Back to Interaction with Other Laws
Telecom Regulations and Telecommunications Act, 2023
How telecom regulations, the Telecommunications Act 2023, and TRAI requirements interact with the DPDPA for telecom operators.
7 min read
Telecommunications Act, 2023
The Telecommunications Act, 2023 contains provisions relevant to data protection in the telecom sector. It addresses subscriber data handling, interception obligations, and data retention requirements.
Telecom operators must reconcile these provisions with the DPDPA, particularly around consent for value-added services, data retention, and lawful interception obligations.
Subscriber Data Protection
Telecom operators handle vast volumes of subscriber data including identity information, call detail records, location data, and browsing metadata. Under the DPDPA, this constitutes personal data requiring consent or a legitimate use basis. Section 3(7) of the Telecommunications Act, 2023 mandates verifiable biometric-based identification for telecom subscribers; while DPDPA emphasises 'data minimisation,' the Telecom Act creates a statutory mandate for biometrics, which qualifies as a 'Legitimate Use' under Section 7(c) of the DPDPA.
Lawful interception obligations and data retention mandates under the Telecom Act and licence conditions may override DPDPA consent requirements under the Section 17 exemptions for State security and sovereignty. See the telecom sector guide for detailed compliance considerations.
Licence Conditions on Data
Telecom licence conditions impose specific obligations on subscriber data handling, including: storage requirements, access provisions for law enforcement, data retention for specified periods, and restrictions on sharing subscriber data with third parties.
These licence conditions continue to apply alongside the DPDPA. Where licence conditions mandate data retention or sharing, the DPDPA's exemption for compliance with any law (Section 7(c)) provides the lawful basis.
Key Overlap Areas
Critical overlap areas include: (a) data retention - telecom licence conditions may require longer retention than DPDPA's R.8; (b) consent for VAS - value-added services require DPDPA-compliant consent; (c) breach notification - telecom-specific incident reporting alongside DPDPA's R.7; and (d) cross-border - subscriber data may be subject to both DPDPA and telecom transfer restrictions.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
