Indian MSMEs picking between PayU and Razorpay meet five RBI/GST rulebooks: Payment Aggregator (PA) license framework, UPI Zero-MDR mandate, card tokenisation, GST invoice + 18% GST on gateway fees, DPDP Act 2023 with data localisation.
An Indian MSME choosing a payment gateway to power its website checkout, WhatsApp-triggered payment links, subscription billing, or invoice payments is not simply comparing MDR rates and integration ease. It is entering five distinct Indian regulatory frameworks that shape which providers are legally permitted to operate, what pricing they can charge, how they must handle customer payment data, how the merchant must invoice, and what withholding obligations apply.
Reserve Bank of India (RBI) Payment Aggregator (PA) framework — under the RBI Guidelines on Regulation of Payment Aggregators and Payment Gateways issued March 2020 and subsequent updates, only entities holding an RBI PA licence can hold funds in a settlement escrow between customer payment and merchant credit. Both PayU Payments Private Limited and Razorpay Software Private Limited operate as PA-licence holders (subject to any ongoing RBI enforcement actions or licensing updates — verify current status on the RBI website's authorised PA list before onboarding). The PA framework imposes minimum net-worth requirement (₹15 crore initially, moving to ₹25 crore over the transition window), escrow account discipline with a scheduled commercial bank, KYC obligations on the aggregator toward the merchant, and periodic RBI reporting.
UPI Zero-MDR mandate. The Ministry of Finance notification effective 1 January 2020 mandated zero Merchant Discount Rate on UPI transactions and RuPay debit card transactions. This is not a suggestion — it is a statutory bar on charging MDR for these payment methods. Since UPI carries the majority of Indian retail digital-payment volume (NPCI publishes monthly transaction data), the gateway pricing conversation on UPI is effectively over: no gateway can compete on UPI MDR because it is zero for everyone. Competition happens on card MDR (Visa/Mastercard credit + non-RuPay debit), international acceptance costs, subscription and value-added service pricing, and integration quality.
RBI card tokenisation mandate. Effective October 2022 with subsequent extensions and refinements, RBI prohibits merchants and payment aggregators from storing actual card numbers (PAN — Primary Account Number, CVV, expiry). All saved-card functionality must operate through tokens issued by the card network (Visa, Mastercard, RuPay, Amex) via a Card-on-File Tokenisation (CoFT) framework. Both PayU and Razorpay support the CoFT framework, but MSMEs migrating from an older gateway or building custom flows need to verify their integration is CoFT-compliant. RBI April 2018 direction on Storage of Payment System Data mandates that all data related to payment systems operated in India must be stored only in India — this is the data localisation direction that shapes where PA-licensed gateways can process and store transaction data.
GST on gateway fees + Merchant invoicing. Payment aggregator commission and platform fees are taxable under GST at 18% (HSN 9971 / financial services). This is a cost line MSMEs commonly overlook — a 2% MDR is effectively 2.36% after GST for the merchant. The gateway issues a GST-compliant tax invoice for its commission; the merchant claims Input Tax Credit (ITC) if registered under GST. Separately, the merchant must issue GST-compliant tax invoices to its own customers under the CGST Act — the gateway does not substitute for the merchant's invoicing obligation. E-invoicing under the GST framework is mandatory for businesses with aggregate turnover above ₹5 crore (current threshold as of most recent notification; verify current threshold via the GST portal) with QR code, IRN (Invoice Reference Number), and real-time upload to the IRP.
TDS 194-O + TCS Section 52 CGST + DPDP Act 2023. Section 194-O of the Income Tax Act requires an ecommerce operator to deduct TDS at 1% on the gross amount of goods or services sold through it (with exemptions for individual/HUF sellers below ₹5 lakh annual turnover on that platform). Section 52 CGST requires an electronic commerce operator to collect TCS at 1% on net taxable supplies. These withholding regimes apply when the MSME sells through a marketplace or aggregator that qualifies as an ecommerce operator — the payment gateway itself is generally not the operator, but the MSME must reconcile settlement amounts against operator-issued Form 26AS entries. The Digital Personal Data Protection Act 2023, enforced by the Data Protection Board of India (DPB) once operationalised, establishes consent-based processing, data-subject rights (access, correction, erasure, grievance redressal), cross-border transfer restrictions to notified countries, significant data fiduciary designations for large processors, and penalties up to ₹250 crore per instance for aggravated violations. Merchant handling of customer data collected in the gateway flow is subject to DPDP requirements.
