Skip to Content

Facial Recognition Technology Under DPDPA: Legal, Ethical & Practical Guidance

Facial Recognition Technology Under DPDPA: Legal, Ethical & Practical Guidance

Your face was scanned. You didn't sign anything. You didn't give permission.

Maybe it happened at a shopping mall, an apartment building entrance, or a workplace. Maybe you found out months later. Maybe you still don't know it happened at all.

Here is the thing most people don't realise: scanning your face without your consent may be a direct violation of India's Digital Personal Data Protection Act (DPDPA), 2023  and you have legal options.

This guide explains exactly what the law says, what your rights are, and what steps to take if your facial data has been collected, stored, or misused without your knowledge.


What Is Facial Recognition Technology  and Why Does It Matter Legally?

Facial recognition technology (FRT) works by capturing the unique geometry of your face  the distance between your eyes, the shape of your jawline, the contour of your nose  and converting it into a numerical code called a faceprint.

This faceprint is then stored in a database and matched against future scans to identify you.

Unlike a password, you cannot change your face. Unlike a phone number, it cannot be revoked. Once your faceprint is in a database, it is there permanently  unless someone with access deletes it.

That permanence is precisely why the law treats facial data as a category requiring the highest level of protection.


How the DPDPA 2023 Covers Facial Recognition

The Digital Personal Data Protection Act, 2023 does not mention facial recognition by name. However, the legal protection it provides is clear and directly applicable.

Your face qualifies as personal data under the DPDPA.

Section 2 of the DPDPA defines personal data as any data about an individual who is identifiable by or in relation to such data. A faceprint  a digital representation of your facial geometry unmistakably identifies you. It falls squarely within this definition.

Facial data is biometric data, and biometric data is sensitive.

While the DPDPA's implementing rules are still being finalised by the Data Protection Board of India, the legislative intent is clear: biometric data  which includes fingerprints, iris scans, and facial faceprints  must be treated as sensitive personal data requiring a higher standard of care and consent.

This means any organisation collecting your facial data must meet stricter obligations than those collecting, say, your name or email address.


The Consent Requirement: What Organisations Must Do Before Scanning Your Face

Under the DPDPA, a Data Fiduciary  any person or organisation that determines the purpose and means of processing your personal data  must obtain your free, specific, informed, and unambiguous consent before collecting your data.

Applied to facial recognition, this means the following must happen before your face is scanned:

1. You must be told clearly what data is being collected. A vague notice saying "CCTV in operation" does not cover facial recognition. The organisation must specifically disclose that your faceprint will be captured, processed, and stored.

2. You must be told why it is being collected. General security cannot serve as an open-ended justification. The stated purpose must be specific and limited.

3. You must actively consent  not just fail to object. Passive acceptance, such as continuing to walk through a door after seeing a small sign, does not constitute valid consent under the DPDPA.

4. You must be able to withdraw consent. The DPDPA gives every data principal  that is, you  the right to withdraw consent at any time. Withdrawal must be as easy as giving consent in the first place.

If any of these four conditions are not met, the collection of your facial data is non-compliant with the DPDPA.


Your Rights as a Data Principal Under the DPDPA

The DPDPA is one of the few Indian laws that directly names individual rights rather than simply imposing obligations on organisations. As a person whose facial data has been collected, you hold the following rights:

The Right to Access Information. You can ask any organisation whether they hold your facial data, what they use it for, and with whom they share it. They are required to respond.

The Right to Correction and Erasure. If your faceprint is inaccurate, or if you have withdrawn consent, you can demand that it be corrected or deleted. The organisation cannot simply ignore this request.

The Right to Grievance Redressal. Every Data Fiduciary must establish a grievance mechanism. If your complaint is not addressed, you have the right to escalate to the Data Protection Board of India.

The Right to Nominate. You can nominate another individual to exercise these rights on your behalf  particularly relevant if you are elderly, incapacitated, or unfamiliar with digital processes.


When Facial Recognition Becomes a Cyber Crime

There is a critical overlap between the DPDPA and the Information Technology Act, 2000 (IT Act) that most people  and even many organisations  do not fully appreciate.

If your facial data has been collected without consent, shared without authorisation, or used to harm you  through identity fraud, wrongful surveillance, or harassment the conduct may attract criminal liability under the IT Act, not merely civil penalties under the DPDPA.

Under Section 43 and Section 66 of the IT Act, unauthorised access to, collection of, or use of another person's data can result in imprisonment of up to three years and fines.

If the data was used to commit fraud, impersonate you, or stalk you, additional provisions under Sections 66C (identity theft) and 66D (cheating by personation using computer resources) may apply  with imprisonment extending up to three years.

