{"id":4748,"date":"2021-12-23T21:03:00","date_gmt":"2021-12-23T15:33:00","guid":{"rendered":"https:\/\/yourcareerheights.com\/?p=4748"},"modified":"2021-12-24T23:35:52","modified_gmt":"2021-12-24T18:05:52","slug":"rbi-extends-card-tokenisation-deadline-by-six-months-to-june-30-2022-all-you-want-to-know-about-card-tokenisation","status":"publish","type":"post","link":"https:\/\/yourcareerheights.com\/?p=4748","title":{"rendered":"RBI extends card tokenisation deadline by six months to June 30, 2022 &#8211; All you want to know about Card Tokenisation"},"content":{"rendered":"<div id=\"pl-4748\"  class=\"panel-layout\" ><div id=\"pg-4748-0\"  class=\"panel-grid panel-no-style\" ><div id=\"pgc-4748-0-0\"  class=\"panel-grid-cell\" ><div id=\"panel-4748-0-0-0\" class=\"so-panel widget widget_sow-editor panel-first-child panel-last-child\" data-index=\"0\" ><div class=\"panel-widget-style panel-widget-style-for-4748-0-0-0\" ><div\n\t\t\t\n\t\t\tclass=\"so-widget-sow-editor so-widget-sow-editor-base\"\n\t\t\t\n\t\t>\n<div class=\"siteorigin-widget-tinymce textwidget\">\n\t<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft\" src=\"https:\/\/i0.wp.com\/images.livemint.com\/img\/2021\/11\/02\/original\/c1_1635873673173.png?resize=511%2C243&#038;ssl=1\" alt=\"\" width=\"511\" height=\"243\" \/><\/p>\n<div class=\"hidden-xs\">\n<h3 class=\"intro\">The RBI in March last year came up with new rules to enhance the security of online transactions made using debit and credit cards.<\/h3>\n<\/div>\n<h3>Online merchants and financial payments companies have been representing to RBI to extend the deadline saying that they lack the infrastructure necessary to comply with the RBI\u2019s Order by December 31, 2021. In light of various representations, Reserve Bank of India on Thursday 23rd December 2021, extended <em>earlier deadline of <\/em><em>December 31, 2021<\/em> for\u00a0card tokenisation\u00a0by six months to June 30, 2022.<\/h3>\n<h3>Post June 30, 2022, merchants will not be able to store card information of users and will have to replace each card number with a randomised token number.<\/h3>\n<p><em><strong>In light of various representations received from Industry Stakeholders in this regard, RBI has advised under Section 10 (2) read with Section 18 of Payment and Settlement Systems Act, 2007 (Act 51 of 2007) as under :<\/strong><\/em><\/p>\n<ol type=\"a\">\n<li><em><strong>the timeline for storing of CoF data is extended by six months, i.e., till June 30, 2022; post this, such data shall be purged; and<\/strong><\/em><\/li>\n<li><em><strong>in addition to tokenisation, industry stakeholders may devise alternate mechanism(s) to handle any use case (including recurring e-mandates, EMI option, etc.) or post-transaction activity (including chargeback handling, dispute resolution, reward \/ loyalty programme, etc.) that currently involves \/ requires storage of CoF data by entities other than card issuers and card networks.<\/strong><\/em><\/li>\n<\/ol>\n<pre>(RBI\/2021-2022\/142 - CO.DPSS.POLC.No.S-1211\/02-14-003\/2021-22 dt.\u00a0December 23, 2021)<\/pre>\n<h4 class=\"headline\" style=\"text-align: center;\"><strong>What tokenisation means and how it will affect card users?<\/strong><\/h4>\n<p><strong>What is tokenisation?<\/strong><\/p>\n<p>In the case of digital transactions, <em><strong>\u201cTokenisation refers to replacement of actual card details with an alternative code called the \u2018Token\u2019, which uniquely combines card, device, token requestor etc.\u201d\u00a0 Credit card tokens are created to protect sensitive data of customers by substituting it with a series of algorithmically generated numbers and letters.<\/strong><\/em><\/p>\n<p><em><strong>Merchants, payment gateways cannot have this data, only an issuer and a network provider are allowed now<\/strong><\/em>.<\/p>\n<p><strong>CoFT<\/strong> ( <em><strong>Card-on-File Tokenisation<\/strong><\/em>) replaces card details with a \u2018token\u2019, which will be unique for every debit or credit card and merchant platform where the card is used.<\/p>\n<p>In a bid to increase customer safety and prevent fraud,\u00a0<a href=\"https:\/\/www.moneycontrol.com\/news\/business\/why-companies-are-lining-up-for-rbis-pa-license-what-the-card-data-hiccup-is-explained-7372341.html\" target=\"_blank\" rel=\"noopener\">RBI guidelines for payment aggregators (PA) and payment gateways (PG)<\/a> state that PAs and merchants shall not store card credentials of customers in their database starting January 1, 2022. This date is extended to 30th June 2022. RBI\u00a0wanted to put an end to the practice of online merchants storing the card details of customers, which the Central bank believed could lead to misuse of cards by fraudsters.