
Loading...
Law Update
Quick note
Below is the official summary and the reference document preview. Use “Open PDF” for full screen view.
The Department of Telecommunications (DoT), under the Ministry of Communications, has brought Section 3(7) of the Telecommunications Act, 2023 into force from 21 August 2026.
The change has been made through Notification S.O. 4616(E). The Central Government issued the notification using its powers under Section 1(3) of the Telecommunications Act, 2023. The Gazette clearly appoints 21 August 2026 as the date on which Section 3(7) becomes operational.
That sounds straightforward, but there is an important distinction. S.O. 4616(E) is mainly a commencement notification. It does not contain a complete telecom KYC process, prescribe a new application form, or create a separate biometric licence.
What it does is activate the statutory provision dealing with identification of users through verifiable biometric-based identification. The detailed position has to be understood by reading Section 3(7) together with the applicable User Identification Rules and DoT directions.
For telecom operators, the change deserves attention because user identification is now tied directly to the framework of the Telecommunications Act, 2023. Businesses holding corporate telecom connections also need to understand their role, particularly where individual employees or other persons are using connections issued in the name of an organisation.
| Particular | Details |
| Issuing Ministry | Ministry of Communications |
| Department | Department of Telecommunications |
| Notification Number | S.O. 4616(E) |
| Notification Date | 21 August 2026 |
| Effective Date | 21 August 2026 |
| Governing Law | Telecommunications Act, 2023 |
| Power Used | Section 1(3) |
| Provision Brought into Force | Section 3(7) |
| Main Subject | User identification through prescribed verifiable biometric-based identification |
| Direct Compliance Procedure in S.O. 4616(E) | Not specified |
| Separate Application Form | Not specified |
| Separate Government Fee | Not specified |
| Separate Registration | Not created by this notification |
| Nature of Notification | Commencement notification |
There is no gap between the date of this notification and the commencement date mentioned in it. Section 3(7) became effective on 21 August 2026 itself.
Section 3(7) is fairly short, but its wording matters.
Under the provision, an authorised entity providing a telecommunication service notified by the Central Government must identify the person receiving that service through a prescribed form of verifiable biometric-based identification.
There are three parts to understand here.
Section 56 of the Telecommunications Act also specifically gives the Central Government rule-making power regarding the verifiable biometric-based identification to be used under Section 3(7).
That is why the Gazette notification cannot be read on its own.
The Telecommunications Act was enacted earlier, but individual provisions of a law do not always become operational on the same date.
Section 1(3) allows the Central Government to appoint commencement dates for provisions of the Act. S.O. 4616(E) uses that power specifically for Section 3(7).
In practical terms, the position is:
| Stage | What It Means |
| Telecommunications Act, 2023 enacted | Parliament created the legal framework |
| Section 3(7) included in the Act | Parliament created the statutory basis for biometric user identification. |
| S.O. 4616(E) issued | Government formally commenced Section 3(7) |
| 21 August 2026 | Section 3(7) became legally operational |
| User Identification Rules and DoT instructions | Detailed implementation has to be understood from these instruments |
This distinction matters because describing S.O. 4616(E) itself as a fresh "biometric KYC rule" would not be legally precise.
The notification activates the section. It does not reproduce the entire operating framework.
DoT's Telecom e-Service Portal now specifically refers to the Telecommunications (User Identification) Rules, 2026 and states that the Rules have been made live on the portal.
DoT has also published separate instructions relating to the implementation of the User Identification Rules. The Department's official resources page lists both the User Identification instructions and a consolidated list of earlier identification/KYC notifications.
This creates a layered framework.
Finally, DoT instructions deal with practical matters such as e-KYC, D-KYC, reverification, and business connections.
For a compliance team, the real job is therefore not simply to read the two-page Gazette. The documents have to be read together.
The DoT instructions explain the categories of authorised entities to which the Rules may apply.
These include entities holding an authorisation under Section 3(1)(a) of the Telecommunications Act, 2023, as well as certain entities continuing under licences granted under the Indian Telegraph Act, 1885 or migrating to the new authorisation framework in accordance with Section 3(6).
This distinction is useful because not every company connected with the telecom industry is automatically an "authorised entity" for this purpose.
A software vendor working for a telecom operator, for instance, does not become the authorised entity simply because it supports a KYC system. The applicable authorisation or continuing licence position has to be checked.
