In India, the unfolding COVID-19 pandemic has gone through two-waves, registering over 3.1 crore cases and killing over 4.2 lakh people.[i] It has collapsed the economy and overburdened the healthcare system. In an effort to contain the volume and pace of transmission, the Government of India launched its contact-tracing application, Aarogya Setu, on 2nd April, 2020.  However, unlike its global contemporaries, this App additionally serves as an informational tool, self-assessment tool, and situational awareness tool.[ii] These manifold purposes alter the type and manner of data collection, thereby raising privacy concerns. These concerns are particularly important during a pandemic, where urgency may confer wide administrative discretion, leading to mass surveillance or usage of collected data beyond this pandemic. This discussion is particularly important since, in  a year of its release, it has become the world’s most downloaded contact-tracing app, and generated significant controversy.[iii]

Currently, there is no statute that deals with state liability for privacy infringement. But in KS Puttaswamy v. Union of India [“Puttaswamy”],[iv] the Supreme Court [“SC”] recognized the right to privacy as a fundamental right, enforceable against the state. It established a four-fold test for its infringement: legality, legitimate goal, proportionality, and procedural safeguards. Using this test, I will argue that while the requirements of legality and a legitimate goal have been satisfied, the privacy infringing act is disproportionate and without adequate procedural safeguards. 

Testing Features of Aarogya Setu against the Constitutional Standard

The right to privacy entitles the individual with the autonomy to make personal life decisions (positive aspect), and restrains the state from unwarranted interference (negative aspect). In Puttaswamy, the SC explicitly recognized the need to protect both these aspects, even during epidemics.[v] Thus, notwithstanding the circumstances, the features and operation of the app must be consistent with the right to privacy. Notably, the first three prongs of the above-mentioned test are necessary conditions.

  • Legality

The infringement of personal privacy by the state must be through a valid and existent law. The government has not passed any legislation or promulgated any ordinance specifically for the app. Therefore, the question is whether it has the power to do so under any existing legislations. So far, the government has invoked the Epidemic Diseases Act, 1897, and the Disaster Management Act, 2005 to justify its actions in containing COVID-19.[vi]

The 1897 Act empowers the central government to frame regulations during epidemics if the existing law is insufficient. However, this conferral is authorized in the limited context of inspecting vessels at ports, and detaining people for the same. Thus, there is no power to curtail the right to privacy under this Act.

The 2005 Act empowers the central government to take all such measures as it deems necessary or expedient for the purpose of disaster management. The term disaster, under Section 2(d), does not ordinarily extend to epidemics. However, on 14 March, the Home Affairs Ministry declared the coronavirus outbreak as a “notified disaster”, thus bringing it within the fold of Section 2(d).[vii] Therefore, releasing an app to contain COVID-19 would be within the powers of the government within the Act.

However, the sweeping powers under this Act make direct and collateral privacy breaches more susceptible. Considering this, the government must consider framing a specific law. Even the BN Srikrishna Commission had recommended the existence of a specific law. However, the government has evaded this by carving out an exception for health emergencies in Personal Data Protection Bill, 2019 [“the Bill”]. 

The need for a specific law is especially important since the rights and obligations of the parties have been defined only in the service terms and privacy policy, whose enforceability remains clouded.[viii] Subsequently, the Government issued the Aarogya Setu Data Access and Knowledge Sharing Protocol, 2020 to establish data obligations. While the Protocol certainly addressed some gaps unaddressed by the Privacy Policy,[ix] the relationship between the two is unclarified, and there are inconsistencies between them.[x] More importantly, the Protocol is in the nature of an executive order, thereby evading any necessary parliamentary scrutiny.

Unfortunately, the government has treaded in the opposite direction. They had originally declared the installation of the app to be mandatory.[xi] However, on backlash, they have obligated employers to ensure compliance on a “best efforts” basis instead.[xii] In practice, the government, and many private players due to the threat of non-compliance, have still insisted on mandatory usage of the app, without passing any specific legislation.[xiii]

  • Legitimate Goal

Any invasion of an individual’s privacy by the state must have a legitimate goal. Indeed, the collection of information to contain an epidemic would be a legitimate goal. However, there is a presumption that this goal must be precise and clearly defined.[xiv] While the privacy policy alludes to only containment as the goal, the intentions of the government are much broader. It plans to integrate telemedicine,[xv] and welfare services within the app.[xvi] Alarmingly, it has added an e-pass feature on the app, to permit limited movement during the lockdown, without mentioning this purpose or feature in its policy.[xvii] Recently, it even officially broadened the App to link the CoWIN portal to facilitate vaccine registration.[xviii]

