PhonePe Payment Gateway
Article

What Is GDPR Compliance and How DPDP Affects Your Payment Gateway

PhonePe PG Team
Published: 
Last Modified: 
4 min read

Highlights:

  • Understand GDPR and DPDP Act requirements for protecting customer payment data stored by your payment gateway
  • Learn RBI's data localisation mandate and card storage restrictions that apply to all Indian merchants
  • Discover penalty structures, GDPR fines reach 4% of revenue, DPDP imposes fixed ₹250 crore caps
  • Follow actionable compliance steps, including PCI DSS verification, tokenisation checks, and breach notification procedures

Introduction

Every online transaction leaves behind more than just a payment confirmation. It creates a trail of personal data: names, phone numbers, email addresses, billing addresses, IP details, and sometimes even behavioural data. For businesses using a payment gateway (PG), protecting this customer data is no longer just a security best practice. It is a legal obligation.

If your payment gateway stores or processes customer information, your business may need to comply with both the European Union’s General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection (DPDP) framework. Even if your company is based in India, GDPR may apply if you handle data from EU customers.

Understanding these regulations is essential. Compliance reduces legal risk, strengthens customer trust, and demonstrates responsible data governance.

What is GDPR?

The General Data Protection Regulation, or GDPR, is a European Union (EU) law that governs how organisations within and outside the EU handle the personal data of EU residents. GDPR was adopted by the European Parliament and Council of the EU in 2016 and took effect on 25 May 2018.

Specifically, GDPR

  • defines legally approved ways to transfer and process personal data;
  • details how organisations must protect personal data at rest and in transit; and
  • establishes EU residents' rights over personal data collection, use and possession.

GDPR defines personal data as any information relating to an identifiable human being, including direct and indirect identifiers. Direct identifiers are a person's unique data points, like their name or credit card number. Indirect identifiers include non-unique traits that can still identify a person, like physical characteristics and dates of birth.  

In GDPR parlance, a data subject is the person a piece of data is about. For example, if a company collects email addresses, the owners of those addresses would be the data subjects. 

While GDPR is a European law, it has a global reach. It applies to any organisation anywhere that collects or uses the personal data of EU residents.

What is DPDP?

DPDP stands for Digital Personal Data Protection.

It refers to India’s Digital Personal Data Protection Act, 2023 (DPDP Act), which is India’s main law for regulating how organisations collect, use, store, and protect personal data in digital form.

The law was introduced to give individuals more control over their personal data and to make businesses more accountable for handling that data responsibly.

In simple terms, what is DPDP?

DPDP sets rules for how companies, websites, apps, and service providers can collect and process personal information, such as:

  • Name
  • Phone number
  • Email address
  • Address
  • Payment details
  • IP address
  • Any other information that can identify a person

If a business collects this type of data digitally, it may need to comply with the DPDP Act.

Why Payment Gateways Need Special Attention

Payment gateways require special attention under GDPR and India's DPDP Act 2023 because they process massive volumes of highly sensitive financial and personal data, making them prime targets for cyberattacks. Both frameworks prioritise explicit consent and strict data handling, with India’s DPDP creating a "processing-centric" regime that holds fintechs strictly accountable, while GDPR imposes heavy global turnover penalties.

Key Reasons for Special Attention:

  • High-Risk Data Handling: Payment gateways manage personal data, financial information, and transaction history, which must be protected through strict security measures, data minimisation, and privacy-by-design principles, as reflected in the security and compliance practices of PhonePe.
  • Stringent Consent Mechanisms: Unlike GDPR, which allows for various legal bases, the DPDP Act makes informed, specific consent the primary requirement, demanding complex, per-transaction consent for swift digital payments.
  • Data Localisation (DPDP): Indian regulations require end-to-end transaction data to be stored within India, demanding strict control over data flows.
  • Severe Penalties: DPDP penalties can reach ₹250 crores (~₹30 million) for breaches, while GDPR allows fines up to 4% of annual global turnover.
  • Interplay of Multiple Regulations: Payment gateways must navigate DPDP simultaneously with existing RBI regulations on cybersecurity and data storage.

Differences in Compliance Focus (GDPR vs DPDP):

  • Consent: While both regulations focus on consent, the DPDP Act (2023) prioritises consent as the primary mechanism, making it more challenging to rely on "legitimate interest".
  • Definitions: DPDP often has a broader definition of personal data, including pseudonymized data.
  • Data Principal Rights: Both regulations empower users to access, erase, and correct their data, with DPDP requiring rapid response mechanisms from data fiduciaries.

