{"id":2981,"date":"2021-03-17T12:11:40","date_gmt":"2021-03-17T06:41:40","guid":{"rendered":"https:\/\/cashfree.com\/blog\/?p=2981"},"modified":"2023-01-10T18:05:05","modified_gmt":"2023-01-10T12:35:05","slug":"payments-digest-by-cashfree-feb-2021","status":"publish","type":"post","link":"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/","title":{"rendered":"Payments Digest by Cashfree: Feb 2021"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_81 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6a8ef6f129c35\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #364250;color:#364250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #364250;color:#364250\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6a8ef6f129c35\"  aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#PART_I-_Implications_of_the_prohibition_on_storing_card_data_under_RBI_PA_norms\" >PART I- Implications of the prohibition on storing card data under RBI PA norms<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#Why_is_change_to_the_prohibition_necessary-_from_a_PAs_perspective\" >Why is change to the prohibition necessary- from a PA\u2019s perspective?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#Are_refunds_chargeback_and_dispute_resolution_processes_impacted\" >Are refunds, chargeback and dispute resolution processes impacted?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#When_will_this_come_into_effect\" >When will this come into effect?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#Table_1_Impact_at_a_Glance_for_PAsMerchants\" >Table 1: Impact at a Glance for PAs\/Merchants<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#PART_II-_The_scope_of_the_new_Digital_Payment_Security_Controls\" >PART II- The scope of the new Digital Payment Security Controls<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#How_do_these_impact_fintechs_and_other_payments_players\" >How do these impact fintechs and other payments players?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#What_are_some_of_the_specific_changes_entailed\" >What are some of the specific changes entailed?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#PART_III-_What_does_Budget_2021_bring_for_digital_payments\" >PART III- What does Budget 2021 bring for digital payments?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#Others\" >Others<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/#Bibliography\" >Bibliography<\/a><\/li><\/ul><\/nav><\/div>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Via our Payments Digest, we aim to provide a view on key payments policy initiatives taken each month. Discussions for Edition 2: Efforts to persuade the RBI to withdraw its prohibition against payment aggregators and merchants storing card data are ongoing- why is this important? The RBI has issued new Digital Payments Security Controls- what do they change? And with February comes the Budget, what\u2019s in it for digital payments?<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-part-i-implications-of-the-prohibition-on-storing-card-data-under-rbi-pa-norms\"><span class=\"ez-toc-section\" id=\"PART_I-_Implications_of_the_prohibition_on_storing_card_data_under_RBI_PA_norms\"><\/span>PART I- <strong><strong>Implications of the prohibition on storing card data under RBI PA norms<\/strong><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The RBI norms for Payment Aggregators (\u2018PAs\u2019) and Payment Gateways (\u2018PGs\u2019) (\u2018PA norms\u2019) brought several welcome changes last year, like greater flexibility and new services for merchants <strong>(Related Read: <a href=\"https:\/\/cashfree.com\/blog\/regulation-2-0-for-payment-aggregators-reimagining-the-role-of-pas-and-what-still-needs-to-change\/\">Regulation 2.0 for Payment Aggregators: Reimagining the role of PAs and what still needs to change<\/a>)<\/strong>. A separate requirement coming into effect this year is a prohibition against PAs and merchants storing card data. Industry efforts for a change to this are ongoing and for good reason- the norms negatively impact the customer experience and possibly digital payments adoption in the long run. So far, the RBI has reaffirmed the prohibition via internal clarifications, allowing storage only for the limited purpose of transaction tracking.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-why-is-change-to-the-prohibition-necessary-from-a-pa-s-perspective\"><span class=\"ez-toc-section\" id=\"Why_is_change_to_the_prohibition_necessary-_from_a_PAs_perspective\"><\/span>Why is change to the prohibition necessary- from a PA\u2019s perspective?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The result of the prohibition is that customers will need to re-enter card data for every card-based payment, including e-mandates\/ standing instructions. Benefits the RBI itself sought to bring in like AFA relaxations for card-based e-mandates are effectively nullified. Merchant provided facilities like card-saving, one-click payments, recurring payments, etc. are all impacted.