Abstract
Deepfake technology represents a recent development in Artificial Intelligence that poses serious questions about the right to privacy. It can be used to create video, image, or other digital content that looks real but has been altered or created by technology.
This can be used for identity theft, digital impersonation and the creation of private or personal material without a person’s consent, impacting a person’s dignity, reputation, privacy, and personal data. This article explores the relationship between deepfake technology and the right to privacy, and considers legal and social issues surrounding its misuse. Deepfake technology, similarly to its benefits, can be harmful, impinging on personal safety, and making it challenging to distinguish digital evidence.
Current laws addressing defamation, cybercrime, and data protection may address certain deepfake related acts, but they may not adequately tackle the unique problems associated with digital impersonation. Thus, there is a need for clearer and more specific legal rules to address the unauthorized use of a person’s face, voice, or likeness. Such rules should safeguard privacy while also allowing for beneficial technological development.
Measures such as the prompt removal of harmful deepfake content, proper identification or labeling of AI-generated media, and improved methods for detecting manipulated content can help to reduce the problem. A balanced legal approach, combined with technology-based solutions and effective enforcement, is required to protect privacy and individual dignity in the digital age.
Keywords
Deepfakes, Artificial Intelligence, Privacy Rights, Synthetic Media, Regulatory Frameworks
1. Introduction
The term ‘deepfake’ is a combination of ‘deep learning’, and ‘fake’. It refers to audio-visual material that has been generated or modified by machine-learning models (typically generative adversarial networks) so that a person appears to say or do something that they never said or did. Early deepfakes required technical expertise and a large amount of footage. Nowadays, free apps can replicate a face or voice using a few seconds of footage, changing the capability from expert labs to smartphones.
The issue with this technology is not the technology itself. Synthetic media has valid uses in cinema, teaching, accessibility aids and parody. The problem is its misuse, producing non-consensual intimate images, to commit fraud, to damage reputations and to deceive the public. In all cases, an individual’s identity is appropriated and exploited without consent, affecting privacy, dignity and personal autonomy.
This paper analyzes whether the current legal system, particularly in India, adequately safeguards the right to privacy against deepfake videos and what changes are necessary.
2. Research Problem and Research Question
The issue is that laws on defamation, cybercrime, forgery, and data protection, were all written in the era in which lifelike synthetic media was impossible, and they target specific harms deepfakes may bring (such as reputational damage or obscenity) but fail to treat the unauthorized creation and distribution of someone’s synthetic likeness as an wrong in itself.
Thus the article asks how far the current legal framework protects the right to privacy from deepfake videos, and what legal and regulatory steps are necessary to close the gaps.
Research Sub-Questions
The analysis is guided by the following sub-questions:
- Does the constitutional right to privacy cover a person’s face, voice, and likeness, in digital form?
- Which current statutory rules can be applied to deepfakes, and in what ways do they prove inadequate?
- How have courts responded, and what insights can be drawn from other legal systems?
3. Objectives of the Study
The objectives of this study are:
- To describe deepfake technology and the types of privacy violation it enables.
- To investigate the constitutional basis of the right to privacy as it relates to digital identity.
- To assess the statutory provisions and court rulings pertaining to deepfake misuse.
- To compare selected foreign regulatory approaches to synthetic media.
- To propose reforms that safeguard privacy without placing excessive restrictions on freedom of expression and innovation.
4. Research Methodology
This study uses the doctrinal approach in legal research. Primary sources include the Constitution of India, statutes, subordinate legislation, and reported judgments. Secondary sources include academic articles and government advisories. A limited comparative approach is used, to examine the European Union, the United States, and China. The study is qualitative and analytical, and does not involve empirical fieldwork. Citations follow the Oxford University Standard for the Citation of Legal Authorities (OSCOLA).
5. Main Discussion and Legal Analysis
5.1 Nature of the Harm
Deepfake harms generally fall into four categories.
- Non-consensual sexual content: A person’s face is superimposed onto explicit material. Women are proportionately more likely to be targeted.
- Financial fraud and impersonation: Cloned voices or video calls are used to induce money transfers.
- Reputational and political manipulation: Fabricated statements are attributed to public figures.
- The ‘liar’s dividend’: Once deepfakes become commonplace, genuine recordings may be dismissed as fake. This erodes trust in authentic recordings.
5.2 Privacy as a Constitutional Right
Privacy was found to be a fundamental right under Article 21 of the Constitution in Puttaswamy. The Court recognized informational privacy and decisional autonomy as elements of the right. It also held that dignity is its cornerstone.
An individual’s face and voice are key identifiers. Unauthorized synthetic replication affects control over personal information and self-presentation. Earlier rulings had already linked privacy with protection against unwanted publicity and surveillance.
The idea that privacy protects individuals from intrusion into private life can be traced to the scholarship of Warren and Brandeis.
One difficulty is that fundamental rights are conventionally enforced against the State. Most deepfakes, however, are created by private individuals. Therefore, the solution must come from legislation, tort law, or the horizontal enforcement of constitutional values by courts.
