UPI now masks customer identifiers. What businesses should change next.

NPCI's customer-data masking deadline has passed. The immediate task for banks, payment apps, merchants and their vendors is to test every place where a UPI identifier can still appear.

By dotSuper Research DeskPublished Sep 6, 2026Reviewed Sep 6, 20267 min read
Editorial diagram showing mobile number, UPI ID and account number masking across payment interfaces
Image: dotSuper editorial illustration based on NPCI circular OC-234 reporting
Daily briefingNPCI circular summary, official UPI data and reported implementation detailUpdated Sep 6, 2026

/ THE SHORT ANSWER

The change is not a ban on collecting the information required to process a UPI payment. It is a display and communication control. UPI member banks and apps must mask UPI IDs, mobile numbers and account numbers across customer-facing surfaces, and apps must support non-mobile-number UPI IDs. Businesses should now test receipts, histories, notifications, support tools, exports and connected vendors, not only the main payment screen.

Key takeaways
  • 01The reported scope covers UPI IDs, mobile numbers and account numbers on customer-facing interfaces and communications.
  • 02The implementation deadline reported for circular NPCI/UPI/OC-234/2026-27 was 4 September 2026.
  • 03A compliant main payment screen does not prove that receipts, histories, support tools, notifications or exports are compliant.
  • 04Merchants outside the UPI app should review whether they expose or retain the same identifiers in their own systems.
  • 05Masking should be implemented as a reusable data-display policy, not as a collection of screen-specific patches.

/ dotSuper point of view

A masked checkout screen is only the visible layer. The durable response is a field-level policy that controls which identifiers may appear in every interface, message, export and support workflow.

What changed

TeamLease RegTech's summary of NPCI circular NPCI/UPI/OC-234/2026-27 says that UPI member banks and UPI apps must mask UPI IDs, mobile numbers and account numbers across customer-facing interfaces and communications. It also says apps must let users create non-mobile-number-based UPI IDs and set them as the default. The reported implementation deadline was 4 September 2026.

Moneycontrol reported more implementation detail: only the last four digits of a mobile number should remain visible to the other party, while a mobile number should not be displayed after a QR-code payment. Its report also connects the change to concerns about strangers using payment-visible numbers for unsolicited contact and harassment.

This does not mean a bank or app can stop processing the identifiers needed to route, reconcile, secure or support a transaction. The immediate requirement concerns what is exposed on customer-facing surfaces. That distinction matters because a team can reduce display risk while still preserving the controlled data needed for legitimate operational purposes.

  • Identify every customer-facing screen, message and document that can render a UPI ID, mobile number or account number.
  • Confirm the approved masking format for each identifier and interaction type.
  • Ensure username-style UPI IDs are available and can become the user's default identifier.

Why it matters to businesses

For a bank or UPI app, the risk is distributed across more than checkout. Transaction history, downloadable statements, push notifications, SMS, email, dispute journeys, support consoles and internal tools can all repeat an identifier. Fixing one visible screen while leaving a receipt or support transcript unchanged creates an inconsistent control and a poor customer experience.

For merchants, marketplaces and software vendors, the circular may not map onto every downstream system in the same way. The practical privacy risk still travels with the data. A merchant receipt, CRM note, help-desk ticket, analytics event or exported reconciliation file can expose the same customer identifier even after the payment app masks it. Businesses should therefore distinguish what the NPCI rule directly requires from the broader data-minimisation choice they should make themselves.

The official NPCI statistics page reported 22.7 billion UPI transactions in June 2026 across 731 live banks. At that scale, a small interface disclosure becomes a repeated systems issue. It also makes manual checking insufficient. Teams need test cases, ownership and evidence that the control works across channels and releases.

A practical exposure map
Business surfaceWhat to inspectEvidence to retain
Payment interfaceConfirmation, history, favourites and QR flowsTest captures by identifier and transaction type
Customer communicationSMS, email, push notifications and receiptsApproved templates and rendered examples
Support operationsAgent console, tickets, chat transcripts and exportsRole-based views and access logs
Data and analyticsEvent payloads, dashboards, recordings and debugging toolsField inventory, retention rule and masking test
Connected vendorsGateways, CRM, messaging, fraud and observability toolsData-flow record and vendor confirmation

What to do next

Start with an identifier inventory, not a visual redesign. List every field that can contain a mobile number, UPI ID or account number, then map where it is collected, stored, displayed, transmitted and exported. Assign a purpose and an owner to each occurrence. This shows which exposures are required for an authorised operational task and which remain visible by habit.

Create one masking policy that applications and vendors can consume. The policy should specify the identifier type, audience, interaction, permitted reveal pattern, logging behaviour and exception process. Then test it through automated interface checks and a small manual audit that includes edge cases such as failed payments, refunds, disputes, screenshots and downloaded files.

Finally, review the full payment-data journey with legal, product, security, customer support and operations together. The most important gap may sit outside the UPI application itself. Record direct compliance obligations separately from voluntary privacy improvements, then track both through a dated remediation plan.

  • Run a same-week audit across screens, messages, support workflows, analytics and exports.
  • Block full identifiers from session recordings, error tools and customer-support transcripts unless a controlled purpose requires them.
  • Add regression tests for masking before every payment-interface release.
  • Give customers a clear path to a non-mobile-number UPI ID where the product controls that experience.
  • Escalate uncertainties about the circular's exact application to qualified payments and privacy counsel.

What this page cannot conclude

  • 01This briefing relies on a legal-update summary and contemporaneous reporting because the official circular file was not reliably accessible through NPCI's public web interface during review.
  • 02It is operational guidance, not a legal opinion or a determination of whether a specific business is directly bound by the circular.
  • 03Masking reduces exposure on customer-facing surfaces. It does not by itself change collection, retention, access or downstream sharing of the underlying data.
  • 04Individual banks and applications may implement approved masking patterns differently. Teams should check the circular, membership obligations and current NPCI guidance that apply to them.

Sources

  1. 01NPCI issued circular on Safeguarding User Information in UPITeamLease RegTech · accessed Sep 6, 2026
  2. 02NPCI wants phone numbers masked, talks on with banks, UPI apps to improve privacyMoneycontrol · accessed Sep 6, 2026
  3. 03Unified Payments Interface product statisticsNational Payments Corporation of India · accessed Sep 6, 2026
  4. 04Unified Payments Interface overviewNational Payments Corporation of India · accessed Sep 6, 2026

Our editorial standard · Found an error? Send a correction with its source.

MAP THE DATA BEFORE PATCHING THE SCREENUPI now masks customer identifiers. What businesses should change next.

/ APPLY THE THINKING

Turn one privacy requirement into an inspectable operating control.

dotSuper can help your team map the workflow, identify exposure points, define ownership and scope the smallest useful remediation sprint.

Question for the working sessionWhat does NPCI's UPI masking requirement change for businesses that build, operate or depend on digital payment journeys?

/ Topic-led working session · UPI now masks customer identifiers. What businesses should change next.

Turn this question\ninto a useful first move.

Bring how this question currently shows up in your business: “What does NPCI's UPI masking requirement change for businesses that build, operate or depend on digital payment journeys?” We’ll test the page’s evidence against your context and define the smallest useful next move.

Live availability from ceo@dotsuper.net Your time zone · Local time
  1. 01Bring the contextWhere this issue shows up in the work.
  2. 02Test the relevanceUse the evidence against your reality.
  3. 03Choose the next moveOne accountable action, clearly owned.
Live availability
  1. Date
  2. Time
  3. Booked

Syncing live times