At scale, every small gap is a large number of people.
The scene
The SIM was activated at a roadside kiosk. The retailer photographed the ID on his own phone to 'save time'. Multiply that phone by a few hundred thousand retailers.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
Telecom law governs our data.
Sectoral rules and DPDPA apply together; neither excuses the other.
Build one control set that satisfies both.
Retailers are independent businesses.
Where they collect for you, they are your processors.
Govern the edge of the network like the core.
We'll deal with SDF status if notified.
Volume and sensitivity make notification likely; the obligations take time to build.
Build the SDF stack before the letter arrives.
Rights at scale
Access, correction and erasure requests at telecom volume cannot be handled by email. They need a product, with identity checks and timelines built in.
The full Telecom briefing 3 deep dives
Deep dive 01 →
The network's weakest node is a retailer's phone.
A photographed ID on a personal phone is a breach with no date yet.
Deep dive 02 →
Prepare for the letter before it arrives.
Significant Data Fiduciary is not a title. It is a timetable.
Deep dive 03 →
A tenth of a percent is a hundred thousand requests.
Rights without a product are a queue. Queues become complaints.
Monday morning
01 Audit five retail points for how IDs are captured and stored.
02 Estimate annual rights requests at 0.1% of subscribers. Plan capacity.
03 Draft the SDF readiness gap list.
Questions, answered plainly
Are telecom companies Significant Data Fiduciaries under DPDPA? +
Only the Central Government can notify Significant Data Fiduciaries. Given the volume and sensitivity of subscriber data, large telecom operators are strong candidates and should prepare for Section 10 obligations.
Do retailers who collect SIM KYC count as Data Processors? +
Where retailers collect and handle subscriber data on behalf of an operator, they generally act as Data Processors, and the operator remains responsible under Section 8(1).
Sector · Insurance Your agent's phone is part of your data estate. Read →
Sector · HR & Staffing The candidate you never hired is still your Data Principal. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).