That is the first compliance question telecom businesses should answer: what is the regulatory status of the entity providing the service?
The expression is important because Section 3(7) does not simply refer to ordinary document verification.
The provision specifically requires a form of identification that is both biometric-based and verifiable, with the detailed method governed through the prescribed framework.
DoT's implementation instructions also make clear that the User Identification Rules work with processes such as e-KYC, D-KYC, and user reverification.
Businesses should avoid oversimplifying this into a statement such as "all users must now complete Aadhaar KYC."
That would go beyond what S.O. 4616(E) itself says.
The correct method depends on the applicable Rules, the user's circumstances, and the relevant DoT instructions.
For telecom operators, this means existing subscriber-verification systems should be checked against the current framework rather than assuming that an older KYC process continues unchanged.
Telecom KYC did not begin in 2026.
DoT has issued subscriber-verification instructions for many years. Its current User Identification notification list refers to earlier directions covering matters such as:
For example, DoT's list records Digital KYC instructions from 2019, Self-KYC and Aadhaar-based e-KYC instructions from 2021, business-connection KYC instructions from 2024, and Internet Telephony KYC requirements from 2025.
The 2026 framework therefore does not begin from an empty regulatory position.
The better approach for operators is to identify which earlier instructions continue to apply, which have been absorbed into the new framework, and whether any newer direction changes the way an existing process must operate.
Simply deleting every old KYC SOP would be as risky as assuming that nothing has changed.
One question businesses are likely to ask is whether every existing telecom user now needs immediate fresh biometric verification.
S.O. 4616(E) itself does not say that.
The commencement notification only brings Section 3(7) into force. It does not contain an instruction requiring every existing subscriber to report for fresh verification on 21 August 2026.
DoT separately maintains instructions dealing with reverification of existing mobile connections. Its current consolidated list refers to reverification directions issued in December 2021 and February 2022.
Any fresh verification requirement should therefore be linked to the applicable Rules or a specific DoT direction rather than assumed merely from the commencement notification.
For operators, that means existing connections and new connections should not automatically be treated as the same compliance situation.
Corporate connections deserve a closer look because there can be more than one person involved.
The connection may be taken in the name of a company, LLP, partnership, government body, or another organisation. In contrast, the SIM or telecom connection is actually used by an employee or another individual.
This creates three different roles that compliance teams may have to distinguish:
This becomes particularly important where connections are regularly reassigned between employees.
DoT's implementation instructions specifically deal with changes in the end user of a business connection.
This is one of the areas where the DoT instructions provide a clear timeline.
According to the instructions published on the Department's portal, the authorised representative of a business user must inform the authorised entity about a change in the end user of a business connection within three working days from the date of the change.
The instructions also state that the authorised representative must ensure that the new end user undergoes biometric-based identification within seven working days from the date of the change.
| Business Connection Event | Time Allowed | Main Responsibility |
| End user of the connection changes | Within 3 working days | Inform the authorised entity |
| New person starts using the connection | Within 7 working days from the change | Ensure biometric-based identification of the new end user |
This has a very practical consequence for employers.
A company that reallocates corporate SIMs between employees cannot treat the change as purely an internal administrative matter. HR, administration, IT and whoever manages the telecom account may need a process for notifying the telecom provider and completing the required identification.
A simple employee-exit checklist may therefore need to connect with the company's telecom-connection records.
For telecom operators, the regulatory change is less about creating one new form and more about checking whether the existing user-identification system still matches the law.
A sensible review would start with the services being provided and the company's authorisation position.
After that, the compliance team can look at the actual customer journey.
Check how a new user is identified before a connection is provided. Existing e-KYC or D-KYC processes should be mapped against the current Rules and portal instructions.
Enterprise connections often remain active for long periods while the individual end user changes. These accounts deserve separate controls because the person using the connection can be different from the company that originally obtained it.
Teams should know what event or direction triggers reverification rather than treating it as an automatic requirement for every subscriber.
Subscriber records, authorised-representative information and end-user changes should remain consistent across customer, billing, KYC and enterprise-account systems.
A regulatory process can fail even when the written policy is correct if retail staff, enterprise teams or customer-support personnel follow an outdated procedure.
That makes training and SOP review a practical part of implementation.
