Data sovereignty is the freedom of the 21st-century citizen
Subtopic: Economy · Data sovereignty, digital public infrastructure and rights
How to structure your answer
Introduction (80-120 words): Open with Justice K S Puttaswamy v Union of India (24 August 2017) — privacy declared a fundamental right under Articles 14, 19, 21. Six years later, the DPDP Act 2023 set the architecture; in 2025, the Draft DPDP Rules clarified consent managers, age verification and the Data Protection Board. Thesis: data sovereignty — over the individual's data, the nation's data layers, and the global rules of data flow — is the new dimension of citizen freedom. A republic that does not control its data layers is, partially, governed from elsewhere.
Body — Argument 1 (~200w): Individual sovereignty. DPDP Act 2023 — purpose limitation, consent (Section 6), right to access/correction/erasure, Data Protection Board. India's DigiLocker, ABDM, Aadhaar-e-KYC as user-controlled rails. Section 17 sectoral exemptions.
Argument 2 (~200w): Sectoral sovereignty. Digital Public Infrastructure (DPI): UPI processing 17 billion+ transactions per month (NPCI March 2025); ONDC for commerce; OCEN for credit; AgriStack; Account Aggregator framework. The DPI Stack as world's most exported open digital scaffold.
Argument 3 (~200w): Global sovereignty. India's data-localisation debates (RBI 2018 payments-data circular); 2024-25 negotiations at WTO Joint Statement Initiative on e-commerce; the BRICS Cross-Border Data Framework proposal; the EU's GDPR adequacy assessment. Submarine cable security as data sovereignty.
Counter-view (~150w): Excessive data-localisation balkanises the internet and raises cost; small economies cannot afford parallel cloud infrastructure. The balance must be risk-based — sensitive personal data localised, business data interoperable.
Conclusion (~100w): Justice D Y Chandrachud in Puttaswamy: 'Privacy is the constitutional core of human dignity.' Data sovereignty is dignity at scale. The 21st-century citizen is free only to the extent that her data is hers, her nation's stack is sovereign, and her global voice in data norms is heard.
Written within the word limit
1128 words · target 1150 words · 85 min
On 24 August 2017, a nine-judge bench of the Supreme Court of India in Justice K S Puttaswamy v Union of India unanimously declared the right to privacy a fundamental right, flowing through Articles 14, 19 and 21. The judgment ran to over 500 pages. Its consequences are still unfolding. Six years later, the Digital Personal Data Protection Act 2023 set the architecture; the Draft DPDP Rules of January 2025 clarified consent managers, age verification and the Data Protection Board. But these statutes belong to a larger frame. Data sovereignty — over the individual's data, the nation's data layers, and the global rules of cross-border data flow — is the freedom of the 21st-century citizen. A republic that does not control its data layers is, partially, governed from elsewhere. To be free in the digital era is to be sovereign at three nested scales.
The first scale is individual. The DPDP Act 2023 embeds purpose limitation, data minimisation, the principle of notice and consent (Section 6), and the rights of the data principal — access, correction, erasure, grievance redress. The Data Protection Board, once fully operational, will adjudicate breaches and impose penalties up to 250 crore rupees. Children's data receives enhanced protection through age-verification and parental-consent requirements. India's existing rails strengthen individual sovereignty in practice: DigiLocker hosts over 600 crore documents owned by the citizen; the Ayushman Bharat Digital Mission gives every Indian a 14-digit health ID under user control; Aadhaar e-KYC enables consent-based identity verification without surrendering the underlying document. Section 17 of the DPDP Act provides for sectoral exemptions, which civil society watches carefully — exemptions, broad enough, can swallow the rule. The proposed Consent Manager framework under Section 7, modelled on Account Aggregators, will let citizens grant and revoke granular permissions through a single interface.
The second scale is sectoral and infrastructural. India's Digital Public Infrastructure has become the world's most-exported open digital scaffold. The Unified Payments Interface processed over 17 billion transactions in a single month in March 2025, a global record; it now interoperates with payment systems in Singapore, the UAE, France, Sri Lanka and Bhutan. The Open Network for Digital Commerce, launched in April 2022, breaks the closed-app model of e-commerce by separating buyers, sellers and logistics on open protocols. The Open Credit Enablement Network democratises lending decisions. The Account Aggregator framework, launched by the RBI in 2021, lets users share financial data across institutions with explicit consent — 90 crore consent-enabled accounts as of mid-2025. AgriStack maps farmer data for crop insurance, credit and advisory. The Ayushman Bharat Digital Mission, the National Logistics Portal and the e-Vidhan initiative add further layers. The DPI Stack is exported actively — to Trinidad and Tobago, Sri Lanka, the Philippines, Mongolia, Morocco and most recently Papua New Guinea under the India Stack diplomacy. Each export is a node of sectoral sovereignty for a developing economy that would otherwise depend on closed foreign platforms.
