The network's weakest nodeis a retailer's phone.
Operators secured the core. The identity documents travel through the edge.
In one line: Where they collect subscriber KYC on behalf of an operator, they generally act as Data Processors. The operator remains responsible under Section 8(1).
A photographed ID on a personal phone is a breach with no date yet.
The scene
The retailer kept a folder of customer ID photos ‘in case activation fails’. The folder synced to a personal cloud account. The phone was sold second-hand eighteen months later.
Where the thinking breaks
Auditing the edge
Sample retail points every quarter. Check devices, not just forms. Measure how often IDs exist outside the official app.
Monday morning
- 01Visit five retail points unannounced.
- 02Check how IDs are captured and where copies go.
- 03Fix the workflow that creates the workaround.
Questions, answered plainly
Are telecom retailers Data Processors under DPDPA?
Where they collect subscriber KYC on behalf of an operator, they generally act as Data Processors. The operator remains responsible under Section 8(1).
What should telecom operators do about ID copies at retail points?
Limit capture to the official process, prohibit local copies, audit devices and contractually bind distributors and retailers to security and deletion obligations.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner