Privacy Beyond Cameras
India's privacy conversation is entering a more complicated phase. For years, the debate has largely centred on surveillance: who can record citizens, how long the state can retain that footage and whether technology is being deployed with adequate safeguards. But the sharper question emerging now is broader and more urgent. Privacy harms are no longer limited to being seen by a camera. They can begin with identification, spread through anonymous online abuse and end with threats at a person's home.
That shift matters because it exposes a gap in India's governance framework. A protester identified on camera may later be doxxed by anonymous accounts, then targeted with intimidation offline. In such a chain, the original recording is only one piece of the harm. The deeper issue is accountability across the entire lifecycle of personal data: collection, identification, dissemination and retaliation. When multiple actors are involved, responsibility becomes difficult to assign, and victims are left navigating a fragmented system that often responds too late.
The same problem is visible in electoral administration. If a decision tied to electoral rolls determines whether a person can vote, privacy is no longer a narrow civil-liberties concern. It becomes a democratic one. Voter eligibility, address verification and identity matching all depend on sensitive personal data. Errors, exclusions or opaque decisions can have direct consequences for political participation. In that context, privacy is not merely about secrecy; it is about fairness, accuracy and the right to contest decisions that affect citizenship in practice.
Accountability Gaps
The most difficult question may be who is responsible when harm is caused by a chain of actors rather than a single institution. If a protester is identified through a camera feed, then targeted by anonymous accounts and later threatened at home, the state, the platform ecosystem and the individuals involved may all play a role. Yet India's current public debate often treats these as separate problems: surveillance on one side, online abuse on another, and physical intimidation as a law-and-order issue. That separation can obscure the cumulative nature of the harm.
Legal and policy experts have long argued that privacy protections must be designed for real-world misuse, not just for idealised data handling. Identification data can be repurposed quickly, especially when images, metadata and location clues are combined with social media amplification. Once a person is named, the risk moves from abstract exposure to concrete danger. The state's duty is therefore not limited to collecting data lawfully; it must also anticipate how that data can be weaponised after collection.
This is where due process becomes essential. Citizens need to know who collected the information, who accessed it, who shared it and what remedies exist when that information is misused. Without clear lines of responsibility, privacy rights can become theoretical. The result is a system in which harm is visible to the victim but diffuse to the institutions meant to prevent it.
Data Custody Questions
A separate but related concern arises when data gathered by the police is held by a private company. That arrangement raises immediate questions about custody, oversight and legal authority. If the police collect sensitive information, what safeguards apply once a private contractor or vendor stores, processes or manages it? Who is liable for a breach, and under what law can the data be audited, deleted or restricted?
This is not a technical footnote. It goes to the heart of public trust. Citizens may accept that law enforcement needs information to investigate crime, but they are far less likely to accept opaque outsourcing of custody to private entities without robust controls. The risk is not only unauthorized access. It is also function creep, weak retention practices and the possibility that data gathered for one purpose is later used for another.
India's policy challenge is therefore twofold. First, it must strengthen protections against surveillance-driven harm, including identification and doxxing. Second, it must clarify the rules governing sensitive data once it leaves direct state control. The law must answer who is accountable, what standards apply and how citizens can seek redress when those standards are breached.
The broader lesson is that privacy cannot be treated as a single issue attached to cameras or apps. It is a chain of rights and safeguards that must hold from collection to use to storage. When that chain breaks, the consequences are not only informational. They are democratic, personal and, in some cases, physical.
