One card base, two opposite trajectories
India’s card base comprises the debit and credit cards in circulation, two categories whose paths have diverged since 2021. India had about 103.43 crore debit cards and 11.58 crore credit cards in circulation in December 2025, according to the Reserve Bank of India’s Payment Systems Report. The base is overwhelmingly debit, yet transaction volumes are moving the other way. Between 2021 and 2025, debit card transactions fell from 408.7 crore to 133.6 crore, an average decline of 24.4% a year. Over the same period, credit card transactions rose from 2.16 billion to 5.7 billion (RBI, Payment Systems Report, December 2025). The number of cards issued and the number of payments made therefore measure two different things. Sizing an Indian market by its card base means counting cards their holders no longer use to pay.
| Debit card | Credit card | |
|---|---|---|
| Volume | 408 crore → 133 crore transactions | 2.16B → 5.7B transactions |
| Value | ₹7.4 lakh crore → ₹4.5 lakh crore | ₹8.9 lakh crore → ₹23.2 lakh crore |
| Annual trend | −24.4% a year by volume | About +27% a year by value |
| Driver | Fully replaced by UPI, free for cardholders and merchants | Credit has no UPI equivalent, except through RuPay |
| Remaining uses | ATM withdrawals, account access, mandate enrollment | Online payments, large tickets, installment plans (EMI) |
Two interoperable QR codes coexist in India. UPI QR carries account-to-account payments, while Bharat QR, which runs on card rails, carries scan-to-pay card payments. In October 2020, the RBI barred payment system operators from launching any new proprietary QR code and confirmed that only these two standards would continue. Merchants accepting QR payments therefore have two options: a free account-to-account (A2A) rail and a fee-bearing card rail.
RuPay: a domestic scheme gaining share through credit
RuPay is India’s domestic card scheme, launched in 2012 by the National Payments Corporation of India (NPCI), a not-for-profit entity owned by banks and supervised by the RBI. According to the NPCI, more than 760 million RuPay cards had been issued across all products as of 2024. That base is mainly a legacy of financial inclusion policies. Accounts opened under the Pradhan Mantri Jan Dhan Yojana program came with a RuPay debit card by default. Like the rest of the debit base described above, these cards now generate almost no payments.
RuPay’s growth now comes from credit, and from a feature reserved for the domestic scheme. RuPay Credit Card on UPI links a RuPay credit card to a UPI ID. The cardholder scans the merchant’s QR code, authenticates with a UPI PIN, and the payment is charged to the credit line. The merchant thus accepts credit without a terminal, on a rail where Visa and Mastercard have no equivalent. The NPCI said in 2025 that 16% of card spending went through RuPay, nearly half of it credit on UPI. The Indian press put RuPay’s share of the credit card market at around 18% in October 2025, though that figure is unofficial.
- National Common Mobility Card (NCMC), since 2019: an open-loop transit card, interoperable across city transit networks, built on RuPay, with an offline wallet stored on the chip.
- National Electronic Toll Collection (NETC) / FASTag, since 2016: interoperable RFID tolling run by the NPCI, mandatory on national highways and funded through prepaid instruments.
- National Financial Switch (NFS), transferred from IDRBT to the NPCI in 2009: the interbank switch for India’s ATM network. It is invisible in market analyses, yet it alone guarantees that withdrawals work across banks.
- Bharat Connect (formerly the Bharat Bill Payment System, 2017), operated by NPCI Bharat BillPay Ltd: an interoperable bill payment rail where a biller connects once and becomes payable from any app.
Network choice: India’s version of opening up the market
Network choice is the cardholder’s right to pick the card network that will carry the card, when it is issued and again when it is renewed. Indian issuers traditionally signed exclusivity agreements with one network, portfolio by portfolio. The RBI ended that practice with a circular dated March 6, 2024, in force since September 6, 2024, after a draft released for consultation on July 5, 2023. The circular bans clauses that stop an issuer from using other networks and requires issuers to offer customers a choice of network at issuance and again at renewal. Issuers with 10 lakh (1 million) active credit cards or fewer are exempt.
The RBI lists five card networks authorized to operate in India: American Express Banking Corp., Diners Club International Ltd, Mastercard Asia/Pacific Pte Ltd, National Payments Corporation of India – RuPay, and Visa Worldwide Pte Ltd. An issuer above the threshold must offer its customers at least two of them. The customer chooses a network once, since the card then carries only one payment application.
