The phrase Digital Public Infrastructure, abbreviated DPI, sounds bureaucratic. The thing it describes is not. India built a set of open digital rails over the past fifteen years that have changed how a billion people prove who they are, send money, share documents, and buy things online. Those rails are open APIs, run as public goods, sitting underneath a marketplace of private and public applications. The collective name is the India Stack. The international name for the architectural pattern is Digital Public Infrastructure. The same idea is now being copied in dozens of countries, and the World Bank, the United Nations, and the G20 have each elevated DPI to a development priority.
For UPSC GS-III, the topic sits at the intersection of science and technology, the digital economy, financial inclusion, and governance reform. The reason DPI matters is that it is one of the few large-scale technology systems that India built earlier and at greater depth than any peer economy. The architecture is now an export. This article walks through what DPI is, what each layer of the India Stack does, who runs it, where the policy lever sits, and why the global community is paying attention.
What Counts as Digital Public Infrastructure

Digital Public Infrastructure is interoperable, open, population-scale digital systems built and maintained as public goods. The three defining qualities are scale, openness, and public-good orientation. Scale means the system serves hundreds of millions or billions of users without breaking. Openness means anybody, public or private, can build on top of the rails by following a published technical specification. Public-good orientation means the rails are not owned by a private platform that extracts rent. They are owned and governed in a way that keeps the rails accessible.
The contrast is with private platform infrastructure, where a small number of corporations operate closed systems that competitors cannot interoperate with. Card payment networks, social media identity, and proprietary cloud-document silos are the closed-platform analogues. DPI flips that pattern. The identity rail is not a Facebook login. The payments rail is not a Visa network. The document wallet is not a Google Drive. Each is a public protocol that any application can plug into.
The India Stack as a Layered Architecture
The India Stack is the working name for India’s stack of DPI platforms. It is conventionally described as four layers stacked vertically. The identity layer at the bottom proves who a person is. The payments layer in the middle moves money between people and businesses. The data empowerment layer above that lets users share documents and financial data with consent. The commerce layer at the top lets buyers and sellers transact through open protocols rather than closed marketplaces. Each layer is a stack of APIs and reference implementations, and each can be used independently by an application that needs only that specific function.
The Identity Layer: Aadhaar and the UIDAI
The identity layer is anchored by Aadhaar, a 12-digit unique identification number issued by the Unique Identification Authority of India. Aadhaar is now held by more than 1.3 billion residents. Beyond the number, the system provides several authentication services that applications can call. Demographic authentication confirms a name and date of birth. Biometric authentication uses a fingerprint or iris scan. One-time password authentication uses the registered mobile number. The Aadhaar e-KYC service returns a digitally signed verification record that a financial institution or service provider can use to onboard a new customer in seconds.
Aadhaar e-Sign is the corresponding signing service. A document can be electronically signed using the Aadhaar OTP, producing a legally valid signature under the Information Technology Act. Together, e-KYC and e-Sign make presence-less authentication and presence-less contracting possible at population scale. The Aadhaar regulatory framework, the legal basis under the Aadhaar Act 2016, and the Supreme Court rulings on its use are central to the layer’s operation.
The Payments Layer: UPI and NPCI
The payments layer is operated by the National Payments Corporation of India, an umbrella organisation set up by the Reserve Bank of India and the Indian Banks Association. NPCI runs several rails, but the most important is the Unified Payments Interface, abbreviated UPI. UPI is an open API that lets any application initiate a real-time bank-to-bank transfer using a virtual payment address. UPI now processes more than 14 billion transactions a month and roughly half of the world’s real-time payment volume. The transaction is free for the user. The economics are subsidised through merchant discount rate exemptions for small merchants and through interchange caps.
The architectural elegance of UPI is that the user-facing application and the bank are decoupled. A user can hold a Punjab National Bank account and pay through Google Pay, PhonePe, Paytm, BHIM, or any new entrant that meets the NPCI specification. The merchant can accept payments without any specific software contract with each bank. The same rail handles person-to-person transfers, person-to-merchant transfers, and recurring mandate payments. The same rail now extends to international corridors with Singapore, the United Arab Emirates, France, and others through bilateral interoperability arrangements.
The Data Empowerment Layer: DigiLocker, Account Aggregators, DEPA

