Live data from Hacker News

Indian online merchants cannot store credit card information from 2022

rbi.org.in

1–10 of 157 posts

Re: Indian online merchants cannot store credit card information from 2022

#2
Kudos to Indian govt, this should be the default for any e-commerce websites. I have to resort to PayPal to avoid my credit card being stored in the e-commerce merchant sites but some of sites do not support PayPal. It seems that Amazon somehow would not even allow me to delete my old and expired credit card from my account.

Re: Indian online merchants cannot store credit card information from 2022

#3

Kudos to Indian govt, this should be the default for any e-commerce websites. I have to resort to PayPal to avoid my credit card being stored in the e-commerce merchant sites but some of sites do not support PayPal. It seems that Amazon somehow would not even allow me to delete my old and expired credit card from my account.

Indian merchants have to support UPI - another payment mechanism which is secure. I tend to use that in most places so that I dont have to store my card details.

Re: Indian online merchants cannot store credit card information from 2022

#5
post #4

How would recurring transactions or metered billing work? Does this only apply to merchants or providers that are not PCI-DSS compliant and cannot safely store cardholder data?

It won't. Like it should be. No one should be able to take your money without your consent.

Re: Indian online merchants cannot store credit card information from 2022

#7
post #4

How would recurring transactions or metered billing work? Does this only apply to merchants or providers that are not PCI-DSS compliant and cannot safely store cardholder data?

This change just says that only the card issuer or card network can store the card number (PAN). Everyone else in the processing chain can only store card tokens.

This isn’t a surprising change and was always going to be the future of PCI compliance.

Re: Indian online merchants cannot store credit card information from 2022

#8
post #4

How would recurring transactions or metered billing work? Does this only apply to merchants or providers that are not PCI-DSS compliant and cannot safely store cardholder data?

There is no exception for recurring payments. Also unfortunately this applies to all online merchants and Payment aggregators regardless of size and certifications. So as it stands a separate auth is needed for each transaction which is completely regressive and precludes a lot of convenience use cases. My guess is that they are doing this to make Upi more convenient in comparison. But I won't be surprised if its just another short sighted we know it all mentality decision from the regulator who has a history of u-turns.

Edit: Looks like they do allow card tokenization (not part of original proposal) which should address a lot of use cases

Here is the commentary about the original proposal:

https://www.businessinsider.in/finance/banks/news/rbi-wants-...

Here is the one after push back from industry (Which allows tokenization):

https://timesofindia.indiatimes.com/business/india-business/...

Re: Indian online merchants cannot store credit card information from 2022

#9
post #4

How would recurring transactions or metered billing work? Does this only apply to merchants or providers that are not PCI-DSS compliant and cannot safely store cardholder data?

The headline is kinda misleading. They can store credit card information, but they can only do that in tokenized format instead of the current way of storing. Tokenized format hides the number and other information making it more secure. You can read more about it here https://www.thequint.com/explainers/rbi-allows-card-on-file-...

Re: Indian online merchants cannot store credit card information from 2022

#10
post #4

How would recurring transactions or metered billing work? Does this only apply to merchants or providers that are not PCI-DSS compliant and cannot safely store cardholder data?

Any card details that are being stored in the merchant's database need to be tokenised. It applies to all entities who are retrieving card details from customers, irrespective of PCI/DSS compliance.
Post reply on HN