top of page

By:

Sagari Gupta

24 March 2026 at 7:46:04 pm

India’s Digital Footprint Is No Longer a Choice

India’s digital economy has made personal data unavoidable. The harder task is ensuring that citizens retain meaningful control over the trails they leave behind. In August this year, the Unified Payments Interface processed about 24.5 billion transactions worth nearly Rs. 29.8 lakh crore, according to data from the National Payments Corporation of India. Aadhaar’s authentication system recorded more than 17,759 crore transactions in FY2025-26, according to UIDAI’s dashboard. Behind these...

India’s Digital Footprint Is No Longer a Choice

India’s digital economy has made personal data unavoidable. The harder task is ensuring that citizens retain meaningful control over the trails they leave behind. In August this year, the Unified Payments Interface processed about 24.5 billion transactions worth nearly Rs. 29.8 lakh crore, according to data from the National Payments Corporation of India. Aadhaar’s authentication system recorded more than 17,759 crore transactions in FY2025-26, according to UIDAI’s dashboard. Behind these numbers sits a question Indian policy has yet to answer clearly: what happens to the data these systems generate, and who controls it? The most pressing privacy question in India today is not what people choose to post online. It is what they are required to leave behind to take part in everyday life. A UPI payment leaves a transaction trail. A loan application generates financial records. A food-delivery order records your address and buying habits. A cab ride shows where you work and when you travel. A social-media post adds something more personal: what you think, like, fear or believe. Individually, these fragments look harmless. Together, they can describe a remarkably detailed version of a person’s life. Orwellian Society This is not digital technology invading a society that was once offline. It is a society in which digital systems have become part of ordinary economic life. For a software professional, deleting social media may be an inconvenience. For a domestic worker paid through a bank account, a student applying for a scholarship or a pensioner completing an identity check, opting out is not a workable choice. Consider an ordinary Saturday. You check the weather, search for a medicine, order groceries, pay through UPI, book a cab and make an online purchase. No single action tells a complete story. Together, they reveal your location, spending patterns, household composition, health concerns and daily routine. Artificial intelligence changes what this data means, because machine systems are increasingly good at connecting fragments that once sat in separate databases. The concern is not that an AI system knows what you searched for once. It is that automated systems can identify patterns across millions of ordinary interactions that, taken individually, meant little. The problem is also one of asymmetry. The individual usually sees only the service being offered; the organisation sees the accumulated information behind it. A single transaction may be trivial, but millions of such transactions can become commercially or administratively valuable when linked and analysed. That makes data different from many other commodities. Once information has been copied, combined or used to build a profile, the original individual may have little visibility into its subsequent journey. The question is therefore not simply who collected the data, but who can combine it, infer from it and act upon those inferences. The public debate on AI scraping is often too simple. Not every online interaction is pulled into an AI model, and not every company holds every piece of a person’s digital life. Collection depends on the platform, its policies, its technical architecture and the applicable law. But the gap is real: the capacity to analyse vast volumes of information is growing faster than most people’s understanding of where their information goes. A PwC India survey found that 56 percent of consumers did not know their rights over personal data, while 70 percent said privacy policies were difficult to understand. When a person does not understand what they are agreeing to, consent risks becoming a formality rather than a genuine choice. There is also a distinction between privacy and secrecy. A person may have nothing embarrassing to hide and still reasonably object to a detailed record of their movements, purchases and associations being assembled without meaningful control. Privacy is less about having something to conceal than about retaining a degree of agency over one’s own life. A Right on Paper The Digital Personal Data Protection Act, 2023 gives individuals rights to correct and erase personal data, subject to the conditions and exceptions set out in the law. The government notified the Digital Personal Data Protection Rules in November 2025, with provisions coming into force in phases. On paper, this changes the relationship between citizens and the organisations that hold their data. In practice, most people do not think in terms of “Data Principal” or “Data Fiduciary” when an app asks for access to their information. They think about whether the app will still work if they say no. That is the test that decides whether a data-protection law functions on the ground. A small retailer selling online may not fully understand the compliance requirements. An elderly customer faces a long privacy notice before completing a routine transaction. A young user accepts an app’s terms because refusing means losing access to a service that friends or employers already use. A right that exists on paper does not guarantee a person’s ability to exercise it. The ability to protect personal data is not distributed evenly. A high-income professional can pay for privacy-focused software, encrypted communication and legal advice. Someone on a smaller income uses whichever free application is available. The same divide applies to time. A person who understands technology can adjust permissions and request deletion. A person working two jobs may accept an app’s terms because reading a 30-page privacy notice at 11 p.m. is hardly realistic. This produces an uneven outcome. The people with the strongest ability to protect their data are often the same people with the clearest sense of what is being collected. Those with fewer resources tend to generate more data while having less power to question how it is used. This is why treating “going offline” as the solution has limited use in India. Cash does not cover every digital transaction. A basic phone does not replace every digital service. Deleting a social-media account does not erase bank or government records. Refusing every digital platform carries its own economic cost, particularly for people who depend on digital payments for income. The realistic goal is not disappearance. It is control. India’s digital economy should not be measured only by payment volumes or platform reach. It should also be measured by whether people understand the exchange taking place underneath that convenience. Regulators should track whether a person can find out what a service holds about them, correct inaccurate information, delete data that is no longer necessary and withdraw consent without clicking through several layers of settings. The sharper test is what happens when data collected for one purpose becomes useful for another. Rising Stakes The stakes will rise as India’s digital infrastructure becomes more deeply embedded in public services, finance and commerce. The country has built impressive systems for moving money and verifying identity; the next challenge is to build equally credible systems for limiting what can be inferred from the information those systems generate. The next phase of India’s privacy debate should move past the idea of digital disappearance, because most people have no practical way to leave the systems through which they earn, pay, borrow, travel, study and access public services. The more useful task is making those systems answerable to the people whose lives they record. The measure of digital freedom is not whether a citizen leaves no trace. It is whether they have a say over where that trace leads. (The writer is an independent public policy researcher. Views personal.)

