Anantam IASPost · 9 June 2026

Data Colonialism: The New Resource Extraction of the Digital Age (UPSC GS2/Economy)

Study Notes · General Studies · GS II · Indian Society · International Relations

Coined by Nick Couldry and Ulises Mejias, data colonialism describes how a handful of US and Chinese tech giants extract human life as data the way old empires seized land and labour. Here is the full picture — the core analogy, the Global South's stakes, and India's sovereignty response through data localisation, the DPDP Act and Digital Public Infrastructure — explained for UPSC GS2.

In the language of a hundred-year-old debate, the most valuable thing a country could own was its land, its mines and the labour of its people. Empires were built by sailing across the world to take those things from someone else. The argument that has crept into trade summits, parliamentary committees and tech-policy seminars over the last few years is that something very similar is happening again — except the resource being shipped out is not cotton or coal but you. The pattern of your purchases, the map of your movements, the words you type and the face you scan to unlock a phone are being harvested at planetary scale by a handful of companies, refined into prediction and sold back to the world. The British sociologist Nick Couldry and the Mexican-American scholar Ulises Mejias gave that pattern a deliberately provocative name: data colonialism.

The phrase matters for an aspirant because it is no longer a fringe academic idea. It now sits underneath real policy fights — over where data must be stored, who may move it across borders, and whether a country can run its digital life without depending on servers it does not control. For India, a nation of more than a billion data-generating citizens that is also building its own homegrown digital rails, the question is sharp and immediate: is India a supplier of raw data to foreign tech empires, or the owner of a strategic national resource? That single tension runs through governance, the economy and international relations, and it is the thread this article follows.

What Data Colonialism Actually Means

Start with the analogy, because the whole concept lives or dies on it. When Couldry and Mejias published their work in 2019, including the book The Costs of Connection, they argued that the data economy is not just a new business model but a new stage of an old process. Historical colonialism appropriated land, natural resources and human labour, and dressed that appropriation up as progress and civilisation. Data colonialism, in their telling, appropriates human life itself — converted into the abstract, tradeable form of data — and dresses it up as connection, convenience and free services. The key move is that they are not saying the data economy is like colonialism as a loose metaphor. They are saying it performs the same underlying function: the large-scale capture of a resource that someone else generates, with the value flowing to a small elite.

What makes the data a resource at all is a process the authors call data relations. Almost every ordinary act of modern life — searching, scrolling, paying, messaging, driving with navigation on — now throws off a stream of data as a by-product. Platforms are designed so that this conversion of life into data feels natural and unavoidable, the price of taking part in society. And because the raw material is generated by users for free and at colossal volume, the cost of acquiring it is close to zero. This is the cheap-data frontier — the digital equivalent of the open land that colonial powers treated as there for the taking. The person generating the data rarely owns it, rarely understands its worth, and almost never shares in the profit.

Crucially, this is not a worldwide free-for-all with everyone on equal terms. The companies that dominate the harvest are concentrated in just two countries — the United States and, increasingly, China. A short list of firms, sometimes called data empires, controls the search engines, social networks, app stores, cloud servers and now the artificial-intelligence models through which most of the world’s data passes. The rest of the planet, and the Global South in particular, tends to occupy a familiar colonial-era role: it supplies the raw material — the behaviour, the faces, the languages, the clicks of billions of people — but does not own the refineries, set the prices or capture the bulk of the value. It is a data supplier and an AI consumer, not a data owner.