PayU Payments Private Limited is the Indian arm of PayU, ultimately owned by Prosus (the international investment arm of Naspers). PayU India has operated since 2011 and holds an RBI Payment Aggregator licence (verify current status on the RBI website). Following Prosus's divestiture of PayU Global's assets in select markets, the India business continues under the PayU brand with its own India-focused product roadmap.
Product suite. PayU India offers a full payment aggregator + payment gateway stack: online checkout (PayU Checkout, redirect + hosted forms + web SDK + mobile SDK), payment links (shareable via WhatsApp, SMS, email, QR), UPI collect and UPI intent, cards (domestic + international), netbanking, wallets, EMI on cards + Bajaj Finserv + cardless EMI, Buy Now Pay Later via LazyPay (PayU's own lending arm), subscriptions and recurring payments, split payments, invoicing, and dispute management dashboard. LazyPay integration gives PayU-checkout merchants access to a captive BNPL flow, which some MSME categories (fashion, electronics, larger-ticket) find lifts conversion.
Enterprise and large-merchant heritage. PayU's history in India has been strong in large-merchant and enterprise segments — Zomato, Snapdeal, Flipkart, Airtel, and Indian government portals have historically been reference customers. This heritage shows up in enterprise-grade features (dedicated account management, custom pricing negotiation, sophisticated fraud tools) and in the depth of enterprise-friendly integrations.
MSME fit. PayU is capable for MSMEs but the product marketing and self-service experience is oriented more toward established mid-market and enterprise merchants than toward first-time startup founders. Pricing is negotiable for higher-volume merchants and can be materially competitive; for smallest-tier merchants the sticker MDR on cards is broadly in line with Razorpay and other PA-licensed players. Onboarding requires standard PA documentation: business PAN, GST registration, bank account in the business name, personal PAN + Aadhaar of authorised signatories, MOA/AOA for private limited or partnership deed, cancelled cheque, and website compliance verification.
Where PayU tends to fit best. Mid-market to enterprise Indian merchants with volume above roughly ₹1-2 crore monthly gross transaction value; merchants who value LazyPay BNPL as a conversion tool; merchants with negotiated custom-pricing arrangements; merchants running higher-ticket categories where large-merchant service level matters; merchants with existing PayU enterprise relationships to extend.
Where PayU can under-fit. First-time MSME founders looking for a completely self-service startup-oriented experience; developer-first teams valuing modern API ergonomics as the primary factor; smallest-tier MSMEs where the setup and account-management overhead may exceed the pricing advantage.
Razorpay Software Private Limited is an Indian fintech unicorn founded in 2014 by Harshil Mathur and Shashank Kumar, headquartered in Bengaluru. Razorpay holds an RBI Payment Aggregator licence (verify current status on the RBI website's authorised PA list; the company operated under an in-principle authorisation for a period before receiving the full licence). Razorpay has expanded beyond pure payment gateway into a broader fintech platform.
Product suite. Razorpay's stack extends from payment gateway (Razorpay Payments — checkout, payment links, subscriptions, invoices, smart routing, optimizer for MDR reduction) into a wider ecosystem: RazorpayX (business banking with corporate cards, vendor payments, payroll integration), Razorpay Payroll (payroll management for SMEs), Razorpay Capital (SME lending), Razorpay Rize (startup community and toolkit), and Curlec (subscription billing acquired 2022). This one-stop-shop positioning is central to the Razorpay MSME value proposition — a startup can run payments, banking, payroll, and access to credit through a single vendor relationship.