Technology Transplants and Their Hidden Fallouts

5 hours ago
5 min read

Developments in the field of AI have left many stakeholders worried. People are concerned about potential job losses. Governments are worried about rising unemployment as well as the security threats that AI can pose. Corporations and computer scientists understand exactly where AI technology stands today on its maturity journey, and what trajectory it is likely to take given the cut-throat competition in this domain. They are worried about the disastrous consequences it may have for humanity if things go out of control.


Although such doomsday theories remain contested, there is general agreement that AI will pose risks and threats quite different from those associated with the giant leaps in technology witnessed so far.


While AI, as a new technology, is grabbing much of the attention and prime-time discussion in this context, the underlying messages, concerns and lessons to be learnt go far beyond AI—and go much further back in time as well. Missing out on those messages and lessons would be like missing the forest for the trees.


Boon- or Bane?

It is often said that technology is neutral. Whether it turns out to be a boon or a bane depends entirely on the use to which it is put. The most common example cited is nuclear technology, which can be used to develop nuclear weapons, generate electricity or help cure disease through nuclear medicine. Similarly, the same technology used to launch missiles to destroy targets also helps launch satellites for purposes that benefit mankind in many ways.


While this ‘boon or bane’ argument is valid in general, it needs to be applied with abundant caution. Factors such as the purpose for which the technology was originally developed, who funded it and why, and, most importantly, when and why it was made publicly available, are critically important in this context.


Take the internet. Although now a commonly available technology in the hands of billions of people, its origins lie in a project initiated and lavishly funded by the US Department of Defense through a special branch of the US military called the Advanced Research Projects Agency (ARPA). It became a communication backbone of the US military during the Cold War era.


After the Cold War ended, Senator Al Gore pushed a novel concept termed the ‘peace dividend’, under which infrastructure built for defence was proposed for use in boosting the US economy. Missile and satellite-launching technology, the Global Positioning System (GPS), integrated-circuit chips with ever-increasing computing power, laser technology and highly intelligent and versatile handheld gadgets that were once seen only in James Bond movies all belong to the same broad category.


