NPCI Tightens UPI Privacy Norms, Directs Apps to Mask Mobile Numbers from September

NPCI has asked UPI apps and partner banks to hide cellphone numbers and other personal details to strengthen user privacy starting September 4. The action is in line with the Digital Personal Data Protection Act and strives to minimise risks of privacy and identity theft.

NPCI tightens UPI privacy norms, directs apps to mask mobile numbers from September
NPCI tightens UPI privacy norms, directs apps to mask mobile numbers from September

The operator of India's payment and settlement systems is pushing for more robust protections for users' personal information across all of the background-working apps and partner institutions. The primary motivation behind this move by the National Payments Corporation of India (NPCI), the entity responsible for running UPI, is the aim to ensure the security of consumer data. The most widely used digital payment system in the country is UPI.

Talks have been kicked off by the NPCI with partner banks and the developers of UPI-based applications. The goal of these meetings was to hasten the implementation of the data security standards mandated by the Digital Personal Data Protection legislation. The NPCI has reportedly already mandated the masking of phone numbers on these apps as a customer safety measure. The decision to disguise mobile phone numbers was based on concerns about privacy risks associated with the UPI system, which uses these numbers to generate and validate payments.

Why NPCI is Opting for Masking the Phone Numbers?

In an effort to safeguard user information and prevent unauthorised access, the payments company issued a formal statement last month requiring mobile apps to mask users' phone numbers. This move was in response to multiple social media concerns from women who were worried about the security of their personal information and the possibility of identity theft.

It appears that the NCPI has established September 4 as the deadline for implementing the necessary technological modifications. The message is loud and clear: both the banks that are part of UPI and the app developers need to make sure that users' personal information, including UPI IDs, mobile numbers, and bank account numbers, stays hidden whenever they interact with the service. When a consumer completes a purchase using a QR code at a vendor point, the provider should only see the last four digits of their mobile phone number. After a transaction is finalised, the NCPI has stated that the apps should not show the phone numbers.

Other Security Features Mandated by NCPI

In addition, the NPCI's circular emphasised that moving forward, apps using UPI as their backend should provide consumers the choice to have identities that aren't tied to their cell numbers. It would be even better if they could make these non-mobile IDs their default. At the moment, users' mobile numbers are chosen as the default virtual private addresses (VPAs) when they set up UPI. Though it has always been available, the majority of users are unaware that they have the option to choose a username.

The most recent circular, however, stresses that a username, not a mobile number, should be the default. Since its inception in 2016, UPI transactions have experienced tremendous growth. There were 55.49 crore users as of June 2026, according to a recent statement by Pankaj Chaudhary, the federal minister of state for finance, who made the announcement in Parliament. In 2021–22, transactions totalled INR 84.16 lakh crore; in 2025–26, they reached INR 314.23 lakh crore.