India Now Pays Food Subsidies in Programmable E-Rupees. The E-Rupee Privacy Rules Don't Exist.
India now pays food subsidies in programmable e-rupees, but e-rupee privacy rules under the DPDP Act bind nobody until May 2027 — and no regulator sits.
#India Now Pays Food Subsidies in Programmable E-Rupees. The E-Rupee Privacy Rules Don't Exist.
Since 14 August, every eligible food-subsidy beneficiary in Chandigarh and Dadra & Nagar Haveli has received their entitlement not as money in a bank account but as programmable Digital Rupee tokens that can only be spent on wheat and rice, only at an authorised fair price shop, and only by scanning that shop's QR code. Yesterday, a detailed legal study of the e-rupee published in SCC Times pointed out the part nobody has been saying out loud: there are no e-rupee privacy rules under the Digital Personal Data Protection Act, the anonymity policy governing the currency has never been published, and the people furthest along into this system are welfare recipients who did not choose it.
That is the story worth your attention today. India has moved programmable central bank money out of the lab and onto the ration queue, and the data-protection architecture that is supposed to govern the resulting transaction trail does not bind anyone until 13 May 2027 — enforced by a Board that, as of last month, still had no chairperson and no members.
#What the 7 September study actually establishes
The piece, The E-Rupee Pilot: A Detailed Study of the Legal Framework and Privacy Implications of India's Central Bank Digital Currency, by Utsav Singh and Garima Wadhwa of NLU Jodhpur, is not an explainer. It is a gap analysis, and its central finding is jurisdictional: the e-rupee's issuance rests on solid statutory ground, while its data governance rests on almost nothing.
The issuance half is genuinely settled. The Finance Act, 2022, notified on 30 March 2022, amended the Reserve Bank of India Act, 1934 to widen the Section 2 definition of "bank note" to include currency in digital form, and to route the digital rupee through the RBI's exclusive issuance power under Section 22. Sections 24 to 26 — denomination, form, and legal tender status — were made applicable. Constitutionally, currency sits at Entry 36 of List I. There is no serious argument that the RBI lacks authority to issue an e-rupee.
The governance half is where the study lands its blows. No rules have been framed under the DPDP Act that are specific to central bank digital currency. No directions have been issued under Section 35-A of the RBI Act — the provision that would let the RBI impose binding privacy conditions on the banks and Token Service Providers actually operating the wallets. The RBI's October 2022 Concept Note acknowledges K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1 and the privacy stakes of a state-issued digital currency, and then leaves the operative choices to administrative discretion.
Scale is what turns that from an academic point into a live one. Retail circulation went from about ₹103 crore in December 2023 to roughly ₹1,016 crore by March 2025 — close to a tenfold rise — across a registered user base that has passed 60 lakh, with the pilot widened from four banks to nineteen plus fintech participants including CRED and MobiKwik. The wholesale segment, by contrast, effectively collapsed: CBDC-W volumes fell about 99.2% between March 2023 and March 2024, as RTGS and NEFT held their ground. The e-rupee's real growth is happening in retail and in government payments — precisely where personal data lives.
#E-rupee privacy rests on a threshold nobody has published
The RBI's stated approach to e-rupee privacy is "managed anonymity": small-value transactions carry cash-like anonymity, higher-value transactions are traceable. As a design philosophy it is defensible and broadly in line with what other central banks have attempted.
As law, it is close to unreviewable, and for one simple reason. The threshold has never been publicly specified. There is no notified figure separating the anonymous tier from the traceable tier, no instrument that fixes it, and no published process for changing it. The RBI has also been explicit in its own materials that it regards true anonymity in a digital setting as a misnomer and a laundering risk — a reasonable regulatory view, but one that cuts against the cash-equivalence claim on which much of the e-rupee's public case rests.
