Consent, Privacy, and Digital Exclusion: A Legal and Statistical Review of India’s Data Governance Regime

Written by Ishan Yadav & Pranshur Sharma students at IIM Rohtak Abstract In a country as big and diverse as India, where millions don’t know where, how, and why they are digitally consenting, the guarantee of privacy is hollow. As digital governance expands unchecked in welfare, identification, and public space the question remains: Are India’s data laws actually protecting the individual, or enacting for data governance in the interest of the state and corporations? This essay engages with the shifting terrain of India’s data governance regime, particularly regarding the privacy, consent, and digital exclusion legal regimes. In light of jurisprudence post-Justice K.S. Puttaswamy v. Union of India and the enactment of the Digital Personal Data Protection Act, 2023, the study reflects on whether laws translated the constitutional right of privacy from theory to practice. With legal argument and empirical insight, the paper brings to the fore how infrastructural gaps, shadowy data practices, and digital illiteracies most unequally affect marginalized communities. The paper argues the need for a model of consent that is not merely legally valid but also meaningfully informed and accessible. The paper concludes on the note of what can make India’s data infrastructure a more ethical, participatory, and human-friendly one. 1. Introduction In the world’s most democratic polity, where technological empowerment has been enshrined as a national article of faith for development, that question of proper consent is all too frequently failing to be asked, let alone answered. The data management of India, a developing country in transition, sits at the juncture of converging tech and an avowedly inegalitarian social order. Whereas legislative creativity, such as the Digital Personal Data Protection Act, 2023 (DPDP Act), is an ambitious attempt to regulate personal data, facts on the ground of digital illiteracy, infrastructural underdevelopment, and socio-economic imbalances cast urgent doubts on the effectiveness and inclusiveness of this measure. The legal phenomenon of consent, so prevalent in global data privacy laws, is not simply the act of agreement, but informed, voluntary, and withdrawable. In a country where millions lack elementary digital literacy and where data tends to be harvested by coercion, ignorance, or infrastructural duress, the idea of “free and informed consent” may seem perilously symbolic. In addition, unequal access to privacy rights and data protection mechanisms creates daunting challenges to the constitutional promise of equality and dignity. This essay critically analyzes India’s existing data protection regime in a twinned optic of legal criticism and statistical evidence. The essay seeks to inquire whether Indian laws provide sufficient protection for individual privacy and consent, particularly for the digitally excluded. The paper, based on an interdisciplinary approach, weighs both the text of law and its de facto impact, providing a somber analysis of the situation of digital justice in present-day India. 2. Legal Framework for Data Protection in India In the wake of increasing anxieties about online privacy, India tabled the Personal Data Protection Bill, 2019 (PDPB) to frame an effective data regime. Passed subsequent to the epoch-making Puttaswamy decision holding the right to privacy a constitutional right, the Bill intends to control the processing of data with the will and liability of the individual at its focal point. 2.1 Salient Features of the PDPB The PDPB classifies individuals handling personal data as Data Fiduciaries and mandates that they process data on the basis of free, specific, and well-informed consent. Under Section 11, consent must be obtained by clear affirmative action, a shift towards user-level control over data. The Bill allows Data Principals the right to access, correct, and remove their data and withdraw consent at any time (Section 19). Section 29 requires automatic notification of breaches to the Data Protection Authority (DPA) and to the affected persons, promoting transparency. One key requirement under Section 33 requires specific forms of data to be localized on national security grounds. Though increasing sovereign power, operational burdens, as well as surveillance possibilities, worry critics. 2.2 Operational Concerns Though the PDPB reiterates consent, its efficacy as a protection is doubtful in a nation whose digital literacy index is low. People agree willingly without knowing what the terms themselves are, thus, “consent” being very procedural than supported. Further, the Bill exempt sweeping expanses of government departments on national security grounds, raising spectres of state excess with minimal oversight. The Data Protection Authority, even if it is independent in theory, still remains subject to central government control, undermining its autonomy. 2.3 Comparison with Global Norms Though patterned after the EU’s General Data Protection Regulation (GDPR), India’s proposed law lacks corresponding enforcement authority. Though GDPR holds violators with severe fines, otherwise India’s model is constructed on more regulation by discretion rather than penalty. And the PDPB provides for data processing for “reasonable purposes” sans consent ,a clause subject to general interpretation, threatening user control. 2.4 Conclusion India’s PDPB is a landmark in digital rights law, but it will come to fruition only if there is the integrity of implementation. With lack of institutional autonomy, successful awareness campaigns, and improved accountability mechanisms, the potential of informed consent rings hollowly as a legal fiction—particularly for the digitally excluded. 3. Statistical Review: India’s Digital Exclusion and Illiteracy to ConsentBarring progress on the law side, data management in India remains characterized by intense digital divides as well as consent illiteracy. Legal mechanisms, altruistic as they are, are a success only to the extent that citizens are well-informed and can exercise their rights. Technology access in India, in especially so, is uneven, while knowledge of privacy in data remains lamentably poor. 3.1 Digital Divide in NumbersIndia had around 759 million internet users in 2022, of whom more than 500 million remained unconnected, according to the Internet and Mobile Association of India (IAMAI).Internet penetration still leans heavily towards urban areas: urban India enjoys a 69% rate of internet penetration, while rural India enjoys 37%.Even among access-holding users, illiteracy in digital matters is minimal. Only 38% of people aged 15 and above were able to use a computer in a 2021 National Sample Survey, and less than

