“The expanding matrix of Digital Public Infrastructure (DPI) in citizen service delivery has created an asymmetric concentration of executive surveillance power.” Analyze this statement in the context of the Right to Privacy.
Introduction
Digital Public Infrastructure (DPI)—comprising open, interoperable layers of identity (Aadhaar), payments (UPI, PFMS), and data exchange (DigiLocker, Account Aggregator)—has transformed citizen service delivery and welfare governance in India. While designed to eliminate leakages, promote digital inclusion, and advance targeted welfare, the systemic convergence of disparate citizen registries has concentrated unprecedented data-gathering and surveillance capabilities within the executive. This informational asymmetry creates acute friction with the Right to Privacy guaranteed as an intrinsic part of the fundamental right to life and personal liberty under Article 21 of the Constitution.
Manifestation of Asymmetric Executive Surveillance Power
- 360-Degree Citizen Profiling: The traditional administrative model preserved privacy through “institutional silos” (e.g., civil supplies, taxation, health, and transport maintained distinct records). DPI dismantles these firewalls via unique identifiers, enabling real-time administrative correlation of a citizen’s financial transactions, physical movements, social habits, and welfare dependence.
- Function Creep: Platforms conceived for targeted fiscal subsidies have incrementally metastasized into mandatory prerequisites for everyday civic and economic life (e.g., linking foundational identity to telecom SIMs, property records, and bank accounts), expanding state surveillance touchpoints.
- Structural Coercion and Compromised Consent: The classical doctrine of “informed and voluntary consent” fails within state welfare monopolies. When essential entitlements such as food grains (PDS) or social pensions are conditioned on digital authentication, consent becomes an involuntary transaction.
- Informational Inversion: The citizen is rendered entirely transparent and legible to the state apparatus, whereas executive processes—such as algorithms determining welfare exclusion, data access protocols, and inter-agency intelligence sharing—remain opaque and immune to public scrutiny.
Constitutional Friction: Testing DPI Against the Puttaswamy (2017) Doctrine
In the landmark Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) verdict, a nine-judge bench held that privacy is a fundamental right. Any state encroachment on privacy must strictly satisfy the Four-Fold Test of Proportionality:
| Proportionality Test Element | Constitutional Requirement | DPI Reality and Executive Practice |
| 1. Legality (Lawful Basis) | State action must be authorized by an accessible, clear, and primary statute. | Multiple DPI layers and departmental integrations operate under executive notifications and secondary rules rather than substantive legislative enactments. |
| 2. Legitimate State Aim | The measure must pursue a constitutionally recognized state objective. | Targeted welfare delivery is a legitimate state aim, but repurposing social welfare data for mass administrative surveillance or predictive profiling fails this nexus. |
| 3. Proportionality & Necessity | The method chosen must be the least intrusive measure available to achieve the goal. | Centralized database aggregation and mandatory biometric checks often exceed the minimal necessary intrusion required for simple identity authentication. |
| 4. Procedural Safeguards | The regime must provide independent oversight, accountability, and grievance redressal. | Surveillance and lawful interception frameworks continue to rely entirely on executive authorization (e.g., Rule 419A of the Telegraph Rules) without prior independent judicial warrants. |
Tamil Nadu Context: Welfare Efficiency vs. Data Safeguards
- State-Level DPI Integration: Through the Tamil Nadu e-Governance Agency (TNeGA), the state has pioneered foundational welfare databases such as the Tamil Nadu State Family Database (TNSFD) and the unique ‘Makkal ID’ to facilitate proactive welfare schemes (Kalaignar Magalir Urimai Thittam, Makkal Thedi Maruthuvam).
- Balancing Necessity with Restraint: While TNSFD eliminates administrative redundancy and duplicate beneficiaries, the state must ensure strict legal and technical segregation between social-security administration and policing databases (such as CCTNS) to prevent welfare records from morphing into executive profiling tools.
Key Statutory and Institutional Deficits
- Overbroad State Exemptions in DPDP Act, 2023: Section 17 of the Digital Personal Data Protection Act, 2023 provides sweeping exemptions to government instrumentalities on grounds of state security and public order, depriving citizens of substantive data fiduciary protections against the state.
