DPI Brief — July 04, 2026

1. CERT-In Probes Tata Electronics Breach Exposing iPhone 18 Pro Data [L7 – Trust/Cybersecurity]

India’s Ministry of Electronics and IT (MeitY) made its first public comments on a major data breach at Tata Electronics — Apple’s contract manufacturer in Hosur, Tamil Nadu. IT Secretary S. Krishnan confirmed that CERT-In has been formally notified and is investigating the incident. A ransomware group dubbed “World Leaks” claims to have stolen 630 GB of confidential data, including iPhone 18 Pro component lists, supplier assignments, and motherboard blueprints, which have surfaced on the dark web. The breach also reportedly contained documents from Tesla, Qualcomm, and TSMC.

Tata Electronics has engaged a global forensics consultant, restricted internal system access, and notified affected clients. Apple is reportedly conducting its own assessment and has issued DMCA takedowns for leaked content. The incident is a watershed moment for India’s cybersecurity posture — it comes days after MeitY hosted a CII Cybersecurity Summit, and underscores the urgent need for supply chain security frameworks under India’s evolving DPDP and CERT-In directives.

Source: Reuters, Hindu BusinessLine

2. UPI Processes 22.72 Billion Transactions in June; Greece Becomes 10th Country [L2 – Payments]

NPCI released its June 2026 payments data: UPI processed 22.72 billion transactions worth ₹28.92 lakh crore, marking a 23% year-on-year increase in volume and 20% in value. While monthly figures dipped marginally from May’s record 23.20 billion transactions, the daily average hit an all-time high of 757 million transactions, confirming UPI’s deepening penetration as the default payment rail for India.

In a significant international milestone, UPI went live in Greece through a partnership between NPCI International Payments Ltd (NIPL) and Eurobank, making Greece the 10th country where Indian travellers can use UPI for merchant payments. Commerce Minister Piyush Goyal witnessed the demonstration in Athens. PhonePe retained its dominant market share at 46.26% by volume and 49.06% by value for May 2026.

Source: NPCI / Entrackr, ET BFSI

3. GoDaddy Challenges Delhi HC Anti-Fake Website Ruling — Global Internet Governance at Stake [L7 – Trust/Legal]

GoDaddy, the world’s largest domain registrar, has challenged sweeping directives from the Delhi High Court designed to curb brand impersonation online. The December 2025 ruling, issued after complaints from over 20 companies including Amazon, McDonald’s, and Microsoft, ordered: (a) domain sellers must stop offering free privacy protection by default, (b) buyer details must be disclosed to anyone with “legitimate interest” within 72 hours, and (c) registration of domain names resembling protected trademarks must be blocked.

GoDaddy filed a 5,000-page appeal arguing the directives are “commercially destabilising,” contradict India’s own DPDP Act privacy-by-default principles, and could force domain registrars to exit India. The case will be heard by a larger bench on July 16. This ruling, if upheld, would fundamentally reshape domain governance norms — not just for India, but globally, since domain names operate across borders.

Source: Reuters, BRIC.TV

4. ONDC Crosses 20 Crore Buyers, 5 Lakh Sellers [L4 – Commerce]

As India’s Digital India programme completed 11 years this week, the Press Information Bureau released updated statistics on the Open Network for Digital Commerce (ONDC). By June 2026, ONDC had expanded to over 20 crore buyers, 5 lakh sellers, presence in 1,000 cities, and nearly 90 lakh monthly transactions. The platform is also powering social commerce through the eSARAS initiative, connecting Self-Help Group products to ONDC’s buyer network across 11+ buyer applications.

Meanwhile, Government e-Marketplace (GeM) has onboarded over 25 lakh sellers and serves 1.36 lakh+ buyer organisations across 10,500+ product categories, with cumulative order value reaching ₹8.69 lakh crore. GeM’s integration with ONDC now enables government-registered sellers to extend their reach beyond public procurement into the broader digital commerce ecosystem.

Source: PIB, PIB eSARAS

5. Data Protection Board Constituted; DPDP Enforcement Clock Ticking [L7 – Trust/Regulation]

The Data Protection Board of India (DPBI) has been formally constituted, activating the enforcement mechanism under the Digital Personal Data Protection (DPDP) Act, 2023. With the DPDP Rules, 2025 notified in November 2025, a three-phase enforcement timeline is now in effect — Phase 1 is already live, with full penalty enforcement (up to ₹250 crore per violation) expected by May 2027. Organisations processing Indian user data must complete consent manager registration, implement UX-compliant consent flows, and establish data protection frameworks ahead of the escalating compliance deadlines.

The enforcement tracker maintained by KensaraAI notes that while the Board structure is in place, finalised rules for operational enforcement are still being worked through. MeitY’s own social media channels have been actively reminding businesses that “the compliance clock is ticking.”

Source: StartupFeed, MeitY/Facebook


Published by DPI Watch — tracking India’s Digital Public Infrastructure daily.