By sector · Telecom & media

Telecom DPDP compliance
licence duties sit beside the Act, not above it.

Operators work under licence conditions, the Telecommunications Act 2023, DoT's cyber security rules and TRAI's commercial communication regime. None of them displaces the DPDP Act. And every business that sends an SMS in India touches TRAI's consent rules, whether it knows it or not.

TCCCPR 2018DLTTelecom Cyber Security Rules 2024DPDP s.9
01

Which laws apply to telecom and media companies?

Telecom operators answer to the Telecommunications Act, 2023, their authorisation or licence conditions, DoT's Telecom Cyber Security Rules and TRAI's regulations, plus the DPDP Act for subscriber data. Media and OTT platforms answer to the DPDP Act and the IT Rules. Any business sending commercial SMS or calls answers to TRAI's TCCCPR.

Law or ruleWhat it governsWho
DPDP Act 2023 and Rules 2025Subscriber and viewer data: notice, consent, purpose, erasure, rightsOperators, OTT and media platforms
Telecommunications Act, 2023Authorisation, user protection including consent to specified messagesTelecom entities
Telecom Cyber Security Rules, 2024Six-hour incident reporting to the Central Government; security policy; a Chief Telecommunication Security OfficerTelecom entities; since October 2025 amendment, some duties for entities using phone numbers to identify customers
TRAI TCCCPR 2018, amended 2025Commercial communications: DLT registration, consent, preferences, opt-outAccess providers and every business sending commercial SMS or calls
IT Rules 2021, amended 2026Intermediary due diligence, synthetic content labellingPlatforms hosting user content. See the AI governance guide
02

The obligation telecom gets wrong: assuming licence conditions displace the Act

Operators already verify subscribers and retain records under licence conditions, so they often assume the DPDP Act adds little. It adds a great deal. Licence-mandated retention is an exception to erasure, but not an exemption from notice, purpose limitation or subscriber rights, and the commercial layer is where exposure sits.

The regulated core is fairly well governed: subscriber verification, call detail records, lawful interception. The exposure is in what is built on top. Location history used to sell footfall analytics, browsing or viewing data used to target ads, and device identifiers shared with an ad network are processing for purposes the subscriber did not agree to when they bought a connection. A CDR kept because the licence says so is lawful; the analytics product built from it is a separate purpose needing separate consent.

Media platforms have an additional problem: age. If a meaningful share of your audience is under eighteen, section 9(3)'s ban on tracking, behavioural monitoring and targeted advertising applies to them, whatever the account holder agreed to. A family plan with one adult payer and three child viewers is four Data Principals, and three of them cannot be targeted.

04

What a business sending SMS must set up

Any company that sends OTPs, order updates or offers by SMS in India is a principal entity under TRAI's regulations, even if it has never thought of itself as touching telecom rules. It must register on a DLT platform, register its sender headers and message templates, and keep promotional traffic within the consent and preference rules.

The work is mostly classification. Each template is registered as transactional, service or promotional, and the category decides who may receive it. TRAI's 2025 explanatory memorandum limits transactional messages to those triggered within thirty minutes of a transaction the customer started; an offer bolted onto a delivery update makes the whole message promotional. Promotional messages then go only to subscribers who have not blocked that category, or who have given explicit consent through the DLT consent process. The SMS vendor handles the pipes, but the principal entity owns the templates and the consents, and is the one blacklisted when they are wrong. Keep your own DPDP consent record for the same person alongside, because TRAI's record answers a different question.

05

Incident reporting for telecom entities

Under the Telecommunications (Telecom Cyber Security) Rules, 2024, notified in November 2024, a telecom entity must report a security incident affecting its network or services to the Central Government within six hours of becoming aware of it, with fuller details within 24 hours. The DPDP breach reports run alongside.

The October 2025 amendment to those rules created a category of telecommunication identifier user entities, meaning businesses that use phone numbers to identify customers or deliver services, and a government mobile number validation platform they may be directed to use. Banks, fintechs and platforms that treat a phone number as identity should watch this closely. If an incident involves subscribers' personal data, the Data Protection Board and every affected subscriber must be told, with the detailed Board report within 72 hours; the breach deadline calculator lays out the clocks together.

06

Telecom and media control checklist

For operators, OTT and media platforms, and any business running SMS or voice campaigns.

ControlWhyEvidence to hold
Retention schedule separating licence-mandated records from commercial dataDPDP s.8(7); licence conditionsSchedule; deletion logs for commercial data
Separate consent for location, viewing and device-data analytics or adsDPDP s.6(1)Consent record per purpose
No targeted ads or profiling for viewers under eighteenDPDP s.9(3)Profile-level age flags; ad configuration
DLT registration of entity, headers and templatesTRAI TCCCPRDLT records per header and template
Opt-out in every promotional message; 90-day re-consent barTCCCPR as amended 2025Template review; revocation log
Six-hour incident reporting to the Central GovernmentTelecom Cyber Security Rules 2024Runbook; incident timestamps
App and web tags held until consentDPDP s.6Two-pass scan of web properties
07

Where to go next

Platforms hosting user content should also read the AI governance guide for the synthetic content rules, and anyone handling young audiences the children's data guide. For the law underneath all of it, read the DPDP Act and Rules 2025 guide. To see what your own website does before a visitor answers the banner, run the free two-pass cookie scan. The consent platform holds versioned notices in 22 languages, a hash-chained consent ledger, withdrawal relayed to each processor, and rights requests and breaches on their statutory clocks. The industries overview compares all eight sectors.

Questions

The things people ask us

Do telecom licence conditions replace the DPDP Act?

No. Licence conditions and the Telecommunications Act, 2023 sit alongside it. Retention the licence or law requires is an exception to DPDP erasure, but not an exemption from notice, purpose limitation or rights. A telecom company owes subscribers the same DPDP duties as any other Data Fiduciary.

What is DLT registration for SMS in India?

Under TRAI's Telecom Commercial Communications Customer Preference Regulations, 2018, every business sending commercial SMS must register as a principal entity on a distributed ledger platform run by an access provider, with its headers and message templates. Unregistered traffic is blocked. Consent for promotional messages is recorded on the same system.

How quickly must a telecom company report a security incident?

Within six hours of becoming aware of it, to the Central Government, under the Telecommunications (Telecom Cyber Security) Rules, 2024, with fuller details within 24 hours. CERT-In's six-hour rule may also apply, and a personal data breach adds the DPDP reports to the Board and each affected subscriber.

Must every promotional SMS include an opt-out?

Yes. TRAI's February 2025 amendment requires the sender to give an opt-out mechanism in the same promotional message. A recipient who revokes consent can opt in again at will, but the sender may only seek consent again after ninety days. Complaints about unsolicited messages can be made within seven days of receipt.

Can a telecom operator use call records for advertising?

Not on the strength of the licence. Call detail records retained under licence conditions are lawful for that purpose. Building an advertising or analytics product on them is a separate purpose that needs the subscriber's consent under the DPDP Act, and for subscribers under eighteen, section 9 bars targeted advertising altogether.

Subscriber data

Separate what the licence requires from what marketing wants.

Scan your web properties, then see how the platform keeps consent per purpose, so the analytics product never runs on data collected for the licence.