scorecardresearch
Add as a preferred source on Google
Friday, October 9, 2026

Support our Journalism

Depth, context and analysis

Subscribe
HomeOpinionIndia’s criminal codes say nothing about facial recognition tools. 3 amendments can...

India’s criminal codes say nothing about facial recognition tools. 3 amendments can fix this

The law does not say whether a facial recognition match counts as credible information. An officer who acts on one is working in a gap.

Follow Us :
Text Size:

The Delhi Police used facial recognition at the Jantar Mantar protests in July and told the Supreme Court in August that the system had identified 2,873 people with criminal records in the crowd. ThePrint then reported, citing police sources and prison records, that 22 of those people were lodged in prison while the protest was on. Some may have been out on parole or furlough, the sources said, so the figure needs checking.

The episode points to a gap in the law. India’s three new criminal codes rest on a simple idea: record how evidence was gathered before anyone trusts it. Yet the same codes say nothing about the software that now helps police decide whom to look for. This piece walks through that gap and suggests three amendments to close it.

The codes ask for proof

The Bharatiya Nagarik Suraksha Sanhita (BNSS) requires police to video-record every search and seizure and send the recording to a magistrate (Sec 105). In serious cases, a forensic expert must visit the crime scene, and that visit must be filmed too (Sec 176(3)). The Bharatiya Nyaya Sanhita (BNS) already treats electronic records as documents (Sec 2(8)).

The Bharatiya Sakshya Adhiniyam (BSA) decides what courts accept as evidence. For an electronic record, Sec 63(4) requires a certificate. The person producing the record fills in Part A. An expert signs Part B, which includes the file’s hash value. A hash value is a digital fingerprint: change a single pixel in a video and the fingerprint changes. In May, the Supreme Court declined to disturb this scheme in Pune Bar Association v. Union of India. It noted that artificial intelligence and deepfakes have sharpened the challenge of proving that a record is genuine.

This regime protects the police as much as the accused, because an officer who can show where a record came from has won half the argument before the trial begins.

The Identification Act says nothing about faces

Facial recognition needs a database of faces. The Criminal Procedure (Identification) Act, 2022 lets police build one. It allows them to take “measurements” from convicts and from anyone arrested in connection with an offence. The list of measurements includes photographs and iris scans (Sec 2(1)(b)). It never mentions facial recognition.

The Act also tells the National Crime Records Bureau (NCRB) to “process” these records alongside crime records and to share them with any law enforcement agency (Sec 4(1)). If facial recognition has a legal home, it sits inside that one undefined word. The rules the government can make under Sec 8 say nothing about how close a match must be, how the software is tested, whether searches are recorded or what happens to faces that do not match. Each force, therefore, writes its own answers. And because the Act covers anyone arrested, the database can include people who were accused and never convicted.

How a match enters an investigation

Sec 35 of the BNSS lets an officer arrest without a warrant on credible information or reasonable suspicion that someone has committed a cognisable offence. The law does not say whether a face match counts as credible information. An officer who acts on one is working in a gap.

RTI replies in 2022 showed that Delhi Police treats a match above 80 per cent similarity as positive and looks for corroboration when the score is lower. Solicitor General Tushar Mehta told the Supreme Court in August that no action automatically follows a match. These are sound instincts, but they live in affidavits and RTI replies. The force has never published how often its system errs at that cutoff, and a similarity score of 80 does not answer the question.

Prediction tools raise the same problem. Sec 170 allows preventive arrest when an officer knows of a design to commit a cognizable offence. A forecast that crime is likely on a certain street gives the officer no such knowledge about any person.

The gap also hurts investigators once a case reaches court. Sec 230 entitles the accused to the police report and the documents sent up with it. If a software lead first pointed police to him, that lead is a document nobody relies on, so it never reaches him and surfaces for the first time in cross-examination. A constable who searches a house must film it, and that footage protects him. A database search deserves the same protection.

The certificate misses the machine

Sec 63 is the last point at which the system could catch an algorithm’s mistake, and the algorithm slips through twice.

The first is timing. A certificate is needed only when someone offers an electronic record to the court. A face match is a lead. It sends officers to a door, and the trial then rests on footage or a witness. Nobody offers the match itself, so nobody certifies it. That arrangement lasts until a defence lawyer asks how the police came to that door.

The second reason goes deeper. The certificate tells the court that the device worked properly and that the file has not changed since it was captured. It says nothing about whether a conclusion drawn from the file is correct. If software matches a blurry frame to the wrong face, the hash will be intact and the paperwork will certify the error faithfully. The expert’s signature does not fix this. Sec 39(2) lets an examiner of electronic evidence say whether a file is genuine. Whether a face-matching programme works on a grainy night-time frame is a scientific question under Sec 39(1), and no provision requires anyone to answer it.

The law asks for a fingerprint on the video and nothing from the programme that reads the face in it.


Also read: After 17 yrs of struggle, court battles, CAPF officers still fighting for their rightful dues


Three amendments

Police have a serious case for these tools, which can find one suspect in hours of footage. The amendments below protect that work by turning assurances the police have already given the Supreme Court into law.

The Identification Act should gain a new Sec 4A. It would allow automated face-matching only through notified agencies and require every search to be logged with the image used, the database searched, the software version, the match threshold, and the score. An independent laboratory would test error rates at the threshold in use and publish them before deployment. Faces that do not match would be deleted at once.

For the BNSS, an explanation to Sec 35(1) and a proviso to Sec 170 should say that an automated output on its own cannot supply the credible information or reasonable suspicion that Sec 35 requires, or the knowledge of a design that Sec 170 requires. Sec 230 should also entitle the accused to every automated output that led the police to him, whether or not the prosecution relies on it.

The third change goes into the BSA. Sec 63(4) should add a Part C to the Schedule for any record that rests on algorithmic output used to identify a person. Part C would name the system and version, state the threshold and score, describe the database, and attach tested error rates. An expert qualified under Sec 39(1) in biometric evaluation would sign it. A prosecution that arrives with Part C loses nothing at trial and gains an identification a court can trust.

Courts distrust a witness who cannot be cross-examined. The algorithm testifies through whichever officer relays it, and that officer must answer for a model he did not build. The codes taught the police to write everything down. The next amendment should let them record what the machine said and how sure it was.

Pranav Jain is an IPS (P) officer and a columnist. Views are personal.

(Edited by Aamaan Alam Khan)

Subscribe to our channels on YouTube, Telegram & WhatsApp

Nine Years, Made Possible by Readers

In 2017, Shekhar Gupta started ThePrint with a simple belief: Indian readers want journalism that asks why and what next, not just what. And that enough of them would be willing to pay for good journalism.

Nine years on, that belief has held.

And, in these nine years, we’ve stayed true to our mission. We’ve been asking the follow-up questions, going beyond the headlines and explaining what’s actually happening. We’ve travelled across the country to bring you in-depth, visually-compelling stories from the ground.

It’s been nine years of readers choosing to make this possible. If you’d like to be one of them:

Support ThePrint

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular