India Is Exporting Its Digital Rails to 25 Nations — But the DPDP Act Isn't Ready to Travel
India's DPI stack is now piloting in 25 countries and moving into AI. Yet the DPDP Act's cross-border and enforcement provisions don't bite until 2027.
#India Is Exporting Its Digital Rails to 25 Nations — But the DPDP Act Isn't Ready to Travel
India's Digital Public Infrastructure (DPI) export has just crossed a symbolic line: as of late July 2026, India's identity and payments stack is in pilot phases across 25 countries, up from 23 earlier this year, and the government is now pitching AI, multilingual, and trusted-data-sharing layers on top. The uncomfortable part is that the DPDP Act — the law meant to govern all the personal data these rails move — still has its cross-border transfer rules and full penalty regime sitting behind a May 2027 switch. India is shipping the plumbing before the guardrails are load-bearing.
That gap is not a technicality. It is the single biggest reason a European bank was told last year it could not send contact details to India, and it is the question every partner government in the Global South should be asking before it wires its citizens' identities into an India-designed system. This post breaks down what was announced, what the DPDP Act actually does and does not yet cover, and what the timing mismatch means for Indian businesses, foreign partners, and ordinary data principals.
#What just happened
At a set of industry sessions reported on July 27–28, 2026, senior officials from the Ministry of Electronics and IT (MeitY) and the Ministry of External Affairs (MEA) laid out how far India's DPI diplomacy has travelled. According to Open Source For You, the foundational stack now on offer covers the Unified Payments Interface (UPI), the Aadhaar-enabled Payment System (AePS), DigiLocker, the Bharat Bill Payment System, FASTag, and DigiYatra — the full spine of what is branded internationally as "India Stack."
Biometric Update reported on July 27 that the strategy is now moving "beyond identity and payments to AI," with the pilot count rising from 23 to 25 nations. MeitY Secretary S. Krishnan told the gathering that "AI has changed the way DPI operates or can operate," pointing to voice-first agricultural services and deeper credit penetration. The Bhashini multilingual platform, the Ayushman Bharat Digital Mission for health, and a pension rail targeting a jump from 100 million to 250 million subscribers were all floated as the next export modules.
Crucially, India is not selling a finished product. It hands partner governments modular, open-source blueprints and lets them assemble localized systems — the model behind the Implementation Framework Agreement signed with Kenya for a DigiLocker pilot. The whole effort traces back to India's 2023 G20 Presidency, which produced the Global Digital Public Infrastructure Repository (GDPIR) as a shared library of DPI code and design patterns.
On its own, this is a genuine soft-power win. The problem is what sits underneath it.
#The DPDP Act is real — but most of it hasn't switched on
It is easy to assume that because the Digital Personal Data Protection Act, 2023 is "in force," the data flowing through India's DPI is fully governed. It isn't yet.
MeitY notified the DPDP Rules 2025 in November 2025 and set three separate commencement dates for different clusters of provisions: November 14, 2025; November 14, 2026; and May 14, 2027. As multiple law firms have mapped out, the substantive obligations — the ones with teeth — land at the far end of that runway:
- Consent Manager framework: operational around November 2026, when registration with the Data Protection Board opens for the intermediaries meant to give every citizen a single dashboard to grant and withdraw consent.
- Cross-border transfer rules (Section 16): not effective until May 2027, and the government has issued no restricted-country list yet.
- Full penalty enforcement, including the headline ₹250 crore ceiling: also keyed to May 2027.
In other words, during the exact window in which India is scaling its DPI to two dozen-plus countries and layering AI on top, the law's most important control on where personal data can go — Section 16's cross-border regime — is still dark. The Data Protection Board itself only got its Chairperson and Members appointed in mid-2026 after a Cabinet Secretary-led search, as Storyboard18 documented. A regulator that is barely months into having a quorum is now nominally responsible for a data ecosystem being replicated across borders.
#Why the timing mismatch matters
Consider what the DPI stack actually does. UPI moves transaction data. DigiLocker moves verified identity documents. The Account Aggregator layer moves consent-based financial data. Aadhaar-linked authentication sits under much of it. When India helps another country stand up its own version, it is exporting not just software but a governance model — the assumption that consent, purpose limitation, and data-principal rights are baked in.
Except, in India, those principles are still statutory promises awaiting operational rules. Three concrete consequences follow.