| India — RBI circular of March 6, 2024 | European Union — Article 8 of Regulation (EU) 2015/751 | |
|---|---|---|
| What is regulated | The contract between issuer and network | The card: it carries two payment applications |
| What is prohibited | Exclusive issuer–network agreements | Preventing co-badging and locking the choice at the point of sale |
| What the cardholder chooses | One network, at issuance and again at renewal | The application used, transaction by transaction |
| Scope | Issuers with more than 10 lakh active credit cards | All schemes and issuers in the European Economic Area |
| Effect on routing | No dynamic routing: the network is fixed at issuance | Routing possible in store and online, based on the choice made |
| Impact on the acquirer | Brand mix is managed at issuance, not at acceptance | Brand mix is managed through payment page configuration |
Zero MDR on RuPay debit and what it destroys
The merchant fee, or MDR (merchant discount rate), is the charge a merchant pays on each card payment it accepts. Since January 1, 2020, under Section 269SU introduced by the 2019 Finance Act, this fee has been set at zero by regulation on RuPay debit cards and BHIM-UPI. The rule bans any charge to the merchant rather than capping it. Interchange disappears along with the fee, leaving RuPay debit issuance with no business model. It survives only because of regulatory mandates and public incentives.
| Instrument presented | Merchant cost | Who gets paid |
|---|---|---|
| RuPay debit card | Zero, banned by law since January 1, 2020 | No one: interchange is abolished |
| Account-to-account UPI | Zero, same regime | No one: the cost is borne by banks and the government |
| Visa or Mastercard debit card | Negotiated MDR, standard regime | Issuer, network, acquirer |
| Prepaid wallet (PPI) used on UPI | Interchange of 1.1% above ₹2,000, zero below | Wallet issuer, since April 1, 2023 (NPCI circular) |
| RuPay credit card linked to UPI | Interchange above ₹2,000, zero below, per the NPCI schedule | Standard card chain; the only credit that can be paid by QR scan |
| Visa or Mastercard credit card | Negotiated MDR | Standard card value chain |
The distortion is explicit and deliberate: the rules treat two debit cards differently depending on the scheme that carries them. Two cards presented to the same merchant do not cost the same to accept. One is free by law, the other is priced at market rates. No other large market has set its national scheme to zero while leaving international networks free to set their prices. Brazil caps debit interchange regardless of scheme, and the European Economic Area caps it at 0.2% for all issuers. Both caps apply to every scheme, whereas India chose to make acceptance free only for its domestic scheme.
The sustainability of this regime is publicly debated in India. The Payments Council of India is calling for a 0.3% MDR on UPI to be reinstated for large merchants only, with a turnover threshold of around ₹40 lakh under discussion. In March–April 2026, the Parliamentary Standing Committee on Finance recommended reinstating a fee for large merchants, calling the current model financially unsustainable. The Ministry of Finance has denied having any firm plan. No decision has been made to date.
Mandatory tokenization and the end of PAN storage
Tokenizing a card means replacing its number with a substitute identifier, the token, whose use is restricted to a defined scope. Since October 1, 2022, Indian merchants, payment aggregators, and payment gateways may no longer store the card number, CVV, or expiration date. That data stays with the issuer and the network. The merchant handles only a token, unique to the card-merchant pair. The rule is an enforceable storage ban, separate from PCI DSS, which still applies on top of it.
| Company | Card number (PAN) | CVV / expiration date | Token | Last 4 digits + issuer |
|---|---|---|---|---|
| Merchant | Prohibited | Prohibited | Allowed | Allowed (tracking and reconciliation) |
| Payment aggregator / payment gateway | Prohibited | Prohibited | Allowed | Allowed |
| Acquirer | Depends on its role in the chain, subject to network rules | Prohibited | Allowed | Allowed |
| Token Service Provider (network, NPCI) | Allowed | Per network rules | Issues and manages | – |
| Issuer | Allowed | Allowed | Receives the detokenized PAN | – |
The December 20, 2023, circular added a second way to create tokens. Cardholders can now generate them from their bank’s app or online banking portal, selecting several merchants at once with a single pooled AFA. The token then shows up on each selected merchant’s payment page. Some of the tokens linked to a merchant are therefore created outside its own checkout flow. The tokenized-card rate the merchant measures thus reflects two things: the usability of its own checkout funnel and enrollment driven by banks.
Recurring mandates: e-NACH, UPI AutoPay, and the 2026 framework
A recurring mandate is a payer’s authorization for a creditor to debit the payer’s account on a recurring schedule. In India, subscriptions, loan installments, insurance premiums, and systematic investment plans run on two families of mandates. NACH, operated by the NPCI, is the bulk clearing rail for recurring direct debits. Its digital version, e-NACH, registers the mandate online through Aadhaar, online banking, or a debit card. UPI AutoPay does the same on the UPI rail, with the mandate linked to the payer’s UPI ID. The choice of rail determines the failure rate, the collection time, and the cost of retries.
| e-NACH (NACH rail) | UPI AutoPay (UPI rail) | |
|---|---|---|
| Payer addressing | Bank account: account number and IFSC code | UPI ID (VPA) |
| Enrollment | Aadhaar, online banking, or debit card; lengthy flow | In the UPI app, in seconds |
| Time to go live | Mandate approved by the payer’s bank, within days | Immediate |
| Execution | Batch clearing, deferred net settlement | Debit on the instant rail |
| Typical use cases | Large amounts, EMIs, premiums, SIPs, government benefit payments via APBS | Consumer subscriptions, small recurring amounts |
| Failed debit | Returns handled in the NACH cycle; retries must be scheduled | Immediate decline; same-day retry possible |
| Role of the card | The debit card only authenticates enrollment | None: the card plays no part |
The legal framework was rewritten on April 21, 2026, by the Digital Payments – E-mandate Framework, 2026 (circular RBI/CO.DPSS.POLC.No.S56/02.14.003/2026-27). The framework repeals and consolidates the circulars issued since 2019 and applies in the same way to cards, UPI, and prepaid instruments, for both domestic and cross-border recurring transactions. It took effect immediately.
