1. Home
  2. From the Ivory Tower
  3. Negotiating the Digital Domain: Strategic Engagement Frameworks in India’s Data Diplomacy

Negotiating the Digital Domain: Strategic Engagement Frameworks in India’s Data Diplomacy

Audio Option is available to paid subscribers. Upgrade your plan

In their article, “Negotiating the Digital Domain: Strategic Engagement Frameworks in India’s Data Diplomacy”, published in Studies in Indian Politics in 2026, Siddhi Wadekar and Aakansha Natani examine how India’s domestic data policies and its international digital negotiations have developed alongside each other. They treat data diplomacy as a “mutually re-enforcing process” in which domestic regulation affects India’s international negotiating position, while economic, technological, and geopolitical considerations also influence domestic policy. The article focuses on cross-border data flows, data localisation, digital trade agreements, and India’s efforts to promote digital public infrastructure (DPI) abroad. The authors argue that India is trying to manage four concerns at the same time: development, digital sovereignty, economic competitiveness, and strategic autonomy.

The first part of the article traces India’s domestic approach to data regulation from the Information Technology Act, 2000, through the privacy debates of the 2010s and the introduction of the Digital Personal Data Protection (DPDP) Act, 2023. Early policy discussions dealt mainly with privacy and the protection of personal information. Data localisation became more prominent later, including through the 2015 National Telecom M2M Roadmap and the Reserve Bank of India’s 2018 requirement that payment data be stored in India. The 2017 Puttaswamy judgment also recognised informational privacy as part of the right to privacy. The Srikrishna Committee’s work then brought cross-border data transfers and localisation into the centre of the policy debate. Its 2018 report supported restrictions on certain categories of data but did not recommend localisation across all sectors.

The authors identify a change in direction with the DPDP Act, 2023. Earlier drafts had placed stronger restrictions on transfers of personal data outside India. The final Act instead permits cross-border transfers unless a country is restricted by the Union government. Wadekar and Natani therefore distinguish India’s present position from a policy of complete localisation. They describe it as “conditional openness”: data can move across borders, but the government retains the authority to restrict transfers where it considers this necessary. They also note a parallel shift in the treatment of non-personal data. The Kris Gopalakrishnan Committee described such data as a national resource, community asset, and form of digital infrastructure. Taken together, these changes show how data policy in India moved beyond privacy and towards questions of economic value and state control.

The article then examines India’s external negotiations on data. The authors look at agreements with Singapore, the UAE, the UK, and the EU. The 2005 India-Singapore CECA dealt with electronic commerce and privacy but did not contain the detailed cross-border data provisions found in later agreements. The India-UAE CEPA, signed in 2022, encouraged cross-border information flows while leaving each country’s domestic data rules intact. The India-UK agreement signed in 2025 also avoided binding commitments on unrestricted data flows and included provisions for future review. The India-EU agreement signed in January 2026 covered digital trade, but did not give India formal data adequacy status. For Wadekar and Natani, these agreements show a preference for relatively flexible provisions that allow digital trade while preserving room for domestic regulation.

This is where the authors make their central connection between domestic regulation and foreign policy. They write that “India’s data diplomacy cannot be understood independently of its domestic data governance agenda”. The shift in domestic policy, from a stronger emphasis on privacy and localisation towards greater openness, has affected India’s position in trade negotiations. International pressures have also fed back into domestic policy. The authors use India’s digital public infrastructure as an example. UPI has been adopted in several countries, and India has sought to promote its wider digital infrastructure through forums including the G20 and BRICS. The point is not simply that India exports digital technology. The authors argue that the promotion of DPI gives India another way to participate in discussions about how digital systems and data should be governed.

The paper places this approach alongside those of the United States, European Union, and China. The United States generally supports cross-border data flows but also retains legal mechanisms for access to data held by American companies. The EU makes international transfers conditional on data protection standards and its adequacy framework. China places greater emphasis on state control, including through data localisation and security reviews. India does not follow any one of these models. Wadekar and Natani describe India’s position as a “distinct approach” that combines participation in global digital markets with the preservation of domestic regulatory authority. They point to India’s decision not to join the G20 Osaka declaration on Data Free Flow with Trust in 2019 and its withdrawal from RCEP over the e-commerce chapter as evidence of the stronger localisation position India initially maintained. They then connect the later movement towards greater flexibility with India’s efforts to expand digital trade and cooperation.

The paper identifies cooperation and disagreement in India’s current digital diplomacy. Cooperation has developed around the international use of India’s DPI, including digital payments and digital identity systems. The authors also discuss “data embassies”, using the proposed India-UAE arrangement as an example of countries storing critical data in another country while retaining control under the laws of the originating state. Contestation remains over data localisation, the EU’s adequacy requirements, and the relationship between the Indian government and major technology platforms. The paper discusses the TikTok ban and the dispute between X and the Indian government over the Sahyog portal as examples of wider disagreements over data access, platform regulation, and state authority in the digital sphere.

Wadekar and Natani conclude that India’s approach is built around maintaining room for domestic regulation while becoming more closely connected to the global digital economy. They point to the DPDP Act, digital trade agreements, the export of DPI, data-centre policies, and discussions around data embassies as parts of this wider approach. They describe data diplomacy as “the newest frontier of India’s digital strategic outlook” and argue that its future will be shaped by the areas where India can cooperate with other data jurisdictions as well as by disputes over localisation, adequacy, data access, and platform regulation.

Latest Stories

More From India's World