RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The archive · 200 retrospective records ↗

The archive / Pricing & economics

Pricing & economics / From the archive · 1 January 2022 event · prepared 16 September 2026

India's central bank banned merchants from storing card numbers

RBI's own 2021 circular required a shift to tokenised card storage from 1 January 2022, covering card-on-file data only.

rbi.org.inprimary record

Tokenisation - Card transactions

Document
8 January 2019
Event
1 January 2022
Retrieved
16 September 2026
No visual was published with this record, so its primary document stands in its place.

The workload

A SaaS business billing Indian cardholders on a recurring basis had to change how it stored payment credentials once India's central bank acted. RBI's own Tokenisation – Card transactions circular (RBI/2018-19/103, 8 January 2019) first authorized card networks to offer tokenisation services, letting a token stand in for a real card number in a recurring-billing relationship. RBI's later circular permitting Card-on-File Tokenisation (CoFT) services (RBI/2021-22/96, 7 September 2021) turned that option into an obligation: "with effect from January 1, 2022, no entity in the card transaction / payment chain, other than the card issuers and / or card networks, shall store the actual card data." Any business or aggregator holding raw Indian card numbers had to migrate to a token before that date.

What the documents show

Verified: the September 2021 circular states tokenisation and de-tokenisation "can be performed by the authorised card network or by the card issuer" only, and that networks "are also mandated to get the token requestor certified for safety and security that conform to international best practices." Verified, same circular: "the token requestor cannot store Primary Account Number (PAN), i.e., card number, or any other card detail," closing the gap that would let a merchant keep a shadow copy of the card number beside its token. Verified, from RBI's own circular extending the scope of permitted devices (RBI/2021-22/92, 25 August 2021): tokenisation had already widened from mobile phones and tablets to "laptops, desktops, wearables ... and Internet of Things (IoT) devices." This entry could not verify any further RBI circular setting a later enforcement date beyond January 2022; other reporting describes later extensions, but no additional circular naming a specific later date was opened here, so none is stated as verified.

The operating cost

RBI's own circulars state no dollar figure; tokenisation is a compliance requirement, not a priced product with a published rate card. Estimated: for a business using a payment aggregator, the practical cost is aggregator-side integration to switch from raw-PAN storage to token references, plus token-requestor certification that RBI requires the network, not the merchant, to administer — so the direct burden sits mostly upstream, at the aggregator layer.

The stop condition

Verified: the storage prohibition has no stated end date in the circulars reviewed — a standing rule, not a phase-in that lapses. Editorial: for a business already integrated with a compliant Indian aggregator, this obligation is effectively invisible day to day; it resurfaces only if that business builds its own card-storage layer instead of relying on a certified token requestor.

  • Does this business's Indian payment aggregator confirm it is a certified token requestor, rather than storing raw card numbers?
  • Has any legacy raw-PAN data from before January 2022 actually been deleted, as RBI's rule requires?
  • Does this rule reach non-card payment methods used for Indian billing, such as UPI, or only card-on-file data as RBI's circular states?

RBI moved the obligation to hold card numbers off the merchant's desk and onto certified networks and issuers. The rule is narrow — card-on-file data only — but for a business that ever touched a raw Indian card number before January 2022, it set a hard deadline for making sure that number was gone.

Sources & reading trail

Tokenisation - Card transactions ↗

RBI's own original circular (RBI/2018-19/103) authorising card networks to offer tokenisation services.

Source published: 8 January 2019 · Retrieved: 16 September 2026

Tokenisation - Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services ↗

RBI's own circular (RBI/2021-22/96) setting the 1 January 2022 deadline after which only card issuers or networks may store actual card data, and the token-requestor certification and no-PAN-storage requirements.

Source published: 7 September 2021 · Retrieved: 16 September 2026

Tokenisation - Card Transactions: Extending the Scope of Permitted Devices ↗

RBI's own circular (RBI/2021-22/92) extending tokenisation eligibility from mobile phones and tablets to laptops, desktops, wearables, and IoT devices.

Source published: 25 August 2021 · Retrieved: 16 September 2026

Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.