Every time you tap a screen, search the web, or scan your fingerprint at a government office, you generate data. This data – invisible, intangible, yet extraordinarily powerful – shapes economies, governments, and personal identities in ways that were unthinkable just a few decades ago. The challenge of our time is striking the right balance between protecting this data and allowing the innovation it fuels. Data privacy is no longer a technical footnote; it sits at the heart of social and political philosophy, raising deep questions about autonomy, state power, and the limits of consent.
Table of Contents
- What is digital data?
- Why ownership is complicated
- Global data laws: how different countries approach privacy
- The EU’s GDPR
- The United States: a fragmented landscape
- India’s DPDP Act, 2023
- The concept of data fiduciaries and consent
- Biometrics and state surveillance
- How Aadhaar works – and what it promises
- The privacy trade-off
- The dissent that still matters
- The future of data privacy
- Cross-border data flows
- Corporate accountability in data breaches
- AI and the new data frontier
- Data sovereignty as a political concept
What is digital data?
Digital data refers to any information that exists in a binary, machine-readable format – from your name and email address to your browsing history, biometric scans, and GPS coordinates. Unlike physical objects, digital data has some unique properties that make it philosophically and legally tricky. It is malleable: data can be copied, modified, merged, and analysed in countless ways. It is ephemeral in one sense – easily deleted with a keystroke – yet remarkably persistent in another, since copies can live on servers across the globe indefinitely.
These characteristics create serious problems for traditional ideas of ownership. When you hand over your phone number to a delivery app, that data doesn’t leave your possession; it multiplies. The app stores it, perhaps shares it with advertising partners, and analytics firms may aggregate it with other data points to build a profile of your habits. As the Brookings Institution has argued, treating data as simple property fundamentally fails because personal information serves multiple interests simultaneously and cannot be neatly confined to a single owner.
Why ownership is complicated
Physical property works on the principle of exclusion: if you own a bicycle, someone else cannot use it at the same time. Data does not follow this rule. A single data point – say, your date of birth – can exist in dozens of databases simultaneously without any copy diminishing another. This non-rivalrous nature means that classical property frameworks struggle to apply. Research published in Philosophy & Technology highlights that calls for data ownership are better understood as demands for the redistribution of resources and recognition of data subjects, rather than as literal property claims.
Moreover, personal data often involves overlapping interests. A photo of a group of friends contains data about every person in the frame. Genetic information about one individual inevitably reveals facts about their biological relatives. These entanglements make it practically impossible to assign exclusive ownership to any single person. The World Bank’s World Development Report cautions that granting individuals property rights over their data could actually deepen inequalities, because economically vulnerable people might feel compelled to sell their personal information for very little value.
Global data laws: how different countries approach privacy
In the absence of a universal framework, countries have developed their own data protection regimes. Three of the most significant are the European Union’s General Data Protection Regulation (GDPR), the United States’ patchwork of privacy laws, and India’s Digital Personal Data Protection Act (DPDP Act), 2023. Comparing them reveals both shared principles and telling divergences.
The EU’s GDPR
Enacted in 2018, the GDPR is widely considered the global benchmark for data protection. It applies to any organisation processing personal data of EU residents, regardless of where that organisation is based. Its core principle is that individuals must give free, specific, informed, and unambiguous consent before their data can be processed. The GDPR also grants robust rights such as data portability, the right to object to automated decision-making, and the right to erasure (commonly known as the “right to be forgotten”).
Enforcement has been aggressive. Cumulative GDPR fines have crossed โฌ5 billion since 2018, and penalty volumes continued to accelerate through 2025, with that year alone accounting for roughly โฌ2.3 billion in fines – a significant year-over-year increase. The regulation’s extraterritorial reach has effectively forced companies worldwide to raise their privacy standards.
The United States: a fragmented landscape
The U.S. still lacks a comprehensive federal privacy law. Instead, privacy protection comes from a combination of sector-specific federal statutes (like HIPAA for health data) and an expanding number of state-level laws. California’s Consumer Privacy Act (CCPA) was a landmark, and since then, states such as Colorado, Virginia, Delaware, Indiana, and Kentucky have enacted their own comprehensive privacy regulations. By 2026, over nineteen states have active consumer privacy laws, covering more than half the American population.
