Reference🌏 Payments in Asia-PacificIntermediate⏱ 22 min read

🇮🇳 RuPay, cards, and tokenization in India

The RuPay domestic scheme and its policy-driven share, mandatory tokenization and the end of merchant PAN storage, e-NACH and UPI AutoPay mandates, data localization, zero MDR on RuPay debit, and payment aggregator licensing

One card base, two opposite trajectories

India’s card base comprises the debit and credit cards in circulation, two categories whose paths have diverged since 2021. India had about 103.43 crore debit cards and 11.58 crore credit cards in circulation in December 2025, according to the Reserve Bank of India’s Payment Systems Report. The base is overwhelmingly debit, yet transaction volumes are moving the other way. Between 2021 and 2025, debit card transactions fell from 408.7 crore to 133.6 crore, an average decline of 24.4% a year. Over the same period, credit card transactions rose from 2.16 billion to 5.7 billion (RBI, Payment Systems Report, December 2025). The number of cards issued and the number of payments made therefore measure two different things. Sizing an Indian market by its card base means counting cards their holders no longer use to pay.

133 crore
debit card transactions in 2025, down from 408 crore in 2021
RBI, Payment Systems Report 2026
₹23.2 lakh crore
value of credit card payments in 2025, up from ₹8.9 lakh crore in 2021
RBI, Payment Systems Report 2026
71,1 %
private banks’ share of outstanding credit cards in December 2025 (67.7% in December 2021)
RBI, Payment Systems Report 2026
73.13 crore
UPI QR codes deployed, up 7.8% in six months
RBI, Payment Systems Report 2026
Debit cardCredit card
Volume408 crore → 133 crore transactions2.16B → 5.7B transactions
Value₹7.4 lakh crore → ₹4.5 lakh crore₹8.9 lakh crore → ₹23.2 lakh crore
Annual trend−24.4% a year by volumeAbout +27% a year by value
DriverFully replaced by UPI, free for cardholders and merchantsCredit has no UPI equivalent, except through RuPay
Remaining usesATM withdrawals, account access, mandate enrollmentOnline payments, large tickets, installment plans (EMI)
Debit and credit in India: the gap widened in four years (2021 → 2025)
🔑
The Indian debit card has changed its role
The Indian debit card is now an account access tool rather than a mass-market payment instrument. Its remaining uses all sit outside the point of sale: ATM withdrawals via the National Financial Switch, authentication when enrolling an e-NACH mandate, and carrying a bank identifier. An acceptance model built on domestic debit in stores therefore no longer has the volume it assumes. Mass-market payments moved to UPI between 2021 and 2025, and the shift did not reverse in any of the fiscal years observed.

Two interoperable QR codes coexist in India. UPI QR carries account-to-account payments, while Bharat QR, which runs on card rails, carries scan-to-pay card payments. In October 2020, the RBI barred payment system operators from launching any new proprietary QR code and confirmed that only these two standards would continue. Merchants accepting QR payments therefore have two options: a free account-to-account (A2A) rail and a fee-bearing card rail.

RuPay: a domestic scheme gaining share through credit

RuPay is India’s domestic card scheme, launched in 2012 by the National Payments Corporation of India (NPCI), a not-for-profit entity owned by banks and supervised by the RBI. According to the NPCI, more than 760 million RuPay cards had been issued across all products as of 2024. That base is mainly a legacy of financial inclusion policies. Accounts opened under the Pradhan Mantri Jan Dhan Yojana program came with a RuPay debit card by default. Like the rest of the debit base described above, these cards now generate almost no payments.

RuPay’s growth now comes from credit, and from a feature reserved for the domestic scheme. RuPay Credit Card on UPI links a RuPay credit card to a UPI ID. The cardholder scans the merchant’s QR code, authenticates with a UPI PIN, and the payment is charged to the credit line. The merchant thus accepts credit without a terminal, on a rail where Visa and Mastercard have no equivalent. The NPCI said in 2025 that 16% of card spending went through RuPay, nearly half of it credit on UPI. The Indian press put RuPay’s share of the credit card market at around 18% in October 2025, though that figure is unofficial.

