Back to Interaction with Other Laws

Draft Telecom Cybersecurity Rules, 2025

Understanding the draft Telecom Cybersecurity Rules 2025 - TIUE concept, MNV Platform, IMEI restrictions, and interaction with DPDPA.

7 min read

TIUE - Telecommunication Identifier User Entity

The TCS Amendment Rules, 2025 formally define the Telecommunication Identifier User Entity (TIUE). A TIUE is any non-licensee entity (for example, a Bank, e-commerce app, or Fintech) that uses telecom identifiers (mobile numbers, IMEI) for user verification. TIUE-related processing overlaps significantly with 'personal data' under the DPDPA. Processing of TIUE data must comply with both the Telecom Cybersecurity Rules and the DPDPA's requirements.

Mandatory National Verification Platform

The Rules establish a Mandatory National Verification (MNV) Platform under Rule 7A. The MNV Platform is decentralised by design - it does not create a large central database of its own. Instead, it acts as a real-time validation bridge: a TIUE sends a request, and the MNV routes it to the relevant Telecom Service Provider (TSP) to confirm whether the number belongs to the claimed identity. The MNV Platform's operations remain subject to DPDPA requirements including purpose limitation, security safeguards, and - depending on its designation - potential SDF obligations.

IMEI-Based Restrictions

The Rules establish a framework for IMEI-based restrictions on stolen, counterfeit, or non-compliant devices. Under the 2025 Rules, entities in the resale market are now statutorily required to 'scrub' (check) every IMEI against the central blacklist before sale. This is a mandatory safety requirement that overrides the need for user consent for that specific check. The interplay between IMEI tracking and DPDPA's purpose limitation principle requires careful analysis - IMEI data collected for security purposes should not be used for other purposes without separate consent or lawful basis.

6-Hour Incident Reporting

The Rules mandate reporting of cybersecurity incidents to CERT-In within 6 hours. This is significantly shorter than DPDPA's R.7 breach notification framework, which requires a notice 'as soon as possible' followed by a detailed report to the Board within 72 hours. Telecom entities cannot 'choose' a single timeline - they must trigger the 6-hour CERT-In/Telecom report first to avoid the ₹50 lakh fine under the Telecom Act, then follow up with the DPDPA's 72-hour detailed submission to the Board. A unified incident response process that meets the stricter telecom timeline while also satisfying DPDPA's content requirements is the most efficient approach.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.