Right to Privacy as a Fundamental Right: What Puttaswamy (2017) Actually Held
On 24 August 2017 a nine-judge Supreme Court bench held privacy is a fundamental right under Articles 14, 19 and 21. What Puttaswamy means for your financial data.
The Statutory Question
On 24 August 2017, a nine-judge Constitution Bench of the Supreme Court of India delivered Justice K.S. Puttaswamy (Retd.) v. Union of India, reported at (2017) 10 SCC 1, and answered a question the Constitution had left unsettled for 63 years: does the fundamental-rights chapter protect a right to privacy? The bench held, unanimously, that it does. Privacy, the Court ruled, is intrinsic to Article 21 (protection of life and personal liberty) and is also traced to Articles 14 and 19 of the Constitution of India, 1950.
The reason nine judges were needed is itself a statutory puzzle. Two much older decisions stood in the way. M.P. Sharma v. Satish Chandra had been decided in 1954 by eight judges, and Kharak Singh v. State of Uttar Pradesh in 1962 by six judges, and both had been read as denying that privacy was a guaranteed right. Under the Supreme Court's own convention on bench strength, no smaller bench could displace an eight-judge ruling, so the matter was referred to a bench of nine. The 2017 judgment expressly overruled M.P. Sharma and Kharak Singh to the extent they held there was no fundamental right to privacy.
For a financial-intelligence readership the stakes are concrete, not abstract. Every Aadhaar-linked bank account, every credit-bureau file held under the Credit Information Companies (Regulation) Act, 2005, every Know Your Customer record demanded under the Reserve Bank of India's KYC Master Direction of 25 February 2016, and every cross-border data report an Indian bank files on a non-resident sits downstream of the constitutional standard that Puttaswamy fixed on 24 August 2017. When Parliament enacted the Digital Personal Data Protection Act, 2023 (which received Presidential assent on 11 August 2023), it was legislating inside the constitutional space this nine-judge bench had defined.
This article is an explainer, not legal advice, and the Oquilia Research Desk does not practise before any court. What follows is a plain-language account of what the 2017 bench actually held, the reasoning it used, and the practical consequences for how your financial data may lawfully be collected, stored and shared.
What the Court Held
The core holding of the 24 August 2017 judgment can be stated in one sentence: the right to privacy is a fundamental right protected as an intrinsic part of the right to life and personal liberty under Article 21, and as a part of the freedoms guaranteed by Part III of the Constitution. All nine judges agreed on that conclusion, delivered through a plurality opinion and several concurring opinions.
The judgment did three distinct things. First, it recognised privacy as a constitutionally protected right rather than a mere common-law or statutory interest. Second, it overruled the 1954 and 1962 precedents that had suggested otherwise. Third, and critically for anyone whose data is collected by the State or by regulated financial entities, it held that the right is not absolute: it may be restricted, but only if the restriction survives a defined constitutional test.
| The road to a fundamental right | Year | Bench | What it was read to hold |
|---|---|---|---|
| M.P. Sharma v. Satish Chandra | 1954 | 8 judges | No constitutional right to privacy against search and seizure |
| Kharak Singh v. State of U.P. | 1962 | 6 judges | Privacy not a guaranteed right (surveillance case) |
| Puttaswamy v. Union of India | 2017 | 9 judges | Privacy IS a fundamental right under Articles 14, 19 and 21 |
| Aadhaar-Puttaswamy (sequel) | 2018 | 5 judges | Applied the 2017 test; restricted mandatory Aadhaar use |
| Digital Personal Data Protection Act | 2023 | Parliament | Statutory data-protection framework built on the 2017 standard |
The Court was careful to say what it was not deciding. The nine-judge bench answered only the threshold reference question about whether privacy is a fundamental right; the specific challenge to the Aadhaar programme was left to be decided by a smaller bench, which ultimately ruled on 26 September 2018. So the 2017 judgment is best read as the constitutional foundation, and the 2018 decision as its first major application to a financial-identity system covering more than a billion enrolled residents.