Startup and SME heritage. Razorpay's origin story is startup-oriented: the company built early traction serving small ecommerce merchants and Indian startups underserved by legacy gateways. This lineage shows up in developer experience — the API documentation is widely praised as best-in-class for Indian payment gateways, self-service onboarding is streamlined, and integration examples cover popular Indian tech stacks (Django, Rails, React, Flutter, WordPress, Shopify). The Razorpay merchant dashboard is generally considered the most polished among Indian PA-licensed gateways.
MSME fit. Razorpay is oriented toward MSMEs and startups as the primary customer segment. Standard pricing is transparent and public (typical listed MDR: 2% on domestic cards + UPI/netbanking, with UPI Zero-MDR override; higher on international cards; standard subscription and value-added feature pricing). Onboarding requires the same PA documentation as PayU: business PAN, GST registration, bank account in business name, personal PAN + Aadhaar of authorised signatories, MOA/AOA or partnership deed, cancelled cheque, and website compliance verification. Self-service onboarding typically completes within a few business days for standard applications.
Where Razorpay tends to fit best. Indian startups and mid-market merchants building modern tech stacks; developer-first teams that value API ergonomics and documentation quality; merchants who want the full RazorpayX banking + Payroll + Capital ecosystem; subscription and SaaS businesses that value Razorpay Subscriptions and Curlec depth; MSMEs building their entire operational tech stack from scratch.
Where Razorpay can under-fit. Very large enterprise merchants requiring highly bespoke pricing and enterprise-grade account management (historically PayU and legacy gateways stronger here); merchants with legacy Indian tech stacks that require custom or older integration approaches; merchants who value being one of many at a large enterprise-focused vendor over being a core-customer segment at a startup-focused vendor.
The single most important pricing reality for Indian payment gateway comparison is the UPI Zero-MDR mandate. The Ministry of Finance notification effective 1 January 2020 mandated zero Merchant Discount Rate on UPI (all variants — Collect, Intent, QR) and RuPay debit card transactions. This is a statutory prohibition, not a competitive floor — no PA-licensed gateway can charge merchants for these transaction types.
The scale of this depends on the transaction mix. NPCI publishes monthly UPI transaction data on npci.org.in — UPI carries the majority of Indian retail digital-payment volume by transaction count, with the value share growing steadily as UPI limits are raised and merchant acceptance deepens. For a typical Indian MSME with a mixed digital-payment mix, UPI is often 60-85% of transaction count and 40-70% of transaction value — all of it at zero MDR through any PA-licensed gateway including PayU and Razorpay.
The competitive economics for the MSME therefore concentrate on non-UPI, non-RuPay-debit transactions:
Credit cards (Visa, Mastercard, Amex, RuPay Credit). Standard MDR for both PayU and Razorpay is typically around 2% + 18% GST for domestic cards, moving to 3-3.5%+ for international cards. Rates negotiate down for higher-volume merchants. This is where sticker-pricing comparison genuinely matters, but for most MSMEs the difference between PayU and Razorpay on credit card MDR is small — often 0-25 basis points at similar volume tiers.
Non-RuPay debit cards. Under RBI rules debit card MDR is capped and typically lower than credit card MDR. Both PayU and Razorpay operate within RBI caps.
Netbanking. Bank-driven fees (usually flat per transaction rather than percentage) are passed through by the gateway with a small platform markup. Comparable at both PayU and Razorpay.
Wallets (Paytm, PhonePe wallet, MobiKwik, Freecharge). MDR varies by wallet and is passed through by the gateway.
International cards. Materially higher MDR (typically 3-3.5%+) reflecting international interchange and cross-border fees. Both gateways support but the merchant needs FEMA-compliant handling and typically an AD Category-I bank relationship for foreign inward remittance.
EMI (cards + cardless). EMI transactions carry variable rates depending on card issuer, tenure, and whether the merchant is bearing the interest subvention. Both gateways offer EMI programs; PayU's LazyPay integration adds a captive BNPL flow.
Subscriptions and recurring payments. Both gateways charge on the transaction (per successful debit) plus platform features for subscription management. Razorpay Subscriptions and Curlec integration is deeper on the recurring-billing product side; PayU offers subscription but the product depth is more oriented toward enterprise implementations.
