Information Technology Act, 2000
IT Act and Right to Privacy: Puttaswamy, Surveillance and Section 69
Topic 8 set out the statutory data protection regime: Section 43A, the SPDI Rules and the DPDP Act. This note looks at privacy from the constitutional side. Since Puttaswamy in 2017, privacy has been a fundamental right, and every power in the IT Act that intrudes on it, above all interception, monitoring and decryption, must pass the test of legality, necessity and proportionality. The note traces the constitutional right, the facets and test that define it, how the Act's surveillance powers are checked, the controversies over traceability and spyware, the right to be forgotten, and the protection of privacy against private actors.
1. The Curtain and the Keyhole
Everyone has the right to draw the curtains of their home. The State may still look through the keyhole, but only with a warrant, for a serious reason, for a limited time, and with someone checking that the warrant was properly issued. Digital life has moved the home onto phones and servers, and the keyhole now takes the form of interception orders, traffic data and decryption. The constitutional question is the same: who may look, on what grounds, and who watches the watcher?
Figure 1: How the right to privacy developed
2. The Constitutional Right
- Before 2017. M.P. Sharma v. Satish Chandra (1954) and Kharak Singh v. State of U.P. (1962) had said there was no fundamental right to privacy, though Kharak Singh struck down night-time domiciliary visits. Later cases recognised privacy in narrower forms: Gobind v. State of M.P. (1975), R. Rajagopal v. State of T.N. (1994) and PUCL v. Union of India (1997) on telephone tapping.
📖 Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 Bench: Nine judges, delivering six concurring opinions. Held: Privacy is a fundamental right, intrinsic to life and personal liberty under Article 21 and to the freedoms in Part III. M.P. Sharma and Kharak Singh were overruled to the extent they held otherwise. The right is not absolute; an intrusion must satisfy legality, a legitimate aim and proportionality. Informational privacy: The plurality recognised that informational privacy is a facet of the right and urged the State to put in place a robust data protection regime. Significance: Every surveillance and data power under the IT Act must now be tested against this standard. |
Figure 2: Three facets of privacy recognised in Puttaswamy
- Selvi v. State of Karnataka, (2010) 7 SCC 263. Involuntary narco-analysis, polygraph and brain mapping tests violate Article 20(3) and the right to mental privacy under Article 21, an early recognition of the privacy of the mind.
3. The Proportionality Test
Figure 3: The four-part proportionality test
- Source. Drawn from Modern Dental College and Research Centre v. State of M.P., (2016) 7 SCC 353, and applied to privacy in the Aadhaar judgment.
- Puttaswamy (Aadhaar), (2019) 1 SCC 1. The majority upheld Aadhaar for welfare and PAN linkage as proportionate, but struck down Section 57 of the Aadhaar Act permitting private entities to require Aadhaar authentication, and read down provisions on data retention. Justice Chandrachud dissented, holding the Act unconstitutional.
- Procedural safeguards. Justice Kaul in Puttaswamy added that there must be procedural guarantees against abuse of State power, which is why the safeguards attached to interception matter so much.
4. State Surveillance under the IT Act
Figure 4: Surveillance powers and their safeguards
- Section 69. The Central or State Government may direct interception, monitoring or decryption of any information in a computer resource on grounds of sovereignty, integrity, defence, security of the State, friendly relations, public order, preventing incitement to a cognizable offence, or investigation of any offence. Intermediaries and subscribers must assist, on pain of punishment.
- The 2009 Rules. Directions are issued by the competent authority, ordinarily the Union or State Home Secretary, with reasons; less intrusive means must be considered; directions last up to 60 days, renewable to a maximum of 180 days; a review committee examines them; and records must be destroyed when no longer needed.
- Section 69B. The Central Government may authorise monitoring and collection of traffic data to enhance cyber security.
- Telecommunications Act, 2023. Interception of telecom messages now rests on Section 20(2) of the 2023 Act and rules made under it in 2024, replacing Section 5(2) of the Telegraph Act and Rule 419A.
- PUCL v. Union of India, (1997) 1 SCC 301. Tapping without safeguards violates privacy; the Court laid down procedural safeguards that shaped both the telegraph rules and the IT Act rules.
