
Loading...
Law Update
Quick note
Below is the official summary and the reference document preview. Use âOpen PDFâ for full screen view.
The Department of Telecommunications (DoT) has brought two specific categories of telecom services within the biometric user-identification requirement under the Telecommunications Act, 2023.
Through notification S.O. 4623(e), dated 21 August 2026, the central government has notified wireless access services and internet telephony services through mobile user terminals. Authorized entities providing these services are required to ensure verifiable biometric-based identification of their users in accordance with the Telecommunications (User Identification) Rules, 2026.
The notification is only two pages long, but its wording has direct compliance consequences for the entities within its scope. At the same time, it should not be read more broadly than it is written. It does not say that every telecom service, every internet calling platform, or every user in India automatically falls under this particular notification.
For telecom operators, the first job is therefore not to rush into a new verification process. It is to establish whether the service being offered is one of the services actually notified.
| Particular | Verified Details |
| Issuing authority | Central Government |
| Ministry | Ministry of Communications |
| Department | Department of Telecommunications |
| Document type | Department of Telecommunications |
| Notification number | S.O. 4623(E) |
| Date | 21 August 2026 |
| Gazette | Gazette of India, Extraordinary |
| Gazette section | Part II, Section 3, Sub-section (ii) |
| Legal basis | Section 3(7) of the Telecommunications Act, 2023 |
| Rules referred to | Telecommunications (User Identification) Rules, 2026 |
| Service 1 | Wireless access services |
| Service 2 | Internet telephony service through mobile user terminals |
| Entity responsible | Authorized entities providing the notified services |
| Main requirement | Verifiable biometric-based identification of users |
| Separate compliance deadline | Not expressly specified in S.O. 4623(E) |
| Transition period | Not expressly specified in S.O. 4623(E) |
| File number | F. No. 800-22/2024-AS.II |
The notification is precise about three things: the services covered, who carries the responsibility and the requirement that identification must follow the Telecommunications (User Identification) Rules, 2026.
It is much less detailed on implementation. There is no separate table of procedures, technology specifications, fees or transition dates in S.O. 4623(E) itself.
The August 2026 notification does not create an isolated biometric-KYC system. It sits within the broader structure of the Telecommunications Act, 2023 and the Telecommunications (User Identification) Rules, 2026.
Section 3(7) of the Telecommunications Act, 2023
Section 3 of the Telecommunications Act deals with authorization. Sub-section (7) states that an authorized entity providing a telecommunication service notified by the Central Government must identify the person receiving that service through a verifiable biometric-based identification method as prescribed.
This explains why S.O. 4623(E) matters.
The Act creates the legal mechanism. The government then issues a notification identifying the telecom services to which that mechanism applies. S.O. 4623(E) names two such categories.
This distinction also prevents an unnecessarily broad interpretation. The legal requirement under Section 3(7) is tied to services notified by the Central Government, rather than being worded in the notification as a blanket requirement for every telecom service.
Telecommunications (User Identification) Rules, 2026
The second part of the framework is the Telecommunications (User Identification) Rules, 2026.
DoT's Telecom e-services Portal confirms that these Rules have been made live on the portal.
S.O. 4623(E) expressly states that the biometric identification of users has to be ensured in accordance with these Rules.
That is why the notification and Rules have to be read together.
A simple way to understand the structure is:
| Legal Instrument | What It Does |
| Telecommunications Act, 2023 | Provides the legal power and wider authorization framework |
| S.O. 4623(E), 2026 | Identifies the telecom services covered by this notification |
| Telecommunications (User Identification) Rules, 2026 | Governs how user-identification requirements operate |
For a telecom business, reading only the Gazette notification is therefore not enough to design an operational KYC process.
The immediate change is that two categories of telecom services have now been expressly notified for Section 3(7).
They are:
The responsibility rests with authorized entities providing those services. They are required to ensure verifiable biometric-based identification of the users to whom the services are provided.
The practical position can be read as follows:
| Compliance Area | Position Under S.O. 4623(E) | Practical Meaning |
| Wireless access services | Expressly notified | Relevant authorized providers come within the notification |
| Internet telephony | Covered where provided through mobile user terminals | Exact service classification matters |
| User identification | Must be verifiable and biometric-based | Provider must follow the applicable identification framework |
| Responsible party | Authorized entity | Compliance responsibility lies with the service provider |
| Manner of compliance | According to the 2026 Rules | S.O. 4623(E) cannot be read as the full operating procedure |
What should not be said is that telecom KYC itself started on 21 August 2026. The notification is narrower than that. Its job is to identify particular services for the biometric requirement under Section 3(7).
