Tokenisation - Card transactions
- Document
- 8 January 2019
- Event
- 1 January 2022
- Retrieved
- 16 September 2026
The workload
A SaaS business billing Indian cardholders on a recurring basis had to change how it stored payment credentials once India's central bank acted. RBI's own Tokenisation – Card transactions circular (RBI/2018-19/103, 8 January 2019) first authorized card networks to offer tokenisation services, letting a token stand in for a real card number in a recurring-billing relationship. RBI's later circular permitting Card-on-File Tokenisation (CoFT) services (RBI/2021-22/96, 7 September 2021) turned that option into an obligation: "with effect from January 1, 2022, no entity in the card transaction / payment chain, other than the card issuers and / or card networks, shall store the actual card data." Any business or aggregator holding raw Indian card numbers had to migrate to a token before that date.
What the documents show
Verified: the September 2021 circular states tokenisation and de-tokenisation "can be performed by the authorised card network or by the card issuer" only, and that networks "are also mandated to get the token requestor certified for safety and security that conform to international best practices." Verified, same circular: "the token requestor cannot store Primary Account Number (PAN), i.e., card number, or any other card detail," closing the gap that would let a merchant keep a shadow copy of the card number beside its token. Verified, from RBI's own circular extending the scope of permitted devices (RBI/2021-22/92, 25 August 2021): tokenisation had already widened from mobile phones and tablets to "laptops, desktops, wearables ... and Internet of Things (IoT) devices." This entry could not verify any further RBI circular setting a later enforcement date beyond January 2022; other reporting describes later extensions, but no additional circular naming a specific later date was opened here, so none is stated as verified.
The operating cost
RBI's own circulars state no dollar figure; tokenisation is a compliance requirement, not a priced product with a published rate card. Estimated: for a business using a payment aggregator, the practical cost is aggregator-side integration to switch from raw-PAN storage to token references, plus token-requestor certification that RBI requires the network, not the merchant, to administer — so the direct burden sits mostly upstream, at the aggregator layer.
The stop condition
Verified: the storage prohibition has no stated end date in the circulars reviewed — a standing rule, not a phase-in that lapses. Editorial: for a business already integrated with a compliant Indian aggregator, this obligation is effectively invisible day to day; it resurfaces only if that business builds its own card-storage layer instead of relying on a certified token requestor.
- Does this business's Indian payment aggregator confirm it is a certified token requestor, rather than storing raw card numbers?
- Has any legacy raw-PAN data from before January 2022 actually been deleted, as RBI's rule requires?
- Does this rule reach non-card payment methods used for Indian billing, such as UPI, or only card-on-file data as RBI's circular states?
RBI moved the obligation to hold card numbers off the merchant's desk and onto certified networks and issuers. The rule is narrow — card-on-file data only — but for a business that ever touched a raw Indian card number before January 2022, it set a hard deadline for making sure that number was gone.
Sources & reading trail
RBI's own original circular (RBI/2018-19/103) authorising card networks to offer tokenisation services.
Source published: 8 January 2019 · Retrieved: 16 September 2026
RBI's own circular (RBI/2021-22/96) setting the 1 January 2022 deadline after which only card issuers or networks may store actual card data, and the token-requestor certification and no-PAN-storage requirements.
Source published: 7 September 2021 · Retrieved: 16 September 2026
RBI's own circular (RBI/2021-22/92) extending tokenisation eligibility from mobile phones and tablets to laptops, desktops, wearables, and IoT devices.
Source published: 25 August 2021 · Retrieved: 16 September 2026
Vendor documentation, regulator records and founder-published documents establish the entry; the workload reading and the stop condition are Solo Product Office editorial analysis. This retrospective draft does not imply the site published on the event date.