2008
NPCI incorporated
Umbrella organization for retail payment systems, set up by banks under the aegis of the RBI and the Indian Banks’ Association.
2012
RuPay launches
Domestic card scheme. The initial selling point is processing cost, since transactions no longer pass through switches outside India.
April 6, 2018
Payment data localization
Circular DPSS.CO.OD No. 2785/06.08.005/2017-2018 requires all payment system data to be stored only in India.
January 8, 2019
Tokenization framework
The RBI allows tokenization of card transactions, initially on cardholders’ devices.
January 1, 2020
Zero MDR on RuPay debit and BHIM-UPI
Under Section 269SU, introduced by the 2019 Finance Act, the merchant fee is set to zero by law.
October 20, 2021
NPCI Tokenisation System (NTS)
The NPCI launches its own tokenization service for RuPay cards, alongside the Visa and Mastercard platforms.
October 1, 2022
End of PAN storage by merchants
Merchants and aggregators may no longer store card numbers, CVVs, or expiration dates.
September 6, 2024
Network choice at issuance
The March 6, 2024, circular takes effect, ending exclusivity between issuers and networks.
September 15, 2025
Consolidated Directions on payment aggregators
A single text replaces the 2020, 2021, and 2023 frameworks and regulates in-person acceptance for the first time.
April 21, 2026
Digital Payments – E-mandate Framework, 2026
A single regime for recurring mandates across cards, UPI, and prepaid instruments.
ℹ️
RuPay Global is not a global network
RuPay acceptance outside India relies on issuing partnerships with third-party networks, mainly Discover Global Network and JCB, plus local acceptance agreements. RuPay has no acceptance infrastructure of its own outside India. A “RuPay Global” card presented in London or Dubai technically runs over the partner network. For a non-Indian acquirer, accepting these cards therefore depends on its agreements with Discover and JCB, not on a contract with the NPCI.
  • National Common Mobility Card (NCMC), since 2019: an open-loop transit card, interoperable across city transit networks, built on RuPay, with an offline wallet stored on the chip.
  • National Electronic Toll Collection (NETC) / FASTag, since 2016: interoperable RFID tolling run by the NPCI, mandatory on national highways and funded through prepaid instruments.
  • National Financial Switch (NFS), transferred from IDRBT to the NPCI in 2009: the interbank switch for India’s ATM network. It is invisible in market analyses, yet it alone guarantees that withdrawals work across banks.
  • Bharat Connect (formerly the Bharat Bill Payment System, 2017), operated by NPCI Bharat BillPay Ltd: an interoperable bill payment rail where a biller connects once and becomes payable from any app.

Network choice: India’s version of opening up the market

Network choice is the cardholder’s right to pick the card network that will carry the card, when it is issued and again when it is renewed. Indian issuers traditionally signed exclusivity agreements with one network, portfolio by portfolio. The RBI ended that practice with a circular dated March 6, 2024, in force since September 6, 2024, after a draft released for consultation on July 5, 2023. The circular bans clauses that stop an issuer from using other networks and requires issuers to offer customers a choice of network at issuance and again at renewal. Issuers with 10 lakh (1 million) active credit cards or fewer are exempt.

The RBI lists five card networks authorized to operate in India: American Express Banking Corp., Diners Club International Ltd, Mastercard Asia/Pacific Pte Ltd, National Payments Corporation of India – RuPay, and Visa Worldwide Pte Ltd. An issuer above the threshold must offer its customers at least two of them. The customer chooses a network once, since the card then carries only one payment application.