While the government certainly has a legitimate goal, it must clarify all its intended goals for which this app will be used. These concerns are deeply-grounded given that the intended goals in the app’s privacy policy have already been amended once without the knowledge or consent of the users.[xix]

  • Proportionality

In Justice K. S. Puttaswamy v. Union of India (II),[xx] the SC held that there are three necessary conditions for a privacy restricting measure to be proportionate: firstly, it must be a suitable means of furthering the legitimate goal (rational connection stage); secondly, there must not be any less restrictive, but equally effective alternative (necessity stage); thirdly, the measure must not have a disproportionate impact on the right-holder (balancing stage).

  • Rational Connection Stage

The app collects information to trace and inform people who have crossed paths with an infected user.[xxi] Furthermore, it prepares anonymized and aggregate datasets,[xxii] such as reports or heat maps, which helps in situational awareness and performance assessment. Thus, the app is a suitable means to the goal of containing COVID-19.

While the App does have a rational connection, its efficiency is questionable. Reportedly, the App has been unable to pick up details about people on“two sides of a shopping mall or even on two sides of a wall”.[xxiii] This can be tied to the weakness of Bluetooth technology as regards contact tracing.[xxiv] Despite this lower efficiency, it is still valuable given the persistently escalating case burden in the country. This is because even limited efficiency allows substantial health-related and economic cost savings.[xxv]

  • Necessity Stage

There are three features that warrant analysis: usage of GPS, manner of Bluetooth usage, and extent of collected data.

  • Usage of GPS

To trace contact between users, the app uses both Bluetooth and GPS.[xxvi] Critics have contended that the application’s use of GPS is redundant, thus violative of proportionality.[xxvii] They argue that Bluetooth is adequate to register contact between user’s devices, as shown by Singapore’s TraceTogether.[xxviii]

While the sole usage of Bluetooth is certainly “less restrictive”, it is not an “equally effective alternative” as GPS serves the unique purpose of preparing anonymized and aggregated datasets.[xxix] These are in-turn used to guide policymaking in, inter alia, understanding hotspots and planning relaxations.[xxx] It must be remembered that while Aarogya Setu may serve as a contact-tracing application, it is not necessary for its goal to be limited to that. As argued earlier, the government’s intended goal is much broader- to contain the pandemic. Therefore, using GPS does not violate proportionality.

  • Extent of Information Collected

Apart from location, Bluetooth ID, and result of the self-assessment test, the app collects a user’s name, age, phone number, sex, profession, and countries visited in the last 30 days.[xxxi] These six pieces of information are then hashed with a unique digital ID, and uploaded on the server.[xxxii] The predominant concern has been regarding the collection of data on sex and profession. However, these concerns are unfounded since this collection serves a role in dataset analysis and policymaking. Given our limited and dynamic understanding of COVID-19, the data on sex helps understand the gendered implications of this virus, if any. The data on profession could aid in a phased-out relaxation of the lockdown.  

  • Manner of Storing Unique Digital ID Bluetooth Usage

In Aarogya Setu, the Unique Digital ID (“DID”), which contains the user’s personal information, is uploaded onto servers without any obfuscation.[xxxiii] This is a downgrade from earlier requirement of hashing such ID in static form, which itself was quite susceptible to third-party privacy breaches.[xxxiv] This is unlike TraceTogether, where the DIDs of the users are random, and changed every 15 minutes.[xxxv] This obfuscation protocol is much more effective and less restrictive in data collection and security. Therefore, the app’s manner of storing DIDs violates proportionality.

In essence, while the usage of GPS and extent of information collected are not disproportionate, the manner of storing DIDs certainly is.

  • Balancing Stage

Most alarmingly, the app has a disproportionate impact on the user. This is because of the unfair data retention, no notice of security breaches, and effectively no liability on the government. I will elaborate on each in turn.

  • Unfair Data Retention

Once the app has been uninstalled, the data is retained for another 30 days.[xxxvi] Notably, this period adds to the ordinary 45 days retention policy,[xxxvii] without any justification. Moreover, it must be noted that the app’s service terms or privacy policy do not have a sunset provision, or any clause that categorically nullify the app post the pandemic. Judging by the government’s statements,[xxxviii] it is more likely that the app will be repurposed. This concern is compounded by the fact that there are methods to de-anonymize the datasets.[xxxix] Thus, the data collected during this pandemic may be unjustifiably used for other purposes. 

