<?xml version="1.0" encoding="UTF-8"?>
<article>
    <front>
        <article-meta>

            <article-id pub-id-type="doi">
                10.65919/uimrj.2026.v2i8002            </article-id>

            <title-group>
                <article-title>
                    Sovereign Data, Open Borders: India’s Regulatory Architecture for Digital Governance in 2026                </article-title>
            </title-group>

            <abstract>
                <p>In 2026, India’s digital economy stands at a inflection point. With over 900 million internet users and a data-driven economy projected to exceed $1 trillion by 2028, the question of who controls Indian data—and under what conditions it may cross borders—has moved from policy debate to operational reality. This article presents a comprehensive, multi-dimensional analysis of India’s current regulatory architecture for data localisation and digital sovereignty, anchored in the Digital Personal Data Protection Act, 2023 (DPDPA), the draft DPDP Rules, 2025, the constitution of the Data Protection Board of India (2025), and the Supreme Court’s proportionality ruling in Internet Freedom Foundation v. Union of India (2025). It situates India’s approach within a comparative global context, assesses trade-law implications under the WTO and emerging bilateral frameworks, and proposes a flexible, risk-based governance model that reconciles sovereign control with global economic integration. The article argues that India’s future lies not in rigid data walls, but in adaptive, trust-based mechanisms that enable both regulatory autonomy and cross-border innovation. Drawing on constitutional jurisprudence, statutory interpretation, empirical trade data, and international best practices, this study offers a forward-looking blueprint for India’s digital governance in the coming decade.</p>
            </abstract>

        </article-meta>
    </front>
</article>