Licence conditions oblige an operator to archive two years of call, event and IP detail records. The DPDP Act hands the subscriber an erasure right over the same data. The licence-mandated archive is protected — but only it. The location analytics, marketing segments and value-management profiles built from those records enjoy no shield and must be separable, which today they are not. Delete too much and it is a licence breach; too little and it is a DPDP breach. The industry body raised this, the breach-reporting clocks, SIM parental consent and consent-manager scope during consultation, and says most of it went unaddressed.
FROM THE SEPTEMBER 2026 PROBLEM REGISTER · 7 TELECOM PROBLEMS SWEPT · 4 SHOWN HERE · HOW THIS WAS BUILT
Each of these is marked confirmed: two independent sources, at least one the instrument itself or a practitioner record — here, the industry association’s own statements on the record.
DPDP s.8(7) and s.12 meet the Department of Telecommunications’ licence security-condition amendment of 22 December 2021: at least two years of call, event and IP detail records and of subscriber login records. The law-in-force carve-out protects that dataset and nothing else. Mediation and analytics stacks copy the records into dozens of downstream systems, so the protected and unprotected copies sit together; a lawful refusal has to name the licence condition for the archive and a real deletion has to reach the derived copies.
SOURCES · DoT licence amendment, 21–22 Dec 2021 (instrument) · DPDP Act s.8(7), s.12 (statute) · The Telecommunications Act 2023 meets DPDP (practitioner)
Confirmed · sweep of 2 Sep 2026CERT-In’s Directions of 28 April 2022 set a six-hour reporting window and 180-day ICT log retention in India. DPDP Rule 7 requires intimating affected principals and the Board without delay, with a detailed report within seventy-two hours, and carries no materiality threshold. The thresholds disagree on what counts — a cyber incident versus a personal-data breach — so classification itself is a compliance decision under a clock measured in hours. COAI formally asked for a unified trigger, window and format, and states that the concern was not addressed.
SOURCES · CERT-In Directions, 28 Apr 2022 (instrument) · DPDP Rules 2025, Rule 7 (text) · COAI statement on the notified Rules (practitioner)
Confirmed · raised in consultation and again after notificationDPDP s.9(1) and Rule 10 meet the DoT KYC regime, executed through lakhs of registered point-of-sale agents who are penalised for keeping subscriber information on their devices. COAI has formally sought exemption from the parental-consent requirement for SIM issuance; no response had been located as of the sweep. Registering a minor’s SIM in a parent’s name shifts the problem rather than solving it — a records-versus-reality mismatch every downstream consent register inherits.
SOURCES · COAI exemption request, Nov 2025, as reported (practitioner) · DPDP Act s.9(1); DPDP Rules 2025, Rule 10 (text) · DoT point-of-sale registration regime (instrument, context)
Confirmed · the least controllable edge of the estateDPDP s.6(7)–(9) and Rule 4 with its First Schedule create registered, interoperable Consent Managers with registration opening in mid-November 2026. Operators already capture consent in their business-support stacks and under TRAI’s DLT-based commercial-communication regime — a sector-specific consent infrastructure that predates DPDP. COAI’s ask on the record: permit a common industry consent layer, or clarify that external Consent Managers are not mandatory where a robust, auditable internal system exists. Unaddressed at notification.
SOURCES · DPDP Act s.6(7)–(9); DPDP Rules 2025, Rule 4 and First Schedule (text) · COAI statement (practitioner) · Outlook Business on the unaddressed concerns (reporting)
Confirmed · the ambiguity and the industry’s stake are both on the recordThe register started from AI-drafted hypotheses and kept only what the instruments supported. These are the telecom-specific claims that changed on the way.
The DoT amended licence security conditions on 22 December 2021 to at least two years for call, event and IP detail records and for subscriber login records. Material still quoting one year predates the amendment.
No SDF class had been notified as of the sweep, and none can bind before s.10 and Rule 13 commence in mid-May 2027. Telecom is a consensus candidate, not a designated class. The planning problem is real — building DPO, DPIA and audit programmes against a designation that does not yet exist — and the register records it as exactly that.
Consent Managers are a channel a data principal may choose; the Act’s design does not oblige a fiduciary to route consent through one. The open question is interoperability once they exist, not whether internal capture is lawful today.
Rule 7 puts principals on “without delay.” The seventy-two-hour clock belongs to the detailed report to the Board. Both start before the facts exist; neither is a customer-notification deadline.
The penalty provisions commence in mid-May 2027 and the Board had no members as of 1 August 2026. What is enforced today is the licence itself, CERT-In’s directions, and TRAI’s commercial-communication regime. The DPDP penalty schedule is stated plainly here, once.
RULES NOTIFIED MID-NOV 2025 · CONSENT-MANAGER REGISTRATION OPENS MID-NOV 2026 · DUTIES, RIGHTS AND PENALTIES MID-MAY 2027 · DATES STATED AS THE NOTIFICATIONS STATE THEM
Everything below is live today and maps to shipped code — the same rule as every page on this site. Capabilities we are still building are not listed here.
Every access and erasure request carries a response deadline computed when it is filed and an escalation ladder when it slips. Erasure is executed against the stores you connect — a parameter-bound delete against the table and column you nominate, every object under the subscriber’s prefix in object storage, deletion through connected tools’ own APIs — and the destruction is recorded, not asserted. The written refusal for the licence-mandated archive lands in the same chain, citing the condition.
Live: DSR orchestration · SLA tracking · erasure connectorsConsent is captured per specified purpose with an itemised, versioned notice; withdrawal is as easy as the grant and honoured across every property. Each decision produces a receipt. This is an internal consent system with an audit trail behind it. We make no claim about Consent-Manager interoperability on this page: no Consent Manager is registered anywhere in India yet, so there is nothing live to have tested against.
Live: purpose-by-purpose consent · versioned notices · cross-domain syncA guardian’s consent is captured as its own record, tied to the minor’s, with the verification method stated — never a stronger claim than the mechanism supports. This is the digital channel. For the retail point of sale, this page claims no capture tool: what happens at lakhs of counters is exactly what the industry has asked the government about, and we would rather say that than imply it is covered.
Live: guardian consent flows for age-gated processingNotices and consent flows are rendered in twenty-two Indian languages by a self-hosted translation model — a subscriber base that spans every state is served one versioned notice, not twenty-two divergent ones. Every consent, erasure, refusal and notice publication is a linked record bound to the one before it, periodically stamped by an independent timestamp authority. Anyone can check it.
Live: 22 Indian languages · tamper-evident audit trail · verifiable receiptsFor collision 02, an incident record tracks the notification obligation under each applicable regime and the seventy-two-hour report countdown — it does not file for you, and it does not send SMS. The register found nothing sector-standard that generates all three filings from one record, and we are not going to claim we are it.