Satish Maurya
8 Sept 2026 10 min read

As AI systems rely heavily on vast amounts of information, they may pose serious risks to an individual's privacy if not regulated properly. In India, the Right to Privacy has been recognized as a fundamental right under Article 21 of the Constitution through judicial interpretation. Therefore, the rapid expansion of AI presents important legal and constitutional challenges. This article examines the relationship between Artificial Intelligence and the Right to Privacy in India, focusing on the existing legal framework, key challenges, and possible solutions. Nowadays, AI is widely used across the world. The privacy concern is increasing day by day regarding Artificial Intelligence (AI) because it collects, processes personal data. The objective of this Article to aware people about AI that how it became a concern regarding our privacy as we know The Right to Privacy is a fundamental right in India that is why the Artificial Intelligence create a legal and constitutional challenge.
UNDERSTANDING ARTIFICIAL INTELLIGENCE
AI stands for Artificial Intelligence that refers to computer systems or machines and gives capacity to think, learn and take decisions. AI improves its performance over time by learning from data and experience. And with minimal human intervention it solves hard work from its experiences. There are some examples of AI …ChatGPT, Siri, Alexa Google Assistants etc. AI applications in various sectors that is Education, Healthcare, Banking, Judiciary, Law Enforcement, social media etc.
RIGHT TO PRIVACY IN INDIA
Privacy is the power to choose what you share and what you keep hidden. It means having boundaries around your body, your thoughts, your home, and your personal data so that others cannot watch, control, or intrude upon you without your permission.
Privacy is a fundamental right in India that is Right to Privacy under article 21 of Indian constitution. It became a fundamental right through judicial expansion (judicial interpretation and case laws) of article 21 it has a broad scope under the constitution of India. This is not an absolute right there is also exception in this rule that if any publication of such matters is based on public record including court record it will be unobjectionable. If a matter becomes a matter of public record the right to privacy no longer exists and it becomes a legitimate subject for comment by press and media among others. Again, an exception must be carved out of this rule in the interests of decency under Art. 19(2)1in the following cases, a female who is the victim of a sexual assault, kidnapping, addiction or a like offence should not further be subjected to the indignity of her name and the incident being published in press or media.
LEGAL FRAMEWORK
Article 21: - The Right to Privacy is protected as an intrinsic part of the Right to Life and Personal Liberty under article 21 and as a part of freedom guaranteed by part 3rd of the constitution2.
Related acts- (1) Digital Personal Data Protection Act, 20233
(DPDP Act) is India’s first comprehensive law explicitly designed to operationalize and protect the fundamental right to digital privacy. Enacted as a direct consequence of the Supreme Court's mandate to safeguard citizens' data, the Act establishes a statutory framework for processing personal information by balancing individual privacy rights with lawful data processing needs.
Section 44(3) of the DPDP Act effectively amends Section 8(1)(j) of the RTI Act, 2005. Previously, public authorities could only deny personal information if it had no public interest. The DPDP Act creates a blanket ban on disclosing any personal data.
1) INDIA CONST. art. 19.
2) INDIA CONSTI. Art. 21.
3) Digital Personal Data Protection Act, No. 22 of 2023, INDIA CODE (2023).
(2) Information Technology Act, 2000 (IT Act)4
(IT Act) was India’s primary legal framework for the digital world before the DPDP Act, 2023. Since the original year 2000 text completely omitted data privacy, the landmark IT (Amendment) Act, 2008 was introduced. This amendment established the foundational statutory protections for digital and bodily privacy in India.
Section 43A (Data Privacy & Compensation): If a corporate entity handles Sensitive Personal Data or Information (SPDI) and is negligent in maintaining reasonable security, it is liable to pay unlimited compensation to the affected person.
Section 66E (Bodily Privacy & Voyeurism): This section criminalizes the act of intentionally capturing, publishing, or transmitting images of a person's private areas without their consent. It carries a penalty of up to 3 years in prison or a ₹2 lakh fine.
Section 72A (Breach of Confidentiality): It punishes any service provider or intermediary who discloses personal information without the user’s consent or in breach of a lawful contract. This carries up to 3 years of imprisonment.
LANDMARK CASE LAWS
(1) Justice K.S. Puttaswamy v. Union of India (2017)5
the petitioners had challenged the Aadhaar Project for creating an identity-related resident data base and the Supreme Court held that constitutional. Thereafter, the Parliament enacted the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, which gave statutory recognition to it. It was challenged as unconstitutional on the ground of being violative of fundamental right to privacy of innumerable citizens of India. A nine-Judge Constitution Bench held -Right to privacy is a fundamental right which can be traced to Articles 14, 19, 21 of the Constitution. The author of majority Judgement was Justice A.K. Sikri who gave judgment on behalf of Chief Justice Dipak Misra, Justice A.M. Khanvilkar, and himself.
4) Information Technology Act, No. 21 of 2000, INDIA CODE (2000).
5) Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 S.C.C.
The Supreme Court held- The architecture of Aadhaar as well as the provisions of the Aadhaar Act do not tend to create a surveillance state. This is ensured by the manner in which the Aadhaar project operates regarding data protection.3 All matters pertaining to an individual do not qualify as being an inherent part of right to privacy. Only those matters over which there would be a reasonable expectation of privacy are protected by Article 21. The Aadhaar Act meets the test of proportionality.
(2) People’s Union of Civil Liberties v. Union of India6
popularly known as Phone Tapping case', the Supreme Court held - Section 5 (2) of the Indian Telegraph Act, 1885 which authorized the Central Government or the State Government to tap telephone was a serious invasion of an individual's right to privacy which is part of the right to "life and personal liberty" enshrined under Art. 21 of the Constitution, and it should not be resorted to by the State except in case of requirement of public emergency or in the interest of