Reasoning
Privacy is intrinsic to liberty, not a gift of statute
The bench's central move was to locate privacy inside Article 21 rather than treat it as something Parliament grants and can withdraw. Life and personal liberty, the Court reasoned, would be hollow without the ability to make intimate choices free of unjustified State intrusion. Because the source is a fundamental right dating to the Constitution's commencement on 26 January 1950, privacy cannot be extinguished by ordinary legislation; any law touching it must itself pass constitutional muster. That is why the Digital Personal Data Protection Act, 2023 had to be framed as a rights-protective statute rather than a licence for unlimited data collection.
The Court also read privacy as having more than one dimension. It spans bodily privacy, informational privacy, and privacy of choice. For financial data, informational privacy is the operative branch: your transaction history, your credit score held under the 2005 Act, your income return filed under the Income-tax Act, 1961, and your Aadhaar number are all informational data in which you retain a constitutionally recognised interest even after you hand them to a bank or a public authority.
The right is not absolute: the proportionality standard
Recognising a right and making it absolute are different things, and the bench was explicit that privacy can yield to legitimate State interest. But it fixed the terms of that surrender. Drawing the threads of the plurality together, the judgment laid down that any State intrusion into privacy must clear a structured test. A restriction is valid only if it rests on a law, pursues a legitimate aim, and is proportionate to that aim.
| Prong of the test | What the State must show | Everyday financial example |
|---|---|---|
| Legality | A valid law authorises the intrusion | RBI KYC Direction of 25 February 2016 mandates identity capture |
| Legitimate aim | The purpose is a genuine State interest | Preventing money laundering under the PMLA, 2002 |
| Proportionality | Means are the least intrusive necessary and rationally connected | Collecting only KYC fields needed, not every data point |
This three-part framework is the reason a bank cannot demand unlimited personal data merely because it is convenient. The 2018 Aadhaar sequel refined the standard further, adding a fourth requirement of procedural safeguards against abuse, and used it to strike down provisions that had allowed private companies to demand Aadhaar authentication. The practical effect from 2018 onwards was that mandatory Aadhaar linking of bank accounts and mobile connections could no longer be forced by private parties.
Overruling the past to protect the future
The third strand of the reasoning was doctrinal housekeeping with real consequences. By expressly overruling M.P. Sharma (1954) and Kharak Singh (1962) on the privacy point, the nine-judge bench removed the precedents that data-collecting authorities had leaned on for decades. Once those cases fell, every surveillance, profiling or data-sharing programme became testable against the new proportionality standard rather than shielded by 1950s-era reasoning.
This matters for the credit economy. Credit Information Companies such as those regulated under the 2005 Act aggregate the repayment records of hundreds of millions of borrowers. After 24 August 2017, the constitutional question is no longer whether a borrower has any privacy interest in that file, but whether the law governing its collection, retention and sharing is proportionate. The framework created the intellectual scaffolding that Parliament later filled with the 2023 statute.
It is worth stressing what overruling does and does not achieve. The 2017 bench did not invalidate any specific data programme by the act of overruling; it changed the standard of review. Before 24 August 2017, a challenger had to argue against the grain of two large-bench precedents from 1954 and 1962. After that date, the burden shifts: once a citizen shows an intrusion into privacy, the State must justify it under the three-part test. That reallocation of the burden of proof is the quiet engine driving every subsequent data-protection dispute, from the 2018 Aadhaar sequel to challenges under the Digital Personal Data Protection Act, 2023.
Practical Takeaways
Privacy jurisprudence sounds remote from a home-loan application, but it shapes concrete rights over the data you surrender every time you transact. A single mortgage file can carry your Aadhaar number, your bank statements for the preceding 6 months, your credit-bureau report and your income-tax returns filed under the Income-tax Act, 1961; after 24 August 2017 each of those data sets carries a constitutional interest. Here is what the holding means in practice.
For borrowers and bank customers:
- Your KYC data, collected under the RBI Direction of 25 February 2016, is constitutionally protected information; the bank is a custodian, not an unconditional owner.
- A lender or recovery agent cannot lawfully publish, broadcast or misuse your personal financial data, because informational privacy is now a recognised right, reinforcing the fair-practice limits the RBI already imposes on agents.
- Consent matters. The Digital Personal Data Protection Act, 2023 builds on the 2017 standard by requiring that most personal-data processing rest on informed consent for a specified purpose.
For investors and depositors:
- Financial-market intermediaries collect extensive profiling data; after Puttaswamy, that collection must be tethered to a legitimate, proportionate purpose rather than open-ended commercial use.