- Vinit Kumar v. CBI (Bombay High Court, 2019). Interception orders in a bribery investigation were quashed because the situation was not a public emergency or a matter of public safety and the rules were not followed; the Court ordered the intercepted material destroyed.
📖 Manohar Lal Sharma v. Union of India (Pegasus, Supreme Court, 2021) Issue: Reports alleged that the Pegasus spyware had been used to target journalists, politicians and activists in India. Order: The Court held that the State does not get a free pass every time national security is raised, and appointed a technical committee overseen by Justice R.V. Raveendran to investigate. Outcome: In 2022 the Court recorded that malware was found on some of the phones examined but could not be conclusively linked to Pegasus, and that the Government had not cooperated with the committee. Significance: Confirms that covert surveillance is subject to judicial scrutiny under the Puttaswamy standard. |
- Traceability. Rule 4(2) of the IT Rules, 2021 requires significant messaging intermediaries to enable identification of the first originator of a message on a court or government order. Messaging services argue that this breaks end-to-end encryption for all users, and the rule has been challenged before the courts.
- Data retention. The CERT-In Directions of 2022 require logs to be kept for 180 days and VPN providers to retain subscriber data for five years, raising proportionality concerns.
- DPDP Act exemptions. Section 17 allows the Central Government to exempt State instrumentalities from the Act on grounds such as security and public order, which critics say is too wide to satisfy Puttaswamy.
5. The Right to Be Forgotten
- Meaning. The right to have personal information removed or de-indexed once it is no longer relevant, outdated or harmful.
- Judicial recognition. High Courts have granted limited relief, for example Jorawer Singh Mundy v. Union of India (Delhi High Court, 2021), directing removal of a judgment acquitting the petitioner from online search results. Courts balance the right against open justice and the public's right to know.
- Statutory right. Section 12 of the DPDP Act gives Data Principals a right to erasure of personal data no longer needed for the purpose, once the substantive provisions commence.
6. Privacy against Private Actors
Figure 5: Vertical and horizontal privacy
- IT Act protections. Compensation for negligent data security (s.43A), punishment for capturing or publishing private images (s.66E), and a civil penalty of up to ₹25 lakh for disclosure of personal information in breach of contract (s.72A) (see Topic 8)
- DPDP Act. Duties of Data Fiduciaries, rights of Data Principals and penalties imposed by the Data Protection Board, applying to private and State actors alike, subject to exemptions.
- Tort. The courts also recognise a civil action for invasion of privacy, drawing on R. Rajagopal (1994)
⚠ Exam trap Do not treat privacy as absolute. Puttaswamy recognises that the State may intrude, but only under a law, for a legitimate aim, by proportionate means and with procedural safeguards. In a problem question on interception under Section 69, test the order against each element: legal authority, grounds, competent authority, reasons, duration, review and destruction. |
7. Quick Revision and Memory Aids
- 'Curtain and keyhole'. Privacy and lawful intrusion.
- 'Body, information, choice'. Facets of privacy.
- 'Aim, connection, necessity, balance'. The proportionality test.
- '60 days, 180 max, review, destroy'. Section 69 safeguards.
- 'No free pass for national security'. Pegasus.
- 'Vinit Kumar: no emergency, no tap'. Limits on interception.
8. Frequently Asked Questions
How does Puttaswamy affect the IT Act?
It makes privacy a fundamental right, so every intrusion under the IT Act, such as interception, monitoring, decryption, traffic data collection and traceability, must be authorised by law, pursue a legitimate aim, be proportionate and carry procedural safeguards.
What safeguards apply to interception under Section 69?
A reasoned order by the competent authority, consideration of less intrusive means, a maximum duration of 60 days renewable up to 180 days, review by a committee, and destruction of records when no longer needed, under the 2009 Rules.
Is there a right to be forgotten in India?
High Courts have recognised it in limited cases, and Section 12 of the DPDP Act gives a statutory right to erasure once its substantive provisions commence.
9. Related Topics
- Topic 8: Privacy and Data Protection. Section 43A, the SPDI Rules and the DPDP Act.
- Topic 17: IT Act and Freedom of Speech. The companion constitutional topic.