New

DPDP Rules 2025 compliance checklist is live —

Read now
← All articles Regulation

DPDP Act for Telecom: KYC, Call Records & Location Data Compliance

VaultDef Team10 Sept 202612 min read

If you have spent any time inside a telecom compliance function in India, you already know that "data protection" was never a new subject for this sector — it was just never called that. Long before the Digital Personal Data Protection Act, 2023 (DPDP Act) existed, telecom service providers (TSPs) were already living under Unified License conditions that told them exactly how long to keep a call detail record, what a Customer Application Form (CAF) had to contain, and when a subscriber's identity had to be re-verified. What the DPDP Act does is not replace that regime. It lays a horizontal, subscriber-rights-first statute directly on top of a sector that has spent two decades building a security-first, retention-heavy, license-driven data architecture. The two regimes were not designed to talk to each other, and telecom is the sector where that silence shows up first — because no other class of Data Fiduciary in India processes personal data at the scale, granularity, and sensitivity that a TSP does by default, simply by keeping the network running.

This piece is written for the people who will actually have to reconcile the two: heads of regulatory affairs, DPOs-designate, network security teams, and the compliance leads at TSPs, MVNOs, ISPs and telecom-adjacent VAS providers who are staring at a 2027 deadline and a decade of legacy data.

Three data streams, one subscriber

Strip away the acronyms and every telecom operator is really managing three distinct but interlinked categories of personal data for every subscriber.

Subscriber identity (KYC). Every mobile connection in India starts with identity verification — historically a paper CAF with a photocopy of a Proof of Identity and Proof of Address, now overwhelmingly a digital process built around Aadhaar-based e-KYC, OTP-linked self-KYC on an app, or a retailer-assisted digital CAF with a live photograph and geo-tagged capture. This evolved the way it did partly because of the Supreme Court's 2018 Aadhaar judgment, which restricted private entities' use of Aadhaar authentication and pushed the industry toward app-based and OTP-based alternatives. The Telecommunications Act, 2023 has now put identity verification on statutory footing: Section 4 requires telecom entities to verify subscriber identity and expressly contemplates verification through biometric-based identification. DoT's 2021 KYC reforms allow CAFs to be digitised and stored electronically, but records for migrated or disconnected subscribers must still be retained for three years from the date of migration or disconnection. The KYC layer has also become the front line of fraud enforcement — the Sanchar Saathi portal lets a citizen see every connection issued in their name and report ones they never took, the nine-SIM cap forces disconnection of excess connections through TAFCOP, and repeated bulk re-verification drives have pushed operators to re-run KYC on subscribers who were verified years earlier under a completely different process. Every one of those re-verification cycles creates a fresh personal-data event layered on top of whatever record already existed for that subscriber.

Call detail records, exchange detail records and IP detail records (CDR/EDR/IPDR). Every call, SMS and data session generates a record — who called whom, when, for how long, from which cell, over which IP. Under Clause 39.20 of the Unified License Agreement, TSPs and ISPs are required to preserve commercial records, CDRs, EDRs and IPDRs for a minimum of two years "for security reasons" — a period DoT extended from one year in a December 2021 amendment made at the request of security agencies. This is arguably the single largest structured personal-data asset any TSP holds, and it is retained not because a product team wants it, but because a license condition says so.

Location data. Every connected handset pings a cell tower, which means the network always knows, at a coarse level, where a subscriber is. This data serves genuinely necessary purposes — emergency location services, network planning, fraud and SIM-swap detection — but it is also precisely the kind of continuously generated, highly re-identifiable data point that data protection regimes worldwide treat with particular caution. Location and traffic data can also be the subject of a lawful interception or monitoring direction under Section 20 of the Telecommunications Act, 2023, operationalised through the Telecommunications (Procedures and Safeguards for Lawful Interception of Messages) Rules, 2024 — orders issued by the Union or State Home Secretary, valid for 60 days and extendable to 180, reviewed bi-monthly by a Review Committee, with intercepted records required to be destroyed on a strict schedule unless a court directs otherwise.

Each of these three streams already carried its own compliance regime before the DPDP Act existed. The Act does not clear that field — it adds a fourth layer.

The DPDP overlay

Once the DPDP Act's substantive provisions apply, a TSP is unambiguously a Data Fiduciary — arguably the most consequential one in the country by subscriber count. A handful of provisions matter most for this sector.

