(Updated as on April 04, 2019)
Q.1 What is tokenisation?
Ans. Tokenisation refers to replacement of actual card details with an alternate code called the “token”, which shall be unique for a combination of card, token requestor and device (referred hereafter as “identified device”).
Q.2 What is de-tokenisation?
Ans. Conversion of the token back to actual card details is known as de-tokenisation.
Q.3 What is the benefit of tokenisation?
Ans. A tokenised card transaction is considered safer as the actual card details are not shared with the merchant during transaction processing.
Q.4 What are the charges that the customer need to pay for availing this service?
Ans. The customer need not pay any charges for availing this service.
Q.5 What are the use cases (instances / scenarios) for which tokenisation has been allowed?
Ans. Tokenisation has been allowed through mobile phones and / or tablets for all use cases / channels (e.g., contactless card transactions, payments through QR codes, apps etc.
Q.6 Can tokenisation be enabled through a smart watch or such other devices?
Ans. The feature of tokenisation is restricted to mobile phones and / or tablets only.
Q.7 Who can perform tokenisation and de-tokenisation?
Ans. Tokenisation and de-tokenisation can be performed only by the authorised card network. The list of card networks authorised by RBI to operate in India is available on RBI website at the link https://www.rbi.org.in/Scripts/PublicationsView.aspx?id=12043.
Q.8 Who are the parties/stakeholders in a tokenisation transaction?
Ans. Normally, in a tokenised card transaction, parties / stakeholders involved are merchant, the merchant’s acquirer, card payment network, token requestor, issuer and customer. However, an entity, other than those indicated, may also participate in the transaction.
Q.9 Are the customer card details safe after tokenisation?
Ans. Actual card data, token and other relevant details are stored in a secure mode by the authorised card networks. Token requestor cannot store Primary Account Number (PAN), i.e., card number, or any other card detail. Card networks are also mandated to get the token requestor certified for safety and security that conform to international best practices / globally accepted standards.
Q.10 Is tokenisation of card mandatory for a customer?
Ans. No, a customer can choose whether or not to let his / her card tokenised.
Q.11 Does the customers have the option to select tokenisation for a particular use case?
Ans. Customers have the option to register / de-register their card for a particular use case, i.e., contactless, QR code based, in-app payments, etc.
Q.12 How does the process of registration for a tokenisation request work?
Ans. The registration for a tokenisation request is done only with explicit customer consent through Additional Factor of Authentication (AFA), and not by way of a forced / default / automatic selection of check box, radio button, etc. Customer will also be given choice of selecting the use case and setting-up of limits.
Q.13 Can the customer set / select own limits for tokenised card transactions?
Ans. Customers have the option to set and modify per transaction and daily transaction limits for tokenised card transactions.
Q.14 Is there any limit on the number of cards that a customer can request for tokenisation?
Ans. A customer can request for tokenisation of any number of cards. For performing a transaction, the customer shall be free to use any of the cards registered with the token requestor app.
Q.15 Can the customer select which card to be used in case he / she has more than one card tokenised?
Ans. For performing any transaction, the customer shall be free to use any of the cards registered with the token requestor app.
Q.16 Is there any limit on the number of devices on which a card can be tokenised?
Ans. A customer can request for tokenisation of his / her card on any number of devices. However, as of now, this facility shall be offered through mobile phones / tablets only.
Q.17 Whom shall the customer contact in case of any issues with his / her tokenised card? Where and how can he / she report loss of device?
Ans. All complaints should be made to the card issuers. Card issuers shall ensure easy access to customers for reporting loss of “identified device” or any other such event which may expose tokens to unauthorised usage.
Q.18 Can a card issuer refuse tokenisation of a particular card?
Ans. Based on risk perception, etc., card issuers may decide whether to allow cards issued by them to be registered by a token requestor.
Q.19 Where can more information on RBI instructions on tokenisation be found?
Ans. The circular issued by RBI on tokenisation is available on the RBI website at the path https://www.rbi.org.in/scripts/FS_Notification.aspx?Id=11449&fn=9&Mode=0.
These FAQs are issued by the Reserve Bank of India for information and general guidance purposes only. The Bank will not be held responsible for actions taken and / or decisions made on the basis of the same. For clarifications or interpretations, if any, one may be guided by the relevant circulars and notifications issued from time to time by the Bank.