The Bharat Bill Payment System (BBPS) on August 15, 2024, issued a notification regarding the Data Security and Privacy Standard Framework for Credit Card Bill Payment Transactions processed through BBPS.
The circular outlines comprehensive guidelines for the secure handling and processing of customer data in credit card bill payments within the Bharat Bill Payment System (BBPS). It classifies customer data into three categories: Customer-Consented Data, which must be stored in encrypted form with time-bound consent; Customer Sensitive Data, which cannot be stored even in encrypted form; and Non-Personal Data, which can be securely stored and transmitted as per the authorized operating unit's (OU) policies. The guidelines stress that all transactions must be customer-initiated and authenticated, and any bill details retrieved must only be displayed to the customer and purged after the consented duration.
In addition to data handling practices, the circular mandates strict compliance with existing RBI directives, data localization requirements, and relevant laws such as the Digital Personal Data Protection Act, of 2023. It specifies that customer data must be stored within systems owned or controlled by the OU, AI, or Participating AI, with access limited to authorized personnel. The guidelines also require robust security measures such as encryption, data masking, and monitoring to ensure data protection. Moreover, remitter details must be captured and shared with issuers as per the Know Your Customer (KYC) norms to enhance transaction security.
Finally, the circular emphasizes the need for implementing a Unified Payment Management System (UPMS) to prevent sending incorrect payment reminders once a payment has been made. This ensures the integrity of the bill payment process and enhances the safety and reliability of the BBPS ecosystem.
[Notification No. NPCI/2024-25/BBPS/005]