Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 36 weeks awayRead handbook →

A Face Scan for a SIM — and Nine Months Before the DPDP Act Governs What Happens to It

India's telecom biometric rules took effect 24 August 2026. They defer retention and security to the DPDP Act, which doesn't bind until 13 May 2027.

D
DPDPBot Research Team
🕐 12 min read

#A Face Scan for a SIM — and Nine Months Before the DPDP Act Governs What Happens to It

Since 24 August 2026, no one in India can buy a SIM card, swap a damaged one, correct a name, or even voluntarily surrender their own number without submitting to a live capture of their face, fingerprint or iris. The rule that compels that biometric capture says the resulting record must be handled "in accordance with applicable data protection law" — and the applicable law, the DPDP Act 2023, does not impose a single retention, erasure or security obligation on a telecom operator until 13 May 2027.

That is a nine-month window in which every new mobile connection in the country generates a biometric record governed by a statute that has not switched on. It is the sharpest collision yet between India's sectoral regulators, who are moving fast, and the DPDP Act, which is still phasing in.

#What the Telecommunications (User Identification) Rules, 2026 actually require

The Department of Telecommunications notified the Telecommunications (User Identification) Rules, 2026 in the Gazette on 21 August 2026 as G.S.R. 750(E), made under Sections 56(1) and 56(2)(a) and (e) of the Telecommunications Act, 2023. The Rules came into force on publication, with the operational checks biting from 24 August. DoT's Licensing Policy Wing had already issued the accompanying portal instructions a week earlier, in Circular no. 2/User Identification/2026 dated 14 August 2026 (F. No. 800-01/2026-LPU), which is listed on the DoT eServices Act & Rules page.

"Biometric identification" under the Rules means a live capture — face, fingerprint or iris — that verifies the physical presence of the person in front of the operator. Per the Internet Freedom Foundation's reading of the notified text, it is mandatory at four separate points:

  • before enrolment for any new connection or SIM;
  • before updating user information — replacing a SIM, or changing name, gender or date of birth;
  • before disconnection at the user's own request;
  • whenever the Central Government directs re-verification under Rule 7.

The third of those is the one that should give compliance teams pause. A person who wants to stop being a subscriber must first submit a fresh biometric. The stated rationale is fraud prevention — stopping someone else from surrendering your number — but the effect is that leaving the system requires one more deposit into it.

The Rules also reach business connections. Under Rule 6(4), the authorised representative of a business user must intimate any change in the end user of a business connection within 3 working days, and must ensure the new end user completes biometric identification within 7 working days. Rule 8 prescribes a form by which an operator informs the Central Government of misrepresentation, keyed to the telecommunication identifier and the details of the misrepresentation. Every enterprise in India running pooled corporate SIMs now has a named, date-bound obligation attached to each handset it reassigns.

Operators have three months from commencement, extendable to six, to move from today's post-facto verification to real-time biometric checks. Reporting places the changeover at 30 November 2026 — 85 days from now.

#Aadhaar holders get no choice, and the operator keeps the Aadhaar number

The Rules set two routes, and which one applies is not a user preference.

e-KYC applies to every Aadhaar number holder. Rule 3(3) mandates it. The operator authenticates the user through UIDAI's Aadhaar e-KYC authentication facility and then stores the e-KYC data, including the Aadhaar number itself, received from UIDAI in the subscriber record.

D-KYC is the fallback, reserved for a user who does not hold an Aadhaar number, or who holds one but cannot complete face, fingerprint or iris capture because of an impairment, disfigurement, injury or amputation. Under D-KYC the operator performs a live capture of the user's face, captures images of identity and address documents, and verifies that the live face matches both the person present and the photograph on the document. Where a claim of identity or address cannot be verified, the operator may conduct a field visit, seek police assistance, or both.

Two things follow. First, the exclusion risk is concentrated exactly where you would expect: people whose fingerprints do not read, whose faces do not match a decades-old document photograph, or whose documentary trail is thin now face a verification path that can end in a police enquiry to obtain a phone number. Second, the storage instruction — Aadhaar number retained in the operator's own customer record — is a data minimisation problem sitting in plain sight in the rule text. The DPDP Act's Section 8 discipline, when it arrives, requires a Data Fiduciary to hold only what the specified purpose needs, and to erase it when the purpose lapses. A permanently stored Aadhaar number, alongside a face template, in the records of four national operators is a hard thing to square with that.

