NPCI asks UPI apps to mask phone numbers and account details by September 4

NPCI has directed banks and UPI apps to limit the display of customer phone numbers, UPI IDs and bank-account details under DPDP-aligned privacy rules. Apps may retain visibility of only the final four mobile digits and offer UPI IDs not tied to phone numbers.

— Source publishedWed, 29 Jul, 2026, 11:17 IST·First seen Wed, 29 Jul, 2026, 11:47 IST·Source Business Today · Latest

What happened

National Payments Corporation of India (NPCI) · NPCI has directed banks and UPI apps to mask customers’ phone numbers, UPI IDs and bank-account details to align

Key facts

  • September 4 implementation deadline
  • Last four digits of mobile number may remain visible

Why this matters

Payments companies should assess partnerships or acquisitions in privacy engineering, tokenized identity and fraud prevention to meet DPDP-aligned requirements while preserving onboarding and payment-conversion performance.

What to watch

  • NPCI clarification on whether masking applies uniformly to payer names, UPI IDs, transaction histories, collect requests and merchant-side dashboards.
  • App-specific implementation choices by PhonePe, Google Pay, Paytm and bank apps, especially treatment of existing phone-number-linked UPI IDs.
  • Increase in mistaken-transfer, refund, chargeback or payment-not-received complaints after rollout.
  • Adoption of verified merchant badges, business aliases and dynamic QR products by payment apps and aggregators.
  • Regulatory enforcement actions or deadline extensions for banks, PSPs or third-party payment providers.
  • Evidence that small merchants experience lower repeat-payment conversion because customers can no longer recognize phone-linked handles.
  • Replace phone-number-based UPI IDs and static QR workflows with branded, non-personal merchant handles where possible.
  • Audit checkout, refund, customer-service and reconciliation processes that rely on visible customer mobile numbers or bank-account details.
  • Add prominent merchant-name, verified-handle and transaction-reference confirmation screens to reduce misdirected-payment risk.
  • Prepare customer-service scripts and self-service flows for payment-status verification without requesting unnecessary personal data.
  • Review fraud controls for impersonation, lookalike UPI IDs, refund diversion and fake payment-confirmation claims.
  • Coordinate with payment aggregators and banks on compliance status, API changes, dispute evidence and rollout timing before September 4.