Privacy is one of the most debated ideas in modern democratic life. But in India, the conversation about privacy is not just modern – it stretches back thousands of years. From Kautilya’s detailed prescriptions on state surveillance in the Arthashastra to the Supreme Court’s landmark 2017 ruling recognizing privacy as a fundamental right, India’s engagement with privacy has always been shaped by the tension between individual freedom and state authority. Understanding this long arc is essential for making sense of current debates around digital data, government surveillance, and personal autonomy.

Table of Contents

Ancient roots: privacy and surveillance in the Arthashastra

The Arthashastra, attributed to Kautilya (also known as Chanakya), is an ancient Sanskrit treatise on statecraft, economics, and military strategy, likely composed between the 2nd century BCE and the 3rd century CE. While it is best known for its advice on governance and diplomacy, it contains one of the earliest and most detailed systems of state intelligence ever documented.

Kautilya prescribed an elaborate network of spies – known as Gudhapurushas – who were classified into different roles and disguises, from monks and merchants to ordinary householders. These agents monitored not only external enemies but also internal threats: corrupt officials, rebellious subjects, and dissenting voices. The king was advised to devote a significant portion of his daily schedule to receiving and acting upon intelligence.

Scholar Roger Boesche has described the Arthashastra’s vision as resembling a surveillance state, where governance depended heavily on the systematic collection of information about citizens. As The SAIS Review of International Affairs notes, in Kautilya’s framework, the state’s duty to gather knowledge for stable governance overshadowed the individual’s right to privacy, since espionage was seen as integral to the state fulfilling its dharmic obligations.

This is a striking contrast to modern democracies where privacy is treated as a right that limits state power. Yet the Arthashastra is relevant precisely because it raises a question that India still grapples with: how much surveillance is justified in the name of security and good governance?

Privacy in other ancient Indian traditions

It would be incomplete to say ancient India was only about surveillance. Hindu, Buddhist, and Jain traditions have long valued the inner life of the individual – meditation, personal spiritual practice, and the protection of domestic spaces from intrusion. The concept of maryada (boundaries) in social life implicitly recognized that individuals and households had zones of autonomy that others – including rulers – should respect. So while the Arthashastra provides one pole of the debate (state power), Indian philosophical traditions provide the other (individual dignity and inner freedom).

The long constitutional silence on privacy

When India adopted its Constitution in 1950, the right to privacy was not explicitly mentioned among the fundamental rights listed in Part III. For decades, this absence created legal ambiguity. In M.P. Sharma v. Satish Chandra (1954), an eight-judge bench of the Supreme Court held that the Indian Constitution did not protect a right to privacy in the way the Fourth Amendment did in the United States. Nearly a decade later, in Kharak Singh v. State of Uttar Pradesh (1963), the majority again declined to recognize a standalone privacy right, although Justice Subba Rao’s powerful dissent argued that privacy was inherent in the right to personal liberty under Article 21.

Over the following decades, however, smaller benches of the Supreme Court repeatedly affirmed aspects of privacy in cases like Gobind v. State of Madhya Pradesh (1975) and R. Rajagopal v. State of Tamil Nadu (1994). This created what legal scholars have called an unresolved contradiction – a situation in which privacy was practically accepted by later courts but formally denied by the earlier, larger bench decisions. India, in effect, treated privacy as a right in practice without clearly declaring it in constitutional law.

The Puttaswamy judgement: privacy becomes a fundamental right

Everything changed on 24 August 2017, when a nine-judge bench of the Supreme Court delivered its unanimous verdict in Justice K.S. Puttaswamy (Retd.) v. Union of India. The court declared unequivocally that the right to privacy is a fundamental right protected under the Indian Constitution, primarily under Article 21 (right to life and personal liberty) and also as part of the freedoms guaranteed by Part III as a whole.

How the case arose

The case originated from a challenge to the government’s Aadhaar scheme – a biometrics-based identity system that the government proposed making mandatory for access to government services and benefits. Justice K.S. Puttaswamy, a retired Karnataka High Court judge, filed a petition arguing that Aadhaar violated the right to privacy. During hearings, the Attorney General of India took the position that the Constitution did not guarantee any fundamental right to privacy. A three-judge bench referred the question to a larger bench, which eventually became the nine-judge bench that decided the case.

What the court held

Writing for a plurality of four judges, Justice D.Y. Chandrachud held that privacy encompasses three key dimensions: repose (freedom from unwanted stimuli), sanctuary (the right to private spaces), and intimate decision-making (autonomy over personal choices). All five remaining judges wrote separate concurring opinions, but the verdict was unanimous on the central point: privacy is a constitutionally protected fundamental right.

The court explicitly overruled the earlier positions in M.P. Sharma and Kharak Singh to the extent that those decisions denied constitutional protection to privacy. Importantly, the court also held that privacy is not an absolute right. Any restriction on privacy must satisfy three conditions: legality (it must be based on a law), legitimate aim (it must serve a valid state purpose such as national security), and proportionality (the means used must be rationally connected to the aim).

