ideational, satirical content, even if offensive to some.
Critical Analysis
Strengths of the Judgment
• Landmark protection of free speech in cyberspace — ensuring citizens can speak without fear of arbitrary legal
consequences.
• Introduced clarity in intermediary liability regime, protecting platforms from undue burden while retaining
accountability.
• Reinforced constitutional principles — vagueness doctrine, rule of law, and proportionality in digital regulation.
Weaknesses / Critiques
• Some argue the Court was too protective of speech, possibly limiting the State’s ability to act against harassment
or malicious speech online.
• The read-down of Section 79 may impose extra burden on intermediaries (e.g., they must wait for court orders).
• Absence of a comprehensive digital speech regulation framework: the judgment “clears the ground” but leaves
legislatures to fill the gap.
• Despite the strike-down, Section 66A is still sometimes used (as a “legal zombie”) in FIRs — implementation and
enforcement gaps remain.
Conclusion
• Shreya Singhal is a watershed judgment in Indian law that robustly reaffirms freedom of speech in the digital
age.
• It renders Section 66A unconstitutional and ensures that charges based on vague and subjective online speech
provisions cannot stand.
• The decision also redefines the liability of intermediaries, insisting that judicial oversight is necessary before
content takedowns.
• While it does not provide a full legislative framework for regulating online speech, it asserts that any future law
must conform to constitutional standards of clarity, narrowness, and procedural fairness.
• It remains a foundational precedent in Indian digital rights jurisprudence—guiding debates on hate speech,
disinformation, social media regulation, and intermediary liability.
Overall Analysis
Principle Established Key Case Reflection in DPDP Act, 2023
Right to privacy as fundamental Puttaswamy (2017) Preamble & Sections 3–5
Informational privacy Aadhaar (2018) Sections 4, 6, 7, 8
Freedom from unlawful surveillance PUCL (1997) Section 17, 29
Data minimization & consent R. Rajagopal (1994) Sections 4–6
State necessity & proportionality Gobind (1975) Sections 17 & 37
Digital autonomy & access Anuradha Bhasin (2020) Sections 3, 16, 37
Conclusion
• The Digital Personal Data Protection Act, 2023 is built on constitutional jurisprudence laid down from
Gobind (1975) to Puttaswamy (2017).
• These cases established that privacy is not a privilege but a constitutional guarantee, and the State has a
positive obligation to enact laws protecting it.
• The DPDP Act, 2023, thus translates judicial principles into statutory form, addressing digital privacy,
consent, data protection, and accountability.
In short:
“The journey from Gobind to Puttaswamy built the philosophy —
and the Digital Personal Data Protection Act, 2023 turned that philosophy into enforceable law.”