India bans Mastercard from signing up new customers
(2021/07/15)
- Reference: 1626315308
- News link: https://www.theregister.co.uk/2021/07/15/india_mastercard_ban/
- Source link:
India’s Reserve Bank yesterday barred credit card giant Mastercard from signing up any new customers in the nation.
A [1]notice from the bank said Mastercard “has been found to be non-compliant with the directions on Storage of Payment System Data”.
Those directions were issued in April 2018, and gave banks and payment systems a deadline of October 15, 2018, to “ensure that the entire data relating to payment systems operated by them are stored in a system only in India”.
[2]
The directive required full end-to-end transaction details and all “information collected/carried/processed as part of the message/payment instruction” to be stored in India. Portions of data describing the offshore parts of cross-border transactions were allowed to be stored outside India.
[3]Jailed for seven years: Cyber-crook who broke into Big Biz to steal bank card info for FIN7 super-gang
[4]Xiaomi and NXP ride a bus to Moscow with a wearable Mastercard
[5]From Libra to leave-ya: eBay, Visa, Stripe, PayPal, others flee Facebook's crypto-coin
[6]NASSCOM shakeup: Accenture's Rehka Menon becomes first woman to chair Indian IT trade org
The Reserve Bank had a bit of a crack at Mastercard in its notice:
Notwithstanding lapse of considerable time and adequate opportunities being given, the entity has been found to be non-compliant with the directions on Storage of Payment System Data.
Mastercard told The Register it is "fully committed to our legal and regulatory obligations in the markets we operate in" and has "provided consistent updates" to the Reserve Bank of India since 2018.
"While we are disappointed with the stance taken by the RBI in their communication dated July 14, we will continue to work with them to provide any additional details required to resolve their concerns."
[7]
Mastercard is, at least, not alone in having failed the Reserve Bank’s test – American Express and Diners Club copped a similar notice in [8]April 2021 . However The Register cannot find evidence that any local bank or payment system has found itself in trouble. ®
Get our [9]Tech Resources
[1] https://www.rbi.org.in/Scripts/BS_PressReleaseDisplay.aspx?prid=51895
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YO@y7Hml@IiM3bH5Qw11FwAAAM4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/06/25/ukranian_fin7_pentest/
[4] https://www.theregister.com/2020/06/19/xiaomi_mastercard_wearable_russia/
[5] https://www.theregister.com/2019/10/11/from_libra_to_leaveya/
[6] https://www.theregister.com/2021/04/23/rehka_menon_nasscom_chairperson/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YO@y7Hml@IiM3bH5Qw11FwAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://rbi.org.in/scripts/BS_PressReleaseDisplay.aspx?prid=51471
[9] https://whitepapers.theregister.com/
A [1]notice from the bank said Mastercard “has been found to be non-compliant with the directions on Storage of Payment System Data”.
Those directions were issued in April 2018, and gave banks and payment systems a deadline of October 15, 2018, to “ensure that the entire data relating to payment systems operated by them are stored in a system only in India”.
[2]
The directive required full end-to-end transaction details and all “information collected/carried/processed as part of the message/payment instruction” to be stored in India. Portions of data describing the offshore parts of cross-border transactions were allowed to be stored outside India.
[3]Jailed for seven years: Cyber-crook who broke into Big Biz to steal bank card info for FIN7 super-gang
[4]Xiaomi and NXP ride a bus to Moscow with a wearable Mastercard
[5]From Libra to leave-ya: eBay, Visa, Stripe, PayPal, others flee Facebook's crypto-coin
[6]NASSCOM shakeup: Accenture's Rehka Menon becomes first woman to chair Indian IT trade org
The Reserve Bank had a bit of a crack at Mastercard in its notice:
Notwithstanding lapse of considerable time and adequate opportunities being given, the entity has been found to be non-compliant with the directions on Storage of Payment System Data.
Mastercard told The Register it is "fully committed to our legal and regulatory obligations in the markets we operate in" and has "provided consistent updates" to the Reserve Bank of India since 2018.
"While we are disappointed with the stance taken by the RBI in their communication dated July 14, we will continue to work with them to provide any additional details required to resolve their concerns."
[7]
Mastercard is, at least, not alone in having failed the Reserve Bank’s test – American Express and Diners Club copped a similar notice in [8]April 2021 . However The Register cannot find evidence that any local bank or payment system has found itself in trouble. ®
Get our [9]Tech Resources
[1] https://www.rbi.org.in/Scripts/BS_PressReleaseDisplay.aspx?prid=51895
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YO@y7Hml@IiM3bH5Qw11FwAAAM4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2021/06/25/ukranian_fin7_pentest/
[4] https://www.theregister.com/2020/06/19/xiaomi_mastercard_wearable_russia/
[5] https://www.theregister.com/2019/10/11/from_libra_to_leaveya/
[6] https://www.theregister.com/2021/04/23/rehka_menon_nasscom_chairperson/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/storage&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YO@y7Hml@IiM3bH5Qw11FwAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://rbi.org.in/scripts/BS_PressReleaseDisplay.aspx?prid=51471
[9] https://whitepapers.theregister.com/
No local issues?
D. Evans
Why would a local financial institution have issues with data being sent outside of India since most IT outsources are in India. Oh wait....
I hope nobody is implying a cloud endpoint in the US constitutes data traveling outside of India. :-)
Anonymous Coward
Similarly I hope US data is not being subject to leakage by being accessible in India. For example it could lead to criminals posing as support personnel to execute confidence scams.
That's how you do it
I love nations that hold giant corporations' feet to the fire.