top of page

Privacy in the Cloud: The Kanpur Google Drive Case and the Limits of Digital Privacy.

  • Geetika Tomar
  • Jul 30
  • 9 min read

Introduction


The digital era has fundamentally changed the way we store, access, and share information. Cloud storage services such as Google Drive have become indispensable, allowing individuals to preserve photographs, confidential documents, financial records, and personal memories with the assurance that their data is secure. However, the same technology that safeguards personal information can also be exploited to store and disseminate illegal content.


This tension came into sharp focus with the recent Kanpur Google Drive case, where Google's automated child safety system reportedly detected suspected Child Sexual Abuse Material (CSAM) stored on a user's Google Drive account. The account was suspended, and the matter was reported to the National Center for Missing & Exploited Children (NCMEC) in the United States, which subsequently shared the information with Indian law enforcement agencies. Acting upon the alert, the Kanpur Cyber Cell traced the accused through the email account, IP address, and IMEI number of the mobile device allegedly used to create the content, leading to his arrest. Police are presently investigating whether the videos remained confined to the cloud account or had been shared further.

 

While the allegations in the case are deeply disturbing and are currently subject to judicial proceedings, the incident has generated a larger constitutional and technological debate:

 

If Google Drive is encrypted, how did Google detect the content? Can technology companies access our private files? Does such access violate the Right to Privacy under Article 21 of the Constitution? Or is it a necessary tool to prevent serious crimes?

 

The Kanpur case is therefore not merely about one criminal prosecution — it represents a critical discussion on the evolving relationship between privacy, technology, and public safety.


Privacy: A Fundamental Right Under Article 21


Privacy occupies a central place in Indian constitutional jurisprudence. In the landmark judgment of Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1, a unanimous nine-judge Constitution Bench of the Supreme Court unequivocally held that the Right to Privacy is a Fundamental Right protected under Article 21 of the Constitution of India. The Court recognised privacy as intrinsic to the rights to life and personal liberty and as an indispensable facet of individual dignity, autonomy, and liberty.

The Court observed that privacy is a broad and multifaceted concept encompassing several interrelated dimensions, including:

  • personal liberty;

  • human dignity;

  • bodily and mental integrity;

  • decisional autonomy;

  • informational self-determination; and

  • freedom of choice.

 

Recognising the realities of the digital age, the Supreme Court underscored that informational privacy has assumed particular significance in an era where individuals routinely create, store, and share vast amounts of personal information through digital platforms. Medical records, financial information, legal documents, photographs, emails, and confidential communications are increasingly entrusted to cloud service providers, giving rise to a legitimate expectation that such information will remain secure and protected from arbitrary interference.

 

While affirming privacy as a fundamental right, the Court was equally clear that the right is not absolute. Justice D.Y. Chandrachud, speaking for the majority, observed that any restriction on the right to privacy must satisfy a constitutional standard comprising:

  • legality, requiring the existence of a valid law;

  • a legitimate State aim; and

  • proportionality, ensuring a rational nexus between the object sought to be achieved and the means adopted to achieve it.

 

The Court emphasised that any invasion of privacy must be justified by law, pursue a legitimate governmental objective, and employ measures that are proportionate to that objective so that individual liberty is not restricted more than is necessary. (Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1).

 

These constitutional safeguards were reaffirmed by the Constitution Bench in K.S. Puttaswamy v. Union of India, (2019) 1 SCC 1, (Aadhaar Judgement) where the Supreme Court reiterated that any interference with informational privacy must satisfy the tests of legality, legitimate State purpose, proportionality, and adequate procedural safeguards against arbitrary or excessive exercise of power. The Court recognised that although the State may collect or process personal data for legitimate purposes, such measures must remain narrowly tailored and subject to constitutional scrutiny.

 

These principles continue to provide the constitutional framework for evaluating digital surveillance, intermediary obligations, automated content detection, and the processing of personal data in India. Consequently, the legal issues arising from the Kanpur Google Drive case must be examined through this constitutional lens, ensuring that efforts to detect and prevent illicit online content remain lawful, proportionate, transparent, and respectful of the fundamental right to privacy.


