What DPDP compliance does a payment aggregator in India need? A Payment Aggregator or Payment Gateway (PA/PG) regulated under RBI's PA-PG Guidelines needs DPDP-layered documentation covering: a customer-facing privacy notice explaining what card and transaction data is processed given the card tokenisation mandate; a merchant-facing Data Processing Agreement clarifying processor obligations; a payments-data localisation statement consistent with RBI's 2018 storage circular; and a breach notification SOP that satisfies both RBI incident-reporting timelines and DPDP's Data Protection Board notification duty. This kit builds all four.
Map your RBI Payment Aggregator obligations — tokenisation, data localisation, merchant onboarding — onto full DPDP Act 2023 compliance documentation.
Why tokenisation is a DPDP data-minimisation control, not just an RBI mandate: RBI's card-on-file tokenisation mandate prohibits PA/PGs and merchants from storing actual card numbers (PAN), CVV or expiry after transaction completion, replacing them with a token. Read alongside the DPDP Act, this is precisely the kind of data-minimisation and storage-limitation practice Section 8's 'reasonable security safeguards' obligation expects — tokenisation reduces the personal data you actually hold, which reduces both breach impact and DPB exposure.
What the gap analysis covers: Whether your token vault architecture, token-mapping access controls, and merchant token-request logging are documented in a way that would satisfy a DPB inquiry into 'reasonable security safeguards' — not just a PCI-DSS or RBI systems audit. Most PA/PGs have the technical control but no DPDP-facing documentation of it; this kit builds that documentation layer.
RBI's 2018 storage circular baseline: Complete payment system data (originating, ending and full transaction cycle data) must be stored only in India, with any processing abroad requiring the foreign leg's data to be deleted from the overseas system within 24 hours and returned to India.
Where DPDP adds a second layer: The DPDP Act's cross-border transfer provisions (Section 16) permit transfers to jurisdictions not restricted by the Central Government, subject to conditions the Government may notify. For a PA/PG, this means any customer or merchant personal data (as distinct from pure payment-system data) sent to an overseas processor, fraud-analytics vendor, or cloud region needs its own DPDP-compliant transfer basis — documented separately from your RBI localisation compliance, because the two regimes cover overlapping but not identical data sets.
Documents selected for your compliance kit:
Payment Aggregators and Gateways sit in the transaction path of nearly every digital payment in India, giving them visibility into card, bank, contact and purchase-behaviour data across thousands of merchants simultaneously. That concentration of financial personal data — combined with RBI's existing regulatory scrutiny — makes PA/PGs a natural early-priority sector once the Data Protection Board begins active enforcement around May 2027. A payment aggregator that is fully RBI-compliant but has no DPDP-specific documentation is still exposed to penalties of up to ₹250 crore for security-safeguard failures.
Niti Bharat runs fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) specifically for regulated fintech infrastructure — payment aggregators, gateways and NBFCs — where RBI and DPDP obligations must be documented as one coherent programme rather than two disconnected compliance efforts. Contact hello@nitibharat.com to scope an engagement.
A common misconception among PA/PG compliance teams is that RBI's card tokenisation mandate, having removed raw card data from most systems, also removes DPDP exposure. It does not: PA/PGs still hold names, phone numbers, email addresses, device identifiers, IP addresses, transaction histories and merchant relationship data — all personal data under the DPDP Act's broad definition. Tokenisation reduces the sensitivity and breach blast-radius of card data specifically; it does not exempt the aggregator from consent, notice, rights-handling or breach-notification obligations for the rest of the personal data it processes.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.