The use of Artificial Intelligence in India is growing, as is its potential to generate assessments related to identity, risk, credibility, eligibility, and reputation from data that is often under-utilized. This poses a significant challenge to privacy in India as current privacy laws in India address primarily data collection and processing. Consequential harm is primarily caused by automated systems that generate assessments and synthesize data. This paper considers whether the privacy provisions in the Indian Constitution, surveillance laws, the responsibilities of intermediaries and the Digital Personal data Protection Act, 2023 address these issues. This study employs a doctrinal approach. It examines existing provisions in the Constitution, the Public Interest Litigation and Landmark judgments, existing Statutes, Executive Orders, and select literature related to profiling, model inversion, membership inference, and generative systems. The study found that the protection of proportionality under Article 21 of the Constitution of India addresses these issues and the other provisions of the Act would provide limited rights to contest the inferred data. Indian privacy laws provide insufficient protection against automated decision-making, and fragmented measures against deepfakes and model leakage. The paper further suggests that privacy-inferenced data should be subjected to constraint of purpose, audit, and review.
Keywords
Artificial Intelligence, Digital Personal Data Protection Act, Deepfakes, Indian Telegraph Act, Right To Privacy, Inference Infrastructure