Gazette Tracker
Gazette Tracker

Core Purpose

The Central Government hereby makes the Telecommunications (User Identification) Rules, 2026, in exercise of powers conferred by sub-section (1) and clauses (a) and (e) of sub-section (2) of section 56 of the Telecommunications Act, 2023.

Detailed Summary

The Ministry of Communications (Department of Telecommunications) has published G.S.R.750(E) on August 21, 2026, to enact the Telecommunications (User Identification) Rules, 2026, which will come into force on their publication date in the Official Gazette. These rules follow the consideration of objections and suggestions received after the draft Telecommunications (User Identification) Rules, 2025, were published via notification G.S.R. 691(E) on September 19, 2025, with copies made available to the public on September 22, 2025. The 2026 Rules mandate verifiable biometric based identification for users of notified telecommunication services by authorised entities holding specific authorisations or licenses under the Telecommunications Act, 2023 (44 of 2023) or the Indian Telegraph Act, 1885 (13 of 1885). This identification is required prior to enrolment, updating user information (under Rule 6), disconnection (under Rule 9), and for reverification (under Rule 7). The process involves either an e-KYC process for Aadhaar number holders, utilizing the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016), or a D-KYC process for non-Aadhaar holders or those unable to undergo e-KYC. D-KYC necessitates live capture of face, collection of user information, and electronic capture of identity and address documents, with due diligence by the authorised entity. The rules also specify obligations for updating user information, managing changes in users (including for business connections), and procedures for suspension and reverification. Authorised entities must explain user duties and consequences of non-compliance, including penalties under sections 29, 33, and 42(3)(e) of the Telecommunications Act, 2023, and obtain explicit acknowledgements. They must also ensure secure transmission of information, maintain subscriber data records, address grievances, and report instances of false information or impersonation to law enforcement and the Central Government. The Central Government may issue alerts to users regarding service requests and has provisions for digital implementation through designated portals (Rule 11). Authorised entities are required to implement necessary technical and organisational measures within three months, with a possible extension of up to three months.

Full Text

REGD. No. D. L.-33004/99 The Gazette of India CG-DL-E-21082026-275657 No. 684] EXTRAORDINARY PART II—Section 3—Sub-section (i) PUBLISHED BY AUTHORITY NEW DELHI, FRIDAY, AUGUST 21, 2026/SHRAVAN 30, 1948 MINISTRY OF COMMUNICATIONS (Department of Telecommunications) NOTIFICATION New Delhi, the 21st August, 2026 [F. No. 24-09/2025-UBB] DEVENDRA KUMAR RAI, Jt. Secy. G.S.R.750(E). - Whereas, a draft of the Telecommunications (User Identification) Rules, 2025 was published, as required under sub-section (1) of section 56 of the Telecommunications Act, 2023 (44 of 2023), in the Gazette of India, Extraordinary, Part II, section 3, sub-section (i), vide notification number G.S.R. 691(E), dated the 19th September, 2025, inviting objections and suggestions from all persons likely to be affected thereby, before expiry of the period of thirty days from the date on which copies of the Official Gazette containing the said notification were made available to the public; And whereas, copies of the said Official Gazette were made available to the public on the 22nd September, 2025; And whereas, objections and suggestions received in that period in respect of the said draft rules have been considered by the Central Government; Now, therefore, in exercise of the powers conferred by sub-section (1) and clauses (a) and (e) of sub-section (2) of section 56 of the Telecommunications Act, 2023 (44 of 2023), the Central Government hereby makes the following rules, namely:- 1. Short title and commencement.—(1) These rules may be called the Telecommunications (User Identification) Rules, 2026. (2) They shall come into force on the date of their publication in the Official Gazette. 2. Definitions.—(1) In these rules, unless the context otherwise requires, — (a) "Aadhaar number" shall have the same meaning as assigned to it in the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016); (b) "Aadhaar number holder" shall have the same meaning as assigned to it in the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016); (c) "Act" means the Telecommunications Act, 2023 (44 of 2023); (d) "authorised representative”, in relation to a business user, means- (i) the whole-time members of the governing body of such business user to which the management of affairs of such business user is entrusted; or (ii) the chief executive of such business user, who is entrusted with substantial powers of management in respect of the whole of the affairs of that business user; or (iii) any other individual specifically authorised in this behalf by such governing body or chief executive; (e) "biometric information" means the biometrics of a user generated from live capture of face, fingerprint or irises, or