India — RBI circular of March 6, 2024European Union — Article 8 of Regulation (EU) 2015/751
What is regulatedThe contract between issuer and networkThe card: it carries two payment applications
What is prohibitedExclusive issuer–network agreementsPreventing co-badging and locking the choice at the point of sale
What the cardholder choosesOne network, at issuance and again at renewalThe application used, transaction by transaction
ScopeIssuers with more than 10 lakh active credit cardsAll schemes and issuers in the European Economic Area
Effect on routingNo dynamic routing: the network is fixed at issuanceRouting possible in store and online, based on the choice made
Impact on the acquirerBrand mix is managed at issuance, not at acceptanceBrand mix is managed through payment page configuration
Two ways to open up the network market: India and the EU regulate different things
⚠️
Don’t carry over the European routing reflex
European techniques for steering the brand at the time of the transaction, such as display priority, preselection, or terminal configuration, have no equivalent in India. The card’s BIN determines which network is used, and the cardholder chose that network at issuance or renewal. The levers available at acceptance are the type of instrument accepted and the channel (card, UPI, prepaid wallet). The brand of the card presented is not one of them.

Zero MDR on RuPay debit and what it destroys

The merchant fee, or MDR (merchant discount rate), is the charge a merchant pays on each card payment it accepts. Since January 1, 2020, under Section 269SU introduced by the 2019 Finance Act, this fee has been set at zero by regulation on RuPay debit cards and BHIM-UPI. The rule bans any charge to the merchant rather than capping it. Interchange disappears along with the fee, leaving RuPay debit issuance with no business model. It survives only because of regulatory mandates and public incentives.

Instrument presentedMerchant costWho gets paid
RuPay debit cardZero, banned by law since January 1, 2020No one: interchange is abolished
Account-to-account UPIZero, same regimeNo one: the cost is borne by banks and the government
Visa or Mastercard debit cardNegotiated MDR, standard regimeIssuer, network, acquirer
Prepaid wallet (PPI) used on UPIInterchange of 1.1% above ₹2,000, zero belowWallet issuer, since April 1, 2023 (NPCI circular)
RuPay credit card linked to UPIInterchange above ₹2,000, zero below, per the NPCI scheduleStandard card chain; the only credit that can be paid by QR scan
Visa or Mastercard credit cardNegotiated MDRStandard card value chain
Where Indian acceptance still carries a fee, and where it no longer does

The distortion is explicit and deliberate: the rules treat two debit cards differently depending on the scheme that carries them. Two cards presented to the same merchant do not cost the same to accept. One is free by law, the other is priced at market rates. No other large market has set its national scheme to zero while leaving international networks free to set their prices. Brazil caps debit interchange regardless of scheme, and the European Economic Area caps it at 0.2% for all issuers. Both caps apply to every scheme, whereas India chose to make acceptance free only for its domestic scheme.

🔑
An ad valorem take rate does not survive India
Pricing set as a percentage of the amount collected loses its base on most Indian volume, since RuPay debit and account-to-account UPI both carry a zero merchant fee. Provider revenue shifts toward terminal or Soundbox subscriptions, reconciliation and refund management services, fraud prevention, and merchant lending based on payment flows. What can still be billed is card acceptance other than RuPay debit, prepaid wallets above ₹2,000, RuPay credit on UPI, and cross-border flows. A margin forecast built on a typical card market therefore overstates Indian revenue, because it applies a rate to volumes that generate no fee.

The sustainability of this regime is publicly debated in India. The Payments Council of India is calling for a 0.3% MDR on UPI to be reinstated for large merchants only, with a turnover threshold of around ₹40 lakh under discussion. In March–April 2026, the Parliamentary Standing Committee on Finance recommended reinstating a fee for large merchants, calling the current model financially unsustainable. The Ministry of Finance has denied having any firm plan. No decision has been made to date.

Mandatory tokenization and the end of PAN storage

Tokenizing a card means replacing its number with a substitute identifier, the token, whose use is restricted to a defined scope. Since October 1, 2022, Indian merchants, payment aggregators, and payment gateways may no longer store the card number, CVV, or expiration date. That data stays with the issuer and the network. The merchant handles only a token, unique to the card-merchant pair. The rule is an enforceable storage ban, separate from PCI DSS, which still applies on top of it.

