Data Localisation and Privacy Issues
| 🧠 The Analogy Imagine a country passing a law that all gold mined within its borders must be stored in its own vaults — it cannot be shipped abroad for safekeeping. Data Localisation is the digital equivalent: data generated within a country must be stored, processed, or mirrored within that country’s borders rather than freely flowing across the world. |
Data Localisation
Data Localisation refers to the policy or legal requirement that data generated within a country — especially personal or sensitive data — must be stored, processed, or mirrored within that country’s borders, instead of being freely transferred across borders.
Rationale / Objectives for Data Localisation
| Objective | Explanation |
| National Security | Prevents foreign surveillance and unauthorised access to sensitive defence, telecom, finance, and governance data by foreign adversaries or corporations. |
| Law Enforcement Access | Enables faster, lawful access to data for investigations and prosecution. Reduces dependence on slow Mutual Legal Assistance Treaties (MLATs) with foreign countries. |
| Data Sovereignty | Ensures citizens’ data is governed under domestic laws and institutions — state control over cross-border data flows. |
| Privacy Protection | Facilitates better enforcement of data protection laws and increases accountability of companies handling personal data. |
| Domestic Digital Infrastructure | Encourages investment in local data centres and cloud services — generates employment and boosts the digital economy. |
| Regulatory Oversight | Simplifies monitoring and auditing by domestic regulators; improves compliance with sectoral regulations (banking, telecom). |
| 📌 MLATs Explained Mutual Legal Assistance Treaties (MLATs) are formal agreements between countries enabling cooperation in criminal investigations, evidence gathering, and prosecution. Without data localisation, India must send formal MLATs to the US to access data stored on American servers — a process that can take months or years. |
Major Data Localisation Laws in India
| Law / Policy | What It Mandates | Status |
| Digital Personal Data Protection (DPDP) Act, 2023 | Allows cross-border transfer but empowers Central Government to restrict transfers to specified countries/territories through notification | Implemented |
| RBI Circular on Payment System Data, 2018 | Entire payment system data (end-to-end transaction details) must be stored ONLY in India; foreign processing allowed only if final storage is in India | Enforced |
| Aadhaar Act, 2016 & UIDAI Regulations | Aadhaar number, biometric data, and core demographic information must be stored and processed within India; cross-border storage PROHIBITED | Enforced |
| ABDM Health Data Policy, 2020 | Health data fiduciaries must store sensitive personal health data in India; limited cross-border transfer subject to consent | Partially implemented |
| CERT-In Directions, 2022 | ICT system logs and related data must be maintained within India for a minimum of 180 days | Enforced |
Concerns with Data Localisation
- Increased compliance costs: Mandating local data storage raises infrastructure and operational costs for global and domestic companies, potentially stunting innovation.
- Impact on ease of doing business: May deter foreign investment and affect India’s integration with the global digital economy.
- Data Balkanisation: Excessive localisation can fragment the internet into isolated national segments, reducing global efficiency and innovation.
- Limited technological capability: Building secure, large-scale domestic data centres requires massive capital and technical expertise.
- Privacy and surveillance risks: Centralised data within national borders can enable state overreach or mass surveillance if oversight is weak.
- Cybersecurity risks: Centralised storage creates a single point of failure — an attractive, high-value target for cyberattacks.
- Trade and diplomatic tensions: Data localisation can conflict with international trade agreements and bilateral digital trade commitments.
Privacy Issues
Privacy is the right of individuals to control their personal data — how it is collected, stored, processed, and shared. In a digital society where your phone, Aadhaar, bank account, health record, and social media profile are all connected, privacy has become the defining civil liberties issue of our era.
The Supreme Court in Justice K.S. Puttaswamy vs Union of India (2017) unanimously declared the Right to Privacy as a Fundamental Right under Article 21 (Right to Life) — a landmark ruling that reshaped India’s entire data governance framework.
Key Privacy Concerns
- Mass Data Collection: Governments and corporations collect enormous volumes of personal data — every app you install, every search you make, every purchase you complete — increasing the risk of misuse.
- Surveillance and Profiling: Continuous monitoring of online behaviour enables detailed behavioural profiling, leading to chilling effects on free speech, dissent, and individual autonomy.
| 📌 Chilling Effect A chilling effect occurs when people avoid exercising their lawful rights — especially freedom of speech — because they fear legal, social, or economic repercussions from surveillance. |
- Data Breaches & Leaks: Sensitive personal data (financial, health, biometric, identity) exposed due to cyberattacks, insider threats, or weak security.
- Weak User Consent: People agree to privacy policies without reading them. Consent becomes formal rather than meaningful — users do not know what they are agreeing to.
- Misuse of Biometric Data: Facial recognition, fingerprints, and voice data collected en masse are prone to abuse — leading to exclusion, discrimination, or identity theft.
- Lack of Transparency: People do not know what data is collected, how long it is stored, or who accesses it.
- State Overreach: Excessive government surveillance without judicial oversight conflicts with the fundamental right to privacy.
- Cross-Border Data Risks: Data transferred abroad may be subject to weaker privacy protections in the destination country.
Indian Legal Framework for Data Privacy
| Initiative / Law | Core Purpose | Key Privacy Provisions |
| DPDP Act, 2023 | Primary data protection law | Consent-based data processing; purpose limitation; data minimisation; regulated cross-border data transfers; rights of data principals |
| IT Act 2000 & IT Rules 2021 | Cybersecurity & intermediary regulation | Addresses unauthorised access, data theft, cyber fraud; due diligence obligations; content takedown; grievance redressal |
| CERT-In | National cyber incident response body | Monitoring cyberattacks and data breaches; issuing advisories; mandatory cybersecurity directions to organisations |
| Aadhaar Act 2016 (Amended 2019) | Protection of Aadhaar data | Restricts mandatory Aadhaar use by private entities; strengthens consent and data security; mandates domestic storage |
Data Localisation vs Privacy — The Complex Trade-off
Here is a paradox that confuses many students: Data localisation sounds like it should protect privacy, but it can actually undermine it. Let us understand why.
Privacy Concerns WITHIN Data Localisation
- Risk of State Surveillance: Centralising data within national borders makes it much easier for the government to access and monitor citizens’ data — especially dangerous without strong judicial oversight.
- Weak Privacy Safeguards: Local storage does not automatically ensure privacy. If data protection laws are inadequate or poorly enforced, citizens’ data can still be misused by domestic actors.
- Centralisation = Single Point of Failure: Puts all eggs in one basket — a single successful cyberattack can expose the data of an entire country.
- Jurisdictional Overreach: Governments may invoke data localisation to justify broad access to data without adequate judicial oversight — conflicting with the Puttaswamy judgment.
- Chilling Effect: Perception of surveillance may discourage free speech, dissent, and online participation.
| Aspect | Data Localisation | Privacy Concerns |
| Core Focus | National control, security, and data sovereignty | Protection of individual rights, autonomy, and consent |
| Primary Risk | State overreach and increased surveillance capability | Data misuse, profiling, and corporate surveillance |
| Key Challenge | Impact on cross-border digital trade and global data flows | Effective enforcement, accountability, and independent oversight |
| Governance Dilemma | Balancing national security with economic openness | Balancing technological innovation with fundamental rights protection |
