Before India Exports Digital Public Infrastructure, It Should Define It at Home
Mustafa Rajkotwala, Dhruv Jadhav / Sep 22, 2026
BRICS 2026 summit banners bearing images of Indian Prime Minister Narendra Modi, Russian President Vladimir Putin and Chinese President Xi Jinping in New Delhi, India, Sept. 12, 2026. (AP Photo/Mukhtar Khan)
India provides software to countries that want to build their own digital public infrastructure (DPI), but has yet to answer important questions about DPI at home.
In the past months, India has signed DPI cooperation agreements for “population-scale digital solutions” with at least 24 countries. At the BRICS ICT Track on Aug. 20, the Minister of State for Telecom announced that India would share modular, open source digital public infrastructure (DPI) frameworks that its 10 other member states could adapt.
In practice, this means a government can build its own biometric identity database on the open source platform underlying Aadhaar, which has reached nearly 1.4 billion enrollments, or develop an instant-payments system on the Unified Payments Interface (UPI), which completed ten years in August and carries the world's largest volume of real-time retail payments.
There is nonetheless a statutory gap. India has defined DPI in policy documents, but no statute determines what such a digital system precisely is — or what safeguards attach to one. The term carries weight in policy, procurement and diplomacy, but none in law.
In a G20 Leaders' Declaration adopted in New Delhi under India's presidency in 2023, DPI is defined as digital systems built by public and private actors on open standards, delivering services at societal scale. The declaration also states that such infrastructure should be accountable and respectful of personal data, privacy and intellectual property rights. Yet in India, there are no legal obligations for DPI operators to protect rights, nor is there a definition of a DPI system.
A valuable designation
Last year, the chief executive of Digi Yatra, an industry-led initiative to introduce paperless airport check-in and security using facial recognition, said that the platform aims to secure “DPI status” to take its technology beyond aviation into hospitality, office access and examinations. What is being sought, and from whom, went unstated.
India has, in practice, two kinds of DPI. Statutory ones such as Aadhaar rest on legislation and a statutory governance architecture. Hybrid ones — UPI, Open Network for Digital Commerce, Digi Yatra — are run by Section 8 companies operating with state endorsement, without any dedicated DPI statute. They perform functions of enormous public significance with substantial state backing, yet, not being state instrumentalities, fall outside the Right to Information Act, 2005, and carry none of the accountability that attaches to a statutory authority.
The consequences are visible in the largest hybrid system. The National Payments Corporation of India (NPCI) sets UPI's rules, standards and transaction limits, while operating its own products on the same network. A Committee Report on Digital Payments commissioned by the Ministry of Finance in 2016 found that just ten large banks held roughly three-quarters of NPCI's equity, and recommended more diffuse ownership and clear separation between infrastructure and regulatory functions. Because there was no obligation, the recommendation went unimplemented: NPCI still promotes its own state-owned mobile payment app, BHIM, competing against the very apps it regulates.
That is not merely an appearance problem. NCPI decides who is admitted to the network, on what technical and operational terms, with direct bearing on the competitors of its own product. Yet no law classifies it as a regulator. Nor is it an ordinary private company, since it performs a public function under the aegis of the Reserve Bank. It therefore falls outside the purview of the Right to Information Act, under which it could be held accountable. That gap is not a mere oversight in the design of NPCI. It follows from the fact that nothing in Indian law clearly defines what a DPI is nor what legal obligations and statutory responsibilities must attach to one.
The safeguards are elusive
Digi Yatra exemplifies the problem even more sharply. The Digi Yatra Foundation manages the Digi Yatra ecosystem. The Airports Authority of India, a statutory authority under the Union Ministry of Civil Aviation, is its largest single shareholder, with a 26 percent stake.
Yet its governance has been opaque. The government maintained that passenger data remained on the traveller's device and was shared only with the airports. However, technical reporting on the original Digi Yatra application in 2024 found that data was allegedly also being transmitted to Amazon Web Services (AWS) infrastructure associated with Dataevolve, the private vendor that built the system. Because no statute required a public, independent impact assessment, that divergence between the stated architecture and the operating one went unexamined until the system had already reached millions of travellers.
Currently, India’s Digital Personal Data Protection Act, 2023 (DPDP Act) does not close that gap. It governs how personal data is handled once a system is running: notice, consent, security, and a fiduciary's answerability for its processor. It does not require anyone to establish, before deployment, that a system operates the way its sponsors describe.
