India digital identity and telecom regulation

India's New Biometric SIM Rules Revive a Mandate the Supreme Court Once Limited

DoT's Telecommunications (User Identification) Rules, 2026 mandate biometric checks at every SIM issue, change, and disconnection, built outside the Aadhaar Act's own safeguards.

India's Biometric SIM Mandate, By the Numbers People of Internet Research · India 4 Biometric trigger points New SIM, info update, disconnectio… 3 months Operator compliance window From the August 21, 2026 notificat… 8 years Years since Puttaswamy limits 2018 Supreme Court ruling curbed m… peopleofinternet.com
India's Biometric SIM Mandate, By the … People of Internet Research · India 4 Biometric trigger points 3 months Operator compliance window 8 years Years since Puttaswamy limits peopleofinternet.com

Key Takeaways

What Changed on August 21

India's Department of Telecommunications notified the Telecommunications (User Identification) Rules, 2026 on August 21, 2026, and the rules took effect the same day they were published on the Telecom e-Service Portal (DoT eServices). They cover two categories under Section 3(7) of the Telecommunications Act, 2023: wireless access services (ordinary mobile SIMs) and internet telephony through mobile user terminals, which brings app-based calling into the same regime (MediaNama).

Operators — the "authorised entities" under the rules — must now run biometric identification at four distinct trigger points: enrolling a new SIM, updating a subscriber's information, disconnecting a connection, and whenever DoT itself directs re-verification. Aadhaar holders go through e-KYC, drawing on UIDAI's existing biometric database. Everyone else goes through D-KYC — a live face capture matched against an official document photo. Telcos have three months to stand up the compliance infrastructure this requires, meaning full operational rollout lands around late November 2026 (MediaNama). The rules follow a draft DoT circulated for consultation in September 2025, so roughly eleven months separate proposal from binding law.

The Legitimate Problem This Targets

Before litigating the objections, it's worth stating the government's case plainly, because it isn't a weak one. Fake and mule SIMs are a documented input into organised financial fraud, phishing operations, and the harassment ecosystem that regulators across the world are scrambling to contain — and DoT has been building toward stricter SIM-identity binding for over a year, including a parallel directive requiring WhatsApp and Telegram to validate mobile numbers under the Telecommunication Cybersecurity Amendment Rules, 2025 (MediaNama). A telecom identity layer resistant to forged documents and impersonation is a reasonable regulatory goal, and biometric matching is genuinely harder to spoof at scale than a photocopied ID card. If the rules did nothing more than close that gap, this would be an unremarkable compliance story.

Where It Runs Into 2018

But the 2023 Act's move toward biometric-based SIM identification was flagged as constitutionally shaky before it was even passed. PRS Legislative Research's analysis of the Telecommunications Bill, 2023 warned that a blanket biometric-verification mandate for telecom users "may not be proportionate, and may infringe upon the fundamental right to privacy," citing the Supreme Court's 2018 Aadhaar judgment, Justice K.S. Puttaswamy (Retd) v. Union of India, in which a five-judge bench struck down mandatory Aadhaar-SIM linking on the ground that "for the misuse of such SIM cards by a handful of persons, the entire population cannot be subjected to intrusion into their private lives" (PRS India).

"For the misuse of such SIM cards by a handful of persons, the entire population cannot be subjected to intrusion into their private lives." — Supreme Court of India, 2018

The 2026 Rules don't repeat the exact mechanism the Court rejected — this is a fresh biometric identification requirement grounded in the Telecommunications Act, 2023 rather than a demand to link every SIM to Aadhaar. That distinction matters legally. It also means the new subscriber-identity data DoT is amassing sits outside the specific statutory scaffolding — purpose limitation, authentication logging, the Aadhaar Act, 2016's dedicated grievance and correction mechanisms — that Parliament built for UIDAI's own database. Digital-rights researchers, including Internet Freedom Foundation's analysis of the draft rules, have pressed DoT on exactly this point: why a second biometric repository is necessary at all when Aadhaar's e-KYC already exists, and whether the new subscriber records carry equivalent retention limits, consent standards, and correction rights. Those questions remain open — the notified rules require subscriber data to comply with "applicable data-protection law" without themselves fixing a retention period, deletion trigger, or encryption standard.

The Execution Problem, Not Just the Policy Problem

Even readers sympathetic to stronger SIM-identity checks should be uneasy about the sequencing here. A rule with immediate legal effect, a three-month operational runway, and four re-verification triggers — including one DoT can invoke unilaterally at any time — hands the government a standing lever to compel re-authentication of any subscriber, on any timeline it chooses, without further parliamentary input. PRS's own critique of the parent Act flagged this pattern independently: DoT's rule-making powers under the 2023 Act let the executive reshape core obligations through notification rather than legislation, the same structure now producing a live-face-matching mandate for hundreds of millions of connections with no published retention ceiling.

The Better Version of This Rule

None of this requires abandoning the underlying goal. India could get the fraud-reduction benefit of biometric SIM identification without the proportionality problem by folding the D-KYC repository into the Aadhaar Act's existing safeguards — its purpose-limitation clause, its statutory grievance redress, its audit trail — rather than standing up a parallel database under telecom rules. DoT should also publish the retention period, deletion rule, and breach-notification standard the current text leaves to "applicable law," and Parliament, not DoT alone, should set the boundaries on when the re-verification trigger can be invoked. A three-month compliance clock is a reasonable ask of telcos; it is not a substitute for the safeguards the Supreme Court already told India it needs.

Sources & Citations

  1. DoT eServices Portal
  2. PRS India — Telecommunications Bill, 2023 analysis
  3. MediaNama — DoT Makes Biometric Identification Mandatory for Mobile SIMs
  4. ID Tech — India Mandates Aadhaar Biometric Verification for New Mobile SIM Cards