Tokenisation for credit and debit card transactions

2022 OCT 3

Preliminary   > Security   >   Cyber security   >   Data security

Why in news?

  • The Reserve Bank of India’s card-on-file (CoF) tokenisation norms have kicked in from October 1, 2022.

More about the news:

  • In September 2021, the RBI prohibited merchants from storing customer card details on their servers with effect from January 01, 2022, and mandated the adoption of card-on-file (CoF) tokenisation as an alternative to card storage.
  • After multiple extensions, the RBI decided not to give any further relaxation in implementing these norms from October 1.
  • It applies to domestic, online purchases.
  • As per new guidelines, online players will have to delete any credit and debit card data stored on their platforms and replace them with token to secure card details of consumers.
  • The token requestor cannot store Primary Account Number (PAN), or any other card details.

What is tokenization?

  • Tokenisation refers to replacement of actual credit and debit card details with an alternate code called the “token”, which will be unique for a combination of card, token requestor and device.

How will tokenisation work?

  • A debit or credit card holder can get the card tokenised by initiating a request on the app provided by the token requester.
  • The token requester will forward the request to the card network which, with the consent of the card issuer, will issue a token corresponding to the combination of the card, the token requester, and the device.
  • The customer will not be charged for availing of the tokenisation service.

Why has RBI issued new guidelines?

  • A tokenised card transaction is considered safer as the actual card details are not shared with the merchant during transaction processing. For example, in case of any data breach or hacking attempt at the merchant’s end, the customer’s card details will be protected
  • Tokenisation lends greater credibility to seamless and secure payments experience.

PRACTICE QUESTION:

The term ‘tokenization’, widely discussed in news, is associated with:

(a) Gene editing

(b) Data security

(c) Marine fishing

(d) Water purification

Answer