India has become a global supplier of digital public infrastructure (DPI) software, signing cooperation agreements with at least 24 nations for what it describes as population-scale digital solutions. At the BRICS ICT Track in August, the Minister of State for Telecom announced plans to share modular, open-source DPI frameworks with the bloc's other 10 member states. Yet despite this international push, India has not resolved fundamental questions about how these systems should be governed, protected and legally defined within its own borders.
The infrastructure India is exporting rests on two flagship platforms. The Aadhaar biometric identity system has enrolled nearly 1.4 billion people, while the Unified Payments Interface (UPI) marked a decade in operation in August and now processes the world's largest volume of real-time retail payments. Other countries can build their own versions on these open-source foundations. Yet India itself has never enacted a statute that defines what constitutes a DPI system or what legal obligations should attach to one.
Policy documents do contain a definition. The G20 Leaders' Declaration adopted in New Delhi during India's 2023 presidency describes DPI as digital systems built by public and private actors on open standards, delivering services at societal scale, and states that such infrastructure should be accountable and respectful of personal data, privacy and intellectual property rights. This language carries weight in policy discussions, procurement decisions and diplomatic negotiations. In law, however, it carries none.
Two models, one gap
India operates two distinct categories of DPI. Statutory systems like Aadhaar rest on dedicated legislation and formal governance structures. Hybrid systems—including UPI, the Open Network for Digital Commerce, and Digi Yatra—are managed by Section 8 companies that operate with state backing but without any dedicated DPI statute. These hybrid platforms perform functions of enormous public importance with substantial government support, yet because they are not state bodies, they fall outside the Right to Information Act, 2005, and lack the accountability mechanisms that attach to statutory authorities.
The National Payments Corporation of India (NPCI), which operates UPI, illustrates the problem. NPCI sets the rules, standards and transaction limits for the entire network while simultaneously operating its own products on that same infrastructure. A 2016 Committee Report on Digital Payments commissioned by the Ministry of Finance found that roughly three-quarters of NPCI's equity was held by just ten large banks, and recommended more dispersed ownership and clearer separation between infrastructure and regulatory functions. That recommendation was never implemented. NPCI continues to promote BHIM, its state-owned mobile payment app, in direct competition with the apps it regulates. NPCI decides which entities gain access to the network and on what technical and operational terms, directly affecting competitors to its own product. Yet no law classifies it as a regulator, and because it performs a public function under the Reserve Bank's aegis, it falls outside the Right to Information Act and cannot be held accountable through that mechanism.
The safeguards are elusive
Digi Yatra, an industry-led initiative to introduce paperless airport check-in and security using facial recognition, demonstrates the governance problem even more sharply. The Digi Yatra Foundation, which manages the ecosystem, has the Airports Authority of India—a statutory authority under the Union Ministry of Civil Aviation—as its largest single shareholder with a 26 percent stake. Yet its operations have remained opaque.
The government stated that passenger data remained on travellers' devices and was shared only with airports. Technical reporting on the original application in 2024 revealed that data was allegedly also being transmitted to Amazon Web Services infrastructure associated with Dataevolve, the private vendor that built the system. Because no statute required a public, independent impact assessment before deployment, this divergence between the stated architecture and the actual operating system went unexamined until the platform had already reached millions of travellers.
India's Digital Personal Data Protection Act, 2023 (DPDP Act) does not address this gap. The law governs how personal data is handled once a system is running—notice, consent, security, and processor accountability. It does not require anyone to establish, before deployment, that a system operates as its sponsors describe. For ordinary data fiduciaries, the DPDP Act does not mandate pre-deployment impact assessments or independent audits. Those obligations apply only to entities separately notified as Significant Data Fiduciaries (SDFs), which must undertake annual Data Protection Impact Assessments and audits.
The absence of a DPI definition means that a system does not automatically attract stricter safeguards simply because it functions at population scale. Its operator must still be separately notified as an SDF. If that notification does not occur, even a system serving hundreds of millions of people may fall outside requirements such as mandatory impact assessments and independent audits.
