Readiness assessment
Fintech & Banking · Payments

The DPDP Act for Payment Platforms

UPI apps, wallets, PPI issuers and gateways process financial data at scale. Here is what the Act requires, and where it meets RBI and NPCI.

In short

Payment platforms are Data Fiduciaries under the DPDP Act. They must obtain explicit, purpose-specific consent, collect only the data a transaction needs, secure financial records, and report breaches to users and the Board, with penalties up to ₹250 crore for non-compliance.

Core impacts across payments

The duties that apply whatever payment model you run.

Dual compliance

The Act works alongside RBI and NPCI rules, not instead of them. RBI data-localization mandates still apply.

Consent without the friction

Every purpose needs clear, notice-based consent, designed to avoid fatigue on fast flows.

Data minimization

Collect only the details a payment needs. Scraping contact lists or call logs violates the Act.

User rights and breaches

Let users access, correct and erase their data, and report breaches to users and the Board.

By payment type

The Act is the same, but each payment model carries its own overlapping regulation. Jump to yours.

UPI apps

In short

UPI apps sit under both the DPDP Act and NPCI's UPI procedural guidelines. The sharp edge is consent: asking per transaction creates fatigue on fast UPI flows, so consent has to be designed at onboarding and mandate level, not per tap.

  • NPCI's UPI guidelines and the DPDP Act apply together. You are meeting both at once.
  • Design consent for high-frequency flows. Handle it at onboarding and mandate level to avoid fatigue.
  • Collect the minimum. A VPA and the payment details, not the contact book or device logs.
High demand, distinct angle. Strong search volume plus the NPCI overlap make UPI a good candidate to graduate into its own page. See the standalone template →

Wallets & PPIs

In short

Wallets and prepaid instruments are governed by the RBI PPI Master Directions on top of the DPDP Act. Your KYC tier, min-KYC versus full-KYC, decides how much identity data you hold, and that data needs purpose limits and retention discipline.

  • RBI PPI Master Directions layer onto the Act. Two frameworks, one wallet.
  • KYC tier drives minimization. Hold only the identity data your tier actually requires.
  • Reconcile RBI KYC retention with erasure. Keep records for the mandated period, then delete.

Gateways & aggregators

In short

Payment gateways and aggregators operate under RBI's PA/PG guidelines. You usually act as a processor for the merchants you serve, so processor contracts, card tokenization and breach flow-down are the core duties.

  • RBI PA/PG guidelines set the baseline. The Act adds the data-protection layer on top.
  • You are often a processor for merchants. Act on instructions under a valid contract.
  • Tokenize and flow down breach duties. Card tokenization and clear breach terms cut exposure.

Go deeper

Niche guides for this area, each naming the specific regulation.

Check your payments stack.

A short readiness check flags consent, minimization and breach gaps specific to payments.

Take the readiness check