Payment aggregator regulation requires authorization, escrow settlements, strict data security, and prohibition on card-on-file storage.
RBI's guidelines impose a compliance regime on non-bank payment aggregators requiring company incorporation with PA activity, authorization under the PSS Act, progressive and maintained net worth, board-monitored governance, merchant background checks and contractual protections, escrow-only settlements with a single scheduled commercial bank, and periodic reporting. Technology rules mandate data security, PCI-DSS/PA-DSS adherence, incident reporting, and forbid storage of card-on-file data by parties other than card issuers and card networks, encouraging tokenization and alternate mechanisms for recurring or post-transaction use-cases. (AI Summary)
RBI's guidelines impose a compliance regime on non-bank payment aggregators requiring company incorporation with PA activity, authorization under the PSS Act, progressive and maintained net worth, board-monitored governance, merchant background checks and contractual protections, escrow-only settlements with a single scheduled commercial bank, and periodic reporting. Technology rules mandate data security, PCI-DSS/PA-DSS adherence, incident reporting, and forbid storage of card-on-file data by parties other than card issuers and card networks, encouraging tokenization and alternate mechanisms for recurring or post-transaction use-cases. (AI Summary)
TaxTMI 