Update
The Department of Telecommunications (DoT) notified the Telecommunications (User Identification) Rules, 2026 on 21 August 2026. The rules require telecom operators to verify users through biometric methods, either Aadhaar-based e-KYC for Aadhaar holders, or D-KYC, involving live facial capture and document verification, for non-Aadhaar holders, at the point of enrolment, when updating account information, when disconnecting service, and during periodic reverification. The rules took effect the day they were notified and apply to wireless access services and to internet telephony provided through mobile user terminals.
The final rules differ from the draft version DoT circulated for public consultation in September 2025. That draft had proposed a Biometric Identity Verification System (BIVS), a shared database that would have let telecom operators cross-check user identities against each other's records using a common identifier. The final rules drop BIVS entirely in favour of operator-specific verification processes. DoT has not published a detailed explanation for the change, though the draft attracted formal objections from digital rights groups, including the Internet Freedom Foundation, which raised concerns about creating a parallel biometric database alongside the existing Aadhaar system without comparable statutory safeguards.
The rules also restrict SIM transfers to relatives or legal heirs, a provision carried over from the draft.
Technical compliance measures must be implemented within three months of notification, extendable by a further three months at DoT's discretion.
Analysis
Whether the rules represent a stronger or weaker privacy outcome compared to the original draft depends on which risk is being weighed. Dropping the shared BIVS database removes the prospect of a single centralised biometric store spanning all telecom operators, a change digital rights groups broadly welcomed. It does not reduce the total amount of biometric data being collected, which is now held separately by each operator rather than in one shared system, and the final rules do not specify a retention period, deletion timeline, or encryption standard for this data, deferring instead to "applicable data protection law." Since the DPDP Act's substantive data-protection obligations do not take effect until May 2027, there is a period during which biometric data collected under these rules will not yet be subject to the Act's operative safeguards.
DoT has not clarified whether the rules' coverage of "internet telephony service through mobile user terminals" extends to over-the-top calling applications such as WhatsApp or Signal. This question has practical significance given DoT's separate, previously reported direction requiring WhatsApp and Telegram to bind accounts to verified SIM numbers under the Telecommunication Cybersecurity Amendment Rules, 2025, a move MediaNama has tracked through right-to-information requests and stakeholder consultations. Traditional telecom operators have separately lobbied for years to bring such messaging services within the scope of telecom regulation more broadly.
The restriction on SIM transfers to relatives or legal heirs was flagged at the draft stage by commentators, including MediaNama, as inconsistent with common practices in India, where a single registered connection is often shared informally within households or small businesses in ways that do not map cleanly onto the categories the rule recognises. This concern was not addressed in the final rules.
International comparisons offer mixed evidence on the underlying premise that biometric SIM registration reduces fraud and crime. A widely cited 2016 GSMA study found no clear evidence that mandatory registration directly reduces criminal activity, and Mexico repealed a similar law in 2012, three years after enacting it, citing a lack of demonstrated results. Nigeria and Pakistan, both of which operate centralised biometric SIM-linkage systems, have taken different approaches on the privacy side: Nigeria has done so alongside a dedicated data protection law enacted in 2023, while Pakistan has not.
Comments
0 commentsNo comments yet — be the first.