of such other biological feature as specified on the portal; (f) "business connection" means one or more telecommunication service connections or subscriber identity modules therefor provided to a business user for its bona fide use; (g) "business user” means a user who- (i) is a legal person constituted under applicable law, and includes a company, partnership firm, limited liability partnership, trust, co-operative society, society, Central Government Department and State Government Department; or (ii) possesses a trade or business license or permit, by whatever name called, issued under applicable law. Explanation. For the purposes of sub-clause (i) of clause (g),— (A) "Central Government Department" means a Ministry, Department, Secretariat or office specified in First Schedule to the Government of India (Allocation of Business) Rules, 1961 and includes an attached office or subordinate office thereof; (B) “co-operative society” means a society registered or deemed to be registered under any law relating to co-operative societies for the time being in force in any State; (C) "limited liability partnership" shall have the same meaning as assigned to it in the Limited Liability Partnership Act, 2008 (6 of 2009); (D) "society" means a society registered under the Societies Registration Act, 1860 (21 of 1860); and (E) “State Government Department" means a Ministry, Department, Secretariat or office- (a) specified in the rules made by the Governor under clause (3) of Article 166 of the Constitution of India, for the allocation of the business of the Government of the State; and (b) a Department of a Union territory Government, and includes an attached office or subordinate office thereof; (F) "trust" means a trust established under the Indian Trust Act, 1882 (2 of 1882) or under any other law for the time being in force. (h) "customer application form", in relation to a user, means the form made available by an authorised entity for such user to furnish information accompanied by supporting documents for enrolment, update of user information or disconnection of any notified service; (i) "D-KYC process" means the process for biometric based identification of a user under rule 5; (j) "e-KYC process" means the process for biometric based identification of a user under rule 4; (k) "end user" of a business connection means the individual who uses, for the purposes permitted by the relevant business user, the subscriber identity module provided to such business user; (l) "live capture" means an image of the face, or a scan of the fingerprints or irises, as the case may be, captured in real-time, using technology capable of verifying that such image or scan is of the user who is physically present; (m) "notified services" means the telecommunication services notified by the Central Government under sub- section (7) of the section 3 of the Act; (n) "portal" means the portal referred to in rule 11; (o) "point of sale" means a person providing point of sale services, who shall be- (i) an authorised entity; or (ii) agent, franchisee or distributor of an authorised entity and shall be a company, partnership firm, sole proprietorship or a person possessing a licence, permit or registration, by whatever name called, to carry on a trade or business, issued under applicable law; or (iii) a person who is employed or engaged otherwise by a person referred to in sub-clause (i) or sub- clause (ii). Explanation. If the point of sale is a person as referred to in sub-clause (iii), such person shall be treated as a distinct point of sale; (p) "point of sale services” means the services relating to one or more of the following, namely:— (i) identification of a user to avail of notified services, including for the purpose of reverification; (ii) enrolment of a user to avail of notified services; (iii) updating of user information; (iv) distribution of subscriber identity module or user terminals; (v) recharge and other billing activities in respect of notified services; and (vi) disconnection of notified services of a user; (q) "relative" shall have the same meaning as assigned to it in the Telecommunications (Authorisation for Provision of Principal Telecommunication Services) Rules, 2026; (r) "subscriber identity module" means a module, by whatever name called, available in any form factor, used to store in a secure manner a unique telecommunication identifier assigned to a user by the authorised entity and the related authentication keys to uniquely identify and authenticate such user on the telecommunication network, and includes a pluggable subscriber identity module, embedded subscriber identity module (e-SIM), integrated subscriber identity module (iSIM), virtual subscriber identity module or any other equivalent subscriber identity module; (s) "subscriber data record", in relation to an authorised entity, means a comprehensive repository of the information specified in clause (b) of sub-rule (2) of rule 4, sub-rule (2) of rule 5, sub-rule (6) of rule 6, sub- rule (2) of rule 8 and sub-rule (2) of rule 9; and (t) "user information", in relation to a user, means the name, gender, date of birth, live capture of face and such other information of such user as specified on the portal. (2) Words and expressions used in these rules and not defined herein but defined in the Act or the rules made thereunder shall have the meanings respectively assigned to them in the Act or the said rules. 