India explainer

Facial Recognition Is Quietly Spreading Across India. Who Said Yes?

It's at the airport, the railway station, increasingly the police station — and almost nobody was asked. How facial recognition spread across India by default, and why consent-by-silence matters.

Somewhere in the last few years, facial recognition in India stopped being a science-fiction prop and became a piece of everyday infrastructure. You may have already used it without quite deciding to: walking through a boarding gate that matched your face to your ticket, passing under a camera at a station, standing in a queue where a screen compared your face to a database. It arrived not through one loud decision but through hundreds of small ones, each defensible on its own, none put to you as a question. That is the strange thing about it. It spread fast, it spread wide, and almost nobody remembers being asked.

I want to walk through what has actually happened, why it happened so quietly, and what it would take to bring some accountability to it. I am not interested in panic. Face recognition can be genuinely useful, and pretending otherwise makes the argument easy to dismiss. What I am interested in is the pattern — the way a powerful capability gets normalised before the public has a chance to weigh in. It is the same pattern I keep tracing in how technology gets captured, and India is one of its clearest live examples.

How it spread: piecemeal, and fast

There was never a single national rollout of facial recognition that citizens could point to and debate. Instead there were deployments — plural, scattered, mostly framed as convenience or security upgrades. Take air travel. Digital, face-based boarding of the DigiYatra kind has reportedly been introduced at a growing number of Indian airports, letting travellers move from entry to gate without repeatedly showing documents. It is genuinely smoother. It is also, functionally, a system that recognises your face at multiple checkpoints — and its framing as pure convenience is exactly what makes it easy to accept.

Policing is another vector. Various state police forces have, by numerous accounts, adopted facial-recognition tools to match images against records — for missing persons, for identifying suspects, for crowd monitoring at large gatherings. The details differ from state to state, and reliable public information is patchy, which is part of the problem. Then there are public spaces: cities have installed large camera networks under smart-city and safety programmes, and in a range of pilots those cameras have been paired with, or proposed for, face-matching. Add the quieter uses — attendance systems in some workplaces and institutions, and face-based verification proposed or trialled in various welfare contexts.

No single one of these is a scandal. But step back and the aggregate is remarkable: a country building, without much coordinated public discussion, a broad capacity to recognise faces across travel, policing, public streets, and essential services. Each deployment was sold on its own merits. The sum is a different thing entirely.

The legal vacuum

Here is what I find most striking. India, as of now, has no dedicated law governing facial recognition. There is no single statute that says when a face may be captured, who may run it against a database, how long the data may be kept, or what recourse you have if it gets you wrong. Instead there is a patchwork: general policing powers, procurement rules, departmental policies, and the broad constitutional backdrop of the right to privacy the Supreme Court recognised as a fundamental right.

Into that gap steps India's emerging data-protection framework — the regime built around the DPDP Act. That framework matters, and it establishes real principles about consent and the handling of personal data. But it is a general data-protection law, not a facial-recognition law, and the two are not the same thing. It does not, on its own, answer the hard questions a face-recognition system raises: Should live face-matching of crowds in public be permitted at all? What error rate is acceptable before a system can flag someone to the police? Who audits the databases? These are not questions a general statute was designed to resolve, and leaving them to be worked out deployment by deployment is how you end up with capability far ahead of accountability.

This is a familiar shape. It is what happened with identity and payments too, the terrain I covered in Aadhaar and UPI: enormously useful systems adopted at civilisational scale, with governance arriving after the fact and struggling to catch up. Facial recognition follows the same sequence, only with a capability that is arguably more intimate — your face is not a number you can be issued a new one of. You cannot revoke it, and you wear it in public every day.

Consent by silence is the heart of the problem

The word that keeps getting used to justify all this is consent. I want to be precise about what it means here, because the version being offered is not the real thing.

You cannot meaningfully consent to a camera you never saw, run by an operator you cannot name, matching your face against a database you have no way to inspect.

Real consent is specific, informed, and refusable. You understand what is being collected, by whom, for what, and you can say no without losing access to something you need. Almost none of the face-recognition you encounter in India meets that bar. Walk through a public square under a smart-city camera and there is no consent event at all — the capture just happens. Show up for a service that increasingly expects face verification and refusal starts to feel like opting out of the service.

This is what I mean by consent by silence, or consent by default. The absence of a clearly voiced no gets treated as a yes. That inversion is the quiet engine of the whole expansion. It is the same move at the core of surveillance capitalism, where your data is taken as the price of participation and the taking is designed to be frictionless enough that you never quite notice it. In the commercial version the currency is your behaviour and attention; in the state and civic version it is your face and your movements. The underlying logic is identical: extract by default, ask forgiveness never, and let sheer convenience carry the arrangement past the point where anyone could reasonably object.

When I look at any technology, the questions I come back to are simple. Who takes? Who pays? Who fights back? Here the ones taking are the operators — agencies and vendors who gain a powerful new capability. The ones paying are ordinary members of the public, who surrender a piece of their anonymity every time they pass a lens, usually without knowing it. And the ones positioned to fight back are, structurally, the weakest in the exchange: you cannot contest a system you were never told about, using rights that were never explained, against errors you may never learn were made about you.

