← AI Incident Database
GovernmentHighMarch 5, 2026
DigiYatra faces Kerala High Court PIL over biometric data privacy and DPDP Act compliance
India's facial-recognition boarding system faced a Public Interest Litigation regarding third-party data sharing and oversight gaps. In 2026, the DigiYatra airport facial recognition system faced severe legal scrutiny via a Public Interest Litigation (PIL) in the Kerala High Court. The PIL alleged that sensitive passenger biometric data was being shared with third-party vendors without adequate cybersecurity clauses or independent oversight, particularly highlighting the delayed setup of the national Data Protection Board.
What caused this
- Integration of sensitive biometric processing with third-party operators lacking enforceable, strict cybersecurity agreements.
- Deployment of a massive biometric collection system prior to the full operationalization of the national Data Protection Board under the DPDP Act.
- Allegations of private operators integrating passenger data into marketing programs without transparent disclosure.
How this could have been avoided
- Third-Party Risk Management: Mandatory vendor cybersecurity and data-handling audits (ISO 42001 Annex A.10 supplier controls).
- DPDP Alignment: Strict adherence to data minimization and explicit consent workflows as mandated by the 2023 Act and 2025 Rules.
- Data Flow Mapping: Complete transparency and verifiable audit trails for all biometric token processing and subsequent 24-hour purges
Need AI assurance for your organisation?
Talk to AramGRC about ISO 42001 readiness, governance reviews, and incident response playbooks tailored to your sector.
Contact AramGRC for AI assurance →