
Loading...
Law Update
Quick note
Below is the official summary and the reference document preview. Use βOpen PDFβ for full screen view.
India's telecom user-verification system now has a fresh set of statutory rules.
The Department of Telecommunications, under the Ministry of Communications, notified the Telecommunications (User Identification) Rules, 2026 through G.S.R. 750(E) on 21 August 2026. The Rules came into force on the date they were published in the Official Gazette.
The change is not limited to people buying a new SIM card. The Rules deal with biometric identification at several points in a telecom connection's life, including new enrolment, specified changes in user information, disconnection and reverification.
They are particularly important for telecom operators and companies using business connections because the framework also deals with authorised representatives, individual end users of corporate connections, Subscriber Data Records and Point of Sale operations.
For businesses, the practical question is simple: who now needs to be identified, when does biometric verification apply, and what internal processes need to change?
That is where the real impact of the 2026 Rules lies.
| Particular | Details |
| Issuing Ministry | Ministry of Communications |
| Notification | G.S.R. 750(E) |
| Notification Date | 21 August 2026 |
| Rules | Telecommunications (User Identification) Rules, 2026 |
| Parent Law | Telecommunications Act, 2023 |
| Effective Date | Telecommunications Act, 2023 |
| Main Requirement | Verifiable biometric-based identification of users |
| Main Verification Routes | e-KYC and D-KYC |
| Business Connections | Specifically covered |
| Corporate End Users | Biometric identification applies where required |
| Technical Readiness Period | Three months from commencement |
| Possible Extension | Further period not exceeding three months, if granted |
| Digital Implementation | Further period not exceeding three months, if granted |
The Gazette makes one point very clear: compliance with these Rules is tied to the authorisation or licence held by the relevant telecom entity. This makes user identification part of the operator's regulatory responsibility, rather than just a customer-onboarding formality.
The final Rules were preceded by a draft.
The Telecommunications (User Identification) Rules, 2025 were published through G.S.R. 691(E) dated 19 September 2025. Copies of the Gazette were made available to the public on 22 September 2025, and objections and suggestions were invited for 30 days from that date.
The final Gazette states that the Central Government considered the objections and suggestions received during the consultation before issuing the 2026 Rules.
That history matters because the August 2026 notification is no longer a draft or proposal. It is the final notified framework.
The Rules have been issued under Section 56 of the Telecommunications Act, 2023.
They apply to biometric-based identification carried out by the authorised entities covered under Rule 3. This includes specified entities operating under authorisations issued under the Telecommunications Act, certain existing licence holders continuing under the conditions recognised by the Act, and entities that have migrated to the new authorisation framework.
The Rules go a step further by stating that compliance with them forms part of the terms and conditions of the relevant authorisation or licence.
So for an authorised telecom entity, non-compliance is not merely an internal KYC lapse. It can also become an issue under its authorisation or licence conditions.
The notification uses several different terms, and they should not be mixed.
A telecom operator, an individual customer, a corporate customer, an employee using a corporate SIM and a retail Point of Sale do not carry the same responsibilities.
| Stakeholder | Why the Rules Matter |
| Authorised telecom entities | They carry the main implementation and verification obligations |
| Relevant licence holders | The Rules form part of applicable licence or authorisation conditions |
| Individual telecom users | They may need biometric identification at specified stages |
| Business users | Corporate and organisational telecom connections are specifically covered |
| Authorised representatives | They represent the business user for relevant telecom matters |
| End users | The individual actually using a business connection may need verification |
| Points of Sale | They handle enrolment and other telecom activities but face strict data-handling controls |
Understanding these roles is important because many of the operational problems are likely to arise where the organisation owning the connection and the person actually using it are different.
That is common with employee SIMs, field-sales numbers, business mobile fleets and other corporate telecom arrangements.
The definition is broader than just a private company. A business user can include a:
A business connection means one or more telecom connections or Subscriber Identity Modules provided to such a business user for its bona fide use.
This is why the Rules have relevance far beyond large telecom companies. Organisations that maintain corporate connections also need to understand how the end-user provisions work.
The authorised representative is the individual recognised for the business user under the Rules.
This person may be:
From a practical point of view, businesses should know who is handling telecom connections on their behalf.
That becomes especially important where hundreds or thousands of employee numbers are linked to one corporate account.
The Rules themselves do not say that every business must use one particular form of board resolution. Any internal documentation should therefore be aligned with the actual legal and telecom-provider requirements instead of being assumed.
An end user is the individual who actually uses the Subscriber Identity Module supplied to a business user.
Suppose a company obtains a telecom connection in its own name and assigns the SIM to an employee. The company is the business user, while the employee using that SIM is the end user for the purpose described in the Rules.
The distinction matters because biometric identification can extend to the authorised representative as well as the individual end user.
