India: Implemented Guidelines on Regulation of Payment Aggregators and Payment Gateways including cybersecurity requirements

Compare with different regulatory event:

Description

Implemented Guidelines on Regulation of Payment Aggregators and Payment Gateways including cybersecurity requirements

On 1 April 2020, the Guidelines on the Regulation of Payment Aggregators (PAs) and Payment Gateways (PGs) issued by the Reserve Bank of India (RBI) were implemented. The Guidelines include a series of technology-related recommendations, which are considered mandatory for PAs and recommended for PGs. The cybersecurity requirements span a variety of sectors, including information security and IT governance, data and cryptography standards, reporting, periodic auditing, risk assessment, vendor risk management, and forensic readiness. Under the Guidelines, the entities are required to implement preventive and detective measures to ensure the security of the stored data.

Original source

Scope

Policy Area
Data governance
Policy Instrument
Cybersecurity regulation
Regulated Economic Activity
digital payment provider (incl. cryptocurrencies)
Implementation Level
national
Government Branch
executive
Government Body
central bank

Complete timeline of this policy change

Hide details
2020-03-17
adopted

On 17 March 2020, the Reserve Bank of India (RBI) adopted the Guidelines on Regulation of Payment A…

2020-04-01
in force

On 1 April 2020, the Guidelines on the Regulation of Payment Aggregators (PAs) and Payment Gateways…