To be clear, I am commenting on the difference between:
"Recurring payments work by storing credit card info in tokenized form, which is still allowed".
vs.
"Recurring payments work by storing a token instead of credit card information."
Those both answer the question, but they say different things on whether "credit card information" is stored. And they say different things about whether the headline is misleading.
Why would you need that?
The rule says nobody can store "actual card data".
If you're using the token for a new payment, you don't retrieve the card number, you use the token directly.
> It seems to be instructing the card brands to issue unique tokens for ever cardholder + merchant pair. No idea how that would work…
Pick a random number and store it in a database with those two other fields...?
To quote the article linked above, "The central bank said the facility of tokenisation shall be offered by TSPs only for the cards issued by/affiliated to them."
Edit: Looks like they do allow card tokenization (not part of original proposal) which should address a lot of use cases
Here is the commentary about the original proposal:
https://www.businessinsider.in/finance/banks/news/rbi-wants-...
Here is the one after push back from industry (Which allows tokenization):
https://timesofindia.indiatimes.com/business/india-business/...
Recurring payment greater than 5000Rs requires a separate auth. (EMI's are not impacted by this)
This isn’t a surprising change and was always going to be the future of PCI compliance.