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The problem is that despite PCI-DSS and other security related requirements, the prohibition on merchants\/PAs has been imposed without considering alternatives, or offering solutions post-prohibition. Consider tokenisation- the current framework is too limited in its scope (card-saving by mobiles\/tablets in 2019) for it to be rolled out on the scale required here. On the other hand, tokenisation that PAs were already doing (for e-mandates say, where only a token was shared) comes to an end.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alternatives can nevertheless be found- you still have UPI AutoPay and eNACH for recurring payments. Card network provided solutions like Visa Checkout, Safe Click, etc., are another alternative for card-saving\/ one-click payments- in fact the RBI has also relaxed AFAs here upto Rs.2k. However, these are yet to be widely available, given issues like integration delays. Further, these may need modification to comply with the new norms, given these may be sharing card data with other stakeholders currently, in keeping with current practices. Despite the alternatives however, benefits like the popularity of cards with customers, providing a wide range of digital payment options, seamless checkout processes, etc. are still lost.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The table below summarizes the impact of the prohibition. A separate consequence is that this impacts the playing field- between PAs and other entities offering similar services (payments banks, PGs, even mobiles\/tablets as per the tokenisation norms), and also between UPI and cards, giving UPI the upper hand.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-are-refunds-chargeback-and-dispute-resolution-processes-impacted\"><span class=\"ez-toc-section\" id=\"Are_refunds_chargeback_and_dispute_resolution_processes_impacted\"><\/span>Are refunds, chargeback and dispute resolution processes impacted?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Chargeback and dispute resolution processes are not dependent on shared card data. Merchants\/ PAs only need to share the transaction reference numbers with the card networks, who effect the reversals, etc. as required. The same also applies for refunds, however, without card data, benefits in the form of say alternative solutions for faster refunds come to an end. Refunds will thus be slower. Other value added services which are dependent on card data are also similarly impacted.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-when-will-this-come-into-effect\"><span class=\"ez-toc-section\" id=\"When_will_this_come_into_effect\"><\/span>When will this come into effect?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For a non-bank PA this will come into effect when it is authorised as a PA. The last date to apply is June 30th, 2021. For bank PAs, the norms came into effect on September 30th, 2020, while for PGs this is a recommendation only, and not mandatory.&nbsp;<\/p>\n\n\n\n<h3 class=\"has-text-align-center wp-block-heading\" id=\"h-table-1-impact-at-a-glance-for-pas-merchants\"><span class=\"ez-toc-section\" id=\"Table_1_Impact_at_a_Glance_for_PAsMerchants\"><\/span>Table 1: Impact at a Glance for PAs\/Merchants<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<figure class=\"wp-block-table is-style-regular\"><table><tbody><tr><td class=\"has-text-align-left\" data-align=\"left\"><\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>Impacted<\/strong><\/td><td><strong>Not impacted\/ Alternatives<\/strong><\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Storage of card data by entities<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Prohibited except for transaction tracking purposes<br>&#8211; Payment Aggregators<br>&#8211; Merchants<\/td><td>&#8211; Payments Banks (M-wallets, etc.)<br>&#8211; Payment Gateways<br>&#8211; Card saving by phones\/ tablets (tokenization)<br>&#8211; Card networks and related payment solutions (Visa Checkout, etc.)<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><br><br><br><br><strong>Recurring Payments<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Card based standing instructions\/ e-mandates- will require input of data for every payment<br><br>Effectively nullifies AFA relaxations provided<\/td><td>&#8211; eNACH e-mandates using debit card authentication<br>&#8211; eNACH e-mandates using net banking authentication<br>&#8211; UPI AutoPay<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Card-saving\/ One-click payments for seamless checkout processes<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Merchant provided solutions- Will require input of card data for every payment<\/td><td>Card network provided solutions provided no card data shared with other stakeholders:<br>&#8211; Card saving (Visa Checkout, Masterclass, etc.)