In a major move to strengthen the security of digital payments, the National Payments Corporation of India (NPCI) has announced new privacy guidelines for UPI users. Banks and UPI service providers will be required to update their platforms to comply with these enhanced privacy standards.
Currently, many UPI applications display users' full mobile numbers or UPI details while sending or receiving payments. This has raised concerns about the misuse of personal information by fraudsters. The issue has become particularly important as incidents of online scams and privacy violations continue to increase.
Under the new guidelines, only the last four digits of a user's mobile number will be visible during UPI transactions. Full mobile numbers will also remain hidden when payments are made by scanning QR codes. In addition, certain account details and UPI identifiers will be masked wherever possible to improve user privacy.
Another significant change relates to UPI IDs (Virtual Payment Addresses - VPA). Instead of creating UPI IDs based on users' mobile numbers, NPCI has advised service providers to offer username-based UPI IDs as the default option for new users. This will further reduce the exposure of personal phone numbers during digital transactions.
Banks and payment service providers have been asked to implement these changes by September 4. The new guidelines are also designed to align with the Digital Personal Data Protection (DPDP) Act, strengthening data privacy and consumer protection in India's rapidly growing digital payments ecosystem.
Officials said the updated rules are intended to enhance user privacy without affecting the speed or convenience of UPI payments. Experts believe these measures will make India's digital payment system more secure and reduce the risk of online fraud.












