Digital Privacy

Who Controls the Controls?
India's Next Digital Frontier Isn't Capability. It's Restraint.

Awadh Bajpai 11 min read 2026-07-19

India can now see almost everything about its citizens. The harder question isn't capability, it's restraint. A founder's honest look at the gap.

Who Controls the Controls? India's Next Digital Frontier Isn't Capability. It's Restraint.

I have spent most of my working life building and working with connected systems: systems that move critical information, carry high-value data, and operate across networks where reliability, access, and security cannot be afterthoughts. Over time, that has given me a close view of security not merely as a product or a technology, but as a fundamental property of how systems must be designed, operated, and trusted.

One lesson keeps returning. The most important question is rarely what a system can do. It's who is allowed to use it, under what authority, for what purpose, and what happens when it gets something wrong.

That is increasingly the question India needs to ask about its own digital infrastructure.

Two pieces of writing pushed me to think this through more carefully this year. Dr. Asvatha Babu, drawing on years of doctoral fieldwork inside Tamil Nadu's policing apparatus, examined how a facial-recognition tool there sits on top of much older, messier layers of crime data: a state database drawing from more than fifteen thousand police stations, feeding into NATGRID, the national intelligence grid that can, by design, assemble a 360-degree profile of almost any adult in the country. Utkarsh Mishra, writing from a different direction, traced India's welfare architecture and the data trail every citizen leaves behind when they authenticate themselves for a pension, a ration, or a hospital visit.

They approach the subject from different directions but arrive at the same structural question: has India's ability to connect information about its citizens grown faster than the institutions designed to govern how that information gets used?

I believe it has. But the answer isn't to stop building.

The Velocity of Connection

India has created digital infrastructure at a scale few democracies have attempted. Aadhaar gave more than a billion people a digital identity. UPI transformed how an entire country moves money. DigiLocker put verifiable documents into people's pockets. Direct Benefit Transfer changed how public benefits reach citizens directly, cutting out a layer of middlemen who had skimmed subsidies for decades.

These are extraordinary achievements, and I'm not writing any of what follows to diminish them. I'm writing it because these achievements are precisely why the next question matters so much: has India's architecture of accountability, purpose limitation, independent oversight, auditable access, a citizen's ability to challenge what a system believes about them, evolved with the same ambition as its architecture of capability? I'm not convinced it has.

Here is the principle I keep returning to: as the technical cost of connecting one piece of information about a citizen to another approaches zero, the institutional threshold for doing so should rise, not fall.

"As the technical cost of connecting one piece of information about a citizen to another approaches zero, the institutional threshold for doing so should rise, not fall."

That idea needs qualifying, though, or it collapses into simple technophobia. Connection itself is not inherently dangerous. A government that can verify a farmer's identity in seconds rather than weeks is doing something genuinely valuable. A police force that can identify a dangerous suspect quickly can save lives. The real question is what happens after the connection becomes technically possible. Who can make it? For what purpose, and is that purpose recorded anywhere a citizen or a court could later examine? If the system gets it wrong, can the mistake actually be corrected, or does it just calcify into the record?

A system that connects information quickly but restricts its use tightly is a fundamentally different animal from one where technical capability keeps outrunning the safeguards around it. That's where India's next challenge sits.

Laundering the Flawed Record

Large government databases are ultimately built by human beings, often working under pressure, dealing with incomplete information, inconsistent spellings, transliterations, and forms designed for circumstances that don't always fit reality. Babu's fieldwork gives an uncomfortable, ground-level view of this. Tamil names get auto-transliterated into English and the errors compound. Data-entry operators, buried under paperwork, leave fields blank when something looks irrelevant. In some cases, officers are instructed to photograph "bad characters" who haven't been charged with anything at all, a precaution that disproportionately touches Dalit, Tribal, and Muslim communities already over-represented in crime data by decades of discriminatory policing.

None of this requires corruption or malicious intent. Errors of this kind are close to inevitable in a bureaucracy operating at this scale. But when imperfect records become inputs into increasingly sophisticated systems, something changes. A questionable database entry becomes an input to a facial match. The match shapes an officer's judgment. That judgment produces another permanent record, one the next official is more likely to trust precisely because it now arrives wearing the authority of a digital system rather than a handwritten note in a paper file.

"Digitising a flawed record doesn't correct it. Sometimes it launders it."

