Payment aggregators and gateways in India must satisfy RBI's PA-PG (Payment Aggregator-Payment Gateway) guidelines, including mandatory card tokenisation and restrictions on storing raw card data, alongside the DPDP Act 2023's consent and data-principal-rights requirements. Tokenisation solves the card-data storage problem but does not by itself satisfy DPDP consent or notice obligations for the transaction and customer data payment companies still hold. This guide maps where PA-PG rules and DPDP requirements intersect and where each applies independently.
Tokenisation and PA-PG guidelines cover card data. DPDP covers everything else you collect. See where the two frameworks meet — and where they do not.
RBI's card-on-file tokenisation framework was a major, mandatory shift for Indian payment aggregators and gateways — it removed raw card data from merchant and gateway systems, replacing it with tokens. This significantly reduces the risk profile around card data specifically. But payment companies process far more than card numbers: transaction history, device fingerprints, IP addresses, merchant relationships, customer contact details, and behavioural data used for fraud detection and analytics. All of this is personal data under the DPDP Act, and none of it is addressed by tokenisation. A payment gateway that is fully PA-PG compliant on tokenisation can still have significant DPDP gaps in notice, consent and data-sharing practices for this broader dataset.
The PA-PG guidelines and DPDP Act also created two separate breach and incident reporting regimes. RBI has its own cybersecurity incident reporting requirements for regulated payment entities; the DPDP Act separately requires breach notification to the Data Protection Board and to affected Data Principals, on its own timeline defined in the DPDP Rules 2025. Payment companies need one integrated breach response plan that satisfies both, rather than treating them as the same obligation.
Given the volume and sensitivity of data payment gateways and aggregators handle, and the higher penalty exposure for security-safeguard and breach failures (up to Rs 250 crore under the DPDP Act), payment companies should prioritise: a comprehensive privacy notice covering all data categories, specific consent for any data sharing with merchants or marketing/analytics partners, a unified breach response plan, and DPDP clauses in every processor and sub-processor agreement. Niti Bharat's Payment Aggregator DPDP Kit is built to layer onto existing PA-PG compliance work, targeting readiness well ahead of the May 2027 enforcement deadline.
A full guide mapping PA-PG tokenisation and RBI requirements against DPDP Act obligations, with a gap-closing checklist for payment companies.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.