Applicability of the Digital Personal Data Protection Act, 2023 to Google

 

The Digital Personal Data Protection Act, 2023 (DPDP Act) applies to the processing of digital personal data by entities that determine the purpose and means of such processing, referred to as Data Fiduciaries under the Act. In the context of cloud storage services, Google acts as a Data Fiduciary insofar as it collects, stores, organises, retrieves, and otherwise processes the personal data uploaded by users to Google Drive.


Under Section 4 of the DPDP Act, personal data may only be processed in accordance with the provisions of the Act and for a lawful purpose. Consequently, Google cannot access, process, or disclose a user's personal data arbitrarily. Every act of processing must have a legal basis under the Act.

 

Further, Section 8 imposes a statutory obligation upon every Data Fiduciary to implement appropriate technical and organisational measures to ensure compliance with the Act and to adopt reasonable security safeguards to prevent personal data breaches. In practical terms, this requires Google to secure user data through measures such as encryption, robust cybersecurity systems, access controls, and continuous monitoring against unauthorised access.

 

At the same time, the Act does not prohibit all processing of personal data. Section 7 recognises certain legitimate uses where personal data may be processed without obtaining fresh consent. Additionally, where another law requires or authorises processing or disclosure of information, compliance with such legal obligations is not inconsistent with the DPDP Act. Therefore, the Act recognises that privacy rights must coexist with legitimate legal obligations and public interest considerations.

 

Applying these principles to the Kanpur Google Drive case, the mere fact that Google's automated systems reportedly detected suspected child sexual abuse material does not, by itself, establish a violation of the user's right to privacy. The crucial legal question is how that detection occurred.

 

If the detection resulted from automated security mechanisms deployed as part of Google's legitimate processing activities such as maintaining platform security, preventing misuse of its services, or complying with legal obligations such processing is capable of being justified within the statutory framework, provided it remains lawful, proportionate, and limited to the purpose for which it is undertaken.

 

However, the DPDP Act does not authorise indiscriminate surveillance or unrestricted monitoring of users' private data. Google's obligations under the Act are accompanied by corresponding duties to ensure transparency, accountability, and the implementation of reasonable security safeguards. Any processing beyond what is necessary for legitimate purposes or authorised by law would remain subject to scrutiny under both the DPDP Act and the constitutional guarantee of privacy recognised under Article 21.

 

Accordingly, the Kanpur case does not raise the question of whether Google may ever process users' data; rather, it raises the more nuanced constitutional and statutory question of whether the manner, purpose, and extent of such processing satisfy the requirements of the DPDP Act and the proportionality principles laid down in Justice K.S. Puttaswamy (Retd.) v. Union of India.


If Google Drive Is Encrypted, How Could Google Detect Illegal Content?

 

As discussed above, the legality of Google's processing of users' data depends upon the nature, purpose, and extent of such processing. To assess whether Google's actions in the Kanpur case could be legally justified, it is first necessary to understand how Google Drive's encryption architecture actually functions. A proper understanding of the underlying technology is essential before examining whether automated detection of illicit content is compatible with the right to privacy.

 

One of the biggest questions raised by the Kanpur Google Drive case was:


"If my Google Drive is encrypted, how could Google detect what I uploaded? Doesn't encryption mean that even Google cannot access my files?"

 

The answer lies in understanding the distinction between cloud encryption and end-to-end encryption.

 

  1. Understanding Cloud Encryption

 

Google Drive encrypts users' files both while they are being transmitted over the internet (encryption in transit) and while they are stored on Google's servers (encryption at rest). This protects users' data from hackers and other unauthorised third parties.

 

However, for standard Google Drive accounts, Google manages the encryption keys. This allows Google's systems to decrypt files when necessary to provide services such as synchronisation, document previews, malware detection, and compliance with lawful obligations.

 

  1. Cloud Encryption vs. End-to-End Encryption

 

A useful analogy is that of a bank locker. While your valuables remain securely locked, the bank retains a controlled mechanism for authorised access. Similarly, Google Drive protects users' data from outsiders but retains the technical capability to process stored files when required for legitimate operational or legal purposes.

