/ THE SHORT ANSWER
The change is not a ban on collecting the information required to process a UPI payment. It is a display and communication control. UPI member banks and apps must mask UPI IDs, mobile numbers and account numbers across customer-facing surfaces, and apps must support non-mobile-number UPI IDs. Businesses should now test receipts, histories, notifications, support tools, exports and connected vendors, not only the main payment screen.
- 01The reported scope covers UPI IDs, mobile numbers and account numbers on customer-facing interfaces and communications.
- 02The implementation deadline reported for circular NPCI/UPI/OC-234/2026-27 was 4 September 2026.
- 03A compliant main payment screen does not prove that receipts, histories, support tools, notifications or exports are compliant.
- 04Merchants outside the UPI app should review whether they expose or retain the same identifiers in their own systems.
- 05Masking should be implemented as a reusable data-display policy, not as a collection of screen-specific patches.
/ dotSuper point of view
A masked checkout screen is only the visible layer. The durable response is a field-level policy that controls which identifiers may appear in every interface, message, export and support workflow.
What changed
TeamLease RegTech's summary of NPCI circular NPCI/UPI/OC-234/2026-27 says that UPI member banks and UPI apps must mask UPI IDs, mobile numbers and account numbers across customer-facing interfaces and communications. It also says apps must let users create non-mobile-number-based UPI IDs and set them as the default. The reported implementation deadline was 4 September 2026.
Moneycontrol reported more implementation detail: only the last four digits of a mobile number should remain visible to the other party, while a mobile number should not be displayed after a QR-code payment. Its report also connects the change to concerns about strangers using payment-visible numbers for unsolicited contact and harassment.
This does not mean a bank or app can stop processing the identifiers needed to route, reconcile, secure or support a transaction. The immediate requirement concerns what is exposed on customer-facing surfaces. That distinction matters because a team can reduce display risk while still preserving the controlled data needed for legitimate operational purposes.
- Identify every customer-facing screen, message and document that can render a UPI ID, mobile number or account number.
- Confirm the approved masking format for each identifier and interaction type.
- Ensure username-style UPI IDs are available and can become the user's default identifier.
Why it matters to businesses
For a bank or UPI app, the risk is distributed across more than checkout. Transaction history, downloadable statements, push notifications, SMS, email, dispute journeys, support consoles and internal tools can all repeat an identifier. Fixing one visible screen while leaving a receipt or support transcript unchanged creates an inconsistent control and a poor customer experience.
For merchants, marketplaces and software vendors, the circular may not map onto every downstream system in the same way. The practical privacy risk still travels with the data. A merchant receipt, CRM note, help-desk ticket, analytics event or exported reconciliation file can expose the same customer identifier even after the payment app masks it. Businesses should therefore distinguish what the NPCI rule directly requires from the broader data-minimisation choice they should make themselves.
The official NPCI statistics page reported 22.7 billion UPI transactions in June 2026 across 731 live banks. At that scale, a small interface disclosure becomes a repeated systems issue. It also makes manual checking insufficient. Teams need test cases, ownership and evidence that the control works across channels and releases.
| Business surface | What to inspect | Evidence to retain |
|---|---|---|
| Payment interface | Confirmation, history, favourites and QR flows | Test captures by identifier and transaction type |
| Customer communication | SMS, email, push notifications and receipts | Approved templates and rendered examples |
| Support operations | Agent console, tickets, chat transcripts and exports | Role-based views and access logs |
| Data and analytics | Event payloads, dashboards, recordings and debugging tools | Field inventory, retention rule and masking test |
| Connected vendors | Gateways, CRM, messaging, fraud and observability tools | Data-flow record and vendor confirmation |
What to do next
Start with an identifier inventory, not a visual redesign. List every field that can contain a mobile number, UPI ID or account number, then map where it is collected, stored, displayed, transmitted and exported. Assign a purpose and an owner to each occurrence. This shows which exposures are required for an authorised operational task and which remain visible by habit.
Create one masking policy that applications and vendors can consume. The policy should specify the identifier type, audience, interaction, permitted reveal pattern, logging behaviour and exception process. Then test it through automated interface checks and a small manual audit that includes edge cases such as failed payments, refunds, disputes, screenshots and downloaded files.
Finally, review the full payment-data journey with legal, product, security, customer support and operations together. The most important gap may sit outside the UPI application itself. Record direct compliance obligations separately from voluntary privacy improvements, then track both through a dated remediation plan.
- Run a same-week audit across screens, messages, support workflows, analytics and exports.
- Block full identifiers from session recordings, error tools and customer-support transcripts unless a controlled purpose requires them.
- Add regression tests for masking before every payment-interface release.
- Give customers a clear path to a non-mobile-number UPI ID where the product controls that experience.
- Escalate uncertainties about the circular's exact application to qualified payments and privacy counsel.
What this page cannot conclude
- 01This briefing relies on a legal-update summary and contemporaneous reporting because the official circular file was not reliably accessible through NPCI's public web interface during review.
- 02It is operational guidance, not a legal opinion or a determination of whether a specific business is directly bound by the circular.
- 03Masking reduces exposure on customer-facing surfaces. It does not by itself change collection, retention, access or downstream sharing of the underlying data.
- 04Individual banks and applications may implement approved masking patterns differently. Teams should check the circular, membership obligations and current NPCI guidance that apply to them.
Sources
- 01NPCI issued circular on Safeguarding User Information in UPITeamLease RegTech · accessed Sep 6, 2026
- 02NPCI wants phone numbers masked, talks on with banks, UPI apps to improve privacyMoneycontrol · accessed Sep 6, 2026
- 03Unified Payments Interface product statisticsNational Payments Corporation of India · accessed Sep 6, 2026
- 04Unified Payments Interface overviewNational Payments Corporation of India · accessed Sep 6, 2026
Our editorial standard · Found an error? Send a correction with its source.