3. Application.—(1) These rules shall apply to verifiable biometric based identification of users of notified services by any authorised entity- (a) who holds an authorisation under clause (a) of sub-section (1) of section 3 of the Act; (b) who holds a license granted under section 4 of the Indian Telegraph Act, 1885 (13 of 1885) for provision of telecommunication services in respect of which the licensee has exercised its right under sub-section (6) of section 3 of the Act to operate under the terms and conditions of such license; or (c) who has migrated to the terms and conditions of the authorisation, under sub-section (6) of section 3 of the Act. (2) The authorised entity shall undertake biometric based identification of a user, including of a business user, in accordance with the process specified under sub-rules (3) and (4), in the following circumstances, namely:— (a) Prior to enrolment of a user for a telecommunication service connection or subscriber identity module therefor; (b) Prior to updating of user information under rule 6; (c) Prior to disconnection under rule 9; (d) Pursuant to direction for reverification under rule 7. (3) The authorised entity shall undertake the following process for biometric based identification of a user under sub- rule (2), namely:- (a) e-KYC process, in respect of a user who is an Aadhaar number holder; or (b) D-KYC process, in respect of a user who is not an Aadhaar number holder or is an Aadhaar number holder but is unable to undergo e-KYC process due to inability to authenticate live capture of face, fingerprints and irises due to reasons such as impairment, disfigurement, injury or amputation. (4) If the user is a business user seeking a business connection, the authorised entity shall undertake biometric based identification of the authorised representative of such business user, and of each end user of such business connection, if any, in accordance with this rule: Provided that the Central Government or its officer authorised in this behalf may, on being satisfied that it is necessary or expedient so to do, exempt an authorised entity from undertaking biometric based identification of an end user or a class of end users, while recording the reasons in writing. (5) Adherence to these rules shall be one of the terms and conditions of authorisation or license held by the authorised entity referred to in sub-rule (1). Explanation. For the removal of doubts, it is clarified that any failure on the part of an authorised entity to adhere to these rules shall constitute breach of the terms and conditions of its authorisation or license, as the case may be. 4. Identification of user through e-KYC process.—(1) An authorised entity shall undertake e-KYC process for identification of a user as referred to in clause (a) of sub-rule (3) of rule 3 in the manner specified under this rule. (2) The authorised entity shall, in accordance with the orders, directions, instructions and guidelines issued by the Central Government from time to time,- (a) undertake the e-KYC process for the purposes of authentication of information of such user using the e-KYC authentication facility; and (b) store and process the following details in the customer application form and subscriber data record, namely:- (i) e-KYC data, including Aadhaar number, as received from the Unique Identification Authority of India established under the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016); and (ii) User information. Explanation. For the purposes of this rule, the expressions “e-KYC authentication facility” and “e-KYC data" shall have the same meanings as assigned to them in the regulations made regarding the procedure for authentication under the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (18 of 2016). 5. Identification of user through D-KYC process.—(1) An authorised entity shall undertake the D-KYC process for identification of a user as referred to in clause (b) of sub-rule (3) of rule 3 in the manner specified under this rule. (2) The authorised entity shall undertake the D-KYC process in accordance with the orders, directions, instructions and guidelines issued by the Central Government from time to time and shall- (a) determine the class of users specified in clause (b) of sub-rule (3) of rule 3 to which the user belongs, and shall record the same in the customer application form and subscriber data record; (b) check against information contained in its subscriber data record whether such user has previously undergone e-KYC process, and if so, shall obtain from such user an undertaking that he is no longer an Aadhaar number holder or is unable to undergo e-KYC process due to inability as referred to in clause (b) of sub-rule (3) of rule 3; (c) undertake live capture of face along with collection of user information and other information as specified on the portal; (d) capture electronically the image of the original of one or more documents as specified on the portal, to be presented by the user to evidence proof of identity and proof of address; (e) store the information captured under this sub-rule in the customer application form and subscriber data record and process the