Key Facts
- Observation: A public visitor register at a Mumbai suburban police station cyber cell
- Physical Location: Kept outside the cyber cell, on a sofa
- Data Collected: Name, address, mobile number, bank account details, and details of the fraud or offence being reported
- Handling: Visitors are sent outside the cyber cell to make entries. No officer verifies the entries. The register is not kept in locked custody.
- Legal Basis: None. No provision in the BNSS, IT Act, or DPDP Act mandates a cyber cell visitor register
- DPDP Act Principle: Section 8 requires data minimisation — only data necessary for the stated purpose may be collected
- DPDP Act Exemption: Section 17 exempts police processing for investigation, but the exemption does not override Sections 8(1) and 8(5)
- Latest Precedent: Supreme Court (August 2026) agreed to examine indiscriminate biometric surveillance by police at protest sites, invoking Puttaswamy and the DPDP Act
- Constitutional Foundation: K.S. Puttaswamy v. Union of India (2017) — legality, legitimate state aim, proportionality
Direct Answer
I visited a cyber cell at a Mumbai suburban police station. The register was not on the officer’s desk. It was outside the cyber cell, on a sofa.
The officer at the desk told me to go outside and make an entry. I walked out. The register had columns for name, address, mobile number, bank account details, and the nature of the complaint.
I filled in my name, address, and mobile number. I left the bank details blank.
The officer told me the form was incomplete. I asked why my bank details were required. He said it was procedure.
There is no procedure. There is no provision in the Bharatiya Nagarik Suraksha Sanhita, 2023, the Information Technology Act, 2000, or the Digital Personal Data Protection Act, 2023 that mandates a cyber cell to maintain a public visitor register.
The register is not a surveillance tool. It is not interception of communication. It is a data collection practice.
And it violates every data protection principle that applies to a data fiduciary in India.
The register is kept outside the cyber cell. Anyone who walks into the police station can read it. Anyone can see the names, addresses, mobile numbers, bank details, and complaint details of every visitor. No officer verifies whether the entries are true. No officer checks whether the entries are being copied. No officer ensures the register is not carried away.
I asked for the legal provision that required the bank details. The officer could not tell me.
In this article:
- What the Register Collected and Where It Was Kept
- The Physical Handling Problem: Outside the Cyber Cell, on a Sofa
- Why Each Data Point Is Problematic
- The Data Protection Framing — Not Surveillance
- The DPDP Act and Data Minimisation
- The DPDP Act Exemption and Its Limits
- The Supreme Court’s August 2026 Intervention
- The Legal Basis for the Register — and Why There Is None
- The Security Vulnerability
- What I Reported and What Happened
- Recommendations for Police Training and Reform
- Frequently Asked Questions (FAQ)
By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police forces since 1996.
What the Register Collected and Where It Was Kept
The register had the following columns:
- Name
- Address
- Mobile number
- Bank account details
- Details of the fraud or offence being reported
The entries dated back to January 2026. Every visitor to the cyber cell — complainants, witnesses, persons accompanying complainants — had filled in the same columns.
The register was not in a locked drawer. It was not on the officer’s desk. It was outside the cyber cell, on a sofa.
I was told to go outside and make the entry. The officer did not accompany me. The officer did not verify what I wrote. The officer did not check whether the entry was accurate.
I was not asked for identification. I was not told what would be done with my data. I was not told how long it would be retained. I was not told who would have access to it.
The Physical Handling Problem: Outside the Cyber Cell, on a Sofa
The physical handling of the register raises distinct issues.
It is outside the cyber cell.
The register is not in the custody of the officer. It is in a public area of the police station. Anyone who walks past the sofa can read it. Anyone who visits the police station — for any purpose — can see the names, addresses, mobile numbers, bank details, and complaint details of every visitor.
Visitors are sent outside to make entries.
The officer sends visitors outside the cyber cell to fill in the register. This means:
- No officer supervises the entry
- No officer verifies the identity of the person making the entry
- No officer checks whether the details entered are accurate
- No officer prevents one visitor from reading another visitor’s details
No verification.
