Back to Sectors & Impact

Telecom

DPDPA compliance for telecom operators - subscriber data, call records, location data, TRAI regulations, and consent management for value-added services.

7 min read

Sector Overview

Telecom operators process vast quantities of subscriber personal data including identity information (name, address, Aadhaar for KYC), call detail records (CDRs), location data, internet usage patterns, and billing information. The DPDPA applies to all digital processing of this data, requiring telecom companies to implement comprehensive data protection practices. The sector must reconcile DPDPA requirements with existing obligations under the Telecommunications Act, 2023 (which has repealed and replaced the Indian Telegraph Act, 1885), TRAI regulations, and Department of Telecommunications (DoT) license conditions.

Key DPDPA Provisions for Telecom

Section 5-6 (Consent): Telecom operators must obtain specific consent for processing subscriber data beyond core service delivery. Value-added services, marketing, data sharing with third parties, and analytics require separate consent. Section 7 (Legitimate Uses): Processing subscriber data for compliance with license conditions, law enforcement assistance (lawful interception), and legal obligations falls under legitimate uses. Section 8 (Obligations): Telecom operators must implement robust security safeguards for subscriber data, CDRs, and location data. Rule 6 requirements for encryption, access controls, and log retention are directly applicable. Section 10 (SDF): Major telecom operators processing data of millions of subscribers are strong candidates for Significant Data Fiduciary designation, triggering enhanced obligations. Section 16 (Cross-Border): International roaming data, interconnection data, and data shared with global technology vendors must comply with cross-border transfer provisions.

Compliance Considerations

1. CDR and Location Data: Call detail records and location data are highly sensitive. Implement stringent access controls, encryption, and retention policies. Review law enforcement access procedures for DPDPA compliance. 2. Value-Added Services: Consent for core telecom services does not extend to value-added services, entertainment bundles, or financial services. Implement granular consent for each service category. 3. SIM Registration and KYC: While Section 7(c) covers KYC processing for SIM registration as a legal obligation (legitimate use), Section 3(7) of the Telecommunications Act, 2023 specifically mandates the use of "verifiable biometric-based identification" for SIM registration. There is a clear tension between DPDPA's data minimisation principle and the Telecom Act's biometric mandate. Using KYC data for marketing or cross-selling beyond SIM issuance requires separate consent. 4. Network Analytics: Analytics on network usage data must comply with purpose limitation. Aggregate, anonymised analytics may fall outside the DPDPA's scope, but individual-level analytics require consent. 5. Third-Party Data Sharing: Review data sharing arrangements with content providers, advertisers, device manufacturers, and analytics companies. Each sharing arrangement requires appropriate consent or legitimate use basis. 6. IoT and M2M: Connected device data processed by telecom operators constitutes personal data if it can identify individuals. Implement appropriate consent and security measures.

Practical Compliance Checklist

*Note: This checklist is interpretive guidance derived from the DPDPA's general provisions (Sections 5-8, 10, 16, Rules 6, 14). It should be validated by legal counsel for your specific organisational context.* • Map all subscriber data processing activities including CDRs, location data, and usage patterns • Implement granular consent for core services vs. value-added services vs. marketing • Upgrade security safeguards for CDR and location data per Rule 6 • Review law enforcement data access procedures for DPDPA alignment • Prepare for SDF designation - appoint DPO, plan for DPIA and audits • Review data sharing agreements with content providers and advertisers • Implement data retention and erasure policies for subscriber data • Establish 90-day grievance redressal mechanism per Rule 14 • Update privacy notices for clarity on data processing purposes • Train customer service and network operations teams on DPDPA obligations

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.