1. Partner governments inherit a template whose safeguards are unfinished. Ajay Rajan of Protean eGov framed digital sovereignty in the AI era as requiring "control over data, identity and intelligence," and rightly insisted on "consent by design, audit by design, privacy by design," grounding these in the DPDP framework. But a partner country adopting India Stack today is copying architecture designed against a law whose consent-manager and cross-border machinery isn't live even at home. Design intent is not the same as an enforceable rulebook.
2. India's own adequacy problem gets sharper, not softer. In a disclosure that still shapes the conversation, the European Data Protection Supervisor declined a European Investment Bank request to transfer contact data to India, citing gaps in India's data-protection framework. The Observer Research Foundation's "adequacy dilemma" analysis explains why: the Data Protection Board sits under MeitY rather than as a statutorily independent authority, and the Act grants the government wide processing exemptions. The GDPR vs DPDP Act contrast is stark here — the GDPR treats privacy as a fundamental right enforced through an independent supervisory authority and adequacy assessments, while the DPDP Act uses a "negative list" model that permits transfers except to jurisdictions the government specifically restricts. Exporting the stack faster than the law matures does nothing to answer the EU's core objection.
3. Citizens carry the risk during the gap. Metadata from population-scale rails — who authenticated where, when, and how often — is exactly the kind of re-identifiable exhaust that a mature cross-border regime is supposed to fence in. Until Section 16 and the Board's enforcement powers are switched on, the practical protection for a data principal whose data crosses a border is thinner than the "privacy by design" branding suggests.
#Data localization is filling the vacuum — awkwardly
Delhi is not blind to this. In March 2026, MeitY issued a cloud framework, reported by News9, that bars "Top Secret" and "Secret" datasets — Aadhaar, PAN, UPI, Voter ID, tax systems — from public cloud platforms, pushing them onto sovereign or government-controlled infrastructure via the National Informatics Centre and State Data Centres.
That is data localization stepping in where the DPDP Act's cross-border rules haven't yet. But it is a blunt instrument: it addresses government datasets and national-security classification, not the everyday commercial personal data that private data fiduciaries move through the same rails. It also sits uneasily beside the export story — India is simultaneously locking its most sensitive data behind sovereign walls at home while encouraging the replication of the collecting architecture abroad. The two impulses, sovereignty and evangelism, are pulling in different directions.
#What Indian businesses should do now
For Indian companies — especially data fiduciaries plugged into DPI rails, and the growing roster of firms selling DPI-adjacent services abroad — the July developments are a prompt to get ahead of the May 2027 cliff rather than treat it as distant.
- Map your cross-border flows today. Section 16's negative-list model means the default is that transfers are permitted, but that default can narrow the moment the government notifies restricted jurisdictions. Know where your data physically goes and through which processors, so a future notification doesn't strand you.
- Build consent infrastructure now, not in Q4 2026. With the Consent Manager framework operational around November 2026, retrofitting granular, revocable, purpose-bound consent is far cheaper before the deadline than after. If you are architecting consent capture, our consent-manager resources walk through what registration-ready consent artefacts need to contain.
- Treat "privacy by design" as an auditable claim. Regulators — and skeptical foreign partners — will increasingly ask for evidence, not slogans. Document data-flow diagrams, retention schedules, and access logs.
- Watch the adequacy track. If you serve EU customers, India's eventual adequacy decision (analysts expect a formal EU assessment to begin in the 2026–2027 window) will reshape your transfer obligations. Our resources hub tracks the moving deadlines.
#The bigger picture
India has built something the world genuinely wants: cheap, open, population-scale digital rails that leapfrog legacy systems. Twenty-five countries piloting them is a diplomatic achievement, and the pivot toward AI, health, and pensions shows the model has room to run. None of that is in doubt.
What is in doubt is sequencing. A data-protection law is only as strong as the day its enforcement provisions go live — and India's most consequential ones are still 10 months out while the collecting architecture races ahead, at home and abroad. The countries adopting India Stack are, in effect, betting on a governance model whose own author hasn't finished installing it. The EU's adequacy hesitation is a preview of the question they will eventually face too.
The fix isn't to slow the export. It's to close the gap: appoint and empower a visibly independent Board, notify the cross-border rules with clarity rather than ambiguity, and make "privacy by design" a documented, audited default before the stack is copied one more time. Until then, India is exporting the future of digital governance faster than it is governing the present.
If your organization is preparing for the DPDP Act's 2026–2027 deadlines — consent managers, cross-border mapping, or breach readiness — start with our resources and consent-manager guides, and don't wait for May 2027 to find out what you should have built in 2026.
Sources: Open Source For You, Biometric Update, India Briefing, Storyboard18, MediaNama, Observer Research Foundation, News9.