Definitional ambiguity Critics have noted that the term "digital public infrastructure" conflates two distinct meanings of "public": population-scale deployment versus public accountability and governance. A system may serve an entire population while remaining structurally unaccountable to those it affects. The G20 definition uses aspirational language ("should be," "can be") rather than verifiable structural conditions, leading scholars to argue that current definitions exclude nothing and therefore define nothing.
Privacy and surveillance Digital public infrastructure systems have raised significant
privacy concerns. Large-scale identity systems collect
biometric data and transaction records that enable comprehensive surveillance of populations. Critics drawing on
Shoshana Zuboff's analysis of
surveillance capitalism argue that DPI systems, even when government-operated, can enable the commodification of personal data and behavioral prediction at population scale. The mandatory nature of some DPI systems, where refusal results in exclusion from essential services, raises questions about whether consent can be freely given when the alternative is denial of food rations, banking, or healthcare.
Exclusion and the digital divide DPI implementations have documented patterns of excluding vulnerable populations. In India, biometric authentication failures in the
Aadhaar system have led to denial of food rations and welfare benefits, with reports linking such failures to deaths from starvation. The
digital divide means that populations without reliable internet access, digital literacy, or stable biometrics (manual laborers, elderly people) face systematic exclusion from systems designed to serve them. The assumption that digital systems improve efficiency can mask the creation of new barriers. Binary authentication (success or failure) replaces human discretion that previously allowed for edge cases and exceptions.
Commons governance Scholars applying
Elinor Ostrom's framework for
common-pool resource governance have argued that most DPI systems fail the conditions required for legitimate commons management. Ostrom's design principles require that those affected by rules participate in making them, that monitoring be accountable to users, and that dispute resolution be accessible and low-cost. Critics observe that DPI systems typically invert these conditions: citizens are fully visible to the system while the system remains opaque to citizens; rules are set through executive or technocratic processes without meaningful public participation; and redress requires litigation rather than accessible local resolution.
Structural accountability Some researchers distinguish between systems that are merely population-scale and those that are structurally accountable to affected populations. This perspective argues that genuine public infrastructure requires: the ability to refuse participation without penalty; transparent and inspectable execution; independent verification of system behavior; binding governance input from those affected; and the feasibility of alternative implementations. By these criteria, systems such as the
Linux kernel,
Let's Encrypt, and
Wikipedia meet structural requirements for public infrastructure, while some systems promoted as DPI do not. == References ==