Close Menu
    Facebook X (Twitter) Instagram
    • Home
    • Contact Us
    • About Us
    • Privacy Policy
    • Terms Of Service
    • Advertisement
    Thursday, October 8
    Facebook X (Twitter) Instagram Pinterest Vimeo
    ABS Africa TV
    • Breaking News
    • Trending
    • Africa News
    • World News
    • Features
    • Technology
    • Sports
    • Politics
    • More
      • Culture
      • Lifestyle
      • Travel
      • Business
      • Environment
      • Legal
      • Health
      • Cameroon
      • Ambazonia
      • AfroSingles
      • Environ/Climate
      • Editorial
      • The Leak Magazine
    • Donate
    Subscription
    ABS Africa TV
    Home»Technology»India’s AI Data Debate Moves Beyond Data Localisation
    Technology

    India’s AI Data Debate Moves Beyond Data Localisation

    Ewang JohnsonBy Ewang JohnsonOctober 8, 2026No Comments13 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    India’s AI Data Debate Moves Beyond Data Localisation
    Share
    Facebook Twitter LinkedIn Pinterest Email

    On September 18, 2026, the Office of the Principal Scientific Adviser (PSA) to the Government of India made public a discussion paper titled “Enabling Cross-Border Data Interoperability for AI Systems”. It was prepared by two of the office’s own policy staff, Animesh Jain and Kunal Thakur.

    Reviewers included officials from within the PSA office, experts from the Indian Software Product Industry Round Table (iSPIRT), a software think tank, and the industry-backed Data Security Council of India. The paper carries a formal caveat that its views “should not be construed as formal policy positions of the PSA Office”.

    It nonetheless argues that mandating local storage and processing of data “raises compliance burdens, particularly for startups and MSMEs [micro, small and medium enterprises]”. Such mandates, it says, limit access to diverse datasets, which can fragment global AI research, and “may trigger retaliatory trade actions”, affecting digital trade and services exports.

    The paper appears after a period of strain in India’s trade relationship with the United States, its largest single-country trading partner. In 2025, the US raised tariffs on Indian goods to 25 per cent and then to 50 per cent, citing, among other reasons, India’s continued purchase of Russian oil.

    In February 2026, the two sides announced a framework deal that brought the reciprocal tariff down to 18 per cent. Digital trade barriers, including data localisation, have featured among the non-tariff issues raised in the negotiations. The paper’s warning about “retaliatory trade actions” does not refer to the tariff dispute.

    The dispute over data localisation is not new. Its terms have long been set as sovereignty against openness, control against innovation, and protection against growth. Earlier arguments, from the Justice B.N. Srikrishna Committee’s 2018 report to successive drafts of a data protection law, were essentially about where records physically sat. The PSA paper argues that this framing does not describe how AI works.

    “In AI systems, the object crossing the border may be raw data, model parameters, analytical outputs or a trained model,” it states. A model trained on sensitive or restricted records, it adds, may retain or reproduce information from them, or enable inferences about it, even where the underlying data remains within the country.

    The concern has been demonstrated. In a widely cited 2021 study, Nicholas Carlini and colleagues from Google, Stanford University, the University of California, UC Berkeley, OpenAI, and other institutions showed that GPT-2, a large language model, could be made, through queries alone, to output verbatim fragments of its training data, including names, phone numbers, and email addresses from public web text. Later research has extended the finding to other models.

    In principle, a country could keep every server inside its borders and still lose control over what can be learned from its citizens’ data if that data is folded into a model whose outputs or weights cross a border the servers never do.

    The proposed framework

    On this basis, the paper proposes what it calls an illustrative “risk-aligned matrix”, which splits data into four tiers by sensitivity and identifiability. Aggregated or statistical data would move through “open/low-friction international exchange”. Fine-grained but non-identifiable data would be shared under standard commercial or research protocols, using “differential privacy and perturbation”. Identifiable data would require a “controlled-access agreement/trusted corridor”, backed by strict legal contracts and audit trails. Data classified as strategic or relating to national security would stay domestic and be processed through “secure model-to-data/federated processing”, with only “approved outputs” leaving where permitted.

    A man walking past a hoarding for the India AI Impact Summit 2026 in New Delhi on February 16, 2026.

