internet Research Lab logo


Governance, Openness and Security of Digital Public Infrastructure in India

26 August 2026

The internet Research Lab is glad to release our research report and project website on the Governance, Openness and Security of Digital Public Infrastructure in India.

Abstract

Digital Public Infrastructure (DPI) is increasingly promoted as a foundational layer of digital development — a framework for expanding service delivery, fostering digital economies, and enabling identification, payments, and data exchange at a large scale. This paper examines the gap between the normative promises of DPI and the operational characteristics of existing DPI systems in India.

While DPI remains under-defined despite its growing prominence, there is still an emerging cohesion around what principles should motivate and inform its design. Academic and government resources often identify "interoperability," "openness", security, privacy and participatory governance as central to DPI. These attributes are also related to policy decisions such as who owns the infrastructure, who operates it, who holds user data, who bears liability for its maintenance, how open participation is to new entrants, and more. In an effort to evaluate the gap between these normative promises and the operational characteristics of existing DPI systems in India, we develop a framework spanning six dimensions: ownership, governance models, voluntariness of use, economic incentives, data collection and use, openness, and security.

We apply this framework to analyse six projects in India, deliberately restricting ourselves to those explicitly termed DPI by the Government of India:

  1. FASTag – toll collection system
  2. Aadhaar eKYC – biometric identity verification
  3. DigiLocker – document storage platform
  4. Account Aggregator – financial data sharing
  5. Bharat Connect – bill payment system
  6. Unified Payments Interface – payments system

Our findings show that Indian DPI systems fall short not only of the aspirational principles articulated by academics and civil society, but of the Indian government's own stated claims.

Our analysis of the ownership, development and deployment of Indian DPIs shows, many key functions of DPIs (and sometimes even regulation) is delegated to private companies that are impervious to public scrutiny. Overall, we find little public control over digital public infrastructure. The Government's claims that Indian DPIs are “open” also do not stand up to empirical scrutiny. There are sparse repositories of open source code, but the core infrastructure remains a black box. In cases where API specifications are public, the API is closed to a set of entities – even for functionalities that could be made open. When it comes to privacy, these DPIs do not just reproduce the risks of equivalent commercial services, but compound them by binding user behaviour to government-issued identifiers, linking user activity across services that previously existed in silos, and concentrating data in centralised repositories accessible to state actors under broad statutory exemptions.

Our findings point to a need for a concerted effort in radically changing current deployments to be oriented towards the idealised vision that motivates the agenda: publicly controlled, privacy-respecting, open digital infrastructure.

Researchers respond

We're also happy to be hosting an essay series in response to our research report. These essays include perspectives from researchers around the world that contextualise the paper's implications in domains that the paper does not address, including foreign policy, political economy and competition policy. If you would like to contribute an essay to the series, please get in touch with us at mail@irl.works.

Visit the project website.

The authors of Governance, Openness and Security of Digital Public Infrastructure in India are Shruti Trikanad, Divyank Katira, Anunay Kulshrestha and Gurshabad Grover.