The most important compliance question is simple: does the service being provided fall within one of the two categories named in the notification?
That question should be answered before technology, paperwork or internal processes are changed.
Wireless Access Services
Wireless access services are expressly mentioned in clause (a) of the notification.
An authorized entity providing a service that falls within this category must therefore consider the biometric user-identification requirement and the corresponding 2026 Rules.
The commercial name used for a service should not be the sole basis for determining applicability. The provider's regulatory authorization and the legal classification of the service should also be checked.
Internet Telephony through Mobile User Terminals
The wording of the second category deserves close attention.
The Gazette does not simply say "internet telephony services." It says:
A business should not assume that every VoIP product, internet calling platform, software application or online communication service automatically falls within this notification merely because voice communication takes place over the internet.
The nature of the service, the way it is delivered, and the regulatory authorization under which it operates have to be looked at together.
Applicability Matrix
| Service or Entity | Position Under S.O. 4623(E) | What Should Be Checked |
| Wireless access service provider | Expressly covered | Authorization and user-identification process |
| Internet telephony through mobile user terminals | Expressly covered | Whether the particular service fits the notified description |
| Authorized entity providing either notified service | Responsible for compliance | Applicable User Identification Rules |
| Other telecom service | Not established by this notification alone | Separate notification, Rules or authorization conditions |
| General software or communication platform | Cannot be decided from name alone | Actual service model and telecom regulatory status |
This is one area where a telecom compliance consultant or internal regulatory team can add value. Applicability should be determined by the legal and operational facts rather than by assumptions about the technology being used.
S.O. 4623(E) places the responsibility on the authorized entity providing the notified service.
The relevant wording says that authorized entities shall ensure verifiable biometric-based identification of the users receiving those services.
That may sound like a small drafting point, but it matters in practice.
The user may have to participate in the verification process. The compliance responsibility under this notification, however, sits with the authorized service provider.
For an operator, that turns biometric identification into more than a customer-KYC task. Legal, compliance, operations and technology teams may all have a role.
The operator needs to know:
Not every item in this list is separately written into S.O. 4623(E). They are practical questions that arise when an authorized entity converts the legal requirement into an operating process.
The notification uses the expression âverifiable biometric-based identificationâ, but it does not provide its own detailed technical procedure.
This is exactly where businesses need to avoid reading too much into a short Gazette notice.
S.O. 4623(E) does not itself say that the only acceptable method is:
Those conclusions should not be added unless they are supported by the Telecommunications (User Identification) Rules, 2026 or another applicable DoT instruction.
The safer compliance approach is first to identify the method permitted or prescribed by the official framework and then check whether the company's existing technology can support it.
Buying a biometric solution and using a biometric solution that meets the applicable regulatory requirements are two different things.
The notification answers âwhich notified services?â
The Rules answer the wider question of âhow user identification must be handled?â
This division is important for management teams because otherwise businesses may treat the Gazette notice as if it were a complete implementation manual.
It is not.
The Department of Telecommunications also lists separate instructions on its e-services portal in connection with the Telecommunications (User Identification) Rules, 2026. The portal shows an item titled âInstructions to be specified on the portal in accordance with the Telecommunications (User Identification) Rules, 2026,â published on 9 August 2026.
That tells affected entities something practical: the compliance framework extends beyond this single notification. The Rules and official instructions need to form part of the review.
For a wireless access provider within the notified category, the issue moves from general awareness to operational readiness.
The provider should first check how users are currently identified and whether that process fits the framework required under the 2026 Rules.
Areas likely to require review include:
Some operators may already have mature digital on boarding systems. Others may rely on several systems or external service providers.
The amount of work required will therefore differ from one authorized entity to another. S.o. 4623(e) does not prescribe a single implementation cost or a standard internal setup for every provider.
Internet telephony providers have an additional issue to settle before looking at compliance mechanics: service classification.
The notification's reference is to internet telephony through mobile user terminals.
A provider should therefore examine what service is actually being supplied, how the customer accesses it and under which telecom authorization the service is offered.
This matters because internet-based communications can take many forms. A business may describe a product commercially as âcalling,â âvoice,â âcommunicationâ, or âVoIP,â but a marketing description by itself does not settle the regulatory position.
If there is uncertainty, an applicability review should come before changes are made to KYC or biometric systems.
For affected providers, on boarding is likely to be one of the first business processes that needs examination.
Biometric identification has to fit somewhere into the journey between a customer requesting a telecom service and that service being provided.
The compliance team therefore needs to look beyond the verification screen itself.
Questions worth checking include:
These are practical review points. They should not be presented as separate duties created by S.O. 4623(E) unless the Rules expressly say so.