&nbsp;<br>&#8211; One-click (Visa Safe Click)<br><br>RBI AFA relaxations here can continue<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Refunds, Chargeback and Dispute Resolution Processes<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">Alternative refund solutions come to an end. <\/td><td>Card data not required for refunds\/chargebacks\/dispute resolution- transactions reference no. alone to be shared with card networks which will effect the reversal.<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Payment Options for Customers (summary)<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">&#8211; Card based SIs\/e-mandates<br>&#8211; Card based one-time payments will require input of card data for every payment<br>&#8211; Merchant provided one-click and card-saving solutions<\/td><td>&#8211; UPI AutoPay, eNACH for recurring payments<br>&#8211; Other payment options- UPI, Net banking, Wallet payments, Cash on Delivery, Gift cards\/vouchers, etc.&nbsp;<br>&#8211; Contactless Payments at PoS, QR Codes, etc. <br>&#8211; Card network provided one-click and card-saving solutions<\/td><\/tr><tr><td class=\"has-text-align-left\" data-align=\"left\"><strong>Others- UPI based payments to credit cards<\/strong><\/td><td class=\"has-text-align-left\" data-align=\"left\">&#8211; Non-consent based creation of UPI VPAs using credit card data by merchants will not be possible, since credit card data cannot be retained.<br>&#8211; Use of consent based UPI VPAs using credit card data by merchants will require sharing of the VPA each time<\/td><td>&#8212;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>(Related Read: <a href=\"https:\/\/cashfree.com\/blog\/the-indian-recurring-payments-landscape-tapping-into-the-potential-of-upi-autopay\/\">The Indian Recurring Payments Landscape: Tapping into the Potential of UPI AutoPay)<\/a><\/strong><\/p>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-part-ii-the-scope-of-the-new-digital-payment-security-controls\"><span class=\"ez-toc-section\" id=\"PART_II-_The_scope_of_the_new_Digital_Payment_Security_Controls\"><\/span>PART II- <strong><strong>The scope of the new Digital Payment Security Controls<\/strong><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Increasing digitization and multiple new payment modes and business models have also led to new vulnerabilities. With customer confidence in digital payments at stake with all the bank downtimes, system outages, cybersecurity issues like compromised card data, etc. off-late, the RBI\u2019s new Digital Payment Security Controls come at a good time. These apply to the regulated entities (\u2018REs\u2019) specified (scheduled commercial banks, small finance banks, payments banks and credit card issuing NBFCs), but the benefit they bring will be for the payments industry as a whole.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-how-do-these-impact-fintechs-and-other-payments-players\"><span class=\"ez-toc-section\" id=\"How_do_these_impact_fintechs_and_other_payments_players\"><\/span>How do these impact fintechs and other payments players?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Many payment products today are built on the rails of in-house services from banks- take UPI, fintech provided API banking, etc. The Controls in essence force REs like the banks to resolve several core issues- securing their tech stack, improving reconciliation, addressing downtimes and refund delays, better grievance redressal, fraud mitigation, etc. Each of these impact the quality of service fintechs and other payment players receive from the banks, and in turn are able to provide to their end-customers. Basically, an improvement in the core issues means fintechs, etc. can improve the all round customer experience as well.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-what-are-some-of-the-specific-changes-entailed\"><span class=\"ez-toc-section\" id=\"What_are_some_of_the_specific_changes_entailed\"><\/span>What are some of the specific changes entailed?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Overall, the Controls aim to introduce new governance structures, and secure channels like internet, m-banking, card payments, etc. They serve as an overarching regulation, securing digital payments even when no specific regulations apply:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Scalability issues- transaction overloads and downtimes<\/strong><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">UPI provides a clear illustration of scalability issues with digital payments. A specific technical issue for instance is that bank servers can process only a limited number of transactions per second (\u2018TPS\u2019), making them unable to properly support UPI volumes. Given issues here, UPI is unsurprisingly a major source of customer complaints (the Ombudsman Report cited 43.89% for funds transfers, UPI, BBPS and BharatQR together). Solutions like imposing volume caps (as for UPI) far from resolving the issue have the opposite effect- of being difficult to enforce technically, and may increase transaction failures once the cap is reached.