The strategic implication: the choice between PayU and Razorpay is rarely won on transaction MDR alone. It is won on product ecosystem fit (banking, lending, payroll integration for Razorpay; large-merchant heritage and LazyPay for PayU), developer experience, dashboard quality, and customer support responsiveness.
Both PayU India and Razorpay operate under identical RBI regulatory obligations as PA-licensed entities. The framework matters for MSMEs because it shapes settlement timing, dispute resolution, data handling, and merchant risk exposure.
Escrow account discipline. PA-licensed aggregators must maintain a nodal or escrow account with a scheduled commercial bank to hold funds between customer payment and merchant credit. Merchant settlement typically operates on T+1, T+2, or T+3 depending on payment method and merchant risk profile — high-risk categories or newly-onboarded merchants may experience longer settlement windows during the initial ramp period. Both PayU and Razorpay offer standard T+1 or T+2 settlement for mature merchants; instant settlement (T+0) is available on premium tiers or specific instruments at additional cost. The escrow discipline protects merchants against aggregator insolvency risk — customer funds sitting in escrow are not available to the aggregator's general creditors.
Card tokenisation (CoFT). RBI's tokenisation mandate prohibits merchants and PAs from storing raw card details (PAN, CVV, expiry). All saved-card and recurring-billing flows must operate through network tokens issued by Visa, Mastercard, RuPay, or Amex under the Card-on-File Tokenisation framework. Both PayU and Razorpay implement CoFT — the merchant integration receives a network token instead of a card number, subsequent transactions initiate against the token. For MSMEs migrating from an older gateway that pre-dates CoFT, a customer's saved-card data does not migrate as-is — the customer must re-authenticate with the new gateway to create fresh tokens.
RBI April 2018 payment-data localisation direction. The direction requires that all data related to payment systems operated in India must be stored only in India. End-to-end transaction details, transactional data, customer-related data, and other payment-system data must reside in Indian data centres. Both PayU and Razorpay operate India-based infrastructure to meet this requirement. Merchants building custom integrations should not attempt to stream payment data to systems outside India; the data localisation direction applies to the merchant's own systems where the merchant is holding payment-related data.
KYC discipline toward merchants. The PA framework requires the aggregator to conduct KYC on the merchant it onboards — business registration verification, GST verification, PAN verification of business and authorised signatories, bank account validation, website content review (for compliance with RBI, MeitY, and category-specific regulations), and periodic KYC refresh. Merchants that misrepresent business category or provide incomplete documentation face suspension.
Merchant risk categorisation. Both PayU and Razorpay categorise merchants by risk profile at onboarding — categories broadly aligning with international card scheme MCC codes. Higher-risk categories (adult, gambling where legally restricted, cryptocurrency for reasons of RBI stance evolution, certain healthcare) face longer settlement windows, higher reserves, or outright rejection. Low-risk MSME categories (retail, services, education, professional services) receive standard onboarding.
Dispute and chargeback. Card chargebacks follow Visa/Mastercard/RuPay scheme rules with defined merchant response windows. Both gateways provide merchant dashboards for chargeback response with documentation upload. RBI's ombudsman scheme for digital transactions provides an escalation path for customer disputes when merchant-level resolution fails.
For feature-by-feature comparison relevant to Indian MSME workflow, the picture is largely parity with meaningful differences in specific areas.
Checkout — hosted and embedded. Both offer hosted checkout (redirect to gateway-branded checkout page) and embedded checkout (checkout inside merchant page via SDK). Razorpay's Standard Checkout modal is widely regarded as smoother and more mobile-optimised for Indian consumer behaviour; PayU's Bolt SDK is competitive but the polish differential is real.
Payment links. Both support shareable payment links (WhatsApp, SMS, email, QR). This is the primary WhatsApp-integrated payment workflow: the merchant generates a link in the dashboard or via API, shares via WhatsApp, customer completes payment on the gateway-hosted page, webhook fires back. Both support customisation, expiry, partial payment, and multi-item cart. Razorpay Payment Pages layered on top adds a template-based storefront capability.