  • No Notice of Security Breach

While the government has utilized the highest security standards in storage and uploading of data,[xl] the user has no right or means to know if a breach of his/her data has occurred. Obtaining knowledge of a breach is the first step for a user to mitigate the ensuing disproportionate impact. Therefore, not providing or denying access to this knowledge compounds the disproportionate impact.

  • Limited Government Liability

In the service terms, the government has waived its liability in relation to the usage of the App.[xli] Thus, even if the government unfairly/illegally discloses information or permits unauthorized access to a user’s information, the user would have no remedy. This is despite the fact that this negligence can cause grave adversities, such as discrimination or ostracization. The public declaration of name and contact details of COVID-19 patients in Ahmedabad, Karnataka, and Punjab indicate the frequency of violation of the app’s own service terms and privacy policy.[xlii]

Moreover, the IT Rules only obligate data processors to provide a privacy policy, and do not prescribe remedies for its breach.[xliii] Furthermore, even the remedy of compensation under the S. 43A of the Information Technology Act, 2000 exempts the state. However, through subsequent amendments to the Privacy Policy, the Government amended paragraph 6 of Terms of Services (3.0) to only limit government liability over accuracy of identification and notification. Thus, it may be argued that unauthorized usage is remediable as a contractual violation in court. The only other remedy the user has is to rescind the contract by uninstalling the app. These are discernibly disproportionate to the loss he/she can potentially suffer.

  • Concerns with the anonymization of and access to collected data

In de-identified form, the collected can be shared with ministries/departments at any level or disaster management authorities or public health institutions so long as it for formulation/implementation of critical health response.[xliv] NIC is required to document the agencies/persons, time, and categories of data shared.[xlv] However, this is only ‘to the extent reasonable’,[xlvi] thus providing a scope for evasion of this obligation. These concerns are well-founded given instances like the Jammu & Kashmir administration sharing such data with law enforcement agencies.[xlvii]

While the Protocol establishes an obligation to anonymize the data, it has so far merely formed a committee to establish these anonymization protocols,[xlviii] without anything actually being done. The continued usage of appropriate anonymization protocols is important since the App has the potential to create a social graph of users by tracking their contact.[xlix] When combined with the government’s existing database, this significantly expands their surveillance powers.

  • Procedural Safeguards

Notably, this prong is not binding in law. Nevertheless, it is persuasive as it provides a normative lens to view state interference in personal privacy. Furthermore, Justice Kaul had proposed this prong to only echo the central requirement under Article 21 of checking abuse of state interference through a “procedure established by law”.[l] However, in a technological paradigm, mere assurances in law against state abuse are inadequate.

To its credit, the government had addressed a bulk of the first stream of privacy concerns by updating its privacy policy. However, contrary to the app’s own privacy policy, a notice of this change was not issued, and revised consent was not sought.[li] While, in theory, this amendment addresses and clarifies concerns such as weak security and extremely broad purposes, it does not provide users with the practical means to verify the same. Currently, there are no means of transparently auditing the app because it is not open source in any meaningful sense for two reasons.[lii] Firstly, the code repository remains stagnated since its release, with a huge backlog of queries and flagged issues. Secondly, the server-side code has not been released. Given that most of AS’ important functions are stored and performed on the server, not the device, little can be gathered without the server-side code.

The government’s failure to provide information about the process of creation of the App only adds to the existing skepticism over inadequate safeguards.[liii] This has been compounded by their evasion of RTI questions regarding the App,[liv] and their refusal to the let the concerned RTI activist attend the show cause hearing.[lv] The Delhi High Court had to intervene to issue a notice to the Public Information Officers of several ministries, who later apologized.[lvi]  Thus, the user has to blindly rely on the good conscience of government officials to adhere to its own policy. However, recent events where the government has violated its own privacy policy justifies skepticism towards the absence of external accountability.[lvii] To ensure greater transparency and accountability, the government must open the source-code or even hire independent third-party auditors.

Conclusion and Way Forward

The app and its features infringe the fundamental right to privacy, as they fail to satisfy the necessary and balancing condition of proportionality. Although there is legality to the app, the government must consider enacting a specific law to address the large scale impact and legal ramifications. The government’s legitimate goal, though presently valid, is unclear due to undefined features on the app and several future plans. Most importantly, the infringing action violates proportionality as it is not the least restrictive means, and has a disproportionate impact on the user. Thus, the app’s features must be amended to meet global standards. Lastly, the government must make appropriate amendments to the source code for greater transparency.

*Ankit Kapoor is a third-year BA-LLB (Hons.) student at the National Law School of India University, Bangalore.

