Associate Professor, Rampur College of Law, Milak, Rampur (U.P.), India
Official Article Landing Page
Sovereign Data, Open Borders: India’s Regulatory Architecture for Digital Governance in 2026
UnivColl International Multidisciplinary Research Journal International Open Access, Peer-reviewed, Refereed Journal
Google Scholar indexing depends on Google Scholar’s crawl schedule. Verify DOI opens the external DOI resolver.
Abstract
In 2026, India’s digital economy stands at a inflection point. With over 900 million internet users and a data-driven economy projected to exceed $1 trillion by 2028, the question of who controls Indian data—and under what conditions it may cross borders—has moved from policy debate to operational reality. This article presents a comprehensive, multi-dimensional analysis of India’s current regulatory architecture for data localisation and digital sovereignty, anchored in the Digital Personal Data Protection Act, 2023 (DPDPA), the draft DPDP Rules, 2025, the constitution of the Data Protection Board of India (2025), and the Supreme Court’s proportionality ruling in Internet Freedom Foundation v. Union of India (2025). It situates India’s approach within a comparative global context, assesses trade-law implications under the WTO and emerging bilateral frameworks, and proposes a flexible, risk-based governance model that reconciles sovereign control with global economic integration. The article argues that India’s future lies not in rigid data walls, but in adaptive, trust-based mechanisms that enable both regulatory autonomy and cross-border innovation. Drawing on constitutional jurisprudence, statutory interpretation, empirical trade data, and international best practices, this study offers a forward-looking blueprint for India’s digital governance in the coming decade.
Official DOI Landing Verification
This is the official published Version of Record. DOI status: Registered.
Authors & Affiliations
Keywords & Indexing Terms
Download Center
Indexing & Verification
Article Metrics
Metrics are indicative and may update periodically after indexing, downloads and citation tracking are enabled.
Article Integrity & Transparency
License & Copyright
© 2026 The Author(s). The author(s) retain copyright and grant the journal the right of first publication. This work is licensed under the Creative Commons Attribution-NonCommercial 4.0 International License .
How to Cite
Singh, M. (2026). Sovereign Data, Open Borders: India’s Regulatory Architecture for Digital Governance in 2026. UnivColl International Multidisciplinary Research Journal, 2(8), 8-31. https://doi.org/10.65919/uimrj.2026.v2i8002
PDF Preview
If the PDF preview does not load on your device, open the PDF directly or use the Download PDF button. Open PDF in new tab
Declarations
Funding
No external funding information has been declared unless stated in the published PDF.
Conflict of Interest
The authors declare no conflict of interest unless otherwise stated in the article.
Ethical Approval
Ethical approval status is as per the article and journal policy.
Data Availability
Data availability is as declared by the author(s) in the published article.
Author Contributions
Author contributions are recorded as per submitted manuscript and editorial records.
AI-use Declaration
AI-use declaration is governed by journal policy and author disclosure.
Publisher's Note
- ✓ The views, opinions and conclusions expressed in this article are solely those of the author(s).
- ✓ Publication of this article does not imply endorsement by UIMRJ, the editorial board or the publisher.
- ✓ Responsibility for the accuracy, originality and integrity of the work remains with the author(s).
- ✓ Readers are encouraged to independently evaluate and verify the information before application or citation.
- ✓ UIMRJ and UnivColl Publications shall not be held liable for any consequences arising from the use of the published content.
References
Showing first 3 references. Click “Show All References” to view complete list.
- 1. Justice K.S. Puttaswamy (Retd.) v. Union of India (2017) 10 SCC 1.
- 2. Internet Freedom Foundation v. Union of India (2025) SC, Writ Petition (Civil) No. 123/2024.
- 3. Anuradha Bhasin v. Union of India (2020) 3 SCC 637.
- 4. Ministry of Electronics and Information Technology (MeitY). (2023). Digital Personal Data Protection Act, 2023. Government of India.
- 5. Ministry of Electronics and Information Technology (MeitY). (2025). Draft Digital Personal Data Protection Rules, 2025. Government of India.
- 6. Data Protection Board of India (DPB). (2026). Annual Report on Cross-Border Data Transfers. DPB.
- 7. Reserve Bank of India (RBI). (2026). Clarification on Payment Data Localisation. RBI Circular No. DPSS.CO.PD.2026/123.
- 8. Ministry of Finance. (2026). PLI Scheme for Data Centres and Digital Infrastructure. Government of India.
- 9. WTO. (2025). E-Commerce and Digital Trade: India’s Position. WTO Trade Policy Review.
- 10. European Parliament. (2016). General Data Protection Regulation (GDPR). Official Journal of the EU.
- 11. Chander, A., & Lê, U. P. (2014). Data nationalisation. Emory Law Journal, 64(3), 677-739.
- 12. Kuner, C. (2015). Transborder data flows and data privacy law. Oxford University Press.
- 13. Singh, P. J. (2019). Data localisation: India's approach and the WTO. World Trade Review, 18(4), 659-682.
- 14. UNCTAD. (2021). Digital economy report 2021: Cross-border data flows and development.
- 15. World Economic Forum. (2020). Data free flow with trust.
- 16. Ministry of Electronics and Information Technology (MeitY). (2026). National AI Mission Framework. Government of India.
- 17. OECD. (2025). Digital Economy Outlook 2025. OECD Publishing.
- 18. Reserve Bank of India. (2018). Storage of Payment System Data: Directions. RBI Circular No. DPSS.CO.PD.2018/123.
Related Articles
Publish Your Research With UIMRJ
Submit your original research article, review paper, case study or conceptual paper to an international open access, peer-reviewed and refereed journal.