Creating and using a card token in India
Cardholder
Explicitly consents to tokenizing the card with this merchant
Consent is specific to each merchant; it cannot be inferred from a pre-checked box or from the terms and conditions
Token requestor
Sends the token request to the Token Service Provider
The token requestor is the merchant, the aggregator, or the acquirer; it must be certified by each network involved
Cardholder
Validates with an additional factor of authentication (AFA)
Creating a token requires AFA. Since the December 20, 2023, circular, a single AFA can cover several merchants selected at once
Token Service Provider
Generates the token and returns it to the token requestor
The TSPs are the networks: Visa, Mastercard, American Express, Diners Club, and the NPCI, through the NPCI Tokenisation System for RuPay
Merchant
Stores the token and no other identifying data
It may keep the **last four digits** of the card number and the issuer’s name, solely for tracking and reconciliation
Next payment
The token goes to authorization in place of the PAN
The TSP detokenizes, and the issuer receives the real PAN and makes the decision. The merchant never sees the data in the clear
CompanyCard number (PAN)CVV / expiration dateTokenLast 4 digits + issuer
MerchantProhibitedProhibitedAllowedAllowed (tracking and reconciliation)
Payment aggregator / payment gatewayProhibitedProhibitedAllowedAllowed
AcquirerDepends on its role in the chain, subject to network rulesProhibitedAllowedAllowed
Token Service Provider (network, NPCI)AllowedPer network rulesIssues and manages–
IssuerAllowedAllowedReceives the detokenized PAN–
Who may hold what since October 1, 2022
⚠️
Guest checkout: the only loophole, and a narrow one
Guest checkout allows limited retention of card data, up to T+4, or until the settlement date if earlier. This allowance covers refund and dispute handling and nothing else. Archiving orders along with card data beyond that window breaches the ban, even if the data is encrypted and hosted in India. A compliance review therefore checks that the data is actually deleted on time: encryption is no substitute for purging.
Oct. 1, 2022
date by which merchants and aggregators had to stop storing PANs
RBI, circular of December 23, 2021; deadline extended on June 24, 2022
56 crore
tokens created in the first year, covering more than ₹5 lakh crore in transactions
RBI, Statement on Developmental and Regulatory Policies, October 6, 2023
Oct. 20, 2021
launch of the NPCI Tokenisation System, the tokenization service for RuPay cards
NPCI
Dec. 20, 2023
tokenization opened up through the issuing bank, in addition to the merchant flow
RBI circular, “Card-on-File Tokenisation – Enabling Tokenisation through Card Issuing Banks/Institutions”

The December 20, 2023, circular added a second way to create tokens. Cardholders can now generate them from their bank’s app or online banking portal, selecting several merchants at once with a single pooled AFA. The token then shows up on each selected merchant’s payment page. Some of the tokens linked to a merchant are therefore created outside its own checkout flow. The tokenized-card rate the merchant measures thus reflects two things: the usability of its own checkout funnel and enrollment driven by banks.

ℹ️
What Indian tokenization really costs a foreign merchant
For a foreign merchant, compliance involves three workstreams. The first is certification as a token requestor with each relevant network, including RuPay through the NTS. Each network requires a separate integration. The second is migrating the stored card database. Cards saved before October 2022 had to be retokenized or purged, and merchants that did not migrate saw their payment success rates drop. The third is token lifecycle management, covering card renewals, lost/stolen card blocks, and issuer changes. If token updates are not processed, recurring payments on those cards start failing, and subscriptions lapse without warning.

Recurring mandates: e-NACH, UPI AutoPay, and the 2026 framework

A recurring mandate is a payer’s authorization for a creditor to debit the payer’s account on a recurring schedule. In India, subscriptions, loan installments, insurance premiums, and systematic investment plans run on two families of mandates. NACH, operated by the NPCI, is the bulk clearing rail for recurring direct debits. Its digital version, e-NACH, registers the mandate online through Aadhaar, online banking, or a debit card. UPI AutoPay does the same on the UPI rail, with the mandate linked to the payer’s UPI ID. The choice of rail determines the failure rate, the collection time, and the cost of retries.