The consequence is that the single most important variable determining how much of a citizen's financial life is visible to the State is set administratively rather than by rule. A data principal cannot read the threshold, cannot know which side of it a given payment falls on, and therefore cannot know whether a transaction was recorded against their identity. Purpose limitation and data minimisation — the DPDP Act's two load-bearing principles — cannot be audited against a number that does not exist in public.
Compare this to how the same question has been handled in payments. When NPCI wanted to reduce identifier exposure in UPI, it issued a circular with a defined obligation and a hard compliance date, and phone number masking went live on 4 September. Whatever that instrument's shortcomings, a bank could read it and a regulator could enforce it. The e-rupee's anonymity policy has neither property.
#Programmable money has reached the ration shop
The welfare rollout is what makes the gap urgent rather than theoretical, and it moved faster in 2026 than most compliance teams noticed.
CBDC-based food subsidy delivery began in Gujarat on 15 February 2026 and in Puducherry on 26 February. Then, on 14 August, Union Minister Pralhad Joshi launched full-coverage CBDC-based Direct Benefit Transfer under the Pradhan Mantri Garib Kalyan Anna Yojana in Chandigarh and Dadra & Nagar Haveli — reported as the first territories in the country to fully digitise food subsidy delivery through Digital Rupee tokens. Earlier efforts were pilots with selected beneficiaries; this one aims at everyone eligible. PMGKAY nationally covers roughly 81.35 crore people under the National Food Security Act, 2013, which is the pool this model is ultimately being built for.
What a beneficiary receives is not rupees. It is a token carrying spending conditions encoded into the money itself. The RBI's own Digital Rupee FAQs, updated 4 February 2026, describe programmability parameters including expiry date, geo-location, merchant category code and merchant VPA. In the PMGKAY implementation the subsidy is purpose-bound to eligible foodgrains, redeemable only at empanelled fair price shops via QR scan. The stated policy goals — plugging leakage, and reducing dependence on biometric authentication at ration shops — are real gains, and the biometric point is a genuine privacy improvement over Aadhaar-authenticated PDS.
But the mechanism produces something the old model did not. Every CBDC transaction is recorded on a digital ledger maintained by the RBI, creating a persistent auditable trail. Bank-account DBT told the State that money had been credited. Programmable CBDC DBT tells the State what was bought, where, and when — for the specific population least able to negotiate the terms, opt out, or absorb the cost of an error. Financial privacy is being restructured from the bottom of the income distribution upward.
#Where the DPDP Act stops short on e-rupee privacy
Three features of the current regime combine to leave this trail lightly governed.
Consent is not the operative gate. Section 7 of the DPDP Act treats State processing for the issuance of a subsidy, benefit, service or certificate as a legitimate use. Where a beneficiary previously consented, or where the data already sits in a State database or register, no fresh consent is required. This was a deliberate design choice to keep welfare delivery running, and it means a PMGKAY beneficiary's e-rupee transaction record is being generated under a legal basis that never asks them anything. Notice and consent — the machinery most compliance programmes are built around — is largely beside the point here.
The exemption power is broad and unexercised. Section 17 lets the Central Government exempt any instrumentality of the State from all or part of the Act by gazette notification, on grounds including sovereignty, security, and public order, without Parliamentary approval. As of early 2026 no such notification had issued. That is the good news and the fragile news at once: the protections currently apply on paper because nobody has yet switched them off, and switching them off requires only a notification.
Nothing substantive binds yet, and nobody is enforcing. Under the phased commencement of the DPDP Rules, 2025, notified 13 November 2025, consent manager registration under Rule 4 activates on 13 November 2026, while the substantive fiduciary obligations — notice, security safeguards, breach reporting, data principal rights — wait until 13 May 2027. Penalties reach ₹250 crore per instance, on paper. Meanwhile the Data Protection Board of India, formally established in November 2025, still had no appointed chairperson and no appointed members as of August 2026. MeitY invited applications on 6 May 2026 and returned to the process on 6 June; the search-cum-selection committee for the chairperson, chaired by the Cabinet Secretary under Rule 17, has been soliciting names rather than finalising them.