public safety. With the growth of highly sophisticated communication technology the right to hold telephone conversation in the privacy of one's home or office without interference is increasingly susceptible to abuse. In the absence of just and fair procedure for regulating the exercise of power under Section 5(2) of the Indian Telegraph Act, it is not possible to safeguard the rights of citizens guaranteed under Arts. 19(1)(a) and 21 of the Constitution. It was held that Right to Privacy is subservient to that of security of state.
(3) R. Rajagopal v. State of Tamil Nadu7
popularly known as "Auto Shanker case", the facts of which have already been discussed under fundamental rights to equality in this book, the Supreme Court held -The "right to privacy", or the right to be let alone is guaranteed by Art. 21 of the Constitution. A citizen has a right to safeguard the privacy of his own, his family, marriage, procreation, motherhood, child-bearing and education among other matters. None can publish anything concerning the above matters without his consent whether truthful or otherwise and whether laudatory or critical. If he does so, he would be violating the right of the person concerned and would be liable in an action for damages. However, position may be differed if he voluntarily puts into controversy or voluntarily invites or raises a controversy.
6) People's Union for Civil Liberties v. Union of India, (1997) 1 S.C.C. 301.
7) R. Rajagopal v. State of Tamil Nadu (1994) 6 S.C.C 632.
AI AND PRIVACY CHALLENGES
1. Massive Data Collection
AI systems collect large amounts of data to function effectively. It collects personal information such as names, phone numbers, email addresses, browsing history, location, biometric data, and online activities. This excessive collection of personal data increases the risk of misuse and unauthorized access, that is serious threat to an individual's privacy.
2. Facial Recognition and Biometric Surveillance
AI collects facial recognition and also biometric surveillance like if go Airport then there is facial recognition is important and if we go to give any government exam there is also need to biometric surveillance that is indirectly infringe the right to privacy.
3. Data Breaches and Cybersecurity Risks
AI systems store vast amounts of sensitive personal information. Weak cybersecurity and unauthorized hacking incidents may result in data breaches, identity theft, financial fraud, and unauthorized disclosure of confidential information.
4. Algorithmic Bias and Discrimination
AI systems may produce biased outcomes if they are trained on incomplete or discriminatory datasets. Such bias can affect decisions relating to employment, education, healthcare, credit, and law enforcement, thereby impacting equality and fairness.
5. Government and Corporate Surveillance
Governments and private companies can use AI to regulate individuals through CCTV cameras, online tracking, and digital profiling. Excessive surveillance without adequate legal safeguards may violate the constitutional right to privacy.
CRITICAL ANALYSIS
The use of Artificial Intelligence (AI) is increasing rapidly across the world and has become an important legal issue concerning the right to privacy. AI systems collect and process large amounts of personal data, which may be misused if adequate legal safeguards are not in place. Although India has enacted the Digital Personal Data Protection Act, 2023, there is still no comprehensive legislation specifically regulating Artificial Intelligence. As AI technology develops much faster than legislation, existing laws may not be sufficient to address emerging privacy challenges. Therefore, the government should establish a comprehensive legal framework that regulates AI while promoting innovation and protecting the fundamental right to privacy.
The Digital Personal Data Protection Act, 2023 protects personal data but does not comprehensively regulate AI systems. AI-based facial recognition and surveillance raise concerns regarding proportionality and individual privacy. India should develop an AI-specific regulatory framework that balances technological innovation with constitutional rights.
SUGGESTIONS
To ensure that Artificial Intelligence develops in a manner consistent with constitutional values and individual rights, the following measures may be considered:
1. Enact a comprehensive AI-specific legislation to regulate the development, deployment, and use of AI systems in India.
2. Strengthen the implementation of the Digital Personal Data Protection Act, 2023, through effective enforcement mechanisms and regulatory oversight.
3. Introduce transparency requirements so that AI systems provide understandable explanations for automated decisions affecting individuals.
4. Establish an independent AI regulatory authority to monitor compliance, investigate violations, and formulate ethical standards.
5. Mandate privacy-by-design principles in AI applications, ensuring that privacy protection is integrated into the design and operation of AI systems from the outset.
6. Enhance public awareness and digital literacy so that individuals understand how their personal data is collected, processed, and protected.
7. Encourage responsible innovation by promoting ethical AI practices while safeguarding constitutional rights, particularly the right to privacy.
CONCLUSION
Artificial Intelligence has become an indispensable part of modern society and offers immense opportunities for economic growth, innovation, and improved public services. However, its dependence on extensive personal data creates significant challenges to the protection of privacy and other fundamental rights.
India has taken important steps by recognizing the Right to Privacy as a fundamental right and enacting the Digital Personal Data Protection Act, 2023. Nevertheless, the evolving nature of AI requires a more comprehensive and forward-looking legal framework capable of addressing emerging risks such as algorithmic bias, mass surveillance, and lack of transparency.
Ultimately, the objective should not be to restrict technological advancement but to ensure that innovation proceeds in a manner that respects human dignity, constitutional values, and the fundamental right to privacy. A balanced regulatory approach, supported by effective enforcement and ethical AI governance, will enable India to harness the benefits of Artificial Intelligence while protecting the rights and freedoms of its citizens.
Satish Maurya
Iswar Saran Degree College (University of Allahabad)
Sign in to join the discussion.

Air pollution has emerged as one of the most serious public health challenges in India, contributing significantly to premature mortality, chronic respiratory and cardiovascular diseases and a reduced quality of life. Despite the existence of regulatory frameworks such as the National Clean Air Programme, air quality levels in many Indian cities consistently exceed national and international standards, indicating systemic policy and enforcement failures.

Childhood is often regarded as the purest expression of human innocence. Yet the very mind we instinctively associate with innocence is also one still learning how to remember, interpret, and make sense of the world.