The data empowerment layer turns documents and financial records into shareable, consent-based digital records. DigiLocker is a cloud-based digital document wallet operated by the Ministry of Electronics and Information Technology. A user can store driving licences, vehicle registration certificates, school certificates, PAN cards, insurance policies, and a long list of issuer-pushed documents. The documents in DigiLocker are issued directly by the source authority, are digitally signed, and are legally equivalent to the original under the Information Technology Act. A verification request returns a tamper-evident document instantly, eliminating the photocopy-and-attest workflow that used to dominate Indian government interactions.
The Account Aggregator framework is the financial-data equivalent of DigiLocker. An Account Aggregator is a regulated non-banking financial company that holds no money but moves data with consent. A user logs in, sees a list of financial information providers including their banks, mutual fund houses, and tax records, gives explicit consent for a specific information user to receive a specific data set for a specific purpose, and the AA pulls and delivers the encrypted record. The framework is the operational expression of the Data Empowerment and Protection Architecture, abbreviated DEPA, which the Indian government articulated as a design philosophy for consent-based data sharing. The Digital Personal Data Protection Act 2023 sits on top of the framework as the legal substrate.
The Commerce Layer: Open Network for Digital Commerce
The Open Network for Digital Commerce, abbreviated ONDC, extends the DPI architectural pattern to the digital commerce space. The closed-platform pattern in commerce is the marketplace owned by a single corporation. The buyer is locked into the buyer app of that marketplace, the seller is locked into the seller app of the same marketplace, and the marketplace decides which seller is shown to which buyer and at what discount. The transaction logic is captured by the platform.
ONDC unbundles that. Buyers use a buyer app of their choice. Sellers list on a seller app of their choice. The two apps communicate through an open protocol, much as UPI lets a payer’s app talk to a payee’s bank. The discovery, ordering, fulfilment, and settlement steps are independent network operations rather than platform-internal flows. ONDC is still scaling, with grocery, food delivery, mobility, and several other verticals onboarded, and the policy bet is that an open commerce protocol can do for online retail what UPI did for digital payments.
Who Runs What: Institutions and Anchoring
Several institutions hold the DPI stack together. The Unique Identification Authority of India runs Aadhaar under the Aadhaar Act and is anchored to the Ministry of Electronics and Information Technology. The National Payments Corporation of India runs UPI and several other rails under the broader regulation of the Reserve Bank of India. The Account Aggregator regulatory framework sits with the RBI as well. DigiLocker is run by MeitY directly. ONDC is incorporated as a non-profit company with the Department for Promotion of Industry and Internal Trade as the policy anchor and a consortium of public-sector banks and other financial institutions as initial shareholders.
The overall policy anchor for digital public infrastructure is the Ministry of Electronics and Information Technology, with the IndiaAI Mission and the broader Digital India Mission providing programmatic budgets. The IndiaStack.global initiative packages the architectural pattern for export to other countries. The G20 New Delhi Leaders’ Declaration in 2023 codified DPI as a development priority, and the One Future Alliance was set up under India’s G20 presidency to advance DPI deployment in the Global South. For deeper context on the broader digital roadmap see NITI Aayog’s DPI 2047 plan and on the parallel research bet in compute see the national quantum mission.
What DPI Has Made Possible

The most cited consequence of DPI is financial inclusion. Pradhan Mantri Jan Dhan Yojana opened bank accounts for hundreds of millions of previously unbanked Indians. Aadhaar-linked direct benefit transfers route subsidies and welfare payments directly to those accounts, reducing leakage and ghost beneficiaries. The combination of identity, account, and mobile, sometimes called the JAM trinity for Jan Dhan, Aadhaar, and Mobile, has transformed welfare delivery for schemes from PM-KISAN to LPG subsidy.
Digital lending has scaled. Account Aggregator-pulled data lets a lender underwrite a small loan in minutes for a borrower who would previously have been considered uncreditworthy. Tax compliance has improved with pre-filled returns drawn from PAN-linked data. Government certification has shifted online. Vaccination certificates during the pandemic, scaled through the CoWIN platform, used the same DPI-pattern architecture. Court services, land records in many states, education certificates, and a long tail of government interactions are migrating to issuer-signed digital records held in DigiLocker.
The cybersecurity implications are significant and the stack has become a high-value target. For the broader threat landscape, see cyber security and the article on types of attacks on computer networks.
Privacy, Consent, and the Critique
The DPI architecture rests on the principle of privacy by design and explicit user consent. Critics have argued, in court and in the broader policy debate, that scale produces structural risks regardless of consent design. The Aadhaar litigation in the Supreme Court, culminating in the 2018 ruling, narrowed permissible uses of the identity number. The Digital Personal Data Protection Act 2023 codifies a baseline of consent, purpose limitation, and grievance redress. The implementation of the Act is still in progress, with the Data Protection Board and rules awaiting full operationalisation.
The case for the architecture is that the alternative is not no surveillance but private surveillance through closed platforms. The case against the architecture is that population-scale identity systems concentrate risk and that mistakes at scale are also at scale. Both points have merit and the policy debate is alive.
Global Adoption
The India Stack has become an export. UPI’s protocol has been licensed or partnered for adoption in Bhutan, Nepal, Singapore, the UAE, France, and others. The MOSIP project, the Modular Open Source Identity Platform, repackages the Aadhaar architectural pattern as an open-source identity stack and has been adopted by the Philippines, Morocco, Ethiopia, Sri Lanka, and several others. The Indian government has signed memoranda of understanding to share DPI know-how with more than a dozen countries.
The Bill and Melinda Gates Foundation, the World Bank, and several UN agencies have channelled funding into MOSIP and adjacent open-source DPI projects. The political message is that DPI is not a country-specific peculiarity but an architectural pattern that any government can adopt to leapfrog the closed-platform stage of digital development.
Prelims and Mains Pointers
For prelims, key facts include the four-layer model, the Unique Identification Authority of India as the issuer of Aadhaar, the National Payments Corporation of India as the operator of UPI, MeitY as the policy anchor for DigiLocker, the Account Aggregator framework as the financial-data layer under RBI regulation, and ONDC as the commerce-layer initiative. The Digital Personal Data Protection Act 2023 is the legal substrate.
For mains, the analytical questions are about the architectural difference between DPI and platform infrastructure, the consent and privacy framework, the financial inclusion and welfare delivery story, and the geopolitical export of the stack as part of India’s tech diplomacy. DPI is one of the few large technology stories where India is a leader rather than a follower, and a working command of its layers is essential for any GS-III answer on the digital economy.
Tell Google you want more of this.
Add Anantam IAS as a preferred sourceOne tap, and this site shows up more often in your own Top Stories, AI Overviews and AI Mode. Remove it any time.