India's First Hard Data-Minimisation Deadline Is 4 September — And the DPDP Act Isn't the One Enforcing It
On 4 September, every UPI app must mask phone numbers, UPI IDs and account numbers — a DPDP Act principle enforced by NPCI, not the Data Protection Board.
#India's First Hard Data-Minimisation Deadline Is 4 September — And the DPDP Act Isn't the One Enforcing It
On 4 September 2026 — five days from now — every UPI member bank and every UPI app operating in India has to stop showing users each other's full mobile numbers, UPI IDs and account numbers. It is the first binding, dated, nationwide data-minimisation obligation India has ever imposed on a major industry, and the DPDP Act 2023 has nothing to do with enforcing it.
That second half is the part Indian businesses should be paying attention to. The mandate comes from the National Payments Corporation of India, in circular NPCI/UPI/OC-234/2026-27 dated 5 June 2026, which gave banks and payment apps until 4 September to mask sensitive information across all customer-facing interfaces and communications. It applies to a system that processed 23.66 billion transactions in July 2026 alone. And it lands twenty months before the DPDP Act's own substantive obligations become enforceable on 13 May 2027, from an institution that is not a data protection regulator, using an instrument that is not a law.
#What actually changes on 4 September
The circular is narrower than "UPI is hiding phone numbers" and wider at the same time. Four things change:
Mobile numbers get masked. Only the last four digits of a user's registered mobile number will be visible to the counterparty in a transaction. The rest is masked on screen.
QR code payments suppress the number entirely. Where a payment is made by scanning a QR code, the payer's full mobile number is not displayed at all — not before the transaction, and not after it completes. This closes the most common harvesting route: pay a street vendor, and the vendor keeps your number.
Account numbers and VPAs are in scope too. The requirement is not limited to phone numbers. UPI IDs — virtual payment addresses — and bank account numbers must be masked across customer-facing surfaces as well. Most coverage has under-reported this. For a lot of apps it is the harder engineering change, because VPAs and masked account digits are threaded through confirmation screens, receipts, transaction histories, SMS templates, push notifications and support flows.
Username-based VPAs become the default. NPCI has directed apps to let users create UPI IDs that are not derived from their mobile number, and to make that the default for new users rather than a setting buried three screens deep. Today the overwhelming majority of Indian UPI IDs are 9876543210@bank — the phone number is the payment identity. Once a username-based VPA is the default, the number stops being structurally recoverable from the identifier itself.
The proximate trigger was not a regulator's white paper. It was a sustained wave of complaints — disproportionately from women — about strangers who pulled a phone number off a payment screen and then used it for unsolicited calls and WhatsApp messages. Business Standard and Business Today both reported the safety framing when the circular surfaced in the press in late July, roughly seven weeks after it was issued. MediaNama's coverage placed the username-VPA push at the centre of the change rather than treating it as a footnote, which is the right read.
#Why it matters that NPCI is the one doing this
The DPDP Act's enforcement body is the Data Protection Board of India. As of the start of this month, it had no appointed Chairperson and no appointed Members — nine months after the DPDP Rules 2025 brought the Board's establishing provisions into force on 13 November 2025. MeitY sought nominations on 6 May 2026 and followed up on 6 June 2026. The search-cum-selection committees exist on paper. No appointment order has been published.
The consequence has been well described: an institutional vacuum in which breach-reporting duties have no recipient, consent managers have no registrar, and courts referring matters to the Board are referring them to an empty room.
Into that vacuum steps NPCI — which is not a statutory data protection regulator and does not claim to be. It is a not-for-profit company incorporated under Section 8 of the Companies Act, an initiative of the RBI and the Indian Banks' Association, authorised by the RBI as a payment system operator under the Payment and Settlement Systems Act, 2007. Its circulars bind UPI member banks and third-party app providers through scheme participation rules and contract, not through statute. There is no ₹250 crore penalty attached to missing 4 September. There is scheme discipline, and there is the RBI standing behind it.
That distinction matters more than it looks. India's first real data-minimisation deadline is arriving through private scheme rules because the public enforcement machinery is not ready. It works — NPCI has the leverage to move Google Pay, PhonePe and Paytm in a way a memo from an unstaffed Board could not — but it is a workaround, and workarounds have edges. Scheme rules bind scheme members. They do not bind the merchant aggregator, the analytics vendor or the lending partner sitting one hop downstream from the payment.
#Where this maps onto the DPDP Act
Press coverage has consistently tied the circular to the DPDP Act. The circular's own published framing is about safeguarding user information rather than about statutory compliance, and no public text of it cites a section of the Act. But the alignment is real, and it is worth being precise about which obligations this anticipates.
Section 6(1) — consent limited to what is necessary. The Act requires that consent be free, specific, informed, unconditional and unambiguous, and that it "be limited to such personal data as is necessary for such specified purpose." Displaying a payer's full mobile number to a payee is not necessary to settle a payment. That is data minimisation stated as a consent constraint, and it is the closest thing the DPDP Act has to the GDPR's Article 5(1)(c). NPCI has effectively pre-enforced it at the interface layer.
Section 5 — notice. A data fiduciary must tell a data principal what personal data is being processed and for what purpose. A payment screen that quietly discloses a phone number to a counterparty is a disclosure most users never had described to them.
