For UPI apps and PSPs, the Act reshapes consent design and data collection, on top of NPCI's UPI guidelines.
In short
UPI apps are Data Fiduciaries operating alongside NPCI's UPI procedural guidelines. The hard problem is consent at UPI speed: it must be clear and purpose-specific without creating fatigue, while you collect only the data a payment needs. Penalties reach ₹250 crore.
What changes specifically for UPI apps.
The DPDP Act and NPCI's UPI guidelines apply together; you meet both.
Design consent at onboarding and mandate level, not per transaction, to avoid fatigue.
A VPA and the payment details are enough; do not pull the contact book or device logs.
Support access, correction and erasure, and report breaches to users and the Board.
Short, cite-able answers, mirrored in FAQPage schema for answer engines.
Fix consent design and data collection first, then work toward certification.
A short readiness check flags consent-design, minimization and breach gaps specific to UPI.
Take the readiness check →