Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, decided unanimously by a 9-judge Constitution Bench on 24 August 2017, holds that the right to privacy is a constitutionally protected fundamental right intrinsic to Article 21, flowing also from Articles 14 and 19. For practitioners, the case establishes three operative tools: (1) a constitutional foundation for privacy claims across bodily autonomy, informational privacy, and decisional autonomy (the three recognised dimensions); (2) a structured four-limb proportionality test that every State restriction must satisfy — legality, legitimate aim, necessity, and proportionality stricto sensu; and (3) the overruling of M.P. Sharma v. Satish Chandra, AIR 1954 SC 300 (8-judge bench) and Kharak Singh v. State of U.P., AIR 1963 SC 1295 (6-judge bench) on the narrow reading of privacy. Puttaswamy is the controlling authority for every challenge involving surveillance, data collection, biometric identification, sexual autonomy, reproductive choice, end-of-life care, and financial privacy. Since 2017 it has been cited in over 500 reported judgments across the Supreme Court and High Courts and forms the doctrinal backbone of the Digital Personal Data Protection Act, 2023.
Case snapshot
| Field | Details |
|---|---|
| Case name | Justice K.S. Puttaswamy (Retd.) and Another v. Union of India and Others |
| Citation | (2017) 10 SCC 1; AIR 2017 SC 4161 |
| Court | Supreme Court of India |
| Bench | 9-judge Constitution Bench (unanimous); six separate opinions — plurality by Chandrachud J. for four judges |
| Date of judgment | 24 August 2017 |
| Ratio decidendi | Privacy is a fundamental right intrinsic to Article 21, also emanating from Articles 14 and 19; State restrictions must satisfy a four-limb proportionality test |
Ratio decidendi and statutory analysis
Privacy as a fundamental right rooted in Article 21. All nine judges agreed that privacy is constitutionally protected. The primary locus is Article 21 (life and personal liberty), supplemented by Article 14 (non-arbitrariness) and the specific freedoms in Article 19. The Court rejected the narrow textual approach of Kharak Singh and emphasised that privacy inheres in human dignity — the animating value of Part III — and therefore cannot be read out of Article 21.
Three operational dimensions of privacy. The Court recognised: (a) bodily privacy — control over one's physical person, including medical procedures, reproductive choices, and bodily integrity; (b) informational privacy — control over the collection, storage, use, and dissemination of personal data; and (c) decisional privacy — the right to make intimate choices regarding family, relationships, sexual orientation, religion, and personal beliefs. Practitioners should identify the specific dimension in pleadings; the evidentiary and doctrinal requirements differ across the three.
Four-limb proportionality test. A State action restricting privacy must satisfy: (i) legality — the restriction must be prescribed by a law, not mere executive instruction; (ii) legitimate aim — the law must pursue a purpose permissible in a democratic society; (iii) necessity — the restriction must be necessary, with no less restrictive alternative reasonably available; and (iv) proportionality stricto sensu — the benefits of the restriction must outweigh the harm to the right. Each limb must be independently satisfied.
Privacy binds the State, but positive obligations arise. The Court noted that Article 21 operates vertically (against the State) but acknowledged that the State has a positive obligation to enact a data protection framework to regulate private actors. This formed the doctrinal impetus for the Digital Personal Data Protection Act, 2023.
M.P. Sharma and Kharak Singh overruled. The Court expressly overruled (a) the observations in M.P. Sharma v. Satish Chandra that the Indian Constitution does not recognise a right to privacy analogous to the US Fourth Amendment, and (b) the majority in Kharak Singh v. State of U.P. to the extent it held privacy was not a fundamental right. Justice Subba Rao's dissent in Kharak Singh was affirmed.
Current statutory framework
Digital Personal Data Protection Act, 2023 (DPDP Act): The Act, notified in August 2023, is the operational implementation of the informational privacy dimension recognised in Puttaswamy. It creates obligations on data fiduciaries, rights for data principals (including the right to access, correction, erasure, and grievance redressal), and establishes the Data Protection Board of India. Counsel advising on data compliance must now anchor privacy compliance in DPDP Act obligations while treating Puttaswamy as the constitutional backstop.
