The Promise of a Seamless Journey
The modern Indian airport experience is increasingly frictionless. Thanks to the widespread adoption of facial recognition technology (FRT) under the DigiYatra initiative, passengers can move from the entrance to the boarding gate with remarkable speed.
The process is undeniably convenient. By linking your identity documents and boarding pass to a biometric profile on your phone, you can bypass long queues and repeated manual checks. This system, now active in dozens of Indian airports, promises not just speed but also enhanced security and reduced operational costs for airports. For the weary traveller, the appeal is obvious: less time in line means a less stressful journey. But this digital transformation is built on a foundation of data—your personal, sensitive data.
What Data Are You Actually Sharing?
When you enrol in a service like DigiYatra, you are providing more than just a selfie. You are sharing personally identifiable information (PII) which may include your Aadhaar details, phone number, and flight PNR, all linked to a biometric map of your face. According to the DigiYatra Foundation, this data is encrypted and stored on your own device, not in a central database. When you travel, a temporary token is created and shared with the airport's system, which is then supposed to be deleted within 24 hours of your flight's departure. While this design is architecturally more privacy-conscious than many international systems, questions remain. The ecosystem involves multiple players: the DigiYatra Foundation, airport operators, airlines, and technology vendors, all falling under the purview of India’s Digital Personal Data Protection (DPDP) Act.
The 24-Hour Deletion Promise Is Not Enough
The core promise to purge data within 24 hours is a crucial safeguard. However, policy experts and privacy advocates have pointed out ambiguities. While the facial biometric data used for a specific journey is slated for deletion, the rules are less clear about other information collected or data that might be stored in different registries. Furthermore, the system relies on trust that every single airport partner is correctly and consistently enforcing this deletion protocol without fail. Without regular and transparent independent audits, this remains a promise, not a guarantee. This ambiguity creates a significant loophole in a system that processes the data of millions of passengers.
The Risk of 'Function Creep'
The biggest danger with creating large, interconnected data systems is 'function creep'—when data collected for one purpose is later used for another. Concerns have been raised about the potential for airport facial recognition data to be integrated into wider government surveillance networks, a step that would transform a convenience tool into a mass monitoring system. While the government has denied using DigiYatra data for purposes like tax enforcement, the technological capability remains. The DPDP Act, 2023, is India's primary legal framework for data protection, but its exemptions for state security and law enforcement are broad. This leaves the door open for future policy changes that could erode the privacy assurances given today.
Stronger Rules for a System We Can Trust
Convenience and privacy should not be a zero-sum game. To build genuine trust, the current framework needs to be strengthened with explicit, legally binding rules. First, data deletion must be comprehensive and auditable, covering all passenger information, not just the temporary biometric token. The right to erasure is a key principle of the DPDP Act. Second, the purpose for which data is collected must be strictly limited. Any sharing of data with third parties for 'value-added services' must be explicitly opt-in, not bundled into vague consent forms. Third, independent, public audits of the entire data lifecycle—from collection to deletion—are essential to verify compliance. Finally, citizens need a clear, accessible process to demand and confirm the deletion of their data from all associated systems, reinforcing their rights as 'Data Principals' under the law.
