e-NACH (NACH rail)UPI AutoPay (UPI rail)
Payer addressingBank account: account number and IFSC codeUPI ID (VPA)
EnrollmentAadhaar, online banking, or debit card; lengthy flowIn the UPI app, in seconds
Time to go liveMandate approved by the payer’s bank, within daysImmediate
ExecutionBatch clearing, deferred net settlementDebit on the instant rail
Typical use casesLarge amounts, EMIs, premiums, SIPs, government benefit payments via APBSConsumer subscriptions, small recurring amounts
Failed debitReturns handled in the NACH cycle; retries must be scheduledImmediate decline; same-day retry possible
Role of the cardThe debit card only authenticates enrollmentNone: the card plays no part
e-NACH or UPI AutoPay: how the two rails differ

The legal framework was rewritten on April 21, 2026, by the Digital Payments – E-mandate Framework, 2026 (circular RBI/CO.DPSS.POLC.No.S56/02.14.003/2026-27). The framework repeals and consolidates the circulars issued since 2019 and applies in the same way to cards, UPI, and prepaid instruments, for both domestic and cross-border recurring transactions. It took effect immediately.

  • The first transaction under a mandate always requires an additional factor of authentication. No exceptions.
  • After that, AFA is not required up to ₹15,000 per transaction. Above that amount, it is required again at the time of debit.
  • Limit raised to ₹1 lakh per transaction for three categories: insurance premiums, mutual fund subscriptions, and credit card bill payments.
  • Pre-debit notification at least 24 hours before each debit, stating the payee’s name, the amount, the scheduled date and time, the mandate reference, and the purpose.
  • Right to opt out of any single transaction and to revoke the mandate, with revocation confirmed by strong authentication.
  • No charge to the customer for the e-mandate service, and a mandatory post-debit notification listing the complaint channels.
  • Dispute resolution mechanism to be set up by the entity that collects the mandate.
🔑
Pre-debit notification moves the failure point one day earlier
A recurring debit breaks down the day before it is due, when the payer reads the mandatory notification and uses the right to opt out. A retry process built only on bank decline codes therefore misses most of India’s losses, because there is no decline to record. A subscription’s success rate then depends on how clear the descriptor is, the payee name displayed, and whether the amount matches what was announced. The 2026 framework has a second effect on mandate design. The ₹15,000 limit and the ₹1 lakh exception now apply to both rails, which removes the regulatory arbitrage that used to exist between cards and UPI.
197 crore
NACH Debit transactions in FY2024-25, up from 99 crore in FY2021-22
NPCI data compiled by FACTLY, 2026
₹21.9 lakh crore
value of NACH Debit collections in FY2024-25, up from ₹9.5 lakh crore in FY2021-22
NPCI data compiled by FACTLY, 2026
₹15 000
limit per recurring transaction without an additional factor of authentication
RBI, Digital Payments – E-mandate Framework, 2026 (April 21, 2026)
24 hours
minimum pre-debit notification period before each recurring debit
RBI, Digital Payments – E-mandate Framework, 2026

Payment data localization

Payment data localization is the requirement to store such data within the country. Circular DPSS.CO.OD No. 2785/06.08.005/2017-2018 of April 6, 2018 requires all payment system operators to store all data related to their systems only in India. The RBI’s stated reason is supervision: it wants unfettered access that does not depend on any foreign jurisdiction. Compliance had to be reported by October 15, 2018. The text is short but sweeping, covering the entire payment chain, from customer details to authentication data.

  • Data in scope: customer details, payment details, transaction data, and authentication information, covering the entire chain, not just the card number.
  • Exclusive storage: the data must reside in India. A mirror copy abroad does not meet the requirement, since it is storage outside India that the rule targets.
  • Cross-border transactions: the foreign leg may be stored abroad, and a copy of the domestic leg may be kept there too.
  • Processing abroad: processing outside India is still allowed, provided the data is brought back and deleted from foreign systems within the set deadline.
  • Proof of compliance: an audit by a CERT-In-empaneled auditor, with a report submitted to the RBI. Compliance is proven with an audit report, not a self-declaration.
⚠️
No contract clause substitutes for a local presence
This regime imposes a data residency requirement, backed by the RBI’s power of direct supervision. It does not work like an adequacy decision, standard contractual clauses, or a regulated transfer mechanism. Serving the Indian market from a shared regional platform in Singapore or Frankfurt is still non-compliant. What counts is where the data is stored, regardless of the outsourcing contract or the level of encryption. Due diligence therefore looks at the physical location of the provider’s databases and backups.