Sections 4 through 7 set out the grounds for processing: consent that is free, specific, informed and revocable, or one of the "certain legitimate uses" under Section 7 that permit processing without consent — for a specified purpose for which the subscriber voluntarily provided data, for compliance with law, or for state functions. This is the natural home for KYC verification mandated by the Telecommunications Act, but it does not extend automatically to every secondary use a TSP makes of that same identity data.

Section 8 sets the general obligations that touch every part of the telecom data estate: implement reasonable security safeguards, notify the Data Protection Board and every affected Data Principal in the event of a personal data breach, and — the provision that matters most for this article — erase personal data once the specified purpose is no longer being served or consent is withdrawn, unless retention is necessary for compliance with any law for the time being in force. That carve-out is doing an enormous amount of work for telecom, and we will come back to it.

Section 10 introduces the Significant Data Fiduciary (SDF) category. Given subscriber volumes running into the hundreds of millions, it is close to inevitable that major TSPs will be designated SDFs, bringing with it a India-resident Data Protection Officer, an independent data auditor, periodic Data Protection Impact Assessments, and — under the DPDP Rules, 2025 — a due diligence obligation over "algorithmic software," a category that for a telecom operator plausibly includes churn-prediction models, fraud-scoring engines, network-optimisation algorithms and targeted-offer systems, all of which run on subscriber CDR and location data.

Sections 11 to 14 give subscribers a right to access, correct, erase and nominate — rights that have to be built into a subscriber self-care app or portal that today is designed around billing and recharge, not data governance. Section 9's protections for children's data are also relevant in a market where family postpaid plans, kids' smartwatches with embedded SIMs and shared handsets mean a "subscriber" on record is frequently not the person actually using the connection.

The DPDP Rules, 2025 were notified on 13 November 2025, bringing the Data Protection Board of India into formal existence, with the Board's recruitment for its Chairperson and Members only opened in May 2026 — meaning the adjudicatory machinery is still assembling even as the compliance clock runs. Consent manager registration opens in November 2026, and the Act's substantive obligations — consent, notice, security safeguards, breach notification, data principal rights, and the full penalty regime, which reaches up to ₹250 crore for a security safeguards failure — come into force on 14 May 2027. For telecom, that date is not a distant milestone. It is the point at which a decade of license-driven data practice has to demonstrate, item by item, that it also satisfies a rights-based statute.

Where this actually gets hard?

Anyone who has sat in a room reconciling these two regimes for a real telecom operator will recognise these as the genuine friction points, not the theoretical ones.

Retention says two years; erasure says "as soon as the purpose ends." Section 8(7)'s legal-retention carve-out is the reason CDR and CAF retention under license conditions can coexist with DPDP's erasure principle — but only for data that is retained because a license condition requires it. Location analytics built on top of that same CDR data for a marketing use case, or a customer-experience dashboard that keeps traffic data past the two-year license floor "just in case," gets no such shelter. Very few telecom data lakes today tag records by why they are being retained, which makes the item-by-item defence the law demands close to impossible to produce on request.

The interception secrecy problem. A TSP cannot tell a subscriber their calls were intercepted under a Section 20 direction — the Lawful Interception Rules require exactly the opposite, with records destroyed on a confidentiality-driven schedule. Yet the DPDP Act expects a privacy notice that honestly describes what data is collected, why, and with whom it is shared. Drafting a notice that is accurate and DPDP-compliant without ever hinting at the possibility of interception is a genuinely difficult piece of legal writing, and most existing telecom privacy policies were never built to do it.

The retail KYC moment was never designed for consent capture. SIM issuance happens at a retail counter or via an app in under two minutes, often in a subscriber's second or third language, through a point-of-sale agent who is functionally handling identity documents, photographs and biometric data on personal devices with no consistent security posture. Retrofitting DPDP-grade notice and consent into that moment, across tens of thousands of distribution points, is an operational problem before it is a legal one.

Recycled numbers carry someone else's history. A disconnected number goes through a cooling-off period and is reissued to a new subscriber, but the previous holder's CDRs, location trails and CAF sit in the same systems for years under the license-mandated retention period. Grievance handling, access requests and correction requests against a mobile number can now genuinely implicate two different people's personal data, and most subscriber-facing systems have no clean way to disambiguate that.