<\/p>\n<p>In the absence of an alternative such as CoF Tokenisation, customers who wish to use their credit or debit cards will have to enter their details afresh for each transaction, including their 16-digit card number, card expiry date and card verification value (CVV).<\/p>\n<p><strong>How will merchant sites work without card data?<\/strong><br \/>\n<a href=\"https:\/\/i0.wp.com\/yourcareerheights.com\/wp-content\/uploads\/2021\/12\/card-tokenisation1.jpg?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-4749 alignleft\" src=\"https:\/\/i0.wp.com\/yourcareerheights.com\/wp-content\/uploads\/2021\/12\/card-tokenisation1.jpg?resize=300%2C151&#038;ssl=1\" alt=\"\" width=\"300\" height=\"151\" data-wp-pid=\"4749\" srcset=\"https:\/\/i0.wp.com\/yourcareerheights.com\/wp-content\/uploads\/2021\/12\/card-tokenisation1.jpg?resize=300%2C151&amp;ssl=1 300w, https:\/\/i0.wp.com\/yourcareerheights.com\/wp-content\/uploads\/2021\/12\/card-tokenisation1.jpg?resize=1024%2C517&amp;ssl=1 1024w, https:\/\/i0.wp.com\/yourcareerheights.com\/wp-content\/uploads\/2021\/12\/card-tokenisation1.jpg?resize=768%2C388&amp;ssl=1 768w, https:\/\/i0.wp.com\/yourcareerheights.com\/wp-content\/uploads\/2021\/12\/card-tokenisation1.jpg?resize=1536%2C776&amp;ssl=1 1536w, https:\/\/i0.wp.com\/yourcareerheights.com\/wp-content\/uploads\/2021\/12\/card-tokenisation1.jpg?resize=1200%2C606&amp;ssl=1 1200w, https:\/\/i0.wp.com\/yourcareerheights.com\/wp-content\/uploads\/2021\/12\/card-tokenisation1.jpg?w=1810&amp;ssl=1 1810w, https:\/\/i0.wp.com\/yourcareerheights.com\/wp-content\/uploads\/2021\/12\/card-tokenisation1.jpg?w=1400&amp;ssl=1 1400w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>Generally, this is how it works: When the bank and card network receive a debit request from a payment gateway, they approve based on the customer\u2019s input on the merchant site. Mandar Agashe, founder, vice-chairman, and managing director, Sarvatra Technologies. explained that it is not the card on file (CoF), or saved card details, that is used to complete a transaction, a token is used instead. At the back-end, the token will be replaced with card data, for the transaction to go through. \u201cYou can\u2019t just use the token anywhere. It is specific for that consumer, that merchant, and that card,\u201d said Agashe.<\/p>\n<p><strong>How does this enhance the security of online transactions?<\/strong><br \/>\nInformation like credit card number, address, account number, can be easily misused if it falls into the wrong hands. However, with tokenisation, merchants can move data between networks without actually exposing such information.<\/p>\n<p>CoFT refers to the replacement of actual card details with a code called a \u2018token\u2019, <em><strong>which will be unique for every debit or credit card and merchant platform where the card is being used<\/strong><\/em>.<\/p>\n<p><strong>For what kind of transactions will tokenisation apply?<\/strong><br \/>\n\u201cTokenisation will be available for all \u2018Card Not Present\u2019 transactions, or online transactions,\u201d said Ravi Buttula, head of merchant acquiring solutions at Wibmo. According to the RBI\u2019s norms, <em>tokenisation has to be done based on customer consent, to be validated through an additional factor authentication. The same bank and card network can do the tokenisation, or even de-tokenise the details based on customer request.<\/em><\/p>\n<p><strong>How will customers be impacted?<\/strong><br \/>\nAt present, while shopping online your card data is stored on the merchant website, and the next time you simply choose the card, enter the CVV number and authenticate the transaction with a one-time password. According to a previous\u00a0RBI\u00a0guideline, the merchant website will not be allowed to store the card data from January 1. <em><strong>Which means you would have had to type out the details for every transaction.<\/strong><\/em><\/p>\n<p><strong>What is the problem with the RBI\u2019s Order?<\/strong><\/p>\n<p>Critics of the RBI\u2019s Order believe that online card transactions are already secure enough since customers need to authenticate transactions through CVV, OTP and other means. Online merchants have also been complaining about the time given by the RBI to comply with its orders, which they believe is too little. This, they argue, will affect their business as customers whose card details are purged may refuse to go through the hassle of having to enter their card details each time they make a purchase. Any failed payments will result in a revenue loss for players across the ecosystem as well as customers.<\/p>\n<p>Customers may also decide not to tokenise their cards and simply opt to switch to cash or other forms of online payment that involve less hassle. The RBI may thus inadvertently push customers away from using cards as a mode of payment. It should be noted that foreign card companies such as Visa and Mastercard have already complained that Indian authorities have been favouring domestic payment methods such as the UPI and RuPay through their policies.