DPI Brief — July 31, 2026

NPCI Orders Phone Number Masking on UPI Apps, Pushes Username IDs as Default

The National Payments Corporation of India (NPCI) has directed all banks and UPI applications to mask customers’ full mobile numbers during transactions and make username-based UPI IDs the default for new sign-ups. The circular, issued this week, requires that only the last four digits of a mobile number be visible to the counterparty. For QR code transactions, apps must not display the mobile number after payment completion. Banks and payment apps have been given a September 4, 2026 deadline for full compliance.

The move comes as NPCI holds discussions with its ecosystem partners on implementing the Digital Personal Data Protection (DPDP) Act. Currently, most UPI users register with their mobile number as their Virtual Payment Address (VPA), which simultaneously serves as a security verification mechanism and a privacy vulnerability. By making custom username-based VPAs the default, NPCI is attempting to resolve a long-standing tension between identity verification and data exposure in the UPI stack. The circular also mandates that UPI IDs and account numbers be masked across all customer-facing interfaces and communications — not just during live transactions.

Sources: Moneycontrol, Business Standard

India Signs DPI Partnerships with 24 Countries; DigiLocker Deployments Begin in Kenya and Cuba

The government has disclosed that India has signed memoranda of understanding with 24 countries to share its Digital Public Infrastructure model. The partnerships, detailed in a Lok Sabha reply by Minister of State Jitin Prasada on July 29, cover capacity building, technical assistance, feasibility studies, and deployment of population-scale digital solutions including the India Stack ecosystem — Aadhaar, UPI, DigiLocker, e-KYC, eSign, and the Account Aggregator framework.

Among the most advanced collaborations, Kenya has signed an Implementation Framework Agreement and Non-Disclosure Agreement with India for a DigiLocker rollout, while development of a foundational DigiLocker solution has commenced in Cuba. UPI-linked payment systems are now operational across 10 international markets — Bhutan, France, Mauritius, Nepal, Qatar, Singapore, Sri Lanka, the UAE, and Cambodia — with cross-border person-to-person transfers recently going live in Nepal and Greece. Discussions are also underway with Laos, Seychelles, Venezuela, Armenia, Fiji, Guyana, and Colombia for adoption of platforms such as e-Sanjeevani, e-Office, and e-Hospital. The government has additionally approved a Social Impact Fund to support pilot DPI deployments in low- and middle-income countries.

Sources: PIB, Times of India

CERT-In Runs 10 AI-Focused Cybersecurity Exercises; Bank of Baroda Breach Exposes Gaps

CERT-In has conducted 10 customised cybersecurity exercises and drills themed “Building Resilience against Frontier AI-driven Cyber Threats” between June and July 2026, involving 1,470 participants from 345 government and private organisations across power, telecom, BFSI, transport, education, health, and space sectors. In June, CERT-In also issued guidelines requiring all OEMs and technology providers to implement AI-accelerated vulnerability protection, including AI-assisted security testing, continuous monitoring, and incident response frameworks.

The urgency of these exercises has been underscored by the Bank of Baroda data breach, which became public on July 27. The public sector bank confirmed a cybersecurity incident following claims of a 1TB data leak on the dark web allegedly exposing customer account details and Aadhaar numbers. Tata Electronics separately raised fresh questions about India’s cybersecurity resilience in the same period, highlighting the widening gap between India’s rapid digital expansion and its defensive infrastructure. The breach at Bank of Baroda — India’s second-largest public sector bank — also follows a Bombay High Court ruling ordering the bank to refund ₹76 lakh to a cyber fraud victim, citing RBI’s zero-liability framework for timely-reported fraud.

Sources: DD India, LatestLY

EY Survey Reveals Enterprise Unreadiness for DPDP Act Implementation

An EY India survey has found that 71% of organisations have limited understanding of the Digital Personal Data Protection Act and its Rules. The survey, released as India approaches the staggered implementation timeline (full provisions by May 2027, Consent Manager registration provisions by November 2026), reveals significant sectoral disparities. Consumer, retail, and e-commerce sectors lead with 50% of respondents having initiated their DPDP compliance journey, while healthcare and life sciences trails at just 9.9%.

The readiness gaps are stark: 80% of organisations have not updated or drafted DPDP-aligned privacy policies, and over 83% have not begun end-to-end implementation. While 48% have initiated gap assessments, only 44% have documented data processing procedures, and 38% have categorised personal data. The Data Protection Board has been established with its head office in the National Capital Region, but its four members have not yet been appointed — leaving the enforcement mechanism for India’s first comprehensive data protection law effectively headless as the compliance clock ticks down.

Sources: CNBC TV18, Mondaq

UPI Crosses Another Border: Burj Khalifa Accepts Online UPI Bookings

NPCI International Payments Limited (NIPL) announced that Indian travellers can now use UPI for online bookings at At the Top, Burj Khalifa — making it the first attraction in the UAE to accept UPI payments. Developed in partnership with NEOPAY and Emaar Entertainment, the integration allows visitors to pay via a familiar, trusted method before even arriving in the country.

This follows UPI’s broader international expansion: Nepal introduced cross-border P2P transfers in June 2026, a person-to-person link with Greece went operational in May, and UPI merchant payments continue expanding across the Gulf and Southeast Asia. Each new acceptance point strengthens the case for UPI as a global payments rail — not just an India-only phenomenon.

Sources: SarkariTel