RBI Extends Card-on-File Storage Ban Deadline to Sept 30, 2022
Current · Source: Reserve Bank of India · RBI/2022-23/77 · issued 24 Jun 2022 · ~1 min read
Quick answerRBI has extended the deadline for purging stored card-on-file (CoF) data by three months to September 30, 2022. Token creation has progressed but guest checkout solutions remain unimplemented. All entities except card issuers and networks must purge CoF data by the new date.
The rule, in the simplest words
By September 30, 2022, all companies except card issuers (banks that give you the card) and card networks (like Visa or Mastercard) must delete any saved card numbers from their systems.
Companies must switch to using tokens (a secret code that stands for your card number) for payments, especially for subscriptions or repeat purchases.
A 'guest checkout' option (where you type your card details fresh each time without saving them) must be ready before the deadline.
If a company does not follow these rules after September 30, 2022, the RBI (India's central bank) can take action against them.
How it plays out — a real example
Priya, a branch operations officer in Indore, uses a payment gateway to collect monthly interest from customers. She reads the RBI extension and tells her tech team: 'We have until September 30 to delete all saved card numbers and set up tokens for recurring payments. Also, build a guest checkout screen so customers can type their card details manually for one-time payments without storing them.'
What changed
The earlier deadline of June 30, 2022 for purging stored CoF data has been extended to September 30, 2022. This follows stakeholder discussions noting token creation progress but slow merchant adoption and lack of a guest checkout alternative.
What it means for you
Banks and payment aggregators get three more months to comply, but must accelerate tokenisation and guest checkout mechanisms. Non-compliant entities risk regulatory action after September 30. The extension signals RBI's willingness to accommodate industry readiness while maintaining data security goals.
What you must do
Ensure all stored CoF data is purged by September 30, 2022, except for card issuers and networks.
Accelerate tokenisation adoption across merchant categories to handle recurring and one-time transactions.
Develop and implement a guest checkout solution for manual card entry transactions before the deadline.
Audit current data storage practices and confirm compliance with the tokenisation framework.
Who it affects
Payment system providers, Payment aggregators and gateways, Merchants storing card data, Card issuers and networks (exempted from purging)
❓ Common questions
What is the new deadline for purging CoF data?
The deadline has been extended to September 30, 2022. After this date, no entity except card issuers and networks can store actual card data.
Why did RBI extend the deadline?
Token creation has progressed but merchant adoption is slow, and a guest checkout alternative for manual card entry has not been implemented yet.
Does this affect guest checkout transactions?
Yes, the industry must implement an alternate system for guest checkout before the new deadline, as it remains unresolved.
📜 Read the original circular — full text as issued by RBI
RBI/2022-23/77
CO.DPSS.POLC.No.S-567/02-14-003/2022-23
June 24, 2022
All Payment System Providers and Payment System Participants
Madam / Dear Sir,
Restriction on Storage of Actual Card Data [i.e. Card-on-File (CoF)]
Reference is invited to Reserve Bank of India (RBI) circulars DPSS.CO.PD.No.1810/02.14.008/ 2019-20 dated March 17, 2020 and CO.DPSS.POLC.No.S33/02-14-008/2020-2021 dated March 31, 2021 on “Guidelines on Regulation of Payment Aggregators and Payment Gateways”, and CO.DPSS.POLC.No.S-516/02-14-003/2021-22 dated September 07, 2021 on “Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services”.
2. In terms of these circulars, with effect from January 1, 2022, no entity in the card transaction / payment chain, other than the card issuers and / or card networks, shall store the CoF data, and any such data stored previously shall be purged. Subsequently, to allow more time to the industry stakeholders for devising alternate mechanism(s) to handle any use case or post-transaction activity, this timeline was extended to June 30, 2022, vide circular CO.DPSS.POLC.No.S-1211/02-14-003/2021-22 dated December 23, 2021 on “Restriction on storage of actual card data [i.e. Card-on-File (CoF)]”.
3. On a review of the issues involved and after detailed discussions with all stakeholders, it is observed that considerable progress has been made in terms of token creation. Transaction processing based on these tokens has also commenced, though it is yet to gain traction across all categories of merchants. Further, an alternate system in respect of transactions where cardholders decide to enter the card details manually at the time of undertaking the transaction (commonly referred to as “guest checkout transactions”) has not been implemented by the industry stakeholders, so far.
4. Given the above, it has been decided to extend the timeline for storing of CoF data by three months, i.e., till September 30, 2022, after which such data shall be purged.
5. This directive is issued under Section 10 (2) read with Section 18 of Payment and Settlement Systems Act, 2007 (Act 51 of 2007).
Yours faithfully,
(P. Vasudevan)
Chief General Manager
Reproduced for reference with acknowledgment — Source: Reserve Bank of India · RBI/2022-23/77 · issued 24 Jun 2022. The plain-English explanation above is BankPulse’s own independent summary.
Example: if you are a Compliance officer at a bank this circular applies to (Payment system providers, Payment aggregators and gateways, Merchants storing card data, Card issuers and networks (exempted from purging)), your first concrete step on “RBI Extends Card-on-File Storage Ban Deadline to Sept 30, 2022” is: “Ensure all stored CoF data is purged by September 30, 2022, except for card issuers and networks.” (RBI issued this 24 Jun 2022).
Circular: RBI/2022-23/77 -- RBI Extends Card-on-File Storage Ban Deadline to Sept 30, 2022
Issued: 24 Jun 2022
Action required: Ensure all stored CoF data is purged by September 30, 2022, except for card issuers and networks.
Action required: Accelerate tokenisation adoption across merchant categories to handle recurring and one-time transactions.
Action required: Develop and implement a guest checkout solution for manual card entry transactions before the deadline.
Action required: Audit current data storage practices and confirm compliance with the tokenisation framework.
Owner: ____________ Target date: ____________
Board/committee approval needed? Y / N
Evidence filed in compliance register on: ____________
Built only from this circular’s own published fields — not legal advice; always confirm against the official RBI source.
💬 Banker Discussion
Discuss this circular with fellow bankers — reply, upvote what helps, report what doesn’t belong. Be professional; no client data. Views are the commenter’s own, not BankPulse’s.
BankPulse Compliance Evidence Pack — generated 03 Aug 2026 · status cross-checked against RBI’s official withdrawal register (refreshed weekly). Official RBI source: https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12345&Mode=0 — Plain-English summary by BankPulse (bankpulse.ai), reviewed by our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India; is our own plain-English paraphrase, not RBI’s original wording.
Help us keep this accurate
Found an inaccuracy or have an improvement? Tell us. Every report is reviewed by our team before any change is made — nothing goes live unverified.
Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗
BANKPULSE · FREE DAILY BRIEF
Get RBI updates for your role
Every important RBI update, decoded in plain English — for your career, exams & financial awareness.
We collect only your email, name and role, used solely to send your brief — never sold or shared. Withdraw anytime via the unsubscribe link in any email. Independent platform, not affiliated with the RBI. Information, not legal advice.
REPORT AN ERROR · BETA
Spotted an error? Earn 500 BankPulse Credits
Help us stay accurate. If your correction is verified true and approved by our founder, you earn 500 BankPulse Credits — redeemable when the platform monetises.
Reviewed by a human before any credit is awarded. We never change the site from crowd input without verification.
WANT A NEW FEATURE · BETA
What would make BankPulse more useful for you?
Tell us what to build next — a tool, a data view, a role page, anything. We read every suggestion.
Thank you — your ideas directly shape what we build.