Author
Arthi M.A. is a final-year (5th Year) B.A. LL.B. student at S. Thangapazham Law College, affiliated to Dr. Ambedkar Law University, Chennai, Tamil Nadu. The blog is co-authored by Meena Santhiya P. and Prakash Raj A.
Introduction
A commercially available headband can today record electroencephalographic (EEG) signals well enough to infer a person’s attention levels, emotional state, and even early markers of neurological conditions. Meditation apps already sell such headbands in India, and neurotechnology firms are testing wearable and implantable brain-computer interfaces (BCIs) for both therapeutic and consumer use. What none of these devices currently face in India is a data protection regime that treats the electrical signal coming out of a human skull any differently from a shopping cart history.
This is the quiet frontier of privacy law. In today’s world the advanced technology is watching a person 24/7 form everywhere through various commercial apps, social media as I said the mobile phones had become our entire world. What I mean is earlier when technology was used. It mainly focused on People’s daily activities. For example, if people were talking about something that technology would identify what they were discussing and then show or suggest content related to those topics.
But now the situation is different. We may be going through a mental breakdown or we may be in happy mode are experiencing any other emotional state. Even the things that we Are thinking about internally can sometimes be identified by these technologies and they are suggesting contents related to those thoughts or emotions. This is known as neurotechnology.
This can happen through various digital platforms such as artificial intelligence, social media’s commercial apps and any other chatting or messaging applications or any other digital platforms.
When artificial intelligence starts processing and predicting, even what we are thinking about, it rises a serious privacy concern. Now this leads to a harder question that whether we have any privacy left at all, even there is no privacy in our thoughts and internal mental space. This blog discusses about the legal issues in the mental privacy and Neuro rights.
Why Brain Data Demands Special Protection
The data’s collected for our brain activity through EEG signals, brain activity patterns and neutral response is called Neurodata, But the biometric identifier is actually different and Neurodata is not merely another biometric identifier.
When the neural signals are decoded can reveal what a person is thinking, feeling, or about to do, this will be a huge barrier to our personal data even there is no privacy in our thinking often before the person is consciously aware of the inclination. Studies how EEG data can reveal far more than expected from a person’s PIN number to their political views and emotional weak points.
The reason this deserves more attention than ordinary privacy comes down to timing. Most data collected about a Person, whether it is browsing history or purchase records, reflects something that has already happened. Brain signals work differently. Scholars refer to this idea as ‘cognitive liberty,’ meaning a person’s right to keep their inner thought process free from outside monitoring, prediction, or influence.
This has already moved from theory into actual policy in a few places. Chile amended its Constitution in 2021 specifically to protect brain data and mental integrity, essentially placing it in the same category as other core constitutional rights. UNESCO followed a similar path in 2025 through its Recommendation on the Ethics of Neurotechnology, calling on countries to treat neural data as sensitive and to create simple complaint mechanisms for people harmed by high risk neurotechnology. A UNESCO recommendation does not carry legal force on its own, but it does indicate where policy is likely heading worldwide.
India has not taken any comparable step so far, whether through a constitutional amendment or a dedicated law addressing brain data specifically.
The Existing Legal Position in India
India already has some constitutional groundwork on mental privacy, even without a specific law covering it. In the case K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1, a nine judge Bench of the Supreme Court held that privacy under the Article 21 of the Constitution. The Court made it clear that privacy is not just about information, it also includes a person’s decisional and mental autonomy.
Even before this, in the case Selvi v. State of Karnataka, (2010) 7 SCC 263, the Supreme Court had ruled that forcing someone into narco analysis, polygraph tests, or brain mapping without consent breaks both the right against self incrimination under Article 20(3) and the right to personal liberty under Article 21, since forcing entry into a person’s mind goes against basic human dignity.
What is missing is proper regulation for how companies actually collect neural data day to day, whether through wellness apps, gaming headsets, or employers monitoring attention levels at work. This is exactly where the law falls short.
The DPDP Act, 2023, India’s first real data protection law, does not go far enough. It covers personal data in general terms, but never singles out neural or brain based data as something needing extra protection. The DPDP Rules, 2025 do not solve this either. In simple terms, a company collecting someone’s raw EEG readings through a headset faces no stricter obligation than a company tracking someone’s browsing habits, even though the two reveal completely different levels of personal information.
This gets worse when you look at the exemptions the DPDP Act gives the State for reasons like national security or public order. Since brain data is not treated as a separate, more sensitive category, these exemptions could apply to it just as easily as any other personal data. That creates a real risk of neuro surveillance existing without any specific legal safeguard to prevent it.