- Data-sharing between group entities cannot be assumed; each transfer must satisfy the legality-aim-proportionality chain the 2017 bench described.
For non-residents (NRIs):
- Cross-border reporting is real: India has exchanged financial-account information under FATCA and the OECD Common Reporting Standard since 2017, and your NRE and NRO account details can be reported to your country of tax residence. Understand the tax side using the NRI tax calculator and read the TDS mechanics before you plan a remittance.
- Reporting is not the same as forfeiting privacy. Even lawful information exchange must operate within a legal framework; the proportionality logic applies to how much is shared and for what purpose. Note that a DTAA governs how income is taxed across borders but does not make any category of income automatically tax-free.
- If you are repatriating funds, the limits and documentation flow from FEMA; plan the mechanics with the repatriation calculator and hold your NRE account papers ready.
For everyone:
- You cannot contract out of a fundamental right by clicking "I agree", but you can and should read what you consent to.
- When a data demand looks disproportionate to the service offered, the 2017 standard gives you a constitutional vocabulary to question it.
FAQ
What exactly did Puttaswamy (2017) decide?
On 24 August 2017 a nine-judge bench of the Supreme Court held, in (2017) 10 SCC 1, that the right to privacy is a fundamental right protected as an intrinsic part of Article 21 and of the freedoms in Articles 14 and 19 of the Constitution. It overruled the 1954 M.P. Sharma and 1962 Kharak Singh decisions on privacy. It did not itself decide the Aadhaar challenge, which a smaller bench resolved on 26 September 2018.
Does a fundamental right to privacy mean the government can never collect my data?
No. The 2017 judgment was explicit that privacy is not absolute. The State may intrude, but only if the action rests on a valid law, serves a legitimate aim, and is proportionate to that aim. So mandatory KYC under the RBI Direction of 25 February 2016 or tax reporting under the Income-tax Act, 1961 can be lawful, provided each collection is authorised and no more intrusive than necessary.
How does this affect my credit score and bureau file?
Credit Information Companies operate under the Credit Information Companies (Regulation) Act, 2005. After 24 August 2017, your repayment data held in those files is treated as constitutionally protected informational privacy. The companies remain custodians bound by law; the question in any dispute is whether the collection, retention and sharing of that data is proportionate, not whether you have any privacy interest at all.
Is the Digital Personal Data Protection Act, 2023 the same thing as this judgment?
No, but they are connected. The 2017 judgment recognised the constitutional right; the Digital Personal Data Protection Act, 2023, which received assent on 11 August 2023, is the statute Parliament enacted to give that right an operational framework, based largely on informed consent for specified purposes. The Act sits inside the constitutional space the nine-judge bench defined and must itself respect the proportionality standard.
As an NRI, can my Indian bank share my account details abroad?
Yes, within a legal framework. India has exchanged financial-account information under FATCA and the OECD Common Reporting Standard since 2017, so NRE and NRO account data can be reported to your country of tax residence. This is lawful information exchange, not a forfeiture of privacy, and it must still satisfy legality and proportionality. Use the NRI tax calculator to model the tax outcome, and remember a DTAA allocates taxing rights rather than granting blanket exemption.
Did Puttaswamy strike down Aadhaar?
No. The 2017 nine-judge bench decided only the threshold question of whether privacy is a fundamental right. The Aadhaar programme itself was upheld on 26 September 2018 by a separate five-judge bench applying the 2017 test, which read down the provisions that had allowed private companies to compel Aadhaar authentication. The net effect was that private parties could no longer force Aadhaar linking of bank accounts and mobile numbers.
Where can I read the judgment myself?
The full text of Justice K.S. Puttaswamy (Retd.) v. Union of India, decided 24 August 2017, is available on Indian Kanoon at indiankanoon.org/doc/91938676. The Constitution of India and statutes such as the Digital Personal Data Protection Act, 2023 are published by the Government of India at indiacode.nic.in, and the RBI's KYC Master Direction of 25 February 2016 is on rbi.org.in. Reading the source is always better than relying on summaries, including this one.
Sources & Citations
- Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1 — Indian Kanoon
- The Constitution of India — Government of India
- Master Direction - Know Your Customer (KYC) Direction, 2016 — Reserve Bank of India