The Bharatiya Nyaya Sanhita, 2023, which replaced the Indian Penal Code, also contains provisions relevant to cheating, criminal intimidation, and privacy violations that may be invoked depending on how the facial data was misused.


Practical Steps If Your Facial Data Has Been Misused

If you believe your facial data has been collected without consent or misused in any way, take the following steps in this order.

Step 1 — Document everything. Take screenshots, photographs, or video of any facial recognition camera visible on the premises. Note the date, time, and location. If you received any notice however inadequate  preserve it.

Step 2 — Send a written complaint to the organisation. Address it to the organisation's Data Protection Officer (DPO) if one is listed, or to their registered address. Request confirmation of whether your data was collected, what it is being used for, and demand deletion. Send this by email with a read receipt or by registered post.

Step 3 — File a complaint with the Data Protection Board. Once the Data Protection Board of India becomes fully operational under the DPDPA, it will be the designated authority to receive and adjudicate complaints about data violations. Complaints can also be filed with the Ministry of Electronics and Information Technology (MeitY) in the interim.

Step 4 — File a cyber crime complaint. If your facial data has been used for fraud, identity theft, or harassment, file a complaint at cybercrime.gov.in or by calling the National Cyber Crime Helpline at 1930. If there has been financial fraud, contact your bank immediately to freeze or flag the relevant accounts.

Step 5 — Consult a cyber lawyer. The intersection of the DPDPA, the IT Act, and the Bharatiya Nyaya Sanhita means your case may involve multiple legal frameworks. A qualified cyber advocate can assess the full picture including whether criminal prosecution is possible, whether civil remedies are available, and whether emergency orders such as injunctions or writs may be warranted.


The Ethical Dimension: What Responsible Organisations Must Do

Beyond legal compliance, responsible use of facial recognition technology demands ethical accountability. Organisations that deploy FRT without transparency, without meaningful consent, and without clear data minimisation policies are not simply cutting corners  they are eroding the foundational right to bodily autonomy and freedom from surveillance.

The DPDPA, in its current form, places the burden of proof on the Data Fiduciary. If your consent was not properly obtained, the law presumes the collection was unlawful. That is a significant protection  but only if you know about it and choose to exercise it.


Key Takeaways

  • Your faceprint is personal data protected under the DPDPA 2023.
  • Organisations must obtain your free, specific, and informed consent before scanning your face.
  • You have the right to access, correct, and delete your facial data.
  • Misuse of facial data may attract criminal liability under the IT Act and the Bharatiya Nyaya Sanhita.
  • If you are a victim, document everything, file a written complaint, and consult a cyber advocate.

Frequently Asked Questions

Q: Is facial recognition legal in India? A: Facial recognition is not banned in India, but its use is subject to the DPDPA 2023. Organisations must have a lawful basis  typically consent  before collecting or processing your faceprint. Unlawful collection can result in penalties and, in some cases, criminal liability.

Q: What can I do if a company scanned my face without asking me? A: Send a written complaint demanding confirmation and deletion of your data. If the company does not respond adequately, escalate to the Data Protection Board or file a complaint at cybercrime.gov.in. Consulting a cyber lawyer will help you determine whether further legal action is appropriate.

Q: What are the penalties for violating DPDPA provisions on personal data? A: The DPDPA provides for financial penalties reaching up to ?250 crore for significant violations. Additionally, if the conduct involves fraud or identity theft, criminal penalties under the IT Act may apply independently.

Q: Can I file a police complaint about facial data misuse? A: Yes. If your facial data has been used to commit fraud, identity theft, or harassment, a First Information Report (FIR) can be filed at your local police station or through the National Cyber Crime Portal at cybercrime.gov.in.

Q: Do I need a lawyer to pursue a DPDPA complaint? A: You are not required to have a lawyer, but given the technical complexity of biometric data cases and the overlap with the IT Act, professional legal guidance is strongly recommended.


 


If your facial data has been collected without consent, or if you are the victim of any cyber crime involving your personal or biometric data, LLM Advocates provides confidential legal consultations for individuals and businesses across Punjab, Haryana, Delhi, and Chandigarh.

Contact us on WhatsApp: +91-8572022292 Email: contact@llmadvocates.com


🔗 Share this post: https://llmadvocates.com/blog/facial-recognition-technology-dpdpa-legal-rights-india

About LLM Advocates

LLM Advocates is a specialized law firm registered with the Punjab & Haryana High Court, focusing on cyber law, AI governance, data privacy, and technology-related legal services. Our advocates hold LLM degrees in Cyber Law and are ISO 42001:2023 Certified Lead Auditors.

Meet Our Advocates →
Bot Avatar

LLMbot

Online