Opportunities don’t wait. Neither should you.
Join 1 Lakh+ law students connected with Lexibal and stay updated with internships, opportunities, competitions and important updates.
Join WhatsApp ChannelCritical Analysis: Research Gaps and Unresolved Concerns
Several distinct problems emerge from this legal vacuum, each worth independent attention.
1. Classification Gap
First, there is a classification gap. The DPDP Act’s framework was not designed with inferential technologies in mind. It regulates data a person provides or that is observably collected about them, not data from which entirely new categories of private information emotional state, cognitive load, even subconscious inclination can be inferred without the person’s active awareness.
A regulatory approach built around consent to data collection struggles when the harm arises from what can be decoded from that data after collection, not merely from the collection itself.
2. Consent Gap
Second, there is a consent gap. Meaningful consent presumes the data subject understands what is being collected and what can be inferred from it. Few consumers purchasing a wellness headband understand that their EEG signal could, with the right decoding model, reveal far more than a relaxation score.
Consent obtained without this understanding is consent in name only a structural weakness the DPDP Act does not address for any data category, but one that is especially acute for neurodata given the opacity of what can be extracted from it.
3. Enforcement Gap
Third, there is an enforcement gap. If an Indian consumer believes their mental privacy has been violated by a neurotechnology provider many of which are foreign entities offering cross-border services it is presently unclear which authority they would even approach, and under what specific provision.
The Data Protection Board of India, established under the DPDP Act, has no neurodata-specific mandate, expertise, or grievance mechanism tailored to this category.
4. Discrimination and Manipulation Risk
Fourth, there is a discrimination and manipulation risk that current law does not anticipate.
Employers monitoring employee attention through workplace neurotechnology, insurers inferring risk from cognitive markers, or political actors using emotional-response data to micro-target messaging all represent plausible near-term uses of neurodata that existing anti-discrimination and consumer protection law was not built to address.
Taken together, these gaps reflect what commentators have described as a “judicial-legislative gap”: robust constitutional principle sitting atop an almost entirely unequipped statutory framework.
The Way Forward
Addressing this gap does not require India to build an entirely new constitutional doctrine Puttaswamy and Selvi already supply the underlying principle that mental integrity deserves heightened protection. What is required is statutory translation of that principle into enforceable rules.
At minimum, this would involve:
- Explicitly classifying neural and brain-derived data as a distinct, sensitive category under the DPDP Act or its Rules.
- Imposing purpose limitation and data minimisation obligations specific to neurotechnology providers, given how much more can be inferred from raw neural signals than from the specific purpose for which they were ostensibly collected.
- Narrowing the availability of State exemptions where neurodata is concerned, given the unique risk of covert cognitive surveillance.
- Empowering the Data Protection Board, or a specialised body, with the technical expertise to handle neurodata-specific grievances.
Chile’s constitutional route and the EU’s technology-neutral approach under the GDPR offer two different models India could draw from a standalone neurorights framework versus extending an existing sensitive-data category. Either path would represent significant progress over the present position, where Indian law treats the most intimate data a person can generate no differently from their online shopping history.
Conclusion
Neurotechnology is moving from research laboratories into everyday consumer products faster than Indian law is moving to meet it. India’s constitutional jurisprudence, through Puttaswamy and Selvi, already recognises that mental autonomy is a facet of dignity deserving protection.
What remains missing is the legislative architecture to make that protection meaningful against the specific and rapidly growing threat of neuro-data exploitation. Until the DPDP Act or a dedicated legal framework explicitly recognises neurodata as a distinct, sensitive category, the last genuinely private space a person has their own mind will remain, as a matter of Indian data protection law, no different from any other data point on a server.
References
- Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1.
- Selvi v. State of Karnataka, (2010) 7 SCC 263.
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023).
- Digital Personal Data Protection Rules, 2025.
- UNESCO, Recommendation on the Ethics of Neurotechnology (2025).
- Constitution of Chile, Art. 19 (as amended, 2021).
- Neuro-Privacy and Indian Constitution: Should Brain Data Be Treated As Sensitive Personal Data?, LiveLaw (2026).
- Securing Neuro-Privacy, Vidhi Centre for Legal Policy (2025).
- UNESCO Recognises Neural Data As Sensitive. What Does It Mean For India?, ETV Bharat (2026).
- Neuro-Rights: Legal Frameworks and Challenges in Protecting Brain Data in the Neurotechnology Era, LIJDLR (2026).
- Neuroprivacy and Brain Data: The Next Frontier of Fundamental Rights, Record of Law (2026).