- Executive Capture of the Regulatory Body: The Data Protection Board of India (DPBI) lacks constitutional or statutory independence, with its appointment and service conditions controlled by the Union executive, impeding its capacity to adjudicate state violations impartially.
- Archaic Surveillance Laws: India lacks a dedicated, modern surveillance reform law; executive agencies continue to wield interception and data-gathering powers governed by colonial-era legislation (Indian Telegraph Act, 1885; Section 69, Information Technology Act, 2000).
Way Forward
- Mandatory Judicial Warrant System: Divest the executive of exclusive interception and data-access powers. State agencies seeking access to citizen DPI metadata or aggregated registries must obtain prior authorization from an independent judicial magistrate.
- Privacy-by-Design Architecture: Re-engineer DPI platforms around Federated Architectures and Zero-Knowledge Proofs (ZKP), verifying citizen eligibility without centralizing or retaining behavioral and relational metadata.
- Statutory Codification of Purpose Limitation: Enact primary legislation that strictly penalizes inter-departmental data linkage unless explicitly authorized by law for a narrowly defined purpose.
- Surveillance and DPDP Reform: Amend Section 17 of the DPDP Act, 2023 to subject state surveillance actions to the Puttaswamy necessity standards, and grant functional autonomy to the Data Protection Board.
Conclusion
Digital Public Infrastructure is an indispensable instrument for equitable public service delivery in a modern welfare state. However, administrative efficiency cannot be achieved by turning the citizen into an open book while the state retreats behind an opaque wall of executive discretion. A democratic republic governed by constitutional morality requires robust statutory firewalls, technical safeguards, and independent judicial oversight, ensuring that DPI remains an engine of socio-economic empowerment rather than an apparatus of asymmetric executive surveillance.
“குடிமக்கள் சேவை வழங்கலில் டிஜிட்டல் பொதுக் கட்டமைப்பின் (DPI) விரிவடைந்து வரும் வலைப்பின்னல், செயலாட்சி அமைப்பின் கைகளில் சமச்சீரற்ற கண்காணிப்பு அதிகாரத்தைக் குவித்துள்ளது.” தனிஉரிமை உரிமையின் (Right to Privacy) பின்னணியில் இக்கூற்றை ஆராய்க.
அறிமுகம் (Introduction) டிஜிட்டல் பொதுக் கட்டமைப்பு (Digital Public Infrastructure – DPI) என்பது மக்கள்தொகை அளவில் குடிமக்களுக்கான சேவைகளையும் நலத்திட்டங்களையும் வழங்க உதவும் டிஜிட்டல் அடையாள அட்டை (Aadhaar), பணப் பரிவர்த்தனை வழிகள் (UPI) மற்றும் தரவுப் பகிர்வு அமைப்புகள் (DigiLocker) ஆகியவற்றை உள்ளடக்கியதாகும். இவை பொது விநியோகத்தில் கசிவுகளைக் குறைத்து வெளிப்படைத்தன்மையை மேம்படுத்திய போதிலும், பல்வேறு துறைகளின் குடிமக்கள் தரவுகள் ஒன்றிணைக்கப்படுவது, அரசின் கைகளில் எல்லையற்ற கண்காணிப்பு அதிகாரத்தைக் குவித்து, அரசியலமைப்புச் சரத்து 21 வழங்கும் ‘தனிஉரிமை உரிமைக்கு’ (Right to Privacy) பெரும் அச்சுறுத்தலாக மாறியுள்ளது.
செயலாட்சி அமைப்பின் சமச்சீரற்ற கண்காணிப்பு அதிகாரம் (Asymmetric Concentration of Executive Power)
- 360° குடிமக்கள் விவரக் குறிப்பு (360° Citizen Profiling): வருவாய்த்துறை, பொது விநியோகத் திட்டம், சுகாதாரம், போக்குவரத்து போன்ற தனித்தனி நிர்வாகத் துறைகளின் தரவுகள் ஒன்றிணைக்கப்படுவதால், ஒரு குடிமகனின் நிதி, இருப்பிடம் மற்றும் நலத்திட்டப் பயன்பாடுகள் அனைத்தையும் அரசு ஒரே இடத்தில் நிகழ்நேரத்தில் (real-time) கண்காணிக்க முடிகிறது.
