← All Insights
Public Interest Litigation — Privacy

The FIR That Never Forgets: Public Data, Private Harm, and the Case for a PIL

Vishal Akshintala

An FIR is, by design, a public document. That principle exists for good reason — police accountability depends on the public being able to see that a complaint was registered and acted upon. But somewhere between that legitimate transparency interest and how FIRs are actually published on state police portals today, something has gone wrong: full name, phone number, residential address, and in several states, caste and community details, sit permanently indexed and searchable, attached to complainants and accused alike, with no redaction for sensitive fields and no removal mechanism even after acquittal or a finding that the complaint was false.

This is not a hypothetical harm. A phone number attached to a public FIR becomes a vector for social engineering. A caste field attached to a criminal complaint becomes a tool for exactly the discrimination the Constitution's equality guarantees exist to prevent — surfaced not by a malicious actor's digging, but by the state's own publication design. Background-check apps scrape these portals routinely; a person named in a later-dismissed complaint can carry that public record indefinitely.

The right to privacy recognized in Puttaswamy does not pause at the police station door. If anything, the state's own publication of identity-linked data demands a higher standard of purpose limitation than a private actor's.

Puttaswamy established privacy as a fundamental right under Article 21, subject to a proportionality test for any state action limiting it. Publishing caste data alongside a criminal complaint fails that test cleanly: the legitimate aim — transparency of police action — does not require the caste field to be public at all. It requires the fact of the complaint and its status to be verifiable. The current design conflates verifiability with indiscriminate disclosure, and that conflation is the actual defect.

The relief sought would not ask courts to make FIRs private, which would undermine the legitimate transparency interest. It would ask for a redaction protocol: phone numbers and addresses withheld from the public-facing copy while remaining available to the investigating officer; caste and community fields removed from public disclosure entirely, since they serve no accountability function; and differentiated treatment for juveniles and for complaints concluding in acquittal or a finding of false complaint.

Why this sits on a page about AI governance and data privacy, not only criminal law: the underlying failure is identical to the one this practice spends most of its time on in the corporate context — a system designed for one purpose disclosing far more than that purpose requires, because nobody engineered purpose limitation into the disclosure itself. DPDPA's purpose-limitation principle exists to prevent exactly this pattern in private data processing. There is no principled reason the state should be held to a lower standard.