A two-column comparison contrasting historical colonialism, which extracted land, raw materials and labour from colonies, with data colonialism, which extracts human life as data from users worldwide
The same pattern, a new resource: where empires once took land and labour, data empires now take the daily flow of human life as data.
A timeline of India's data-sovereignty measures, from the RBI's 2018 payment-data localisation circular through the Digital Personal Data Protection Act 2023 to the spread of Digital Public Infrastructure
India’s answer in stages: from localising payment data to legislating data protection to exporting its own digital rails.
A data-centre server rack with rows of drives and blinking green lights
The servers and cloud where the world’s data is stored — and controlled. Photo: Domaintechnik / Unsplash

Why the Global South Worries — and What’s at Stake

The reason this framing has caught on in development circles is that the economic stakes are concrete, not philosophical. Think about where value is captured in the data economy. The data is generated everywhere, but it is processed, stored and monetised in a handful of places — overwhelmingly in the data centres of a few American and Chinese firms. The physical infrastructure tells the same story: the world’s internet traffic runs through undersea cables increasingly financed and owned by the same tech giants, and the cloud market that stores humanity’s data is concentrated in barely three or four corporate hands. So even as a country’s citizens produce vast quantities of data, the jobs, the profits, the cutting-edge research and the taxable economic activity tend to migrate to where the servers and the engineers are. The data flows out cheap and comes back expensive, packaged as a paid service or a subscription.

Artificial intelligence has sharpened this enormously. The large AI models now reshaping the economy are trained on staggering quantities of text, images, voices and labelled examples — much of it scraped or sourced from across the world, including from Global South languages and communities, often without consent or compensation. A worker in Kenya or India may be paid a few dollars an hour to label the data that trains a model worth billions, a pattern critics call the new digital plantation. The finished model is then sold back into those same markets. This is the asymmetry at the heart of the worry: the Global South furnishes the training data and the cheap labour but owns neither the model nor the profit, deepening rather than closing the digital divide between data-rich economies and data-poor ones.

This is also why data has become a live issue in trade diplomacy. At the World Trade Organization and in modern free-trade agreements, the United States and other developed economies have pushed for binding rules guaranteeing the free flow of data across borders and banning mandatory data localisation — the requirement that data be stored within a country. Wealthy economies frame this as keeping the internet open and frictionless. Many developing countries, India among them, have resisted, arguing that signing away the right to govern their own data is like a nineteenth-century colony agreeing never to process its own raw materials at home. They want what is sometimes called policy space: the freedom to decide where data lives, who can move it, and on what terms — the digital version of the right to industrialise rather than stay a permanent exporter of raw inputs.

India’s Answer: Localisation, the DPDP Act and Digital Sovereignty

India has not just complained about data colonialism in the abstract; it has built a layered policy response, and you can trace it through clear milestones. The first big move came from the central bank. In April 2018, the Reserve Bank of India issued its payment-data localisation directive, requiring that the entire data relating to payment systems — full end-to-end transaction details for operators such as Visa, Mastercard and the major digital-payment firms — be stored only on servers inside India. Processing abroad was allowed, but the data had to be brought back and any foreign copy deleted within 24 hours. The RBI’s stated reasoning was supervisory access and security: regulators needed unfettered access to payment data, and that data needed to sit under Indian law rather than in someone else’s jurisdiction. It was, in plain terms, an early assertion of data sovereignty over the country’s financial nervous system.

The legislative arc took longer and is worth getting right, because the details are examinable. India’s first attempt, the Personal Data Protection Bill introduced in 2019, leaned hard toward localisation — it proposed that certain categories of sensitive and critical personal data be kept within the country. That bill was eventually withdrawn in 2022 after years of debate, and replaced by the slimmer Digital Personal Data Protection Act, or DPDP Act, passed in 2023. The DPDP Act took a notably more open stance on cross-border flows. Rather than mandating that data stay in India, it adopted what lawyers call a negative-list or blacklist model: personal data may, by default, be transferred to any country, except to jurisdictions the central government specifically notifies as off-limits. That is the mirror image of Europe’s approach, which permits transfers only to countries it has positively approved. The Act does leave a sovereignty backstop — the government can still require that certain data, handled by the largest entities it designates as Significant Data Fiduciaries, be processed only in India — but the overall posture shifted from “keep it home” toward “let it flow, unless we say otherwise.”