- பணி விலகல் (Function Creep): மானிய விநியோகத்திற்காகத் தொடங்கப்பட்ட டிஜிட்டல் அடையாளங்கள், பின்னர் படிப்படியாக சிம் கார்டு, வாக்காளர் அடையாள அட்டை, சொத்துப் பதிவு போன்ற குடிமை உரிமைகளுக்கான கட்டாயத் தேவையாக மாற்றப்பட்டு கண்காணிப்பு வளையம் விரிவாக்கப்படுகிறது.
- கட்டாயச் சம்மதம் (Coerced Consent): நியாயவிலைக் கடைப் பொருட்கள், முதியோர் ஓய்வூதியம் போன்ற அடிப்படை வாழ்வாதார நலன்களுக்கு டிஜிட்டல் அடையாளம் கட்டாயமாக்கப்படுவதால், குடிமகன் தனது சுயவிருப்பத்தின் பேரில் ‘உண்மையான சம்மதத்தை’ (informed consent) அளிக்க முடிவதில்லை.
- தகவல் சமச்சீரற்ற தன்மை (Informational Asymmetry): குடிமக்கள் அரசின் பார்வைக்கு முற்றிலும் வெளிப்படையானவர்களாக மாறுகின்றனர்; ஆனால், அரசு அந்தத் தரவுகளை எவ்வாறு அணுகுகிறது, சேமிக்கிறது மற்றும் பயன்படுத்துகிறது என்பது மக்களுக்குத் தெரியாத வகையில் ஒளிவுமறைவாகவே உள்ளது.
புட்டசுவாமி தீர்ப்பு (2017) மற்றும் தனிஉரிமை மீதான தாக்கம் (Impact on Right to Privacy)
நீதிபதி கே.எஸ். புட்டசுவாமி எதிர் இந்திய ஒன்றியம் (2017) வழக்கில், 9 நீதிபதிகள் கொண்ட உச்ச நீதிமன்ற அமர்வு தனிஉரிமையைச் சரத்து 21-ன் பிரிக்க முடியாத அடிப்படை உரிமை எனத் தீர்ப்பளித்தது. அரசின் எந்தவொரு தரவு சேகரிப்பும் பின்வரும் நான்கு சோதனைகளை நிறைவு செய்ய வேண்டும்:
- சட்டப்பூர்வத் தன்மை (Legality): பல டிஜிட்டல் கட்டமைப்பு அடுக்குகள் நாடாளுமன்றத்தின் நேரடிச் சட்டங்களுக்குப் பதிலாக, நிர்வாக அறிவிக்கைகள் மூலமே செயல்படுத்தப்படுகின்றன.
- நியாயமான நோக்கம் (Legitimate State Aim): நலத்திட்டங்களை வழங்குவது அரசின் நியாயமான நோக்கமே ஆயினும், அதற்காகத் திரட்டப்படும் தரவுகளை நிர்வாகக் கண்காணிப்பிற்குப் பயன்படுத்துவது அரசியலமைப்புக்கு எதிரானது.
- விகிதாசாரத் தன்மை (Proportionality): அடையாளச் சரிபார்ப்பிற்குத் தேவையான குறைந்தபட்ச அளவைத் தாண்டி, வாழ்நாள் முழுவதும் தரவுகளை மையப்படுத்தப்பட்ட சேமிப்பகங்களில் (centralized databases) சேமிப்பது விகிதாசாரக் கோட்பாட்டை மீறுகிறது.
- நடைமுறைப் பாதுகாப்புகள் (Procedural Safeguards): டிஜிட்டல் தனிநபர் தரவுப் பாதுகாப்புச் சட்டம், 2023-ன் பிரிவு 17 அரசு அமைப்புகளுக்குப் பரவலான விலக்குகளை வழங்குகிறது; மேலும் சுதந்திரமான நீதித்துறை மேற்பார்வைக்கான (Judicial Oversight) வழிமுறைகள் இன்றி நிர்வாக அதிகாரிகளே முடிவெடுக்கும் சூழல் நீடிக்கிறது.
