UPI Phone Number Masking Went Live on 4 September. The DPDP Act Had Nothing to Do With It.
UPI phone number masking went live 4 September 2026 under an NPCI circular — a DPDP Act Rule 6 control landing 20 months before the law requires it.
#UPI Phone Number Masking Went Live on 4 September. The DPDP Act Had Nothing to Do With It.
Three days ago, on 4 September 2026, roughly 55 crore Indians quietly lost the ability to see each other's full mobile numbers on a UPI transaction. UPI phone number masking is now mandatory across every UPI app and member bank in the country — and it arrived not from the DPDP Act, whose own masking requirement does not bind anyone until 13 May 2027, but from a circular issued by a not-for-profit company that is not a data protection regulator at all.
That gap is the story. India's most consequential data-minimisation mandate to date was delivered by NPCI under payments law, twenty months ahead of the equivalent obligation in the Digital Personal Data Protection Rules, and with none of the enforcement architecture the DPDP Act was supposed to bring with it.
#What the NPCI circular actually requires
The instrument is circular NPCI/UPI/OC-234/2026-27, dated 5 June 2026, titled Safeguarding User Information in UPI. It gave UPI member banks and UPI apps a three-month runway to a hard compliance date of 4 September 2026. Two obligations sit at its core.
First, masking. Sensitive user details — UPI IDs, mobile numbers and account numbers — must be masked across all customer-facing interfaces and communications. In practice, as reported by Business Standard and Business Today, the counterparty to a transaction now sees only the last four digits of a registered mobile number. For QR code payments the full number is not displayed at all, even after the transaction completes.
Second, identifiers. UPI apps must let users create a UPI ID that is not derived from their mobile number, and must allow that alternative handle to be set as the default virtual payment address. Medianama's reading of the circular is that NPCI wants a username, not a phone number, to become the standard payment address for new users.
The stated trigger was not a regulator's audit finding. It was a sustained volume of public complaints — particularly from women — about harassment, identity exposure and personal safety flowing directly from the fact that paying a stranger for a ₹40 auto ride handed them a working phone number.
The scale makes this the largest privacy-motivated interface change in Indian fintech. NPCI's own figures, as reported in early coverage, put UPI at 55.49 crore users as of June 2026, with ₹314.23 lakh crore in transaction value across FY 2025-26.
#The DPDP Act asks for exactly this — in a rule that isn't switched on
Here is what makes the timing awkward. Masking is not a novel idea that NPCI invented. It is written into the DPDP Rules, 2025, almost verbatim.
Rule 6(1)(a) requires every Data Fiduciary to implement "appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data." Rule 6 goes further than the GDPR's Article 32 in one respect: where the European provision speaks generically of "appropriate technical and organisational measures," India's rule names the specific controls — masking among them — and adds a hard requirement under Rule 6(1)(e) to retain access logs and personal data for at least one year for detection and investigation purposes.
The DPDP Act's substantive obligations, Rule 6 included, become enforceable on 13 May 2027. The Consent Manager registration framework opens earlier, on 13 November 2026. Until those dates, Rule 6 is a published requirement with no bite.
So a payments body issued a masking mandate in June, enforced it in September, and covered 55 crore people — while the statutory masking obligation that would have compelled the same outcome sits 20 months out, backed by penalties of up to ₹250 crore for security-safeguard and breach failures that no one can yet levy.
#Who enforced this, and under what authority
NPCI is not a regulator. It is a not-for-profit company incorporated under Section 8 of the Companies Act, 2013 (originally Section 25 of the 1956 Act), set up by the Indian Banks' Association and the Reserve Bank of India under the Payment and Settlement Systems Act, 2007, and owned by a consortium of banks. Its circulars bind UPI participants because participation in UPI is contractual and because the RBI stands behind it — not because Parliament granted it rule-making power over personal data.
The practical consequences of that distinction matter more than the constitutional nicety:
- No data principal rights attach. A user unhappy with how their masked-but-still-collected number is used has no statutory right of access, correction or erasure flowing from this circular. Those rights live in Sections 11 to 13 of the DPDP Act, and they are not yet enforceable.
- No independent adjudicator. Complaints route through bank and app grievance channels, and onward to the RBI's ombudsman scheme — not to the Data Protection Board of India.
- No penalty exposure for the harm. The circular creates a compliance obligation on banks and apps toward NPCI. It creates no monetary liability toward the affected individual.
The Data Protection Board's own status remains murky, which is part of why sectoral bodies keep filling the vacuum. MeitY invited applications for the Chairperson and four Member posts in May 2026, and reporting on whether those appointments have actually been made and taken effect is inconsistent. What every tracker agrees on is the bottom line: no DPDP enforcement action or penalty has been reported to date. Commentators have been blunt that the Board has been established in law but largely absent in fact.