The Federal Trade Commission remains the primary federal enforcer, pursuing companies under its authority over unfair and deceptive practices. However, the absence of a unified federal standard creates a complex compliance environment for businesses operating across state lines and makes the U.S. system notably less coherent than the GDPR.
India’s DPDP Act, 2023
India enacted its first comprehensive data protection law – the Digital Personal Data Protection Act – in August 2023, following the Supreme Court’s landmark 2017 ruling in Justice K.S. Puttaswamy v. Union of India, which established informational privacy as a fundamental right under the Indian Constitution. The DPDP Act adopts several GDPR-like principles: consent must be free, specific, informed, and unambiguous. It introduces the concept of data fiduciaries (equivalent to GDPR’s “controllers”) who bear primary responsibility for lawful data processing.
However, there are key differences. The DPDP Act applies only to digital personal data and does not distinguish between personal and sensitive personal data the way the GDPR does. It also does not grant a right to data portability. Notably, the Indian government retains broad powers to classify certain entities as significant data fiduciaries, imposing additional obligations such as appointing independent auditors. Penalties can reach up to โน250 crore (approximately โฌ28 million) per violation. As Latham & Watkins’ comparative analysis notes, the DPDP Act follows broadly similar principles to the GDPR but reflects India’s specific regulatory priorities, including the emphasis on ease of doing business alongside privacy protection.
The concept of data fiduciaries and consent
A thread running through all these frameworks is the importance of consent and the fiduciary duty that data handlers owe to individuals. The idea of a data fiduciary draws from the legal concept of a trustee: just as a trustee must act in the best interests of beneficiaries, a data fiduciary must handle personal data responsibly, transparently, and for specified purposes only. This concept shifts the burden away from individuals (who cannot realistically read every privacy policy) and onto the organisations that collect and process data. It is a recognition that the power asymmetry between data subjects and data collectors demands legal intervention beyond simple consent mechanisms.
Biometrics and state surveillance
Perhaps no issue illustrates the tension between data privacy and public welfare more vividly than the use of biometric identification systems by governments. India’s Aadhaar programme is the world’s largest biometric identity system, with over a billion enrolments linked to fingerprints and iris scans.
How Aadhaar works – and what it promises
Aadhaar assigns every enrolled resident a unique 12-digit identity number tied to their biometric and demographic data. The system was designed to ensure that welfare benefits – food subsidies, cooking gas subsidies, pension payments – reach the people who need them, eliminating the “leakage” caused by duplicate or fictitious identities. As the Center for Global Development explains, Aadhaar has facilitated the restructuring of service delivery across public distribution systems, social pensions, and mobile payments, affecting the lives of millions of people and billions of dollars in public spending.
The privacy trade-off
The benefits are real, but so are the risks. Critics have argued that linking a person’s biometric data to a centralised database gives the state an unprecedented capacity for surveillance. Every time a citizen authenticates their identity via Aadhaar – whether to collect rations, open a bank account, or receive a subsidy – a transaction record is created. Over time, these records could theoretically be used to track a person’s movements, spending patterns, and social interactions.
The Indian Supreme Court took up this question in 2018. In a 4-to-1 majority decision, the Court upheld the constitutional validity of Aadhaar but imposed significant restrictions. The majority held that the data collected was “minimal” and that Aadhaar’s architecture did not create a surveillance state. However, it struck down Section 57 of the Aadhaar Act, which had allowed private companies to require Aadhaar authentication, ruling that this violated the fundamental right to privacy. The Court also declared unconstitutional a provision that allowed intelligence officers to access the Aadhaar database for national security purposes without judicial oversight.
The dissent that still matters
Justice D.Y. Chandrachud – who had authored the earlier landmark privacy ruling – dissented sharply. He argued that the Aadhaar framework posed genuine risks of surveillance and profiling, and that biometric data is qualitatively different from other personal information because, once compromised, it cannot be changed or revoked. As Privacy International’s analysis observed, the dissent highlighted the digital security risks for over a billion Indians and held that Aadhaar directly violated rights to informational privacy and self-determination.
The Aadhaar debate captures a dilemma that every society must confront: at what point does the pursuit of administrative efficiency and welfare delivery justify requiring citizens to surrender biometric data to the state? Is the exclusion of even a small percentage of people from essential services an acceptable failure rate when scaled to a population of over a billion?
The future of data privacy
Data privacy is not a problem that any single law or court ruling can solve permanently. Several emerging challenges are reshaping the landscape and will demand new thinking from philosophers, policymakers, and technologists alike.