தமிழ்நாட்டுச் சூழல் (Tamil Nadu Perspective)
- தமிழ்நாடு மின்னாளுமை முகமை (TNeGA) மூலம் நடைமுறைப்படுத்தப்படும் தமிழ்நாடு மாநிலக் குடும்பத் தரவுத்தளம் (TNSFD) மற்றும் ‘மக்கள் எண்’ (Makkal ID) ஆகியவை கலைஞர் மகளிர் உரிமைத் திட்டம், மக்களைத் தேடி மருத்துவம் போன்ற திட்டங்களை வெளிப்படையாக வழங்கப் பயன்படுகின்றன.
- எனினும், நலத்திட்டங்களுக்காகத் திரட்டப்படும் இக்குடும்பத் தரவுகள், குடிமக்களை அரசியல் ரீதியாகக் கண்காணிப்பதற்கோ அல்லது அவர்களின் உரிமைகளைப் பறிப்பதற்கோ வழிவகுக்காத வண்ணம் கடுமையான தொழில்நுட்ப அரண்களால் (firewalls) பாதுகாக்கப்பட வேண்டியது அவசியமாகும்.
முன்னோக்கிய பாதை (Way Forward)
- நீதித்துறை அனுமதி ஆணை (Judicial Warrants): அரசு அமைப்புகள் குடிமக்களின் மெட்டாடேட்டா அல்லது ஒருங்கிணைந்த தரவுகளை ஆய்வு செய்வதற்கு, நிர்வாக ஒப்புதலுக்குப் பதிலாக நடுநிலையான நீதிமன்றங்களின் முன்கூட்டிய அனுமதி கட்டாயமாக்கப்பட வேண்டும்.
- வடிவமைப்பிலேயே தனிஉரிமை (Privacy by Design): மையப்படுத்தப்பட்ட தரவுச் சேமிப்பைத் தவிர்த்து, பரவலாக்கப்பட்ட கூட்டமைப்புக் கட்டமைப்பு (Federated Architecture) மற்றும் ஜீரோ-நாலேஜ் ப்ரூஃப் (ZKP) போன்ற நவீனத் தொழில்நுட்பங்களைப் பயன்படுத்த வேண்டும்.
- நோக்க வரம்பு (Purpose Limitation): எந்த நலத்திட்டத்திற்காகத் தரவு பெறப்பட்டதோ, அதற்கு மட்டுமே அதைப் பயன்படுத்த வேண்டும்; பிற நோக்கங்களுக்குப் பகிர்வதைச் சட்டப்படி தண்டனைக்குரிய குற்றமாக்க வேண்டும்.
- DPDP சட்டச் சீர்திருத்தம்: தரவுப் பாதுகாப்புச் சட்டத்தில் அரசுக்கு வழங்கப்பட்டுள்ள அளவுகடந்த விலக்குகளைக் குறைத்து, தரவுப் பாதுகாப்பு வாரியத்திற்குத் தன்னாட்சி அதிகாரம் வழங்கப்பட வேண்டும்.
முடிவுரை (Conclusion) டிஜிட்டல் பொதுக் கட்டமைப்பு என்பது நவீன பொதுநல அரசின் செயல்திறனை உயர்த்தும் வலிமையான கருவியாகும். ஆனால், நிர்வாக வசதிக்காகக் குடிமகனை அரசின் முன் முற்றிலும் வெளிப்படையாக்கிவிட்டு, அரசை ஒரு ஒளிவுமறைவான கண்காணிப்பு அமைப்பாக மாற்றுவது ஜனநாயகக் குடியரசின் அடித்தளத்தையே தகர்த்துவிடும். ஆகவே, வலுவான சட்டக் கட்டுப்பாடுகள், சுதந்திரமான நீதித்துறை தணிக்கை மற்றும் தொழில்நுட்பப் பாதுகாப்புகளின் வாயிலாக மட்டுமே குடிமக்களின் தனிஉரிமையைப் பாதுகாத்து, டிஜிட்டல் பொதுக் கட்டமைப்பை உண்மையான மக்கள் நலக் கருவியாக நிலைநிறுத்த முடியும்.