This is one of the provisions that may require companies to improve internal tracking of employee connections.
The notification uses the broader term Subscriber Identity Module rather than limiting the Rules to a traditional plastic SIM card.
The definition includes:
This keeps the framework usable even as the technology used to identify telecom subscribers changes.
Biometric identification is not limited to the first purchase of a connection.
Rule 3 identifies four main situations.
| Situation | Requirement |
| New connection or SIM enrolment | Biometric identification before enrolment |
| Specified user-information update | Biometric identification before the update |
| User-requested disconnection | Biometric identification before accepting disconnection |
| Reverification | Required when directed under Rule 7 |
This creates an identity check at points where control of the connection or its subscriber information could materially change.
For users, that means activities such as SIM replacement or changing certain identity details can no longer be viewed as routine database updates alone.
For operators, each of those activities needs to be mapped into the correct verification workflow.
The Rules create two separate identification routes.
e-KYC is the route applicable to an Aadhaar number holder under the framework laid down in Rule 4.
The authorised entity uses the e-KYC authentication facility and processes the relevant e-KYC data and user information in accordance with Government directions and the applicable Aadhaar framework.
D-KYC is provided for a person who:
This second route is important because it means the Rules do not simply say that Aadhaar is the only possible way to obtain telecom service.
| Area | e-KYC | D-KYC |
| User category | Aadhar number holder | Non-Aadhar holder or specified person unable to complete e-KYC |
| Main route | Aadhaar-linked authentication | Document and biometric verification |
| Live facial capture | As required under the applicable process | Expressly part of D-KYC |
| Supporting documents | Governed by applicable framework | Expressly part of D-KYC |
| Due diligence | Authentication-led | Detailed identity and document checks |
| Field verification | Not the central process | May be used where Rule 5 permits |
The e-KYC process is not simply a face scan taken at a retail counter.
The authorised entity must follow the orders, directions, instructions and guidelines issued by the Central Government from time to time.
It must use the e-KYC authentication facility for authenticating user information and store or process the prescribed details in the Customer Application Form and Subscriber Data Record.
The information includes e-KYC data received through the applicable Aadhaar framework, including the Aadhaar number, along with user information.
The wider point for operators is that customer onboarding systems, subscriber records and authentication processes all need to work together.
D-KYC involves a more detailed verification process. The authorised entity first determines the category under which the user qualifies for D-KYC. If the records show that the person has previously completed e-KYC, the entity may also need to obtain the undertaking required under Rule 5.
The process includes live facial capture and collection of user information. The authorised entity must electronically capture images of the original proof-of-identity and proof-of-address documents specified through the portal.
As part of the due diligence, the entity must verify:
In the circumstances specified under Rule 5, the authorised entity may also conduct a field visit, seek police assistance for verification, or use both measures.
One point remains open. The Gazette does not itself provide the final list of acceptable identity and address documents. This list may be specified through the digital portal.
The Rules recognise that one standard biometric method will not work for every person.
Where a user cannot undergo live facial capture for reasons such as impairment, disfigurement or injury, the authorised entity must offer an accessible alternative for providing other biometric information.
The D-KYC provisions then apply with the necessary adjustments. This is not an optional customer-service gesture. It forms part of the identification framework itself.
Business connections deserve separate attention because the Rules recognise both the organisation and the person actually using the connection.
Where a business user seeks a business connection, the authorised entity must carry out biometric identification of:
There is also a power for the Central Government or an authorised officer to exempt an authorised entity from carrying out biometric identification of an end user or a class of end users when the legal conditions are satisfied and reasons are recorded in writing.
For a company managing corporate SIMs, the practical lesson is that the telecom account cannot be managed only as a bulk inventory of mobile numbers. The identity of the actual person using the connection now becomes relevant to the regulatory process.
This is likely to be one of the more operationally important rules for corporate users.
If the end user linked to a business connection changes, the authorised representative of the business must inform the authorised telecom entity within the period specified through the portal.
The authorised representative must also ensure that the new end user completes biometric identification within the portal-specified period.
If the verification is not completed within that period, the authorised entity must suspend the business connection until the new end user completes biometric identification.
The Gazette does not specify the exact number of days for either action. That timeline is left to the portal.
Companies should, therefore, avoid assuming a fixed legal deadline. Instead, they should create an internal process that can be updated once the Department of Telecommunications specifies the applicable period through the portal.
Rule 6 requires biometric identification when the user seeks to:
The authorised entity must also carry out due diligence and compare the information collected during biometric verification with the existing Subscriber Data Record.
This makes SIM replacement and important identity changes more controlled transactions rather than simple service requests.
Yes, but only within the framework set by Rule 6. A change of user can be made in relation to:
The new user is treated as receiving a new telecom connection.
