Prepaid wallets and PPI issuers hold KYC-tiered identity and transaction data under the RBI PPI Master Directions, with the DPDP Act layered on top.
In short
Wallets and prepaid instruments are Data Fiduciaries governed by the RBI Master Directions on Prepaid Payment Instruments alongside the DPDP Act. Your KYC tier decides how much identity data you hold; all of it needs purpose-specific consent, minimization and retention discipline. Penalties reach ₹250 crore.
What changes for this niche, and the specific rule it turns on.
The RBI PPI Master Directions and the DPDP Act apply together; the RBI storage and KYC rules do not go away.
Min-KYC and full-KYC wallets collect different identity data; hold only what your tier requires.
RBI mandates KYC-record retention; reconcile it with the DPDP right to erase and document the legal hold.
RBI payment-data storage rules apply regardless of the DPDP cross-border default; store where RBI requires.
Short, cite-able answers, mirrored in FAQPage schema.
Fix KYC-tier minimization and retention first.
The readiness check flags KYC-tier, retention and localisation gaps.
Take the readiness check →