Telecom operators hold the most granular personal data in India — call records, location, internet activity, and KYC for hundreds of millions of subscribers. DPDP Rules 2025 impose strict consent and purpose-limitation obligations that fundamentally change how this data can be used.
The DPDP Act 2023 and DPDP Rules 2025 apply fully to all telecom operators, ISPs, MVNOs, and OTT communication apps operating in India — all of which are Data Fiduciaries processing personal data of Indian subscribers at massive scale. Telecom entities must implement explicit, purpose-specific consent frameworks covering subscriber KYC, Call Detail Records (CDRs), location data, usage patterns, and device identifiers. TRAI regulations do not substitute for DPDP compliance — both operate independently. Lawful interception obligations under the Indian Telegraph Act provide a narrow legitimate use carve-out, but subscriber data cannot be repurposed for advertising or analytics without separate, freely given consent. The enforcement deadline is May 13, 2027, with penalties reaching ₹250 crore per incident.
Telecom operators sit at the intersection of sector regulation and data protection law, processing more personal data per subscriber than almost any other industry.
Jio, Airtel, and Vi collectively process KYC documents, call records, and usage patterns for over 900 million subscribers. Implementing a DPDP-compliant consent framework at this scale is operationally complex — existing systems must be retrofitted to capture, store, and honour purpose-specific consent for each data category. Bulk consent bundled into service terms is not valid under DPDP; each distinct processing purpose requires a separate, documented consent signal from each subscriber.
TRAI's privacy regulations, IUC (Interconnect Usage Charge) data sharing obligations, and lawful interception requirements under the Indian Telegraph Act all intersect with DPDP's consent and purpose-limitation framework. These are separate legal systems — compliance with TRAI directions does not satisfy DPDP obligations and vice versa. Telecom operators need an integrated compliance framework that maps each data processing activity to its applicable regulatory basis across both regimes, identifying conflicts and documenting justified exceptions before enforcement begins.
CDRs capture originating number, destination number, call duration, timestamp, and cell tower location — all of which are directly linked to an identifiable subscriber and therefore constitute personal data under DPDP Act 2023. CDRs require strict access controls limiting retrieval to authorised personnel for documented purposes. Retention must be bounded by a lawful purpose — CDRs retained for billing or lawful interception compliance cannot simultaneously be mined for analytics, network planning, or advertising without separate consent and a distinct data silo.
Telecom analytics teams routinely segment subscribers by usage patterns — data consumption, call frequency, app preferences, roaming behaviour — to enable targeted advertising and product recommendations. DPDP Act 2023 requires that each such use be explicitly consented to by the subscriber. Usage data collected for network provisioning and billing cannot be repurposed for commercial analytics or advertising without a distinct consent event. Operators must redesign their analytics pipelines to enforce purpose segregation and prevent unauthorised secondary use by internal teams.
Every category below is personal data under the DPDP Act. Each requires a valid legal basis, purpose documentation, and Data Principal rights enablement.
A structured approach built for the operational scale of telecom — not a generic compliance checklist designed for smaller organisations.
Document every data processing activity — SIM activation, CDR generation and retention, lawful interception, IUC data sharing, analytics, and advertising — and map each to its applicable regulatory basis. For each activity, identify whether the legal basis is (a) a TRAI or DoT direction (creating a legitimate use basis under DPDP), (b) a contractual necessity, or (c) subscriber consent. Where TRAI obligations require data retention beyond the period justified under DPDP, document the legal justification and ensure it is defensible. This mapping exercise surfaces the 15–20 structural conflicts every major telecom operator will need to resolve before enforcement begins.
Design and deploy a consent management layer that can handle consent collection, storage, and withdrawal for hundreds of millions of subscribers. DPDP requires that consent be purpose-specific, freely given, and withdrawable at any time without affecting the core service. For telecom operators, this means separating mandatory data processing (KYC for SIM issuance, CDRs for billing and lawful compliance) from optional processing (targeted advertising, data analytics, third-party data sharing). The consent layer must integrate with SIM activation flows, MyJio/Airtel Thanks/Vi app interfaces, IVR systems, and retail point-of-sale to capture consent at the moment of collection — not buried in terms and conditions at account opening.
Implement technical and organisational controls that prevent internal data science, marketing, and advertising teams from accessing subscriber data beyond the purposes for which consent was obtained. This requires data warehouse segmentation — creating separate analytical environments for (a) consented analytics use cases and (b) operational data used for billing, network management, and regulatory compliance. Access control policies must enforce purpose limitation at the query level, with audit logs that document what data was accessed, by whom, and for what purpose. Analytics pipelines that currently operate across the full subscriber dataset must be redesigned to filter for consented subscribers only.
Telecom operators face two critical milestone dates. Given subscriber scale, implementation typically takes 9–15 months — planning must begin immediately.
Fixed-price tools and expert engagements built for India's telecom sector. Start with a free assessment or jump straight to a paid deep-dive.
Tell us about your organisation and your biggest DPDP concern. We'll come prepared with observations specific to your subscriber data profile and regulatory landscape — not generic advice.
Answers to the questions we hear most from telecom operators, ISPs, and their regulatory and legal teams.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.