NPCI asks UPI apps to mask phone numbers and account details by September 4
NPCI has directed banks and UPI apps to limit the display of customer phone numbers, UPI IDs and bank-account details under DPDP-aligned privacy rules. Apps may retain visibility of only the final four mobile digits and offer UPI IDs not tied to phone numbers.
What happened
National Payments Corporation of India (NPCI) · NPCI has directed banks and UPI apps to mask customers’ phone numbers, UPI IDs and bank-account details to align
Key facts
- September 4 implementation deadline
- Last four digits of mobile number may remain visible
Why this matters
Payments companies should assess partnerships or acquisitions in privacy engineering, tokenized identity and fraud prevention to meet DPDP-aligned requirements while preserving onboarding and payment-conversion performance.
What to watch
- NPCI clarification on whether masking applies uniformly to payer names, UPI IDs, transaction histories, collect requests and merchant-side dashboards.
- App-specific implementation choices by PhonePe, Google Pay, Paytm and bank apps, especially treatment of existing phone-number-linked UPI IDs.
- Increase in mistaken-transfer, refund, chargeback or payment-not-received complaints after rollout.
- Adoption of verified merchant badges, business aliases and dynamic QR products by payment apps and aggregators.
- Regulatory enforcement actions or deadline extensions for banks, PSPs or third-party payment providers.
- Evidence that small merchants experience lower repeat-payment conversion because customers can no longer recognize phone-linked handles.
- Replace phone-number-based UPI IDs and static QR workflows with branded, non-personal merchant handles where possible.
- Audit checkout, refund, customer-service and reconciliation processes that rely on visible customer mobile numbers or bank-account details.
- Add prominent merchant-name, verified-handle and transaction-reference confirmation screens to reduce misdirected-payment risk.
- Prepare customer-service scripts and self-service flows for payment-status verification without requesting unnecessary personal data.
- Review fraud controls for impersonation, lookalike UPI IDs, refund diversion and fake payment-confirmation claims.
- Coordinate with payment aggregators and banks on compliance status, API changes, dispute evidence and rollout timing before September 4.