

“Guidelines on Regulation of Payment Aggregators and Payment Gateways”, circular dated September 07, 2021 on “Tokenisation – Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services” and, circulars dated December 23, 2021 and june 24 2022 on “Restriction on Storage of Actual Card Data [i.e. Card-on-File (CoF)]”.
In terms of the above circulars, with effect from October 1, 2022, no entity in the card transaction / payment chain, other than the card issuers and / or card networks, shall store CoF data, and any such data stored previously shall be purged.
The requirements were specified, the following are advised –
a) There shall be no change in the effective date of implementation of the requirements – all entities, except card issuers and card networks, shall purge the CoF data before October 1, 2022.
b) For ease of transition to an alternate system in respect of transactions where cardholders decide to enter the card details manually at the time of undertaking the transaction (commonly referred to as “guest checkout transactions”), the following are being permitted as an interim measure –