INTRODUCTION
India is building something without real precedent: an open, interoperable digital infrastructure layer running beneath its entire economy. Aadhaar biometric identity, UPI real-time payments, DigiLocker document vaults, ONDC open commerce, and the Account Aggregator framework together make up what is now called India Stack -a digital public square where over a billion people transact, authenticate themselves, and assert their legal identity every day.
The legal scaffolding around this infrastructure remains contested. Questions about the right to privacy, the scope of data sovereignty under the Digital Personal Data Protection Act 2023, and the balance between state surveillance and individual autonomy sit at the centre of Indian technology law. This piece asks three questions: what obligations attach to Digital Public Infrastructure; whether the DPDP Act meets them; and how India might weigh sovereignty against dignity.[1]
DIGITAL PUBLIC INFRASTRUCTURE AND ITS LEGAL CHARACTER
Digital Public Infrastructure (DPI) refers to shared, open, and interoperable digital systems that underpin public and private services -much like roads or electricity grids do for the physical economy. India’s core pillars are digital identity through Aadhaar (a twelve-digit biometric identifier covering 1.4 billion residents), digital payments through UPI (a real-time payment rail processing over fourteen billion transactions a month), and digital credentials through DigiLocker and the Account Aggregator framework, which let citizens share their own data with third parties on a consent basis.[2]
DPI is also a regulatory architecture: each layer is governed by its own law, including the Aadhaar Act 2016, the Payment and Settlement Systems Act 2007, and the Information Technology Act 2000, alongside sector-specific RBI and SEBI regulation.[3] Its constitutional validity has already been tested. In Puttaswamy v Union of India (Aadhaar), a five-judge Bench upheld the Aadhaar Act four-to-one, while striking down mandatory private-entity authentication, the inclusion of children in the CBSE and NEET databases, and Aadhaar-based SIM verification.[4] Justice Chandrachud, dissenting, took the view that the entire architecture was unconstitutional and enabled mass profiling without adequate safeguards -a position that remains contested but continues to inform debates over mission creep. The proportionality test -legitimate aim, necessity, and proportionality of costs to benefits -has since become the central lens for evaluating DPI legislation.
INDIA STACK: THE CONSENT LAYER AND ITS LIMITATIONS
India Stack, as conceptualised by iSPIRT, is the layered set of open APIs built atop government DPI, enabling private enterprises to build products -loan applications, insurance aggregators, health records platforms -using government-issued identity and consent infrastructure. The Account Aggregator framework is the most legally significant innovation: it lets citizens become data fiduciaries of their own financial information, granting machine-readable, time-bound, purpose-limited consents to lenders -a notable departure from traditional banking relationships.
India Stack’s ingenuity and its primary legal risk both reside in this consent layer. Consent arguably offers weaker protection when it is a precondition for welfare or credit access: a person who cannot obtain a bank loan without authorising extensive data sharing may not be consenting altogether freely, given the pressure of economic necessity. The DPDP Act 2023 addresses this tension through deemed-consent provisions for state purposes, while also exempting government from several of its own obligations.[5] Whether this asymmetry -robust consent duties for private fiduciaries, broader exemptions for the state -is constitutionally legitimate remains an open question before Indian courts.
DATA SOVEREIGNTY: STATE, CITIZEN, AND CORPORATION
Data sovereignty operates at three levels in Indian legal discourse, and conflating them causes confusion. At the state level, India’s data localisation policy -notably the RBI’s 2018 mandate requiring payment data to be stored within Indian territory -reflects a nation-state claim over data as a strategic resource.[6] The DPDP Act 2023 extends this by empowering the Union Government to approve cross-border transfer destinations, a move the US-India Trade Policy Forum has characterised as a non-tariff barrier, leaving the tension between sovereignty and trade liberalisation unresolved.
At the individual level, the nine-judge Bench in Puttaswamy (2017) unanimously held that informational privacy -the right to control one’s own data -is a fundamental right under Article 21, a mandate later given statutory shape in the DPDP Act.[7] The Act grants rights of access, correction, and erasure, but omits a standalone right to data portability and curtails erasure through vague public-interest exceptions. Personal data, on this reading, is constitutive of identity rather than merely an economic resource.
