A Circular That Took Seven Weeks to Make News
On June 5, 2026, the National Payments Corporation of India (NPCI) issued Circular NPCI/UPI/OC-234/2026-27, titled "Safeguarding User Information in UPI." It sat largely unnoticed until late July, when MediaNama and other outlets reported its two operative changes. First, UPI apps and member banks must mask mobile numbers, account numbers and UPI IDs (VPAs) across customer-facing screens — showing only the last four digits of a registered mobile number, with QR-code payments withholding the number entirely, even after the transaction completes. Second, apps must let users create a username-based VPA and set it as their default, replacing the mobile-number-based ID that most first-time users pick without realizing an alternative exists. Both changes are due by September 4, 2026 — a three-month runway from public disclosure, though banks technically had the full circular text since early June.
The Case For the Rule, Stated Fairly
The rationale is not manufactured. Reporting on the circular ties it directly to "ongoing social media complaints, especially from women, about safety and identity theft risks associated with visible phone numbers during payments," per MediaNama's sourcing. A UPI transaction is often the only interaction a user has with a stranger — a delivery rider, a marketplace seller, a scam caller posing as a merchant — and until now that stranger walked away with a working mobile number, a durable, portable identifier usable for harassment, stalking, or SIM-swap-enabled fraud. A mobile-number VPA also silently defeats the DPDP Act's data-minimisation principle: it exposes a piece of PII (the phone number) for a transaction that only requires proof of a valid payment address. India's Supreme Court, in Justice K.S. Puttaswamy v. Union of India (2017), held that privacy is protected under Article 21 as intrinsic to liberty and dignity — establishing the constitutional predicate that Parliament later codified as the Digital Personal Data Protection Act, 2023 (full text via PRS India). Masking a payment identifier that need not be disclosed at all is a textbook application of that principle.
Why This Rule, Specifically, Deserves Support
What distinguishes this circular from the broader run of Indian tech regulation is what it doesn't do. It doesn't create a new consent-management bureaucracy, a data-localisation mandate, or a licensing regime. NPCI isn't asking banks to collect less data or retain it for a shorter period — backend records of the full mobile number remain intact for banks, NPCI, and law enforcement to use in fraud investigation and dispute resolution. The change is purely presentational: what appears on a screen. That is about as low-cost and high-yield a privacy intervention as regulation gets, and it is scoped to a documented, specific harm (harassment enabled by visible numbers) rather than a generalized anxiety about data flows. Compare this to the compliance apparatus DPDP's consent-manager framework will eventually impose on much of the same industry, and the contrast is instructive: proportionate rules that fix one clearly identified problem should be the norm, not the exception, in Indian tech policy.
Where the Friction Will Actually Show Up
The rule is sound; the rollout is tighter than it looks. UPI now processes roughly 22.7 billion transactions a month across 731 banks and dozens of apps, per NPCI data reported by Entrackr — but PhonePe and Google Pay alone carry the large majority of that volume, and large platforms can re-skin a display layer in weeks. Smaller PSPs and regional bank apps, with thinner engineering benches, effectively learned about a September 4 deadline from press coverage in late July — closer to five weeks of practical dev time than the three months the circular's dates imply. NPCI and the regulator should watch for two failure modes: apps that quietly miss the deadline without consequence (undermining the rule's credibility), and apps that over-comply by making the underlying number harder for banks' own fraud and grievance teams to retrieve when a user legitimately needs a transaction traced. Masking the display layer while preserving backend access is the right design; NPCI should say so explicitly so banks don't over-engineer confusion into customer support.
The Bigger Picture
With 55.49 crore (about 555 million) users, per a parliamentary statement cited by StartupTalky, UPI is the plumbing of everyday Indian commerce, and small design defaults at that scale compound fast. A mobile-number-default VPA was a reasonable choice in UPI's early years, when the priority was onboarding hundreds of millions of first-time digital-payment users as quickly as possible. Three years into the DPDP Act's existence, and a decade into UPI's, shifting the default toward a username-based identifier is a sensible correction, not an imposition. If NPCI wants this precedent to hold — regulation as narrow, harm-specific correction rather than sweeping new bureaucracy — it should resist the temptation to bundle future privacy asks into broader, costlier compliance packages. This one is worth getting right precisely because it shows what "privacy by design" can look like without becoming a byword for red tape.