This should not be interpreted as a free right to hand over a SIM to any other person.
Several provisions depend on the Subscriber Data Record maintained by the authorised entity. When relevant user information changes, the authorised entity must update its records while keeping both the old and new information along with a timestamp.
Users must also promptly inform their service provider about changes to their address and other relevant information.
From a compliance perspective, this places greater importance on keeping subscriber records accurate and up to date instead of treating KYC as a one-time exercise. For telecom operators, poor data quality could create issues that go beyond billing or customer service.
The Rules also place responsibilities on the person using the telecom service. Users must provide correct information while establishing their identity.
They must not:
Users are also expected to make bona fide use of notified telecom services and promptly report changes in their address and user information.
Where the address changes, supporting evidence of the new address must be provided.
Authorised entities have to clearly explain these duties and obtain an explicit acknowledgement from users.
The new framework is much wider than performing KYC at the time of sale. An authorised entity has to manage several connected responsibilities.
Customers must be told, in clear terms, what their duties are and what may happen if those duties are ignored.
Records must be updated properly, and old and new information needs to be retained with timestamps where the Rules require it.
Corporate accounts need a process for authorised representatives and changes in end users.
Complaints related to biometric identification have to be addressed through the grievance mechanism established by the authorised entity.
False documents, impersonation and similar issues cannot remain merely an internal customer-service case. The Rules create specific escalation requirements.
Retail outlets, agents, distributors and other Points of Sale need to operate within strict information-handling controls.
Taken together, these requirements make telecom KYC a cross-functional compliance issue involving operations, legal, technology, information security, customer support and enterprise-account teams.
Retail telecom operations often involve large dealer and distributor networks, making Rule 8 particularly important.
Where a Point of Sale collects or receives user information or biometric information under the Rules, it must securely transmit that information to the relevant systems of the authorised entity. The Point of Sale must not store the information in physical or electronic form.
For operators, this may require a closer review of how retail applications, devices and local systems currently handle user data.
Practices such as using screenshots, local folders, printed copies or unofficial applications could create compliance issues if they result in prohibited storage.
Internal controls such as device restrictions, application permissions, staff training and retail audits may therefore become important implementation measures, even though the notification does not prescribe each of these controls by name.
Biometric information is highly sensitive from an operational perspective. The Rules require the Subscriber Data Record to be operated and maintained in accordance with applicable law, including laws relating to data protection and security.
The Government may also issue further directions covering the confidential, secure, non-repudiable and immutable storage and maintenance of user information.
This means compliance cannot stop at asking, "Was the user verified?" Operators should also consider:
Those are likely to become important questions during implementation.
Every authorised entity must use its established grievance mechanism to deal with complaints relating to biometric-based identification. That sounds straightforward, but the underlying cases may not be.
A complaint could involve:
A workable grievance process will therefore need access to both customer-facing records and technical verification information.
The Rules require a formal response.
If the authorised entity becomes aware that false, incorrect or forged information or documents were presented or used during biometric identification, material information was suppressed, or impersonation took place, it must inform the police or relevant law-enforcement agency for registration of an FIR.
The authorised entity must also inform the Central Government about the steps taken in the form and manner specified through the portal.
If the Central Government finds that the authorised entity did not take the required action, it can direct the entity to report the matter and may initiate further action under the Telecommunications Act or licence conditions.
For operators, this makes fraud escalation an area that should be clearly allocated internally. A case cannot simply remain unresolved between a retail outlet and customer-support team.
Rule 7 deals with connections provided in violation of the identification requirements. If such a case comes to the notice of the Central Government, it may direct the authorised entity to immediately suspend the connection or Subscriber Identity Module.
Fresh biometric identification can then be required within the period specified by the Government. If the identification is not completed as directed, the Central Government may direct disconnection.
The broad sequence is:
Suspension- Fresh Biometric Verification- Possible Disconnection
Other proceedings available under the Telecommunications Act may continue separately.
A user's request to disconnect a telecom connection is also subject to identity checks. Before accepting the request, the authorised entity must undertake biometric identification and due diligence to confirm the user's identity.
The captured information must be checked against the Subscriber Data Record. After disconnection, the relevant records must be updated while retaining the previous and updated information along with timestamps.
This process reduces the risk of an unauthorised person shutting down someone else's telecom connection.
Rule 10 allows the Central Government to require authorised entities to send alerts through a user's existing telecom connections. The purpose is to confirm whether the person actually made the request relating to the connection or Subscriber Identity Module.
This could be useful for detecting unusual enrolment, SIM replacement, information-change or disconnection requests.
The alert mechanism is not automatically triggered for every transaction simply because the Rules exist. It applies when required through Government orders, directions, instructions or guidelines.
A negative response can trigger immediate safeguards.