Information Technology Act, 2000: Section 43A (compensation for failure to protect sensitive personal data) and Section 72A (punishment for disclosure of information in breach of lawful contract) continue to operate alongside the DPDP Act. Section 69 (interception/monitoring) must be read through the Puttaswamy proportionality lens.
Indian Telegraph Act, 1885: Section 5(2) (interception of messages) remains the primary statutory authority for telephone tapping. Interception orders issued under this provision must satisfy both the PUCL (1997) procedural safeguards and the Puttaswamy proportionality test.
Aadhaar framework: The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 was partially upheld in K.S. Puttaswamy (Aadhaar) v. Union of India (2019) 1 SCC 1, which applied the proportionality test. Mandatory Aadhaar linkage for bank accounts and mobile numbers was struck down; linkage for PAN and subsidies was upheld.
Sector-specific frameworks: Health data (Clinical Establishments Act, 2010 and rules thereunder), financial data (RBI circulars on KYC and data localisation), and telecommunications metadata all now operate under the shadow of Puttaswamy proportionality.
Key subsequent developments
Navtej Singh Johar v. Union of India (2018) 10 SCC 1 — Relied on decisional privacy and dignity to decriminalise consensual adult same-sex relations by reading down Section 377 of the Indian Penal Code, 1860.
Joseph Shine v. Union of India (2019) 3 SCC 39 — Invoked decisional privacy to strike down Section 497 of the Indian Penal Code, 1860 (adultery) as violating Articles 14, 15, and 21.
K.S. Puttaswamy (Aadhaar) v. Union of India (2019) 1 SCC 1 — 5-judge Bench applied the proportionality test to the Aadhaar Act; upheld the architecture with carve-outs (mandatory linkage for bank accounts and mobile numbers struck down).
Anuradha Bhasin v. Union of India (2020) 3 SCC 637 — Applied proportionality to internet shutdown orders in Jammu and Kashmir; required publication of orders and periodic review.
Manohar Lal Sharma v. Union of India (Pegasus case) (2022) 3 SCC 796 — Court-appointed committee to examine alleged use of Pegasus spyware; Court reaffirmed that mass surveillance would face stringent proportionality scrutiny.
Supriyo @ Supriya Chakraborty v. Union of India (2023) 14 SCR 1 — Though declining to recognise same-sex marriage, the Court reaffirmed Puttaswamy's decisional privacy dimension.
X v. Principal Secretary, Health and Family Welfare Department, NCT of Delhi (2023) 9 SCC 433 — Extended bodily autonomy and reproductive privacy under Puttaswamy to uphold a 24-week-pregnant unmarried woman's right to medical termination.
Practice implications
Advising on data protection compliance: For corporate clients, compliance now runs on two layers. The statutory layer is the DPDP Act, 2023 — which mandates consent, purpose limitation, data minimisation, security safeguards, and breach notification. The constitutional layer is Puttaswamy, which operates whenever State action (including State-mandated data-sharing obligations) intersects with a client's data handling. Corporate privacy policies, data processing agreements, and cross-border transfer documentation should now reference both layers.
Challenging surveillance or data collection orders: The petition must attack on all four proportionality limbs. At the legality limb, identify the exact statutory provision authorising the action; executive circulars or office memoranda are insufficient. At the necessity limb, argue that less intrusive alternatives (targeted rather than bulk collection, narrower data fields, shorter retention) were available. Evidentiary disclosure applications seeking the underlying authorisation, scope, and retention parameters of the State action are critical; courts have increasingly directed such disclosures post-Puttaswamy.
Defending State action against privacy challenges: The State should lead with the legitimate aim (national security, welfare delivery, tax administration, public health) and structure the record to show necessity — document the less restrictive alternatives considered and rejected with reasons. The Aadhaar judgment shows that well-documented necessity analysis survives; the Pegasus litigation shows that mere security invocations without record evidence do not.
