top of page

Telecom User Identification Rules Notified

21 August 2026

I. A Retreat Dressed as an Advance


The final Telecommunications (User Identification) Rules, 2026 are narrower than what the September 2025 draft proposed, and this narrowing is the story the notification's framing obscures. The draft's Biometric Identity Verification System, a shared cross-operator database allowing telecom companies to check identities against each other's records, has been dropped entirely in favour of operator-specific e-KYC and D-KYC processes. Civil society objections to BIVS as an unnecessary parallel biometric collection without Aadhaar-equivalent statutory safeguards evidently succeeded, at least partially. Coverage describing these rules as a biometric mandate is correct on the narrow point but understates the extent to which the more invasive shared-database architecture was abandoned.


II. Operator-Level Biometric Silos Are Not a Privacy Win


The absence of a shared database does not mean less biometric data is being collected, only that it is collected and retained separately by each operator rather than pooled centrally. From a fraud-prevention standpoint this is arguably a regression, since a customer's biometric identity verified with one operator provides no cross-operator fraud signal. From a privacy standpoint it is a mixed result: no single centralised biometric honeypot, but a larger number of operator-held stores, each subject to its own security posture, with no rule-specified retention period, deletion timeline, or encryption standard. The rules explicitly defer to "applicable data protection law" without specifying how DPDP obligations, once in force, will apply to this dataset, leaving open exactly the ambiguity the DPDP Act's phased rollout was meant to resolve.


III. The Internet Telephony Question Remains Deliberately Unanswered


The extension of biometric identification to "internet telephony service through mobile user terminals" is the most consequential unresolved element of this notification. The Department of Telecommunications has not clarified whether this reaches over-the-top calling applications, meaning WhatsApp, Signal, and similar services could plausibly fall within scope depending on future interpretation. Given DoT's separate, already controversial SIM-binding directions to WhatsApp and Telegram under the Telecommunication Cybersecurity Amendment Rules, 2025, this ambiguity is unlikely to be accidental. Clients operating any calling functionality within a mobile application should treat this as an open compliance question requiring monitoring, not a settled exclusion.


IV. The SIM-Sharing Restriction Ignores Documented Field Reality


The rules carry forward from the draft a restriction preventing SIM transfer to anyone other than relatives or legal heirs. This provision does not reflect how mobile connectivity actually functions across much of India, where a single registered connection is commonly shared informally within households, small businesses, or extended family networks that do not map cleanly onto the relative or legal heir categories the rule recognises. MediaNama's draft-stage commentary flagged this gap and it survives into the final rules unaddressed, suggesting the underlying policy assumption about individual, exclusive SIM ownership was never revisited despite direct feedback.


V. Comparative Note


India's operator-level biometric model sits between two established international patterns. Nigeria links every SIM to a centrally issued National Identification Number and enforces this by barring unlinked lines, all within a jurisdiction that separately enacted a Data Protection Act in 2023, giving the collection mandate a statutory privacy backstop. Pakistan operates a similar centralised linkage without an equivalent data protection framework, and has documented both black market unregistered SIM activity and periodic mass deactivations as enforcement responses. India's choice of decentralised, operator-held biometric verification without a shared identifier, arriving before the DPDP Act's substantive obligations take effect in May 2027, currently resembles Pakistan's regulatory sequencing, biometric collection preceding privacy law, more than Nigeria's. It is also worth noting the empirical record these comparators offer on effectiveness: a widely cited 2016 GSMA study found no clear evidence that mandatory SIM registration directly reduces crime, and Mexico repealed its own 2009 registration law three years later for want of demonstrated results. India's rules proceed on an implicit fraud-reduction rationale that the closest comparable international experiments have not clearly validated.


VI. Practitioner Guidance


Telecom-adjacent clients, including any mobile application offering calling functionality, should seek written clarification from DoT on internet telephony scope before assuming exclusion, given the demonstrated pattern of DoT extending biometric identification requirements to messaging platforms through separate but related directives. Clients operating as licensed telecom entities should treat the three month compliance window, extendable by three more months at DoT's discretion, as the operative deadline for building D-KYC infrastructure, and should not assume the extension will be granted absent an explicit application demonstrating good faith progress. Given the absence of a specified retention period or encryption standard, clients should adopt internal data governance standards for biometric records that anticipate DPDP's eventual substantive obligations, rather than waiting for a future rule to specify minimum safeguards that may arrive only after significant data has already been collected under looser interim practices.


bottom of page