RBI extends the scope of tokenization
- RBI has extended the scope of tokenization from mobile phones and tablets to include all consumer devices (such as laptops, desktops, wearables, and IoTs, etc).
- Earlier, RBI had prohibited payment gateways and payment aggregators from storing customer card details.
- The deadline for stakeholders to comply with this norm was January 2022.
Tokenization:
- It refers to the replacement of actual card details with an alternate code called the “token”.
- Token will be unique for a combination of card, token requestor, and device.
- The token requestor is the entity that accepts a request from the customer for tokenization of a card and passes it on to the card network to issue a corresponding token.
Process of tokanisation:
- When a token requestor initiates a request on app then the cardholder’s card will be tokenized.
- The token requestor will forward the request to the card network.
- And the card network, with the consent of the card issuer, will issue a token corresponding to the combination of the card, the token requestor, and the device.
- It will be allowed through mobile phones or tablets for all use cases/channels (e.g., contactless card transactions, payments through QR codes, apps, etc.)
- Tokenisation can be performed only by the authorized card network.
Stakeholders in a tokenization transaction:
- Normally, in a tokenized card transaction, parties/stakeholders involved are merchants, the merchant’s acquirer, card payment network, token requestor, issuer, and customer.
- Tokenization of a card is not mandatory for a customer, it is their choice whether or not to let his/her card be tokenized.
Advantages of tokenization:
- The actual card details are not shared with the merchant during transaction processing.
- The token requestor cannot store Primary Account Number (PAN), i.e., card number, or any other card detail.
- It will prevent fraud.
- There are no charges for availing of this service.
- It reduces the risk of data breaches.
- It also minimizes red tape and drives technology behind popular payment services like mobile wallets.