A second, general regime has since been layered on top of this sector-specific requirement. The Digital Personal Data Protection Act, 2023 was brought into force by the Digital Personal Data Protection Rules, 2025. The rules were notified on November 13, 2025, and published in the Gazette of India the next day. The main obligations apply 18 months later, on May 13, 2027. The DPDP takes the opposite approach from the RBI: transfers outside India are allowed by default, except to countries or entities designated by the government. Restrictions remain possible for certain categories of data held by Significant Data Fiduciaries.

ℹ️
Two regimes that do not cancel each other out
The general data protection framework does not relax the sector-specific rule. A payments company remains subject to the 2018 circular for its payment system data, and to the DPDP for any other personal data it processes. The two sets of obligations apply cumulatively, each to its own data. The DPDP’s transfer allowance covers only data within its scope and leaves the 2018 circular’s local storage requirement untouched.

PAs and PGs: who may collect payments in India

Collecting payments on behalf of third parties is a licensed activity. The Guidelines on Regulation of Payment Aggregators and Payment Gateways of March 17, 2020, set the principle. The payment aggregator (PA) handles merchants’ funds and is therefore regulated and authorized by the RBI. The payment gateway (PG), which only routes messages, remains a technology provider subject to security recommendations. On September 15, 2025, a single text consolidated the whole framework: the Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025, which replace the 2020, 2021, and 2023 frameworks.

CategoryScopeWhat to watch
PA-O (online)Remote payment collection for merchantsOriginal 2020 regime; escrow required, PAN storage banned
PA-P (physical)Face-to-face collection, with the instrument and terminal physically presentCategory created by the 2025 Directions; firms previously operating as technology providers now need a license
PA-CB (cross-border)Import, export, or both (PA-CB-I, PA-CB-E, PA-CB-E&I)Prior registration with FIU-IND; limit of ₹25 lakh per unit of goods or services
The three aggregator license categories and what they allow
  • Capital: net worth of ₹15 crore when applying and ₹25 crore within three years of authorization, maintained at all times thereafter.
  • Segregated account: collected funds pass through an escrow account held with a scheduled commercial bank; merchant funds are never commingled with the aggregator’s own funds.
  • PA-P timeline: in-person payment firms had to apply before December 31, 2025; those that did not had to wind down by February 28, 2026.
  • PA-CB timeline: existing players had to reach a net worth of ₹25 crore by March 31, 2026, after registering with FIU-IND.
  • Governance: a fit and proper test for directors and shareholders; any takeover or change in management must be reported to the RBI within 15 days.
  • Merchant due diligence: identity checks on onboarded merchants, monitoring of merchant websites and transaction flows, and a complaint handling process.
⚠️
The first check to run on an Indian provider
Due diligence starts with the exact license category and its date. A firm licensed as a PA-O may not collect cross-border payments, and a PA-CB-E license does not cover imports. A provider that presents itself as a payment gateway has no license to show. That is legitimate, but it means the provider cannot hold merchant funds. The second checkpoint is the escrow bank: an aggregator that relies on a single bank exposes its merchants’ collections to a continuity risk. The RBI’s cancellation of Paytm Payments Bank’s license on April 24, 2026, made that risk real across the market.
The players a merchant actually meets in IndiaRARazorpayPAPayU IndiaCACashfree PaymentsPIPine LabsPaytmPhonePeBIBillDeskJUJuspay

In India, dispute handling depends on the rail the payment used. Cards keep their chargeback mechanism, governed by the rules of the network chosen at issuance. UPI has no chargeback in the card sense. Disputes are escalated to the bank, then to the RBI Ombudsman. That route has no liability shift to the merchant comparable to a card network’s. A merchant accepting on both rails therefore manages two separate dispute regimes, with two sets of deadlines and two counterparts.