Home › Credit Cards

Credit Cards

Every RBI rule that touches Credit Cards, simplified for bankers. 9 current circulars.

9
current circulars shown below
0
withdrawn / superseded — moved to archive

Status from our nightly regulatory-lineage check. Only circulars with no recorded withdrawal appear below — always confirm current applicability against the official RBI source linked on each circular.

OverviewCredit cards combine unsecured lending with a payments rail, so they are governed by a dedicated master direction covering issuance, billing transparency, interest and charge disclosure, consent for activation and limit changes, card-network choice and closure timelines. Co-branding, add-on cards and the treatment of unsolicited cards are all addressed, alongside grievance-redress and compensation requirements.
Key dataSee the numbers behind Credit Cards: Credit & Deposit Growth — bank credit & deposit growth trends, updated from official RBI data. Related live data: NPA / Asset-Quality Tracker.
Key termsPlain-English definitions of the terms on this page — see the full Indian banking glossary. Key Facts Statement (KFS) · Gross NPA (GNPA) · Special Mention Account (SMA) · KYC / AML · Card Tokenisation · Customer liability on unauthorised transactions (zero-liability)
Part of clusterThis topic is part of the Retail & Secured Lending cluster — explore related rules, FAQs and live data across the theme.

Latest circulars in this cluster

Bank Credit Growth Surges to 18.3% in June 2026

Non-food bank credit grew 18.3% y-o-y in June 2026, up from 9.3% a year ago. Industry and services led the surge, while

· 17 hours ago · 63267

Non-Food Bank Credit Growth at 17.4% as of May 31, 2026

Non-food bank credit grew 17.4% YoY as of May 31, 2026, up from 8.8% a year ago. Industry and services led the surge, wi

· 4 weeks ago · 63052

RCB Customer Liability Limits for Unauthorised EBTs Revised

RBI has revised liability rules for unauthorised electronic banking transactions at Rural Co-operative Banks (RCBs), app

· 1 month ago · 0

UCB Customer Liability Limits for Unauthorised EBTs Revised

RBI has revised liability rules for unauthorised electronic banking transactions at UCBs, effective Jan 1, 2027. New def

· 1 month ago · 0

RRB Customer Liability Limits for Unauthorised EBTs Revised (Third Amendment Directions, 2026)

RBI issued the Third Amendment Directions, 2026, revising customer liability rules for unauthorised electronic banking t

· 1 month ago · 0

SFB Customer Liability Rules for Unauthorised Digital Transactions Updated

RBI revised liability rules for SFB customers on unauthorised electronic transactions, effective Jan 1, 2027. New defini

· 1 month ago · 0

RBI Tightens Customer Liability Rules for Unauthorised EBTs (Applicable from Jan 1, 2027)

RBI has revised liability limits for unauthorised electronic banking transactions (EBTs) applicable to transactions on o

· 1 month ago · 0

RBI's New Credit & Debit Card Conduct Directions 2025

RBI issued consolidated directions for commercial banks on credit/debit card issuance and conduct, effective immediately

· 1 month ago · 0

RBI Amends Credit Card Reporting and Late Payment Charges

RBI amends credit card reporting and late payment charges rules, effective April 1, 2027. Banks must report 'past due' a

· 1 month ago · 0

How RBI card-network tokenisation protects your card

RBI’s card tokenisation framework changed how online merchants handle your card. Instead of storing your real card number, they store a meaningless merchant-specific token. Here is how that protects you, step by step:

  1. Understand what a card token is. Under the RBI Card-on-File (CoF) tokenisation framework, your actual 16-digit card number (the PAN) is replaced by a unique, randomly generated 'token' for each merchant. The token is useless anywhere else, so the merchant never has to store — and can never leak — your real card details.
  2. See why RBI mandated it. RBI barred merchants and payment aggregators from storing actual card data on their servers and required tokenisation instead. The aim is to cut the blast radius of a data breach: if a shopping site is hacked, attackers get only merchant-specific tokens, not card numbers that work everywhere.
  3. Know how a token gets created. When you tick 'save this card securely as per RBI guidelines' at checkout, the card network (Visa, Mastercard, RuPay, etc.) issues a token tied to that one merchant and device, with your explicit one-time consent and an additional-factor authentication step. You can create, view and delete your saved tokens with the card issuer.
  4. Check what stays protected. Each token is merchant-specific and device-specific, so a token saved at one store cannot be replayed at another. Your bank still applies the usual transaction limits, OTP/additional-factor authentication and fraud monitoring. If you lose the card or it is reissued, the linked tokens can be revoked without exposing the underlying number.
  5. Act as a cardholder. Prefer the 'tokenise as per RBI guidelines' option over letting a site keep your raw card number, review the list of saved cards/tokens in your banking app, and delete tokens for merchants you no longer use. Tokenisation is free, optional and within your control — you can always choose to key in the full card details manually instead.
Illustrative worked example

Suppose you save your card at an online store. The store now holds a token like 5123 xxxx xxxx 9012 mapped only to that merchant, not your real number. If that store is later breached, the leaked token cannot be used to pay anywhere else, and your bank can revoke it instantly — your underlying card stays safe. Example is illustrative; exact behaviour depends on your issuer and the card network.

This is our plain-English explainer, not RBI text; every rule links to its official page on rbi.org.in. under the editorial review of our expert reviewer, CA Amit Jain. Independent platform, not affiliated with the Reserve Bank of India.

Frequently asked questions

What must a card issuer disclose before charging interest?

Issuers must clearly show the billing cycle, the way interest is computed on unpaid balances, and all fees and charges, so a cardholder can see the true cost of revolving credit before they incur it.

Can a card be activated without the customer's consent?

No. A card cannot be activated, nor a limit increased, without the cardholder's explicit consent. If a card is not activated within the defined window, the issuer must close it without cost, subject to the applicable circular.

Can customers choose their card network?

RBI has moved to give eligible cardholders a choice of card network rather than having it tied solely to the issuer's arrangement. The relevant instruction is in the cluster below.

Related topics & data

Department of Regulation

family for this topic.

Personal Loans

Related BankPulse topic cluster.

Digital Payments / UPI

Related BankPulse topic cluster.

KYC / AML

Related BankPulse topic cluster.

Public beta — plain-English informational summaries. Always verify against the official RBI source (circular number cited on every page) before making compliance, credit, treasury, audit, or operational decisions. · Join our WhatsApp channel ↗