Sitting above these rules is a broader idea the government keeps returning to: that data generated by Indians should ultimately be owned by, and benefit, Indians. This is digital sovereignty — a nation’s claim to govern the data, infrastructure and digital activity within its borders, rather than ceding that control to foreign platforms. It is the same impulse that drives data-localisation arguments worldwide and feeds the so-called splinternet, the gradual fragmenting of one global internet into national or bloc-level zones with their own rules. India’s challenge, and the reason its policy looks like a balancing act rather than a wall, is that it wants the benefits of global digital trade and foreign investment without surrendering control of its citizens’ data. The DPDP Act’s flexible stance is precisely that compromise — sovereignty held in reserve, not slammed down as a blanket barrier.

Digital Public Infrastructure: India’s Constructive Counter-Model

Localisation and data-protection law are the defensive half of India’s answer. The more interesting, constructive half is that India has tried to build an alternative to platform dependency rather than merely fence itself off from it. That alternative is Digital Public Infrastructure, or DPI — and the flagship example is India Stack, the layered set of open, public digital systems that includes the Aadhaar digital identity, the Unified Payments Interface for instant payments, and consent-based data-sharing and document layers such as DigiLocker. The crucial design choice is that these are run as public utilities on open standards, not as the private property of a foreign corporation. When a citizen pays through UPI, the rails belong to a public ecosystem governed under Indian rules, not to a Silicon Valley payment giant extracting fees and data. The argument is that DPI lets a country capture the convenience of digital platforms while keeping ownership and governance at home — sovereignty by construction rather than by prohibition.

This is why India has pushed DPI so hard on the world stage, including during its G20 presidency, as a template for the Global South. The pitch is pointed: instead of every developing country renting its digital backbone from a US or Chinese firm and exporting its citizens’ data in the bargain, it can adopt open, locally governed infrastructure. Elements of the India Stack model have already travelled — the Modular Open Source Identity Platform, MOSIP, born from the Aadhaar experience, is now used by more than twenty countries across Africa and Asia to run their own identity systems. Analysts increasingly describe this as a postcolonial alternative: a Global South nation modelling digital sovereignty for others, rather than the North dictating the terms. It does not abolish the risks — concentration, exclusion and surveillance can occur within public systems too, and critics rightly press on Aadhaar’s privacy record — but it reframes the choice. The question stops being “which foreign platform do we depend on?” and becomes “can we own our own rails?”

For India, then, the response to data colonialism has two engines working together. One is governance and law — localisation directives, a data-protection statute, and a reserved power to restrict cross-border flows — which sets the rules of the game. The other is infrastructure — DPI and India Stack — which changes the game itself by giving citizens and the state a homegrown system to use in the first place. Neither alone is sufficient, and both carry real trade-offs between openness and control. But together they represent the most developed attempt by any large developing economy to answer the colonial analogy with something other than resignation: not just to resist extraction, but to build the refinery at home.

Data Colonialism — key ideas at a glance

For Your Mains Answer

This is a high-value, genuinely cross-cutting topic. Its natural home is GS Paper 2 — governance (e-governance, the role of the state in the digital economy), and international relations (the politics of global data flows, the WTO, and India’s leadership in the Global South). It also reaches into GS Paper 3 on the economy (mobilisation of resources, the digital economy, the asymmetry of value capture) and on science and technology and data security. And it is rich material for the Essay paper on themes of sovereignty, technology and development. The skill examiners reward here is conceptual command: explain the analogy precisely, show you understand both its force and its limits, and then ground it in India’s concrete policy response.

How to Build the Answer

Open by defining the concept cleanly — Couldry and Mejias, the extraction of human life as data echoing the colonial appropriation of land and labour — and resist the urge to sound alarmist. Then move in a logical chain: what data colonialism is, why the Global South loses out (value capture, AI training-data extraction, the digital divide, asymmetric data flows), how it plays out in trade rules (the WTO push for free data flows versus localisation), and finally India’s two-part response — governance (RBI 2018, the DPDP Act 2023) and infrastructure (DPI and India Stack as a sovereignty model). Close by weighing the openness-versus-control trade-off rather than declaring a winner. That arc — define, diagnose, contextualise, respond, evaluate — fits almost any question on digital sovereignty or the data economy.

