RBI extends card tokenization deadline by 6 months - Key points you need to know

ZeeBiz WebTeam | Dec 24, 2021, 12:48 PM IST

In a major development, the card tokenisation deadline by the Reserve Bank of India (RBI) has been extended by 6 months. RBI in a statement said, "The timeline for storing of CoF data is extended by six months, i.e., till June 30, 2022." Earlier, RBI had given a deadline of December 31 for tokenisation.

Now, with the extension in the tokenisation deadline, let us go through the important facts, we need to know about tokenisation.

 

 

1/8

What is tokenisation?

What is tokenisation?

Tokenisation refers to the replacement of actual card details with an alternate code called the “token”, which shall be unique for a combination of card, token requestor (i.e. the entity which accepts the request from the customer for tokenisation of a card and passes it on to the card network to issue a corresponding token) and device (referred hereafter as “identified device”). Source: Reuters

 

2/8

What will this mean?

What will this mean?

Earlier, RBI had given a deadline of December 31 for tokenisation. This meant that from January 1, merchants will not be able to store the card information of users and will have to replace each card number with a randomised token number. However, with the six months' extension coming into place, it means that the merchants will face the same issue from July 1, 2022. Source: Reuters

 

Also read: https://www.zeebiz.com/personal-finance/news-what-is-tokenisation-benefits-charges-is-it-safe-mandatory-for-cardholders-faqs-answered-here-174333

 

3/8

Benefits of tokenisation

Benefits of tokenisation

A tokenised card transaction is considered safer as the actual card details are not shared with the merchant during transaction processing. Source: Reuters

Also read: https://www.zeebiz.com/personal-finance/news-what-is-tokenisation-benefits-charges-is-it-safe-mandatory-for-cardholders-faqs-answered-here-174333

4/8

How can the tokenisation be carried?

How can the tokenisation be carried?

The card holder can get the card tokenised by initiating a request on the app provided by the token requestor. The token requestor will forward the request to the card network which, with the consent of the card issuer, will issue a token corresponding to the combination of the card, the token requestor, and the device. Source: Reuters

 

5/8

Who can perform tokenisation and de-tokenisation?

Who can perform tokenisation and de-tokenisation?

Tokenisation and de-tokenisation can be performed only by the authorised card network. The list of card networks authorised by RBI to operate in India is available on the RBI website at the link https://www.rbi.org.in/Scripts/PublicationsView.aspx?id=12043. Source: Reuters

 

6/8

Safety after tokenisation?

Safety after tokenisation?

Actual card data, token and other relevant details are stored in a secure mode by the authorised card networks. Token requestor cannot store Primary Account Number (PAN), i.e., card number, or any other card detail. Card networks are also mandated to get the token requestor certified for safety and security that conform to international best practices / globally accepted standards. Source: Reuters

 

7/8

Is it mandatory?

Is it mandatory?

No, a customer can choose whether or not to let his / her card tokenised. Source: Reuters

 

8/8

How the process works?

How the process works?

The registration for a tokenisation request is done only with explicit customer consent through Additional Factor of Authentication (AFA), and not by way of a forced / default / automatic selection of check box, radio button, etc. Customers will also be given the choice of selecting the use case and setting-up of limits. Source: Reuters

 

By accepting cookies, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.

x