- The first transaction under a mandate always requires an additional factor of authentication. No exceptions.
- After that, AFA is not required up to ₹15,000 per transaction. Above that amount, it is required again at the time of debit.
- Limit raised to ₹1 lakh per transaction for three categories: insurance premiums, mutual fund subscriptions, and credit card bill payments.
- Pre-debit notification at least 24 hours before each debit, stating the payee’s name, the amount, the scheduled date and time, the mandate reference, and the purpose.
- Right to opt out of any single transaction and to revoke the mandate, with revocation confirmed by strong authentication.
- No charge to the customer for the e-mandate service, and a mandatory post-debit notification listing the complaint channels.
- Dispute resolution mechanism to be set up by the entity that collects the mandate.
Payment data localization
Payment data localization is the requirement to store such data within the country. Circular DPSS.CO.OD No. 2785/06.08.005/2017-2018 of April 6, 2018 requires all payment system operators to store all data related to their systems only in India. The RBI’s stated reason is supervision: it wants unfettered access that does not depend on any foreign jurisdiction. Compliance had to be reported by October 15, 2018. The text is short but sweeping, covering the entire payment chain, from customer details to authentication data.
- Data in scope: customer details, payment details, transaction data, and authentication information, covering the entire chain, not just the card number.
- Exclusive storage: the data must reside in India. A mirror copy abroad does not meet the requirement, since it is storage outside India that the rule targets.
- Cross-border transactions: the foreign leg may be stored abroad, and a copy of the domestic leg may be kept there too.
- Processing abroad: processing outside India is still allowed, provided the data is brought back and deleted from foreign systems within the set deadline.
- Proof of compliance: an audit by a CERT-In-empaneled auditor, with a report submitted to the RBI. Compliance is proven with an audit report, not a self-declaration.
A second, general regime has since been layered on top of this sector-specific requirement. The Digital Personal Data Protection Act, 2023 was brought into force by the Digital Personal Data Protection Rules, 2025. The rules were notified on November 13, 2025, and published in the Gazette of India the next day. The main obligations apply 18 months later, on May 13, 2027. The DPDP takes the opposite approach from the RBI: transfers outside India are allowed by default, except to countries or entities designated by the government. Restrictions remain possible for certain categories of data held by Significant Data Fiduciaries.
PAs and PGs: who may collect payments in India
Collecting payments on behalf of third parties is a licensed activity. The Guidelines on Regulation of Payment Aggregators and Payment Gateways of March 17, 2020, set the principle. The payment aggregator (PA) handles merchants’ funds and is therefore regulated and authorized by the RBI. The payment gateway (PG), which only routes messages, remains a technology provider subject to security recommendations. On September 15, 2025, a single text consolidated the whole framework: the Reserve Bank of India (Regulation of Payment Aggregators) Directions, 2025, which replace the 2020, 2021, and 2023 frameworks.
| Category | Scope | What to watch |
|---|---|---|
| PA-O (online) | Remote payment collection for merchants | Original 2020 regime; escrow required, PAN storage banned |
| PA-P (physical) | Face-to-face collection, with the instrument and terminal physically present | Category created by the 2025 Directions; firms previously operating as technology providers now need a license |
| PA-CB (cross-border) | Import, export, or both (PA-CB-I, PA-CB-E, PA-CB-E&I) | Prior registration with FIU-IND; limit of ₹25 lakh per unit of goods or services |
- Capital: net worth of ₹15 crore when applying and ₹25 crore within three years of authorization, maintained at all times thereafter.
- Segregated account: collected funds pass through an escrow account held with a scheduled commercial bank; merchant funds are never commingled with the aggregator’s own funds.
- PA-P timeline: in-person payment firms had to apply before December 31, 2025; those that did not had to wind down by February 28, 2026.
- PA-CB timeline: existing players had to reach a net worth of ₹25 crore by March 31, 2026, after registering with FIU-IND.
- Governance: a fit and proper test for directors and shareholders; any takeover or change in management must be reported to the RBI within 15 days.
- Merchant due diligence: identity checks on onboarded merchants, monitoring of merchant websites and transaction flows, and a complaint handling process.
In India, dispute handling depends on the rail the payment used. Cards keep their chargeback mechanism, governed by the rules of the network chosen at issuance. UPI has no chargeback in the card sense. Disputes are escalated to the bank, then to the RBI Ombudsman. That route has no liability shift to the merchant comparable to a card network’s. A merchant accepting on both rails therefore manages two separate dispute regimes, with two sets of deadlines and two counterparts.