MODERNIZATION OR MONITORING? THE SURVEILLANCE SHADOW OF THE INCOME TAX BILL, 2025

Written by Ms. Rishita Dasgupta & Mr. Samik Mukherjee students at School of Law and Justice, Adamas University, Kolkata In recent times our lives have become digitalized like banking, communication, medical records, social relationships, even thoughts through digital notes, the Income Tax Bill, 2025 gives unprecedented power to tax authorities to invade into an individual’s private sphere. In the disguise of modernization and anti-evasion measures, this bill’s most debatable provisions risk normalizing a state of digital surveillance, where every little personal data is subject to governmental scrutiny. If left unrestricted, these measures may not just curtail our privacy, it could quietly push citizens into a digital prison, where frequent surveillance replaces the constitutional assurance of freedom. The Income Tax Bill, 2025, which will replace the current Income Tax Act, 1961, from April 1, 2026, is being praised as a step towards simplification of procedures and increase of productivity. However, gently hidden within its legal prose is a shocking expansion of state power, that is the authorization for tax officers to access a taxpayer’s “virtual digital space”. This includes email accounts, cloud storage, mobile devices, social media platforms, investment apps, and several other online apps. Further, officers are not only allowed to request access from individuals, they may even override passwords and encryptions, without any permission from the judiciary. In simple terms, if you’re under investigation, the state can forcefully enter your digital life, extract your private data, and use it against you, all without you even knowing in reality. This isn’t just a tax tool, it’s a surveillance system. Tax compliance is essential, but the instruments employed to enforce compliance have to withstand the test of constitutionality, especially the right to privacy identified by the Supreme Court in Justice K.S. Puttaswamy v. Union of India (2017) . This historic judgment held privacy to be a fundamental right, safeguarded under Article 21 of the Constitution. It laid down the threefold test: legality, necessity, and proportionality. The necessity test asks is the intrusion absolutely essential for achieving the state’s objective? While preventing tax evasion is a legitimate aim, the government has other less intrusive tools already at its disposal like PAN-Aadhaar linkage, Income Disclosure Schemes, TDS and GST data tracking, AI-based risk flagging systems. Thus, granting unrestricted access to personal cloud storage or encrypted chats isn’t strictly essential. This broad power looks more like convenience for the state than a necessary measure in a democratic society. Proportionality requires that the measure has a rational nexus to the objective, is the least restrictive option, and does not disproportionately harm rights compared to the benefit gained. In this case granting tax officers unfiltered access to all personal data, with no judicial safeguards, is highly disproportionate. The harms like loss of dignity, fear, censorship, and potential misuse, far outweigh the revenue benefits, especially for ordinary taxpayers. At the heart of the controversy is the phrase “virtual digital space”, a term not clearly defined anywhere in the bill. In legal drafting, clarity and precision are key. Vague terms allow discretionary interpretation by authorities, and in the realm of fundamental rights, this vagueness becomes dangerously elastic. What falls under this space? Is it limited to financial accounts, or does it include health data, romantic messages, or cloud-synced writing apps? The government has left it ambiguous, perhaps intentionally. Such elasticity gives the state a key to every digital lock under the justification of preventing tax fraud. But this trade-off is grossly disproportionate and ripe for legal challenge. This is no longer about tax evasion, it’s about control. One of the most chilling aspects of the bill is its suggestion to bypass encrypted security measures. With cybersecurity threats running amok in the modern world, encryption, as sensitive information, is what keeps citizens safe from hackers, identity thieves, and abuse of surveillance. By weakening encryption, the government is not only violating our personal space but disassembling the entire digital security framework. It violates EU GDPR, DPDP 2023, and IT Rules 2011 by not taking informed consent before accessing their data. It also constitutes a red flag under our Constitution. Article 20(3) of the Constitution also guarantees protection from self-incrimination. When a citizen is compelled to open their digital devices or give passwords, isn’t that a flagrant violation? This coercive tool essentially forces the taxpayer to help build a case against himself. In democracies, aggressive state action is counterbalanced by judicial supervision. Wiretapping, search and seizure, or invasion of private correspondence usually require advance court sanction. But under the new law, tax officials are able to gain cyber access with no such scrutiny. The mechanism is all executive and eliminates the judiciary from the chain. This absence of checks is not merely a defect, it is a risk in the system. It builds an ecosystem where there is much potential for abuse, harassment, and politicization. An official with bad intentions might threaten citizens, expose confidential information, or go after political rivals. History teaches us that unchecked power is often abused, and the state must be designed to