same, in accordance with orders, directions, instructions and guidelines issued by the Central Government; (f) undertake due diligence to— (i) satisfy itself regarding the claims relating to identity and address of the user; (ii) verify that— (A) the live capture of face referred to in clause (c) matches the face of the user; (B) the image of documents referred to in clause (d) matches the original documents presented by the user; and (C) the live capture of face matches the image of the face that is contained in the documents referred to in clause (d); and (iii) check against information in its subscriber data record as to whether the user had previously obtained any telecommunication service connection, and if so, undertake verification of the user information captured under this sub-rule with such information in its subscriber data record; and (g) adhere to such orders, directions, instructions and guidelines as specified on the portal under these rules, including in respect of electronically verifying the information presented by or captured from the user under this sub-rule with the databases of the authorities dealing with the preparation or maintenance of such documents. (3) If a user is unable to undergo live capture of face due to reasons such as impairment, disfigurement or injury, the authorised entity shall offer him an accessible alternative to provide other biometric information, and the provisions of sub-rule (2) shall apply mutatis mutandis in respect of the same. (4) The authorised entity may, regarding any claim relating to identity or address of the user under clauses (d) or (f) of sub-rule (2), carry out checking through a field visit or take assistance of the police for verification or both. 6. Updating of user information.—(1) Each authorised entity shall, in addition to the other obligations under these rules, undertake, in accordance with rule 3, biometric based identification of the user— (a) if he seeks to replace a subscriber identity module; or (b) if he seeks to change his name, gender or date of birth; or (c) if there is change of user under sub-rules (3) or (4). (2) The authorised entity shall, in addition to the biometric based identification pursuant to sub-rule (1), also undertake due diligence to— (a) satisfy itself regarding the claims relating to user information, including identity of the user; and (b) check whether the user information captured for biometric based identification matches with the user information corresponding to such user in its subscriber data record. (3) Any change in the user of a telecommunication service connection or subscriber identity module therefor (hereinafter referred to as “existing user”) may be done only in respect of relatives or legal heirs of such user, or any other class of users as specified on the portal (hereinafter referred to as "new user"), on a request made by the existing user or new user, subject to the following, namely:— (a) the provision of telecommunication service connection or subscriber identity module therefor to the new user being treated as a new telecommunication service connection; and (b) fulfilment of the following conditions, namely:- (i) submission of no objection certificate from the existing user and biometric based identification of both the existing user and the new user in accordance with rule 3: Provided that in case the existing user is unable to fulfil any requirement under this clause due to his incapacity, in lieu of such requirement, a medical certificate shall be submitted to evidence such incapacity; or (ii) in case the existing user is deceased, submission of his death certificate and biometric based identification of the new user in accordance with rule 3: Provided that the Central Government or its officer authorised in this behalf may, on being satisfied that it is necessary or expedient so to do, exempt or relax any condition under this sub-rule in respect of a user or class of users, while recording the reasons in writing. (4) In case of a business connection, the authorised entity shall explain in clear and explicit manner to the authorised representative of the business user concerned that if there is any change in end user of such business connection, such representative shall ensure the following, namely:— (a) the authorised representative of the business user shall have the obligation to intimate such change to the authorised entity within such period specified in this behalf on the portal; and (b) the authorised representative of the business user shall have the obligation to ensure that the new end user undergoes biometric based identification within the period specified in this behalf on the portal, failing which such business connection shall be suspended by the authorised entity, till the successful undergoing of biometric based identification by such new end user: Provided that nothing in this sub-rule shall apply in respect of any end user or class of end users exempt under the proviso to sub-rule (4) of rule 3. (5) The authorised entity may, in respect of any information given or document submitted under this rule, carry out checking through a field visit or take assistance of the police for verification or both. (6) The authorised entity shall update in its subscriber data record all changes made under this rule to user information, while maintaining the old and new information along with time stamp. 