DPI Brief — August 21, 2026
PIB Revisits UPI’s Decade of Scale; Zero MDR Stays for Consumers
The Press Information Bureau released a comprehensive retrospective on UPI’s ten-year journey, confirming that the platform processed 24,162 crore transactions worth ₹314 lakh crore in FY26 — a 60.9% CAGR from FY21’s 2,233 crore transactions. The data reveals that 86% of Person-to-Merchant (P2M) transactions were below ₹500, underscoring UPI’s deep integration into everyday retail commerce. P2P low-value transfers also continued to expand. Critically, Finance Minister Nirmala Sitharaman reiterated that UPI will remain free for consumers, even as the Payments Council of India and Startup Policy Forum push for a tiered MDR structure — zero for small merchants, 0.3% for large ones (above ₹20 lakh annual turnover). Government incentive outlay for FY27 stands at ₹2,000 crore, which the PCI considers insufficient against the ecosystem’s processing costs. The policy tension between sustainability and inclusion remains unresolved.
Source: PIB Press Release
GFF 2026: Cross-Border UPI Export to Africa, South America, and Nepal
NPCI’s international arm (NIPL) will centre-stage cross-border payments and DPI export at the Global Fintech Fest 2026, scheduled for September 8–11 in Mumbai. The seventh edition will bring together policymakers, central banks, and fintech firms from 70+ countries. NPCI is actively deepening UPI engagement across Africa and South America, aiming to replicate India’s real-time payment model in developing markets. Separately, India-Nepal digital payment connectivity expanded further: Kumari Bank launched a Nepal-India cross-border P2P remittance service via the UPI network on August 17, and QR-based UPI acceptance for Indian tourists in Nepal is growing. With UPI now live in 8+ countries and MoUs signed with 23 nations, the platform’s internationalisation is accelerating from pilot to infrastructure.
TRAI Opens Consultation on Network Slicing and QoS Standards
TRAI has released a Consultation Paper on Draft Amendments to the Standards of Quality of Service of Access and Broadband Service Regulations, 2024. Released on August 5 with comments open until September 7, the paper proposes new quality-of-service norms for mobile network slicing — a 5G-era mechanism allowing operators to allocate dedicated network slices for specific use cases (enterprise, IoT, emergency services). TRAI mandates that operators can charge differential tariffs only when they possess sufficient spectrum capacity, and that all tariff offerings must declare measurable download and upload speeds. This is significant for DPI: as sectoral layers (L5 — health, agriculture, governance) increasingly depend on reliable mobile connectivity, network slicing quality standards directly affect the performance of ABHA, AgriStack, and CPGRAMS at the last mile.
GeM Crosses ₹5 Lakh Crore GMV in FY26; MSME Participation Deepens
The Government e-Marketplace (GeM) recorded gross merchandise value exceeding ₹5 lakh crore in FY26, pushing cumulative procurement past ₹18.4 lakh crore since its 2016 launch. The platform now hosts over 68,000 buyer organisations and 60+ lakh registered sellers, with MSMEs winning a significant share of orders. GeM’s fully digital, cashless, paperless procurement model — mandatory under Rule 149 of the General Financial Rules 2017 — processed 51 lakh orders worth ₹2.36 lakh crore in FY26 alone, with over 11 lakh MSMEs active on the platform. The milestone reflects GeM’s maturation from a procurement portal into a structural pillar of India’s public commerce infrastructure (L4), enabling demand aggregation, reverse auctions, and transparent price discovery at scale.
DPDP Compliance Clock Ticks: May 2027 Deadline Looms
With the Digital Personal Data Protection Rules, 2025 now issued by MeitY, the compliance deadline of May 13, 2027 is approaching. KPMG and other advisory firms are actively guiding organisations through DPDP readiness assessments — covering consent management, data principal rights, breach notification (aligned with CERT-In’s 6-hour reporting mandate), and cross-border transfer restrictions. For the DPI ecosystem, this is cross-cutting: every layer from Aadhaar-authenticated eKYC (L1) to UPI payment processors (L2) to DigiLocker document custodians (L3) and ONDC buyer apps (L4) must demonstrate DPDP compliance. The interaction between DPDP’s breach notification obligations and CERT-In’s existing 6-hour incident reporting requirement under the IT Act 2000 creates overlapping compliance burdens that data fiduciaries are still working to reconcile.
DPI Brief is published daily by DPI Watch. Covering all 7 layers of India’s Digital Public Infrastructure.