Fintech & Digital Money
Card Tokenisation: Protecting Card Details Online
How replacing card numbers with tokens makes online payments safer, and why India required tokenisation from 2022.
When you save a credit or debit card on a shopping website, your card details could be exposed if that website is hacked. Tokenisation reduces this risk by replacing card details with a unique code called a token.
How tokenisation works
- When you save a card with a merchant, your actual card number is sent to the card network or bank.
- The network creates a token, a unique substitute number tied to your card, that merchant and often a device.
- The merchant stores only the token, not your real card number.
- When you pay, the token is sent, and the network matches it to your real card behind the scenes.
If hackers steal a merchant’s tokens, they cannot use them elsewhere, because each token works only with that specific merchant.
India’s rule
The Reserve Bank of India prohibited merchants and payment aggregators from storing actual card details, known as card-on-file data, from 1 October 2022. Merchants had to switch to tokens. Customers need to give consent, often with a one-time password, to tokenise a card with each merchant.
Benefits
- Reduced fraud risk: large data breaches expose fewer usable card numbers.
- Convenience: customers can still save cards for quick checkout.
- Control: customers can see and remove tokens for specific merchants.
Tokenisation elsewhere
Mobile wallets like Apple Pay and Google Pay also use tokens, so the phone never shares the real card number with the shop.
A popular shopping website suffers a data breach. In the past, thousands of stored card numbers might have been stolen and used for fraud. With tokenisation, the hackers obtain only tokens, which are useless at other websites. Customers' actual card numbers remain safe with the card networks.
Accessibility
Tokenisation steps, such as entering OTPs and consenting to save cards, must work with screen readers so blind customers can use them independently.
Tokenisation protects stored card data, but fraud can still occur if someone tricks you into sharing an OTP or making a payment. Staying alert to scams remains important.
- Tokenisation replaces card numbers with merchant-specific tokens.
- Stolen tokens cannot be used at other merchants.
- India banned merchants from storing actual card details from 1 October 2022.
- Tokens reduce data breach risks, but scam awareness is still needed.
No recording for this one yet - EconReader can read it aloud for you.