7. Suspension and reverification.—(1) If it comes to the notice of the Central Government that an authorised entity has provided any telecommunication service connection or subscriber identity module therefor to a user in violation of these rules, the Central Government may direct such authorised entity to suspend forthwith such connection or module and undertake biometric based identification of such user afresh, in accordance with rule 3 within such period of time as may be specified by the Central Government, failing which, the Central Government may direct the authorised entity to disconnect such telecommunication service connection or subscriber identity module therefor: Provided that any action taken under this rule shall be without prejudice to any proceedings against the authorised entity or user or both under relevant provisions of the Act. (2) An authorised entity shall undertake reverification through biometric based identification of a user in accordance with rule 3 where so required pursuant to orders, directions, instructions or guidelines issued by the Central Government for the purposes of ensuring proper and bona fide use of telecommunication service connection or subscriber identity module therefor. 8. Additional obligations of authorised entities.—(1) Every authorised entity shall explain to each of its users, in clear and explicit manner, the following, namely:- (a) the duty and obligation of the user to- (i) provide correct information for establishing his identity at the time of biometric based identification under these rules; and (ii) ensure compliance with clause (a) of section 29 of the Act and not provide false, incorrect, or forged information or documents, or suppress any material information, or impersonate, while establishing his identity; and (iii) not resell or transfer or lease his telecommunication service connection or subscriber identity module therefor to any other user, save for a transfer pursuant to sub-rules (3) or (4) of rule 6 or any other rule made under the Act; and (b) the consequences of the user not adhering to his duties and obligations, including in terms of the provisions of- (i) section 33 of the Act, for furnishing of any false particulars, suppression of any material information, or impersonation of another person, while establishing his identity for availing of telecommunication services; and (ii) clause (e) of sub-section (3) of section 42 of the Act, for the offence of obtaining of subscriber identity modules or other telecommunication identifiers through fraud, cheating or personation. (2) Every authorised entity shall also explain to each of its users, in clear and explicit manner, his duty and obligation to- (a) ensure bona fide use of notified services, and the consequences of misuse of such notified services as per applicable law; (b) forthwith provide information to the authorised entity of any change in the address of such user, accompanied by a document evidencing the new address; and (c) forthwith provide information to the authorised entity of any change to his user information, to ensure the accuracy and integrity of information in such authorised entity's databases, including in its subscriber data record: Provided that the authorised entity shall duly update information provided by the user under clauses (b) and (c) in its subscriber data record, while maintaining the old and new information along with time stamp. (3) Every authorised entity shall obtain an explicit acknowledgement from each user in respect of sub-rules (1) and (2). (4) Every authorised entity shall ensure the following, namely:- (a) if the user information or biometric information is collected by or presented to its points of sale pursuant to these rules, such information is transmitted in a secure manner to the relevant systems of the authorised entity, and no such information shall be stored in physical or electronic form by its points of sale; (b) the obligations in respect of point of sale under the Telecommunications (Authorisation for Provision of Principal Telecommunication Services) Rules, 2026 are adhered to by its points of sale; and (c) the subscriber data record is operated and maintained while adhering to applicable law, including law relating to data protection and security. (5) Every authorised entity shall address any grievance relating to biometric based identification through the mechanism for redressal of grievances established by it. (6) If it comes to the notice of the authorised entity that false, incorrect or forged information or document was presented or used, or any material information was suppressed or impersonation was done, in the course of biometric based identification of a user, such authorised entity shall- (a) inform the police or relevant law enforcement agency for registration of a first information report, with requisite details, including details of such information, document or impersonation; and (b) inform the Central Government, in the form and manner specified in this behalf on the portal, the steps taken pursuant to clause (a). (7) If it comes to the notice of the Central Government that the authorised entity has failed to take action under sub- rule (6), the Central Government may direct such authorised entity to inform the police or relevant law enforcement agency for registration of a first information report and may also initiate action against that authorised entity under Chapter VIII of the Act or under the terms and conditions of the license, as the case may be. 9. Disconnection at request of user.