prevent, not enable, such risks. When people know they are under surveillance, they talk differently, think differently, and live differently. This is the chilling effect, where the threat of surveillance chills freedom of expression, association, and dissent. Now consider knowing that a government official may read your private messages, memes, jokes, diary entries, or even photos. This fear can result in self-censorship both online and in thought. The bill, in granting complete access to online platforms, instills fear and compels citizens into a state of mental imprisonment. We might have not witnessed prison bars, but they exist in disguise of digital submission and behavioural compliance. Privacy activists have drawn similarities between this bill and China’s surveillance ecosystem, where the state monitors digital behaviour of it’s citizens to assign “citizen scores” impacting their mobility, employment, and social standing. While India is far from such apocalypse, the basic frameworks of a surveillance state are introduced, justified by noble-sounding objectives like security of the citizens or revenue generation. Adding to India’s growing interest

Law, Consent, and Control: Rethinking Biometric Data Governance

Written by Aaransha Shankar & Khushi Jain students at Dr. Ram Manohar Lohiya National Law University, Lucknow Abstract Many automated verification systems commonly use biometrics since it offers several advantages over traditional verification methods. The leakage of such sensitive information will certainly lead to the violation of an individual’s privacy. It further causes serious and continued problems due to the irreplaceable nature of biometric data. The article attempts to provide legal and policy recommendations along with a way forward to address existing inadequacies and policy gaps.  Introduction Biometric refers to detailed information about someone’s body, like patterns of colour in their eyes, that can be used to prove who that person is and can be added to a database to authenticate an individual’s identity. In today’s digital and security-driven world, biometric technology is key to identity verification and access control, though it raises serious privacy concerns. While the DPDP Act provides a foundational framework for data protection, proposals related to bringing technological, procedural and structural innovations tailored for biometric data are needed. The paper thus addresses regulatory gaps and establishes a new gold standard for biometric privacy.  The article aims to examine the legal gaps and challenges of the use of biometric technology, which contribute to growing concerns over privacy and data protection. It further offers legal recommendations to address these issues. The article concludes with a suggested way forward for the effective and responsible implementation of biometric systems. Evolution And Legal Impediment The evolution of biometrics dates to the archaic practices of Babylon, wherein fingerprints were used to identify the modern digital systems of the present. During the 19th century, anthropometry was introduced by Alphonse Bertillon, followed by the development of fingerprint classification by Sir Francis Galton, laying down the initial stones of the foundation of a biometric system. With the advent of the 20th century, biometrics and automated systems became popular in law enforcement, further advancing during the 1990s. The biometric system gained mainstream significance with the advancement of smartphones, and the systems of India’s Aadhaar further widened its horizon. The expeditious advancement and inclusion of biometric data collection systems in government, law enforcement, and private sector applications have raised significant concerns about privacy, security and ethics. The scope of privacy encompasses several areas. For instance, it assumes sociological, economic, and political perspectives and has been included in numerous documents that define human rights.  The current framework fails to provide ample safeguards against centralization risks, mass surveillance, unauthorized access and indefinite retention of biometric records. Moreover, present legislation, such as the Aadhaar Act, DPDP Act and IT Rules 2011, does not completely address the unique privacy risks connected to the processing of biometric data, like data breaches, and misuse by public or private organizations. Preventing unprecedented privacy invasions, loss of user autonomy and widespread security risks requires the growth of biometric data gathering in a structured regulatory framework. Legal and Policy Recommendations  The concerns pertaining to the biometric data collection procedure can be addressed through the following measures: Path Ahead A well-structured multi-phase implementation approach is necessary to execute and implement the model effectively. Conclusion The implementation of a Privacy-Preserving Biometric Data Governance Framework holds transformative potential for securing biometric data while upholding individual privacy and ethical standards. The integration of HE, ZKP authentication, FD and on-device storage potentially focuses on the eradication of impediments associated with centralized biometric databases, reducing the threat of mass data breaches. The exorbitant costs incurred by the development of privacy dashboards, self-destructing biometrics, and automated data portability tools offer long-term benefits, ensuring user autonomy, minimizing misuse, and enhancing system resilience. A strategic investment in security infrastructure, legal frameworks and compliance mechanisms is quintessential. Moreover, establishing an independent regulatory body and performing periodic PIA yields long-term advantages by ensuring compliance and resolving grievances.  Penultimately, the article calls for a privacy-oriented forward-looking approach to biometric governance, which not only safeguards fundamental rights and bolsters public trust but will position India as a global leader in responsible and ethical biometric innovation. By setting a high standard for secure and consent-based biometric authentication, India can lead the way in shaping a digitally advanced and rights-respecting future. 