A biometric user-identification requirement cannot normally be managed by one department working alone.
Legal and Compliance Team
The first responsibility is interpretation.
This team should determine whether the service is covered, identify the relevant authorization and map the notification against the User Identification Rules and DoT instructions.
A good compliance review should separate what is legally compulsory from what the company chooses to introduce as an internal control.
KYC and Customer-On boarding Team
The KYC team is responsible for turning regulatory requirements into a customer-facing process.
If an existing process was designed under earlier instructions, it should be checked against the current framework rather than being carried forward automatically.
Technology Team
Technology teams need a clear legal requirement before they start changing systems.
That reduces the risk of building a verification process around a technology that is not required or overlooking a condition that the applicable Rules actually prescribe.
Operations Team
Operations teams usually deal with what happens after a process goes live.
They may need clear internal instructions covering staff responsibilities, unsuccessful verification, customer communication, and escalation.
Information Security and Data Governance
Biometric information requires careful handling.
Any duty concerning storage, retention, access, sharing, or security should be derived from the applicable legal framework. S.O. 4623(E) itself does not prescribe a retention period or a detailed data-storage process.
This section is just as important as explaining what the Gazette does say.
S.O. 4623(E) does not expressly provide:
That does not mean these subjects can never arise under another provision.
It means they should not be attributed to this notification without checking the Telecommunications Act, the 2026 Rules, relevant authorization conditions and other official DoT instructions.
This approach matters because compliance content can easily become inaccurate when missing information is filled with assumptions.
No. S.O. 4623(E) by itself does not establish a biometric requirement for every telecom service in India.
It expressly identifies two categories:
A provider operating another telecommunications service should check its own legal position separately.
The reverse is also true. A service not named in S.O. 4623(E) should not automatically be treated as free from every user-identification requirement. Other Rules, notifications, authorization terms or DoT instructions may still be relevant.
The correct approach is service-by-service regulatory assessment.
The clearest way to understand the legal position is to separate the requirements stated in S.O. 4623(E) from the wider implementation framework.
What S.O. 4623(E) Expressly Requires
For the services notified:
What Must Be Checked Separately
The following should be verified from the Rules and applicable DoT instructions rather than assumed from the Gazette notification:
This separation helps keep the compliance position accurate.
A practical review does not need to start with a large technology project. It can start with a few basic questions.
1. Confirm Whether the Service Is Covered
Map the actual service against the two categories notified in S.O. 4623(E).
If classification is unclear, settle that issue first.
2. Check the Authorization Position
Identify the authorization or legacy licensing framework under which the service is being provided.
The status of the entity and the nature of the authorized service can affect the compliance analysis.
3. Read the User Identification Rules alongside the Notification
Do not treat S.O. 4623(E) as the complete procedure.
The Rules should be mapped to the business model and customer on boarding process.
4. Review the Existing KYC Process
Document how the entity currently identifies users.
The objective is to determine whether the current process already meets the applicable requirements or needs changes.
5. Carry out a Compliance Gap Assessment
A compliance gap assessment can examine the difference between the current process and the verified DoT requirements.
The review may cover legal interpretation, on boarding procedures, technology controls, record management and internal ownership.
6. Check Technology Readiness
Any biometric or digital verification system should be tested against the regulatory requirements before major changes are made.
A provider should not assume that commercially available biometric technology is automatically acceptable under the telecom framework.
7. Give Each Team Clear Ownership
Legal, KYC, technology, information-security and operations teams should know which parts of the process they are responsible for.
8. Keep Monitoring DoT Instructions
The DoT portal continues to publish material linked to user identification. Regulatory teams should monitor official updates rather than relying only on the original Gazette notification.
The effect will not be identical for every company.
| Stakeholder | Immediate Impact | Likely Operational Effect | Main Concern |
| Authorized telecom entities | Need to confirm applicability | Regulatory and process review | Correct service classification |
| Wireless access providers | Service expressly notified | User-verification process may need alignment | Compliance with 2026 Rules |
| Covered internet telephony providers | Scope must be checked carefully | KYC and technology review | Whether service fits the notified wording |
| Legal and compliance teams | Need to map notification and Rules | More regulatory coordination | Whether service fits the notified wording |
| KYC teams | Existing process needs review | Possible workflow changes | Correct user identification |
| Technology teams | System capability may need assessment | Integration or configuration changes | Using the permitted verification method |
| Management | Cross-team ownership needed | Resource and implementation planning | Avoiding both under- and over-compliance |
The notification may appear to deal only with user verification, but its operational effect can extend across several parts of a telecom business.
That is why telecom regulatory compliance services can be useful when service classification, existing KYC systems, and regulatory requirements need to be examined together rather than separately.
