HomeCirculars › RBI/2022-23/77

RBI Extends Card-on-File Storage Ban Deadline to Sept 30, 2022

Current · Source: Reserve Bank of India · RBI/2022-23/77 · issued 24 Jun 2022 · ~1 min read
Quick answerRBI has extended the deadline for purging stored card-on-file (CoF) data by three months to September 30, 2022. Token creation has progressed but guest checkout solutions remain unimplemented. All entities except card issuers and networks must purge CoF data by the new date.
The rule, in the simplest words
How it plays out — a real example

Priya, a branch operations officer in Indore, uses a payment gateway to collect monthly interest from customers. She reads the RBI extension and tells her tech team: 'We have until September 30 to delete all saved card numbers and set up tokens for recurring payments. Also, build a guest checkout screen so customers can type their card details manually for one-time payments without storing them.'

What changed

The earlier deadline of June 30, 2022 for purging stored CoF data has been extended to September 30, 2022. This follows stakeholder discussions noting token creation progress but slow merchant adoption and lack of a guest checkout alternative.

What it means for you

Banks and payment aggregators get three more months to comply, but must accelerate tokenisation and guest checkout mechanisms. Non-compliant entities risk regulatory action after September 30. The extension signals RBI's willingness to accommodate industry readiness while maintaining data security goals.

What you must do

Who it affects

Payment system providers, Payment aggregators and gateways, Merchants storing card data, Card issuers and networks (exempted from purging)

❓ Common questions

What is the new deadline for purging CoF data?

The deadline has been extended to September 30, 2022. After this date, no entity except card issuers and networks can store actual card data.

Why did RBI extend the deadline?

Token creation has progressed but merchant adoption is slow, and a guest checkout alternative for manual card entry has not been implemented yet.

Does this affect guest checkout transactions?

Yes, the industry must implement an alternate system for guest checkout before the new deadline, as it remains unresolved.

📜 Read the original circular — full text as issued by RBI
RBI/2022-23/77 CO.DPSS.POLC.No.S-567/02-14-003/2022-23 June 24, 2022 All Payment System Providers and Payment System Participants Madam / Dear Sir, Restriction on Storage of Actual Card Data [i.e. Card-on-File (CoF)] Reference is invited to Reserve Bank of India (RBI) circulars DPSS.CO.PD.No.1810/02.14.008/ 2019-20 dated March 17, 2020 and CO.DPSS.POLC.No.S33/02-14-008/2020-2021 dated March 31, 2021 on “Guidelines on Regulation of Payment Aggregators and Payment Gateways”, and CO.DPSS.POLC.No.S-516/02-14-003/2021-22 dated September 07, 2021 on “Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services”. 2. In terms of these circulars, with effect from January 1, 2022, no entity in the card transaction / payment chain, other than the card issuers and / or card networks, shall store the CoF data, and any such data stored previously shall be purged. Subsequently, to allow more time to the industry stakeholders for devising alternate mechanism(s) to handle any use case or post-transaction activity, this timeline was extended to June 30, 2022, vide circular CO.DPSS.POLC.No.S-1211/02-14-003/2021-22 dated December 23, 2021 on “Restriction on storage of actual card data [i.e. Card-on-File (CoF)]”. 3. On a review of the issues involved and after detailed discussions with all stakeholders, it is observed that considerable progress has been made in terms of token creation. Transaction processing based on these tokens has also commenced, though it is yet to gain traction across all categories of merchants. Further, an alternate system in respect of transactions where cardholders decide to enter the card details manually at the time of undertaking the transaction (commonly referred to as “guest checkout transactions”) has not been implemented by the industry stakeholders, so far. 4. Given the above, it has been decided to extend the timeline for storing of CoF data by three months, i.e., till September 30, 2022, after which such data shall be purged. 5. This directive is issued under Section 10 (2) read with Section 18 of Payment and Settlement Systems Act, 2007 (Act 51 of 2007). Yours faithfully, (P. Vasudevan) Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2022-23/77 · issued 24 Jun 2022. The plain-English explanation above is BankPulse’s own independent summary.
🧰 Tools — save, print, templates & related
Topics: Digital Payments / UPI
Key dataSee the live numbers behind this topic: RBI Penalty Tracker, Credit & Deposit Growth — updated from official RBI data.
Key termsPlain-English definitions of terms in this circular — see the full Indian banking glossary. UPI · KYC / AML · Deposit insurance (DICGC) · NEFT / RTGS
Worked example & action-note template

Example: if you are a Compliance officer at a bank this circular applies to (Payment system providers, Payment aggregators and gateways, Merchants storing card data, Card issuers and networks (exempted from purging)), your first concrete step on “RBI Extends Card-on-File Storage Ban Deadline to Sept 30, 2022” is: “Ensure all stored CoF data is purged by September 30, 2022, except for card issuers and networks.” (RBI issued this 24 Jun 2022).

  1. Circular: RBI/2022-23/77 -- RBI Extends Card-on-File Storage Ban Deadline to Sept 30, 2022
  2. Issued: 24 Jun 2022
  3. Action required: Ensure all stored CoF data is purged by September 30, 2022, except for card issuers and networks.
  4. Action required: Accelerate tokenisation adoption across merchant categories to handle recurring and one-time transactions.
  5. Action required: Develop and implement a guest checkout solution for manual card entry transactions before the deadline.
  6. Action required: Audit current data storage practices and confirm compliance with the tokenisation framework.
  7. Owner: ____________ Target date: ____________
  8. Board/committee approval needed? Y / N
  9. Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.

💬 Banker Discussion

Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.

Loading comments…
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly).
Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12345&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