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Controls here take a welcome approach- it addresses the issue from the core, requiring work on capacity building, scalable infrastructure, minimising technical declines, higher availability of channels, etc. For instance, take the \u2018multi-tier application architecture\u2019 requirement. For this a given system will be segmented into multiple tiers and applications, allowing say fixing issues (say a cybersecurity attack) in one part without affecting another, in turn increasing availability and reducing downtimes. It also allows faster technical upgrades with less disruption, like for improving the TPS.<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"2\">\n<li><strong>Improving API based banking with banks opening up servers<\/strong><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">For fintech provided services, a bank\u2019s application architecture forms the backbone. As banks become more tech-savvy and secure, and thereby more comfortable with opening up their servers to third parties, a more secure API banking experience is also possible.  Changes for example include requiring properly implemented APIs for secure data, storage and communications. Checks and balances are also required to prevent transactions from unauthorised apps, say steps like IP whitelisting to recognize authorised API requests.&nbsp;Multi-factor authentication is also specified here- allowing limiting login attempts and blocking of compromised API payment credentials. <\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"3\">\n<li><strong>On card data and storage <\/strong><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The focus on data security is evident throughout the Controls. For card data specifically, security requirements are prescribed including new PCI compliance obligations (PCI-PIN, PCI-P2E, etc.) and verifying merchant compliance with the same. On card storage they require compliance with extant laws\/instructions, which will also include the PA norms\u2019 prohibitions discussed above. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Another requirement is for REs to ensure that all \u2018its vendor locations, systems and applications\u2019 don\u2019t store card data in plain text. This is likely referring to entities like the REs\u2019 technical partners (like vendors for debit card\/ credit card\/ EMI, etc.). Such entities are anyway subject to PCI-DSS obligations which require encryption, whether applicable directly or passed on contractually by REs (which are themselves otherwise restricted from sharing card data). <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What is unclear is if this requirement also applies to entities like UPI\u2019s TPAPs. Though unlikely, this could resolve issues like with UPI VPAs mapped to credit card (CC) numbers. UPI VPAs float in plaintext, exposing CC data when using UPI for payments to CCs this way. The key difference is that while standard UPI VPAs allow sending funds to the account alone, a leaked CC number also allows pulling funds from the account. This is a major concern particularly with recent issues that have emerged of creation of such UPI VPAs without customer consent.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If applicable, the Controls will require encryption of UPI VPAs containing card data. Even if not, the protection under the Controls goes beyond \u2018card data\u2019 alone to broader categories of \u2018customer data\u2019 and \u2018payments data\u2019. Here, while the safeguards are not prescribed but left to the RE\u2019s discretion and risk perception, it very much requires assessing and addressing risk with such data. For example, the Controls ask for security controls focusing on how digital payments apps handle payment data, security of data in transit, minimising data collection in m-apps, etc.<\/p>\n\n\n\n<ol class=\"wp-block-list\" start=\"4\">\n<li><strong>Reconciliation issues and impact on flexible settlement timelines<\/strong><\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The Controls require REs to implement real-time\/ near real-time reconciliation, within 24 hours of receiving the settlement file. Reconciliation can be a major pain point for service providers and merchants, since a certain number of transactions normally fail (~2% for bank transfers). Identifying these failed transactions and rerouting\/ reversing them is complicated- for instance, for different banks and payment modes, the reporting formats and types of issues also vary. Delays here only add to customer grievances, making the requirement welcome. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Separately, the real-time reconciliation requirement will have no impact on the flexible\/delayed settlement timelines allowed under the PA norms, given that settlement and reconciliation are two completely different processes. <\/p>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-part-iii-what-does-budget-2021-bring-for-digital-payments\"><span class=\"ez-toc-section\" id=\"PART_III-_What_does_Budget_2021_bring_for_digital_payments\"><\/span>PART III- <strong><strong>What does Budget 2021 bring for digital payments?