    A man walking past a hoarding for the India AI Impact Summit 2026 in New Delhi on February 16, 2026.
    | Photo Credit:
    Shashi Shekhar Kashyap

    The matrix sits alongside three “pillars”. Compatibility means shared technical and semantic standards that let national systems work together without becoming identical. Accountability means certification and enforceable agreements, and coordination means cooperation among regulators and institutions. The paper calls the whole “an overlaid interoperability layer on extant governance mechanisms”, not a new AI data-governance regime.

    It tests the framework on India’s health-data ecosystem, which it describes as having relatively well-developed technical, semantic, and institutional arrangements. It cites standards such as HL7 FHIR by Health Level Seven International (HL7) for health records and Digital Imaging and Communications in Medicine (DICOM) for medical imaging, and the Medical Imaging and Information Datasets for India (MIDAS) project of the Indian Council of Medical Research (ICMR).

    Its most concrete illustration is a collaboration announced at the AI Impact Summit 2026 between the ICMR and the French Health Data Hub to test the Data Empowerment and Protection Architecture (DEPA). DEPA is a consent-and-access technology built within the iSPIRT ecosystem. The paper says the aim is “secure and traceable access to Indian and French health data for public-interest research”.

    A Letter of Intent on the secondary use of health data was subsequently signed by the ICMR, the Department of Health Research, and the French agency. Even so, India’s existing standards and approvals “do not yet provide a single coordinated route” for cross-border AI research, secondary use, and model outputs, according to a summary of the paper by The Policy Edge. The paper’s recommendations are meant to close that gap.

    The economic case

    The paper’s economic case for openness is more conventional. It cites a 2025 study by the Organisation for Economic Co-operation and Development and the WTO, which found that balanced approaches, in which data flows are permitted with safeguards, could raise global GDP by around 1.77 per cent and global exports by about 3.6 per cent if every economy adopted them.

    “Highly restrictive or fragmented data regimes”, the paper says, may cut global GDP by nearly 4.5 per cent and exports by around 8.5 per cent. The study’s 4.5 per cent figure describes a scenario in which all economies fully restrict data flows.

    The same study finds that the gains from an open, safeguarded regime would be proportionally largest for low-income and lower-middle-income economies, whose GDP could rise by more than 4 per cent. The PSA paper does not dwell on this.

    A footnote describes the figures as “computable general-equilibrium simulations based on hypothetical global scenarios, rather than observed economic outcomes”. It also cites earlier modelling, from 2014, by the European Centre for International Political Economy that put the GDP impact of selected localisation measures in India at around 0.1 per cent, rising to roughly 0.8 per cent under economy-wide localisation.

    These estimates are far smaller than the global scenarios the paper leads with, although they measure different things: one is a national estimate for India’s own measures, the other a simulation of worldwide restrictions.

    An estimate attributed to the Indian Council for Research on International Economic Relations puts the trade cost to India of a 1 per cent contraction in cross-border data flows at $696.71 million. Figures of this kind describe a scenario that has not occurred. India has never operated a fully localised data regime, so what a “fragmented” scenario would cost the country remains a model output, not a measured loss.

    The paper enters a regulatory history that has changed direction several times since 2018. The Srikrishna Committee’s 2018 draft envisaged a strict mandate: a “serving copy” of all personal data kept on servers in India, and a category of “critical personal data” barred from leaving the country.

    Justice B. N. Srikrishna’s committee’s draft in 2018 envisaged a strict mandate where critical personal data is barred from leaving the country.

    Justice B. N. Srikrishna’s committee’s draft in 2018 envisaged a strict mandate where critical personal data is barred from leaving the country.
    | Photo Credit:
    P.V. SIVAKUMAR

    The Personal Data Protection Bill, 2019, softened this. It allowed “sensitive” personal data to be transferred abroad with the individual’s explicit consent, provided a copy was kept in India, while “critical” data remained local. The 2022 draft moved to a “whitelist” model, under which the Centre would name the countries data could go to and transfers to every other country were presumptively banned.

    The Digital Personal Data Protection Act, 2023 (DPDP Act), which Parliament eventually passed, changed direction again. It adopted what the PSA paper calls a “negative-list model” under Section 16, which permits cross-border transfers by default except to countries the government restricts.

