
Fingerprints are one of the oldest tools in criminal investigation, but their role in India today has grown to much more than that. They are now used for Aadhaar enrollment, employee attendance systems, background checks, professional licensing, and many other identity verification processes.
As fingerprint collection has grown more widespread, so have debates around privacy and individual rights. A fundamental question has been repeatedly raised by citizens, civil society groups, and the judiciary alike: does compulsory fingerprinting violate the right to privacy? The Aadhaar biometric enrollment program became the most visible point for this debate.
In response, India has built a layered legal framework governing every stage of the fingerprinting process: who can collect prints, under what authority, how long they can be stored, when they are admissible in court, and what rights individuals retain over their own biometric identity.
Protection Against Self-Incrimination (Article 20(3))
Per this article of the Indian Constitution, people cannot be forced to testify against themselves in criminal cases. But courts have clarified that providing fingerprints does not count as self-incrimination. This is because fingerprints are physical identifiers, not statements or personal testimony. As a result, law enforcement agencies can legally collect fingerprints when required by the law.
Right to Privacy (Article 21)
The right to privacy is a fundamental right in India. Since fingerprints are personal biometric data, authorities must ensure that their collection and storage follows legal procedures, and that their use is reasonable and proportionate to the purpose for which it is collected.
The CPI Act, 2022, is the primary law governing the collection of fingerprints and other biometric information in India. It replaced the older Identification of Prisoners Act, 1920, and expanded the government's authority to collect and store biometric data.
The Bharatiya Sakshya Adhiniyam, 2023, which replaced the Indian Evidence Act, sets out the rules for how fingerprint evidence can be used in Indian courts. There are two main requirements that allow fingerprints to be accepted as evidence:
Expert Verification
Fingerprint matches are not automatically treated as proof in court. A qualified fingerprint expert must examine and compare the prints and provide an opinion on whether they belong to the same person. The court can consider this expert opinion as valid evidence when deciding a case.
Authentication of Digital Records
Today, most fingerprint records are stored and analyzed digitally through systems such as NAFIS. Because these records are electronic, courts require proof that the data is genuine and has not been altered. For this, authorities have to provide a certificate confirming that the system was functioning properly and that the electronic records are authentic and reliable.
The Bharatiya Nagarik Suraksha Sanhita, 2023, which replaced the Criminal Procedure Code (CrPC), lays down the procedures that investigating authorities must follow while collecting and handling fingerprints as evidence.
While the CPI Act, 2022 gives authorities the power to collect fingerprints, the BNSS governs how that process must be carried out during an investigation. It lays down the legal procedures for collecting, documenting, and preserving fingerprint evidence. The law also helps ensure that fingerprint records are properly handled from the time they are collected until they are presented in court.
Under India's IT Rules, biometric information, including fingerprints, is classified as sensitive personal data or information. This means that the organizations and authorities collecting or storing fingerprint data are expected to handle it with a higher level of care and security than ordinary personal information. And since fingerprint records are increasingly being stored and processed through digital systems now, protecting this information from unauthorized access becomes much more important. The Information Technology Act, 2000, contains provisions that address unauthorized access, data breaches, hacking, and misuse of electronic records.
The Section 29 of the Aadhaar Act, 2016 contains strict rules to protect the privacy and security of biometric information collected for Aadhaar enrolment and authentication. Given below are some of the rules laid down under this section:
Right to Alternative Biometrics When Fingerprints Fail
Fingerprint scanning does not always work. Sometimes factors such as old age, worn fingerprints, some skin conditions, injuries, or medical conditions can make fingerprints difficult or impossible to capture. To address this issue, UIDAI regulations require authentication agencies to use alternative biometric methods when fingerprints cannot be read. You cannot be denied a license or service solely because your fingerprints are unreadable. Indian authorities are legally obligated to offer iris and face scanning or OTP authentication as a backup.
Many private organizations are increasingly using fingerprint-based systems for employee attendance, access control, identity verification, and security. The Digital Personal Data Protection Act, 2023 includes rules for how such biometric data must be handled.