Readiness assessment
Fintech & Banking · Payments · Wallets & PPIs

The DPDP Act for Wallets & PPIs

Prepaid wallets and PPI issuers hold KYC-tiered identity and transaction data under the RBI PPI Master Directions, with the DPDP Act layered on top.

In short

Wallets and prepaid instruments are Data Fiduciaries governed by the RBI Master Directions on Prepaid Payment Instruments alongside the DPDP Act. Your KYC tier decides how much identity data you hold; all of it needs purpose-specific consent, minimization and retention discipline. Penalties reach ₹250 crore.

Core impacts

What changes for this niche, and the specific rule it turns on.

Dual regime

The RBI PPI Master Directions and the DPDP Act apply together; the RBI storage and KYC rules do not go away.

KYC tier drives minimization

Min-KYC and full-KYC wallets collect different identity data; hold only what your tier requires.

Retention vs erasure

RBI mandates KYC-record retention; reconcile it with the DPDP right to erase and document the legal hold.

Localisation still bites

RBI payment-data storage rules apply regardless of the DPDP cross-border default; store where RBI requires.

Common questions

Short, cite-able answers, mirrored in FAQPage schema.

Does the DPDP Act apply to wallets and PPIs?
Yes. A wallet or PPI issuer is a Data Fiduciary under the DPDP Act, in addition to the RBI PPI Master Directions.
Can a wallet delete KYC data on an erasure request?
Only after the RBI-mandated retention period. Legal-retention obligations override the erasure right, but you must document the basis and delete once it lapses.
Where must PPI data be stored?
Follow the RBI payment-data storage rules, which can require India-only storage; the DPDP permissive cross-border default does not relax them.

Check your wallet data.

The readiness check flags KYC-tier, retention and localisation gaps.

Take the readiness check