Other Data privacy

India telecom data ownership review

This matters to teams running SMS alerts, OTP, customer messaging, and CPaaS integrations in India because the compliance question is shifting from simple consent capture to end-to-end accountability for subscriber, traffic, location, device, and outsourced processing data. On 23 July 2026, TRAI opened a consultation on privacy, security, and ownership of telecom-sector data, on top of the new authorisation framework launched in late June. Any follow-on rules could reshape retention, data sharing, audit evidence, and vendor access design.

Published:07/29/2026 Updated:07/29/2026

1. Regulatory focus

TRAI’s 23 July consultation is not just another generic privacy exercise. It reopens the core question of who may control, use, share, and retain telecom-sector data across subscriber records, traffic data, location data, device identifiers, and third-party processing scenarios. For SMS and OTT operators, the timing matters: this consultation follows India’s new telecom authorisation framework notified on 23 June and operationalised from 25 June, which means any future privacy obligations may be tied not only to policy principles but also to authorisation terms, audit trails, and vendor-accountability conditions.

2. Business impact

If message logs, OTP failure reasons, number-status data, location tags, or support-chat summaries are spread across aggregators, CRM tools, fraud engines, and offshore cloud services, the first compliance weakness will not be content review. It will be the inability to explain data flows, complete deletion, and constrain outsourced access. For cross-border CPaaS and multichannel messaging teams, this directly affects localisation choices, least-privilege architecture, access logging, cross-border transfer assessments, and contract splits with Indian carriers or local partners. Once the rules become specific, proving who holds which dataset, for how long, and for what purpose may determine launch readiness before delivery metrics do.

3. Operating recommendations

The practical move now is not to wait for final rules, but to redraw the messaging data inventory by object type. Map phone numbers, template receipts, error codes, device identifiers, location fields, and support-message records against source, purpose, retention period, transfer path, and approved access roles. Next, put aggregators, cloud vendors, BPO teams, and fraud providers under one evidence framework with documented processing instructions, log retention, deletion closure, and incident-escalation terms. If India later hardwires privacy duties into authorisation conditions or sector rules, this preparation will reduce the need for emergency redesign across the SMS and messaging stack.

Frequently Asked Questions

We only send OTP and notification texts. Does this consultation still matter to us?
Yes. The consultation is not limited to marketing content. It goes to the control and sharing of associated data such as phone numbers, delivery logs, failure codes, device data, and location data. Even if your text content is low risk, OTP workflows that rely on aggregators, cloud logging, or offshore support can still be scrutinised for retention, access, and deletion accountability.
Which systems should we review first to prepare for more detailed rules?
Start with four areas: SMS gateways and delivery-report platforms, customer messaging or ticketing systems, fraud and number-scoring tools, and cloud logging or monitoring stacks. The issue is not the product name but whether these systems hold phone numbers, message-template data, location tags, device identifiers, and access records, and whether deletion and export controls can be evidenced end to end.
If we use a local Indian partner for messaging, can we shift the compliance responsibility to them?
Usually not. A local partner may handle delivery, filings, or operator connectivity, but your company still needs to explain who collects the data, who can access it, who sets retention periods, and who executes deletion or incident-response actions. If the contract only covers service levels and lacks processing instructions and audit rights, your position will be weak once enforcement expectations tighten.
This article is for informational purposes only and does not constitute legal advice.

Need compliance guidance?

Contact us for guidance on target markets, message scenarios, and sending routes.

Get in Touch