—(1) A user may seek disconnection of subscribed telecommunication service connection or subscriber identity module therefor: Provided that while accepting the request of the user for disconnection of subscribed telecommunication service connection or subscriber identity module therefor, the authorised entity shall- (a) undertake biometric based identification of such user in accordance with rule 3; and (b) undertake due diligence to— (i) satisfy itself regarding the claims relating to user information, including identity of the user; and (ii) check whether the user information captured for biometric based identification matches with the user information corresponding to such user in its subscriber data record. (2) Every authorised entity shall update the relevant fields in its subscriber data record pursuant to any disconnection of telecommunication service connection or subscriber identity module therefor, while maintaining the old and new information along with time stamp. 10. Miscellaneous.—(1) The Central Government may, by order or through instructions, directions or guidelines, require that every authorised entity that undertakes biometric based identification of a user under these rules, shall send to him an alert specifying, among other relevant details, the telecommunication service connection concerned or the subscriber identity module therefor, through each of his existing telecommunication service connections or subscriber identity modules therefor, seeking confirmation from him that he is the user who had made the request in respect of such connection or module. (2) If the response of the user to the alert under sub-rule (1) is in the negative, the authorised entity shall forthwith and till it has ascertained relevant facts and taken appropriate action for closure, take the following measures, namely:- (a) in case the alert was sent in connection with enrolment of a user for a telecommunication service connection or subscriber identity module therefor, suspend the telecommunication service connection concerned and the subscriber identity module therefor; (b) in case the alert was sent in connection with biometric based identification under sub-rule (1) of rule 6,- (i) under clause (a) thereof, suspend the subscriber identity module concerned; (ii) under clause (b) or clause (c) thereof, restore the user information in the subscriber data record if it has been updated or changed, or otherwise keep in abeyance update or change of the same; and (c) in case the alert was sent in connection with biometric based identification under rule 9, restore the telecommunication service connection or subscriber identity module therefor if it has been disconnected, or otherwise keep in abeyance the request for such disconnection. (3) The Central Government may, for the purposes of giving effect to these rules, issue orders, directions, instructions or guidelines not inconsistent with the Act or these rules, including in respect of (a) storage and maintenance of user information by authorised entities, individually or collectively, in a confidential, secure, non-repudiable and immutable manner; and (b) performance of functions and actions by authorised entities to ensure that user information is identifiable, distinguishable and recordable. (4) Every authorised entity shall implement appropriate technical and organisational measures for providing necessary assistance to its users while undertaking biometric based identification in accordance with these rules. (5) An authorised entity shall, when called upon to do so by the Central Government or any agency authorised by in this behalf, provide such information regarding implementation of these rules, including in respect of any instance of failure of biometric based identification undertaken under these rules as the Central Government or such agency may specify. (6) Every authorised entity shall, within a period of three months from the date of coming into force of these rules, take appropriate technical and organisational measures, and establish necessary infrastructure for effective observance of these rules: Provided that the Central Government may, after assessing the state of preparedness of the authorised entities for implementation of such measures, if it considers it necessary in public interest, extend the said period for a further period not exceeding three months. 11. Digital implementation.—The Central Government may, in furtherance of section 53 of the Act, notify one or more portals for digital implementation of these rules, including for providing any form, list of proof of identity and proof of address documents, manner, order, direction, instruction or guideline to be specified under these rules. Uploaded by Dte. of Printing at Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054.

Never miss important gazettes

Create a free account to save gazettes, add notes, and get email alerts for keywords you care about.

Sign Up Free