One incident, four clocks. A network security event can simultaneously trigger a six-hour reporting obligation to CERT-In, an incident report to the designated authority under the Telecommunications (Telecom Cyber Security) Rules, 2024, and a DPDP obligation to notify the Data Protection Board without delay along with a detailed report within 72 hours and separate notice to every affected subscriber. Each regime has a different recipient, a different format and a different clock, and satisfying one does not discharge the others.

The distributor and vendor tail. Between the TSP and the subscriber sits a long chain of franchisees, POS agents, BPO-run call centres (several offshore), value-added service providers and network equipment vendors, each of whom touches raw identity documents, CDRs or location data at some point. Under the DPDP Act these are Data Processors, and the TSP carries primary accountability for what they do — but very few of these relationships today run on a Data Processing Agreement that reflects DPDP obligations, and fewer still are actually audited.

SDF cross-border restrictions meet global infrastructure. Network analytics, fraud detection and churn modelling routinely run on hyperscaler infrastructure that is not confined to Indian regions. An SDF designation brings cross-border transfer scrutiny for exactly this kind of processing, and disentangling which pipelines touch personal or traffic data — as opposed to aggregated network telemetry — is a mapping exercise most operators have not yet done.

Two regulators, one complaint. If a subscriber alleges that a TSP wrongly retained or mishandled their data, does that grievance belong before the Data Protection Board of India under the DPDP Act, or before TRAI under its existing consumer-protection framework? Section 38 of the DPDP Act says its provisions are in addition to, and prevail over, any conflicting law — but the Board and TRAI have different remedial powers, different procedures, and, at least for now, no formal protocol for deciding which of them takes a given complaint. A TSP defending a single processing decision could plausibly face two regulators reaching two different conclusions, with no mechanism to reconcile them.

None of these are hypothetical concerns for a compliance memo. They are the specific, line-item questions a Data Protection Board, or a subscriber exercising an access or erasure right, is entitled to ask starting in May 2027 — and "our license requires it" is only a complete answer for the subset of data that is actually, demonstrably, tied to that requirement.

Where VaultDef fits?

This is precisely the kind of problem that does not get solved with a policy document. It gets solved with a live, defensible map of every category of personal data a TSP holds — KYC records, CDR/EDR/IPDR, location data, traffic logs — tagged against its actual legal basis: license condition, lawful interception order, consent, or legitimate use under Section 7. VaultDef is built for exactly this kind of structured, evidence-first DPDP compliance work, and for a telecom operator specifically it can help in the places outlined above:

  • Data and legal-basis mapping that distinguishes CDR retained under Clause 39.20 from the same data reused for analytics, so retention-versus-erasure decisions are automated and auditable rather than argued from memory during a Board inquiry.
  • Consent and notice workflows designed for high-volume, multi-language onboarding moments — retail KYC, app-based e-KYC, IVR — with a verifiable audit trail for each subscriber.
  • SDF readiness tooling — DPIA workflows, DPO evidence packs, and documentation support for the algorithmic due diligence that Rule 12 expects for churn, fraud and network-optimisation models.
  • A unified breach playbook that maps a single incident to its CERT-In, Telecom Cyber Security Rules, and DPDP obligations in parallel, so the six-hour and 72-hour clocks are met from one workflow instead of three separate scrambles.
  • A subscriber rights layer that can sit on top of existing CRM and billing systems to handle access, correction, erasure and nomination requests while correctly applying the Section 8(7) legal-retention exception — so nothing gets deleted that a license condition still requires, and nothing gets retained that no longer has a defensible basis.
  • A processor and vendor risk register for the distributor, BPO and platform ecosystem that sits between the TSP and the subscriber, with DPA tracking built in.

Telecom will not get a grace period on this. The subscriber base is too large, the data too sensitive, and the regulatory attention too high for "we're working on it" to be an acceptable answer once the Act's substantive provisions take effect. Operators that start mapping their KYC, CDR and location data against both the Telecommunications Act and the DPDP Act now — rather than in the run-up to May 2027 — are the ones who will be able to answer a Data Protection Board's questions with evidence instead of explanation. If that mapping exercise is where you are starting from, Vaultdef is worth a look.