DPDP Guide for Telecom Retailers
Telecom shops process Aadhaar and biometric data for SIM cards. This guide explains DPDP requirements for KYC, recharges, and customer. Get expert help.
Discuss this page with an LLM
DPDP Action Sheet
Use this before your next workflow goes live. It keeps the useful parts visible and turns DPDP into checks your team can actually answer.
For DPDP Guide for Telecom Retailers, the DPDP question is how personal data enters the workflow, where it is stored, which tools touch it, what purpose was explained, and how deletion or withdrawal will work.
1. Lead Forms
Check:
- What data are you collecting?
- Is the purpose clear at the point of collection?
- Is marketing consent separate from service communication?
- Can the user withdraw consent later?
Common mistake: one checkbox that silently covers newsletters, sales calls, partner sharing and remarketing.
2. Email and WhatsApp
Check:
- Who is on the list?
- Where did consent come from?
- Is the list imported from a vendor, event, webinar, scrape or old CRM?
- Can you prove the source of consent?
Common mistake: treating every lead as permanently marketable.
3. Ads and Retargeting
Check:
- Are pixels or ad platforms receiving identifiable user behavior?
- Are audiences built from customer lists?
- Are lookalike or remarketing audiences using personal data?
Common mistake: assuming "the ad platform handles it" means your company has no DPDP responsibility.
4. Website Analytics
Check:
- Which tools run on the site?
- Are IP address, device identifiers, session IDs or form fields being captured?
- Is analytics used only for measurement, or also for profiling and targeting?
Common mistake: installing tools first and asking privacy questions later.
5. Vendor List
Make a quick list:
- CRM
- Email platform
- WhatsApp provider
- Analytics
- Ad pixels
- Form tool
- Landing page builder
- Webinar tool
For each vendor, answer: what data goes there, why, who can access it and how deletion works.
6. This Week's Action
Map one campaign from first click to final follow-up. Mark every place personal data is collected, enriched, shared, uploaded or used for targeting.
If your team cannot answer where the data came from and where it goes next, start with a data flow map before rewriting policy copy.
Book a DPDP clarity callWant all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.
Handling Identity Documents and SIM Activation
Telecom retailers handle sensitive identity data including Aadhaar numbers, biometric logs, and live photographs. When you perform a Point of Sale (POS) activation, you are collecting personal data that can lead to identity theft if mishandled. You must ensure that physical photocopies of customer IDs are not left visible on counters or stored in unlocked drawers. If you use a mobile app for KYC, you must verify that the app does not save images to your phone’s public photo gallery.
Managing Recharge Logs and Customer Lists
Mobile recharge shops often maintain digital or paper logs of customer phone numbers and transaction amounts. Under DPDP, these logs are collections of personal data. You cannot share these lists with third-party agents, such as loan providers or insurance salesmen. Your responsibility is to protect this contact information from unauthorized access. If you maintain a “khata” or credit book with customer names and numbers, this data must also be kept secure and used only for payment recovery.
Data Risks in Telecom Retail
| Business Activity | Personal Data Involved | DPDP Risk Level |
|---|---|---|
| New SIM Activation | Aadhaar, Live Photo, Address Proof | High |
| Mobile Number Porting (MNP) | UPC Code, Identity Proofs, Phone Number | High |
| Prepaid/Postpaid Recharges | Mobile Number, Payment Status | Medium |
| Device Sales & Warranty | Name, Contact Number, IMEI | Low |
| Biometric KYC | Fingerprint Data, Aadhaar Number | Very High |
This week
Check your shop for any physical photocopies of customer ID cards (Aadhaar, PAN, Voter ID) from previous SIM activations. If the SIM is already active and the data is uploaded to the telecom company, shred these physical documents immediately.
Now think about your work. Where does personal data enter your workflows? Where does it sit? Who else touches it?
Frequently asked questions
Can I use my customer recharge list to send ads for my other shop services?
No. DPDP requires purpose limitation. If a customer gave their number for a mobile recharge, you cannot use it for marketing other products without separate, specific consent.
Is it okay to store photos of customer Aadhaar cards on my personal smartphone?
No. Storing sensitive KYC documents in a personal gallery creates high risk. You must use the official telecom operator app and ensure no local copies remain on your device.
What should I do with physical SIM registration forms from last year?
You must securely destroy them if the activation purpose is complete. DPDP mandates deleting personal data once it is no longer needed for the original service.