DPI Brief — July 29, 2026
NPCI Mandates UPI Phone Number Masking by September 4
The National Payments Corporation of India (NPCI) has directed all UPI apps and partner banks to mask users’ phone numbers during transactions, moving toward username-based handles as the default identifier. The mandate, first reported by NewsBytes and confirmed by Moneycontrol, is being positioned as a compliance measure under the Digital Personal Data Protection (DPDP) Act. Currently, UPI apps display full phone numbers of both sender and receiver during transactions — a practice that exposes personal data to bystanders and screenshots. NPCI is in active discussions with banks and third-party app providers (PhonePe, Google Pay, Paytm, etc.) to implement the change. The shift to handles (like user@paytm) as the primary UPI identifier has been on the cards for years, but this is the first time NPCI has set a hard deadline. This is a meaningful privacy upgrade for India’s 400 million+ UPI users.
Digital Payment Frauds Total ₹3,588 Crore; UPI Remains Safest Channel
Data shared in Parliament on July 28 reveals that Indians lost ₹3,588.22 crore across 5.83 lakh digital payment fraud cases between FY22 and September 2026. Banks managed to recover only ₹238.83 crore — roughly 6.6% of total losses. According to Fortune India, credit card and internet banking frauds accounted for the bulk (₹1,447 crore from 2.43 lakh credit card cases alone). Crucially, UPI transactions accounted for a minimal share of total losses, reinforcing that the UPI rails themselves remain highly secure — the vulnerability lies in social engineering (Authorised Push Payment frauds) where users are tricked into approving transactions. RBI released a discussion paper in April 2026 on safeguards for digital payment frauds, and NPCI is running its multilingual “Main Moorkh Nahi Hun” awareness campaign.
Paytm Payments Bank Formally Wound Up by Delhi High Court
The Delhi High Court has formally ordered the winding up of Paytm Payments Bank Limited (PPBL), bringing an eight-year regulatory saga to a close. As reported by TechTimes, the order followed RBI’s audit findings of persistent KYC compliance failures and irregular transactions. PPBL’s customers’ UPI handles have already been migrated to partner banks through NPCI, ensuring continuity of UPI payments. The winding up underscores that India’s digital payments ecosystem, while robust at the rail level, demands strict compliance from the entities that ride on it. For the DPI ecosystem, this is a signal that regulatory tolerance for KYC lapses — the identity layer (L1) meeting the payments layer (L2) — is at an all-time low.
J&K Accelerates ABDM Rollout, Targets Universal ABHA Coverage
Jammu & Kashmir’s Chief Secretary has directed an accelerated rollout of the Ayushman Bharat Digital Mission (ABDM), with the state now targeting universal ABHA (Ayushman Bharat Health Account) coverage. According to Digital Health News, the administration is pushing health facilities to integrate with Health Information Exchange (HIE) and adopt digital health records. J&K’s push is significant because ABDM adoption has historically been slower in Union Territories and special-status regions. Universal ABHA linkage would enable portability of health records across the country — a core promise of India’s health DPI stack. Separately, the National Health Authority concluded a two-day “Chintan Shivir” reviewing the next phase of Ayushman Bharat reforms, stressing digital health adoption and financial sustainability, as reported by DD News.
Digital India Awareness Workshop in Nagaland on July 30
The Ministry of Electronics and Information Technology (MeitY) is organising a Digital India State Awareness Workshop in Nagaland on July 30, bringing together government departments and stakeholders to accelerate adoption of key DPI platforms: DigiLocker, API Setu, EntityLocker, Meri Pehchaan, UMANG, and myScheme. The workshop will also cover the DPDP compliance framework — a timely inclusion given NPCI’s UPI masking mandate and the approaching November 2026 deadline for Consent Manager registration. For smaller states like Nagaland, these workshops serve as the primary on-ramp to India’s DPI stack, often determining whether state-level services actually integrate with national platforms or remain siloed.
Covering L1 (Identity), L2 (Payments), L3 (Documents), L5 (Health), L6 (Governance), and L7 (Trust) layers of India’s Digital Public Infrastructure.