The register records whatever the visitor writes. A person can write a false name, a false address, a false mobile number, a false bank account. No one checks.
The register can be carried away.
The register is not secured. It is not locked. It is not chained to the desk. It can be picked up and carried away. A person who takes the register — or photographs the pages — has the names, addresses, mobile numbers, bank details, and complaint details of every visitor since January 2026.
Who can misuse it?
- Scammers can use the bank details and mobile numbers for financial fraud
- Press reporters can use the complaint details to identify victims and publish their stories without consent
- Criminals can use the addresses and mobile numbers to target victims of financial crime, cyberstalking, or sextortion
- Anyone with the register can identify vulnerable individuals and exploit them
The register is a goldmine.
It is not a record of visitors. It is a ready-made target list. And it is sitting outside a cyber cell on a sofa.
Why Each Data Point Is Problematic
Name
The name is necessary. A complaint cannot be registered without identifying the complainant. But the name should be recorded in the FIR register under Section 173 of the BNSS, not in a publicly accessible visitor register.
Address
The address is not necessary for receiving a complaint. It may be necessary for investigation, but it is not necessary at the intake stage. It should be recorded in the case diary, not in a public register.
Mobile Number
The mobile number is not necessary for receiving a complaint. It may be useful for follow-up, but the complainant can be asked for it when the follow-up is required. It should not be collected from every visitor.
Bank Account Details
The bank account details are not necessary for receiving a complaint. They are not necessary for registering an FIR. They are not necessary for anything the cyber cell does at the intake stage. They are collected because the register has a column for them.
Details of the Fraud or Offence
The details of the fraud or offence being reported are the most sensitive data in the register. They may reveal that the complainant was a victim of a financial crime, a cyberstalking offence, or a sextortion attempt. They are visible to anyone who reads the register. They should be recorded in the FIR, not in a public visitor register.
The cumulative effect:
The register collects more data than is necessary for any legitimate purpose. It stores that data in a publicly accessible location. It retains that data without a stated retention period. It exposes that data to anyone who walks past the sofa.
The Data Protection Framing — Not Surveillance
The register is not a surveillance tool. It is not interception of communication. It is not bulk surveillance. It is a data collection practice.
That distinction matters because the legal framework is different.
Surveillance involves the interception or monitoring of communication. It engages the right to privacy under Article 21 and the standards laid down in the Puttaswamy judgment and subsequent interception cases.
Data collection involves the gathering and storage of personal data. It engages the DPDP Act, 2023, the data minimisation principle, the purpose limitation principle, and the storage limitation principle.
The register is a data collection practice. It should be assessed under the DPDP Act.
The DPDP Act and Data Minimisation
The DPDP Act, 2023, imposes obligations on every data fiduciary.
Section 8: General obligations of a data fiduciary
A data fiduciary must:
- Process personal data only for the lawful purpose for which it was collected
- Collect only the personal data that is necessary for the stated purpose
- Retain personal data only as long as necessary for the stated purpose
- Implement appropriate security safeguards
The data minimisation principle:
A data fiduciary shall not collect personal data unless it is necessary for the stated purpose. The purpose must be specific, clear, and lawful. The data collected must be limited to what is necessary to achieve that purpose.
The application to the register:
The stated purpose of the register is to record visitors to the cyber cell. The data necessary for that purpose is the visitor’s name and contact number. The data actually collected — bank details, address, and complaint details — exceeds what is necessary.
The register violates the data minimisation principle.
The DPDP Act Exemption and Its Limits
Section 17 of the DPDP Act exempts processing of personal data by the State for certain purposes, including the prevention, detection, investigation, or prosecution of offences.
What the exemption covers:
Processing necessary for a specific law enforcement purpose. The exemption is intended to allow the police to process personal data without the consent and notice requirements that apply to private entities.
What the exemption does not cover:
Indiscriminate collection of personal data. The exemption does not authorise the police to collect data that is not necessary for a legitimate purpose.
The critical limitation:
Section 17(1) exempts Chapter II — except sub-sections (1) and (5) of Section 8. This means Sections 8(1) and 8(5) continue to apply even where the Section 17 exemption applies.
