RBI reinforces security norms for payment companies
By MYBRANDBOOK
The Reserve Bank of India (RBI) has tightened its supervision norms over payments companies storing customer data, due to the rising cybersecurity threats and breaches in India. All the payment system operators (PSOs) will now have to submit detailed “compliance certificates” to the central bank twice a year from April 1, 2021, onwards.
The documents have to be signed by their Chief Executive Officer (CEOs) or managing directors (MDs), confirming the adherence to all the RBI regulations around security and storage of payment data.
RBI’s department of payment and settlement systems (DPSS) issued a letter to all the PSOs operating in India, asking them to submit their certificates on April 30 and October 31 for the period ending March 31 and September 30, respectively.
Along with this, the Indian PSOs will also have to submit board-approved system audit report (SAR) by CERT-empanelled auditors. The central bank had introduced this provision back in April 2018 and it will continue in practice, even as the PSOs take a step to ensuring proper certifications.
The new specification comes at a time when several Indian payments and tech startups across the sectors have witnessed data leaks and cyber-attacks. Some of these companies are grocery delivery giant BigBasket (acquired by Tata), edtech startup Unacademy, crowdfunding platform Impact Guru and many others.
Merchants like Amazon, Microsoft, Netflix, Flipkart, Zomato and others to store customers’ credit card credentials “and related data” on their servers under the new payment aggregators and payment gateway (PA-PG) norms that come into effect this year, are also prohibited by the RBI. The guidelines also bar payment aggregators from storing customer card credentials within their database or the servers assessed by the merchants.
RBI has decided to not allow merchants to store such financial data as they would anyway not be answerable in case of any security breaches since the norm pertains to payment aggregators and gateways. The new guidelines will treat all payment aggregators as regulated entities under the Payment and Settlement Systems Act (2007) under the central bank’s direct supervision.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
DIGISOL SYSTEMS LTD.
HIMACHAL FUTURISTIC COMMUNICATIONS LTD.
TECHROUTES NETWORK PRIVATE LIMITED
EXATRON SERVERS MANUFACTURING PVT. LTD.
Icons Of India : GAUTAM ADANI CHAIRMAN ADANI GROUP
Gautam Adani is the Founder and Chairman of the Adani Group, which ran...
ICONS OF INDIA : SUNIL BHARTI MITTAL
Sunil Bharti Mittal is the Founder and Chairman of Bharti Enterprises,...
Icons Of India : Kumar Mangalam Birla
Aditya Birla Group chairman Kumar Mangalam Birla recently made a comeb...
BSE - Bombay Stock Exchange
The Bombay Stock Exchange (BSE) is one of India’s largest and oldest...
CSC - Common Service Centres
CSC initiative in India is a strategic cornerstone of the Digital Indi...
IFFCO - Indian Farmers Fertiliser Cooperative
IFFCO operates as a cooperative society owned and controlled by its fa...
Indian Tech Talent Excelling The Tech World - George Kurian, CEO, Netapp
George Kurian, the CEO of global data storage and management services ...
Indian Tech Talent Excelling The Tech World - AJAY BANGA, President - World Bank
Ajay Banga is an Indian-born American business executive who currently...
Indian Tech Talent Excelling The Tech World - Vinod Dham, Founder & Executive Managing Partner, IndoUS Venture Partners
Vinod Dham, known as the “Father of the Pentium Chip,” has left an...