Depending on the type of request, the authorised entity may need to:
The measure continues while the entity checks the facts and takes appropriate action.
This part of the framework gives the user a way to challenge an identity-sensitive telecom request before the consequences become permanent.
The Rules do not give authorised entities an unlimited period to prepare.
Every authorised entity must, within three months from the date the Rules came into force, take appropriate technical and organisational measures and establish the infrastructure needed for effective compliance.
The Central Government may extend that period, but only after assessing preparedness and where it considers an extension necessary in the public interest.
Any extension cannot exceed a further three months.
| Stage | Position |
| Rules notified | 21 August 2026 |
| Rules effective | Date of Gazette publication |
| Initial preparation period | Three months |
| Initial preparation period | Possible, but not automatic |
| Maximum additional period | Not more than three months |
Businesses should not assume that the additional period has already been granted.
Unless the Government issues such an extension, compliance planning should be based on the original three-month window.
The Gazette creates the legal framework, but not every operational detail appears in the 17-page notification. Rule 11 allows the Government to notify one or more digital portals.
These portals may provide:
The portal is also relevant to several provisions elsewhere in the Rules, including deadlines connected with changes in business end users. This creates an important compliance distinction.
Some requirements are already part of the law. Their operating detail, however, may still depend on a later portal specification.
The first priority should not be buying new software. It should be understanding exactly where the current process differs from the Rules.
A structured review could start with these questions:
These questions give management a much clearer picture than treating implementation as a single "KYC update".
Businesses that use corporate connections do not need to become telecom KYC providers. They do, however, need better control over who is using each connection.
A practical starting point is to:
The company should not start collecting employee biometric information on its own simply because these Rules require biometric identification by authorised telecom entities.
The new system can improve control at several points where telecom identity misuse may occur.
Potential benefits include:
These are reasonable outcomes of the regulatory design. They should not be presented as a guarantee that telecom fraud will disappear.
The biggest challenge is unlikely to be understanding the idea behind biometric verification. It will be implementing it at scale.
A large telecom operator may have retail outlets, franchisees, distributors, enterprise teams, call centres, mobile applications and multiple customer databases. Changing one KYC process can affect all of them.
Initial work may involve:
There will also be ongoing work. New end users have to be managed, D-KYC exceptions need handling, subscriber information must remain current, disputes need investigation and later DoT instructions will need to be incorporated.
The Gazette does not specify how much this will cost. Any cost estimate should therefore come from an operator's own technology and operational assessment.
It is both a stronger control mechanism and a more demanding compliance system.
| What the Framework Improves | What Businesses Must Manage |
| Identity assurance | Biometric technology |
| Subscriber traceability | More detailed records |
| Corporate SIM accountability | End-user administration |
| Fraud detection | Escalation and reporting |
| PoS information control | Retail network monitoring |
| Secure subscriber data | Cybersecurity obligations |
| Digital implementation | New portal integration |
From a regulatory standpoint, requiring stronger proof of the person behind a telecom connection has clear logic, particularly where SIMs can be used for financial, digital and identity-linked activities. The main challenge will be execution. If future portal instructions are clear and systems work reliably, the framework can improve subscriber accountability without making routine telecom transactions unnecessarily difficult.
If implementation is fragmented, operators may face customer delays, retail confusion and higher operational workload. The quality of the final implementation will therefore matter just as much as the wording of the Rules.
New compliance requirements normally create demand for systems and support that help businesses implement them.
Under this framework, that may include work relating to:
These are likely commercial effects of implementation. They are not Government incentives or guaranteed business opportunities.
Several mistakes could create problems during implementation. One is treating the notification only as a "new SIM KYC rule". It goes much further.
Other risks include:
The Telecommunications (User Identification) Rules, 2026 affect more than customer onboarding. They touch telecom KYC, subscriber records, corporate connections, Point of Sale operations, data protection, fraud reporting and internal operating procedures.
For organisations dealing with these requirements, the first need is usually clarity: which Rules apply, what is already compliant, and where does the current process need to change?
Corpseed can support telecom operators and relevant businesses through telecom regulatory compliance services tailored to their actual operating structure.
Support may include:
A telecom compliance consultant can help an organisation organise these requirements into practical work streams, but professional support does not replace the Department of Telecommunications or guarantee any regulatory outcome.
Businesses that need help understanding their position under the 2026 Rules can use telecom regulatory consulting services to review existing KYC, corporate SIM, subscriber-data and Point of Sale processes before implementation gaps turn into operational problems.
The Telecommunications User Identification Rules, 2026 introduce a more structured approach to identifying people who obtain, use, update, or disconnect notified telecom services. The key compliance points for businesses are:
Document Preview
Embedded reference document
Related
Explore more updates from the same department.