HomeCirculars › RBI/2020-21/117

RBI Extends Compliance Deadline for Non-Bank PAs on Card Data Storage to Dec 2021

No longer current — replaced by RBI Brings Cross-Border Payment Aggregators Under Direct Regulation
RBI's own words: “A reference is invited to the Reserve Bank of India (RBI) circulars on – ‘Guidelines on Regulation of Payment Aggregators and Payment Gateways’ – (b) CO.DPSS. POLC.No.S33/02-14-008/2020-2021 dated March 31, 2021” — RBI/2023-24/80
Source: Reserve Bank of India · RBI/2020-21/117 · issued 31 Mar 2021 · ~2 min read
Quick answerRBI has extended the deadline for non-bank Payment Aggregators to implement tokenisation and stop storing customer card credentials by six months, to December 31, 2021. This one-time relief aims to give industry time to deploy workable solutions like tokenisation.
The rule, in the simplest words
How it plays out — a real example

A branch operations officer in Indore, Mr. Kumar, is working with a Payment Aggregator to ensure they meet the RBI's deadline. He coordinates with the technology team to finalise and test tokenisation solutions, ensuring that customer card credentials are not stored beyond December 31, 2021. This helps the Payment Aggregator to comply with the RBI's regulations and maintain a secure payment system.

What changed

The RBI circular dated March 17, 2020, mandated that neither Payment Aggregators nor their merchants can store customer card credentials. Based on industry requests, RBI has now extended the compliance timeline for non-bank PAs by six months, to December 31, 2021, as a one-time measure. All other provisions of the earlier circular remain unchanged.

What it means for you

Non-bank Payment Aggregators get additional time to implement tokenisation and other secure solutions, reducing immediate compliance pressure. Banks and other payment system participants must continue to ensure that no card credentials are stored beyond the new deadline. This extension provides a window for smoother transition but does not dilute the ultimate requirement to stop storing sensitive card data.

Historical instruction — do not use for current compliance. This is what was required at the time; it no longer reflects current RBI requirements. If no replacement rule is linked above, that only means none is recorded on our register yet — it does not prove no later applicable rule exists. Confirm on the official RBI source below.

What banks were required to do at the time

Who it affects

Non-bank Payment Aggregators, Payment Gateways, E-commerce marketplaces involved in payment aggregation, Merchants onboarded by Payment Aggregators

❓ Common questions

Regulatory timeline

Built from our lineage records — each fact carries its provenance; missing history simply is not shown (never guessed).

Does this extension apply to bank Payment Aggregators as well?

No, the extension is specifically for non-bank Payment Aggregators. Bank PAs were already required to comply by September 30, 2020, as per earlier circulars.

What happens if a non-bank PA fails to comply by December 31, 2021?

The circular does not specify penalties, but non-compliance would mean violating RBI's directive under the Payment and Settlement Systems Act, 2007, which could lead to regulatory action including possible suspension or revocation of authorisation.

Are e-commerce marketplaces that use a separate PA affected by this rule?

Yes, but only if they are directly undertaking payment aggregation. If they use a separate PA, they are treated as merchants and must ensure their PA complies with the storage ban.

