Custody and control
Data Sovereignty and Constitutional Personhood
In this framework, data sovereignty means more than server location. It means accountable custody of citizen records, lawful transfer, traceable access, correction rights, recovery questions and remedy when compromised data produces harm.
What the archive can show
The MeitY and digital-harm records raise questions about stolen or foreign-held data. The present material supports a public-interest question: which authority is responsible for identifying, recovering, restoring or lawfully destroying compromised citizen data where law permits?
Evidence required
- source of the compromised record;
- custodian and transfer path;
- access and modification history;
- reporting and response record;
- remedy or absence of remedy.
Limits
This page does not assert that every exposed record can be recovered. It states the accountability question and source-record standard for future case files.
Data sovereignty beyond server location
The phrase "data sovereignty" is often used in international relations and technology policy to mean that a country's citizen data should be stored on servers located within that country's jurisdiction. This is a necessary but insufficient definition. In the Digital Constitutional Personhood framework, data sovereignty means something more fundamental: that the citizen whose data is held retains constitutional rights in relation to that data, and that the public authority responsible for collecting, storing, using or transferring the data is accountable to the citizen and to the Indian constitutional framework for what it does with those records. A citizen's biometric template or identity record stored on a server inside India but used, shared or compromised without the citizen's knowledge or constitutional protection is not meaningfully sovereign from the citizen's perspective. Sovereignty, in this framework, is an accountability relationship, not a geography.
The MeitY and digital-harm dimension
The Supreme Court petition W.P.(Crl.) 163/2026 raises data sovereignty questions in the context of MeitY (the Ministry of Electronics and Information Technology) and Indian citizen data that may be held, accessed or transferred in ways that do not meet the constitutional accountability standard. The DISHA research archive supports this petition with source-backed evidence items concerning the custodianship of citizen digital records, the disclosure practices of government and contracted digital platforms, and the absence of adequate correction and remedy pathways for citizens whose data has been compromised. These records are treated under the DISHA claim-to-source system: government records are verified records, the research analysis is a DISHA assessment, and gaps in institutional response are recorded as unresolved questions pending official disclosure.
Custodian accountability and the transfer question
Every citizen data record held by a public authority has a custodian: the ministry, agency, vendor or platform that controls access to the record and is responsible for its accuracy, security and lawful use. Data sovereignty in practice requires that this custodian be identifiable by the citizen, reachable through a complaint or correction process, and answerable to a constitutional accountability standard when things go wrong. The transfer question arises when citizen data moves from one custodian to another — from a government portal to a contracted operator, from a domestic system to an international platform, from a programme database to a law-enforcement agency. Each transfer point is a potential accountability gap. The DISHA archive's evidence standard for data-sovereignty cases requires documentation of the transfer path, the legal authority for each transfer, and the record of what happened to the data at each stage.
Correction, deletion and the remedy architecture
Constitutional accountability for citizen data does not end with storage security. It includes the right to correct inaccurate records, to request deletion where law permits, to know what data a public authority holds, and to receive a meaningful remedy when data is compromised in ways that cause harm. The Digital Constitutional Personhood framework asserts that these correction and remedy rights are not merely regulatory preferences; they are expressions of the constitutional rights to equality, dignity and personal liberty that Articles 14 and 21 protect. The archive's accountability test for data-sovereignty cases therefore asks not only whether a breach or unauthorised transfer occurred, but whether the affected citizen was informed, whether a correction process was available, whether a remedy was provided, and whether the public authority responsible has disclosed what it did in response to the compromise.