 

This differs from end-to-end encryption (E2EE), where only the sender and the intended recipient possess the encryption keys. Messaging platforms such as WhatsApp and Signal use E2EE for messages, meaning that even the service provider cannot ordinarily read the content of those communications.

 

Google Drive functions differently because it is a cloud storage service. Features such as document previews, real-time collaboration, file synchronisation, account recovery, and malware detection require Google's systems to process stored data. Consequently, Google manages the encryption keys for standard Google Drive accounts, enabling these features to function.

 

Accordingly, while encryption protects users' data from unauthorised access, it does not necessarily mean that the service provider is technically incapable of accessing or processing the data where required for legitimate purposes.


What Actually Happened in the Kanpur Google Drive Case?

 

Following the Kanpur case, a common misconception was that Google employees had manually accessed and reviewed the user's Google Drive account. However, the publicly available reports do not support this conclusion.

 

According to media reports, Google's automated child safety systems detected suspected Child Sexual Abuse Material (CSAM) stored in the user's Google Drive account. There is no public indication that Google employees manually searched or routinely monitored the contents of the account before the matter was reported.

 

Most large technology companies rely primarily on automated detection technologies to identify suspected illegal content rather than human review. Such systems are designed to detect known child sexual abuse material and other serious abuses while minimising unnecessary human access to users' private data.

 

Based on publicly available information, the sequence of events appears to have been as follows:

The suspected illegal content was uploaded to Google Drive.

  1. Google's automated child safety system detected the suspected CSAM.

  2. Google suspended the user's account.

  3. Google reported the matter to the National Center for Missing & Exploited Children (NCMEC), as required under applicable U.S. law.

  4. NCMEC subsequently shared the information with Indian law enforcement authorities.

  5. Acting on the alert, the Kanpur Cyber Cell traced the accused using technical evidence, including the email account, IP address, and the IMEI number of the mobile device allegedly used to record the videos.

  6. Criminal proceedings were initiated under the Bharatiya Nyaya Sanhita (BNS) and the Protection of Children from Sexual Offences (POCSO) Act.

 

The publicly available reports therefore suggest that the investigation was triggered by Google's automated detection mechanisms, rather than by routine manual examination of users' private files. This distinction is significant, as it helps separate automated content detection designed to prevent serious criminal activity from the misconception that cloud service providers routinely monitor every file uploaded by their users.

 

Drawing the Constitutional Balance

 

The Kanpur case demonstrates that the debate should not be framed as privacy versus security.

 

Both are indispensable constitutional values.

 

The Right to Privacy protects ordinary citizens against arbitrary intrusion into their personal lives. At the same time, privacy cannot be interpreted as a legal shield for storing or distributing child sexual abuse material or other serious criminal content.

 

The constitutional challenge therefore lies in ensuring that technological measures remain:

  • authorised by law;

  • directed towards a legitimate public purpose;

  • proportionate to the objective;

  • transparent; and

  • accompanied by meaningful safeguards against misuse.

 

Equally, technology companies must ensure that automated detection systems remain narrowly tailored to serious unlawful content and do not evolve into instruments of indiscriminate mass surveillance.

 

Conclusion

 

The Kanpur Google Drive case illustrates the complex intersection of technology, privacy, and law in the digital age. While the incident arose from the detection of suspected child sexual abuse material, it has also prompted broader questions about the extent to which cloud service providers can process users' data without infringing the constitutional right to privacy.

 

The case demonstrates that encryption and privacy are not synonymous with absolute secrecy. Cloud storage services such as Google Drive are designed not only to safeguard users' data against unauthorised access but also to maintain the security and integrity of their platforms through legitimate technological measures. At the same time, the existence of such capabilities does not grant technology companies unfettered authority to monitor or access users' private information.

 

Ultimately, the Kanpur Google Drive case is not merely about one criminal investigation. It reflects the growing challenge of ensuring that digital platforms remain safe without compromising the constitutional promise of privacy. As cloud technologies continue to evolve, the law must ensure that the detection of serious criminal content remains lawful, transparent, proportionate, and subject to appropriate safeguards. The true constitutional challenge lies not in choosing between privacy and security, but in ensuring that both are protected in equal measure.

 

Recent Posts

See All
bottom of page