Banned at Home, Sold Abroad: Corporate Due Diligence and the Export Door Europe Left Open

In July 2026, Delhi Police stationed two surveillance vehicles outside Jantar Mantar, the site the police designate for protest in the capital. Assembly elsewhere in New Delhi is not unlawful in itself. It requires police permission, and prohibitory orders under section 163 of the Bharatiya Nagarik Suraksha Sanhita 2023 sit over the district often enough that the distinction wears thin. The Supreme Court held in Mazdoor Kisan Shakti Sangathan that regulation must not harden into prohibition, and told the Police Commissioner to frame guidelines. Practice has not caught up with that ruling.

Inside one of the vehicles, a van named Ikshana, live footage of the protest ran through facial recognition software that drew green boxes around faces and matched them against a police database. Police later told the government that 2,873 people had been examined over violence during the demonstrations, of whom 989 had records of serious offences, identified through facial recognition, CCTV and video footage.

Nobody has published which company built the software in that van. The Internet Freedom Foundation has filed fresh Right to Information applications on the private vendor arrangement behind it.

That gap is a business and human rights problem before it is a constitutional one. The vendor’s responsibility under the UN Guiding Principles attaches when the sale is made. It does not wait on a writ petition in Delhi, and it does not lapse if the petition fails.

Earlier the same month, Investigate Europe reported, in an account carried by Tech Policy Press, that facial recognition software made by the Spanish firm Herta Security runs on an estimated 4,000 cameras across India. The reporting places it in 143 railway stations in the east of the country, three prison complexes in Delhi, the Ram Mandir at Ayodhya, and a municipal control room in Ahmedabad. Four European scholars of AI and biometrics law reviewed two of those deployments and concluded they would be unlawful inside the European Union.

They would be unlawful because Article 5 of the EU Artificial Intelligence Act has prohibited real-time remote biometric identification in publicly accessible spaces for law enforcement since February 2025, subject to narrow exceptions requiring prior judicial authorisation. Herta has received more than €3.3 million in European research funding since 2020. Brando Benifei, the Italian MEP who led the Parliament’s negotiations on the Act, called the findings a dangerous double standard, and takes the view that the Act should bar such exports outright.

The shape of the thing is plain. A firm may not sell a product for a given use at home. It sells it for that use abroad. The buyer is a police force in a country with no statute on biometric surveillance. Indian law is thin here, and that is a real failure, but it is not the only one. The sale has a European address.

The Instrument’s Defence

Herta’s answer to Investigate Europe was the familiar one. The company said it takes the legal concerns seriously, that its products are built to European data protection principles wherever they are sold, and that it cannot “control how public authorities or system integrators implement the technology in specific environments”.

Classical Indian philosophy worked this ground carefully. The Nyāya-Vaiśeṣika school sorted causes into kinds, and the standard illustration is a pot. The clay is the material cause, upādāna-kāraṇa. The potter is the efficient or instrumental cause, nimitta-kāraṇa. The wheel and the stick are auxiliary causes, sahakāri-kāraṇa. Surendranath Dasgupta sets the potter and the wheel together on one side of the line and the clay on the other (A History of Indian Philosophy, vol 1, Cambridge University Press 1922, ch 8).

Read what the scheme actually does. It does not excuse the wheel. It classifies the wheel. Everything on the list is a cause of some kind, which is the whole reason for having a list. The instrument is placed alongside the potter, not alongside the clay.

Principle 13 of the UN Guiding Principles on Business and Human Rights sorts corporate involvement in much the same manner. A company may cause an adverse human rights impact, contribute to one, or stand directly linked to one through a business relationship. All three categories engage the corporate responsibility to respect human rights. The Guiding Principles are not binding, and Principle 13 allocates responsibility rather than liability. What the categories change is the response expected of the company. A company that causes or contributes is expected to remediate. A company that is only linked is expected to exercise its leverage, as the commentary to Principle 19 sets out. The third category exists because many modern harms travel through supply chain relationships. None of the three is a way out.

A wheel knows nothing. The firm that sells the wheel does, and knowledge is what the Guiding Principles run on. Herta’s position gives away the point it was meant to win. If the company cannot control what a police buyer does with the software, then it knows the risk is unmanaged, and knowing is where due diligence begins.

The standard that follows is not demanding. Principles 17 to 19 ask a company to find its most severe human rights risks and act on what it finds. Principle 20 asks it to check whether the action worked. A vendor selling biometric identification to a police force has taken on an obvious severe risk. Whether that risk can be managed depends almost entirely on the law governing the buyer.

Selling Into an Ungoverned Market

In India there is little law to depend on in this context. No statute regulates police use of facial recognition. The Digital Personal Data Protection Act 2023 exempts instrumentalities of the State broadly. Delhi Police have disclosed, in responses to the Internet Freedom Foundation, that no rule governs their use of the technology, that no privacy impact assessment was ever carried out, and that a score of 80 per cent counts as a positive match. A private member’s bill that would require magistrate approval has sat dormant in the Rajya Sabha since December 2023.

So the buyer operates without a framework. There is no independent body watching. A person wrongly matched has no way of learning that the match happened, which means no way of contesting it. The mitigation that Principles 17 to 19 contemplate has nothing to fasten to. A constitutional challenge in India could take years and might never reach the vendor at all. The corporate responsibility to respect human rights does not await the enactment of a domestic statute. It arises at the point of sale.

Three things follow.

First, a sale of biometric identification to a state security buyer should carry a presumption of heightened due diligence. Where the buyer’s jurisdiction has no statute on police use of the technology, that presumption should harden into a presumption against sale. It can be rebutted, but only by use restrictions the vendor is able to monitor and enforce. A contractual assurance the vendor cannot verify is not a mitigation measure.

Second, European public research funding should travel with conditions. Money that helped build a system prohibited at home should not follow it quietly out of the Union.

Third, the export regime should match the prohibition. The Dual-Use Regulation already requires exporters to seek authorisation for cyber-surveillance items they know or suspect may be used for internal repression or serious human rights violations. The Commission’s 2024 guidelines do name facial recognition. It heads the list of non-listed technologies said to warrant vigilance. Then the guidelines take most of it back. Facial recognition does not fall within the definition automatically. It qualifies only where it monitors or analyses stored video images, and even then only where the software was specially designed for covert surveillance, which the guidelines read as requiring that covert surveillance was the main purpose of the design. Cameras filming people in public spaces are excluded outright.

A marked police van parked at a designated protest site fails that test on its face. Yet the same guidelines accept that surveillance carried out in public may still count as covert where a person cannot objectively expect to be under it, or where the data is processed for purposes never disclosed to them. Both are true at Jantar Mantar. The reasoning that would pull the deployment inside the Regulation is already sitting in the guidelines. It is simply not being used.

The ask is therefore narrow. The Commission should revise section 2.2.1 of the guidelines so that remote biometric identification conducted in publicly accessible spaces by or for law enforcement is presumptively in scope, on the guidelines’ own reasoning about covertness. The durable fix is to list remote biometric identification systems in Annex I, where the question of covert design does not arise. Until then, a member state may impose a national authorisation requirement and have the item published in the C series under Article 5(6), which puts every exporter in the Union on notice. SIPRI researchers have found the catch-all little used. A prohibition inside the Union that carries no consequence at its border is a prohibition with a door in it.

The pot exists. Someone turned the wheel. The remaining question is whether we intend to keep saying that a wheel answers for nothing.

Author

Leave a Reply

Discover more from BHRJ Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading