top of page

By:

Sagari Gupta

24 March 2026 at 7:46:04 pm

India’s Digital Footprint Is No Longer a Choice

India’s digital economy has made personal data unavoidable. The harder task is ensuring that citizens retain meaningful control over the trails they leave behind. In August this year, the Unified Payments Interface processed about 24.5 billion transactions worth nearly Rs. 29.8 lakh crore, according to data from the National Payments Corporation of India. Aadhaar’s authentication system recorded more than 17,759 crore transactions in FY2025-26, according to UIDAI’s dashboard. Behind these...

India’s Digital Footprint Is No Longer a Choice

India’s digital economy has made personal data unavoidable. The harder task is ensuring that citizens retain meaningful control over the trails they leave behind. In August this year, the Unified Payments Interface processed about 24.5 billion transactions worth nearly Rs. 29.8 lakh crore, according to data from the National Payments Corporation of India. Aadhaar’s authentication system recorded more than 17,759 crore transactions in FY2025-26, according to UIDAI’s dashboard. Behind these numbers sits a question Indian policy has yet to answer clearly: what happens to the data these systems generate, and who controls it? The most pressing privacy question in India today is not what people choose to post online. It is what they are required to leave behind to take part in everyday life. A UPI payment leaves a transaction trail. A loan application generates financial records. A food-delivery order records your address and buying habits. A cab ride shows where you work and when you travel. A social-media post adds something more personal: what you think, like, fear or believe. Individually, these fragments look harmless. Together, they can describe a remarkably detailed version of a person’s life. Orwellian Society This is not digital technology invading a society that was once offline. It is a society in which digital systems have become part of ordinary economic life. For a software professional, deleting social media may be an inconvenience. For a domestic worker paid through a bank account, a student applying for a scholarship or a pensioner completing an identity check, opting out is not a workable choice. Consider an ordinary Saturday. You check the weather, search for a medicine, order groceries, pay through UPI, book a cab and make an online purchase. No single action tells a complete story. Together, they reveal your location, spending patterns, household composition, health concerns and daily routine. Artificial intelligence changes what this data means, because machine systems are increasingly good at connecting fragments that once sat in separate databases. The concern is not that an AI system knows what you searched for once. It is that automated systems can identify patterns across millions of ordinary interactions that, taken individually, meant little. The problem is also one of asymmetry. The individual usually sees only the service being offered; the organisation sees the accumulated information behind it. A single transaction may be trivial, but millions of such transactions can become commercially or administratively valuable when linked and analysed. That makes data different from many other commodities. Once information has been copied, combined or used to build a profile, the original individual may have little visibility into its subsequent journey. The question is therefore not simply who collected the data, but who can combine it, infer from it and act upon those inferences. The public debate on AI scraping is often too simple. Not every online interaction is pulled into an AI model, and not every company holds every piece of a person’s digital life. Collection depends on the platform, its policies, its technical architecture and the applicable law. But the gap is real: the capacity to analyse vast volumes of information is growing faster than most people’s understanding of where their information goes. A PwC India survey found that 56 percent of consumers did not know their rights over personal data, while 70 percent said privacy policies were difficult to understand. When a person does not understand what they are agreeing to, consent risks becoming a formality rather than a genuine choice. There is also a distinction between privacy and secrecy. A person may have nothing embarrassing to hide and still reasonably object to a detailed record of their movements, purchases and associations being assembled without meaningful control. Privacy is less about having something to conceal than about retaining a degree of agency over one’s own life. A Right on Paper The Digital Personal Data Protection Act, 2023 gives individuals rights to correct and erase personal data, subject to the conditions and exceptions set out in the law. The government notified the Digital Personal Data Protection Rules in November 2025, with provisions coming into force in phases. On paper, this changes the relationship between citizens and the organisations that hold their data. In practice, most people do not think in terms of “Data Principal” or “Data Fiduciary” when an app asks for access to their information. They think about whether the app will still work if they say no. That is the test that decides whether a data-protection law functions on the ground. A small retailer selling online may not fully understand the compliance requirements. An elderly customer faces a long privacy notice before completing a routine transaction. A young user accepts an app’s terms because refusing means losing access to a service that friends or employers already use. A right that exists on paper does not guarantee a person’s ability to exercise it. The ability to protect personal data is not distributed evenly. A high-income professional can pay for privacy-focused software, encrypted communication and legal advice. Someone on a smaller income uses whichever free application is available. The same divide applies to time. A person who understands technology can adjust permissions and request deletion. A person working two jobs may accept an app’s terms because reading a 30-page privacy notice at 11 p.m. is hardly realistic. This produces an uneven outcome. The people with the strongest ability to protect their data are often the same people with the clearest sense of what is being collected. Those with fewer resources tend to generate more data while having less power to question how it is used. This is why treating “going offline” as the solution has limited use in India. Cash does not cover every digital transaction. A basic phone does not replace every digital service. Deleting a social-media account does not erase bank or government records. Refusing every digital platform carries its own economic cost, particularly for people who depend on digital payments for income. The realistic goal is not disappearance. It is control. India’s digital economy should not be measured only by payment volumes or platform reach. It should also be measured by whether people understand the exchange taking place underneath that convenience. Regulators should track whether a person can find out what a service holds about them, correct inaccurate information, delete data that is no longer necessary and withdraw consent without clicking through several layers of settings. The sharper test is what happens when data collected for one purpose becomes useful for another. Rising Stakes The stakes will rise as India’s digital infrastructure becomes more deeply embedded in public services, finance and commerce. The country has built impressive systems for moving money and verifying identity; the next challenge is to build equally credible systems for limiting what can be inferred from the information those systems generate. The next phase of India’s privacy debate should move past the idea of digital disappearance, because most people have no practical way to leave the systems through which they earn, pay, borrow, travel, study and access public services. The more useful task is making those systems answerable to the people whose lives they record. The measure of digital freedom is not whether a citizen leaves no trace. It is whether they have a say over where that trace leads. (The writer is an independent public policy researcher. Views personal.)