Section 8(1): A Data Fiduciary shall be responsible for complying with the provisions of this Act and the rules made thereunder.
Section 8(5): A Data Fiduciary shall protect personal data in its possession or under its control by taking reasonable security safeguards to prevent personal data breach.
The police are not exempt from the obligation to protect personal data. They are not exempt from the obligation to take reasonable security safeguards. They are not exempt from the data minimisation principle embedded in Section 8(1) as read with the Act’s scheme.
A register that collects bank details from every visitor, keeps them on a sofa outside the cyber cell, and allows anyone to read them is not a reasonable security safeguard.
The Supreme Court’s August 2026 Intervention
In August 2026, the Supreme Court agreed to examine a challenge to the Delhi Police’s use of facial recognition technology and biometric surveillance at protest sites.
The petition, filed by Rajya Sabha MP A.A. Rahim, sought a declaration that “indiscriminate biometric surveillance of participants in peaceful assemblies is unconstitutional”.
The petition invoked Puttaswamy and argued that the surveillance failed the tests of legality, legitimate aim, and proportionality. It argued that biometric data was collected without consent and stored in violation of the DPDP Act, 2023.
The petition also raised concerns over the involvement of private companies in operating surveillance tools and handling sensitive biometric data without any public disclosure on data-sharing agreements.
The application to the register:
The register collects personal data from every visitor — name, address, mobile number, bank details, complaint details — without consent, without purpose limitation, and without safeguards.
The Supreme Court’s intervention in the facial recognition case signals that indiscriminate data collection by police is now under judicial scrutiny. The register at the cyber cell is another form of indiscriminate collection. It is not biometric surveillance, but it is personal data collection without a legal basis.
The Legal Basis for the Register — and Why There Is None
There is no specific provision in the Bharatiya Nagarik Suraksha Sanhita, 2023, the Information Technology Act, 2000, or the Digital Personal Data Protection Act, 2023 that mandates a cyber cell to maintain a public visitor register.
What the BNSS requires:
- A General Diary for station administration
- A First Information Report register under Section 173
- Case Diaries for investigations
None of these provisions authorises a separate, publicly accessible register for visitors.
What the register likely is:
The register is almost certainly maintained under executive instructions — internal police circulars, commissioner’s orders, or station-level standard operating procedures.
Such instructions do not have the force of law. They cannot override the data minimisation principle under the DPDP Act, and they cannot override the right to privacy under Article 21.
The Security Vulnerability
A publicly accessible register containing names, addresses, mobile numbers, bank details, and complaint details is a data breach waiting to happen.
The problem:
- Anyone who visits the police station can read the register
- The register is outside the cyber cell, on a sofa
- No officer supervises the entries
- No officer verifies whether the entries are true
- The register can be carried away
- The entries I saw dated back to January 2026
- There is no access control
- There is no audit trail
- There is no retention limit
What can be done with the data:
A person who reads the register can link a name, an address, a mobile number, a bank account, and the nature of the complaint. That is enough to identify vulnerable individuals — victims of financial crime, victims of cyberstalking, victims of sextortion — and to attempt targeted fraud, extortion, or social engineering.
The register becomes a ready-made target list.
What the courts have said:
The Karnataka Director General of Police has issued statewide guidelines prohibiting unauthorised disclosure of information related to criminal investigations, intelligence inputs, and sensitive cases.
The fact that such guidelines are necessary confirms that the problem is systemic.
What I Reported and What Happened
I reported the register to the senior officer at the station.
I was told the register was a long-standing practice. I was told it was maintained for “record purposes.” I was told the matter would be looked into.
I followed up a week later. The register was still on the sofa outside the cyber cell. New entries had been added.
I asked whether the practice had a legal basis. I was told the matter was under review.
I was not told what the review was. I was not told when it would be complete. I was not told whether the register would be abolished.
The register is still there.
Recommendations for Police Training and Reform
1. Abolish the practice
There is no legal basis for a cyber cell visitor register that collects data beyond what is necessary. A formal police circular should prohibit it.
