Solutions · Telecom

Two years of call records,
and a right to erase them.

Licence conditions oblige an operator to archive two years of call, event and IP detail records. The DPDP Act hands the subscriber an erasure right over the same data. The licence-mandated archive is protected — but only it. The location analytics, marketing segments and value-management profiles built from those records enjoy no shield and must be separable, which today they are not. Delete too much and it is a licence breach; too little and it is a DPDP breach. The industry body raised this, the breach-reporting clocks, SIM parental consent and consent-manager scope during consultation, and says most of it went unaddressed.

FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 7 TELECOM PROBLEMS SWEPT · 4 SHOWN HERE · HOW THIS WAS BUILT

What the ground actually looks like

Four collisions, each read from the instrument.

Each of these is marked confirmed: two independent sources, at least one the instrument itself or a practitioner record — here, the industry association’s own statements on the record.

01 · THE ARCHIVE AND ITS SHADOWS

Two years of CDR, EDR and IPDR are licence-mandated; the analytics built from them are not — and the two are physically interleaved.

DPDP s.8(7) and s.12 meet the Department of Telecommunications’ licence security-condition amendment of 22 December 2021: at least two years of call, event and IP detail records and of subscriber login records. The law-in-force carve-out protects that dataset and nothing else. Mediation and analytics stacks copy the records into dozens of downstream systems, so the protected and unprotected copies sit together; a lawful refusal has to name the licence condition for the archive and a real deletion has to reach the derived copies.

SOURCES · DoT licence amendment, 21–22 Dec 2021 (instrument) · DPDP Act s.8(7), s.12 (statute) · The Telecommunications Act 2023 meets DPDP (practitioner)

Confirmed · sweep of 2 Sep 2026
02 · ONE INCIDENT, THREE REPORTS

The same security incident is reportable to CERT-In in six hours, under DoT licence conditions, and to the Data Protection Board and every affected subscriber under Rule 7 — on different triggers and different definitions.

CERT-In’s Directions of 28 April 2022 set a six-hour reporting window and 180-day ICT log retention in India. DPDP Rule 7 requires intimating affected principals and the Board without delay, with a detailed report within seventy-two hours, and carries no materiality threshold. The thresholds disagree on what counts — a cyber incident versus a personal-data breach — so classification itself is a compliance decision under a clock measured in hours. COAI formally asked for a unified trigger, window and format, and states that the concern was not addressed.

SOURCES · CERT-In Directions, 28 Apr 2022 (instrument) · DPDP Rules 2025, Rule 7 (text) · COAI statement on the notified Rules (practitioner)

Confirmed · raised in consultation and again after notification
03 · SIM KYC AT LAKHS OF COUNTERS

Parental consent for a minor’s SIM is operationally impossible at a retail point of sale — and the industry has formally asked to be exempted.

DPDP s.9(1) and Rule 10 meet the DoT KYC regime, executed through lakhs of registered point-of-sale agents who are penalised for keeping subscriber information on their devices. COAI has formally sought exemption from the parental-consent requirement for SIM issuance; no response had been located as of the sweep. Registering a minor’s SIM in a parent’s name shifts the problem rather than solving it — a records-versus-reality mismatch every downstream consent register inherits.

SOURCES · COAI exemption request, Nov 2025, as reported (practitioner) · DPDP Act s.9(1); DPDP Rules 2025, Rule 10 (text) · DoT point-of-sale registration regime (instrument, context)

Confirmed · the least controllable edge of the estate
04 · WHOSE CONSENT MANAGER

The Rules do not say whether an operator’s internal consent system suffices, or whether it must interoperate with registered external Consent Managers from November 2026.

DPDP s.6(7)–(9) and Rule 4 with its First Schedule create registered, interoperable Consent Managers with registration opening in mid-November 2026. Operators already capture consent in their business-support stacks and under TRAI’s DLT-based commercial-communication regime — a sector-specific consent infrastructure that predates DPDP. COAI’s ask on the record: permit a common industry consent layer, or clarify that external Consent Managers are not mandatory where a robust, auditable internal system exists. Unaddressed at notification.

