Skip to content
FaceOff Technologies

DPDP by industry

DPDP for telecom operators and handset OEMs

Telcos sit on subscriber data, location, device identifiers and CDRs, and distribute through a retailer network they do not directly employ. The consent surface is wider than the systems that record it.

Deadline
13 May 2027
Pressure points
3 identified
Controls
4 products
Max penalty
₹250 Cr, per instance

Already regulated by

  • TRAI
  • DoT
  • MeitY
  • CERT-In

DPDP sits alongside these rather than replacing them. Where a sectoral rule requires retention and the Act requires erasure, both are satisfiable — but only where the basis is recorded per attribute.

Where the pressure lands

What DPDP actually changes for telecom & handset oems

The Act applies uniformly. The obligations that bite first do not — these are the ones this sector fails on.

Sec. 6(1), 6(4)

Consent captured at the retail counter

Activation happens through distributors and retailers. Consent taken there has to be specific and evidenced, and withdrawal has to reach the same systems that activation did.

Sec. 4, 8(7)

Location and device data as personal data

Identifiers and location resolve to an individual, so they carry the same notice, purpose-limitation and erasure duties as name and address — including where they feed analytics products.

Sec. 8(1)–(2)

Value-added services and third-party sharing

VAS partners and advertising platforms inherit subscriber data under the operator's Fiduciary liability, which makes the processor register a commercial control, not just a compliance artefact.

What closes them

The controls, in the order they land

Discovery first, because every other obligation is undeliverable without a catalogue. Everything after that consumes what it built.

  1. 01

    Consent Management

    Capture valid consent per purpose, give people self-service control, and make it the authoritative signal everywhere.

    Sec. 5, 6, 9

  2. 02

    Privacy Program Governance

    Run the whole privacy programme from one control plane, so the next regulation lands as configuration.

    Sec. 4, 7, 10, 16

  3. 03

    Intelligent Data Mapper

    Replace stale inventories with a live, identity-resolved map of every place personal data actually lives.

    Sec. 8(3), 8(7)

  4. 04

    DSAR Management

    Receive, verify, fulfil and audit every access, correction, erasure and grievance request inside the statutory clock.

    Sec. 11–14

Sequence

A readiness plan that buys down the biggest exposure first

The same four phases apply in every sector; what changes is which systems go first.

  1. Phase 1

    Weeks 1–6

    See the estate

    • Deploy Discovery across priority systems
    • Build the identity-resolved catalogue
    • Reconcile collected data against notice
  2. Phase 2

    Weeks 4–12

    Stop the bleeding

    • Mask non-production and analytics estates
    • Deploy breach detection and playbooks
    • Wire intimation to the catalogue
  3. Phase 3

    Weeks 8–18

    Fix the basis

    • Roll out purpose-level consent and notice
    • Enforce withdrawal parity and cessation
    • Turn on children's age-band gating
  4. Phase 4

    Weeks 14–26

    Prove it

    • Automate DSAR intake and fulfilment
    • Run DPIA cadence for SDF duties
    • Open the auditor workspace

Also defending telecom & handset oems?

On-device trust scoring embedded into the handset stack, giving carriers SIM-swap protection, verified onboarding, and fraud signals at activation.

See the Telecom & Handset OEMs solution

Find the gaps in your telecom & handset oems programme.

A readiness walkthrough maps what you already run onto the eighteen obligations, and names what is missing with the exposure attached.