← AI Incident Database
GovernmentHighMarch 5, 2026

DigiYatra faces Kerala High Court PIL over biometric data privacy and DPDP Act compliance

India's facial-recognition boarding system faced a Public Interest Litigation regarding third-party data sharing and oversight gaps. In 2026, the DigiYatra airport facial recognition system faced severe legal scrutiny via a Public Interest Litigation (PIL) in the Kerala High Court. The PIL alleged that sensitive passenger biometric data was being shared with third-party vendors without adequate cybersecurity clauses or independent oversight, particularly highlighting the delayed setup of the national Data Protection Board.

What caused this

  • Integration of sensitive biometric processing with third-party operators lacking enforceable, strict cybersecurity agreements.
  • Deployment of a massive biometric collection system prior to the full operationalization of the national Data Protection Board under the DPDP Act.
  • Allegations of private operators integrating passenger data into marketing programs without transparent disclosure.

How this could have been avoided

  • Third-Party Risk Management: Mandatory vendor cybersecurity and data-handling audits (ISO 42001 Annex A.10 supplier controls).
  • DPDP Alignment: Strict adherence to data minimization and explicit consent workflows as mandated by the 2023 Act and 2025 Rules.
  • Data Flow Mapping: Complete transparency and verifiable audit trails for all biometric token processing and subsequent 24-hour purges

Need AI assurance for your organisation?

Talk to AramGRC about ISO 42001 readiness, governance reviews, and incident response playbooks tailored to your sector.

Contact AramGRC for AI assurance →
WhatsApp