DPI Brief — August 25, 2026

DoT Makes Biometric Verification Mandatory for All SIM Cards — Aadhaar eKYC Forced for Holders

Layer: L1 (Identity) + L7 (Trust)

The Department of Telecommunications on August 21 notified the Telecommunications (User Identification) Rules, 2026 (G.S.R. 750(E)), making live biometric verification — face, fingerprint, or iris — mandatory not just for new SIMs but for replacements, detail changes, and even SIM surrender. Aadhaar holders have no alternative: they must use Aadhaar e-KYC, with no option for offline or document-based verification.

A companion circular operationalises the Digital Intelligence Platform (DIP) from August 24, which distributes a “representative image” of every subscriber to all telecom operators daily. The Internet Freedom Foundation has flagged that Rule 4 requires operators to store raw Aadhaar numbers in their customer records — directly contradicting UIDAI’s own Data Vault and tokenisation norms designed to prevent Aadhaar number proliferation across business databases.

The rules also raise exclusion concerns: a failed biometric scan — common among manual labourers and the elderly — now means a lockout from a phone number, which in turn gates access to UPI, DigiLocker, bank accounts, ration e-KYC, and welfare payments. The convergence of Aadhaar (L1) with telecom identity creates a single point of failure for digital public life.

UPI Completes 10 Years: 741 Banks, ₹314 Lakh Crore in FY26

Layer: L2 (Payments)

The Unified Payments Interface turns a decade old on August 25. NPCI’s numbers tell the scale: from a transaction value of ₹7,000 crore in FY2016-17 to ₹314 lakh crore in FY2026 — a nearly 13,000-fold increase. Monthly volumes crossed 2,320 crore transactions in May 2026, with 741 banks now live on the network.

The merchant payment story is particularly notable: 86% of person-to-merchant transactions are below ₹500, confirming UPI’s deep penetration into everyday retail. The platform has also gone international with linkages in Sri Lanka (PickMe rides), UAE, Singapore, and Nepal — though domestic volumes remain overwhelmingly dominant.

Centre Raps States Over AgriStack Delays — 39% of Sown Area Still Without Farmer ID

Layer: L5 (Sectoral)

At a National Conference on AgriStack in New Delhi on August 22, Union Agriculture Minister Shivraj Singh Chouhan publicly questioned states over delays in implementing the Digital Agriculture Mission. As of August 15, only 61% of India’s net sown area has been linked to a Farmer ID — nearly two years after the mission launched. Most states have not yet drafted standard operating procedures for cultivator categories.

The Farmer ID is being positioned as the gateway for direct benefit transfers and government procurement. Andhra Pradesh has already made it mandatory for government procurement, with 51.83 lakh farmers registered against a target of 64.71 lakh. Jammu & Kashmir has digitised 70 lakh land parcels for AgriStack integration. But the 39% gap — concentrated in states with smaller and marginal landholders — raises questions about whether the digitisation push will exclude the farmers it most needs to reach.

CERT-In Advisory on Microsoft 365 Attacks Amid IT Sector Cyber Alerts

Layer: L7 (Trust)

On August 7, CERT-In issued a critical advisory warning of increased attacks targeting Microsoft 365 accounts through password spraying and phishing. The advisory gained urgency after threat actors claimed access to employee data from TCS and HCLTech cloud environments. Both firms confirmed to stock exchanges that no breach of internal systems or client environments was found, but the incidents underscore the expanding attack surface as India’s IT giants deepen their cloud infrastructure.

The DIP’s daily distribution of subscriber biometric images to all operators (see above) adds a new high-value target to India’s already strained cybersecurity landscape. The intersection of biometric data centralisation and CERT-In’s repeated advisories on identity-based attacks is a tension the DPDP Act’s enforcement mechanism — still not fully operational — will eventually have to address.