The broader impact

The Puttaswamy judgement did far more than settle the privacy question. As noted by the Columbia University Global Freedom of Expression project, the ruling was expected to trigger constitutional challenges to a wide range of Indian legislation. That prediction proved correct: within a year, the Supreme Court relied on Puttaswamy to decriminalize homosexuality in Navtej Singh Johar v. Union of India (2018) and to strike down the offence of adultery in Joseph Shine v. Union of India (2018). The judgement also provided the constitutional impetus for India’s first comprehensive data protection law.

From judgement to legislation: India’s data protection journey

Following the Puttaswamy verdict, the government constituted a Committee of Experts under the chairmanship of retired Supreme Court judge Justice B.N. Srikrishna. The committee’s mandate was to examine data protection issues and propose a legislative framework for India. In July 2018, the committee submitted its report, titled “A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians,” along with a draft Personal Data Protection Bill.

Key recommendations of the Srikrishna Committee

The Srikrishna Committee recommended that any data protection law should be technology-neutral and applicable to both private organizations and the government. It emphasized that consent must be genuine, data processing should be minimal and limited to essential purposes, and strong penalties should be imposed for improper data handling. The committee also recommended rights like the right to be forgotten and the right to data portability – drawing substantially from the EU’s General Data Protection Regulation (GDPR).

However, the committee also flagged the need to balance individual rights with state interests. It observed that harms arising from data processing – including financial loss, identity theft, and unreasonable surveillance – should be regulated under the new law.

The long road to the DPDP Act, 2023

The legislative journey was far from smooth. A government version of the bill was introduced in Parliament in 2019 as the Personal Data Protection Bill. This version was referred to a Joint Parliamentary Committee, which submitted its report in 2021. But the government withdrew the bill entirely in August 2022, citing the need for a fresh approach. A new draft was released for public consultation in November 2022, and the final version – the Digital Personal Data Protection (DPDP) Act, 2023 – was passed by Parliament and received presidential assent on 11 August 2023.

The DPDP Act is India’s first cross-sectoral data protection law. It establishes a consent-based framework where entities collecting personal data (called data fiduciaries) must obtain clear, informed consent from individuals (data principals). It grants individuals rights to access, correct, and erase their data, and it creates a Data Protection Board of India to enforce compliance and adjudicate disputes. Penalties for violations can go up to โ‚น250 crore.

Notably, Justice Srikrishna himself was critical of the final version, particularly the broad exemptions it grants to government entities on grounds of sovereignty and public order. The Act also dropped the right to data portability and the right to be forgotten – both of which the Srikrishna Committee and the Joint Parliamentary Committee had recommended retaining.

India’s approach compared with GDPR and U.S. privacy law

Understanding India’s data protection framework requires placing it alongside the two other major models: the EU’s GDPR and the U.S. approach.

GDPR: the comprehensive model

The European Union’s General Data Protection Regulation, which came into effect in 2018, is widely regarded as the global benchmark for data protection. It applies to all forms of personal data (not just digital), has true extraterritorial reach, and distinguishes between personal and sensitive personal data. It gives individuals expansive rights including data portability, the right to object to automated decision-making, and the right to restrict processing. Penalties can reach up to 4% of an organization’s global annual turnover.

India’s DPDP Act was significantly influenced by GDPR, particularly in its emphasis on consent, transparency, and accountability. However, there are important differences. The DPDP Act applies only to digital personal data and does not create a separate category for sensitive personal data. It also offers narrower individual rights and provides broader government exemptions than the GDPR does.

The U.S.: a fragmented approach

The United States has no single, comprehensive federal privacy law. Instead, it relies on a patchwork of sector-specific statutes – HIPAA for health data, GLBA for financial data, COPPA for children’s online data – supplemented by state-level laws like the California Consumer Privacy Act (CCPA). This fragmented model emphasizes notice and opt-out mechanisms rather than the affirmative consent that India and the EU require.

India’s centralized approach under the DPDP Act contrasts sharply with this U.S. model. However, India shares with the U.S. a strong emphasis on national security exemptions, and both countries face criticism for giving the state substantial leeway in accessing personal data.

Where India stands

India occupies a middle ground. Its law is less comprehensive than GDPR but far more unified than the U.S. system. The DPDP Act reflects India’s specific concerns – massive digital adoption, the Aadhaar infrastructure, and the need to balance a booming digital economy with individual rights. The challenge going forward is whether implementation and enforcement will match the law’s ambitions.

Challenges: security, surveillance, and democratic accountability

The tension between privacy and security runs through every aspect of India’s privacy debate. The Aadhaar system, which has enrolled over a billion people, remains both a tool of efficient governance and a source of anxiety about mass surveillance. Programmes for lawful interception of communications and the proposed use of facial recognition technology raise similar concerns.

Critics point out that the DPDP Act’s broad exemptions for state agencies – particularly on grounds of sovereignty and public order – risk hollowing out privacy protections. Without robust judicial oversight or an independent supervisory authority, these exemptions could be used to justify extensive surveillance with limited accountability. The government’s power to appoint and remove members of the Data Protection Board further raises questions about the Board’s independence.

On the global stage, India’s approach will also need to reckon with cross-border data flows. As companies increasingly operate across jurisdictions, aligning India’s framework with international standards while preserving national policy autonomy will be a continuing challenge.