<\/strong><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Another significant development in Feb is the Budget- here the unchanged zero MDR stand was disappointing, but the payments industry can now look forward to the Rs.1500 crore fund instead. A scheme outlining how the funds will be deployed is still expected- predictions range from a boost to the PIDF, alternative acceptance infra subsidies, or typical direct financial incentives (think past Meity reimbursement and bonus schemes for merchants\/customers). An MDR refund is perhaps unlikely- the current fund falls short by various calculations (eg.: banks had sought Rs.2000 crore per year last year), and moreover this is a one-time allocation only.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One general incentive is the enhanced tax audit exemption for businesses with 95% digital transactions and sales below Rs.10 crore. Apart from this, the payments industry may also benefit from the support promised in the Budget for a \u2018world-class Fintech Hub\u2019 for the Gujarat International Finance Tec-City (GIFT). Reports suggest a fintech policy will be revealed, which is said might also target payment companies to boost the fintech infrastructure at GIFT. Here, the scope for the fintech benefit for GIFT entities can include neobanking services for payments processing, cross border trade and remittance, payroll services, etc.&nbsp;<\/p>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-others\"><span class=\"ez-toc-section\" id=\"Others\"><\/span><strong>Others<\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Payments innovation:<\/strong> The application date for Umbrella Entities has been extended to March 31<sup>st<\/sup>, 2021. SEBI has also opened its regulatory sandbox to non-SEBI regulated entities, creating scope for even payment companies to participate and experiment with innovation here.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Seeking new avenues:<\/strong> The recent RBI permission for residents to invest in securities issued by non-resident entities at GIFT\u2019s IFSC via the Liberalised Remittance Scheme brings up an old ask- allow payment companies like PAs to process such capital account transactions, thereby bringing the fintech benefit here as well. Current norms restrict this to Authorized Dealers, allowing use of non-bank entities for specified current account transactions alone.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-css-opacity is-style-wide\"\/>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-bibliography\"><span class=\"ez-toc-section\" id=\"Bibliography\"><\/span><strong><span class=\"has-inline-color has-cyan-bluish-gray-color\">Bibliography<\/span><\/strong><span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Amendment to section 44AB of Income Tax Act, 1961, The Finance Bill, 2021, dated February 1, 2021.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Article by Asheeta Regidi and Reeju Datta, <em>Regulation 2.0 for Payment Aggregators: Reimagining the role of PAs and what still needs to change, <\/em>Cashfree Blog dated May 29, 2020.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Article by Asheeta Regidi and Reeju Dutta: <em>The Indian Recurring Payments Landscape: Tapping into the Potential of UPI AutoPay<\/em>, Cashfree Blog, dated August 25, 2020.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Article by Komal Gupta: <em>Representation on Clarifications on Guidelines on Regulation of Payment Aggregators and Payment Gateways<\/em>, NASSCOM Policy Advocacy, dated January 4, 2021.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Article by Srikanth Lakshmanan, Cashless Consumer:<em> Airtel, ZoomCar leaking Credit Card Number during merchant refunds<\/em>, Medium, dated February 26, 2021.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Cashfree Report: <em>Top Reasons Bank Transfers fail in India <\/em>(First Edition).<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Government of India Document: <em>Budget 2021-2022 Speech of Nirmala Sitharaman Minister of Finance<\/em>, dated February 1, 2021.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Media Report by Ashwin Manikandan &amp; Anandi Chandrashekhar: <em>Juspay Data Leak fallout: RBI swings into action to curb cyberattacks<\/em>, The Economic Times, dated January 06, 2021.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Media Report by Dinesh Unnikrishnan: <em>HDFC Bank\u2019s digital outages: 7 key takeaways from RBI action, <\/em>Money Control, dated December 03, 2020.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Media Report by Kapil Dave: <em>New fintech park proposed by Gujarat for GIFT City, <\/em>The Times of India, dated January 28, 2021.