The same concern shows up in a different form on the welfare side. Every pension collected, ration drawn, or wage paid through Direct Benefit Transfer is also a timestamped, biometrically verified data point. Mishra's argument, and researchers studying India's welfare-digitisation platforms have made a related point, is that the same entity-resolution techniques used in intelligence work are increasingly stitching Aadhaar, ration, job-card, and pension records into single citizen profiles, on a legal basis that is, at best, unclear. There's a second-order version of this worth sitting with too: India's welfare databases don't record caste directly, but the combination of village, land-holding, and scheme enrolment makes caste inferable anyway. You don't need a category field for a discriminatory pattern to re-emerge from data that looks neutral on its face.

Which brings me to a principle that deserves more attention than it gets: information given for one purpose is not automatic permission to use it for another.

"Information given for one purpose is not automatic permission to use it for another."

I encountered a small, everyday version of this after moving from Sweden to India. I was struck by how routinely a mobile number gets requested for the most ordinary transactions: a purchase, a warranty registration, a loyalty programme, a delivery I'd never repeat. Eventually I started keeping a separate number for these. This isn't evidence of government surveillance, and it isn't uniquely an Indian problem, but it points at something companies and governments both quietly forget. A phone number given to a retailer for one transaction isn't an invitation into every other part of someone's life. A fingerprint used to authenticate a pension shouldn't automatically become permission to build an unrelated behavioural profile. That boundary is rarely a technical one. It has to be designed on purpose, or eventually it stops existing.

The Architecture of the Brake

India's Digital Personal Data Protection Act is a genuine step toward drawing boundaries like these. It was passed in 2023, and its implementing rules were finally notified in November 2025, later than many hoped but not, contrary to how the delay still gets described, still pending today. That correction matters, because it changes what the live argument actually is.

The live argument is Section 17. It lets the central government exempt its own agencies from the Act entirely, in the interest of sovereignty, security, or public order, categories the Act never tightly defines. And the Data Protection Board, the body meant to enforce all of this, is appointed by and answerable to the very government whose agencies it may one day need to discipline. A law that constrains private companies while leaving the state largely free to exempt itself isn't a data protection law in the full sense. It's half of one.

"A law that constrains private companies while leaving the state largely free to exempt itself isn't a data protection law in the full sense. It's half of one."

My own frame of reference here is Sweden, where I lived for more than a decade, and I want to resist the easy version of this comparison, because it's wrong. Sweden is no privacy paradise. It has kept population registers for centuries, and its personal identity number, the personnummer, touches nearly every interaction a Swede has with government, banks, and healthcare. Public records there are startlingly open by Indian or American standards. And in 2026, Sweden's parliament authorised the police to use live facial recognition in public spaces, a capability the country didn't have before, in direct response to a documented rise in gang violence.

So the honest difference between India and Sweden was never "Europe protects data, India collects it." That framing doesn't survive contact with the facts. The real difference is in what surrounds the capability. Sweden's new law is scoped to a specific list of serious crimes: kidnapping, trafficking, offences carrying at least four years' imprisonment, imminent threats to life. It requires prosecutorial or judicial authorisation as the default, with a strict twenty-four-hour window for retroactive approval in genuine emergencies. Every use has to be reported to Sweden's privacy regulator, and a fundamental rights impact assessment has to exist before the technology is deployed for the first time, not after.

Five years earlier, that same regulator fined the Swedish police roughly a quarter of a million euros for using Clearview AI without authorisation: a handful of officers acting on their own initiative, no different in spirit from the discretionary FRS checks Babu describes Tamil Nadu officers running on instinct. The difference is what happened next. The regulator investigated, fined the force, and ordered the data deleted. The capability crossed a line. The institution around it noticed, and held.

"That, to me, is the real test of a mature digital democracy: not how much it can see, but how reliably it notices, and corrects itself, when seeing turns into misuse."

Security Is More Than Detection

I think about this the way I think about a well-run security operations centre, because that's the frame I know best. No competent organisation would give a single operator unrestricted, permanent access to every camera, every recording, and every customer file it holds, with no log of who looked at what, or why. That isn't paranoia. It's basic professional discipline: role-based access, purpose-based permissions, audit trails that can't be edited after the fact, retention limits, and a clear chain of accountability when something goes wrong. None of this is bureaucratic overhead bolted onto security. It is security, the same way brakes aren't an accessory to a car's engine.