A stronger identification process can have practical value when it is implemented correctly.
For authorized entities, clearer user-identification controls can improve the reliability of subscriber records and reduce uncertainty about how a connection was issued.
Other possible benefits include:
These should be treated as potential regulatory and operational benefits, not guaranteed outcomes.
S.O. 4623(E) does not promise that biometric verification will eliminate fraud, reduce operating costs or make on boarding faster.
The harder part for many operators may be implementation rather than understanding the two-page notification.
Existing Systems May Need Review
A company may already have digital KYC tools in place. That does not automatically mean those systems satisfy the current Rules.
The existing setup has to be checked against the actual legal requirement.
Different Teams Need to Work Together
If the legal team interprets the requirement one way while the technology team builds something different, the company may end up with a process that is expensive but still incomplete.
Clear internal ownership reduces that risk.
Smaller Operators May Have Fewer Resources
Entities with limited in-house regulatory or technology teams may depend more heavily on external vendors.
This can make it even more important to define the legal requirements before purchasing or modifying technology.
Compliance Costs Will Differ
S.O. 4623(E) does not prescribe a standard implementation fee or cost.
Actual expenses, where they arise, may depend on existing systems, integration requirements, staffing, vendor arrangements and internal compliance work.
No fixed figure should therefore be presented as a government-prescribed cost for complying with this notification.
The answer depends on which part of the change is being considered.
Where the Requirement Can Help
From a regulatory-control perspective, stronger identity verification can make subscriber records more dependable.
It can also make responsibility clearer. The authorized entity knows that identification cannot simply be treated as an informal customer on boarding step where the notified service is concerned.
A defined biometric framework may also improve consistency in how users are verified across regulated services.
Where Businesses May Feel the Burden
Implementation can require time and resources.
Some operators may need changes to their technology. Others may need to revisit procedures, vendor contracts, training or internal controls.
The burden may be greater when an entity starts with an older or fragmented KYC system.
There is another risk as well: over-compliance.
A business that assumes the notification requires more than it actually does could spend money on technology or procedures that are not legally necessary.
A Balanced View
S.o. 4623(e) is useful because it clearly identifies the services brought within the Section 3(7) mechanism.
The practical difficulty lies in translating that requirement into the correct operating process.
For most authorized entities, the sensible approach is not to treat biometric identification as either purely beneficial or purely burdensome. The better question is whether the company can implement the verified requirement accurately without building unnecessary layers around it.
Several risks can be reduced simply by reading the wording carefully.
Businesses should avoid:
Avoiding these mistakes can save both compliance effort and unnecessary implementation cost.
These actions are a practical readiness plan. They should not all be described as separate legal duties written into S.O. 4623(E).
| Priority | Action | Responsible Team | Expected Result |
| High | Confirm whether the service is covered by S.O. 4623(E) | Legal/Compliance | Clear applicability position |
| High | Review the Telecommunications (User Identification) Rules, 2026 | Legal/Compliance | Verified requirement mapping |
| High | Check the current user-identification process | KYC/Operations | Existing gaps identified |
| High | Review authorization status and service classification | Legal/Regulatory | Correct regulatory context |
| Medium | Assess technology readiness | Technology/Operations | Clear implementation requirements |
| Medium | Assign internal ownership | Management/Compliance | Defined accountability |
| Medium | Review documentation and controls | Compliance/KYC | Better audit readiness |
| Ongoing | Monitor official DoT instructions | Regulatory Team | Updated compliance position |
The starting point is always the same: find out exactly what service is being provided and which part of the regulatory framework applies to it.
For a telecom provider, the difficult question is often not whether biometric identification exists as a regulatory requirement. The harder part is deciding whether the requirement applies to the service, what the applicable Rules require and what needs to change inside the business.
Corpseed supports businesses through relevant telecom regulatory compliance services, including:
Professional support should help a business understand and apply the rules correctly. It cannot guarantee a regulatory outcome or replace the authority of the Department of Telecommunications.
For authorized entities that are unsure whether their service falls within S.O. 4623(E), working with a telecom compliance consultant can help settle the applicability question before money is spent on new systems or process changes.
Businesses looking for telecom regulatory compliance services can also use professional support to review their current user-identification framework, identify gaps and organize implementation around the requirements that actually apply.
The DoT biometric user identification notification 2026 is focused rather than general. It brings two identified service categories within the biometric user-identification requirement under Section 3(7) of the Telecommunications Act, 2023.
Affected providers should first confirm applicability and then review their KYC, technology and operational processes against the applicable Rules.
Document Preview
Embedded reference document
Related
Explore more updates from the same department.