Indian Journal for Research in Law and Management

Advancing Law and Management

ISSN No. : 2583-9896

DIGITAL PAYMENTS SECURITY LAWS

Cite this Article

Ranveer Singh Tanwar (2026). DIGITAL PAYMENTS SECURITY LAWS. The Indian Journal for Research in Law and Management, Volume III(Issue 11). Retrieved from https://ijrlm.com/journal/digital-payments-security-laws/

Abstract

Someone calls claiming to be from a bank. The voice is convincing, the caller knows the last 4 digits of the account and there is enough urgency in the conversation, that the threat appears to be real: verify immediately, or the account will be blocked. A few minutes later, the money is gone. But the transaction record has a much different story. The correct credentials were used. The OTP was entered. The payment was successfully verified. For the bank's system, there may be nothing unusual about this transaction. If the individual has lost the funds, it is obvious that it is a scam. The law is somewhere in between these two renditions of the same event. The question is one that is very hard to answer in the world of digital payment security today. India's payment system has turned into a remarkable machine at determining if the right PIN, password or OTP was provided. It is much less clear if the question is whether the person entering it really intended the transaction that ensued. This distinction matters because fraud itself has evolved. Being a criminal doesn't require necessarily hacking into a bank's servers or a password. In some cases, it is sufficient to make the victim feel the need to trust them, to make them feel like there's been a serious emergency, or to successfully mimic a familiar voice so that the victim will go through with the transaction on their own. Indian law doesn't attempt to solve this issue in a single act. The Payment and Settlement Systems Act 2007 has put payment systems under the regulatory control of the Reserve Bank of India . The Information Technology Act, 2000 provides for dealing with the problem of identity theft, cheating through personation and some failures in the context of electronic data. In addition to the remedies provided by consumer protection law, India's data protection law also imposes obligations on banks with regard to the security of personal data. In addition to these laws, there is a huge regulatory infrastructure set up by the RBI . So, the challenge isn't that India doesn't have a law pertaining to digital payments. It has several. The more serious issue is whether the various legal principles yield a definite result at the crucial time: when the fraudulent payment has been actually made, who is to suffer the loss? This article contends that India's digital payment framework needs to move beyond an almost binary understanding of bank fault and customer negligence. However, authentication is not always a secure basis for meaningful authorisation, especially when fraud has evolved into a tactic of exploiting consent, not bypassing or defeating technology. Existing law doesn't resolve another question that needs to be addressed in the next generation of payment regulation: who to believe if payments are recorded on the machine and the person says they were misled - the machine or the human being?

Journal Information

The Indian Journal for Research in Law and Management
ISSN No.
2583-9896
Submit Manuscript
Licensing
All research articles published in The Indian Journal for Research in Law and Management are fully open-access. i.e. immediately freely available to read, download, and share. Articles are published under the terms of a Creative Commons license, which permits use, distribution, and reproduction in any medium, provided the original work is properly cited.
Disclaimer
The opinions expressed in this publication are those of the authors. They do not purport to reflect the opinions or views of the IJRLM or its members. The designations employed in this publication and the presentation of material therein do not imply the expression of any opinion whatsoever on the part of the IJRLM.

Article Analytics

19
Page Views
0
Downloads