Most writing on DPI risk focuses on the big, dramatic ones: surveillance states, mass exclusion, data breaches. They're real.

But the risk I've actually watched play out is quieter. A secure product slowly turning into an insecure deployment.

The short answer: the main risks of digital public infrastructure are exclusion (people who can't enrol or access services), privacy and surveillance (misuse of sensitive personal data), security (breaches and attacks), and inadequate recourse (no way to fix errors or challenge decisions). The UN's Universal DPI Safeguards Framework sets out 13 key risks across the DPI lifecycle, with more than 300 recommendations. In practice, one of the most common risks is implementation drift: deployments quietly diverging from the recommended security setup.

Key facts:

  • The Universal DPI Safeguards Framework was released in September 2024 by the UN Tech Envoy's office and UNDP (UNDP)
  • It identifies 13 key risks across the DPI lifecycle and over 300 recommendations (UNU)
  • Its launch coincided with the Global Digital Compact, in which 193 member states recognised DPI's potential (UNDP)
  • A DPI Safeguards Accelerator now supports safeguards work in specific projects (Biometric Update)

The big risks

Risk What it looks like Typical safeguard
Exclusion People without documents, connectivity or literacy can't enrol or access services Assisted and offline channels, non-digital fallbacks
Privacy and surveillance Personal data used beyond its purpose, or combined to track people Consent, purpose limits, data minimisation, oversight
Security Breaches, ransomware, insider misuse Security by design, independent testing, monitoring
Inadequate recourse Errors that nobody can correct, decisions nobody can challenge Correction processes, grievance channels, audit trails
Lock-in One vendor controls the system and its costs Open standards, data portability, open source

The UN framework covers the first four in far more depth than I can here. If you're designing a national system, read it.

The risk nobody writes about: implementation drift

DPGs come with recommended configurations for hosting, networking and security. But governments have the final say. Systems often run on government hardware, behind government VPNs and security tools, with local decisions made along the way.

Each decision is small and usually reasonable. Over a few years, they add up. The live deployment drifts away from best practice until a well-designed, well-tested product is running in a poorly configured, insecure way.

I've seen it happen. It rarely makes the news because nothing dramatic triggers it.

My take: drift is the most underrated risk in DPI, because the frameworks focus on design and the damage happens during operations.

How to guard against drift

  1. Keep a written baseline of the recommended configuration from day one
  2. Pen-test your own deployment, not just the product
  3. Review the live system against the baseline every year
  4. Make upgrades part of the support contract, so you don't fall versions behind
  5. Give one named person ownership of security posture

More on support contracts in what happens after go-live.

assorted electric cables
02 / IN CONTEXTPhoto: John Barkiple / Unsplash

Does the UN framework get used in practice?

Honestly, I can't tell you how widely it's applied day to day in national projects. It's a relatively recent framework, and the new accelerator programme suggests the UN is now pushing it from guidance into practice.

What I'd say is this: the framework is excellent for design and governance. Pair it with operational discipline, because that's where drift gets you.

Is open source riskier?

No. Open code can be inspected by anyone, including your own security team, and good DPGs test independently. OpenCRVS, for instance, has every release penetration tested by an independent firm.

The risk profile depends far more on how a system is deployed and run than on whether its code is public. See open source vs proprietary.

Frequently asked questions

What are the risks of DPI? Exclusion, privacy and surveillance, security breaches, inadequate recourse and vendor lock-in, plus implementation drift after launch.

What is the Universal DPI Safeguards Framework? A UN framework, released in 2024, setting out 13 key DPI risks and over 300 recommendations for safe and inclusive DPI.

Can DPI be used for surveillance? It can if safeguards are weak. Consent, purpose limits, data minimisation and independent oversight reduce that risk.

Sources

Reviewing the risk posture of a DPI deployment? Let's talk.

Choose from all 20 guides