Digital Public Infrastructure Has Transformed Indian Governance, but Who Is Watching It
Aadhaar, UPI and the India Stack solved real delivery problems while leaving oversight questions largely unanswered
Unified Payments Interface transactions now run into the tens of billions each month, a scale of real-time digital payment adoption that has drawn genuine interest from central banks and governments around the world. Aadhaar, the biometric identity system built over the preceding decade, underpins direct benefit transfers that have measurably reduced leakage in schemes ranging from cooking gas subsidies to pension payments. Taken together with the broader India Stack of interoperable digital public goods, this is a genuine Indian governance achievement, one that solved delivery problems that had defeated policymakers for decades using conventional administrative reform. It would be dishonest to write about India's digital public infrastructure without acknowledging that scale of accomplishment. It would be equally dishonest to stop there, because the institutions meant to hold this infrastructure accountable have consistently trailed behind its deployment.
The Delivery Case Is Real
Before Aadhaar-linked direct benefit transfers, subsidised cooking gas cylinders and kerosene were diverted at scale, sold on the open market by intermediaries who intercepted the subsidy before it reached genuine beneficiaries. Linking these transfers to verified bank accounts closed a significant channel of leakage, and independent evaluations, while disputing the precise magnitude, generally confirm the direction of the effect. Similarly, the rapid adoption of UPI has brought a meaningful share of previously cash-based small transactions into a traceable digital system, with benefits for tax compliance, credit history building for small merchants, and convenience that ordinary users have adopted voluntarily at a scale that no government mandate could have achieved on its own. These are not trivial accomplishments, and critics of digital governance sometimes understate how much genuine public value has been created.
The Exclusion Problem
The same infrastructure that closed one form of leakage opened new forms of exclusion. Biometric authentication failures, a worker whose fingerprints have worn down from manual labour, an elderly person whose iris scan fails to match, have in documented cases resulted in genuine beneficiaries being denied rations or wages, sometimes with serious consequences. The Jharkhand starvation deaths reported in 2017 and 2018, where Aadhaar authentication failures were linked to denial of rations, remain the starkest illustration, and while the government has since introduced exception-handling mechanisms, researchers who track implementation continue to document authentication failures at rates that matter enormously to the individuals affected even when they represent a small percentage of overall transactions. A system judged only by its aggregate leakage reduction will systematically underweight this kind of exclusion, because the people affected are, by definition, poorly positioned to make their case heard.
Where Is the Regulator
For a data infrastructure of this scale, the institutional architecture for oversight has been slow to arrive. The Personal Data Protection framework, first proposed in a Justice B.N. Srikrishna committee report in 2018, went through multiple redrafts before Parliament finally passed the Digital Personal Data Protection Act in 2023, five years after the Supreme Court's Puttaswamy judgment had already established privacy as a fundamental right. Even with the Act in place, the Data Protection Board it establishes has significant executive control over its composition, raising questions about how independently it can act against government agencies that are themselves among the largest processors of personal data through Aadhaar and other platforms. A regulator overseeing digital infrastructure but structurally dependent on the government that built much of that infrastructure faces an inherent tension that will need to be tested in practice.
Algorithmic Decisions Without Algorithmic Accountability
As states increasingly use automated systems, algorithmic detection of welfare fraud, automated flagging of tax anomalies, facial recognition in policing, to make or inform decisions affecting individuals, the legal and institutional framework for challenging those decisions has not kept pace. Several states have deployed facial recognition systems for policing purposes with limited public disclosure of accuracy rates, error margins, or the legal basis for retention of collected data, and civil liberties groups including the Internet Freedom Foundation have documented cases where such deployments proceeded without the kind of parliamentary or judicial scrutiny that a technology with this much potential for misidentification and misuse would warrant in most democracies with mature oversight traditions.
A Reasonable Defence of the Pace
Officials involved in building this infrastructure have a reasonable response: regulation that moves too early can freeze innovation before its benefits are understood, and India built much of its digital public infrastructure precisely because it did not wait for a complete regulatory framework before acting, unlike some other jurisdictions where extensive prior consultation delayed comparable payment and identity systems by years. There is something to this argument, and UPI's success owes something to the National Payments Corporation of India's ability to iterate quickly. But the argument for regulatory patience becomes weaker, not stronger, as the infrastructure scales and touches more vulnerable populations, because the cost of unaddressed failure modes grows with scale rather than shrinking.
Building the Second Half of the System
India's digital public infrastructure achievement is real and deserves recognition on its own terms, including from those who are otherwise skeptical of large state technology projects. But an infrastructure this consequential needs an oversight architecture of comparable seriousness: an independent data protection regulator genuinely insulated from the agencies it oversees, transparent audit mechanisms for algorithmic decision systems used in welfare and policing, and fast, accessible grievance redress for the individuals who fall through authentication gaps. Building the delivery half of this system took the Indian state the better part of two decades. Building the accountability half with comparable seriousness is the unfinished task that will determine whether this remains a governance success story or becomes, in the fine print, a cautionary one.


