Authority Guides6 mins

DPDP Act 2023 Authority Guide for Telecom and Communication Providers

An authoritative breakdown of DPDP Act 2023 obligations for telecom enterprise compliance teams, focusing on SDF requirements, TDSAT enforcement, and verifiable audit trails before the notified implementation dates.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

Executive Summary

Telecom and communication providers operate at the intersection of the Digital Personal Data Protection Act, 2023, TRAI regulations, and telecommunication mandates. For a Head of Compliance, reconciling these frameworks requires immediate control over vast subscriber data volumes to avoid regulatory exposure. The DPDP Act introduces severe financial risk with penalties reaching up to INR 250 crore for severe data breaches. As the Central Government prepares to notify the implementation dates, enterprise teams must establish verifiable audit trails and automated consent architectures. Manual tracking cannot scale to meet the rights request volumes expected across millions of Data Principals in India.

Statutory Framework

Section 3 of the DPDP Act 2023 dictates that the law applies to the processing of digital personal data within the territory of India, and processing outside India if connected to offering goods or services to Data Principals in India. For communication providers, this covers digital subscriber onboarding, call detail records, and internet usage logs regardless of where the servers sit. Consent is the primary basis for processing, except where Section 7 legitimate uses apply, such as compliance with judgments or state functions. Section 44 uniquely impacts this sector by amending the TRAI Act, 1997, to designate the existing Telecom Disputes Settlement and Appellate Tribunal (TDSAT) as the appellate body for DPDP decisions. This centralises dispute resolution for operators already familiar with TDSAT proceedings.

Rules 2025 Operational Layer

The DPDP Rules 2025 introduce execution mechanics that telecom Data Fiduciaries must actively integrate into their operations. Notices must be itemised, presenting exactly what data is collected and for what specified purpose across multiple regional languages. In the event of a personal data breach, operators must submit a detailed report to the Data Protection Board of India within 72 hours, alongside providing intimation to affected Data Principals without delay. The Rules 2025 also formalise Significant Data Fiduciary obligations, applying to large telecom operators based on sheer data volume and risk. These entities must appoint a resident Data Protection Officer, conduct Data Protection Impact Assessments, and execute independent data audits.

Enforcement And DPBI

The Data Protection Board of India functions as a digital-first regulator focused on documented accountability. Financial penalties scale up to INR 250 crore for failing to take reasonable security safeguards to prevent personal data breaches. When the DPBI investigates a complaint, the burden of proof rests entirely on the control owner to produce a verifiable evidence pack demonstrating compliance at the exact time of processing. Since appeals route through TDSAT under Section 44, the jurisprudence will inevitably merge data protection principles with existing telecommunication compliance standards. Regulators will demand to see a live Record of Processing Activities rather than static spreadsheet policies.

Comparative Context

Unlike older sectoral guidelines that mandated strict local storage for certain network logs, the DPDP Act addresses cross-border data flows with a different approach. Under the DPDP framework, cross-border transfers of personal data are generally permitted unless the Central Government restricts transfer to notified countries or territories via a negative list. This allows global telecommunication providers to route data through standard international nodes, provided those destinations are not explicitly restricted. Enterprise compliance teams must ensure their vendor agreements enforce these standards down the supply chain. Data localisation requirements from specific telecom licenses remain active and must be mapped alongside these cross-border rules.

Decision Matrix

Scenario 1 Subscriber Onboarding. The primary obligation is itemised notice and multi-language consent collection. The control owner is the Chief Compliance Officer. The exact artifact required is a time-stamped consent artefact stored in an immutable ledger.

Scenario 2 Call Detail Record Processing. The primary obligation is purpose limitation and secure retention. The control owner is Network Operations. The exact artifact required is an automated data minimisation schedule and erasure log.

Scenario 3 Third-Party App Integrations. The primary obligation is verifiable data processor agreements. The control owner is Vendor Risk Management. The exact artifact required is a signed processor addendum containing explicit audit rights.

What To Ask Any Provider

When evaluating compliance platforms for a large enterprise, decision makers must look past generic dashboards to assess actual operational capability. Ask if the platform can generate a regulator-ready evidence pack that links a specific Data Principal rights request to the underlying data store within legal SLA windows. Question how the tool handles consent revocation syncs across fragmented legacy billing and CRM systems without requiring excessive manual engineering hours. Require proof that the provider supports the Rules 2025 breach workflow, including automated 72-hour DPBI reporting templates. Assess whether the platform natively integrates Data Protection Impact Assessment modules that satisfy independent audit requirements.

Implementation Roadmap

Enterprise compliance teams must proactively operationalise these exact requirements before the enforcement dates notified by the Central Government begin.

1. 30 Day Milestone. Map all subscriber data entry points and complete a baseline Record of Processing Activities across the enterprise.

2. 60 Day Milestone. Deploy consent management tooling capable of capturing itemised consent in regional languages and establish the internal breach intimation workflow.

3. 90 Day Milestone. Run a simulated Data Protection Impact Assessment on the highest-risk data flows, update processor contracts, and finalise the DPBI evidence generation process.

Further Reading

Governing complex data supply chains requires continuous oversight and precise documentation. Read our guides on managing Data Processor relationships under DPDP standards and preparing evidence trails for DPBI inquiries to strengthen your compliance posture. A successful defence against regulatory action relies entirely on the quality of your operational records. To evaluate your current readiness against the Rules 2025 and identify critical gaps in your subscriber data workflows, initiate a baseline assessment at freescan.complydp.com.

Sources

Frequently asked questions

How does the DPDP Act 2023 affect existing telecom licensing data rules?

Telecom providers must comply with both sets of regulations concurrently. While telecom licenses may dictate specific data retention periods for law enforcement purposes, the DPDP Act governs how personal data is collected, processed, and deleted once that legal purpose expires.

Will large telecom operators be classified as Significant Data Fiduciaries?

Yes, due to the high volume of personal data processed and the potential risk to consumer rights, major telecom operators will likely meet the threshold for Significant Data Fiduciaries. The Rules 2025 require SDFs to appoint a resident Data Protection Officer, conduct regular DPIAs, and undergo independent data audits.

What are the breach notification timelines for telecom providers under the Rules 2025?

Under the Rules 2025, Data Fiduciaries must submit a detailed breach report to the Data Protection Board of India within 72 hours. Simultaneously, they must provide intimation to affected Data Principals without delay, outlining the nature of the breach and mitigation steps.

How should enterprise compliance teams handle cross-border data routing?

Under the DPDP Act, cross-border transfers are generally permitted unless the Central Government issues a negative list restricting specific countries. However, existing telecom localisation rules still apply, meaning compliance heads must map DPDP rules against sector-specific mandates.

Can our existing GRC software handle DPDP Rules 2025 compliance?

Most legacy GRC tools lack the specific workflows required for the DPDP Rules 2025, such as verifiable parental consent mechanics and automated 72-hour DPBI reporting templates. Purpose-built tools are necessary to generate the exact evidence packs the regulator will demand during an inquiry.