There's a related distinction that matters more with every year AI enters these systems. A camera is not a security system. An AI match is not evidence. A confidence score is not a verdict. The EU's own AI rules make this concrete rather than aspirational: before an AI facial match can lead to any action against someone, two separately qualified people have to independently confirm the identification first. That single procedural rule is a better description of the difference between detection and judgment than any amount of philosophy. Detection is what the machine does. Judgment is what a human has to do afterward, on the record, accountable for getting it wrong.

"A camera is not a security system. An AI match is not evidence. A confidence score is not a verdict."

I don't see why a government's information architecture should be held to a lower standard than the one I'd insist on for a commercial security system a fraction of its size.

None of this is an argument for India to build less. Quite the opposite. But restraint is not the opposite of capability. It's the harder half of the same engineering problem, and India has, so far, mostly solved the easier half. A national identity system doesn't need to know everything a policing system knows. A welfare database doesn't need to be legible to every other arm of the state. A facial match shouldn't become a verdict on someone's guilt without an independent human standing behind it. Access to sensitive citizen data shouldn't depend mainly on whether an official has the technical means to retrieve it.

These are architecture questions as much as legal ones. Systems can be built around least-privilege access. Queries can be logged. Unusual access patterns can trigger automatic review. Data collected for one purpose can be walled off from another by default, not by policy memo. Citizens can be given a real mechanism to see and correct what a system believes about them. And independent institutions, not ones appointed by the same authority they're meant to watch, can be empowered to keep asking the one question that matters most: who looked, and why?

Who Drives in 2040?

The systems being built right now will outlive the people building them. They will almost certainly outlive the political mood that shaped them. A database designed under one government gets inherited by the next one, and then the one after that, unchanged in its architecture even as the hands on the wheel change completely. That isn't a partisan worry. It's just how infrastructure works. Roads don't ask who's driving.

"Roads don't ask who's driving."

So the question worth sitting with isn't whether today's officials mean well. I think most of them do. It's whether the systems we're handing to the officials of 2040 have brakes built into their architecture, or whether we're simply trusting that whoever's driving will always choose to slow down on their own.

India has already shown the world it can build the engine. The harder, more consequential problem, the one that will actually decide what kind of digital democracy this becomes, is whether it can build the brakes with the same ambition.

"India has already shown the world it can build the engine. The harder problem is whether it can build the brakes with the same ambition."


Quick Answers

Is Aadhaar a surveillance system?

Aadhaar was built as an identity and welfare-delivery system, not a surveillance system. But because every authenticated transaction leaves a biometric, timestamped record, and because those records can be linked across databases and agencies, it can function as one in practice, even without that being the original design intent.

What is India's DPDP Act, and does it stop government surveillance?

The Digital Personal Data Protection Act, 2023, is India's first comprehensive data protection law, with rules notified in November 2025. It regulates how private and public entities handle personal data, but Section 17 allows the central government to exempt its own agencies from the Act for reasons of sovereignty, security, or public order, so it does not fully constrain state surveillance activity.

Does GDPR make Europe safer from surveillance than India?

Not in any simple sense. European states, including Sweden, are actively expanding police use of biometric surveillance and facial recognition. The meaningful difference isn't whether the state can see citizens; it's the friction required before that seeing produces a consequence: judicial authorisation, mandatory reporting, independent oversight, and the possibility of a system being caught and disciplined when it's misused.

What is NATGRID and how does it connect to Aadhaar?

NATGRID is India's National Intelligence Grid, a national database linking information from policing systems, Aadhaar, banking, telecom, travel, and other sources for use by security agencies. It illustrates how identity, financial, and behavioural data can be fused into a single profile once the underlying databases are connected.


Awadh Bajpai has spent over two decades working across telecom, broadcast infrastructure, and modern security technology, in roles spanning the USA, Israel, Sweden and India. He writes about the intersection of technology, governance, and citizenship from the perspective of someone who has built the systems he writes about.

Tags

Digital Privacy India Surveillance Aadhaar DPDP Act NATGRID Facial Recognition India GDPR vs India Digital Governance Founder Perspective India Tech Policy

Related topics

Digital Privacy India Surveillance DPDP Act Aadhaar NATGRID

A
Awadh Bajpai

Co-founder, Intelitor Technologies · Coimbatore

Discover Your Path

See how we protect your property step-by-step

WHICH PROPERTY TO PROTECT?

Shopping Cart

Your cart is empty

Add some products to get started.

Total: ₹0

Add items to send a quote.