They all have their roots in military-funded research. Yet they are either sitting directly in the hands of ordinary people today or indirectly affecting their daily lives in a big way.


Dangerous Consequences

There is nothing inherently wrong with applying technologies developed for one domain to other domains. But it needs to be done with due caution and an in-depth assessment of both its short-term and long-term fallouts.


Immediate benefits may often mask not only unintended and potentially disastrous long-term consequences, but also intended long-term objectives and ulterior motives, if any.


One could compare this with the seemingly simple act of an airline passenger carrying a harmless live culture, plant or animal from one country to another. However simple it may appear, such a transplant is generally banned by law and governed through stringent processes because of its potential impact on the target environment. Technology transplants are no different.


Three distinct scenarios stand out in this regard. The first is the invention of technologies such as electricity and the telephone, which were developed by companies entirely in the civilian domain, with no involvement of the military. These technologies immensely benefited ordinary people and society without causing any serious damage.


The second concerns technologies such as nuclear technology and missiles. They were funded and developed in the military domain, with warfare as the primary objective. They were later transplanted into the civilian domain through applications in nuclear power generation, nuclear medicine and satellites launched for civilian use.


Although this was a technology transplant, the core technology itself did not fall directly into the hands of ordinary people. Common people were merely customers who paid for the benefits and consumed them like any other product or service.


The third scenario concerns technologies developed in the military domain with all the vision, strategy and power required to dominate and win a war, but which later landed in the hands of ordinary people for various reasons.


Those reasons could simply be economic, such as monetising an underlying technology that the military does not necessarily want to restrict to itself under the given circumstances. Or they could very well emanate from the same political or military agenda.


Seamless connectivity across the world through high-speed data, and several applications that ride on it, such as social media, are typical cases in point.


Equaliser Effect

The so-called equaliser effect of the internet, and its immediate benefits for developing countries in a globalising economy, were obvious and substantial. However, the long-term implications of the sudden and massive cultural short-circuiting it triggered, the expectations it shaped, the soft power it propagated and the habits it changed were neither anticipated nor fully understood.


Similarly, the immediate benefits of global social media, coupled with highly sophisticated algorithms and powerful search engines running behind them, were obvious. Those algorithms and search engines were originally designed with military intelligence and law-enforcement applications in mind. Yet, when transplanted into civilian use on a mass scale, the impact they created (deliberately or otherwise) on the thought processes of people, their mental capabilities, attention span, memory and concentration was neither obvious nor proactively assessed.


New chips with top-notch computing power and gadgets with cutting-edge technology continue to be invented for the military domain. Their next-best or older versions subsequently land in the hands of ordinary people through powerful cell phones, wearable devices and addictive high-speed 3-D gaming applications that are continuously upgraded to monetise the technology.


The impact of these technology transplants on human beings becomes far more serious for a country like India, which counts on the capabilities of its human capital to reap its population dividend.


It reminds one of an era when US companies in the electrical power-generation business used to distribute very high-wattage light bulbs totally free of cost to the general public outside shopping malls. The whole idea was to induce people to consume more electricity, irrespective of whether they really needed such a powerful light bulb at home.


Enacting an IT Act relatively late in the game, the late appreciation of issues such as data privacy and the right to be forgotten, and attempts to restrict minors from accessing social media are all essentially afterthoughts in a damage-control mode.


Public discourse these days often highlights the role of the internet, social media and algorithmic promotion or suppression of content in fanning public unrest in several countries and even influencing elections.


It underlines the same serious lacuna on the part of successive governments in anticipating and managing the unintentional or deliberate impact of putting military-grade technology directly into the hands of a vast population.


It is worth noting, in the same larger context, how another populous country, China, handled the internet and global social media very differently from day one with the Great Firewall, and how it is investing in and managing AI at this stage.


When such transplanted, free-of-cost technologies put in the hands of ordinary people begin to look like highly sophisticated solutions in search of genuine problems, governments, particularly ours, need to sit up and take note.


(The writer has worked in the information technology sector. Views personal.)

Comments


bottom of page