DATA PRIVACY AND CYBERSECURITY IN ONLINE EDUCATION PLATFORMS:

“A Focus on Children’s Data and the Need for Targeted Regulation” Written by Sukriti Chaudhary & Rudra Swami students at National University of Study and Research in Law, Ranchi. CHAPTER I : INTRODUCTION The COVID-19 pandemic has dramatically reshaped education around the world, pushing schools and colleges to fully embrace digital learning. In India, platforms like Byju’s, Vedantu, and WhiteHat Jr saw a huge increase in users and investments, signalling a major change in the EdTech scene. This digital shift has connected millions of kids under 18 with online learning tools. While features like video lectures and real-time interactions have enhanced the learning experience, they’ve also raised significant privacy issues. Many EdTech companies gather sensitive information like biometrics, geolocation, and behavioural data often without getting proper consent from parents. The absence of regulatory protections has resulted in data misuse, surveillance, and even profiling of children. Although the Digital Personal Data Protection Act, 2023 is a positive step, it doesn’t specifically address educational data or the unique risks faced by minors. Therefore, there’s an urgent need for child-focused data protection policies in India’s EdTech industry to ensure safe learning environments and protect data integrity. CHAPTER II : RISKS INVOLVED: CHILDREN’S DATA AND CYBERSECURITY CHALLENGES As online education platforms continue to grow, they increasingly depend on gathering a wealth of personal data from children to create tailored learning experiences. This data encompasses personally identifiable information (PII) like names, ages, and contact details, along with more sensitive information such as biometric data, location history, device identifiers, academic performance, and behavioural learning analytics. Often, this data collection happens passively through cookies, third-party software development kits (SDKs), and embedded trackers tools that are often invisible to young users and their parents.  Children are particularly vulnerable in the digital world. For starters, they don’t have the legal or cognitive ability to give informed consent about how their data is collected and used. Many educational technology (EdTech) applications sidestep parental consent requirements or rely on complicated privacy policies that parents seldom read or fully grasp. Additionally, children are more easily influenced by personalized learning feeds, notifications, and targeted ads that are based on their behaviour. Finally, the long-term profiling of children starting from their early years can have significant repercussions, shaping their educational paths and even their job prospects down the line. Real-life data breaches and controversies highlight just how serious these risks are. For instance, in India, WhiteHat Jr, a subsidiary of Byju’s, faced backlash for silencing criticism about its privacy practices and for exposing sensitive information about minors. On a global scale, platforms like ClassDojo have come under fire for collecting too much student data and sharing it with advertising partners. These cases reveal the cybersecurity weaknesses of many EdTech platforms, which often lack proper encryption, use outdated cloud storage methods, or share data with third-party vendors without being transparent about it.  In addition, typical cyber threats like phishing, malware, and data breaches impact younger users, many of whom lack fundamental cyber hygiene knowledge, even more. In the absence of robust data protection and cybersecurity policies, the digital learning ecosystem stands to be abused instead of being harnessed to empower learners. CHAPTER III : LEGAL LANDSCAPE IN INDIA A. DPDP Act, 2023 DPDP Act, 2023 is India’s first legislation directly governing data protection and dealing with the regulation of the collection and storage of digital personal data. The act introduces a consent-based framework, which mandates data fiduciaries to obtain explicit consent of the individuals before entering into the processing of personal data. For children, who are persons under 18 years of age, the Act requires verifiable parental consent for any action related to data processing. In addition, it prohibits tracking or targeted advertising to children and requires data fiduciaries to adopt “reasonable” protective measures. Nonetheless, even with its progressive approach, the DPDP Act is beset by severe shortcomings in the context of educational technology. Firstly, it lacks provisions dedicated to the education sector for the handling of educational data, even though children form a significant user base on EdTech platforms. Secondly, the commonly used age criterion of 18 years is not able to distinguish between a 6 years and a 17 years and is hence ignoring the development potential of adolescents, a differentiation well understood in global legal systems. Thirdly, the Act establishes imprecise obligations on platforms consumed by children, without outlining compliance processes or accountability structures that are dedicated to educational service providers. B. Information Technology Act, 