Lateral upgrade to ailing annihilation

Sep 9, 2024
3 min read

Updated: Oct 21, 2024

Lateral upgrade to ailing annihilation

Being the first person from the private sector to be appointed as chairperson of Securities and Exchange Board of India (SEBI) as part of the government’s lateral initiative, Madhabi Puri Buch also holds the honour of being the first woman to hold the top post as capital market regulator.

But the laurels that the former private sector banker enjoyed in her earlier stint with ICICI Bank, was marred with allegations that she and her husband were having a stake in offshore entities, which were used to artificially inflate shares of Adani group companies.

Terming the allegation as `character assassination, Buch clarified that all disclosures have already been furnished and the fund in question did not invest in any securities involving the Adani group.

When it rains, it pours. This allegation was subsequently followed by Congress Party allegation that Buch had received salary and post-retirement benefits from ICICI Bank after she quit the private sector bank.

In its clarification to the stock exchanges, ICICI Bank asserted that the payments made to Buch were purely retirement benefits after her exit from the bank and they were neither salary nor employee stock options.

Prior to these allegations, Buch tenure at SEBI was all about bringing in quick reforms on operational issues by changing the format of consultation paper to bring in larger responses digitally. Being data savvy, the rationale of her decisions were democratic based on big data analysis derived from the responses received to the consultation papers.

Further she bifurcated the duties of the SEBI staff between operations and enforcement, which were done by the same persons earlier. Having worked for the private sector in the capital market domain space, Buch had a better understanding of the subject compared to officers from the administrative service in the past that reflected even in her orders as a whole-time director at SEBI before becoming the chairperson. As a whole time director at SEBI, her orders on adjudication issues were more directional to the capital market space, according to experts in the compliance space. She was also quick to revamp the old provisions of the 90s at SEBI.

Being tech and data savvy, Buch enhanced regulatory surveillance and detection of market manipulation, insider trading and fraud while also emphasizing on strengthening corporate governance by introducing stricter rules for independent directors and enhancing disclosures for related-party transactions.

To put in perspective, the annual report of the capital market regulator in the just concluded financial year revealed that the number of investigations related to insider trading jumped to 175 in 2023-24 from 85 in the preceding year while probes related to front running jumped over three times to 83 from 24 in the preceding year.

Transparency in mutual funds by implementing measures to protect retail investors along with tightening norms for initial public offers, particularly in the SME platforms were some of her other positive initiatives including confirmation of denial of any market rumours within 24 hours for the top 100 listed companies which will be extended to top 250 companies from December 1. However increased transparency and compliance with tightening regulations led to increased operational costs for the market participants and hence faced resistance from certain quarters. Born in 1966, Buch completed her primary education in Mumbai and graduated with specialization in Mathematics from Delhi and later obtained a management degree from Indian Institute of Management, Ahmedabad. In between, she got engaged to Dhawal Buch, a director at a consumer goods multinational at the age of eighteen and got married at the age of 21.

Besides ICICI Bank, Buch also worked as a lecturer at a college in England, worked at Greater Pacific Capital in Singapore and ICICI Securities as its CEO. She also worked as executive director on several private sector companies and as a consultant for New Development Bank (Brics Bank).

What now remains to be seen, is whether Buch, who survived the 26/11 terror attack when she along with her husband, was attending a meeting at Taj, be able to overcome the current ordeal. Keeping fingers crossed for the times to come.

Comments


bottom of page