📜 This document’s life story (3 recorded events, each backed by RBI’s own words)
Extended by RBI Extends Timeline for Storing Card-on-File Data to June 2022
RBI’s words: “the timeline for storing of CoF data is extended by six months, i.e., till June 30, 2022”
Extended by RBI Expands Card Tokenisation to Card-on-File (CoFT) Services
RBI’s words: “and CO.DPSS.POLC.No.S33/02-14-008/2020-2021 dated March 31, 2021 on “Guidelines on Regulation of Payment Aggregators and Payment Gateways””
Superseded by RBI Brings Cross-Border Payment Aggregators Under Direct Regulation
RBI’s words: “A reference is invited to the Reserve Bank of India (RBI) circulars on – ‘Guidelines on Regulation of Payment Aggregators and Payment Gateways’ – (b) CO.DPSS. POLC.No.S33/02-14-008/2020-2021 dated Mar”
📜 Read the original circular — full text as issued by RBI
RBI/2020-21/117 CO.DPSS.POLC.No.S33/02-14-008/2020-2021 March 31, 2021 All Payment System Providers and Payment System Participants Madam / Dear Sir, Guidelines on Regulation of Payment Aggregators and Payment Gateways We invite a reference to our circular DPSS.CO.PD.No.1810/02.14.008/2019-20 dated March 17, 2020 (as updated from time to time) and the clarification dated September 17, 2020 issued on the subject ( Annex ). Accordingly, neither the authorised Payment Aggregators (PAs) nor the merchants on-boarded by them can store customer card credentials within their database or server. 2. Based on the representations received from the industry seeking additional time for implementing the above instructions, it has been decided, as a one-time measure, to extend the timeline for non-bank PAs by six months, i.e., till December 31, 2021, to enable the payment system providers and participants to put in place workable solutions, such as tokenisation, within the framework set out in the circular dated March 17, 2020 cited above and our circular DPSS.CO.PD No.1463/02.14.003/2018-19 dated January 08, 2019 on “Tokenisation – Card transactions”. All other provisions of the circular dated March 17, 2020 referred to above, shall remain unchanged. 3. This directive is issued under Section 10 (2) read with Section 18 of Payment and Settlement Systems Act, 2007 (Act 51 of 2007). Yours faithfully, (P. Vasudevan) Chief General Manager Encl.: As above Annex RBI circular CO.DPSS.POLC.No.S33/02-14-008/2020-2021 dated March 31, 2021 Clarification issued by RBI on circular DPSS.CO.PD.No.1810/02.14.008/2019-20 dated March 17, 2020 (as updated from time to time) on “Guidelines on Regulation of Payment Aggregators (PAs) and Payment Gateways (PGs)” 1. Definition and applicability related 1.1. The circular is applicable to online PAs and PGs. The guidelines seek to regulate the activities of online PAs while providing baseline technology-related recommendations to PGs. 1.2. In the case of bank PAs, there is no requirement of authorisation; they shall ensure compliance with the guidelines by September 30, 2020 (as extended vide circular DPSS.CO.PD.No.1897/02.14.003/2019-20 dated June 04, 2020 ). For non-bank PAs, the instructions will come into force from the date of their authorisation, subject to the submission of application for authorisation before the end date of June 30, 2021. 1.3. The circular is also applicable to e-commerce marketplaces that are undertaking direct payment aggregation; e-commerce marketplaces availing the services of a PA shall be considered as merchants. 1.4. The circular is not applicable on ‘Delivery vs. Payment’ transactions but addresses the transactions where the payment is made in advance while the goods are delivered in a deferred manner. 2. Authorisation, capital and net-worth related 2.1. Banks maintaining the escrow account/s need not monitor the net-worth of the PA. 2.2. For existing non-bank PAs, the CA certificate of net-worth evidencing that the requirement of net-worth is ensured (as on March 31, 2021) will be required to be submitted to RBI at the time of application for authorisation (in case of an existing entity desirous of applying before March 31, 2021 a similar certificate shall be submitted as on the nearest half-year ending date). Newly incorporated non-bank entities which may not have an audited statement of financial accounts shall submit a certificate from their CA regarding the current net-worth along with provisional balance sheet. 3. Governance related 3.1. The Promoters / Promoter Groups, shall conform to the Reserve Bank’s ‘fit and proper’ criteria. Director of the PA company shall be deemed to be a “fit and proper” person if: 3.1.1. Such person has a record of fairness and integrity, including but not limited to: financial integrity; good reputation and character; and honesty; 3.1.2. Such person has not incurred any of the following disqualifications: Convicted by a court for any offence involving moral turpitude or any economic offence or any offence under the laws administered by the RBI; Declared insolvent and not discharged; An order, restraining, prohibiting or debarring the person from accessing / dealing in any financial system, passed by any regulatory authority, and the period specified in the order has not elapsed; Found to be of unsound mind by a court of competent jurisdiction and the finding is in force; and Is financially not sound. 3.1.3. If any question arises as to whether a person is a fit and proper person, the RBI’s decision on such question shall be final. 