Telecom operators handle vast volumes of subscriber data including identity information, call detail records, location data, and browsing metadata. Under the DPDPA, this constitutes personal data requiring consent or a legitimate use basis. Section 3(7) of the Telecommunications Act, 2023 mandates verifiable biometric-based identification for telecom subscribers; while DPDPA emphasises 'data minimisation,' the Telecom Act creates a statutory mandate for biometrics. Where this involves disclosure of subscriber information to the State for verification, that disclosure may qualify as a 'Legitimate Use' under Section 7(d) of the DPDPA, which covers disclosure of information to the State under a law requiring such disclosure; it does not extend more broadly to the collection of biometric data itself. A proviso to section 7(d) requires that such disclosure accord with the disclosure provisions of the other law under which it is made.
Lawful interception obligations and data retention mandates under the Telecom Act and licence conditions may override DPDPA consent requirements under the
Section 17 exemptions for State security and sovereignty. See the
telecom sector guide for detailed compliance considerations.