The controversy over surveillance at the Jantar Mantar student protests has moved from the streets into India’s privacy debate.
Delhi Police has acknowledged that live facial-recognition technology was used around the protest site, saying its purpose was to identify wanted criminals, history-sheeters and people with criminal antecedents—not to conduct indiscriminate surveillance of peaceful protesters. (Indian Express)
But that explanation immediately raises another question:
What database is the system comparing people’s faces against?
Facial recognition does not work like a magic camera that simply “knows” someone’s identity. The system captures a face, converts its features into a digital representation and compares it against images contained in a reference database.
And Delhi Police has confirmed that it has a large database containing photographs of criminals.
The public, however, has not been given a complete picture of the database’s source, scope, retention rules or the safeguards governing its use.
That is where the controversy begins.
The 2026 Question Has a 2020 Backstory
In 2020, during the investigation into the Delhi riots, an RTI-based controversy emerged over the Election Commission’s sharing of voter information with Delhi Police.
According to RTI activist Saket Gokhale, the Election Commission provided Delhi Police with voters’ photographs and addresses from Northeast Delhi to help identify suspects.
Gokhale pointed to an ECI communication that stated that the electoral database of an entire constituency or district should not be shared with police authorities.
But there is an important counterpoint.
The Election Commission rejected the allegation that it had violated its rules, saying at the time that it had not deviated from its existing guidelines.
So it would be inaccurate to state as an established fact that the ECI “illegally handed over the voter database.”
What is established is that voter photographs and addresses were shared with Delhi Police in the 2020 riot investigation, while the legality and interpretation of the applicable ECI rules became a subject of dispute.
And now, six years later, the question has returned in a different technological form.
Did the Election Database Become Part of the Facial-Recognition System?
There is currently no public evidence establishing that it did. This distinction is crucial.
The presence of an ECI database in a 2020 investigation does not prove that the same database—or any ECI database—is being used for facial recognition at Jantar Mantar in 2026.
In fact, reporting on the current surveillance operation says Delhi Police is using its criminal database for facial recognition. Police have not publicly said that the system is connected to the Aadhaar database or the Election Commission’s voter database.
That means the allegation currently raises a legitimate question, rather than establishing a fact.
And that question deserves an answer.
The Database Question Is Bigger Than Aadhaar
If Delhi Police says it is matching faces against people with criminal antecedents, the public should be able to understand the provenance of that database.
Does it contain:
Police photographs of people arrested or convicted?
History-sheeter records?
Prison photographs?
Passport or immigration data?
Driver’s licence photographs?
Voter photographs?
Images obtained during previous investigations?
CCTV-derived facial images?
Data supplied by other government departments?
And perhaps most importantly:
How are people added to the database, and how are they removed? A database can be powerful.
But a wrong entry in a database can also have serious consequences when an algorithm subsequently flags someone as a potential match.
The Technology Is Already Operating in Public Spaces
The Delhi Police’s Ikshana mobile surveillance van has reportedly been deployed around Jantar Mantar.
According to The Indian Express, the vehicle has eight fixed cameras providing a 360-degree field of view, and footage from cameras in the area was being processed through facial-recognition software. (Indian Express)
The police say the purpose is to identify known criminals.
But protesters have raised a different concern:
If everyone’s face is being scanned, everyone is entering the surveillance system before the software determines whether they are a “match.” That distinction matters enormously in a democracy.
A person doesn’t have to be a criminal to be concerned about being continuously identified at a political demonstration.
And the Supreme Court Is Now Looking at It
The controversy has already reached the Supreme Court.
The Court agreed to hear a petition challenging the use of facial recognition and other biometric-surveillance tools at protest sites. The petition raises questions concerning privacy, freedom of expression and the chilling effect such surveillance could have on democratic participation.
That scrutiny comes at an important moment.
The Supreme Court has previously recognised privacy as a fundamental right, while requiring restrictions on that right to satisfy constitutional standards such as legality, necessity and proportionality.
The central question therefore isn’t simply:
“Can police use technology?”
It is:
“Under what law, for what purpose, against whom, for how long—and with what safeguards?”
What About the DPDP Act?
There is also an important factual correction to the claim that India’s Digital Personal Data Protection law has remained entirely unimplemented since Parliament passed it in 2023.
The Digital Personal Data Protection Act, 2023 was enacted in August 2023, and the government notified the DPDP Rules, 2025, on November 14, 2025, describing this as the full operationalisation of the framework. (Press Information Bureau)
However, that does not resolve the facial-recognition controversy.
The DPDP framework contains exemptions for certain processing connected with law enforcement, prevention, detection and investigation of offences, while the broader constitutional questions surrounding police facial recognition remain.
As The Indian Express has noted, India’s legal framework does not currently provide a dedicated, comprehensive set of rules governing police facial recognition—including issues such as watchlists, matching thresholds, independent audits and specific retention periods.
So the debate has moved beyond simply asking whether the DPDP Act exists.
The question is whether India’s existing safeguards are sufficient for biometric surveillance by the State.*
The 80% Match Question
Another detail deserves attention.
An RTI response cited by The Indian Express showed that Delhi Police had previously considered a facial-recognition match “positive” at an 80% accuracy/similarity threshold.
That does not mean that an 80% match automatically results in arrest.
But it highlights why facial recognition should ideally be treated as an investigative lead rather than conclusive proof of identity.
A machine-generated match is not the same thing as a human being being proven guilty.
Delhi Police’s Position
The police have strongly defended the technology.
Their stated position is that facial recognition was being used for law-and-order purposes and to identify known criminals, rather than to target peaceful protesters.
The police have also argued before the Supreme Court that the protest involved people with criminal histories and that surveillance was part of maintaining public safety.
That explanation cannot simply be dismissed.
But it also doesn’t answer the database question.
What Delhi Police Should Disclose
Without compromising genuine criminal investigations, the police could provide basic transparency about the system:
1. What databases are being used?
2. Who supplied the photographs?
3. Is the Election Commission database connected to the system?
4. Is Aadhaar data connected to it?
5. Are transport or tax databases connected to it?
6. What is the legal authority for each data source?
7. How long is protest footage retained?
8. Are people who produce no criminal match still stored or identified?
9. What happens after a false match?
10. Is there an independent audit of the technology?
These aren’t unreasonable questions.
They’re the questions any modern democracy should be asking when the State gains the ability to identify people in a crowd automatically.
The Real Fear Isn’t the Camera
A CCTV camera records what happened.
Facial recognition can potentially tell the State who was there.
That is a fundamentally different capability.
Someone attending a protest may be a student, journalist, lawyer, researcher, passer-by—or simply a citizen exercising the right to peacefully assemble.
If their face is automatically identified and linked to an extensive government database, the technology can create a detailed record of political participation.
That possibility is precisely why the Supreme Court’s scrutiny matters.
Delhi Police says: “We’re only looking for criminals.”
Fine.
Then there should be no reason for the public to be kept guessing about where the photographs come from, which databases are connected, what happens to the scans and how long the information is retained.
The 2020 ECI episode does not prove that voter photographs are being used at Jantar Mantar today.
But it does make the question worth asking.
And the answer should not require an RTI years later.
In a democracy, the State should not ask citizens to trust a machine simply because the machine belongs to the State.
If facial recognition is being used in public protests, the public deserves to know the rules behind the camera.
Because the most important question isn’t “Whose face did the machine recognise?”
It’s “Who gave the machine the right to recognise us in the first place?”