5.3 Why Deepfakes Challenge Existing Legal Categories
A deepfake might contain no genuine private fact concerning the victim. Traditional privacy torts and the law of confidence protect against the disclosure of actual private information rather than its fabrication.
Defamation requires a false statement that lowers a person’s reputation. Yet, a flattering or neutral deepfake may damage dignity without necessarily harming reputation.
Data protection law safeguards ‘personal data’. However, whether synthetic content generated from a person’s image is itself personal data remains unclear.
These gaps explain why the law must directly address the unauthorized use of a person’s likeness.
5.4 Evidentiary Consequences
Indian law requires a certificate for electronic records to be admissible. That certificate addresses the source and integrity of the device and record. However, it does not, by itself, prove that the content portrays real events.
Courts will increasingly require forensic verification of audio-visual material. Meanwhile, the law of evidence has yet to develop a clear standard for manipulated media.
6. Relevant Statutory and Judicial Analysis
6.1 Information Technology Act, 2000
Several provisions apply by analogy to deepfake-related offences.
- Section 66C: Penalizes the fraudulent use of someone else’s electronic signature, password, or any other unique identification feature.
- Section 66D: Penalizes cheating by personation through a computer resource.
- Section 66E: Penalizes the capturing, publishing, or transmitting of an image of a person’s private area without their consent.
- Section 67: Penalizes the publication of obscene material in electronic form.
- Section 67A: Penalizes the publication of sexually explicit material in electronic form.
- Section 69A: Allows the Central Government to direct the blocking of content on specified grounds.
- Section 79: Makes the safe harbour available to intermediaries conditional on due diligence.
These provisions are useful in specific cases. However, Section 66E deals with an image of a person’s private area, whereas a deepfake produces a synthetic image instead of capturing one.
Whether a fabricated body image falls within the scope of this section remains open to argument.
6.2 Bharatiya Nyaya Sanhita, 2023
The Bharatiya Nyaya Sanhita, 2023 contains provisions that might be invoked in deepfake cases. These include:
- Section 356: Defamation.
- Section 336: Forgery for the purpose of harming reputation.
- Section 319: Cheating by personation.
- Section 77: Voyeurism.
None of these provisions specifically names synthetic media. Prosecutors must therefore fit deepfakes into offences designed for different conduct. This creates uncertainty and may lead to inconsistent charging.
6.3 Intermediary Regulation
The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 require intermediaries to inform users that they must not host content that impersonates another person.
They also require the removal of content showing a person in sexual conduct, including impersonation through artificially morphed images, within a short period after receiving a complaint.
The Ministry of Electronics and Information Technology has also issued advisories reminding platforms of these duties in relation to deepfakes.
The regulatory position on mandatory labelling of synthetic content has been evolving. Therefore, the current status of any amendments to the 2021 Rules should be verified before publication.
6.4 Digital Personal Data Protection Act, 2023
The Digital Personal Data Protection Act, 2023 requires a lawful basis, ordinarily consent, for processing digital personal data. It also places obligations on data fiduciaries.
A person whose photographs are used to train or generate a deepfake has a strong argument that their personal data was processed without a lawful basis.
However, the Act contains exemptions, including for personal or domestic purposes. It also does not provide a dedicated remedy for synthetic impersonation.
6.5 Judicial Response: Personality Rights
In the absence of a specific statute, Indian courts have relied on personality rights and passing off to address unauthorized uses of identity.
In Anil Kapoor v. Simply Life India, the Delhi High Court issued an injunction barring the use of the actor’s name, voice, likeness, and image, including through artificial intelligence tools.
Previously, in Amitabh Bachchan v. Rajat Nagi, the Delhi High Court had safeguarded the actor’s name, voice, and image from commercial misuse.
The Bombay High Court followed similar reasoning in Arijit Singh v. Codible Ventures LLP, restraining voice cloning through AI tools. The Delhi High Court has also extended comparable relief to other public figures facing AI-generated misuse, as seen in Jackie Shroff’s case.
These rulings are significant, yet they have limitations. They primarily protect celebrities who possess commercial goodwill. Moreover, most of these orders are interim orders.
Ordinary people, who often suffer from non-consensual deepfakes, are left to depend on criminal complaints and takedown requests.
Free Expression and Deepfake Regulation
On free expression, Shreya Singhal reflects the caution the Court exercises over online speech regulation. It requires blocking and takedown mechanisms to align with Article 19(2) and procedural safeguards.
Any regulation of deepfakes must therefore be drawn narrowly. It must leave room for parody, satire, and legitimate research.
