Complete Guide to Fingerprinting in India
Guide

Complete Guide to Fingerprinting in India

Chapters
The History of Fingerprinting in IndiaWhat Is NAFIS? India's National Automated Fingerprint SystemFingerprinting Laws in India: Collection, Storage, and UseTypes of Fingerprinting in IndiaWhat Is a Fingerprint Card? Types, Uses, and How Prints Are ClassifiedHow Fingerprinting Works for Aadhaar and Passport in IndiaFingerprinting in India for Visa and Immigration ProcessFingerprinting for Indian Police Clearance CertificatesFingerprinting in India for International Background ChecksFingerprinting for Administrative Purposes in IndiaApostille, Attestation & Translation of Documents in IndiaCommon Reasons for Fingerprint Rejection in India and How to Prevent ThemHow To Choose The Right Fingerprinting Service in India
HomeGuidesComplete Guide to Fingerprinting in IndiaFingerprinting Laws in India: Collection, Storage, and Use
Chapters

Fingerprinting Laws in India: Collection, Storage, and Use

Fingerprints are one of the oldest tools in criminal investigation, but their role in India today has grown to much more than that. They are now used for Aadhaar enrollment, employee attendance systems, background checks, professional licensing, and many other identity verification processes.

As fingerprint collection has grown more widespread, so have debates around privacy and individual rights. A fundamental question has been repeatedly raised by citizens, civil society groups, and the judiciary alike: does compulsory fingerprinting violate the right to privacy? The Aadhaar biometric enrollment program became the most visible point for this debate.

In response, India has built a layered legal framework governing every stage of the fingerprinting process: who can collect prints, under what authority, how long they can be stored, when they are admissible in court, and what rights individuals retain over their own biometric identity.

Constitutional Foundations

Protection Against Self-Incrimination (Article 20(3))

Per this article of the Indian Constitution, people cannot be forced to testify against themselves in criminal cases. But courts have clarified that providing fingerprints does not count as self-incrimination. This is because fingerprints are physical identifiers, not statements or personal testimony. As a result, law enforcement agencies can legally collect fingerprints when required by the law.

Right to Privacy (Article 21)

The right to privacy is a fundamental right in India. Since fingerprints are personal biometric data, authorities must ensure that their collection and storage follows legal procedures, and that their use is reasonable and proportionate to the purpose for which it is collected.

Fingerprint Collection Under the Criminal Procedure (Identification) Act, 2022

The CPI Act, 2022, is the primary law governing the collection of fingerprints and other biometric information in India. It replaced the older Identification of Prisoners Act, 1920, and expanded the government's authority to collect and store biometric data.

  • Broader Definition of Biometric Data The Act allows authorities to collect fingerprints, palm prints, footprints, photographs, iris and retina scans, signatures, handwriting samples, and certain biological samples.
  • Collection Without Consent For specified offences, authorities can collect fingerprints and other measurements even if the individual does not consent.
  • Long-Term Data Storage The collected records can be stored in digital databases for up to 75 years.
  • Record Deletion in Eligible Cases Individuals who are released without trial, discharged, or acquitted may request the deletion of their records, subject to the conditions prescribed under the law.

Fingerprint Evidence in Indian Courts - BSA, 2023

The Bharatiya Sakshya Adhiniyam, 2023, which replaced the Indian Evidence Act, sets out the rules for how fingerprint evidence can be used in Indian courts. There are two main requirements that allow fingerprints to be accepted as evidence:

Expert Verification

Fingerprint matches are not automatically treated as proof in court. A qualified fingerprint expert must examine and compare the prints and provide an opinion on whether they belong to the same person. The court can consider this expert opinion as valid evidence when deciding a case.

Authentication of Digital Records

Today, most fingerprint records are stored and analyzed digitally through systems such as NAFIS. Because these records are electronic, courts require proof that the data is genuine and has not been altered. For this, authorities have to provide a certificate confirming that the system was functioning properly and that the electronic records are authentic and reliable.

Collecting and Handling Fingerprint Evidence - BNSS, 2023

The Bharatiya Nagarik Suraksha Sanhita, 2023, which replaced the Criminal Procedure Code (CrPC), lays down the procedures that investigating authorities must follow while collecting and handling fingerprints as evidence.

While the CPI Act, 2022 gives authorities the power to collect fingerprints, the BNSS governs how that process must be carried out during an investigation. It lays down the legal procedures for collecting, documenting, and preserving fingerprint evidence. The law also helps ensure that fingerprint records are properly handled from the time they are collected until they are presented in court.

Protecting Fingerprint Data Under the IT Act, 2000

Under India's IT Rules, biometric information, including fingerprints, is classified as sensitive personal data or information. This means that the organizations and authorities collecting or storing fingerprint data are expected to handle it with a higher level of care and security than ordinary personal information. And since fingerprint records are increasingly being stored and processed through digital systems now, protecting this information from unauthorized access becomes much more important. The Information Technology Act, 2000, contains provisions that address unauthorized access, data breaches, hacking, and misuse of electronic records.

Biometric Privacy Under the Aadhaar Act, 2016

The Section 29 of the Aadhaar Act, 2016 contains strict rules to protect the privacy and security of biometric information collected for Aadhaar enrolment and authentication. Given below are some of the rules laid down under this section:

  • Your core biometric information, such as fingerprints and iris scans, cannot be downloaded or transferred to third parties. Not even with consent.
  • No identity information collected during authentication can be publicly displayed. This is why government departments are legally barred from publishing lists containing full Aadhaar numbers on their websites. Only masked versions (like, xxxx-xxxx-2236) are permitted for public records.
  • Any entity that receives your identity information, like a bank or a telecom provider during KYC, is strictly prohibited from sharing it with anyone else or using it for any purpose beyond what was originally specified.

Right to Alternative Biometrics When Fingerprints Fail

Fingerprint scanning does not always work. Sometimes factors such as old age, worn fingerprints, some skin conditions, injuries, or medical conditions can make fingerprints difficult or impossible to capture. To address this issue, UIDAI regulations require authentication agencies to use alternative biometric methods when fingerprints cannot be read. You cannot be denied a license or service solely because your fingerprints are unreadable. Indian authorities are legally obligated to offer iris and face scanning or OTP authentication as a backup.

Fingerprinting in the Private Sector - DPDP Act, 2023

Many private organizations are increasingly using fingerprint-based systems for employee attendance, access control, identity verification, and security. The Digital Personal Data Protection Act, 2023 includes rules for how such biometric data must be handled.

  • Consent Is Non-Negotiable Fingerprints are classified as sensitive biometric data. Their processing requires explicit, informed, and withdrawable consent.
  • Valid Purpose Companies cannot collect fingerprints "just because." They must prove a specific purpose, such as workplace security, access to a meeting room or halls, or identity verification.
  • Prior Notice Before scanning a finger, the companies are required to provide a notice in clear language, explaining what data is collected and why.
  • Protection of Biometric Data Employers must use biometric templates to ensure raw fingerprint images are never stored, only encrypted mathematical hashes.
  • Deletion Upon Request or Exit The company needs to have a policy allowing employees to request the deletion of their biometric data.
In This Chapter
Share This Guide
Share This Guide
Share This Guide