2000 & Intermediary Rules (2021) The Information Technology Act of 2000 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules of 2021 enacts a broad framework for the regulation of online content and digital intermediaries in India. The legislation imposes responsibilities on intermediaries, such as social media companies, to secure data, handle content, and resolve issues. EdTech companies may be considered intermediaries or digital platforms, but the regulatory environment is mostly concerned with social media, with little applicability in the case of educational data governance. There is no regulatory guidance on whether schools, which use third-party EdTech tools, are facilitators or data fiduciaries. This absence of guidance undermines enforcement of privacy protection controls at the institutional level. C. Discrepancies Identified While the EdTech space has grown rapidly and the use of online education has increased, India does not have a specific law that governs the collection and use of data in educational institutions. Schools and private EdTech players are equated, although they have different data practices and intentions. No specialized regulatory body or agency is in place to keep a check on data practices of child-centric education platforms. Unregulated, children are at the risk of being exploited, spied on, and commercially profiled. CHAPTER IV : ROLE OF STAKEHOLDERS Online learning can open up incredible opportunities for children but it must also be a safe space. Protecting their privacy and security isn’t the job of one player alone. It takes a shared commitment from governments, EdTech companies, and schools to ensure that children can

Reimaging Data protection for the Marginalized: Why India’s Digital Policies Must Prioritize the Vulnerable First

Written by Setu Kumar Rai & Tanisha Nath students at National Law University, Meghalaya. Introduction India’s digital revolution has transformed commerce, education, governance, and social interaction at an unforeseen speed. From the introduction of Aadhar in 2009 to the large-scale adoption of 4G networks in the late 2010s, more than 820 million Indians now regularly use the internet from a mere 250 million in 2014 , yet this growth remains geographically, gender-wise, caste-wise, and income-wise unevenly distributed. While the urban hubs enjoy average broadband speeds of 50 Mbps, numerous rural districts still fight for 2 Mbps connections, with some panchayats reporting a complete lack of reliable service. This dichotomy fuels a digital divide that both constrains opportunity and makes marginalized populations increasingly vulnerable to data exploitation in the absence of proper safeguards, individual information like biometric data, financial transactions, health records can be gathered, abused, or weaponized by state and corporate actors.  Across the world, regulations like the European Union’s General Data Protection Regulation (GDPR) have increased the standards of individuals’ rights, requiring transparency, consent, and minimization of data. These, however, assume an architecture of digital literacy and agency as a given ,privileges that are simply not available to millions of Indians, particularly women, rural dwellers, and economically poor constituencies. As India is finishing its Digital Personal Data Protection (DPDP) Bill, 2023, it is at a crossroads: mimic global standards or lead a “vulnerability-first” approach that centers the interests of the least empowered in its data governance. This blog pleads for the latter drawing out the digital divide in India, discussing the increased risks faced by marginalized groups, critiquing current legislations, and presenting tangible, inclusive policy reform suggestions.  The Digital Divide in India India’s base of internet users grew from 400 million in 2017 to more than 820 million as of the end of 2023, yet penetration is persistently skewed. The Telecom Regulatory Authority of India’s 2021 report estimated urban internet penetration at 72%, versus only 38% in the countryside. In Jharkhand and Bihar, rural connectivity had fallen as low as 24%, whereas Kerala and Punjab had more than 60% rural coverage. Such differences are rooted in the infrastructure deficit—only 42% of Indian villages were covered by 4G by 2022—and the affordability barrier, with rural users paying an average of ₹130 per month for data, compared to ₹250 in cities. Indian women are disproportionately impacted by the digital divide. Based on GSMA’s 2020 Mobile Gender Gap report, just 37% of Indian women use mobile internet—approximately 20 percentage points behind men. Socio-cultural values restrict women’s mobility and education, hindering both access to technology as well as digital literacy training. Smartphone ownership is still taboo for women in certain patriarchal rural communities, while safety issues and online harassment additionally deter women from joining online. Exclusion based on caste adds to these disparities. Scheduled Castes (SCs) and Scheduled Tribes (STs) have average internet adoption of 30% and 28%, respectively far less than the overall national average. Poorer households, which incur less than ₹150 a month