SOURCES · DPDP Act s.6(7)–(9); DPDP Rules 2025, Rule 4 and First Schedule (text) · COAI statement (practitioner) · Outlook Business on the unaddressed concerns (reporting)

Confirmed · the ambiguity and the industry’s stake are both on the record
What the law actually says — and what it doesn’t

Claims we corrected before putting them here.

The register started from AI-drafted hypotheses and kept only what the instruments supported. These are the telecom-specific claims that changed on the way.

“CDR retention is one year” is outdated.

The DoT amended licence security conditions on 22 December 2021 to at least two years for call, event and IP detail records and for subscriber login records. Material still quoting one year predates the amendment.

“Telecom operators are near-certain Significant Data Fiduciaries” cannot be stated as fact.

No SDF class had been notified as of the sweep, and none can bind before s.10 and Rule 13 commence in mid-May 2027. Telecom is a consensus candidate, not a designated class. The planning problem is real — building DPO, DPIA and audit programmes against a designation that does not yet exist — and the register records it as exactly that.

The Act does not require a fiduciary to use a Consent Manager.

Consent Managers are a channel a data principal may choose; the Act’s design does not oblige a fiduciary to route consent through one. The open question is interoperability once they exist, not whether internal capture is lawful today.

“Subscribers must be notified within 72 hours” is wrong.

Rule 7 puts principals on “without delay.” The seventy-two-hour clock belongs to the detailed report to the Board. Both start before the facts exist; neither is a customer-notification deadline.

No DPDP penalty can be imposed on anyone today.

The penalty provisions commence in mid-May 2027 and the Board had no members as of 1 August 2026. What is enforced today is the licence itself, CERT-In’s directions, and TRAI’s commercial-communication regime. The DPDP penalty schedule is stated plainly here, once.

RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM

Where Consent Tree fits today

The refusal that names the licence,
and the deletion that reaches the rest.

Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.

FOR 01 · THE ARCHIVE AND ITS SHADOWS

A rights request executed against the derived copies, with the licence-mandated refusal evidenced

Every access and erasure request carries a response deadline computed when it is filed and an escalation ladder when it slips. Erasure is executed against the stores you connect — a parameter-bound delete against the table and column you nominate, every object under the subscriber’s prefix in object storage, deletion through connected tools’ own APIs — and the destruction is recorded, not asserted. The written refusal for the licence-mandated archive lands in the same chain, citing the condition.

Live: DSR orchestration · SLA tracking · erasure connectors
FOR 04 · THE INTERNAL SYSTEM

Purpose-level consent, versioned and withdrawable, as the auditable internal register COAI describes

Consent is captured per specified purpose with an itemised, versioned notice; withdrawal is as easy as the grant and honoured across every property. Each decision produces a receipt. This is an internal consent system with an audit trail behind it. We make no claim about Consent-Manager interoperability on this page: no Consent Manager is registered anywhere in India yet, so there is nothing live to have tested against.

Live: purpose-by-purpose consent · versioned notices · cross-domain sync
FOR 03 · THE MINOR SUBSCRIBER

Guardian consent flows for age-gated processing — on the digital journey

A guardian’s consent is captured as its own record, tied to the minor’s, with the verification method stated — never a stronger claim than the mechanism supports. This is the digital channel. For the retail point of sale, this page claims no capture tool: what happens at lakhs of counters is exactly what the industry has asked the government about, and we would rather say that than imply it is covered.

Live: guardian consent flows for age-gated processing
FOR ALL OF IT · EVIDENCE, IN 22 LANGUAGES

Notices in the Eighth Schedule languages, and an audit trail a regulator can verify without trusting us

Notices and consent flows are rendered in twenty-two Indian languages by a self-hosted translation model — a subscriber base that spans every state is served one versioned notice, not twenty-two divergent ones. Every consent, erasure, refusal and notice publication is a linked record bound to the one before it, periodically stamped by an independent timestamp authority. Anyone can check it.

Live: 22 Indian languages · tamper-evident audit trail · verifiable receipts

For collision 02, an incident record tracks the notification obligation under each applicable regime and the seventy-two-hour report countdown — it does not file for you, and it does not send SMS. The register found nothing sector-standard that generates all three filings from one record, and we are not going to claim we are it.