In a circular issued, the Reserve Bank of India (RBI), instructed all parties—aside from card networks and card issuers—to delete all previously stored Card-on-File (CoF) data by-
Correct Answer :
October 1, 2022
Solution :
The correct option/answer is October 1, 2022.
Step-by-Step Explanation:
1. Concept of Card-on-File (CoF) Data: Card-on-File refers to the practice where merchants, payment aggregators, and payment gateways store customers' card details (such as card number, cardholder name, and expiry date) to facilitate faster checkouts for future transactions.
2. RBI Security Mandate: To enhance the security of online card transactions and safeguard consumer financial data from cyber threats and data breaches, the Reserve Bank of India (RBI) introduced guidelines stating that no entity other than card networks and card issuers can store actual card data.
3. Tokenisation Alternative: Instead of storing actual card details, merchants and payment providers were mandated to adopt "tokenisation," which replaces sensitive card data with a unique, encrypted code called a "token."
4. Deadline Extensions and Final Date: The initial timeline for purging CoF data was extended multiple times by the RBI to allow stakeholders and merchants sufficient time to build and test their tokenisation systems. The final deadline mandated by the RBI for deleting all stored CoF data and moving to the tokenised framework was set for September 30, 2022. Consequently, all stored card details had to be purged by October 1, 2022.
Access expert-curated educational resources and study materials—completely free.
Create, conduct, and manage professional online assessments with Mindyard. Perfect for teachers and institutes.
Copyright © 2026 Mindyard. All Rights Reserved.