UPI apps, wallets, PPI issuers and gateways process financial data at scale. Here is what the Act requires, and where it meets RBI and NPCI.
In short
Payment platforms are Data Fiduciaries under the DPDP Act. They must obtain explicit, purpose-specific consent, collect only the data a transaction needs, secure financial records, and report breaches to users and the Board, with penalties up to ₹250 crore for non-compliance.
The duties that apply whatever payment model you run.
The Act works alongside RBI and NPCI rules, not instead of them. RBI data-localization mandates still apply.
Every purpose needs clear, notice-based consent, designed to avoid fatigue on fast flows.
Collect only the details a payment needs. Scraping contact lists or call logs violates the Act.
Let users access, correct and erase their data, and report breaches to users and the Board.
The Act is the same, but each payment model carries its own overlapping regulation. Jump to yours.
In short
UPI apps sit under both the DPDP Act and NPCI's UPI procedural guidelines. The sharp edge is consent: asking per transaction creates fatigue on fast UPI flows, so consent has to be designed at onboarding and mandate level, not per tap.
In short
Wallets and prepaid instruments are governed by the RBI PPI Master Directions on top of the DPDP Act. Your KYC tier, min-KYC versus full-KYC, decides how much identity data you hold, and that data needs purpose limits and retention discipline.
In short
Payment gateways and aggregators operate under RBI's PA/PG guidelines. You usually act as a processor for the merchants you serve, so processor contracts, card tokenization and breach flow-down are the core duties.
Niche guides for this area, each naming the specific regulation.
From consent design to a certifiable posture, in five stages.
A short readiness check flags consent, minimization and breach gaps specific to payments.
Take the readiness check →