For ordinary data fiduciaries, the DPDP Act does not mandate a pre-deployment impact assessment or independent audit. Those obligations attach only to entities separately notified as Significant Data Fiduciaries (SDFs), which must undertake annual DPIAs and audits.
Defining DPI matters because, at present, a system does not attract stricter safeguards simply because it functions as DPI. Its operator must still be separately notified as an SDF. If that does not happen, even a system operating at population scale may fall outside requirements such as mandatory impact assessments and independent audits.
A remedy in sight?
These questions have now reached the courts. In Digi Yatra Foundation v. Data Evolve Solutions, the Delhi High Court is examining whether the Foundation or its former vendor retains IP rights over the underlying software.
The dispute exposes a significant governance question: who controls the infrastructure that processes the personal data of over 100 million Indians? The court intervened in March 2024, restraining the Dataevolve from using or copying the data, while directing the handover of server access, source code, domain certificates and cloud credentials to Digi Yatra. That the court needed to spell out what control of the platform entails, is itself the point. These data protections came as interim relief in a commercial dispute, rather than from any standard attached to Digi Yatra as public digital infrastructure. The suit still remains pending, though it was framed for trial in Oct. 2025.
Accountability, human rights, personal data and intellectual property are among the various attributes India endorsed together with the G20 in 2023. They are also, precisely, what this suit is about, and none are on track to be settled by anything other than a contractual dispute between a Digi Yatra and its vendor. We consider this gap as a serious risk.
A proper legal status for DPI could require an operator to retain control over critical infrastructure and data, and prescribe minimum terms for contracts with private vendors, including access to source code and cloud credentials, audit rights, restrictions on use of personal data, and transition obligations when a vendor exits.
Laws do this elsewhere already. In banking, the Reserve Bank of India (RBI) does not outsource a critical technology entirely to a contractor. Regulated entities must retain oversight, audit and access rights, and plan for the return or transfer of data and systems when the relationship ends. A DPI framework could do the same. It could also attach transparency obligations to DPI operators even where, as with the Digi Yatra Foundation, their present corporate form as Section 8 companies, excludes them from the Right to Information Act.
Why this is urgent
Two developments make this urgent. The first is artificial intelligence: the India AI Governance Guidelines envisage DPI and AI converging, with government applications such as Bhashini for language and translations built on shared rails, and national compute moving past 58,000 GPUs. Once AI agents transact on these systems, questions of liability and data provenance will multiply and will be hard to settle for a category with no legal boundaries. AI compounds the problem by involving more actors, more uses of the same data, and potentially more competing claims over the same systems.
The second is that these issues matter to the expanding list of India’s DPI partner countries. Bangladesh suspended its UPI-inspired Binimoy platform in 2025 and is rebuilding with open-source Mojaloop software. Sri Lanka holds an Indian grant of about $35 million for its digital identity project, but has not yet resolved how to fund the rest of the cost. Nepal has used UPI for cross-border transfers, but has not decided on a digital identity program. What remains open in each case is institutional as well as technical: how the system is governed, who answers for it, and what it costs.
An Indian statute would not decide those questions for another sovereign, but it would supply a reference position. A recipient government evaluating the Indian stack against another vendor compares the software architecture as well as the terms that come with it. At present India can point to no baseline: no test for what qualifies as DPI, no obligations that attach on qualification, no account of where ownership of the infrastructure, control of the data and rights in the software are meant to sit. Each partner therefore negotiates those terms from scratch, as Sri Lanka is now doing, and as Bangladesh did before abandoning the model. A definition would give India something to offer beyond the software, namely a shortcut to its own governance model.
For a statutory definition to offer clarity to hybrid platforms, it needs to do only two things. First, set a threshold: population scale, open standards, interoperability, and a function on which access to a service or entitlement effectively depends. Second, provide for legal obligations and statutory responsibilities: publish impact assessments, enforce purpose limitation, extend RTI Act transparency, and provide independent grievance redress.
The timing is favourable. Substantive obligations under the Digital Personal Data Protection Act, 2023 become enforceable in May 2027, and the entities they would apply to are mapping their systems and data governance structures now A definition framed now would be absorbed into work already underway rather than retrofitted later, and it would add what the Act leaves out: obligations that attach to a system because of what it is, not merely because of what it processes.
India has built infrastructure the rest of the world wants to emulate. The rulebook of data protections that goes with it would be a valuable contribution. A country that defines DPI in law exports a standard as well as the software that billions of people will depend on worldwide.
Authors


