Readiness assessment
Fintech & Banking · Payments · UPI

The DPDP Act for UPI Apps

For UPI apps and PSPs, the Act reshapes consent design and data collection, on top of NPCI's UPI guidelines.

In short

UPI apps are Data Fiduciaries operating alongside NPCI's UPI procedural guidelines. The hard problem is consent at UPI speed: it must be clear and purpose-specific without creating fatigue, while you collect only the data a payment needs. Penalties reach ₹250 crore.

Core impacts for UPI

What changes specifically for UPI apps.

NPCI overlap

The DPDP Act and NPCI's UPI guidelines apply together; you meet both.

Consent at UPI speed

Design consent at onboarding and mandate level, not per transaction, to avoid fatigue.

Minimal collection

A VPA and the payment details are enough; do not pull the contact book or device logs.

Rights and breaches

Support access, correction and erasure, and report breaches to users and the Board.

Common questions about DPDP for UPI

Short, cite-able answers, mirrored in FAQPage schema for answer engines.

Does the DPDP Act apply to UPI apps?
Yes. A UPI app is a Data Fiduciary for its users' personal data and must meet the DPDP Act alongside NPCI's UPI guidelines.
How should UPI apps handle consent?
Design consent at onboarding and at the mandate level with clear, purpose-specific notices, rather than asking per transaction, which causes consent fatigue.
What data can a UPI app collect?
Only what a payment needs, such as the VPA and transaction details. Scraping contacts, media files or call logs breaches the Act.
What are the penalties for a UPI app?
Up to 250 crore rupees for failing to take reasonable security safeguards, with the amount set by the Data Protection Board based on the breach.

Check your UPI flow.

A short readiness check flags consent-design, minimization and breach gaps specific to UPI.

Take the readiness check