2. Apply the data minimisation principle
The DPDP Act requires data fiduciaries to collect only the data necessary for the stated purpose. The police are subject to this principle, subject only to the specific exemptions in Section 17.
3. Secure the register
If a visitor register is required for any legitimate purpose, it must be kept in secure custody, with access controls, and with a stated retention period. It must not be left on a sofa outside the cyber cell.
4. Train officers on data protection
Station-level officers are not trained in data protection principles. The DPDP Act applies to them. They need to know what the law requires.
5. Adopt digital alternatives
The CCTNS and NCRP systems should be used for all complaint registration. A digital system can enforce access controls, audit trails, and data retention limits that a paper register cannot.
6. Establish accountability
The Karnataka DGP’s guidelines provide a model: any officer who leaks or misuses data faces departmental inquiry and criminal proceedings.
7. Seek a judicial declaration
A public interest litigation challenging the practice would force the police to justify the register. The DPDP Act’s data minimisation principle and the Supreme Court’s August 2026 intervention provide a clear framework for such a challenge.
The register I saw is evidence of a practice that has no legal sanction and creates a documented security risk. My instinct to document it was correct. The next step is to demand that the police justify it — or abolish it.
Frequently Asked Questions (FAQ)
What did I see at the cyber cell?
A public visitor register collecting name, address, mobile number, bank account details, and details of the complaint. The register was kept outside the cyber cell, on a sofa. The entries dated back to January 2026.
Was the register in the officer’s custody?
No. The register was outside the cyber cell. Visitors were sent outside to make entries. No officer supervised the entries or verified whether they were true.
Is there a law that requires a cyber cell visitor register?
No. There is no provision in the BNSS, the IT Act, or the DPDP Act that mandates a cyber cell to maintain a public visitor register.
Why is the register a data protection issue and not a surveillance issue?
Surveillance involves interception or monitoring of communication. The register involves collection and storage of personal data. It is governed by the DPDP Act, 2023, and the data minimisation principle.
What does the DPDP Act require?
Section 8 requires data fiduciaries to process personal data only for the lawful purpose for which it was collected, to collect only the data necessary for that purpose, to retain it only as long as necessary, and to take reasonable security safeguards.
Does the DPDP Act apply to the police?
Section 17 of the DPDP Act exempts processing of personal data for the prevention, detection, investigation, or prosecution of offences. But the exemption does not override Sections 8(1) and 8(5), which require the data fiduciary to protect personal data and take reasonable security safeguards.
What did the Supreme Court do in August 2026?
The Supreme Court agreed to examine a challenge to the Delhi Police’s use of facial recognition technology and biometric surveillance at protest sites. The petition argued that indiscriminate biometric surveillance is unconstitutional and violates the DPDP Act.
What are the security risks?
A publicly accessible register containing names, addresses, mobile numbers, bank details, and complaint details is a data breach waiting to happen. Anyone who visits the police station can read the register. It can be carried away. It is a goldmine for scammers, reporters, and criminals.
Why are digital systems not used?
Institutional inertia, lack of training, and supervisory neglect. The CCTNS and NCRP systems are operational, but station-level officers are not trained in their use.
What should be done?
Abolish the practice. Apply the data minimisation principle. Secure the register if it must exist. Train officers on data protection. Adopt digital alternatives. Establish accountability. Seek a judicial declaration.
Explore More:
Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.
Author:
Adv. Shoeb Hakim
Author Bio:
Adv. Shoeb Hakim is a Mumbai-based criminal defence, AML, digital forensics and cybercrime specialist. Former General Counsel at Credit Suisse. Has been training police forces since 1996. Provides expert commentary on data protection, police accountability, and constitutional law.
Article Publisher:
Adv. Shoeb Hakim
Article Section:
Data Protection | Police Accountability | Constitutional Law | Privacy
Article Tags:
police cyber cell, visitor register, data minimisation, DPDP Act, Section 8, Section 17, August 2026 judgment, BNSS, police reform, data protection, Adv Shoeb Hakim



Leave a Reply