    As of mid-2026, the Centre had not notified any restricted country under that section, ThePrint reported. The DPDP Rules were notified on November 13, 2025, after a public draft in January 2025. Their substantive cross-border provisions are not due to take effect until May 13, 2027.

    Payment data has been subject to a stricter India-only storage requirement since the Reserve Bank of India’s direction of April 6, 2018. The PSA paper calls this “localisation-first” and cites it, with other sectoral rules, as evidence that India already applies stricter controls where risk is higher.

    Commentators on the draft DPDP Rules have raised concerns that have nothing to do with AI. Writing in the Edinburgh-based journal SCRIPTed in December 2025, Khushi Malviya and Eeshaan Singh, listed as law students at the West Bengal National University of Juridical Sciences, criticised draft Rule 14, on cross-border transfers, and draft Rule 12(4), on Significant Data Fiduciaries.

    They argue that the draft provisions give the government broad discretion to impose localisation through subordinate legislation, call the approach “regressive”, and say it appears inconsistent with the parent Act’s focus on blocking transfers to risky countries rather than particular types of data.

    Akriti Gaur, a fellow at Harvard University’s Berkman Klein Center for Internet and Society, made a related argument on the German public-law platform Verfassungsblog in March 2025, before the rules were finalised. She wrote that the draft’s “ambiguous wording” gave the executive “unfettered discretion” over localisation, and that this, together with a lack of legislative protection for citizen privacy, undermined “India’s own data diplomacy project”.

    Neither commentary is concerned with AI. But the PSA paper proposes a layer built “on top of” existing mechanisms, so it would inherit any ambiguity in them.

    Sovereignty and trade

    Not everyone accepts the paper’s premise that openness with safeguards is the benchmark against which restriction should be measured. A parallel and older strand of Indian policy thinking, associated with civil-society groups such as IT for Change and with India’s own positions at multilateral forums, treats data less as a resource whose free circulation raises collective welfare than as collectively held wealth that developing countries have historically been persuaded to surrender too cheaply.

    At the WTO’s eleventh ministerial conference in Buenos Aires in 2017, India resisted what it read as the “hyper-liberalisation” of cross-border data flows, seeing it as a route to consolidating the global dominance of American digital services firms. In 2019, it declined to endorse the Osaka Track, the “data free flow with trust” initiative pushed by Japan, the European Union, and other advanced economies.

    On this reading, the right to what proponents call “development sovereignty” over data is inseparable from the right to privacy. Treating the two as separate matters, one of consent and protection and the other of trade efficiency, understates what a country forfeits economically when its citizens’ data moves through infrastructure it does not control.

    Set against this tradition, the PSA paper’s vocabulary of “trusted data corridors” and “mutual recognition” could be read either as an attempt to preserve sovereignty within an interoperable system, or as a technocratic softening of the liberalisation that India’s own trade negotiators have long resisted.

    The paper does not choose between these readings. Its own list of risks from unrestricted flows, which includes foreign surveillance, reduced oversight where data is processed in jurisdictions with weaker safeguards, and “the risk of data concentration in the hands of a few global technology firms”, overlaps with the sovereignty argument more than its headline recommendations do.

    Control over location

    A third position holds that the argument over where data physically sits may be answering the wrong question. Writing in ThePrint in June 2026, three months before the discussion paper appeared, Suresh Prabhu, a former Union Cabinet Minister, and Shobhit Mathur, co-founder and Vice Chancellor of Rishihood University, argued that India’s “digital sovereignty debate is still trapped in a misleading image: the server”.

    Storing data inside the country creates only an “assumption” of control, they wrote, one that “made sense in an earlier internet era” but is no longer sufficient in the age of cloud computing and AI. Their argument centres on what they call the “command layer”: who holds the encryption keys, who can update or shut down a system, and under whose law a cloud provider ultimately operates.

    Former Union Minister Suresh Prabhu, along with Shobhit Mathur, co-founder and Vice Chancellor of Rishihood University, argued that storing data inside the country only provided an assumption of control.

    Former Union Minister Suresh Prabhu, along with Shobhit Mathur, co-founder and Vice Chancellor of Rishihood University, argued that storing data inside the country only provided an assumption of control.
    | Photo Credit:
    K. MURALI KUMAR

    On their account, India’s welfare systems, examinations, and health platforms could run on Indian soil, serving only Indian users, and still depend on foreign-governed compute, foundation models, and orchestration software underneath them. By that reasoning, a coordination layer for cross-border AI data flows, however carefully designed, would address a real but secondary problem and leave India’s dependence on foreign chips, cloud infrastructure, and foundation models largely untouched.

