UPI privacy concerns put merchant access to customer data under scrutiny
An opinion piece argues that UPI payment flows can expose customer names and, in some cases, mobile numbers to merchants, creating risks of unsolicited contact and harassment. It calls for data minimisation, merchant audits and stronger enforcement under India’s data-protection law.
Opinion piece flags UPI payment flows as a consumer-privacy risk, alleging merchants can access customers’ names and sometimes mobile numbers, enabling unsolicited contact. It calls for data minimisation, harassment reporting, merchant audits and enforcement under India’s Digital Personal Data Protection Act.
Why this matters
The privacy concern follows UPI’s FY26 scale-up to 55.49 crore users and ₹314 lakh crore in transactions, while Delhi data shutdowns highlighted reliance on UPI for retail and app-based services.
Retail-company signals are accelerating, up 1,101,900% QoQ.