Common Mistakes to Avoid

Do not frame this as a security-and-surveillance scare story — the analytical core is economic and developmental, about who owns a resource and who captures its value. Do not claim the DPDP Act 2023 mandates strict data localisation; it does the opposite, defaulting to free cross-border transfer under a negative-list model, with localisation held only as a reserved power. Do not present digital sovereignty as a simple good — over-strict localisation can fragment the internet, raise costs and deter investment, so always note the trade-off. And do not treat data colonialism as settled fact; flag that it is an influential framework with critics, which is exactly the nuance that earns marks.

A Compact Answer Spine

Data colonialism (Couldry & Mejias, 2019) = extraction of human life as data, echoing colonial seizure of land and labour → resource generated everywhere, refined and monetised by a few US/Chinese data empires → Global South as data supplier and AI consumer, not owner: value capture, cheap AI training labour, widening digital divide → contested in trade rules (WTO free-flow push vs localisation) → India’s response: governance (RBI 2018 payment localisation; PDP Bill 2019 → DPDP Act 2023, negative-list cross-border model, SDF localisation backstop) + infrastructure (DPI / India Stack — UPI, Aadhaar, MOSIP — as a sovereignty model for the Global South) → verdict: balance openness with sovereignty; build the refinery at home rather than ban the trade.

Diagram or Flowchart Idea

Draw a simple two-column “before/after” — left column “Old colonialism: land · raw materials · labour → value to empire”; right column “Data colonialism: behaviour · faces · clicks → value to data empires” — with an arrow from a Global South box to a small cluster of US/China platforms. Beside it, sketch a short India-response ladder: RBI 2018 → DPDP Act 2023 → DPI / India Stack. The parallel plus the ladder communicates the whole answer at a glance.

A Balanced-Conclusion Line

A line that lands the marks: “If data is the new resource being extracted from the Global South, India’s reply is neither to wall itself off nor to surrender the flow, but to write its own rules and build its own rails — answering the colonial analogy by trying to own the refinery rather than merely export the ore.”

How to Use Data Without Cramming

You need only a few anchors, not a reading list: the concept’s authors (Couldry and Mejias, 2019), the RBI’s 2018 payment-data localisation rule (storage in India, 24-hour return), the DPDP Act 2023 (negative-list cross-border transfers), and one travelling-DPI fact (MOSIP adopted in 20-plus countries). Attribute them plainly in prose — “as Couldry and Mejias argued” — rather than scattering numbers loose.

Frequently Asked Questions

What is data colonialism in simple terms?

Data colonialism is a concept coined by Nick Couldry and Ulises Mejias around 2019 to describe how the large-scale extraction of human life as data — your searches, locations, faces, purchases and messages — mirrors the way old empires extracted land, raw materials and labour from colonies. A small number of mostly US and Chinese tech firms harvest this data cheaply from users worldwide, refine it into prediction and sell it back, with most of the value flowing to a corporate elite while the people generating the data own almost none of it.

How does data colonialism affect the Global South?

The Global South tends to play the supplier’s role: its billions of users generate vast amounts of data and provide cheap labour to label AI training sets, but the data is processed, stored and monetised abroad in the cloud servers of a few firms. So the jobs, profits and cutting-edge research migrate to where the infrastructure is, while developing countries import the finished products. This deepens the digital divide and recreates an asymmetric, extractive relationship between data-rich and data-poor economies.

What is India doing to assert data sovereignty?

India has a two-part response. On governance, the RBI’s 2018 directive requires payment-system data to be stored in India, and the Digital Personal Data Protection Act 2023 governs how personal data is handled — defaulting to free cross-border transfers except to countries the government blacklists, while keeping a reserved power to require localisation for the largest data handlers. On infrastructure, India has built Digital Public Infrastructure — India Stack, including Aadhaar, UPI and DigiLocker — as publicly governed, open-standard rails that reduce dependence on foreign platforms and which it now promotes across the Global South.