\u00a0<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Media Report by Ridhima Saxena: <em>Convenience Vs Security: RBI\u2019s Proposed Rules On Card Payments Prompt Debate<\/em>, BloombergQuint, updated on February 24, 2021<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Media Report: <em>HDFC Bank submits action plan to RBI, hopes to fix outage issue in 3 months<\/em>, Business Standard, updated on January 23, 2021.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\"><span style=\"color: rgb(171, 184, 195);\">Media Report: <\/span><em style=\"color: rgb(171, 184, 195);\">Zero MDR: FinMin says no to banks\u2019 compensation plea<\/em><span style=\"color: rgb(171, 184, 195);\">, The Hindu Business Line, dated January 07, 2020<\/span>.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Meity Notification: <em>Subsidizing MDR charges on Debit Cards\/BHIM UPI\/AePS transactions of value less than or equal to Rs. 2000\/-<\/em>, dated 27 December, 2017.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Meity Notification: <em>Extension and Modification in the BHIM(Bharat Interface For Money) Referral Bonus Scheme for Individuals<\/em>,\u00a0 dated 14 August, 2017.<span style=\"color: rgb(171, 184, 195);\">NPCI Operation Circular: <\/span><em style=\"color: rgb(171, 184, 195);\">Guidelines on volume cap for Third Party App Providers(TPAP\u2019s) in UPI<\/em><span style=\"color: rgb(171, 184, 195);\">, NPCI\/UPI\/OC-97\/2020-21, dated November 5, 2020.<\/span><\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI Circular: <em>Tokenisation \u2013 Card transactions<\/em>, RBI\/2018-19\/103, dated January 08, 2019.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI FAQs: <em>Tokenisation \u2013 Card Transactions<\/em>, dated May 18, 2020.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI Notification: <em>Card transactions in Contactless mode &#8211; Relaxation in requirement of Additional Factor of Authentication<\/em>, RBI\/2020-21\/71, dated December 04, 2020.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI Notification: <em>Card Not Present transactions \u2013 Relaxation in Additional Factor of Authentication for payments upto \u20b9 2000\/- for card network provided authentication solutions, RBI\/2016-17\/172<\/em>, dated December 6, 2016.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI Notification: <em>Directions for opening and operation of Accounts and settlement of payments for electronic payment transactions involving intermediaries<\/em>, RBI\/2009-10\/231, dated November 24, 2009.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI Notification: <em>Guidelines on Regulation of Payment Aggregators and Payment Gateways<\/em>, RBI\/2019-20\/174, dated March 17, 2020.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI Notification: <em>Master Direction on Digital Payment Security Controls<\/em>, RBI\/2020-21\/74, dated February 18, 2021.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI Notification: <em>Operationalisation of Payments Infrastructure Development Fund(PIDF) Scheme<\/em>, RBI\/2020-21\/81, dated January 05, 2021.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI Notification: <em>Processing of e-mandate on cards for recurring transactions, <\/em>RBI\/2019-20\/47, dated August 21, 2019.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI Notification: <em>Processing of e-mandates for recurring transactions<\/em>, RBI\/2020-21\/74, dated December 04, 2020.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">RBI Publication: <em>Annual Report of Ombudsman Schemes, 2019-20<\/em>, dated February 08, 2021.<\/mark><\/li>\n\n\n\n<li><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-cyan-bluish-gray-color\">Terms and Conditions for Cash Management Services, Kotak Mahindra Bank Limited<\/mark><\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>India\u2019s digital payments policy updates for February 2021- Card data storage, Digital Payments Security Controls &#038; Budget 2021.<\/p>\n","protected":false},"author":11,"featured_media":6949,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"_themeisle_gutenberg_block_has_review":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_wpcom_ai_launchpad_first_post":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1,1412],"tags":[2107,2190],"class_list":["post-2981","post","type-post","status-publish","format-standard","has-post-thumbnail","category-all","category-policy","tag-experts-speak","tag-payment-policies"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Payments Digest by Cashfree: Feb 2021 - Cashfree Payments Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Payments Digest by Cashfree: Feb 2021 - Cashfree Payments Blog\" \/>\n<meta property=\"og:description\" content=\"India\u2019s digital payments policy updates for February 2021- Card data storage, Digital Payments Security Controls &amp; Budget 2021.