#The retention gap: a rule that defers to a law not yet in force

Here is the specific defect, and it is the reason this story matters more than a routine KYC tightening.

The Rules provide that the subscriber data record must be maintained in accordance with applicable data protection law. They do not specify a retention period. They do not specify a deletion trigger. They do not specify an encryption standard for the biometric or the e-KYC payload.

Now line that up against the DPDP commencement schedule. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 with a staggered rollout: Rules 1, 2 and 17–21 immediately; Rule 4, the consent manager registration framework, on 13 November 2026; and Rules 3, 5–16, 22 and 23 — the substantive engine of the Act, covering notice, security safeguards, retention, erasure and breach reporting — on 13 May 2027.

So a rule in force today points at obligations that arrive in nine months' time. In the interval, the only thing standing between a face template and indefinite retention is each operator's own policy. The DPDP Act's Section 8(7) erasure duty — delete when consent is withdrawn or when it is reasonable to assume the specified purpose is no longer served, whichever is earlier — is not yet operative against them. Nor does the Third Schedule to the DPDP Rules help: its three-year default erasure clocks attach to large e-commerce, online gaming and social media entities, not to telecom operators.

When the DPDP obligations do land, the operator's defence will be that retention is necessary for compliance with law. That defence is only as wide as the law it points to — and the Telecom Rules, by staying silent on retention, do not actually require indefinite storage. They just fail to forbid it. Every operator will have to decide for itself where the line falls, and the Data Protection Board will eventually have to decide whether it agreed.

#The lawful basis problem nobody has answered

There is a second, quieter question that the DPDP Act poses to this scheme, and it has no clean answer in the statute.

Section 7 of the DPDP Act is a closed list. It sets out the legitimate uses on which a Data Fiduciary may process personal data without consent, and no further ground can be read into it. Clause (b) and clause (c) cover processing by the State. Clause (d) covers fulfilling an obligation under Indian law to disclose information to the State. Clause (e) covers compliance with a judgment, decree or order. Clause (i) covers employment. There is no general "compliance with a legal obligation" ground available to a private company.

A telecom operator capturing and storing a face template is not the State. It is not disclosing that template to the State at the moment of capture — the DIP feed and the Rule 8 misrepresentation form are separate acts, and those may well sit inside clause (d). The capture and retention themselves do not. Which leaves consent under Section 6 as the residual basis — consent that Section 6(1) requires to be free, specific, informed, unconditional and given by clear affirmative action, and that Section 6(2) confines to the personal data necessary for the specified purpose.

Consent to a face scan, where refusing means you cannot have a phone, is a strange kind of free. That tension is not fatal — statutory mandates and consent frameworks coexist in many jurisdictions — but it is unresolved, and it will be unresolved on 13 May 2027 unless MeitY or DoT addresses it. Enterprises building DPDP consent architecture on the assumption that "we were required to collect it" is a lawful basis should check that assumption against the Section 7 text. It is one of the sharpest divergences between the DPDP Act and the GDPR, whose Article 6(1)(c) legal-obligation ground handles this case directly.

#Your photograph, distributed daily to every operator

Running alongside the Rules is a companion DoT instruction that has attracted far less attention and is arguably the more novel privacy event.

To enforce the long-standing cap on mobile connections — nine per individual nationally under instructions dating to 9 August 2012, six in Jammu & Kashmir, Assam and the North-Eastern service areas — DoT has directed operators to work off the Digital Intelligence Platform (DIP). From 23 August 2026, a "representative image" of every subscriber who has already hit the cap is made available on the DIP, and operators must download those images daily and use them to identify applicants at the point of sale. Blocking of over-cap applications began 24 August 2026, with operators required to align their processes to the platform by 30 November 2026.