A third dimension concerns large digital intermediaries -foreign platforms such as Meta, Google, and Amazon, and domestic conglomerates such as Reliance Jio. India’s draft Digital Competition Bill 2024, modelled on the EU’s Digital Markets Act, would designate Systemically Significant Digital Enterprises subject to ex-ante interoperability and data-sharing obligations.[8] Whether such mandates disproportionately restrict the Article 19(1)(g) right to carry on business, or are saved as reasonable restrictions under Article 19(6), is a question courts will likely resolve as the Bill progresses.[9]
THE DPDP ACT, 2023: STRENGTHS, GAPS, AND CONSTITUTIONAL QUESTIONS
The Digital Personal Data Protection Act 2023 is India’s first comprehensive data protection law. It establishes a Data Protection Board, mandates purpose limitation, storage limitation, and data minimisation, and creates a consent-based processing regime.[10] Critics, including the Internet Freedom Foundation and members of the Parliamentary Standing Committee, have raised three structural concerns about the Act’s constitutional durability.[11]
First, executive overreach: sections 17 and 36 give the Union Government wide powers to exempt any government entity, any class of data fiduciaries, or any category of data from the Act’s requirements by executive notification. This raises a genuine constitutional question. Parliament’s delegation of the power to define the scope of fundamental-rights protections to the executive, without specific legislative standards, sits uneasily with the non-delegation doctrine and may not survive constitutional scrutiny.
Second, a comparatively limited data protection authority: the Data Protection Board functions mainly as an adjudicatory body rather than a proactive regulator. Unlike data protection authorities under the EU’s General Data Protection Regulation, it does not have express powers to conduct audits, issue binding guidance, or investigate data breaches on its own motion. This may leave violations undetected until an aggrieved individual files a complaint, which could limit the Board’s ability to address systemic data misuse at scale.
Third, the children’s data paradox: section 9, which prohibits tracking and behavioural monitoring of children and requires verifiable parental consent, relies on Aadhaar-based age verification -using a privacy-invasive tool to enforce privacy protection, a circularity that may undercut the provision’s own purpose.
CONCLUSION
India Stack is among the most ambitious state-led digital infrastructure projects in history, and its architecture is a genuine contribution to global digital-governance thinking. India is already exporting this model through the G20 Global DPI Summit, and bilateral agreements across Africa, Southeast Asia, and Latin America, with UPI live in Singapore, the UAE, the UK, France, and Mauritius.[12] This export strategy must include a corresponding legal transplantation strategy: independent oversight and constitutional anchoring in recipient states. The code is neutral; the constitutional commitments embedded in it are not, and cannot be assumed to travel automatically.
To fulfil the constitutional promise of Puttaswamy, three reforms are urgently needed.
First, an independent, proactive Data Protection Authority with suo motu powers -not merely an adjudicatory tribunal.
Second, a sunset clause on executive exemption powers under the DPDP Act, requiring Parliamentary review of any exemption within three years of notification.
Third, a DPI Governance Framework mandating algorithmic impact assessments, mandatory security audits, and public accountability reports for all core DPI components.[13]
Data sovereignty, ultimately, is not a binary choice between citizen, state, and corporation. In a constitutional democracy, data flows must be governed by law, protected by courts, and accountable to the people. The legal architecture has not kept pace with the technical architecture -closing that gap is a constitutional imperative.
Author(s) Name: Yogesh Badgujar (Shri Balaji Law College)
References:
[1] Justice K S Puttaswamy (Retd) v Union of India (2017) 10 SCC 1.
[2] Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016.
[3] Payment and Settlement Systems Act 2007.
[4] Justice K S Puttaswamy (Retd) v Union of India (Aadhaar) (2018) 1 SCC 809.
[5]Digital Personal Data Protection Act 2023.
[6] Reserve Bank of India, ‘Storage of Payment System Data’ (Circular No DPSS.CO.OD.No.2785/06.08.005/2017-18, 6 April 2018) https://rbidocs.rbi.org.in accessed 23 July 2026.
[7]Constitution of India, art 21.
[8] Ministry of Corporate Affairs, Draft Digital Competition Bill 2024 (12 March 2024) < https://pib.gov.in> accessed 23 July 2026.
[9] Constitution of India, arts 19(1)(g), 19(6).
[10]Digital Personal Data Protection Act 2023, ss 8, 10.
[11] Internet Freedom Foundation, Analysis of the Digital Personal Data Protection Act 2023 (August 2023) <https://internetfreedom.in> accessed 23 July 2026.
[12] Ministry of Electronics and Information Technology, Year End Review 2022 (Press Information Bureau, 30 December 2022) <https://www.pib.gov.in > accessed 23 July 2026.
[13] G20, G20 Framework for Systems of Digital Public Infrastructure (New Delhi Leaders’ Declaration, September 2023) <https://www.g20.org> accessed 23 July 2026.

