RBI Extends Timeline for Storing Card-on-File Data to June 2022
Current · Source: Reserve Bank of India · RBI/2021-2022/142 · issued 23 Dec 2021 · ~2 min read
Quick answerRBI has extended the timeline for storing actual card data (CoF) by non-bank payment aggregators and merchants to June 30, 2022. After this date, all such stored data must be purged. Industry can use tokenisation or alternate mechanisms for use cases like recurring payments and chargebacks.
The rule, in the simplest words
Non-bank payment aggregators (companies that help merchants accept card payments) and merchants must delete all stored card data by June 30, 2022.
After June 30, 2022, no one except the card issuer (the bank that gave the card) and card networks (like Visa or Mastercard) can keep actual card numbers.
For things like recurring payments (automatic monthly bills) or chargebacks (disputing a payment), companies can use tokenisation (replacing card numbers with a safe code) or other new methods allowed by RBI.
The deadline was moved from December 31, 2021 to June 30, 2022, giving extra six months to clean up stored card data.
How it plays out — a real example
A branch operations officer in Indore, Priya, checks her bank's system and finds that her payment aggregator partner still stores customer card numbers for EMI payments. She immediately schedules a purge of all that data before June 30, 2022, and starts testing tokenisation so her customers can still pay their EMIs safely without the bank keeping their card details.
What changed
The earlier timeline for storing CoF data was extended by six months from December 31, 2021 to June 30, 2022. Post this date, such data shall be purged. Additionally, RBI now allows industry stakeholders to devise alternate mechanisms beyond tokenisation for handling use cases that require CoF data, such as recurring e-mandates, EMI options, and dispute resolution.
What it means for you
Banks and payment aggregators get a six-month breather to comply with the CoF storage ban, but must ensure all stored card data is purged by June 30, 2022. The flexibility to create alternate mechanisms means lenders can explore solutions beyond tokenisation for recurring payments and chargebacks, reducing operational disruption. Non-compliance post-deadline could attract regulatory action under the Payment and Settlement Systems Act.
What you must do
Audit all systems to identify where actual card data (CoF) is stored by your entity or merchants you onboard.
Plan and execute purging of all stored card data by June 30, 2022, ensuring no residual copies remain.
Evaluate and implement tokenisation or approved alternate mechanisms for recurring payments, EMI, chargebacks, and loyalty programs.
Communicate the revised timeline and compliance requirements to all merchants and third-party vendors handling card data.
Who it affects
Non-bank payment aggregators, Merchants on-boarded by payment aggregators, Payment system providers and participants (excluding card issuers and card networks)
❓ Common questions
What is the new deadline for purging stored card data?
The deadline has been extended from December 31, 2021 to June 30, 2022. After this date, all actual card data stored by non-bank payment aggregators and merchants must be purged.
Can we use alternatives to tokenisation for recurring payments?
Yes, RBI permits industry stakeholders to devise alternate mechanisms for use cases like recurring e-mandates, EMI options, chargeback handling, and loyalty programs, in addition to tokenisation.
Does this circular apply to card issuers and card networks?
No, the restriction on storing CoF data applies to entities other than card issuers and card networks. Issuers and networks are exempt from this purging requirement.
📜 Read the original circular — full text as issued by RBI
RBI/2021-2022/142
CO.DPSS.POLC.No.S-1211/02-14-003/2021-22
December 23, 2021
All Payment System Providers and Payment System Participants
Madam / Dear Sir,
Restriction on storage of actual card data [i.e. Card-on-File (CoF)]
In terms of our circular DPSS.CO.PD.No.1810/02.14.008/2019-20 dated March 17, 2020 on “Guidelines on Regulation of Payment Aggregators and Payment Gateways”, the authorised non-bank payment aggregators and merchants on-boarded by them were prohibited from storing card data (CoF) from June 30, 2021. At the request of industry stakeholders, this timeline was extended to December 31, 2021 vide circular CO.DPSS.POLC.No.S33/02-14-008/2020-2021 dated March 31, 2021 . Further, regulations on CoF Tokenisation (CoFT) were issued vide circular CO.DPSS.POLC.No.S-516/02-14-003/2021-22 dated September 07, 2021 on “Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services”.
2. In light of various representations received in this regard, we advise as under:
the timeline for storing of CoF data is extended by six months, i.e., till June 30, 2022; post this, such data shall be purged; and
in addition to tokenisation, industry stakeholders may devise alternate mechanism(s) to handle any use case (including recurring e-mandates, EMI option, etc.) or post-transaction activity (including chargeback handling, dispute resolution, reward / loyalty programme, etc.) that currently involves / requires storage of CoF data by entities other than card issuers and card networks.
3. This directive is issued under Section 10 (2) read with Section 18 of Payment and Settlement Systems Act, 2007 (Act 51 of 2007).
Yours faithfully,
(Sudhanshu Prasad)
General Manager (Officer in Charge)
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2021-2022/142 · issued 23 Dec 2021. The plain-English explanation above is BankPulse’s own independent summary.
Audit all systems to identify where actual card data (CoF) is stored by your entity or merchants you onboard.
📜 Compliance
Plan and execute purging of all stored card data by June 30, 2022, ensuring no residual copies remain.
Evaluate and implement tokenisation or approved alternate mechanisms for recurring payments, EMI, chargebacks, and loyalty programs.
Communicate the revised timeline and compliance requirements to all merchants and third-party vendors handling card data.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template
Example: if you are an IT/Systems lead at a bank this circular applies to (Non-bank payment aggregators, Merchants on-boarded by payment aggregators, Payment system providers and participants (excluding card issuers and card networks)), your first concrete step on “RBI Extends Timeline for Storing Card-on-File Data to June 2022” is: “Audit all systems to identify where actual card data (CoF) is stored by your entity or merchants you onboard.” (RBI issued this 23 Dec 2021).
Circular: RBI/2021-2022/142 -- RBI Extends Timeline for Storing Card-on-File Data to June 2022
Issued: 23 Dec 2021
Action required: Audit all systems to identify where actual card data (CoF) is stored by your entity or merchants you onboard.
Action required: Plan and execute purging of all stored card data by June 30, 2022, ensuring no residual copies remain.
Action required: Evaluate and implement tokenisation or approved alternate mechanisms for recurring payments, EMI, chargebacks, and loyalty programs.
Action required: Communicate the revised timeline and compliance requirements to all merchants and third-party vendors handling card data.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12211&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.