Read that carefully. A facial image collected by one operator, under one contract, for one subscriber relationship, is routed through a government platform and pushed daily to competitors who have no relationship with that person at all. When Chapter II of the DPDP Act commences, each of those recipients becomes a Data Fiduciary in respect of an image it holds without consent, for a purpose the person never specified, about someone who is not its customer. Purpose limitation is not a stylistic preference in the Act — it is the mechanism the whole statute runs on.

#What was dropped, and what it tells you

The September 2025 draft of these Rules proposed a Biometric Identity Verification System (BIVS): a single cross-industry biometric database, assigning unique identifiers to telecom customers and letting operators verify against each other's records. It did not survive. Biometric Update reports that BIVS was cut from the final text after civil society objections — the Internet Freedom Foundation, which filed detailed objections in October 2025, had argued it amounted to an unnecessary parallel biometric collection without the consent, retention and correction safeguards that the Aadhaar Act at least nominally provides.

That is a real consultation win, and it is worth recording as one. But note what replaced it: not a shared database, but a shared daily image feed through the DIP. The centralised store was removed; the distribution was not.

There is also a constitutional shadow here. In K.S. Puttaswamy (Aadhaar-5J.) v. Union of India, decided 26 September 2018, the Supreme Court struck down the DoT circular of 23 March 2017 that had required all licensees to re-verify every existing subscriber through Aadhaar-based e-KYC. Rule 3(3) does not re-verify the existing base by default — but Rule 7 lets the Central Government direct re-verification, and Rule 3(3) makes Aadhaar e-KYC the only route for anyone who holds an Aadhaar number. Whether that combination is meaningfully different from what the Court rejected is a question a petitioner will eventually put to a bench.

#What operators and enterprises should do before 30 November

The compliance work does not wait for May 2027, because the two regimes will be assessed together the moment the Board starts adjudicating.

  1. Write the retention schedule the Rules didn't. Fix a period for the biometric template, the e-KYC payload and the stored Aadhaar number, document the justification, and build the deletion job now. Retrofitting erasure onto a biometric store in 2027 is materially harder than designing it in 2026.
  2. Separate the template from the record. Store biometric material under distinct keys and distinct access control from the ordinary subscriber record. Under the DPDP Schedule, failure to take reasonable security safeguards to prevent a personal data breach carries a ceiling of ₹250 crore — the highest penalty in the Act, above even the ₹200 crore ceiling for failing to notify a breach.
  3. Map the DIP feed as its own processing activity. It has a different source, a different purpose and a different set of data principals from your own subscriber base. Treat downloaded images as a separate dataset with a separate retention rule, and delete daily unless there is a documented reason not to.
  4. Fix the business-connection workflow. Rule 6(4)'s 3-day and 7-day clocks apply to every corporate SIM pool in the country. Most enterprises currently have no mechanism to detect, let alone report, a handset changing hands within three working days.
  5. Re-examine your lawful basis paperwork. If your DPDP readiness documentation records "legal obligation" as the basis for KYC processing, check it against the closed Section 7 list before it becomes an enforcement exhibit.

Our compliance resources track the sectoral obligations that are already live against the DPDP milestones that are not, and the consent manager explainer covers the Rule 4 registration route opening on 13 November 2026 — the other date on this year's calendar that is closer than it looks.

#What it means if you are just buying a phone

For an ordinary subscriber, three things changed on 24 August and most people have not been told any of them.

You will be asked for a live face scan at the point of sale, and if you have an Aadhaar number you cannot opt for the document route instead. Your Aadhaar number will sit in your operator's own records, not merely in UIDAI's. And if you already hold nine connections, a picture of you is being circulated daily to every operator in the country so that they can refuse you a tenth.

None of that is unlawful. All of it is happening before the law that is supposed to govern it has come into force. That sequencing — sectoral mandate first, data protection discipline nine months later — is now the defining feature of Indian privacy regulation in 2026, and it is the gap that businesses, not regulators, will be left to close.


Sources: Internet Freedom Foundation · Biometric Update · MediaNama · Mobile ID World · tele.net.in · Deccan Chronicle · DoT eServices — Act & Rules

Automate your DPDP compliance

Capture consent, honour data principal rights, and stay audit-ready — all in one platform.

Start free trial