The third scale is global. India's data-localisation debates began with the Reserve Bank of India's circular of 6 April 2018 requiring storage of payment system data within India. The Srikrishna Committee's draft Personal Data Protection Bill 2018 proposed broader localisation; the 2019 Bill softened it; the DPDP Act 2023 takes a flexibility approach — the central government may by notification specify countries to which transfers are restricted. At the World Trade Organization, the Joint Statement Initiative on e-commerce continues to negotiate cross-border data flow rules; India has been a careful participant, balancing trade liberalisation against policy space. The BRICS Cross-Border Data Framework proposal of 2024 attempts an alternative to United States-led free-flow norms and Chinese localisation maximalism. The European Union's GDPR adequacy assessment for India remains pending — an external recognition that data-protection law is comparable. The 2025 strategic concern is submarine cable security: 95 per cent of intercontinental data traffic flows through under-sea cables vulnerable to physical and digital attack. The Indian government's 2024 Telecommunications Act and the National Critical Information Infrastructure Protection Centre have begun addressing this dimension.
A serious counter-view must be heard. Excessive data-localisation balkanises the internet and raises costs, particularly for smaller economies that cannot afford parallel cloud infrastructure. An Indian software firm serving European clients needs to move data; a global pharmaceutical company running trials in three continents must aggregate findings. The balance must be risk-based: highly sensitive personal data (health, biometrics, children's data) localised; business and operational data interoperable under strong contractual safeguards. Crude maximalism in either direction — full localisation or full free-flow — fails on its own terms. The European Union's Schrems II ruling of 2020 demonstrated that even within the developed world, cross-border data flow regimes can collapse under privacy scrutiny.
The architecture must respect what the underlying right actually is. Justice D Y Chandrachud, writing the lead opinion in Puttaswamy, located privacy not in a single article but in a constellation: 'Privacy is the constitutional core of human dignity.' Dignity is what the citizen possesses at the centre, not at the State's pleasure. Data is the digital silhouette of personhood. To be in command of one's data is, in 2026, what it once was to be in command of one's body, one's home, one's vote. To be in command of one's national data stack is what it once was for a republic to be in command of its coinage. To be heard in global data-norms is what it once was to be a peer at international treaty tables.
The state itself must be a data-sovereign actor, not merely a data-localisation regulator. Indigenous email platforms for sensitive communication, NIC cloud infrastructure for ministries, BOSS for government computing and Bhashini-powered Indic interfaces reduce dependence on foreign-controlled stacks. The Defence Communication Network and Air Force Net represent the security-sovereignty version of the same principle.
The civil-society dimension is equally important. The Internet Freedom Foundation, the Centre for Internet and Society, the Software Freedom Law Centre and the Vidhi Centre for Legal Policy together provide the technical and legal capacity to scrutinise data legislation in real time. Citizens who understand their data rights are the foundation on which DPDP enforcement will ultimately rest. The Data Protection Board can adjudicate complaints only if complaints are filed; complaints will be filed only if citizens recognise violations.
The implication is clear and demanding. The 21st-century citizen is free only to the extent that her personal data is hers under enforceable law, her nation's digital stack is sovereign and open, and her global voice in data-rule negotiations is heard. The three scales reinforce one another. Strong national DPI gives citizens better individual control; strong individual rights make national DPI legitimate; strong global engagement defends both from external rule-making. India's particular contribution to the world's data politics — open public infrastructure with privacy-respecting law and active multilateral participation — is, on its better days, a coherent model. The republic that follows the model fully will be one whose citizens carry their freedoms not only in their hands but also in their bytes. Data sovereignty is dignity, at scale and at speed.
What an examiner expects to see
- Puttaswamy v Union of India (24 August 2017)
- DPDP Act 2023
- Draft DPDP Rules 2025
- DPI stack — UPI, ONDC, OCEN, AgriStack, AA
- RBI 2018 payments-data localisation circular
- GDPR adequacy assessment
- WTO JSI on e-commerce 2024-25
- DigiLocker, ABDM
- Hindi: 'data praabhuta 21vi sadi ki nagrik swatantrata hai'
Concrete cases, schemes and judgments
- Justice K S Puttaswamy v Union of India (24 August 2017)
- DPDP Act 2023
- UPI — 17 billion+ monthly transactions, March 2025
- ONDC, launched April 2022
- Account Aggregator framework (RBI 2021)
- RBI Storage of Payment System Data circular, 6 April 2018