on data, must make a choice between basic internet connectivity and irreducible necessities. Additionally, digital literacy programs frequently go to waste in marginalized hamlets since NGO and government outreach efforts target more accessible and denser areas. Vulnerability of Marginalized Groups in the Digital Ecosystem In K.S. Puttaswamy v. Union of India, the Supreme Court of India affirmed privacy as a fundamental right under Articles 14, 19, and 21 of the Constitution. Yet the subsequent rollout of Aadhaar—a biometric database covering over 1.3 billion residents—underscored the perils of large-scale data collection without adequate safeguards. Although Aadhaar aimed to streamline welfare delivery, authentication failures disproportionately impacted rural residents. In Rajasthan, 15% of users experienced failed authentications due to worn fingerprints; in Tamil Nadu, women laborers with manual-skill-induced fingerprint erosion faced a 20% higher failure rate than men. When we speak, these failures have grave material effects, denial of rations, pension payments, and LPG subsidies, services essential for subsistence. Privacy International’s December 2021 report highlights that over 2 million individuals faced service exclusion in 2020 alone, primarily from marginalized castes and remote hamlets. Unable to navigate complex grievance-redress mechanisms or contest data inaccuracies, these citizens endure bureaucratic limbo. Beyond state surveillance, private platforms routinely harvest user data under opaque consent clauses. Economically disadvantaged users—unaware of the implications—click “agree” on lengthy, jargon-laden terms to access essential mobile banking or health apps. The result: granular behavioral profiles used for targeted marketing, micro-credit algorithms that penalize the poor, and risk assessments that reinforce existing socioeconomic biases. International human-rights organizations underscore that vulnerable groups worldwide suffer similar fates. Access Now’s 2023 report documents how indigenous communities in Latin America faced algorithmic profiling for resource allocation, while African informal workers were excluded from digital lending services due to biased credit scoring models. These global parallels reinforce the urgency for India to design data protection that explicitly shields its most vulnerable cohorts. Evaluation of India’s Digital Laws  The Digital Personal Data Protection Bill, 2023 The DPDP Bill, tabled in Parliament in August 2023, is India’s effort to legislate data protection principles. The main provisions are: These are GDPR principles closely adhered to, though there is still much to be done about marginalized users: Comparative International Frameworks These examples demonstrate that embedding equity provisions—accessible communication, mandatory impact assessments, dedicated oversight—yields more inclusive outcomes. Policy Proposals for Inclusive Digital Reform To make data protection meaningfully benefit India’s most marginalized, the following practical reforms are essential: Implementation: Collaborate with panchayats, self-help groups, and grassroots NGOs to provide customized workshops on data rights, consent mechanisms, and foundational cybersecurity. Metrics: Synchronize with NITI Aayog’s 2021 digital transformation strategy reaching 10 million rural beneficiaries per year. Design: Implement Interactive Voice Response (IVR) technology in local languages, visual consent cards, and in-app audio descriptions. Spain’s Data Protection Authority pilot of elderly audio-visual consent resulted in a 40% increase in informed assent. Requirement: Modify the DPDP Bill to mandate VIAs for all large-scale data processing—especially national ID schemes, financial inclusion initiatives, and health-data projects.

THE EVOLUTION OF PAPARAZZI: FROM LA DOLCE VITA TO SOCIAL MEDIA FRENZY

Written by Dipanshu Raj & Harsh Gupta students at Maharashtra National Law University, Chhatrapati Sambhajinagar. The assertive photographers and journalists, called “Paparazzi”, play a paramount role in clicking interesting photos of celebrities. This fad started with the Italian film La Dolce Vita and has now spread to all corners of the world. This period started with the beginning of the ravenous public desire for a peek into famous individuals’ lives. In India, this growth of paparazzi following the moves of Bollywood stars, cricketers, and politicians is part of a larger change in which privacy boundaries are increasingly being probed. With the advent of social media, this effect has only been heightened, with the dispersal of paparazzi material far and wide. Paparazzi are freelance photographers who click pictures of famous people like celebrities, cricketers, and politicians. Paparazzi are well known for their persistent following of celebrities in their private space, such as the gym, vehicle, restaurant, and home, to capture exclusive or private moments. They usually click pictures of their daily routine. Earlier, to make a living, paparazzi used to sell their photographs to media agencies and earn money from them. But clicking photos of the celebrity’s day-to-day affairs acts as a double-edged