UPI: Privacy concerns

| Photo Credit:

My niece recently discovered a fascinating new feature of India’s digital payments ecosystem. When she at times paid an auto/taxi driver or small merchant using UPI, strangers began sending her WhatsApp messages. Some were merely curious. Others were conversational. A few displayed the confidence of people who believe a ₹143 payment for an auto ride constitutes the beginning of a meaningful relationship.She had not joined a social networking platform. She had simply paid for transportation. Somewhere between scanning a QR code and receiving a payment confirmation, her mobile number had apparently become public property, along with her name. Welcome to one of India’s most under-discussed privacy problems: The QR code that knows too much!When consumers make payments through UPI applications such as G-Pay, PayTm or PAyU, details such as names and sometimes mobile numbers can become visible to merchants. In most cases this is intended to facilitate transactions. In some cases, however, it also facilitates unsolicited calls, WhatsApp messages and social media searches — soliciting dates, money and even selling other services.Safeguarding personal dataIndia’s Digital Personal Data Protection Act, 2023, attempts to address precisely such situations. The Act is built around a radical concept that should not be controversial: personal data belongs to the individual. Not to merchants. Not to payment intermediaries. Not to random strangers who happened to receive money.Private data so collected cannot be used beyond the purpose for which it is collected and a breach is violation of the law. Consent matters. Purpose limitation matters. Privacy matters. At least on paper.In India, customer databases circulate like festival sweets. Many organisations continue treating personal data as a business asset rather than a customer trust. A transaction becomes surveillance.Cautionary stepsWhat should payment providers do to end this menace? Celebrating record transaction volumes while quietly leaking customer privacy is rather like a bank boasting about its vault while leaving the front door open. A few sensible measures are overdue:* Hide customer phone numbers from merchants wherever possible.* Show only the information required to complete the transaction. Perhaps a user name can be provided to each account holder?* Provide one-click reporting for harassment linked to payment transactions. Customers should not need a detective agency to report misuse.* Create temporary communication channels when necessary, instead of handing out permanent access to personal numbers.* Constitute audit trails whenever customer information is misused.* Educate merchants about privacy obligations and the consequences of treating customer data as a complimentary gift.Consumers also need defensive habits. Use privacy settings available within payment applications. Avoid showing unwanted information on public profiles. They may consider separate phone numbers for such payments. Report merchants who misuse personal information and block unsolicited contacts immediately. Most critically, refuse to accept such behaviour. The phrase “It happens all the time” is not a privacy policy.Enhancing trustUPI might be a great success, but trust is the real currency. Consumers will continue embracing digital payments only if they believe their personal information remains protected. The issue is not just about unwanted messages but about consent, dignity and about maintaining boundaries between commercial transactions and personal lives.My niece only wanted to pay for a ride. She did not enrol in a social networking service. She did not consent to becoming discoverable by strangers. She certainly did not agree to participate in India’s newest unofficial matchmaking platform.In the digital economy, the most valuable asset is not data. It is trust. Money transferred through UPI should reach the merchant. The customer’s phone number should not.The writer is a Fortune-500 advisor, start-up investor and co-founder of the non-profit Medici Institute for InnovationPublished on July 25, 2026