Home You are here : path  Digital Banking path Cards path FAQs on Tokenisation Modified

debit-card   FAQs on Tokenisation

As per RBI mandate, starting from 1st October, 2022 clear card number, CVV, card expiry date and any other sensitive information related to cards cannot be stored by merchants for processing online transactions and card number will be replaced by a Token to be generated online through algorithm process. The entire process is called Tokenisation. We are listing below the FAQs for the benefit of understanding of our Bank customers.

The following are the FAQs for the benefit and awareness of our Bank’s customers.

  1. Q 1.What is tokenisation?

Answer: Tokenisation refers to replacement of actual or clear card number with an alternate code called the “Token”. This shall be unique for a combination of card, token requestor (i.e., the entity which accepts request from the customer for tokenisation of a card and passes it on to the card network to issue a corresponding token) and the merchant (token requestor and merchant may or may not be the same entity).

  1. Q 2.Where will these tokens get used?

Answer: Once created, the tokenised card details will be used in place of an actual card number for future online purchases initiated or instructed by the card holder.

  1. Q 3.What is the benefit of tokenisation?

Answer: A tokenised card transaction is considered safer as the actual card details are not shared / stored with the merchants to perform the transaction.

  1. Q 4.How can the tokenisation be carried out and what are the steps involved?


Answer:

  • Step 1 – The card holder can get the card tokenised by initiating a request on the website/app provided by the token requestor and any such similar facility provided by the merchant.
  • Step 2 – The token requestor / merchant will forward the request directly to the Bank which has issued the applicable card or to VISA / Mastercard / RuPay, with the consent of the card issuing Bank.
  • Step 3 – The party receiving the request from token requester, will issue a token corresponding to the combination of the card, the token requestor and the merchant.
  1. Q 5.Is the tokenisation guideline applicable for both Debit and Credit cards?

Answer: Yes. Starting 1st, October 2022, both Debit and Credit cards have to be Tokenised.

  1. Q 6.Is Tokenisation applicable for International Card-on-File transactions?

Answer: No. Tokenisation is applicable only for Domestic transactions.

  1. Q 7.How can I manage my tokenised cards?

Answer: Bank will provide a portal to the card holders to view and manage the tokenised cards. Card holders can view / delete tokens for the respective cards through the portal provided.

  1. Q 8.Will tokenisation have any impact on the PoS transactions that the card holder does at merchant outlets?

Answer: No. Tokenisation is only required for carrying out the online transactions.

  1. Q 9.What are the charges that the cardholder needs to pay for availing this tokenization service?

Answer: The customer need not pay any charges for availing the service of tokenising the card.

  1. Q 10.Who can perform tokenisation and de-tokenisation?

Answer: Tokenisation and de-tokenisation can be performed only by the card issuing Bank or VISA / Mastercard / RuPay, who are referred as authorised card networks.

  1. Q 11.Are the customer’s card details safe, after tokenisation?

Answer: Actual card data, token and other relevant details are stored in a secure encrypted mode by the card issuing Bank and / or authorised card networks. Token requestor / merchants cannot store full card number or any other card details.

  1. Q 12.Is tokenisation of card mandatory for a customer?

Answer: No. A customer can choose whether or not to let his / her card tokenised. If not tokenised, starting from 1st October, 2022, the cardholder must enter the full card number, CVV and expiry date of the card every time to complete his/her online transactions.

  1. Q 13.How does the process of registration for a tokenisation request work?

Answer: The registration for a tokenisation request is done only with explicit customer consent through Additional Factor of Authentication (AFA), and not by way of a forced / default / automatic selection of check box, radio button, etc. Customer will also be given a choice of selecting the use case and setting-up of limits.

  1. Q 14.Is there any limit on the number of cards that a customer can request for tokenisation?

Answer:  A customer can request for tokenisation of any number of cards to perform a transaction.

  1. Q 15.Can the customer select which card to be used in case he / she has more than one card tokenised?

Answer: To performing any transaction, the customer shall be free to use any of the cards registered with the token requestor / merchant.

  1. Q 16.Once card is tokenised, how will the customer see the card details on the merchant page?

Answer: The customer will be able to see the last 4 digits of the card on the merchant page.

  1. Q 17.What will happen to the token once the customer’s card gets replaced or renewed or reissued or upgraded?

Answer: The customer should again visit the merchant page and create a fresh token.

  1. Q 18.Will the card tokenisation need to be done at every merchant?

Answer: Yes. A token must be unique to the card at a specific merchant. If the customer intends to have a card on file at different merchants, then tokens must be created at all the merchants.

  1. Q 19.If the card holder is having 3 different cards, then is the cardholder expected to create 3 different tokens at the same merchant.

Answer: Yes. As mentioned earlier, token must be unique for a combination of card and merchant.

  1. Q 20.Can a card issuer refuse tokenisation of a particular card?

Answer: Based on risk perception etc. card issuers may decide whether to allow cards issued by them to be registered by a token requestor / merchant.

  1. Q 21.What will be expiry date of the tokenized card?

Answer: The expiry date of the tokenized card is linked to the card expiry date.

Product Information/ FAQs will also be made available in our Bank’s website www.unionbankofindia.co.in for the benefit of cardholders of our Bank.

The guidelines on Tokenisation will also be available on RBI Website www.rbi.org.in and may be referred from time to time.

Electronic Display will also be made available in branches of our Bank.


union

union