DPDP compliance for payment aggregators and payment service providers
Payment aggregators sit at the centre of financial data flows for millions of Indians. Here is how the DPDP Act applies alongside RBI's Payments Aggregator framework.
What financial data do payment aggregators process under DPDP?
Payment aggregators process: cardholder data (card number, expiry, CVV for tokenisation), UPI VPAs and linked bank account details, transaction history (amount, merchant, timestamp), KYC data for merchant onboarding (GSTIN, PAN, Aadhaar, bank account verification), chargeback and dispute records, and device fingerprinting data for fraud prevention. Card and account data is sensitive personal data under the Act — it requires the highest security safeguards and explicit consent for any processing beyond transaction facilitation.
How do RBI Payment Aggregator guidelines and DPDP interact?
RBI's October 2020 guidelines on Payment Aggregators require that all payment data be stored only in India, prohibit PAs from storing card data after transaction authorisation (except via tokenisation), and mandate PCI DSS compliance. DPDP's requirements — data minimisation, purpose limitation, security safeguards, breach notification — align with and reinforce these RBI obligations. The key gap: DPDP adds individual rights obligations (customer access, correction, erasure) that RBI's framework does not explicitly address. Build a unified programme that covers both.
Are payment aggregators likely to be Significant Data Fiduciaries?
Large payment aggregators processing millions of daily transactions for hundreds of millions of Indians are among the most likely SDF candidates — they process sensitive financial data at extraordinary scale, their failure would cause widespread harm, and they have significant systemic importance. SDF designation would require a DPO, periodic DPIAs (including for fraud detection algorithms), and independent audits. Prepare SDF-ready governance now: appoint a DPO candidate, establish a data governance committee, and commission a pre-emptive DPIA on your fraud and risk systems.
How does DPDP apply to fraud detection and risk scoring?
Payment fraud detection involves profiling transaction behaviour to identify anomalies. This is automated processing that significantly affects individuals — a wrongly flagged transaction can result in payment failure, reputational harm, or account suspension. Under DPDP, individuals have the right to contest such decisions. Build explainability into your fraud system: when a transaction is declined based on your risk model, the system should be able to generate a reason code, and your customer support team should be able to explain and review it.
What DPDP obligations arise from payment data sharing with merchants?
Sharing transaction data with merchants — settlement information, chargeback details, transaction history — is data processing that must be covered in your Merchant Agreement. Merchants should not receive more transaction data than they need to reconcile payments and manage chargebacks. If you provide merchants with customer analytics (average transaction value, purchase frequency), this is a secondary use of customer data that requires consent beyond the transaction processing relationship. Review your merchant API data fields for data minimisation.
How does DPDP breach notification work for payment incidents?
A payment data breach — cardholder data exposure, UPI fraud, account takeover — triggers multiple notification obligations: CERT-In within 6 hours of knowledge; RBI within the prescribed timeline under PA guidelines; and the DPDP Data Protection Board within the DPDP-prescribed period (working assumption: 72 hours). Design your incident response runbook to trigger all three notifications simultaneously, with separate notification templates for each regulator. Train your ops team to start the clock at the moment of discovery, not confirmed validation.
Frequently asked questions
Do we need consent to use transaction data for credit scoring?
Using transaction data from your payment platform to build or contribute to credit scores is a secondary use not covered by the transaction processing consent. If you operate a BNPL or lending product using payment history for credit decisions, you need explicit consumer consent for the credit scoring use — distinct from the consent for payment processing. Be specific in the consent form about what data is used, how the score is computed, and who the score is shared with.
How does DPDP apply to UPI data from NPCI?
UPI infrastructure is operated by NPCI, and banks/PSPs participating in UPI follow NPCI's data governance framework. DPDP applies to PSPs as Data Fiduciaries for UPI transaction data they hold. NPCI's rules on data sharing and UPI transaction data localisation align with DPDP's spirit. If you use UPI transaction data for purposes beyond payment facilitation — analytics, cross-sell, fraud profiling — ensure your privacy notice discloses these uses and you have the required consent.
Must we notify every affected customer after a payment data breach?
Under DPDP, you must notify affected data principals when a breach is likely to cause harm to them. A breach exposing card numbers or bank account details clearly meets this threshold — customers need to know to take protective action (block card, monitor account). Notification should be timely, plain-language, and include what data was affected, what risk it poses, and what the customer should do. Do not wait for your forensic investigation to be complete before notifying customers at clear risk.
Assess your payment aggregator DPDP compliance
Niti Bharat's DPDP Readiness Assessment covers payment aggregators — RBI overlap, SDF readiness, fraud system explainability, breach response, and merchant data sharing agreements.
Start Payment Aggregator DPDP Assessment