The specific risks, stated plainly

It is worth being concrete about what can go wrong, because vague unease is easy to wave away.

Identification and tracking at a distance. Unlike a fingerprint or a password, your face can be read without your cooperation, from across a street, by a camera you never approach. Link enough cameras and you can follow a person's movements through a city over time — not because anyone decided to build a tracking system, but because the pieces, once deployed, quietly compose into one. That capability exists whether or not it is fully used today.

Uneven error rates. Face-matching is not equally accurate for everyone. A large body of research, in many countries, has found that error rates can differ across skin tone, gender, and age — meaning some groups are more likely to be falsely matched than others. In a policing context a false match is not an abstract statistic; it is a real person flagged, questioned, or worse, on the strength of a machine's mistake. When the burden falls hardest on those already most exposed to scrutiny, the technology does not just reflect existing inequities, it mechanises them.

The loss of ordinary anonymity. There is a kind of freedom in being unremarkable in public — able to attend a gathering, visit a clinic, walk a route, without any of it logged against your name. Pervasive face recognition erodes that quietly. You need not be doing anything wrong to lose something real when every public appearance becomes, in principle, an identifiable and recordable event. A society in which people assume they are being recognised behaves more cautiously than one in which they are not — and that chilling effect is a cost even if no database is ever misused.

Function creep. This is the one I would underline hardest. A system introduced for one narrow, sympathetic purpose — finding missing children, smoothing airport queues — rarely stays confined to it. The infrastructure, once built and paid for, becomes a standing temptation to reach for in the next situation, and the next. Cameras installed for traffic get repurposed for crowd identification; verification built for one benefit gets extended to another. Nobody has to decide to build a surveillance state; you can arrive at one incrementally, each expansion small and reasonable, precisely because the capability was already sitting there.

What accountability could look like

None of this argues for banning the technology outright. The useful question is not whether facial recognition should exist but on what terms — and right now the terms are being set by default rather than by decision. A few things would change that.

Transparency, first. You cannot consent to, or contest, what you do not know exists. At a minimum, people should be able to find out where facial recognition is deployed, who operates it, what it is used for, and against which databases faces are matched. A public register of systems, clear signage where cameras run face-matching, and honest disclosure of error rates would move this out of the shadows. Secrecy is not a neutral default; it is what makes consent by silence possible in the first place.

Limits, second. A serious framework would draw lines rather than treat every deployment as equivalent. There is a real difference between one-to-one verification you actively initiate and continuous one-to-many scanning of everyone in a public space. Purpose limitation — a rule that a face captured for one reason cannot simply be reused for another — is the specific antidote to function creep, and it needs teeth, not just guidance.

Oversight, third. Powerful capabilities need someone independent watching how they are used — with authority to audit systems, test them for accuracy and bias, and halt deployments that fail. Self-certification by the same body that wants to run the system is not oversight. This is where a general data-protection regime needs supplementing by something specific to the technology, with genuine independence and the power to say no.

A society that recognises every face by default, and asks permission from none, has made a decision about itself — it should at least make that decision on purpose.

Redress, last and most important. If a system gets you wrong, there has to be a way to find out, to challenge it, and to be made whole. The right to know a decision was made about you by a face-matching system, to see the basis for it, and to appeal it, is what turns an abstract protection into a real one. Without redress, every other safeguard is just a promise.

The choice we are making by not choosing

What unsettles me about facial recognition in India is not any single deployment. It is the absence of a moment of decision. We are building something consequential — a standing capacity to identify and track people across the ordinary spaces of their lives — in the passive voice, through procurement orders and pilot programmes and convenience upgrades, none of which ever surfaced as the civic question it actually is.

The technology is not the villain. The default is. A capability adopted by silence, governed by a patchwork, and expanded by function creep will keep growing in the direction of least resistance unless someone chooses otherwise. Choosing otherwise does not mean rejecting the tool. It means insisting that a society reaching for something this powerful do so deliberately, in the open, with transparency, limits, oversight and redress from the start — and with real consent, the kind you can actually give and actually refuse, rather than the kind assumed from your silence. We can still make that choice. But the window in which it stays a choice, rather than a fact we inherited, is narrower than it looks.

Kenney Jacob is the author of Captured, a history of who takes, who pays, and who fights back.

Frequently asked questions

Where is facial recognition used in India?

It has spread across airports and travel (through digital boarding programmes), policing and public-space cameras, some welfare and attendance systems, and a range of commercial uses. Deployment has been piecemeal and fast, often without a specific public debate.

Is facial recognition legal in India?

There is no dedicated facial-recognition law, so uses are governed by a patchwork of general rules and the emerging data-protection framework. Critics argue this leaves powerful surveillance running ahead of clear limits, oversight or redress.

Why is facial recognition a privacy concern?

Because it enables identification and tracking at a distance, without consent or awareness, and errors fall unevenly across groups. Once cameras and databases are linked, ordinary anonymity in public space quietly disappears — a large change made with little explicit agreement.

← All articles