Back to Interaction with Other Laws

TRAI Digital Connectivity Rating

TRAI's Digital Connectivity Infrastructure Ratings and their data transparency implications under the DPDPA.

6 min read

The Rating Framework

TRAI's Digital Connectivity Infrastructure Ratings, under the 2024 Regulations, assess and publicly report on the digital connectivity of properties (buildings, apartments, and commercial complexes) - rather than regions. The framework is property-centric, designed to help buyers and tenants understand indoor connectivity. The assessment criteria are infrastructure-focused: Fiber readiness, in-building mobile coverage, Wi-Fi coverage, and Open Access for all Telecom Service Providers (TSPs). 'Customer service quality' is a general QoS metric and is not a scoring criterion in the Digital Connectivity Rating (DCR) manual.

Data Processing Implications

The TRAI DCR framework is designed to be infrastructure-led, not subscriber-led. Assessments are conducted by Digital Connectivity Rating Agencies (DCRAs) using signal testers and physical audits of the building's layout. If an operator provided 'subscriber usage patterns' or 'location-correlated data' to TRAI for property ratings, it would likely violate the data minimisation principle of the DPDPA, since property ratings can be achieved via objective signal testing without touching subscriber personal data. Where any limited subscriber-linked data is unavoidable, DPDPA requirements apply and operators must ensure that the data is appropriately anonymised or processed with a lawful basis.

Balancing Transparency and Privacy

Because the DCR framework publishes ratings for the property/building rather than the individual, there is no realistic scenario where a building's '4-star connectivity rating' could be reverse-engineered to identify a specific subscriber. Anonymisation remains a DPDPA best practice but is largely a precaution rather than a structural risk in this context. Operators should still: (a) avoid sharing subscriber-level data where infrastructure testing suffices; (b) maintain clear purpose limitation - data collected for service delivery should not be repurposed for ratings without an appropriate basis; and (c) align practices with the DPDPA's purpose limitation principle (Section 5) and data minimisation requirements. See the privacy notice requirements for how to communicate these purposes to subscribers.

Practical Steps for Operators

Operators (TSPs) should: (a) confirm that the primary 'Data Fiduciary' for the rating process is typically the Property Manager (Developer/Builder) or the DCRA, with TRAI acting as the regulator/overseer and TSPs acting as 'collaborators' who provide technical feasibility, not the core data for the rating; (b) limit any data shared to objective signal/infrastructure measurements; (c) conduct privacy impact assessments for any data submitted; (d) ensure any data processing arrangements with DCRAs and property managers address DPDPA requirements; and (e) maintain documentation of the lawful basis for any subscriber data processing in the ratings context.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.