Subscriptions and recurring billing. Razorpay Subscriptions is deeper and more polished than PayU's subscription offering, with card-based subscriptions (via CoFT tokens post-tokenisation mandate), UPI AutoPay (which materially improved subscription retry economics), and Curlec integration for enterprise SaaS billing. PayU offers subscription functionality but the product depth is more oriented toward custom enterprise implementation than self-service SaaS.
EMI (cards + cardless). Both support standard EMI on Visa/Mastercard/RuPay credit cards from participating issuers, plus cardless EMI via lending partners. PayU's captive LazyPay integration adds a first-party BNPL option — for merchants in fashion, electronics, and higher-ticket categories where cart lift matters, this is a meaningful PayU advantage.
Split payments. Both support split payments for marketplace or partnership scenarios where a single customer payment must settle to multiple merchant sub-accounts. Razorpay Route is the mature product for this; PayU has equivalent functionality through custom implementation.
Invoicing and GST integration. Both offer invoice generation and management. For GST e-invoicing compliance (mandatory above ₹5 crore aggregate turnover), the invoice generated in the gateway is not by itself a GST e-invoice unless the merchant's accounting system uploads it to the IRP. Both gateways integrate with Indian accounting software (Tally, Zoho Books, QuickBooks India, Vyapar) via connectors or API — the recommended pattern is to generate the GST-compliant e-invoice in the accounting system with the payment recorded from the gateway webhook.
International acceptance and FEMA compliance. Both support international cards for Indian merchants accepting cross-border payments. The merchant must comply with FEMA (Foreign Exchange Management Act) — typically through an AD Category-I bank relationship for foreign inward remittance advice, purpose code assignment, and reconciliation for RBI reporting.
Fraud and risk tools. Both offer transaction risk scoring, velocity checks, blacklist/whitelist rules, and 3D-Secure enforcement. Both integrate with card network fraud services. Merchant tuning of risk rules is more polished on Razorpay's dashboard; PayU's risk console works but is oriented toward account-manager-guided configuration for enterprise merchants.
Developer experience. Razorpay's API documentation, sandbox environment, and code samples are widely regarded as best-in-class for Indian gateways. PayU documentation is functional and comprehensive but less polished — the difference is meaningful for developer-first teams and negligible for teams using pre-built plugins on Shopify, WooCommerce, or WordPress.
The right choice depends on merchant size, tech stack maturity, product portfolio need, and specific vertical.
Pick Razorpay if the MSME is: an early-stage startup or growing SME with in-house development capability that values developer experience; a subscription/SaaS business needing depth on recurring billing and UPI AutoPay; a merchant that will use RazorpayX for banking + Razorpay Payroll + Razorpay Capital as an integrated fintech stack; a Shopify/WooCommerce/WordPress merchant wanting the smoothest self-service onboarding; a merchant that values dashboard quality and self-service configuration over account-manager-mediated setup.
Pick PayU if the MSME is: a mid-market or enterprise Indian merchant with volume above roughly ₹1-2 crore monthly GTV and appetite for negotiated custom pricing; a merchant in fashion, electronics, or higher-ticket categories where LazyPay BNPL as a first-party checkout option lifts conversion; a merchant with existing PayU enterprise relationships to extend; a merchant valuing the enterprise-heritage account-management model over startup-oriented self-service.
Pick neither and evaluate alternatives if the MSME is: a very small merchant with monthly GTV under ₹1 lakh where any PA-licensed gateway's fees exceed the value delivered — some categories work better with a UPI-first workflow using Google Pay for Business, PhonePe for Business, or Paytm for Business direct integration without a full PA gateway; a merchant in a category where a specialist vertical player (Instamojo for creators, Cashfree for platform businesses, Juspay for large enterprises, PayGlocal for cross-border enterprise) delivers a more focused fit; a merchant with genuinely complex enterprise needs (multi-legal-entity settlement, custom banking integration, sophisticated tokenisation flows) that benefits from a Juspay orchestration layer over one or more PAs.