Section 8(5) — reasonable security safeguards. Every data fiduciary must take reasonable security safeguards to prevent a personal data breach. Not displaying an identifier is the cheapest safeguard available: data you never render cannot leak from the rendering. Under the Schedule to the Act, failure here carries the heaviest penalty band — up to ₹250 crore.
Section 10 — Significant Data Fiduciaries. The large payment apps are among the most obvious future candidates for SDF designation, given data volume and the risk profile of financial data. No SDF list has been notified under Section 10(1). When one is, additional obligations follow: a Data Protection Impact Assessment, independent audits, and an India-based Data Protection Officer.
So the honest characterisation is this: NPCI has imposed, by contract and on a nine-month runway, a subset of what the DPDP Act will require by law on an eighteen-month runway. The engineering work overlaps almost entirely. The legal exposure does not — yet.
#What masking fixes, and what it does not
It would be a mistake to read 4 September as a privacy win in the round. Masking is a display-layer control. It changes what one user can see about another user. It changes nothing about what the payment ecosystem itself collects, retains, infers or shares.
Privacy researchers have made this point sharply, and it holds. Behind every masked screen, the same entities still know the same things. The payment app still holds the full number. So does the payer's bank, the payee's bank, the payment service provider, the switch, and in many flows a merchant aggregator and its analytics stack. Identity resolution across those parties is untouched. Transaction-level behavioural profiling is untouched. Data sharing with lending, insurance and commerce arms of the same corporate group is untouched. As the Storyboard18 analysis put it, the privacy problem in UPI runs deeper than phone numbers.
The structural risk is also unchanged. A payment today routes through a merchant platform, a gateway, an API, a cloud environment, a bank and several technology partners; as one recent assessment noted, every one of those connections is also a potential point of failure, across a system that moved more than ₹314 lakh crore in FY26. Masking the number on the confirmation screen does not shrink that surface by a single node.
What masking genuinely fixes is a specific, real and widespread harm: the trivial harvesting of a stranger's phone number by anyone who transacts with them. For the women who filed the complaints that produced this circular, that is not a small thing. It is just not the same thing as data protection.
#The lesson for Indian businesses is not about UPI
Most Indian companies have built their DPDP planning around a single date: 13 May 2027, when the substantive obligations — notice, consent, security safeguards, breach reporting, data principal rights — become enforceable. Treating that as the compliance deadline is a mistake, and 4 September is the proof.
The real compliance calendar is a rolling sequence of sectoral instruments that convert DPDP principles into binding rules years ahead of the Act itself. RBI's payment-data localisation directions have operated independently of the DPDP framework since 2018. NPCI has now imposed interface-layer minimisation on the entire retail payments industry. There is no reason to expect SEBI, IRDAI, TRAI or the health-data authorities to behave differently in their own domains, and every reason — given that the Board still has no members — to expect them to move first.
Three practical implications follow.
Your regulator will probably reach you before the Board does. If you operate in a regulated sector, the instrument that first forces you to minimise, mask or localise personal data will almost certainly be a circular from your sectoral regulator, not an order from the Data Protection Board. Watch that channel with the same seriousness you watch MeitY.
Build to the principle, not to the circular. A team that implements masking as a hard-coded patch on three UPI screens will do this work again for the next circular, and again for May 2027. A team that builds a field-level classification of personal data and a policy layer governing what is rendered where will absorb every subsequent mandate as configuration. The second approach costs more this quarter and less every quarter after.
The eighteen-month runway is not a grace period. It is the outer bound. Sectoral regulators are compressing it in practice, and MeitY has itself floated compressing it in law — a proposal discussed at a January 2026 stakeholder consultation would have cut the timeline for Significant Data Fiduciaries from eighteen months to twelve, though nothing has been gazetted. Planning as though 13 May 2027 is the first date anything is required of you is planning to be caught out.
If you are mapping which of your data flows are exposed to this pattern, our resources library covers the notice, consent and minimisation obligations under the Act section by section. For organisations that will need to plug into the consent infrastructure when registration opens on 13 November 2026, our consent manager documentation walks through what the Rule 4 framework will require.
#What individual users can do this week
Three things, none of which require waiting for an app update.
Change your default UPI ID to a username-based VPA rather than your mobile number, in every app you use. Most major apps already support this; the circular makes it the default going forward, but existing users generally have to switch manually.
Check what your apps display after a QR payment. From 4 September the full number should not appear. If it does, that is a reportable gap.
Understand what you have and have not gained. Your number is now harder for a stranger to harvest at a shop counter. It is exactly as available to your payment app, your bank and their partners as it was last week. The DPDP Act is the instrument that will eventually govern that second category, and it does not bind them until 13 May 2027.
#The deadline to actually watch
4 September will tell us something worth knowing. If the large apps ship cleanly on the date, it establishes that a well-drafted circular with a fixed deadline can move Indian digital infrastructure on privacy grounds — a useful precedent for every regulator watching. If the deadline slips, or if apps ship masking on the primary payment screen while leaving numbers visible in receipts, transaction history and support flows, that tells us something too: that compliance in India will default to the visible surface unless someone is empowered to look past it.
Looking past the visible surface is precisely the job the Data Protection Board of India was created to do. Five days out from the country's first real data-minimisation deadline, it still has nobody to do it.
Tracking a DPDP obligation that applies to your business? Start with our resources library for a section-by-section breakdown of the Act and the DPDP Rules 2025.