On-Prem

Storage

India lets Mastercard issue new cards again

Compliance with onshore data storage laws took almost a year – far longer than India has given the rest of the tech world to comply with infosec changes


India’s Reserve Bank has lifted its ban on Mastercard issuing new cards within the nation.

The ban was imposed in July 2021 when the Bank (RBI) found Mastercard to be “non-compliant with the directions on Storage of Payment System Data”.

Those directions were issued in April 2018 and gave banks and payment systems six months to store “full end-to-end transaction details / information collected / carried / processed as part of the message / payment instruction” on Indian soil. If a transaction involved a foreign entity, replication of data offshore was allowed.

On Thursday the RBI announced that Mastercard had become compliant, so was allowed to resume issuing new cards in India.

India’s enormous size, and rapid modernisation, make it an attractive market. The nation’s increasing de-emphasis of cash payments – in 2016 it barred use of its highest-value banknotes in an effort to reduce corruption by making the cash economy deal with wads of smaller-denomination bills – also make it an important target for payments players.

Mastercard will be mightily relieved to have been allowed back in.

News of Mastercard’s return came in the same week that a third VPN – this time, NordVPN – quit India because it feels compliance with the nation’s new infosec Directive requiring extensive logging and reporting of infosec matters is not possible.

The Directive, announced in April with compliance required on June 27th, call for verbose logging of users’ activities on VPNs or clouds, requires most entities operating in India to report adverse security incidents within six hours of their discovery, and even specifies which network time protocol servers it is permissible to use within India.

Local organisations and international lobby groups alike have pointed out the rules are problematic on grounds of privacy and the imposition of enormous compliance burdens that must be achieved within two months.

The Register offers that recap in light of Mastercard’s restoration: the giant credit card company had six months to become compliant with data storage requirements introduced in 2018 and almost three years later managed to end up on the wrong side of the law.

Good luck to all Indian readers working to meet the deadlines set in the Directive. ®

Send us news
4 Comments

China's first undersea datacenter sinks – as planned

PLUS: India's landmark digital law delayed; Singaporean banks de-digitize some accounts; AUKUS to unleash AI

Microsoft hikes prices across Asia

PLUS: Japan Moon landing scheduled; Mastercard's APAC pay-by-face trial; Scammers feast on restaurant QR code

Rackspace runs short of Cloud Files storage in LON region

Rackspace? More like Lackspace as customers face upload and delete problems

India's CERT given exemption from Right To Information requests

Activists worry investigations may stay secret, and then there's those odd incident reporting requirements

Chromebooks are problematic for profits and planet, says Lenovo exec

Also: India's PC ban didn't take into account needs of ecosystem

India's Moon mission pulled off another trick: an experimental orbital sequel

Swift software development effort saw Chandrayaan-3 propulsion module make an unexpected return to Earth

Trust us, says EU, our AI Act will make AI trustworthy by banning the nasty ones

Big Tech plays the 'this might hurt innovation' card for rules that bar predictive policing, workplace emotion assessments

Amazon on the hook for predictably revolting use of concealed clothes hook spy cam

Judge finds plaintiff's claim – that Amazon knew about illicit usage – credible enough for case to proceed

Watchdog claims retaliation from military after questioning cushy federal IT contracts

IT-AAC had a hand in scrutinizing JEDI, now faces probe for challenging $300M+ single-source deals

Meta goes to war with FTC over right to profit from kids' personal data

Awkward hill to die on, but OK

Epic decision sees jury find Google's Play store is illegal monopoly

Fortnite dev hails 'a win for all app developers and consumers around the world'

Raspberry Pi sizes up HAT+ spec for future hardware add-ons

First to wear it will be an M.2 connector that draws power from PCIe