Practical Steps to Ensure GDPR and DPDP Compliance

Ensuring compliance with GDPR and India's DPDPA involves auditing data, mapping flows, updating consent mechanisms, and implementing security measures like encryption. Key steps include appointing a Data Protection Officer (DPO), managing subject rights requests, and ensuring third-party contracts are updated to meet legal requirements.

Practical Steps for Compliance (2026 Focus)

  • Data Discovery and Mapping: Conduct audits to classify personal data, identifying where it is collected, stored, and shared.
  • Implement Data Subject Rights Procedures: Establish systems to handle requests for access, correction, or deletion (erasure) within mandatory deadlines.
  • Revamp Consent Mechanisms: Ensure consent is freely given, specific, informed, and easy to withdraw (opt-in/opt-out).
  • Appoint a Data Protection Officer (DPO): Designate a DPO to oversee compliance, especially for significant data fiduciaries under DPDPA.
  • Strengthen Cybersecurity Measures: Utilise encryption and pseudonymization for data at rest and in transit.
  • Update Third-Party Vendor Contracts: Ensure data processing agreements (DPAs) are in place, particularly for cross-border transfers.
  • Data Retention and Deletion Policies: Define retention periods and set up automated deletion for data that is no longer necessary.
  • Employee Training: Build a privacy-first culture by training staff on data protection obligations.

Key Compliance Differences: GDPR vs DPDP for Payment Data

Compliance AreaGDPR (EU)DPDP (India)
Scope of data coveredPersonal data, including online identifiers and payment-related metadataDigital personal data only, covering data collected or digitised electronically
Who it protectsIndividuals in the European UnionIndividuals in India
Business role is defined asData Controller / Data ProcessorData Fiduciary / Data Processor
Consent requirementsMust be freely given, specific, informed, and explicit in many casesMust be clear, informed, and affirmative
Legal basis beyond consentMultiple legal bases, such as contract, legal obligation, legitimate interestPrimarily consent-based, with certain legitimate uses allowed
Data subject rightsAccess, correction, deletion, portability, restriction, objectionAccess, correction, erasure, grievance redressal, consent withdrawal
Breach notificationMandatory notification to the supervisory authority within 72 hours in many casesNotification required to the Data Protection Board and affected individuals as prescribed
Cross-border data transferAllowed under strict adequacy and safeguard mechanismsAllowed except for countries restricted by the Indian government
Children’s dataSpecial protections, parental consent under age thresholdsStrong protections, verifiable parental consent required for minors
PenaltiesUp to €20 million or 4 per cent of global annual turnoverFinancial penalties under the DPDP Act, depending on the violation

Key Takeaways for Compliance-Focused Merchants

Payment gateway compliance isn't a one-time checklist; it's an ongoing obligation requiring vigilance as regulatory frameworks evolve. With DPDP core requirements effective May2027, Indian merchants have less than one year to implement consent mechanisms, breach notification protocols, and data security safeguards. Verify your payment gateway's RBI datalocalisationcompliance, PCI DSS certification, and tokenisation implementation now before regulatory deadlines arrive.

FAQs

What is GDPR, and does it apply to my Indian business?

GDPR is the EU's data protection law, effective May2018. If your business processes payment data from EU customers, even if the India-based GDPR applies. An Indian merchant shipping to Germany must comply when storing EU customer card details via a payment gateway.

What is India's DPDP Act, and when does it take effect?

India's Digital Personal Data Protection Act was enacted in August2023, with core compliance requirements effective May 13, 2027. It governs how Indian businesses collect, store, and process customer payment data digitally. All merchants using payment gateways must comply with this deadline.

What is the difference between GDPR and DPDP compliance for payment gateways?

GDPRcovers all personal data and requires multiple legal bases for processing, with penalties up to 4% of global revenue.DPDPcovers only digital personal data, relies primarily on consent, and imposes fixed penalties up to ₹250 crore. Indian merchants processing EU payments must comply with both frameworks simultaneously.

Can my payment gateway store customer card details in India?

No. RBI's June2022circular prohibits payment gateways and merchants from storing actual card numbers. Only card issuers and networks can store card details. Your gateway must use RBI-approved tokenisation, replacing card numbers with secure tokens for saved card features.

What is GDPR, and does it apply to my Indian business?

GDPR is the EU's data protection law, effective May2018. If your business processes payment data from EU customers, even if the India-based GDPR applies. An Indian merchant shipping to Germany must comply when storing EU customer card details via a payment gateway.

Sign up for PhonePe Payment Gateway now and start accepting payments instantly

Sign up for PhonePe Payment Gateway

  • check iconEasy Onboarding
  • check iconDeveloper friendly APIs
  • check icon24/7 Support
Footer Banner