    In a 2021 analysis of the 2019 Bill, the Internet Freedom Foundation, a digital-rights group, argued that the safety of personal data does not depend on where it is stored, and that without surveillance reform, requiring data to stay in India raises the risk of intrusion by the state itself.

    The PSA paper takes a different course from a blanket rule. Its matrix keeps strategic and national-security data fully domestic and opens the tiers below, so localisation remains a tool for the most sensitive uses but not a general requirement. Whether a line drawn by data type and intended use will satisfy either side is untested for AI data flows.

    The cost claim

    The compliance-cost claim, which led ThePrint’s coverage, rests on one citedy and Innovation Foundation (ITIF), a Washington think tank whose supporters include Alphabet, Amazon, Apple, Meta, and Microsoft, according to ITIF’s own list

    The report is a global study, not an India-specific survey of the startups the claim concerns. That does not make the underlying intuition implausible. Smaller firms typically lack the balance sheets to run parallel domestic infrastructure that larger, often foreign, competitors can absorb as an ordinary cost of doing business, and industry bodies made versions of this argument in earlier rounds of DPDP rulemaking. The paper gives no figure for what compliance costs an Indian AI startup today.

    The paper sets out three positions side by side. Unrestricted localisation carries economic and scientific costs; unrestricted openness carries risks of surveillance, weaker oversight, and platform concentration; and a graded, risk-based middle path can be built. It does not choose between the groups that have argued over this ground for close to a decade, and it says it is meant as “a basis for deliberation and further discussion”, not as policy.

    Whether the coordination body it proposes is built inside the National Data Governance Committee, whether the negative list under Section 16 is still empty when its provisions take effect in May 2027, and whether collaborations such as the ICMR’s work with the French Health Data Hub become templates rather than isolated pilots remain open. The answers will depend on which of these groups sets the terms of what follows, once the discussion paper is no longer only a discussion.

    Amit Kumar is a data analyst based in Bangalore who writes on policy, politics, and technology.

    Post Views: 19

    Beyond data debate Indias moves
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Ewang Johnson
    • Website

    Related Posts

    India’s developmental ties with Africa guided by partners’ needs, priorities: EAM Jaishankar

    October 8, 2026

    FINCA Ventures awards $400,000 to six African startups

    October 7, 2026

    Not Microsoft. Not Google. Analysts Call This $2.7 Trillion Tech Titan the Most Undervalued AI Play.

    October 6, 2026
    Leave A Reply Cancel Reply

    Search
    Latest Post

    Uganda targets stronger Kenya tourism links as visitor numbers rise

    October 8, 2026

    Indian airlines lobby government to release emergency funds

    October 8, 2026

    Three people killed in attacks on Saudi Arabia airports, officials say

    October 8, 2026

    ILO backs action to advance sustainable labour mobility between Africa and Arab States

    October 8, 2026

    India’s developmental ties with Africa guided by partners’ needs, priorities: EAM Jaishankar

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • TikTok
    ABS TV and ABS Network News is a leading Pan-African 24/7 broadcasting network delivering nonstop news, talk shows, lifestyle programs, and digital media content worldwide through Satellite, Streaming Platforms, and Roku TV.
     
    Based in the United States, we connect Africa to the world while empowering creators, journalists, and brands through innovative media and broadcasting services.
    Facebook X (Twitter) Pinterest WhatsApp Instagram

    Our Picks

    Travel

    Uganda targets stronger Kenya tourism links as visitor numbers rise

    World News

    Indian airlines lobby government to release emergency funds

    Africa News

    Three people killed in attacks on Saudi Arabia airports, officials say

    Most Popular

    Features

    ILO backs action to advance sustainable labour mobility between Africa and Arab States

    Trending

    India’s developmental ties with Africa guided by partners’ needs, priorities: EAM Jaishankar

    Breaking News

    Dangote takes its record refinery IPO to East Africa with almost 20% of shares on offer

    © 2026 Copyright. All Rights Reserved by ABSAFRICATV
    • Privacy Policy
    • Terms of Services

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.