AMLEGALS — Strategic Lawyering

SIM KYC and Retailers: DPDPA Risk at the Edge of the Telecom Network

SIM KYC and Retailers: DPDPA Risk at the Edge of the Telecom Network

A photographed ID on a personal phone is a breach with no date yet.

The scene

The retailer kept a folder of customer ID photos ‘in case activation fails’. The folder synced to a personal cloud account. The phone was sold second-hand eighteen months later.

Where the thinking breaks

The unclear thought What it breaks The clearer thought

Retailers are independent businesses.

When collecting KYC for the operator, they act on its behalf.

Govern retailers as processors, through distributors.

Digital KYC solved the paper problem.

Workarounds recreate it on personal devices.

Make the compliant path faster than the workaround.

Auditing the edge

Sample retail points every quarter. Check devices, not just forms. Measure how often IDs exist outside the official app.

Monday morning

01 Visit five retail points unannounced.

02 Check how IDs are captured and where copies go.

03 Fix the workflow that creates the workaround.

Questions, answered plainly

Are telecom retailers Data Processors under DPDPA? +

Where they collect subscriber KYC on behalf of an operator, they generally act as Data Processors. The operator remains responsible under Section 8(1).

What should telecom operators do about ID copies at retail points? +

Limit capture to the official process, prohibit local copies, audit devices and contractually bind distributors and retailers to security and deletion obligations.

Sector · Telecom A billion subscribers. A billion Data Principals. Read →

Telecom · Deep dive Prepare for the letter before it arrives. Read →

Telecom · Deep dive A tenth of a percent is a hundred thousand requests. Read →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).