India payments privacy regulation

NPCI's UPI Phone-Number Masking Mandate Is Narrow Regulation Done Right

NPCI's June 2026 circular masks UPI mobile numbers by September 4 — a rare DPDP-aligned rule that fixes a real harm without new compliance overhead.

UPI's Privacy Reset, by the Numbers People of Internet Research · India Sep 4, 2026 Compliance deadline NPCI's masking and default-VPA rul… Last 4 only Mobile digits shown QR payments hide the number entire… ~555 million Registered UPI users 55.49 crore users as of June 2026,… 22.72 billion Monthly UPI transactions June 2026 volume across 731 banks … peopleofinternet.com
UPI's Privacy Reset, by the Numbers People of Internet Research · India Sep 4, 2026 Compliance deadline Last 4 only Mobile digits shown ~555 million Registered UPI users 22.72 billion Monthly UPI transactions peopleofinternet.com

Key Takeaways

A Circular That Took Seven Weeks to Make News

On June 5, 2026, the National Payments Corporation of India (NPCI) issued Circular NPCI/UPI/OC-234/2026-27, titled "Safeguarding User Information in UPI." It sat largely unnoticed until late July, when MediaNama and other outlets reported its two operative changes. First, UPI apps and member banks must mask mobile numbers, account numbers and UPI IDs (VPAs) across customer-facing screens — showing only the last four digits of a registered mobile number, with QR-code payments withholding the number entirely, even after the transaction completes. Second, apps must let users create a username-based VPA and set it as their default, replacing the mobile-number-based ID that most first-time users pick without realizing an alternative exists. Both changes are due by September 4, 2026 — a three-month runway from public disclosure, though banks technically had the full circular text since early June.

The Case For the Rule, Stated Fairly

The rationale is not manufactured. Reporting on the circular ties it directly to "ongoing social media complaints, especially from women, about safety and identity theft risks associated with visible phone numbers during payments," per MediaNama's sourcing. A UPI transaction is often the only interaction a user has with a stranger — a delivery rider, a marketplace seller, a scam caller posing as a merchant — and until now that stranger walked away with a working mobile number, a durable, portable identifier usable for harassment, stalking, or SIM-swap-enabled fraud. A mobile-number VPA also silently defeats the DPDP Act's data-minimisation principle: it exposes a piece of PII (the phone number) for a transaction that only requires proof of a valid payment address. India's Supreme Court, in Justice K.S. Puttaswamy v. Union of India (2017), held that privacy is protected under Article 21 as intrinsic to liberty and dignity — establishing the constitutional predicate that Parliament later codified as the Digital Personal Data Protection Act, 2023 (full text via PRS India). Masking a payment identifier that need not be disclosed at all is a textbook application of that principle.

Why This Rule, Specifically, Deserves Support

What distinguishes this circular from the broader run of Indian tech regulation is what it doesn't do. It doesn't create a new consent-management bureaucracy, a data-localisation mandate, or a licensing regime. NPCI isn't asking banks to collect less data or retain it for a shorter period — backend records of the full mobile number remain intact for banks, NPCI, and law enforcement to use in fraud investigation and dispute resolution. The change is purely presentational: what appears on a screen. That is about as low-cost and high-yield a privacy intervention as regulation gets, and it is scoped to a documented, specific harm (harassment enabled by visible numbers) rather than a generalized anxiety about data flows. Compare this to the compliance apparatus DPDP's consent-manager framework will eventually impose on much of the same industry, and the contrast is instructive: proportionate rules that fix one clearly identified problem should be the norm, not the exception, in Indian tech policy.

Where the Friction Will Actually Show Up

The rule is sound; the rollout is tighter than it looks. UPI now processes roughly 22.7 billion transactions a month across 731 banks and dozens of apps, per NPCI data reported by Entrackr — but PhonePe and Google Pay alone carry the large majority of that volume, and large platforms can re-skin a display layer in weeks. Smaller PSPs and regional bank apps, with thinner engineering benches, effectively learned about a September 4 deadline from press coverage in late July — closer to five weeks of practical dev time than the three months the circular's dates imply. NPCI and the regulator should watch for two failure modes: apps that quietly miss the deadline without consequence (undermining the rule's credibility), and apps that over-comply by making the underlying number harder for banks' own fraud and grievance teams to retrieve when a user legitimately needs a transaction traced. Masking the display layer while preserving backend access is the right design; NPCI should say so explicitly so banks don't over-engineer confusion into customer support.

The Bigger Picture

With 55.49 crore (about 555 million) users, per a parliamentary statement cited by StartupTalky, UPI is the plumbing of everyday Indian commerce, and small design defaults at that scale compound fast. A mobile-number-default VPA was a reasonable choice in UPI's early years, when the priority was onboarding hundreds of millions of first-time digital-payment users as quickly as possible. Three years into the DPDP Act's existence, and a decade into UPI's, shifting the default toward a username-based identifier is a sensible correction, not an imposition. If NPCI wants this precedent to hold — regulation as narrow, harm-specific correction rather than sweeping new bureaucracy — it should resist the temptation to bundle future privacy asks into broader, costlier compliance packages. This one is worth getting right precisely because it shows what "privacy by design" can look like without becoming a byword for red tape.

Sources & Citations

  1. PRS India — Digital Personal Data Protection Act, 2023 (full text)
  2. Indian Kanoon — Justice K.S. Puttaswamy v. Union of India (2017)
  3. MediaNama — NPCI asks UPI apps to mask phone numbers, pushes username IDs
  4. StartupTalky — NPCI Tightens UPI Norms, Directs Apps to Mask Mobile Numbers
  5. Entrackr — UPI clocks 22.72 Bn transactions worth Rs 28.92 lakh Cr in June