The burden on an ordinary corporate user is different from the burden on the telecom operator.
A company does not become responsible for operating the telecom provider's KYC system. It does, however, need control over the information it provides to the telecom company.
Businesses with a sizeable pool of corporate connections should be able to answer a few basic questions without searching through several departments.
These sound like small administrative details, but the three-working-day and seven-working-day requirements make them much more important for business connections.
A useful internal arrangement is to connect telecom allocation with employee onboarding, transfers and exits. That reduces the chance of a company-owned connection continuing in the name of an old end user.
| Telecom Operator / Authorised Entity | Corporate or Business User |
| Apply the prescribed identification framework | Provide accurate business and user information |
| Carry out the required identification process | Maintain an appropriate authorised representative |
| Follow applicable DoT instructions | Inform the provider of relevant end-user changes |
| Maintain subscriber information required under the framework | Keep internal SIM/end-user records current |
| Handle applicable reverification | Ensure the new end user participates in required verification |
| Maintain regulatory controls around the process | Coordinate telecom records with employee changes |
This distinction matters because articles on telecom KYC often speak about "business compliance" without explaining whether the obligation belongs to the telecom provider or to its customer.
The two may have connected responsibilities, but they are not interchangeable.
DoT's 2026 implementation instruction also refers to Rule 8 of the User Identification Rules and provides a format through which an authorised entity can inform the Central Government about specified misrepresentation.
The format records the telecommunication identifier, the nature of the misrepresentation, and the steps taken by the authorised entity.
This shows that user identification is not being treated merely as a one-time onboarding exercise.
Accuracy of subscriber information remains relevant after the connection has been issued.
For telecom operators, this means suspected identity misuse should be connected with the appropriate internal escalation and regulatory process.
For businesses, it reinforces a simpler point: information relating to the actual user of a business connection should remain accurate.
Because the Gazette is so short, there is a risk of reading much more into it than it actually contains.
S.O. 4616(E) does not, by itself:
Its legal function is much narrower: it brings Section 3(7) into force from 21 August 2026.
Operational details should therefore be taken from the applicable Rules and DoT instructions, not inserted into the commencement notification.
No. S.O. 4616(E) does not create a separate licence or registration simply for biometric user identification.
Section 3(7) operates within the larger authorisation framework of the Telecommunications Act, 2023. Section 3(1) separately deals with the requirement to obtain Central Government authorisation for specified telecom activities.
Existing and new authorisation matters therefore need to be assessed under the relevant authorisation provisions and rules.
They should not be mixed with the commencement of Section 3(7).
This distinction is particularly relevant for businesses researching compliance online because phrases such as "biometric telecom registration" or "Section 3(7) licence" can easily create the impression that a separate application has been introduced. The attached Gazette does not support that conclusion.
The biggest challenge is unlikely to be understanding the two-page notification. The harder part is translating the wider framework into day-to-day operations.
For a large telecom operator, user identification can touch several teams at once: legal, regulatory affairs, customer onboarding, enterprise sales, KYC operations, IT, fraud control, and customer support.
A change that looks minor from a legal perspective may therefore require several systems to communicate correctly.
Business accounts present another practical issue. A company may own hundreds or thousands of active connections spread across offices and employees. The telecom provider may have one record, while HR has another and IT asset management has a third.
If those records are not aligned, identifying the actual end user can become difficult.
The new framework makes that gap worth examining.
Rather than redesigning every process immediately, businesses can start with a focused compliance review.
| Priority | Practical Review |
| 1 | Confirm whether the entity falls within the relevant authorised-entity framework |
| 2 | Identify which of its telecommunication services are covered by the applicable notification |
| 3 | Review current e-KYC, D-KYC and reverification procedures |
| 4 | Check the process followed for business connections |
| 5 | Review how changes in corporate end users are recorded |
| 6 | Check whether the 3-working-day and 7-working-day business-user timelines have been built into internal processes |
| 7 | Review existing SOPs and staff instructions |
| 8 | Monitor the DoT portal for updated directions and clarifications |
The purpose of this exercise is not to create paperwork for its own sake.
It is to find out whether what the business actually does matches the rules it is now expected to follow.
Possibly, but the impact will not be the same for every operator.
S.O. 4616(E) itself does not prescribe an implementation fee.