sword, it acts as money-making for the paparazzi on one side, while on the other hand, it also violates the celebrities’ privacy. INTEREST OF THE PAPARAZZI AND CELEBRITIES  This feeds the paparazzi industry, which records unguarded moments of celebrities to heighten consumption for the public, which is greatly fascinated with the celebrity lifestyle. With the social media that have gained momentum of late, their addiction has risen further into demanding uncensored access to the lives of public personas. In contrast to the well-manicured postings online, the seeming authenticity of the paparazzi photos raises demand for exclusive content. The media outlets exploit this demand and sell subscription services to fans to get a close-up look at their favourite celebrities. This has influenced the function of the celebrities themselves within the paparazzi economy. Gone are the days when celebrities used to be simple passive subjects to uninvited photography; instead, today most of them carefully cultivate the industry to extend their visibility and bolster brand strength. They nourish parasocial interactions, that is, one-sided emotional relationships that feel close, with their fans by inclusions of paparazzi photos in their public selves. In a time when attention has to be brief on digital platforms, these exchanges are relevant. Celebrities also exploit paparazzi photos by promoting lifestyle, fashion, and/or accessory products to reinforce their status as marketable “brands.” For this reason, the paparazzi have two jobs: one of knowingly violating privacy and one of providing celebrities with a strategic means of self-marketing. It is in this sense that the mutually reinforcing relationship underlines the way that celebrity culture, in its mergers of fashion, fame, and business, has commodified itself. For the money-shot-grabbing paparazzi and the celebrities who either want or believe in some sort of enduring cultural the more iconic a star becomes, the more resilient their unpoliced moments in time. IMPORTANT REGULATION AND GUIDELINES FOR THE PAPARAZZI  While coming to the legislation and regulation regarding the paparazzi in India, there is no such regulation for the same, but recent legal developments have sought to address the privacy issues resulting from the actions of paparazzi. Section 78(2) of the Bhartiya Nyaya Sanhita, 2023, makes it punishable to invade privacy by surveillance or recording. This Act gives more strength to privacy rights and remedies. The Press Council of India has issued guidelines that establish ethical media practices and privacy. However, these guidelines are not legally binding in due time, but they are generally anticipated to be complied with by the media and the paparazzi. It is often that the paparazzi would use Article 19(1)(a) as well as Article (1)(g), which covers freedom of speech, trade, and occupation respectively, to defend the invasive actions, which is a legal weakness in terms of privacy. The concept, although, has no direct protection from the Constitution, may find a place in the apex jurisdiction vide Article 21, which speaks about the ‘right to life and thereby connotes liberty. In “Kharak Singh v. State of Uttar Pradesh, the Supreme Court defined privacy to be associated with personal liberty. Likewise, in the R. Malkani v. State of Maharashtra. In Rajagopal v. State of Tamil Nadu, the Supreme Court upheld people’s rights to privacy over personal information and held that the media cannot publish or broadcast such information without consent. Thus, the right to privacy shields and protects the celebrities from the constant stalking and harassment by paparazzi and the use of photos and videos without their consent, and provides a proper balance between freedom of expression with human dignity and privacy. However, the changes brought by the law and judgments are a step toward remedying the challenges to privacy in India. FIRST-HAND EXPERIENCES The recent cases in India have pointed out the increasing tension between paparazzi practices and celebrities’ private rights. In R. Rajagopal Alias R.R Gopal and Another v. State of Tamil Nadu and Others, the Supreme Court ordered that snapping pictures without consent inside a celebrity’s house is an invasion of privacy and prohibited the magazine from republishing or hosting the photos online. Similarly, in the Shilpa Shetty Kundra case, the Bombay High Court granted an injunction against a photographer who shot unauthorized pictures of Shilpa Shetty Kundra and her family while on tour. The court, though conscious of the right to free expression of the defendant, weighed that such freedom had to be balanced against private rights and held the activities of the photographer illegal. The privacy of celebrities and their families has also been an issue. Recently, Virat Kohli and Anushka Sharma expressed their discontent over illegal pictures of their daughter, while Saif Ali Khan and Kareena Kapoor requested the media not to photograph their son, Taimur Ali Khan, excessively, which set off debates regarding the privacy of children. In other cases, there have been companies

THE RIGHT WAY TO BE FORGOTTEN: WHAT INDIA CAN BORROW FROM THE E.U.