Migration considerations for MSMEs switching gateways. Card tokenisation post-CoFT means saved-card data does not migrate as-is — customers must re-authenticate to create fresh tokens with the new gateway. UPI mandates and mandate-based subscriptions typically require re-registration. Historical transaction data can be exported from the old gateway and imported into accounting systems for continuity; live-transaction ETL between gateways is not standard. Merchant KYC re-verification is required at the new gateway — timeline typically a few business days for standard applications.
Reversibility and vendor risk. Both PayU and Razorpay are RBI PA-licensed with escrow discipline, so merchant funds are protected against aggregator insolvency risk. Merchant switching cost is real but not prohibitive — an MSME that chooses one and later switches typically loses a few weeks of dashboard optimisation and integration adjustment, not permanent value. The decision is important but not irreversible; MSMEs should not spend disproportionate deliberation time on the choice compared to the value at stake.
The Digital Personal Data Protection Act 2023 (DPDP) received Presidential assent in August 2023 and is being operationalised through subsequent rules and the constitution of the Data Protection Board of India (DPB). Merchants processing customer personal data collected through the gateway flow — name, contact details, address, transaction history, and behavioural signals — are Data Fiduciaries under DPDP.
Consent framework (Section 6). Processing personal data requires the consent of the Data Principal, which must be free, specific, informed, unconditional, unambiguous, and given through clear affirmative action. For a gateway checkout, the merchant must obtain consent for the specific processing purposes at collection — payment processing (contract necessity may apply as an alternative lawful ground under Section 7 legitimate uses); marketing communications (separate specific consent); analytics beyond immediate transaction purpose (separate consent). Bundled consent for all purposes in a single checkbox does not meet the DPDP specificity requirement.
Data Principal rights (Sections 11-14). Access, correction, erasure, grievance redressal, nomination. Merchants must operationalise a process to respond to data principal requests within a reasonable timeframe (rules under drafting at the time of writing — verify current DPDP rules and DPB advisories via meity.gov.in).
Cross-border transfer (Section 16). DPDP permits cross-border data transfer to countries or territories notified by the central government, subject to conditions the government may specify. This differs from the pre-existing sector-specific rules (RBI's payment data localisation direction continues to apply for payment-related data — DPDP does not override it). Merchants storing customer non-payment data (marketing lists, CRM profiles, analytics) in international infrastructure must verify DPDP compliance in addition to any sector-specific rules.
Significant Data Fiduciary designation (Section 10). Larger data-processing entities may be designated as Significant Data Fiduciaries with additional obligations — mandatory appointment of Data Protection Officer, independent data auditor engagement, and Data Protection Impact Assessment for specified processing activities. Most small MSMEs will not initially fall under this designation, but growing MSMEs should track how the designation criteria evolve.
Breach notification (Section 8(6)). In the event of a personal data breach, the Data Fiduciary must notify the Data Protection Board and each affected Data Principal in the manner prescribed. Timelines and format are being specified through the DPDP rules process.
Penalties (Schedule). DPDP provides for penalties up to ₹250 crore per instance for aggravated violations (failure to take reasonable security safeguards leading to breach), lower amounts for lesser violations. This is materially higher than the pre-DPDP information technology rules regime.
Practical MSME discipline for merchants using PayU, Razorpay, or any Indian PA-licensed gateway: (1) publish a privacy notice covering categories of personal data processed, purposes, lawful grounds, retention, cross-border transfer, and data principal rights; (2) obtain specific consent at collection for each processing purpose beyond immediate transaction execution; (3) operationalise a data principal request response process; (4) implement reasonable security safeguards including access control, encryption at rest and in transit for sensitive data, and audit logging; (5) maintain a breach response plan with DPB notification workflow; (6) periodic review of processor contracts (with the gateway, with hosting providers, with analytics vendors) for DPDP alignment; (7) monitor DPB advisories and rules issuance for evolving requirements.
Data + numbers referenced in this article are sourced from these public documents:
BossBot integrates with Indian PA-licensed gateways and handles WhatsApp payment-link workflows for MSMEs.
Explore BossBotNot ready to sign up yet? Try the free demo →