6.6 Comparative Approaches
Different jurisdictions have adopted approaches to regulate deepfakes and protect individuals from synthetic impersonation.
| Jurisdiction | Legal Framework | Key Approach |
|---|---|---|
| European Union | Artificial Intelligence Act | Sets transparency duties requiring deployers of systems that produce deepfakes to disclose that the content is artificially generated or manipulated. |
| European Union | General Data Protection Regulation | Grants data subjects rights concerning the processing of their personal data. |
| United States | TAKE IT DOWN Act, 2025 | Makes the publication of non-consensual intimate imagery, including digital forgeries, a criminal offence and obliges covered platforms to remove it upon notice. |
| China | Deep Synthesis Rules | Governs deep synthesis services through rules that mandate labelling and real-identity verification. |
Taken together, these models point to three shared tools:
- Disclosure: Identifying content that has been artificially generated or manipulated.
- Swift removal: Enabling the prompt removal of harmful synthetic content.
- Liability for harmful use: Holding responsible parties accountable for the misuse of synthetic media.
Findings and Observations
The right to privacy under Article 21 is wide enough to encompass control over one’s digital likeness. Yet, it offers no clear private-law remedy against those who create deepfakes.
Existing criminal provisions apply only indirectly. They were framed for conduct like forgery, cheating and obscenity. Their application to synthetic media remains unclear.
Intermediary rules offer a practical route for takedowns. However, enforcement depends on complaints from users and on how quickly platforms respond.
Judicial protection through personality rights is developing. However, it primarily helps well-known individuals and operates through interim relief.
Evidentiary law has yet to adapt to the fact that convincing-looking audio-visual material can be fabricated.
Foreign legal frameworks combine disclosure requirements, takedown obligations and targeted offences. Indian law does not currently bring these measures together.
Conclusion and Suggestions
Deepfake technology illustrates a mismatch between conventional legal categories and the realities of synthetic media. The right to privacy, understood as safeguarding dignity and control over identity, offers the normative basis. However, statutory and procedural instruments remain fragmented.
The following reforms are proposed:
1. A Distinct Offence for Deepfakes
- A distinct offence for creating or disseminating a synthetic depiction of a real person without consent, with harsher punishment for sexual content, fraud and electoral manipulation.
2. A Statutory Right in Likeness
- A statutory right in likeness, available to everyone other than celebrities, with civil remedies such as injunctions and damages.
3. Compulsory Labelling and Watermarking
- Compulsory labelling or watermarking of AI-generated media by creators and platforms, accompanied by provenance standards.
4. Time-Bound Takedown Obligations
- Time-bound takedown obligations for platforms, with a grievance mechanism and safeguards against wrongful removal in line with Article 19(2).
5. Exceptions for Legitimate Expression
- Explicit exceptions for parody, satire, journalism, education and research.
6. Evidentiary Guidelines and Forensic Capabilities
- Evidentiary guidelines and forensic capability for verifying audio-visual evidence in courts, along with training for police and judges.
7. Public Awareness and Victim Support
- Public awareness and support services for victims, along with investment in detection technology.
A Balanced Approach to Deepfake Regulation
A balanced approach that combines legal rules, technological safeguards and effective enforcement is essential to protect privacy and individual dignity, while preserving space for beneficial innovation.
Bibliography
Cases
- Amitabh Bachchan v Rajat Nagi, 2022 SCC OnLine Del 4110.
- Anil Kapoor v Simply Life India, 2023 SCC OnLine Del 6914.
- Anvar PV v PK Basheer, (2014) 10 SCC 473.
- Arijit Singh v Codible Ventures LLP, 2024 SCC OnLine Bom 2445.
- Arjun Panditrao Khotkar v Kailash Kushanrao Gorantyal, (2020) 7 SCC 1.
- Jaikishan Kakubhai Saraf v The Peppy Store (Delhi High Court, 2024).
- Justice KS Puttaswamy (Retd) v Union of India, (2017) 10 SCC 1.
- Kharak Singh v State of Uttar Pradesh, AIR 1963 SC 1295.
- PUCL v Union of India, (1997) 1 SCC 301.
- R Rajagopal v State of Tamil Nadu, (1994) 6 SCC 632.
- Shreya Singhal v Union of India, (2015) 5 SCC 1.
Legislation and Regulations
- Bharatiya Nyaya Sanhita 2023 (India).
- Bharatiya Sakshya Adhiniyam 2023 (India).
- Constitution of India 1950.
- Digital Personal Data Protection Act 2023 (India).
- Information Technology Act 2000 (India).
- Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021 (India).
- Regulation (EU) 2016/679 (General Data Protection Regulation).
- Regulation (EU) 2024/1689 (Artificial Intelligence Act).
- TAKE IT DOWN Act 2025, Pub L 119-12 (United States).
Secondary Sources
- Chesney R and Citron D, ‘Deep Fakes: A Looming Challenge for Privacy, Democracy, and National Security’ (2019) 107 California Law Review 1753.
- Cyberspace Administration of China, Provisions on the Administration of Deep Synthesis Internet Information Services (2022).
- Ministry of Electronics and Information Technology, Advisory on deepfakes and synthetic media (December 2023).
- Warren S and Brandeis L, ‘The Right to Privacy’ (1890) 4 Harvard Law Review 193.
Written By: Shivani Pareek

