DPI Brief — July 30, 2026

NPCI Orders Phone Number Masking on UPI Apps by September 4

Layer: L2 — Payments

The National Payments Corporation of India (NPCI) has directed all UPI apps and partner banks to mask users’ mobile phone numbers, making username-based UPI IDs the default identifier for new users. The directive, reported by Business Standard and CXO Today, sets a September 4 compliance deadline. The move is explicitly framed as alignment with the Digital Personal Data Protection (DPDP) Act’s requirements on how companies collect, store, and share personal data.

Currently, UPI transactions expose the recipient’s phone number — a long-standing privacy concern that makes the number a de facto financial identifier. Masking phone numbers and pushing UPI IDs as the primary discovery mechanism is a meaningful shift, though Moneycontrol’s analysis correctly notes this is one piece of a larger puzzle: UPI’s identity verification model still places significant onus on the sender.

India Stack Exports Expand to 24 Countries; DigiLocker Deployments Begin in Kenya and Cuba

Layers: L1 — Identity, L3 — Documents, L4 — Commerce

India has signed DPI export agreements with 24 countries, moving beyond MoUs into active deployment. According to Times of India, work has begun on deploying DigiLocker systems in Kenya and Cuba. UPI merchant payments are now live in 10 overseas markets — Bhutan, France, Mauritius, Nepal, Qatar, Singapore, Sri Lanka, the UAE, Cambodia (added June 2026), and Greece (person-to-person link operational since May). A Social Impact Fund has been approved to provide financial and technical assistance for DPI pilots in low- and middle-income countries.

Delegations from Kenya, Rwanda, Nepal, Indonesia, and South Africa have engaged with UIDAI, NPCI, NIC, and C-DAC. Discussions are underway with Laos, Seychelles, Venezuela, Armenia, Fiji, Guyana, and Colombia for platforms including e-Sanjeevani, e-Office, and e-Hospital.

Bank of Baroda Breach: 1 TB of Aadhaar and Account Data Dumped by TripleX

Layers: L1 — Identity, L7 — Trust

The TripleX ransomware group has dumped approximately 1 TB of Bank of Baroda customer data — including Aadhaar numbers paired with photographs and financial records — on the dark web, freely accessible with no ransom demanded. As Tech Times reports, this is not a typical ransomware incident: TripleX operates a data-exfiltrate-and-publish model targeting state-owned financial institutions (they previously hit Indonesia’s PT Bank Negara).

The breach exposes a critical regulatory gap: the DPDP Act’s breach notification requirements and penalty provisions (up to ₹250 crore) do not become enforceable until May 2027. Current enforcement relies on CERT-In’s six-hour incident reporting mandate and the RBI’s Cyber Security Framework — tools that are narrower in scope. Bank of Baroda has not confirmed the total number of affected customers as of July 29.

IndiaAI Mission Clears 58 Centres of Excellence and 543 Data and AI Labs

Layers: L5 — Sectoral, L7 — Trust

MeitY Minister of State Jitin Prasada informed the Lok Sabha on July 29 that the IndiaAI Mission has approved 58 AI Centres of Excellence and 543 data and AI labs across India, as reported by Communications Today. The Mission operates across seven pillars, including the IndiaAI Challenge for Transforming Governance in partnership with Andhra Pradesh’s Real Time Governance Society — where Stage 1 evaluations are underway for AI use cases across government departments.

The government has outlined standards for AI deployment in citizen-facing services, including requirements for transparency, algorithmic fairness, and independent audit — directly referencing the DPDP Act’s framework of purpose limitation, data minimisation, and Data Protection Impact Assessments for Significant Data Fiduciaries.


Covered layers: L1 (Identity), L2 (Payments), L3 (Documents), L4 (Commerce), L5 (Sectoral), L7 (Trust)