From Kautilya to data principals: what ties it all together

India’s privacy story is not a simple march from ignorance to enlightenment. The Arthashastra shows that Indian political thought has always been deeply aware of the power of information – and willing to use it. What has changed is the normative framework. Where Kautilya saw surveillance as a virtue of effective governance, the Puttaswamy court declared that individual dignity demands constitutional limits on the state’s power to intrude. The DPDP Act attempts to translate that constitutional commitment into a practical regulatory system, though its adequacy remains contested.

This evolution – from an ancient acceptance of state surveillance to a modern assertion of privacy as a fundamental right, and now to the ongoing struggle of building effective data protection institutions – captures something essential about democratic self-governance. It shows that rights are not simply declared; they must be continuously built, defended, and refined.

What do you think? Can India’s digital data protection framework effectively protect individual privacy while still enabling the state to pursue legitimate security interests? And does Kautilya’s ancient vision of information as the backbone of governance offer any lessons – positive or cautionary – for how we think about state surveillance today?

How useful was this post?

Click on a star to rate it!

Average rating / 5. Vote count:

No votes so far! Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?

References
  1. https://en.wikipedia.org/wiki/Arthashastra
  2. https://saisreview.sais.jhu.edu/the-indic-roots-of-espionage-lessons-for-international-security/
  3. https://www.scobserver.in/cases/puttaswamy-v-union-of-india-fundamental-right-to-privacy-case-background/
  4. https://ohrh.law.ox.ac.uk/defining-the-right-to-privacy-in-india-in-light-of-justice-ks-puttaswamy-anr-v-union-of-india-2017/
  5. https://globalfreedomofexpression.columbia.edu/cases/puttaswamy-v-india/
  6. https://prsindia.org/billtrack/digital-personal-data-protection-bill-2023
  7. https://carnegieendowment.org/research/2023/10/understanding-indias-new-data-protection-law
  8. https://fpf.org/blog/the-digital-personal-data-protection-act-of-india-explained/
  9. https://www.globalprivacyblog.com/2023/12/indias-digital-personal-data-protection-act-2023-vs-the-gdpr-a-comparison/

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Social and Political Philosophy (Indian & Western)

1 Rights

  1. Kinds of Rights
  2. Human Rights
  3. Animal Rights
  4. Rights and Duties
  5. Criticisms and Justifications

2 Equality

  1. Equality as advocated by John Rawls
  2. Amartya Sen on Equality
  3. Ronald Dworkinโ€™s Notion of Equality

3 Liberty

  1. Kinds of Liberty
  2. Two Aspects of Liberty
  3. The Concept of Liberty in Indian Framework
  4. Liberty and Freedom

4 Justice

  1. Kinds of Justice
  2. Indian Conception(s) of Justice
  3. The Concept of Justice Conceived by Western Thinkers
  4. Justice and Equality

5 Individualism

  1. Individualism and Philosophy
  2. Renaissance
  3. Reformation
  4. The Metaphysical Self
  5. Subject in Social and Political Philosophy
  6. Contemporary Theories: Mill and Berlin
  7. Phenomenology and Existentialism

6 Democracy

  1. Democracy: Conceptual Evolution of its Definition in History
  2. The Basic Institutional Principles and Ideas Constituting Democracy
  3. Democracy as a Value vs. Democracy as a Mechanism
  4. Different Types of Democracy

7 Communism

  1. Life
  2. Marx and Philosophy
  3. Dialectical Materialism
  4. Ideology
  5. Class
  6. Alienation
  7. Exploitation
  8. Communism and the Communist Manifesto
  9. Rethinking Communism

8 Secularism

  1. The Concept and its Etymology
  2. Historical Background and the Rise of Secularism
  3. Public Sphere, Religion, Secularism: The Problematic
  4. Different Types of Secularism
  5. Criticism and the Future of Secularism

9 Nationalism

  1. Nationalism: Some Underlining Conceptions
  2. Theories of Nationalism
  3. Types of Nationalism
  4. Critique of Nationalism

10 Social Discrimination

  1. Understanding Social Discrimination
  2. Diversity and Discrimination
  3. Social Justice: A Solution

11 Swaraj

  1. Macrocosm and the Microcosm in Relation through Swaraj
  2. Political Swaraj
  3. Economic Swaraj
  4. Social Swaraj

12 Torture

  1. Definition of the Concept Torture
  2. Various kinds of Torture
  3. Ethical Concerns
  4. Institutionalized Torture and its Moral Justification

13 Affirmative Action

  1. Forms of Affirmative Action
  2. Philosophical Criticism of Affirmative Action Policy
  3. Justification of Affirmative Action

14 Migration

  1. Who is a migrant?
  2. Terminologies of Migration
  3. Theories of Migration
  4. Causes of Migration
  5. Issues and Challenges

15 Privacy

  1. Situational deliberations regarding privacy
  2. Privacy: As a Historical, Philosophical and Legal Concept
  3. Consent
  4. Philosophical Critiques of Privacy
  5. Privacy Debate in India
  6. Privacy and Data