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/\" \/>\n<meta property=\"og:site_name\" content=\"Cashfree Payments Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-03-17T06:41:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-01-10T12:35:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2021\/04\/PG-Feb.png?fit=1200%2C628&ssl=1\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"628\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Asheeta Regidi\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Asheeta Regidi\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Payments Digest by Cashfree: Feb 2021 - Cashfree Payments Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/","og_locale":"en_US","og_type":"article","og_title":"Payments Digest by Cashfree: Feb 2021 - Cashfree Payments Blog","og_description":"India\u2019s digital payments policy updates for February 2021- Card data storage, Digital Payments Security Controls & Budget 2021.","og_url":"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/","og_site_name":"Cashfree Payments Blog","article_published_time":"2021-03-17T06:41:40+00:00","article_modified_time":"2023-01-10T12:35:05+00:00","og_image":[{"width":1200,"height":628,"url":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2021\/04\/PG-Feb.png?fit=1200%2C628&ssl=1","type":"image\/png"}],"author":"Asheeta Regidi","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Asheeta Regidi","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/#article","isPartOf":{"@id":"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/"},"author":{"name":"Asheeta Regidi","@id":"https:\/\/blogrevamp.cashfree.com\/#\/schema\/person\/48fad2546fc9f8dd8157e001f39cfe6d"},"headline":"Payments Digest by Cashfree: Feb 2021","datePublished":"2021-03-17T06:41:40+00:00","dateModified":"2023-01-10T12:35:05+00:00","mainEntityOfPage":{"@id":"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/"},"wordCount":2725,"commentCount":0,"image":{"@id":"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2021\/04\/PG-Feb.png?fit=1200%2C628&ssl=1","keywords":["Experts Speak","Payment Policies"],"articleSection":["All","Policy Radar"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/blogrevamp.cashfree.com\/payments-digest-by-cashfree-feb-2021\/","url":"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/","name":"Payments Digest by Cashfree: Feb 2021 - Cashfree Payments Blog","isPartOf":{"@id":"https:\/\/blogrevamp.cashfree.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/#primaryimage"},"image":{"@id":"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2021\/04\/PG-Feb.png?fit=1200%2C628&ssl=1","datePublished":"2021-03-17T06:41:40+00:00","dateModified":"2023-01-10T12:35:05+00:00","author":{"@id":"https:\/\/blogrevamp.cashfree.com\/#\/schema\/person\/48fad2546fc9f8dd8157e001f39cfe6d"},"breadcrumb":{"@id":"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/#primaryimage","url":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2021\/04\/PG-Feb.png?fit=1200%2C628&ssl=1","contentUrl":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2021\/04\/PG-Feb.png?fit=1200%2C628&ssl=1","width":1200,"height":628},{"@type":"BreadcrumbList","@id":"https:\/\/www.cashfree.com\/blog\/payments-digest-by-cashfree-feb-2021\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blogrevamp.cashfree.com\/"},{"@type":"ListItem","position":2,"name":"All","item":"https:\/\/blogrevamp.cashfree.com\/category\/all\/"},{"@type":"ListItem","position":3,"name":"Payments Digest by Cashfree: Feb 2021"}]},{"@type":"WebSite","@id":"https:\/\/blogrevamp.cashfree.com\/#website","url":"https:\/\/blogrevamp.cashfree.com\/","name":"Cashfree Payments Blog","description":"Cashfree Payments- Payment Gateway for India","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blogrevamp.cashfree.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blogrevamp.cashfree.com\/#\/schema\/person\/48fad2546fc9f8dd8157e001f39cfe6d","name":"Asheeta Regidi","description":"Head, Fintech Policy at Cashfree.","url":"https:\/\/blogrevamp.cashfree.com\/author\/asheetaregidi\/"}]}},"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9MjXo-M5","jetpack_likes_enabled":false,"jetpack_featured_media_url":"https:\/\/i0.wp.com\/blogrevamp.cashfree.com\/wp-content\/uploads\/2021\/04\/PG-Feb.png?fit=1200%2C628&ssl=1","_links":{"self":[{"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/posts\/2981","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/comments?post=2981"}],"version-history":[{"count":77,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/posts\/2981\/revisions"}],"predecessor-version":[{"id":17047,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/posts\/2981\/revisions\/17047"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/media\/6949"}],"wp:attachment":[{"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/media?parent=2981"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/categories?post=2981"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogrevamp.cashfree.com\/wp-json\/wp\/v2\/tags?post=2981"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}