A remedy in sight?
These governance questions have now reached the courts. In Digi Yatra Foundation v. Data Evolve Solutions, the Delhi High Court is examining whether the Foundation or its former vendor retains intellectual property rights over the underlying software. The dispute raises a fundamental question: who controls the infrastructure that processes the personal data of over 100 million Indians?
In March 2024, the court intervened by restraining Dataevolve from using or copying the data and directing handover of server access, source code, domain certificates and cloud credentials to Digi Yatra. That the court needed to spell out what control of the platform entails is itself revealing. These data protections emerged as interim relief in a commercial dispute rather than from any standard attached to Digi Yatra as public digital infrastructure. The suit remains pending, though it was framed for trial in October 2025.
Accountability, human rights, personal data protection and intellectual property are attributes that India endorsed alongside the G20 in 2023. These same issues are precisely what the court case addresses, yet none are on track to be settled by anything other than a contractual dispute between Digi Yatra and its vendor. A proper legal status for DPI could require operators to retain control over critical infrastructure and data, and prescribe minimum terms for contracts with private vendors, including access to source code and cloud credentials, audit rights, restrictions on use of personal data, and transition obligations when a vendor exits.
Precedent exists elsewhere. In banking, the Reserve Bank of India does not outsource critical technology entirely to contractors. Regulated entities must retain oversight, audit and access rights, and plan for the return or transfer of data and systems when relationships end. A DPI framework could operate similarly. It could also attach transparency obligations to DPI operators even where, as with the Digi Yatra Foundation, their corporate form as Section 8 companies currently excludes them from the Right to Information Act.
Why this is urgent
Two developments make legislative action pressing. The first is artificial intelligence. The India AI Governance Guidelines envisage DPI and AI converging, with government applications such as Bhashini for language and translation built on shared infrastructure, and national compute capacity expanding past 58,000 GPUs. Once AI agents transact on these systems, questions of liability and data provenance will multiply and become difficult to resolve for a category with no legal boundaries. AI compounds the problem by introducing more actors, more uses of the same data, and potentially more competing claims over the same systems.
The second reason is that these issues matter to the growing number of countries adopting India's DPI model. Bangladesh suspended its UPI-inspired Binimoy platform in 2025 and is rebuilding with open-source Mojaloop software. Sri Lanka holds an Indian grant of approximately $35 million for its digital identity project but has not yet resolved how to fund the remainder of the cost. Nepal has used UPI for cross-border transfers but has not decided on a digital identity program. What remains unresolved in each case is institutional as well as technical: how the system is governed, who answers for it, and what it costs.
An Indian statute would not dictate those answers for another sovereign nation, but it would establish a reference position. A recipient government evaluating the Indian stack against another vendor compares both the software architecture and the terms that accompany it. Currently, India can point to no baseline: no test for what qualifies as DPI, no obligations that attach upon qualification, no clarity about where ownership of the infrastructure, control of the data and rights in the software should reside. Each partner therefore negotiates those terms independently, as Sri Lanka is now doing and as Bangladesh did before abandoning the model. A statutory definition would give India something to offer beyond the software itself—namely a shortcut to its own governance model.
For a statutory definition to provide clarity to hybrid platforms, it needs only two components. First, establish a threshold: population scale, open standards, interoperability, and a function on which access to a service or entitlement effectively depends. Second, provide for legal obligations and statutory responsibilities: publish impact assessments, enforce purpose limitation, extend Right to Information Act transparency, and provide independent grievance redress.
The timing is favourable. Substantive obligations under the Digital Personal Data Protection Act, 2023 become enforceable in May 2027, and entities subject to them are currently mapping their systems and data governance structures. A definition framed now would be absorbed into work already underway rather than retrofitted later, and it would address what the Act leaves out: obligations that attach to a system because of what it is, not merely because of what it processes.
India has built infrastructure that the rest of the world wants to replicate. The rulebook of data protections that accompanies it would be a valuable export. A country that defines DPI in law exports a standard as well as the software that billions of people will depend on globally.