The practical cost is more likely to arise from internal changes: updating technology, adjusting onboarding systems, training customer-facing teams, managing corporate-user records, and reviewing existing processes.
Large operators may already have much of this infrastructure because DoT had KYC, Digital KYC, Aadhaar-based e-KYC, business-connection and reverification instructions before 2026.
For such businesses, the work may be more about aligning existing systems with the new statutory framework.
Smaller organisations may find the process heavier if user-identification controls have historically been spread across different systems or teams.
No single implementation-cost figure should therefore be treated as applicable to the whole industry.
There is a clear policy logic behind stronger identification of telecom users.
A connection linked more reliably with its actual user can make subscriber records more dependable.
It may also make it harder to maintain connections using false or outdated identities.
For business connections, accurate end-user records can help answer a basic question that can otherwise become surprisingly difficult: who was actually using this connection at a particular time?
Other possible benefits include:
greater consistency between user-identification systems and the new Telecommunications Act framework.
These should be viewed as expected regulatory benefits, not guarantees that identity fraud will disappear.
It is both a stronger control and an additional operational responsibility.
| Positive Side | Compliance Concern |
| Better assurance about user identity | More work in onboarding and account management |
| Improved traceability | Technology and system changes may be required |
| Better corporate end-user records | Companies need tighter SIM allocation controls |
| More structured response to identity misuse | Staff and channel teams need updated training |
| Stronger statutory basis for user identification | Operators must align old KYC processes with the new framework |
From the regulator's side, there is a reasonable case for improving the quality of subscriber identification. Telecom connections can be misused when identity information is false, outdated, or disconnected from the person actually using the service.
From the business side, stronger controls do not come without effort.
The biggest burden is likely to fall on organisations handling very large numbers of users or corporate connections. Updating a single connection is straightforward. Keeping thousands of employee connections correctly mapped while people join, leave or move roles is a different exercise.
The policy therefore looks less like a completely new KYC system and more like an attempt to place a firmer statutory structure around user identification.
Its success will depend on how workable the prescribed processes remain for both operators and genuine users.
There is also an unusual drafting point business should be aware of.
The DoT PDF currently available on the official portal for instructions under the User Identification Rules contains blank placeholders in parts of its header. The displayed document shows an incomplete date and circular number, and the reference to the notified services is also left incomplete in the text.
At the same time, the same document contains substantive directions, including the three-working-day and seven-working-day requirements for changes in business-connection end users.
This does not justify ignoring the document, but it does mean compliance teams should keep watching the DoT portal for a corrected, replaced, or clarified version.
Where a document itself contains a visible drafting gap, businesses should not fill it with assumptions.
Telecom user identification is no longer something that can be checked by looking at one KYC circular.
Depending on the business, the answer may involve the Telecommunications Act, the User Identification Rules, earlier DoT instructions, the company's existing licence or authorisation position, business-connection controls and the way end-user changes are handled internally.
This is where a telecom compliance consultant can help a business turn the legal framework into a practical review of its existing processes.
Corpseed can support relevant telecom operators and businesses with:
The purpose of professional support is not to replace the Department of Telecommunications or to guarantee a regulatory outcome. It is to help businesses identify the correct rules, understand what applies to their operations and reduce avoidable gaps between regulatory requirements and day-to-day practice.
Businesses that need help reviewing their user-identification, corporate connection or DoT compliance processes can work with a telecom compliance consultant for a focused assessment instead of treating every telecom notification as a separate filing requirement.
Section 3(7) of the Telecommunications Act, 2023 became operational on 21 August 2026 through S.O. 4616(E).
The provision requires an authorised entity providing a notified telecommunication service to identify the user through prescribed verifiable biometric-based identification.
The Gazette itself does not explain the complete KYC process. Detailed implementation has to be read with the Telecommunications (User Identification) Rules, 2026 and applicable DoT directions.
DoT's current implementation instructions expressly refer to e-KYC, D-KYC, and user reverification.
For business connections, an end-user change is particularly important. DoT's portal instructions require intimation within three working days and biometric-based identification of the new end user within seven working days from the change.
Businesses should therefore focus less on creating unnecessary new filings and more on checking whether existing telecom KYC, corporate connection and user-management processes match the current framework.
Document Preview
Embedded reference document
Related
Explore more updates from the same department.