DPI Brief — August 02, 2026
NPCI’s August 1 UPI Overhaul: Caps, Autopay Restrictions, and Fraud Controls
Layer 2 — Payments
Starting August 1, the National Payments Corporation of India (NPCI) has enforced sweeping operational changes to UPI aimed at preventing the kind of server outages seen in April-May 2025. The new rules, notified via NPCI’s May 21 circular on UPI and API usage guidelines, introduce hard daily caps on balance checks (limited per app), restrict linked bank account views to 25 per day, and cap payment reversal requests at 10 per 30 days. Autopay mandate executions are now limited to one attempt plus three retries per mandate, and all autopay processing is restricted to non-peak hours (outside 10:00–13:00 and 17:00–21:30). Transaction status checks for pending payments are limited to three attempts with a 90-second cooling period between each.
Perhaps most significant for consumer protection: the beneficiary’s registered bank name will now be displayed before confirming a payment, reducing impersonation fraud. NPCI has also warned that non-compliant PSP banks and apps may face penalties, API restrictions, or suspension of new customer onboarding. These changes reflect a maturation of India’s payment rails — shifting from growth-at-all-costs to reliability and security-first engineering.
Sources: NPCI Guidelines, NDTV, Economic Times
India Post Goes Full DPI: ONDC and GeM Integration Approaches Completion
Layer 4 — Commerce
The Department of Posts is in the final stages of migrating its entire network of approximately 165,000 post offices to a modernized IT 2.0 platform, with full integration targeted by August 4, 2025. Over 86,000 offices are already live on the new application. The twin integrations with ONDC and the Government eMarketplace (GeM) are the headline moves: ONDC integration enables prepaid wallet bookings, centralised order tracking via open APIs, and automated reconciliation, while GeM’s backend links India Post for API-driven automated pricing and COD settlement dashboards.
India Post has already begun fulfilling ONDC orders as a logistics service provider, marking a significant milestone for the open commerce network’s last-mile ambitions. The Department has also launched 344 new delivery centres offering morning, evening, and holiday delivery slots — a direct competitive response to private logistics operators. For ONDC’s small sellers, particularly in tier-3 and rural India, India Post’s ubiquitous physical presence could be the missing logistics link.
Source: PIB Press Release
SEBI’s “@valid” UPI Handles: A New Trust Layer for Capital Markets
Layer 2 — Payments (Cross-sectoral)
SEBI has mandated standardised, validated, and exclusive UPI IDs for all registered intermediaries — brokers, mutual funds, and investment advisors — effective October 1, 2025. The new UPI handles follow a structured format: username@valid.bankname, with a visible green checkmark for verified entities. SEBI has also launched the “SEBI Check” tool, allowing investors to independently verify any payment credential before transferring funds.
This is a targeted intervention against the rising tide of impersonation fraud in capital markets, where fake UPI IDs mimicking legitimate brokers have duped retail investors. By creating a verified namespace (@valid) exclusively for SEBI-registered entities, the regulator is essentially building a DNS-like trust layer atop the existing UPI infrastructure — a pattern that could extend to other regulated sectors.
Source: SEBI PR No. 31/2025, Groww
CERT-In’s Comprehensive Cyber Audit Mandate: Every Business is Now in Scope
Layer 7 — Trust
Effective July 25, 2025, CERT-In’s new Comprehensive Cyber Security Audit Policy Guidelines (CISG-2025-02) impose mandatory annual third-party cybersecurity audits on all public and private enterprises operating in India — not just critical infrastructure. Audits must align with ISO/IEC 27001 and follow frameworks including OWASP, OSSTMM, and CSA CCM. Organisations must retain system logs for at least 180 days, share attack vectors and malware samples with CERT-In during investigations, and report breaches within the existing 6-hour window.
The guidelines also mandate Software Bill of Materials (SBOM) disclosure, going beyond software to cover infrastructure components. For India’s DPI ecosystem — which processes Aadhaar authentications at scale, handles billions of UPI transactions, and stores sensitive health and agricultural data — these audit requirements create a much-needed accountability baseline. The timing aligns with the DPDP Rules’ phased implementation, reinforcing a converging regulatory posture on data protection and cybersecurity.
Sources: CERT-In Guidelines, Strobes Analysis, MediaNama
Aadhaar App Crosses 40 Million Downloads; mAadhaar Retired
Layer 1 — Identity
The new Aadhaar App has crossed 40 million (4 crore) downloads, with UIDAI reporting that over 40 million people have updated their mobile numbers through the app. The older mAadhaar app was retired on June 30, 2026, with all users migrated to the new application. Starting July 1, the app also supports email ID updates — free for the first six months — further reducing dependence on physical Aadhaar Seva Kendras for routine updates.
The app’s rapid adoption (from 21 million downloads in May to 40 million by mid-July) signals that mobile-first identity services are becoming the primary interface for India’s 1.44 billion Aadhaar holders. UIDAI has also waived charges for biometric updates (MBU-1) for children aged 7-15 for one year from October 1, 2025, and extended fee relaxation for document updates through the SSUP portal until June 2027.
Source: UIDAI Press Release
Covering layers L1 (Identity), L2 (Payments), L4 (Commerce), and L7 (Trust). Today’s brief is anchored by the NPCI UPI rule changes effective August 1 — the most consumer-facing DPI update this cycle.