#What masking fixes, and what it conspicuously does not
It would be wrong to dismiss this as theatre. Removing a working phone number from millions of daily merchant-to-customer interactions is a genuine reduction in real-world harm, and it is the kind of change that only a central mandate could achieve — no single app would have moved first and accepted the friction alone.
But masking operates at the display layer, not the collection layer. Nothing in the circular changes what the ecosystem gathers, retains, infers or shares. As Storyboard18 noted in canvassing the reaction, privacy advocates argue that limiting number visibility alone does not address profiling, identity exposure or data sharing within the payments ecosystem — and that it remains unsettled which entities in the UPI chain actually bear responsibility for protecting that data.
Four specific gaps are worth naming:
- Legacy VPAs persist. The mandate makes non-phone-based UPI IDs available and defaults them for new users. It does not retire the hundreds of millions of existing
mobilenumber@bankhandles, each of which still discloses the number in the identifier itself. - Names are still shown in full. Masking covers numbers and account identifiers. The payee's full name remains a visible trust signal — and a full name plus the last four digits of a mobile number is frequently enough to re-identify someone.
- A real fraud trade-off. Users have long relied on the visible number and name to confirm they are paying the right person. Reducing that surface may cut harassment while increasing misdirected transfers and social-engineering scope. The circular does not resolve who carries the loss when that goes wrong.
- Retention is untouched. Under Rule 6(1)(e) a Data Fiduciary will eventually have to keep access logs for a year and justify retention beyond purpose. Payments entities separately face multi-year RBI retention mandates. That collision — one of several unresolved tensions between DPDP and the sectoral regimes — is still ahead.
#What this means for Indian businesses right now
If your business touches UPI, the 4 September date has already changed your operating reality, whether or not anyone in your compliance function logged it.
Merchant reconciliation and support workflows break quietly. Any process that matched a customer to a transaction using a full mobile number pulled from a UPI interface — reconciliation scripts, refund verification, CRM enrichment, support agent lookup screens — is now working from four digits. Teams that patched around this by asking customers to state their number aloud have moved a privacy problem into a call recording.
Marketing pipelines lose an input they were never meant to have. Harvesting payer mobile numbers from payment interfaces to build outreach lists was always poorly grounded under the DPDP Act's purpose limitation. It is now largely foreclosed technically. Anyone whose growth funnel depended on it needs a consent-based substitute, not a workaround.
The direction of travel is now unmistakable for anyone hoping the May 2027 deadline slips. In the space of three weeks, Indian businesses have absorbed the telecom biometric identification regime that took effect on 24 August, tightening breach-notification expectations, and now a sector-wide masking mandate. Sectoral regulators are not waiting for the Data Protection Board, and they are converging on DPDP-shaped controls. The readiness data suggests most firms are not tracking this: an EY survey of over 150 professionals found roughly 71% of Indian enterprises still struggle to interpret the Act and Rules, with fewer than half having begun a gap assessment.
The cost of getting it wrong is rising independently of enforcement. India's average data breach cost hit a record ₹25.5 crore in 2026, per IBM's annual study — a 15.9% year-on-year increase, before a single rupee of DPDP penalty has been imposed.
#The practical read
Treat NPCI's circular as a preview of how Rule 6 will be interpreted, not as an unrelated payments matter. When the Data Protection Board eventually assesses whether a Data Fiduciary took "appropriate data security measures," the fact that an entire national payments system successfully masked identifiers at the display layer in 90 days will be the available benchmark. "Operationally infeasible" became a harder argument to make on 4 September.
Three things are worth doing before 13 May 2027, in this order. Inventory every interface — internal and customer-facing — where a raw phone number, account number or government identifier is rendered in the clear, because Rule 6(1)(a) reaches all of them and not just the payment screen. Decide now whether masking, tokenisation or encryption is the right control for each, since Rule 6 is deliberately technology-neutral and the choice is yours to justify. And separate the display fix from the collection question: masking what a counterparty sees does nothing about data you should not be gathering in the first place.
The DPDP Act's own machinery is still assembling — the Consent Manager registration framework opens 13 November 2026, and full obligations follow six months after that. If you are mapping which of those obligations already apply to you and which are still pending, our resources library tracks the phased commencement dates in detail, and our consent manager guidance covers what the November framework will require of entities planning to register or to integrate with a registered Consent Manager.
The lesson of 4 September is not that the DPDP Act is irrelevant. It is that waiting for the Board to knock is the wrong compliance strategy in a country where the sectoral regulators got there first.
Sources: TeamLease RegTech — NPCI circular NPCI/UPI/OC-234/2026-27 · Business Standard · Business Today · Medianama · Storyboard18 · DPDP Rules 2025, Rule 6 · King Stubb & Kasiva on Rule 6 · LiveLaw on the Data Protection Board · EY readiness survey via BestMediaInfo · IBM breach cost report via Deccan Chronicle