India’s ambitious digital public infrastructure, built around Aadhaar and UPI, raises complex legal and constitutional questions about privacy, state control, and data sovereignty amid new legislation and technological advances.
India’s digital infrastructure has become one of the most ambitious state-led technology projects in the world. Built around Aadhaar identity, UPI payments, DigiLocker, ONDC and the Account Aggregator framework, it has created an interoperable layer that sits beneath daily commerce and administration for more than a billion people. According to the material supplied, this system is not just a technical stack but a new legal and constitutional environment, raising questions about privacy, state power and the meaning of data sovereignty.
The legal significance of that architecture lies in its reach. The framework depends on open interfaces and consent-based data sharing, allowing users to authenticate themselves, move money and pass documents to third parties with relative ease. But the same design also exposes a fault line: consent can become less meaningful when access to credit, welfare or basic services depends on agreeing to extensive data use. The related summaries describe the Digital Personal Data Protection Act 2023 as India’s first comprehensive data protection law, but also one that gives the Union Government wide exemption powers and allows cross-border transfer rules to be set centrally.
That makes data sovereignty a three-part issue in Indian law. At state level, the debate concerns localisation, cross-border transfers and whether data should be treated as a strategic asset. At individual level, it concerns the right to informational privacy, which the Supreme Court recognised as part of the constitutional right to life and personal liberty in the Puttaswamy judgment. At corporate level, it concerns the influence of large digital platforms and whether future competition rules should impose interoperability and data-sharing duties on systemically significant firms. The article argues that these tensions cannot be reduced to a simple choice between sovereignty and openness.
The strongest criticism of the DPDP Act is structural rather than procedural. It creates a Data Protection Board and sets out familiar privacy principles such as minimisation, storage limitation and purpose limitation, but critics say it does not go far enough on independent enforcement. The Act is also said to contain a children’s data paradox: rules meant to prevent tracking rely on age verification methods that may themselves be privacy intrusive. The broader conclusion is clear. India’s digital public infrastructure may be technically successful, but the constitutional safeguards around it have not yet caught up.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