3.2. Para 5.4 related to disclosure of comprehensive information regarding merchant policies, customer grievances, privacy policy and other terms and conditions on the website and / or their mobile application, refers to policies of the PA and not of individual merchants on-boarded by it. 4. KYC and merchant on-boarding related 4.1. In case a PA is maintaining an account-based relationship with the merchant, the KYC guidelines of Department of Regulation (DoR), RBI is applicable. Thus, to this extent, para 6 on ‘Safeguards against Money Laundering (KYC / AML / CFT) Provisions’ shall also be applicable. 4.2. For merchant on-boarding, the PA can have a Board approved policy (Para 7.1). There would not be a requirement to carry-out entire process of KYC (in accordance with the KYC guidelines of DoR), in cases where the merchant already has a bank account which is being used for transaction settlement purpose. 5. OPGSP related 5.1. Entities functioning as OPGSP and undertaking cross-border transactions in terms of OPGSP guidelines shall ensure compliance with the instructions issued vide A.P. (DIR Series) Circular No.16 dated September 24, 2015 . 5.2. If OPGSP is also an entity which is functioning as PG or PA under the guidelines stipulated by DPSS, for undertaking any domestic leg of import / export transaction, it has to be ensured that the timelines and other guidelines, including those relating to authorised modes of collection, i.e. debit card, credit card and internet banking, indicated for the purpose of cross-border transactions in A.P. (DIR Series) Circular No.16 dated September 24, 2015 , are also adhered to. 6. Security, fraud prevention and risk management framework related 6.1. The PA needs to ensure compliance of the infrastructure of the merchants to security standards like PCI-DSS and PA-DSS, as applicable. 6.2. Merchants are not allowed to store payment data irrespective of their being PCI-DSS compliant or otherwise. They shall, however, be allowed to store limited data for the purpose of transaction tracking; for which, the required limited information may be stored in compliance with the applicable standards. 6.3. The PA cannot also store customer card credentials within its database or the server (irrespective of it being accessed by merchant or not) except for the limited purpose of transaction tracking; for which, required credentials may be stored in compliance with the applicable standards. 6.4. Para 10.5: A standard system audit, including cyber security audit, conducted by CERT-In empanelled auditors may be carried out. 7. Settlement and escrow account related 7.1. For the purpose of maintenance of the escrow account, the operations of PAs are deemed to be ‘designated payment systems’ under the Payment and Settlement Systems Act (PSS Act) after the entity obtains authorisation from RBI. 7.2. The applicability of circular DPSS.CO.PD.No.1102/02.14.08/2009-10 dated November 24, 2009 on “Directions for opening and operation of Accounts and settlement of payments for electronic payment transactions involving intermediaries” shall be as follows: 7.2.1. The circular shall be considered repealed for authorised PAs from the date of authorisation; 7.2.2. The circular shall be considered repealed with effect from June 30, 2021 except for such PAs who have applied for authorisation and a decision on it is pending with RBI. 7.3. The existing entities can continue to maintain nodal accounts till they have been authorised by RBI. Since the PA needs to move towards an escrow account, the bank and the PA may take a call about maintaining the same from an earlier date as well. However, this alone shall not make them eligible for a “designated payment system” status under Section 23A of the PSS Act. 7.4. If the bank can satisfactorily establish that the nodal account of an entity has been migrated to escrow account in compliance with the new instructions, it can allow the balances under existing nodal accounts of PAs to be considered for calculation of ‘Core portion’. 7.5. Those entities who have not attained the requisite net-worth as of March 31, 2021 shall wind up their PA business. Banks shall be required to close such nodal accounts after June 30, 2021 unless the PA produces evidence to the bank regarding application for authorisation being made to RBI. 7.6. The pre-funding has been allowed to tide over temporary mis-matches. Taking back of surplus pre-funding is not allowed. 7.7. There can be different “t” for different merchants as per the agreement between PA and merchants. 7.8. Para 8.6: The amount due to the merchant will be reckoned only after the settlement and credit to the escrow account. There is no need to prefund the account for this purpose. However, the proceeds shall be credited to escrow on the settlement day itself. 7.9. Where PAs have no control over incoming funds and its delay thereof, the PAs need to follow the instructions and transfer the funds to the merchant within T+0 / T+1 basis, post receiving of funds into its account. 7.10. The settlement accounts opened under Bharat Bill Payment System (BBPS) would be governed by BBPS instructions.
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2020-21/117 · issued 31 Mar 2021. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Topics: Digital Payments / UPI
Key dataSee the live numbers behind this topic: RBI Penalty Tracker, Credit & Deposit Growth — updated from official RBI data.
Key termsPlain-English definitions of terms in this circular — see the full Indian banking glossary. UPI · KYC / AML · Deposit insurance (DICGC) · NEFT / RTGS

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12050&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