DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr

Quick Answer

What DPDP compliance does a payment aggregator in India need? A Payment Aggregator or Payment Gateway (PA/PG) regulated under RBI's PA-PG Guidelines needs DPDP-layered documentation covering: a customer-facing privacy notice explaining what card and transaction data is processed given the card tokenisation mandate; a merchant-facing Data Processing Agreement clarifying processor obligations; a payments-data localisation statement consistent with RBI's 2018 storage circular; and a breach notification SOP that satisfies both RBI incident-reporting timelines and DPDP's Data Protection Board notification duty. This kit builds all four.

Payment Aggregator DPDP Compliance Kit — RBI PA-PG + DPDP Act

Map your RBI Payment Aggregator obligations — tokenisation, data localisation, merchant onboarding — onto full DPDP Act 2023 compliance documentation.

Free Compliance Outline Full Kit ₹1,999
Tell us about your PA/PG business
We tailor the kit to your licence status, merchant base and data flows.
Entity
Scale
Data & Tokenisation Status
Documents to Generate
Contact
Free Preview: PA/PG Compliance Kit
The tokenisation-to-DPDP mapping and data-localisation outline are visible. The full customer notice, merchant DPA clauses and breach SOP unlock with purchase.
Free Preview

Unlock the Full Payment Aggregator DPDP Kit

₹1,999 one-time
The complete customer privacy notice, merchant DPA clauses, dual-timeline breach SOP and sub-processor audit checklist — built for RBI-regulated PA/PGs.
  • Customer-facing privacy notice (checkout-flow ready)
  • Merchant Data Processing Agreement clause set
  • Payments data localisation statement (RBI 2018 circular + DPDP overlay)
  • Breach notification SOP with dual RBI/DPB timeline
  • Sub-processor / payment partner audit checklist
  • Data Principal rights process for cardholders
  • Tokenisation-to-DPDP security safeguard mapping
  • RBI + DPB combined evidence file checklist
Secure payment via Razorpay · Delivered in 15 min · Not legal advice

Why payment aggregators are a DPB enforcement priority sector

Payment Aggregators and Gateways sit in the transaction path of nearly every digital payment in India, giving them visibility into card, bank, contact and purchase-behaviour data across thousands of merchants simultaneously. That concentration of financial personal data — combined with RBI's existing regulatory scrutiny — makes PA/PGs a natural early-priority sector once the Data Protection Board begins active enforcement around May 2027. A payment aggregator that is fully RBI-compliant but has no DPDP-specific documentation is still exposed to penalties of up to ₹250 crore for security-safeguard failures.

Niti Bharat runs fixed-price DPDP compliance engagements (₹75,000–₹3.2 lakh) specifically for regulated fintech infrastructure — payment aggregators, gateways and NBFCs — where RBI and DPDP obligations must be documented as one coherent programme rather than two disconnected compliance efforts. Contact hello@nitibharat.com to scope an engagement.

Tokenisation reduces risk — but does not remove DPDP obligations

A common misconception among PA/PG compliance teams is that RBI's card tokenisation mandate, having removed raw card data from most systems, also removes DPDP exposure. It does not: PA/PGs still hold names, phone numbers, email addresses, device identifiers, IP addresses, transaction histories and merchant relationship data — all personal data under the DPDP Act's broad definition. Tokenisation reduces the sensitivity and breach blast-radius of card data specifically; it does not exempt the aggregator from consent, notice, rights-handling or breach-notification obligations for the rest of the personal data it processes.

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
Pharma DPDP Compliance PackPrivacy Champion Programme Kit - Launch a Network…Privacy Metrics Reporting PackDPDP Compliance for Retail & E-Commerce: What Ever…See all Generators & Reports tools →📝 How to Write Employee Privacy Notice DPDP📝 Build Your DPDP Consent Notice