On 30 August 2026, NPCI International Payments Ltd (NIPL), the international arm of India's National Payments Corporation, signed a commercial agreement with Uzbekistan's National Interbank Processing Centre (NIPC), which operates the HUMO payment system. Indian travellers can scan UZQR, Uzbekistan's national interoperable QR code, from their UPI apps and pay merchants straight from Indian bank accounts, according to Free Press Journal's report of the Finance Ministry statement. The Reserve Bank of India and the Central Bank of Uzbekistan approved the arrangement, and the Uzbek central bank designated HUMO as NIPL's authorised merchant-acceptance partner. Some outlets call Uzbekistan the eleventh UPI destination. Other agency copy lists ten countries without it, so treat the count as unsettled.
The count matters less than the design. This is a test of whether digital public infrastructure (DPI) can be exported without being imposed.
The strongest case for caution
Critics of DPI exports have a fair point. A payments rail is also a data rail and a source of geopolitical leverage. The EFF's September 2026 essay on digital sovereignty warns that the term can be used to splinter networks and entrench new dependencies. It argues that sovereignty should mean people and communities can choose, control and use technology. A government that adopts a foreign payment standard might hand a foreign operator, and by extension a foreign state, power over its citizens' transactions. India's own regulators worry about the same thing in reverse. At India Mobile Congress 2026, Airtel's Abhishek Biswal said sovereignty goes beyond storage to the ability to access data and whether another government can cut it off.
Why the Uzbek model answers much of that worry
The Uzbek deal is not an adoption of UPI. Uzbekistan keeps UZQR and HUMO, its own national QR code and its own domestic payment system. India's contribution is a connector. A visitor's app reads a local code, and NIPL and its partner settle the transaction between the two systems. No Uzbek merchant has to install an Indian app or onboard to an Indian network. That is the same interoperability logic the RBI and the Monetary Authority of Singapore announced in 2021, when they said users of each system could make instant, low-cost transfers without being onboarded to the other's system.
This is what a pro-innovation approach to payments should look like. Each country retains control of its domestic rails. Travellers get lower friction, and the Finance Ministry statement says direct bank-account payments reduce reliance on cards, cash and foreign-exchange markups. Merchants gain customers without new hardware. Regulators on both sides approved it before launch, which is proportionate oversight: authorisation of the cross-border leg, with no attempt to control the whole domestic market.
It also contrasts with two other models. One is closed card networks that charge merchants for cross-border acceptance. The other is state-mandated platforms that require foreign participants to run on the host country's stack. A bilateral link of two open QR standards is a lighter-touch way to get interoperability.
The unresolved problem: India's data rules
The risk lies in what India asks of its own operators while promoting this model abroad. The RBI's 6 April 2018 directive on storage of payment system data requires that the entire data relating to payment systems be stored "only in India", while allowing the foreign leg of a transaction to be stored abroad if required. That carve-out is what makes outbound UPI workable. It is also a reminder that India's approach is location-based. As MediaNama reported from the IMC panel, CERT-In's 2022 directions require system logs to be kept within Indian jurisdiction for 180 days, and the Digital Personal Data Protection Act's Section 16, which lets the government restrict transfers to notified countries, takes effect only on 13 May 2027.
The consequence for exports is practical. A partner country that is asked to accept a rail built around localisation will ask whether its own data must also stay in India, or in a mirror of India's rules. If the answer is a negotiated, reciprocal carve-out for the cross-border leg, as with Uzbekistan, the model scales. If localisation becomes a condition of participation, the model starts to resemble the dependency the EFF warns about, and partners with alternatives will take them.
What to watch
- Rollout evidence. Early reports describe acceptance in the future tense. Merchant coverage, settlement times and the cost to travellers will show whether this works in practice.
- Disclosure. NIPL should publish the data-handling terms of its partner agreements. Indian and Uzbek users deserve to know what leaves each country.
- Reciprocity. The strongest test is Uzbek visitors paying in India through UZQR. A one-way export is a product launch. A two-way link is infrastructure.
- Consistency at home. India's DPDP transfer rules, still pending, should follow a risk-based, notified-country approach, not blanket localisation. Blanket localisation weakens the case for open, interoperable systems that India is making abroad.
Conclusion
The Uzbekistan link is a good example of DPI diplomacy because it adds a connector and does not replace a sovereign system. India can credibly promote that model only if its own rules treat cross-border data flows as something to manage by risk and reciprocity, rather than as a threat to be fenced off by location.