Does the DPDP Act 2023 require data to stay in India?

No, not as a general rule. The DPDP Act 2023 takes a relatively open, negative-list approach: personal data may by default be transferred to any country, except to specific jurisdictions the central government notifies as restricted. This is the opposite of a blanket localisation mandate, and it differs from Europe’s whitelist model. The Act does, however, let the government require that certain data handled by designated Significant Data Fiduciaries be processed only in India — a sovereignty backstop rather than a default.

Practice Questions

Prelims MCQs

  1. The concept of “data colonialism” is most closely associated with which of the following?
    (a) The free flow of data guaranteed under WTO rules
    (b) The argument that large-scale extraction of human life as data echoes the colonial appropriation of land and labour
    (c) A mandatory data-localisation treaty signed by developing countries
    (d) The technical standard for undersea internet cables
    Answer: (b) The term, coined by Nick Couldry and Ulises Mejias, argues that harvesting data at scale mirrors historical colonial extraction of land, resources and labour.
  2. The Reserve Bank of India’s 2018 directive on payment-system data required that such data be
    (a) shared freely with global payment networks
    (b) stored only on servers located in India
    (c) encrypted and sent abroad for processing permanently
    (d) deleted entirely after each transaction
    Answer: (b) The April 2018 RBI directive mandated storage of full payment-system data in India, allowing processing abroad only if the data was returned within 24 hours and foreign copies deleted.
  3. With reference to the Digital Personal Data Protection Act, 2023, which statement about cross-border data transfer is correct?
    (a) It mandates that all personal data be stored within India
    (b) It permits transfers only to countries positively approved by the government
    (c) It permits transfers by default, except to jurisdictions the government specifically restricts
    (d) It bans all cross-border transfer of personal data
    Answer: (c) The DPDP Act 2023 adopts a negative-list or blacklist model — transfers are allowed by default unless the central government notifies a jurisdiction as restricted.
  4. “India Stack” refers to
    (a) India’s foreign-exchange and gold reserves
    (b) a layered set of open Digital Public Infrastructure including Aadhaar, UPI and DigiLocker
    (c) India’s stockpile of strategic petroleum reserves
    (d) a stack of trade agreements at the WTO
    Answer: (b) India Stack is the suite of open, publicly governed digital systems — digital identity, instant payments and consent-based data sharing — cited as a model of data sovereignty.
  5. The Modular Open Source Identity Platform (MOSIP), associated with India’s digital-identity experience, is significant because it
    (a) is owned by a US technology firm
    (b) has been adopted by more than twenty countries to run their own identity systems
    (c) replaces the WTO’s data-flow rules
    (d) mandates data localisation globally
    Answer: (b) MOSIP, derived from the Aadhaar experience, is open-source identity infrastructure now used by more than twenty countries, illustrating DPI as a Global South sovereignty model.

Mains Practice Questions

  1. “Data colonialism describes the extraction of human life as data, echoing the colonial appropriation of land and labour.” Critically examine this framework and assess its relevance to the Global South. (15 marks, 250 words)
  2. Examine how the asymmetry in the global data economy — in value capture, AI training-data extraction and infrastructure ownership — affects developing countries. What policy options are available to India? (15 marks, 250 words)
  3. Discuss the evolution of India’s data-governance regime from the RBI’s 2018 payment-data localisation directive to the Digital Personal Data Protection Act, 2023. How does India balance digital sovereignty with the benefits of open data flows? (15 marks, 250 words)
  4. “Digital Public Infrastructure is India’s constructive answer to platform dependency.” Analyse, with examples, how India Stack functions as a model of data sovereignty for the Global South. (10 marks, 150 words)
  5. The push for free cross-border data flows at the WTO is contested by many developing economies. Evaluate the arguments for and against mandatory data localisation in the context of the data-colonialism debate. (15 marks, 250 words)