Cross-border data flows
Data does not respect national borders. A social media post made in Mumbai may be stored on a server in Virginia and analysed by an algorithm running in Dublin. This reality creates enormous regulatory complexity. According to Baker McKenzie’s 2026 global risk outlook, geopolitical tensions are driving a widening divergence in cross-border data transfer requirements, with some countries prioritising data sovereignty and localisation while others advocate for free data flows built on mutual trust.
The EU, for instance, only permits data transfers to countries it considers to have “adequate” data protection. The EU-US Data Privacy Framework attempts to bridge transatlantic data flows, but its long-term stability remains uncertain. Meanwhile, countries like China and Russia enforce strict data localisation mandates, requiring that certain types of data be stored within their borders. India’s DPDP Act takes a middle path, restricting transfers to certain jurisdictions while allowing the government to designate approved countries. The Global Cross-Border Privacy Rules Forum, launched in 2025, is an attempt to build multilateral consensus, but progress has been slow.
Corporate accountability in data breaches
The frequency and scale of data breaches have made corporate accountability a pressing concern. The global average cost of a data breach reached $4.88 million in 2024, and regulators worldwide are tightening breach notification requirements and imposing heavier penalties. The EU’s enforcement trajectory tells the story: cumulative GDPR fines have now exceeded โฌ5.8 billion, and the pace of enforcement actions is increasing rather than declining.
But fines alone may not be sufficient. There is a growing philosophical argument that corporations holding vast quantities of personal data should be treated not merely as service providers but as custodians with fiduciary obligations. This would mean that a company’s failure to protect user data would be treated not just as a regulatory violation but as a breach of trust – analogous to a bank losing its customers’ deposits. This shift in framing, from compliance to custodianship, could fundamentally alter how data breach accountability is structured in law.
AI and the new data frontier
Artificial intelligence adds another layer of complexity. Generative AI models are trained on vast datasets, raising questions about whether the use of personal data in training constitutes processing under existing privacy laws. Brazil’s data protection authority set a notable precedent by suspending Meta’s processing of personal data for AI training purposes. The EU AI Act, becoming fully applicable in August 2026, introduces risk-based obligations for high-impact AI systems that intersect directly with existing data protection requirements. The philosophical question at the core of this debate is whether individuals retain any meaningful claim over insights, patterns, and inferences that AI systems derive from their personal data – even if the original data has been anonymised or aggregated.
Data sovereignty as a political concept
Beyond individual privacy, data has become a matter of national sovereignty. Governments increasingly view data as a strategic resource – comparable to oil or minerals – and seek to control its flow in and out of their jurisdictions. This trend complicates the originally borderless vision of the internet and forces a reckoning with competing values: the economic benefits of open data flows versus the political imperatives of national security and digital self-determination.
What do you think? If data is central to who we are in the digital age, should individuals have a fundamental right to control every trace of information they generate – or is some loss of control an unavoidable price of participating in a connected society? And when the state collects biometric data in exchange for welfare benefits, who bears the greater risk: the citizen who surrenders their fingerprints, or the government that promises to keep them safe?
References
- https://www.brookings.edu/articles/why-data-ownership-is-the-wrong-approach-to-protecting-privacy/
- https://link.springer.com/article/10.1007/s13347-020-00404-9
- https://wdr2021.worldbank.org/spotlights/who-owns-personal-data/
- https://secureprivacy.ai/blog/data-privacy-trends-2026
- https://www.mcdonaldhopkins.com/insights/news/u-s-and-international-data-privacy-developments-in-2025-and-compliance-considerations-for-2026
- https://en.wikipedia.org/wiki/Digital_Personal_Data_Protection_Act,_2023
- https://www.globalprivacyblog.com/2023/12/indias-digital-personal-data-protection-act-2023-vs-the-gdpr-a-comparison/
- https://www.cgdev.org/blog/indias-supreme-court-ruling-privacy-and-aadhaar
- https://iapp.org/news/a/the-indian-supreme-courts-aadhaar-judgement-a-privacy-perspective
- https://privacyinternational.org/long-read/2299/initial-analysis-indian-supreme-court-decision-aadhaar
- https://www.lexology.com/library/detail.aspx?g=9b12696f-ddd9-4b87-87ca-8a0cfbfde603
Leave a Reply