HomeCirculars › RBI/2022-2023/95

RBI Finalises Card-on-File Storage Ban: Oct 1 Deadline Stands

Current · Source: Reserve Bank of India · RBI/2022-2023/95 · issued 28 Jul 2022 · ~2 min read
Quick answerRBI confirms no extension to the October 1, 2022 ban on storing actual card data (CoF) by non-issuers/networks. Merchants and PAs get a T+4 day window for guest checkout settlement data only; acquirers can store for post-transaction activities until January 31, 2023.
The rule, in the simplest words
How it plays out — a real example

A branch operations officer in Indore, Priya, processes a customer's one-time card payment for a loan. She knows that after the payment settles, she must delete the card number within 4 days, not save it for future use. She sets a reminder to purge the data on day 3 to stay safe from RBI penalties.

What changed

RBI has firmly rejected any change to the October 1, 2022 deadline for purging Card-on-File (CoF) data by all entities except card issuers and networks. As an interim relief, merchants and payment aggregators can retain CoF data for up to T+4 days (or until settlement, whichever is earlier) solely for settling guest checkout transactions. Acquiring banks are allowed to continue storing CoF data for post-transaction activities until January 31, 2023.

What it means for you

Banks and payment aggregators must urgently complete the purge of stored card data by October 1, 2022, or face penal action including business restrictions. The narrow T+4 day window for guest checkout data is a temporary concession, not a relaxation of the overall ban. Acquiring banks have a slightly longer runway until January 31, 2023, to adjust their post-transaction processes, but must plan for full compliance thereafter.

What you must do

Who it affects

All payment system providers and participants, Merchants and payment aggregators (PAs), Acquiring banks, Card issuers and card networks (exempted from purge)

❓ Common questions

What is the exact deadline for purging CoF data?

The deadline remains October 1, 2022. No extension has been granted. All entities except card issuers and networks must purge stored card data by this date.

Can we store CoF data for guest checkout transactions after October 1?

Yes, but only as an interim measure. Merchants and PAs can store CoF data for a maximum of T+4 days (T being transaction date) or until settlement, whichever is earlier, and only for settlement purposes. The data must be purged immediately after.

What happens if we fail to comply?

RBI has warned of appropriate penal action, including imposition of business restrictions, for any non-compliance. This is a serious regulatory requirement.

📜 Read the original circular — full text as issued by RBI
RBI/2022-2023/95 CO.DPSS.POLC.No.S-760/02-14-003/2022-23 July 28, 2022 All Payment System Providers and Payment System Participants Madam / Dear Sir, Restriction on Storage of Actual Card Data [i.e. Card-on-File (CoF)] Reference is invited to Reserve Bank of India (RBI) circulars DPSS.CO.PD.No.1810/02.14.008/2019-20 dated March 17, 2020 and CO.DPSS.POLC.No.S33/02-14-008/2020-2021 dated March 31, 2021 on “Guidelines on Regulation of Payment Aggregators and Payment Gateways”, circular CO.DPSS.POLC.No.S-516/02-14-003/2021-22 dated September 07, 2021 on “Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services” and, circulars CO.DPSS.POLC.No.S-1211/02-14-003/2021-22 dated December 23, 2021 and CO.DPSS.POLC.No.S-567/02-14-003/2022-23 dated June 24, 2022 on “Restriction on Storage of Actual Card Data [i.e. Card-on-File (CoF)]”. 2. In terms of the above circulars, with effect from October 1, 2022, no entity in the card transaction / payment chain, other than the card issuers and / or card networks, shall store CoF data, and any such data stored previously shall be purged. 3. On a review of the issues involved and after detailed discussions thereon with all stakeholders, as also keeping in view that sufficient time has elapsed since the requirements were specified, the following are advised – a) There shall be no change in the effective date of implementation of the requirements – all entities, except card issuers and card networks, shall purge the CoF data before October 1, 2022. b) For ease of transition to an alternate system in respect of transactions where cardholders decide to enter the card details manually at the time of undertaking the transaction (commonly referred to as “guest checkout transactions”), the following are being permitted as an interim measure – Other than the card issuer and the card network, the merchant or its Payment Aggregator (PA) involved in settlement of such transactions, can save the CoF data for a maximum period of T+4 days (“T” being the transaction date) or till the settlement date, whichever is earlier. This data shall be used only for settlement of such transactions, and must be purged thereafter. For handling other post-transaction activities, acquiring banks can continue to store CoF data until January 31, 2023. 4. Appropriate penal action, including imposition of business restrictions, shall be considered by the RBI in case of any non-compliance. 5. This directive is issued under Section 10 (2) read with Section 18 of the Payment and Settlement Systems Act, 2007 (Act 51 of 2007). Yours faithfully, (P. Vasudevan) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2022-2023/95 · issued 28 Jul 2022. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Topics: Digital Payments / UPI
Key dataSee the live numbers behind this topic: RBI Penalty Tracker, Credit & Deposit Growth — updated from official RBI data.
Key termsPlain-English definitions of terms in this circular — see the full Indian banking glossary. UPI · KYC / AML · Deposit insurance (DICGC) · NEFT / RTGS
Who does what — compliance checklist
⚙️ Operations
  • For guest checkout transactions, ensure CoF data is retained only for T+4 days or until settlement, whichever is earlier, and then deleted.
💻 IT / Systems
  • Review and update internal systems and agreements with merchants and PAs to enforce the new data retention limits.
📜 Compliance
  • Purge all stored Card-on-File (CoF) data by October 1, 2022, except for card issuers and networks.
  • Acquiring banks: continue storing CoF data for post-transaction activities only until January 31, 2023, and plan for full deletion by that date.
  • Prepare for potential RBI audits and ensure compliance documentation is ready to avoid penal action.
Grouped from the action items above — a single circular may involve more than one team.
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (All payment system providers and participants, Merchants and payment aggregators (PAs), Acquiring banks, Card issuers and card networks (exempted from purge)), your first concrete step on “RBI Finalises Card-on-File Storage Ban: Oct 1 Deadline Stands” is: “Purge all stored Card-on-File (CoF) data by October 1, 2022, except for card issuers and networks.” (RBI issued this 28 Jul 2022).

  1. Circular: RBI/2022-2023/95 -- RBI Finalises Card-on-File Storage Ban: Oct 1 Deadline Stands
  2. Issued: 28 Jul 2022
  3. Action required: Purge all stored Card-on-File (CoF) data by October 1, 2022, except for card issuers and networks.
  4. Action required: For guest checkout transactions, ensure CoF data is retained only for T+4 days or until settlement, whichever is earlier, and then deleted.
  5. Action required: Acquiring banks: continue storing CoF data for post-transaction activities only until January 31, 2023, and plan for full deletion by that date.
  6. Action required: Review and update internal systems and agreements with merchants and PAs to enforce the new data retention limits.
  7. Action required: Prepare for potential RBI audits and ensure compliance documentation is ready to avoid penal action.
  8. Owner: ____________ Target date: ____________
  9. Board/committee approval needed? Y / N
  10. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12363&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