Bodily and decisional privacy claims: For litigation involving reproductive choice, medical autonomy, sexual orientation, gender identity, and end-of-life care, Puttaswamy supplies the direct constitutional foundation. Cite the relevant dimension — bodily for reproductive/medical, decisional for identity/intimate choices — and frame State interference as failing the necessity limb. Courts have applied a heightened scrutiny in this category, closer to strict necessity than deferential review.
Financial and tax privacy: The proportionality test now applies to tax investigations, financial intelligence-sharing, and KYC data pooling. While courts have been relatively deferential on tax enforcement (K.S. Puttaswamy (Aadhaar) upheld PAN-Aadhaar linkage), disproportionate or indefinite data retention faces challenges. Advising clients on responses to investigation notices should incorporate privacy objections where the scope appears overbroad.
Tactical considerations: Privacy challenges to large-scale State frameworks (CCTV policies, database consolidations, welfare ID schemes) are typically filed in the Supreme Court under Article 32, given the pan-India implication. Individual surveillance or data misuse claims can be pursued under Article 226 in the appropriate High Court. Interim relief requires a clear proportionality imbalance — courts are reluctant to stay operational State systems absent demonstrated irreparable harm.
Frequently asked questions
What is the proportionality test a State must satisfy to restrict privacy after Puttaswamy?
The four-part test is: (i) the restriction must be backed by a law — express statutory authority is required; (ii) the law must serve a legitimate State aim; (iii) the restriction must be necessary — there must be no less restrictive alternative reasonably available; and (iv) the restriction must be proportionate stricto sensu — benefits must outweigh the harm to the right. All four limbs must be satisfied; failure on any one invalidates the restriction. See (2017) 10 SCC 1 at para 325 (Chandrachud J.) and the Aadhaar judgment (2019) 1 SCC 1.
Can a private entity violate the right to privacy under Puttaswamy?
Article 21 binds the State, not private entities. However, Puttaswamy acknowledged that the State has a positive obligation to enact a data protection framework regulating private actors. That obligation is now substantially met by the Digital Personal Data Protection Act, 2023. Actions by private entities are actionable under that Act, Section 43A of the Information Technology Act, 2000, and tortious privacy doctrines, rather than directly under Article 21.
How should a writ petition invoking privacy be framed after Puttaswamy?
Plead: (a) the specific dimension of privacy engaged — bodily, informational, or decisional; (b) the State action or inaction that allegedly infringes it; (c) detailed application of the four-limb proportionality test with record evidence on necessity and less restrictive alternatives. Generic privacy pleadings without a dimension and a proportionality analysis are insufficient under the post-Puttaswamy framework.
Does Puttaswamy apply to surveillance and interception orders?
Yes. Surveillance orders under Section 5 of the Indian Telegraph Act, 1885 and Section 69 of the Information Technology Act, 2000 must satisfy the proportionality test. The PUCL v. Union of India (1997) 1 SCC 301 safeguards remain the procedural baseline, but the substantive constitutional test is now Puttaswamy proportionality. See Manohar Lal Sharma v. Union of India (Pegasus case) (2022) 3 SCC 796 for application to mass surveillance.
Does Puttaswamy protect the right against self-incrimination in the digital age?
Puttaswamy's informational privacy dimension supports arguments against compelled decryption, biometric unlocking of devices, and access to password-protected data. Article 20(3) remains the primary textual protection, but Puttaswamy supplements it by recognising the constitutional stakes of compelled disclosure of digital information. The interaction of Article 20(3) and Puttaswamy in the context of encryption keys is a live area of litigation.
Source attribution
Primary source: Supreme Court of India — judgment in Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1. This analysis is provided for informational purposes and does not constitute legal advice. Given the rapidly evolving interaction between Puttaswamy and the Digital Personal Data Protection Act, 2023, practitioners should consult current statutory text and recent case law before advising clients.