Back to Interaction with Other Laws

Telecom Regulations and Telecommunications Act, 2023

How telecom regulations, the Telecommunications Act 2023, and TRAI requirements interact with the DPDPA for telecom operators.

7 min read

Telecommunications Act, 2023

The Telecommunications Act, 2023 contains provisions relevant to data protection in the telecom sector. It addresses subscriber data handling, interception obligations, and data retention requirements. Telecom operators must reconcile these provisions with the DPDPA, particularly around consent for value-added services, data retention, and lawful interception obligations.

Subscriber Data Protection

Telecom operators handle vast volumes of subscriber data including identity information, call detail records, location data, and browsing metadata. Under the DPDPA, this constitutes personal data requiring consent or a legitimate use basis. Section 3(7) of the Telecommunications Act, 2023 mandates verifiable biometric-based identification for telecom subscribers; while DPDPA emphasises 'data minimisation,' the Telecom Act creates a statutory mandate for biometrics. Where this involves disclosure of subscriber information to the State for verification, that disclosure may qualify as a 'Legitimate Use' under Section 7(d) of the DPDPA, which covers disclosure of information to the State under a law requiring such disclosure; it does not extend more broadly to the collection of biometric data itself. A proviso to section 7(d) requires that such disclosure accord with the disclosure provisions of the other law under which it is made. Lawful interception obligations and data retention mandates under the Telecom Act and licence conditions may override DPDPA consent requirements under the Section 17 exemptions for State security and sovereignty. See the telecom sector guide for detailed compliance considerations.

Licence Conditions on Data

Telecom licence conditions impose specific obligations on subscriber data handling, including: storage requirements, access provisions for law enforcement, data retention for specified periods, and restrictions on sharing subscriber data with third parties. These licence conditions continue to apply alongside the DPDPA. Where licence conditions mandate sharing of subscriber data with the State, the DPDPA's legitimate use for disclosure of information to the State (Section 7(d)) provides the lawful basis for that disclosure; retention obligations that do not involve disclosure to the State are not themselves covered by Section 7(d).

Key Overlap Areas

Critical overlap areas include: (a) data retention - telecom licence conditions may require longer retention than DPDPA's R.8; (b) consent for VAS - value-added services require DPDPA-compliant consent; (c) breach notification - telecom-specific incident reporting alongside DPDPA's R.7; and (d) cross-border - subscriber data may be subject to both DPDPA and telecom transfer restrictions.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.