Skip to main content

What are restrictions on storage of actual card data?

Reserve Bank of India (RBI) restricts storage of actual card data [i.e. Card-on-File (CoF)] by non-bank payment aggregators and merchants.

What is Card-on-File (CoF)?

Card-on-file (CoF) is the storing of customer card and payment information by a merchant, i.e. keeping card information “on file”.

What are the guidelines on storage of actual card data [i.e. Card-on-File (CoF)]?

No entity in the card transaction / payment chain, other than the card issuers and / or card networks, shall store Card-on-File (CoF) data, and any such data stored previously shall be purged.

From when are the restrictions on storage of actual card data [i.e. Card-on-File (CoF)] applicable?

Reserve Bank of India (RBI) had periodically extended the deadline for effecting the restriction on storage of actual card data [i.e. Card-on-File (CoF)] from June 30, 2021 to September 30, 2022, taking into account the representations received from the stakeholders.

All entities, except card issuers and card networks, are required to purge the CoF data before October 01, 2022.

What relaxations are allowed for “guest checkout transactions”?

For ease of transition to an alternate system in respect of transactions where cardholders decide to enter the card details manually at the time of undertaking the transaction (commonly referred to as “guest checkout transactions”), the following are permitted as an interim measure –

  • Other than the card issuer and the card network, the merchant or its Payment Aggregator (PA) involved in settlement of such transactions, can save the CoF data for a maximum period of T+4 days (“T” being the transaction date) or till the settlement date, whichever is earlier. This data shall be used only for settlement of such transactions, and must be purged thereafter.
  • For handling other post-transaction activities, acquiring banks can continue to store CoF data until January 31, 2023.


References

Reserve Bank of India. (2020, March 17). 'Guidelines on Regulation of Payment Aggregators and Payment Gateways (Updated as on November 17, 2020)'. Retrieved from https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=11822&Mode=0

Reserve Bank of India. (2021, December 23). 'Restriction on storage of actual card data [i.e. Card-on-File (CoF)]'. Retrieved from https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12211&Mode=0

Reserve Bank of India. (2022, June 24). 'Restriction on Storage of Actual Card Data [i.e. Card-on-File (CoF)]'. Retrieved from https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12345&Mode=0

Reserve Bank of India. (2022, July 28). 'Restriction on Storage of Actual Card Data [i.e. Card-on-File (CoF)]'. Retrieved from https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12363&Mode=0


Follow at - Telegram   Instagram   LinkedIn   Twitter

Comments

Popular Posts

Report of the Committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) in the Financial Sector

Reserve Bank of India (RBI) has released the report of the committee to develop a framework for responsible and ethical enablement of artificial intelligence (FREE-AI) in the financial sector. Committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) in the Financial Sector In the financial sector, Artificial Intelligence (AI) has the potential to unlock new forms of customer engagement, enable alternate approaches to credit assessment, risk monitoring, fraud detection, and offer new supervisory tools. At the same time, increased adoption of AI could lead to new risks like bias and lack of explainability, as well as amplifying existing challenges to data protection, cybersecurity, among others. To encourage the responsible and ethical adoption of AI in the financial sector, the committee to develop a Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) in the Financial Sector (Chairperson: Dr. Pushpak B...

Continuous Clearing and Settlement on Realisation in Cheque Truncation System (CTS)

Reserve Bank of India (RBI) has issued direction on continuous clearing and settlement on realisation in Cheque Truncation System (CTS). What is Cheque Truncation System (CTS)? Cheque Truncation System (CTS) involves halting the physical movement of the cheque and its replacement by images of the instrument and the corresponding data contained in the MICR line.  In CTS, 3 images are taken of each cheque – front Gray Scale, front Black & White and back Black & White. MICR (Magnetic Ink Character Recognition) is a 9-digit code printed at the bottom of cheques using magnetic ink – first 3 digits indicate City Code, middle 3 digits indicate Bank Code and the last 3 digits indicate Bank Branch Code. Only CTS-2010 standards compliant instruments can be presented for clearing through CTS. The presenting banks which truncates the cheques need to preserve the physical instruments for 10 years. From when will the continuous clearing and settlement on realisation in CTS be implemented...

Investments in Debt Instruments by Non-residents

Reserve Bank of India (RBI) has issued directions on investments in debt instruments by non-residents. What are the channels for investments in debt instruments by non-residents? General Route – for investment in Government securities and corporate debt securities by Foreign Portfolio Investors (FPIs) subject to specified investment limits and macro-prudential limits. Voluntary Retention Route (VRR) – for investments in Government securities and corporate debt securities, free of certain macro-prudential limits applicable to FPI investments in debt markets under the General Route, by FPIs that commit to remain invested for a stipulated retention period. Fully Accessible Route (FAR) – for investments by non-residents in certain specified categories of Central Government securities (‘specified securities’) without any restriction. Scheme for Trading and Settlement of Sovereign Green Bonds (SGrBs) issued by the Central Government by eligible foreign investors in the International Finan...

What is KYC?

Be it opening a new bank account, applying for a new credit card, registering for new e-wallet, or any other account or facility involving financial matters, the application process is incomplete until KYC is done.  What is KYC? KYC or Know Your Customer is a process of customer identification and verification while opening an account or undertaking a financial transaction. Why is KYC process needed? To prevent money laundering To combat financing of terrorism What is verified under KYC? The banks / financial institutions collect the relevant documents from the customers to verify the following – Proof of identity Proof of address Which documents can be collected for KYC? As per RBI’s Master Direction - Know Your Customer (KYC) Direction, 2016 (Updated as on May 10, 2021), “Officially Valid Document” (OVD) means – Passport Driving licence Proof of possession of Aadhaar number Voter's Identity Card issued by the Election Commission of India Job card issued by NREGA duly signed by an...

Non-Fund Based Credit Facilities

Reserve Bank of India (RBI) has issued directions on non-fund based credit facilities. To whom shall the directions be applicable? The directions shall apply to the following Regulated Entities (REs) for all their Non-Fund Based (NFB) exposures such as guarantee, letter of credit, co-acceptance etc. Commercial Banks (including Regional Rural Banks and Local Area Banks) Primary (Urban) Co-operative Banks (UCBs) / State Co-operative Banks (StCBs) / Central Co-operative Banks (CCBs) All India Financial Institutions (AIFIs) Non-Banking Financial Companies (NBFCs) including Housing Finance Companies (HFCs) in Middle Layer and above, only for the issuance of Partial Credit Enhancement. The directions shall not apply to the derivative exposures of a RE. Which NFB facilities are permitted to be issued by RE? RE shall issue a NFB facility only on behalf of a customer having funded credit facility from the RE. However, this shall not be applicable in respect of – Derivative contracts entered int...