So the sequence is: programmable welfare money at full territorial coverage in August 2026, substantive data protection obligations in May 2027, an enforcement body whenever it is staffed. The infrastructure is arriving roughly nine months ahead of the law that governs it, and further ahead of the regulator.
#Two unresolved legal questions businesses should track
Can conditional money be legal tender? Section 26(1) of the RBI Act declares the e-rupee legal tender "at any place in India." A token that functions only at an empanelled merchant, within a geofence, or before an expiry date is not spendable at any place in India. The study frames this as a live statutory tension rather than a settled matter, and it carries a property-rights dimension nobody has litigated: if welfare tokens can be programmed to expire, an unspent entitlement can be extinguished by configuration. There is no published rule on what happens to unspent PMGKAY tokens.
Who is the data fiduciary for an e-rupee wallet? The e-rupee reaches users through an indirect model — the RBI issues, banks and Token Service Providers distribute and operate wallets. Each layer touches transaction data. The RBI's Concept Note names this an accountability risk without resolving it, and the DPDP Act's fiduciary-and-processor framework has not been mapped onto the chain by rule. For any bank or fintech in a CBDC pilot, this is not abstract: on 13 May 2027 you will owe notice, security safeguards, breach reporting and rights fulfilment on data whose controllership is currently undefined. Determining your own status is work to start now, not after the Board is constituted.
#What to do before May 2027
For regulated entities in the CBDC chain, the practical asks are unglamorous. Map every e-rupee data flow your systems touch and record where transaction-level data lands, how long it is retained, and who else receives it. Write down your fiduciary-versus-processor position for each flow and the reasoning behind it. Do not assume that Section 7 legitimate use for the sponsoring department extends to your own commercial processing of the same records — it does not. Build purpose limitation into the ledger now, while the design is still cheap to change. Our /resources library tracks the phased obligations by date, and if you are assessing how consent infrastructure will interact with State-facing flows, /consent-manager covers the Rule 4 registration regime that switches on this November.
For citizens, the honest position is that a PMGKAY beneficiary in Chandigarh today has fewer effective data rights over their food-subsidy transaction history than a UPI user has over their phone number, and that this will remain true until at least May 2027.
#The gap that needs closing
The recommendations in yesterday's study are the right ones and none of them require new legislation: publish the managed-anonymity threshold, issue CBDC-specific privacy directions under Section 35-A of the RBI Act, frame CBDC rules under the DPDP framework, and put statutory footing under programmability rather than leaving it to configuration. Each is achievable within existing powers. None has been done.
India's data protection law is being built in the right order in most respects — rules first, then registration, then substantive duties, then enforcement. Programmable central bank money delivered to welfare recipients is the exception. It has arrived first, at the bottom of the income distribution, with the least legal cover and the least capacity to object. Closing that gap before the DPDP Act's substantive provisions commence is the difference between a data protection regime that shaped the e-rupee and one that inherited it.
Tracking DPDP obligations against a 13 May 2027 clock? Start with our /resources compliance timeline, and review the /consent-manager framework before Rule 4 takes effect on 13 November 2026.
Sources: SCC Times — The E-Rupee Pilot: Legal Framework and Privacy Implications · Swarajya — CBDC-based DBT rollout in Chandigarh and Dadra & Nagar Haveli · Upstox — CBDC-based DBT for food subsidy rolled out · MediaNama — Centre launches digital currency pilot for food subsidies in Puducherry · RBI — Digital Rupee (e₹) FAQs, updated 4 February 2026 · LiveLaw — India's Data Protection Board: Established In Law, Absent In Fact · Storyboard18 — Cabinet Secretary to head search panel for Data Protection Board chairperson · MediaNama — DPDP Rules 2025: government exemptions questioned · DPDPA.com — Section 17 with interpretation