<\/p>\n<p><strong>Work that is yet to be done<\/strong><\/p>\n<p>Beyond PGs (Payment Gateways) and card networks creating tokens, work needs to be completed on two more fronts. One is integrating multiple internal systems for various kinds of payments, including EMIs and recurring payments, to tokenisation. The other is customer education.<\/p>\n<p>All card networks as well as major payment service providers such as\u00a0<a href=\"https:\/\/www.moneycontrol.com\/news\/business\/razorpay-launches-tokenhq-card-in-partnership-with-mastercard-rupay-and-visa-7617051.html\" target=\"_blank\" rel=\"noopener\">Razorpay<\/a>,\u00a0<a href=\"https:\/\/www.moneycontrol.com\/news\/business\/payu-launches-tokenisation-solution-payu-token-hub-with-visa-mastercard-7641721.html\" target=\"_blank\" rel=\"noopener\">PayU<\/a>,\u00a0<a href=\"https:\/\/www.moneycontrol.com\/news\/business\/phonepe-becomes-first-to-tokenise-cards-on-visa-mastercard-and-rupay-7831751.html\" target=\"_blank\" rel=\"noopener\">PhonePe<\/a> and Juspay are ready with their tokenisation products.\u00a0While major merchants are already prompting customers to tokenise their cards, many smaller merchants and PGs, too, are yet to be fully integrated into the system.<\/p>\n<p><strong>What to expect<\/strong><\/p>\n<p>With gaps yet to be filled, the industry expects initial disruptions, and a short-term revenue loss as customers may switch to cash payments while they come to terms with the sea change in a process that has been around for years.<\/p>\n<p><em>Companies are largely expected to comply with RBI\u2019s Order by next year\u2019s deadline<\/em>.<\/p>\n<p>Please click to read :\u00a0<a href=\"https:\/\/www.rbi.org.in\/Scripts\/NotificationUser.aspx?Id=12211&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">Restriction on storage of actual card data [i.e. Card-on-File (CoF)]\u00a0<\/a><br \/>\n<a href=\"https:\/\/www.rbi.org.in\/Scripts\/NotificationUser.aspx?Id=12159&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">Tokenisation \u2013 Card Transactions: Permitting Card-on-File Tokenisation (CoFT) Services<\/a><br \/>\n<a href=\"https:\/\/www.rbi.org.in\/Scripts\/NotificationUser.aspx?Id=12152&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">Tokenisation \u2013 Card Transactions : Extending the Scope of Permitted Devices <\/a>;<br \/>\n<a href=\"https:\/\/www.rbi.org.in\/Scripts\/NotificationUser.aspx?Id=11449&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">Tokenisation \u2013 Card transactions<\/a> &amp;<br \/>\n<a href=\"https:\/\/www.rbi.org.in\/Scripts\/NotificationUser.aspx?Id=11822&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">Guidelines on Regulation of Payment Aggregators and Payment Gateways (Updated as on November 17, 2020)<\/a><\/p>\n<p>Source: rbi.org.in. Livemint, Business Standard, Money Control &amp; Business Line.<\/p>\n<\/div>\n<\/div><\/div><\/div><\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Reserve Bank of India on Thurday extended card tokenisation deadline by six months to June 30, 2022. The earlier deadline was December 31, 2021. Post June 30, 2022, merchants will not be able to store card information of users and will have to replace each card number with a randomised token number.  <\/p>\n","protected":false},"author":1,"featured_media":4750,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1004,1003,38,1044,220,221,71,45],"tags":[1045,40],"class_list":["post-4748","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-account-aggregator","category-account-aggregator-system","category-banking","category-card-tokenisation","category-cashless-economy","category-digital-banking","category-payment-systems","category-rbi","tag-card-tokenisation","tag-rbi"],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/yourcareerheights.com\/wp-content\/uploads\/2021\/12\/Card-tokenization.png?fit=2236%2C884&ssl=1","jetpack_sharing_enabled":true,"jetpack-related-posts":[],"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=\/wp\/v2\/posts\/4748","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4748"}],"version-history":[{"count":5,"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=\/wp\/v2\/posts\/4748\/revisions"}],"predecessor-version":[{"id":4755,"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=\/wp\/v2\/posts\/4748\/revisions\/4755"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=\/wp\/v2\/media\/4750"}],"wp:attachment":[{"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4748"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/yourcareerheights.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}