Written by Khyati Sinha & Suyash Srivastava students at Maharashtra National Law University, Chhatrapati, Sambhajinagar. INTRODUCTION We leave behind a data trail while using the internet, either actively or passively, across various websites and platforms. These digital footprints build up over time and incorporate everything from online activities, interactions, and personal information collected by the platforms, often without their users’ explicit consent. One such instance occurred in 2023, when Meta was fined $1.3 billion for violating E.U. data privacy rules. It results in the violation of individual privacy, which is protected under Article 21 of the Constitution of India. Due to the data being collected on a large scale, it becomes imperative to safeguard individual privacy by prohibiting unauthorized storage and processing of personal data. To address the privacy concerns, the concept of the Right to be Forgotten has emerged, which enables individuals to seek erasure of their personal information in certain situations. The first legal recognition of this right was in the EU in Google Spain SL v. Agencia Española de Protección de Datos (AEPD) and Mario Costeja González (2014), granting people the right to ask organizations to erase their data when it is no longer required. This caused a worldwide movement for the importance of privacy and RTBF. In the absence of dedicated legislation that explicitly recognizes RTBF, the framework on data protection in India has been profoundly shaped by the seminal case of Justice K.S. Puttaswamy v. Union of India, which established the right to privacy as a fundamental right, leading to the unfolding of significant developments thereafter. This blog aims to provide a comparative analysis of the data protection framework in India and the EU concerning RTBF. It also offers suggestions on what India can learn from the EU to implement its data protection framework effectively. RIGHT TO BE FORGOTTEN IN THE EUROPEAN UNION By the demands and requirements of society, laws relating to RTBF have rapidly evolved over the past few years. However, a significant milestone in this evolution was observed in the Google Spain case, when the European Court of Justice held that “Every individual has the right, under certain conditions, to ask search engines to remove links with personal information about them.” The judgment paved the way for this right to be granted recognition in 2016 under Article 17(1) of the GDPR, which allows Data Subjects to seek prompt erasure of their data from the data controller. This right is applicable under specific conditions, including when: 1. The data is no longer necessary for the purpose for which it was collected; 2. The data subject withdraws consent previously given for processing; 3. The data is being processed unlawfully, or 4. There is a legal obligation to erase the data.  However, the right is subject to certain exceptions mentioned in Article 17(3) of GDPR, notably, where processing is necessary for the exercise of the right of freedom of expression and information, for public interest, for research or statistical purposes, or to comply with legal obligations. Through this ruling, the court aimed to balance an individual’s right to privacy with the public’s right to access information. The jurisprudence developed in the Google Spain case laid the groundwork for Google v. CNIL, wherein it was held that under EU law, RTBF is only applicable in its 28 member states, and there is no obligation on Google and other search engines to apply it globally. Article 51 of GDPR establishes Data Protection Authorities, one of the main elements of the European mechanism of data protection. They are independent public bodies responsible for enforcing the application of the regulation within each EU member state. This includes their ability to ensure compliance, provide guidance to data controllers and processors, handle complaints, and issue fines. RIGHT TO BE FORGOTTEN IN INDIA The legal landscape around the concept first surfaced in 2017 after the right to privacy was recognized as a fundamental right under Article 21 of the Constitution of India in the Puttaswamy case. While several cases have been filed seeking enforcement of RTBF, the courts have been hesitant and inconsistent in their application. In Dharamraj Bhanushankar Dave v. State of Gujarat (2015),  a writ petition was filed under Article 226 praying for permanent restraint of the public exhibition of a non-reportable judgment that was displayed on several websites where the petitioner was charged with culpable homicide amounting to murder and other various criminal offenses. He contended that the display of the same had affected his personal as well as professional life, even after he was acquitted by the Sessions Court and, subsequently, the High Court. However, the court dismissed the petition, stating the publication of the judgment did not violate Article 21. However, in Sri Vasunathan v. Registrar General, the Karnataka High Court gave a conflicting ruling, wherein it upheld the petitioner’s claim to remove the name of his daughter from the cause title, stating it was ‘in line with the trend in the western countries’ to protect the modesty and reputation of women involved in sensitive cases. Further, in Zulfiqar Ahman Khan v. Ms. Quintillion Business Media Pvt Ltd., the Delhi High Court directed the removal of defamatory articles concerning #MeToo allegations against the petitioner and recognized the ‘right to be forgotten’ as an integral part of the right to privacy. In 2021, the Delhi High Court in Jorawar Singh Mundy v. Union of India, also acknowledged the need to balance an individual’s right to privacy with the public’s right to information and granted interim relief to the petitioner by directing websites to remove access to the judgments as it infringed the petitioner’s privacy and dignity.  LEGISLATIVE FRAMEWORK IN INDIA In the 2019 draft of the Personal Data Protection Bill, the inclusion of RTBF was recommended by the B.N. Srikrishna Committee in cases where data is misleading, outdated, or humiliating. In a welcoming move, the Digital Personal Data Protection Act, 2023,  adopted a revised framework tailored to modern privacy challenges and global best practices.  A key strength of the DPDP