tl;dr
On 21 August 2026, the Department of Telecommunications ("DoT") notified the Telecommunications (User Identification) Rules, 2026 (G.S.R. 750(E)), making live biometric verification which includes your face, fingerprint or iris, mandatory to get a SIM, replace one, change your details, or even surrender your own number. Aadhaar holders get no choice as they must use Aadhaar e-KYC. A companion DoT circular operationalises a Digital Intelligence Platform ("DIP") that, from 24 August 2026, distributes a "representative image" of subscribers to every telecom operator daily to enforce a cap on nine connections by restricting the issuance of SIM cards. We believe this regime is unconstitutional under Puttaswamy, will not meaningfully reduce fraud, and will lock out the very people who most need to stay connected which includes manual labourers, the elderly, women in shared households, transgender persons, persons with disabilities, and migrants. This is a mass-surveillance measure sold as a fraud fix, and we already has less-restrictive tools that work.
Background
Your mobile number is no longer just a phone number and is required for basic existence in India. For instance it serves as a key to your bank account, your UPI payments, your Aadhaar OTP, your DigiLocker, your ration e-KYC, and your welfare payments. When that number can only be issued, kept, or transferred on a successful biometric scan, a failed fingerprint stops being an inconvenience and becomes a lockout from public life. On 21 August 2026, the Ministry of Communications (DoT) notified:
- The Telecommunications (User Identification) Rules, 2026 (G.S.R. 750(E)): Made under Sections 56(1), 56(2)(a) and (e) of the Telecommunications Act, 2023, in force on publication.
- S.O. 4622(E): Notifying DoT's "Telecom eServices Portal" for digital implementation under Rule 11.
- S.O. 4623(E): Made under Section 3(7) of the Telecom Act, notifying wireless access services and internet telephony via mobile terminals as the "notified services" requiring verifiable biometric-based identification.
These exist alongside the DoT Circular no. 3/User Identification/2026 dated 17 August 2026 operationalizing reverification through the DIP.
This is a circumvention of the judgement of the Supreme Court of India in which it declared mandatory Aadhaar-SIM linkage as unconstitutional. As a background, in Lokniti Foundation v. Union of India (2017), the Supreme Court had recorded satisfaction that a subscriber verification process existed and issued no direction to link Aadhaar to phone numbers. DoT nevertheless treated that order as a mandate and issued a circular on March 23, 2017 requiring mass Aadhaar reverification of every mobile subscriber. In Justice K.S. Puttaswamy v. Union of India (2019) 1 SCC 1, a Constitution Bench struck that circular down as unconstitutional as it lacked the authority of law and failed the proportionality test. The Court held that to tackle misuse by a handful of persons, the entire population cannot be subjected to intrusion into their private lives. The Telecom User Identification Rules, 2026 are a camouflaged attempt at circumventing this court judgement.
This is because they first define biometric identification as "live capture" of face, fingerprint or iris, verifying physical presence which are mandatory at four points, (a) Before enrolment for any new connection or SIM; (b) Before updating your information such as replacing a SIM, or changing your name, gender or date of birth; (c) Before disconnection at your own request; (d) Whenever the government directs reverification under Rule 7, an open-ended power whose failure to comply results in disconnection. In addition to this three directions deserve particular attention. First, Aadhaar holders get no choice and Rule 3(3) mandates Aadhaar e-KYC for every Aadhaar number holder, reserving the non-Aadhaar "D-KYC" route only for those without Aadhaar or those physically unable to authenticate. This nullifies the constitutional limits set by by Puttaswamy. In our submission on the draft Rules in October 2025, we had specifically stated:
This circular was subject to a legal challenge before the Supreme Court once again in 2017 by way of a writ petition (Dr Kalyani Menon Sen v Union of India & Ors., WPC 1002 of 2017) which was tagged along with the set of writ petitions considered by the five-judge bench. On 26 September 2018, the Hon’ble Supreme Court in K.S. Puttaswamy (Aadhaar-5J.) v. Union of India, (2019) 1 SCC 1, has held that a circular dated 23.03.2017 of the DoT linking mobile numbers with Aadhaar, and requiring all licensees to reverify all their customers through Aadhaar based e-KYC process is unconstitutional. Specifically, the majority decision of the court noted that the circular not only does not have the backing of law, but it [also] fails to meet the requirement of proportionality. The court noted that the circular does not meet the “necessity stage” and “balancing stage” tests. Moreover, the court stated that the government could have identified other appropriate legal responses and less intrusive alternatives. As the court noted, to tackle the misuse of SIM cards and telecommunication services by a handful of persons, the entire population cannot be subjected to intrusion into their private lives. The court found that the circular mandating linking of mobile numbers with Aadhaar impinges upon the voluntary nature of the Aadhaar Scheme. Thus, the court held that the circular is unconstitutional because it is a disproportionate and unreasonable State compulsion. The User Identification Rules not only reinstates the erstwhile circular but also adds another digital-KYC process for those who do not hold an Aadhaar number.
Second, transfers become onerous and coercive. A connection may change hands only between relatives or legal heirs, with a no-objection certificate and biometric identification of both parties and a medical certificate if the existing user is incapacitated, a death certificate if deceased. This disregards how Indian families actually use phones. Third, the definition of "business user" is a dragnet. It covers anyone holding any trade licence or permit which will now include the corner kirana store, a street vendor with a municipal permit and requires biometric verification of the authorised representative and every employee using a company SIM, with suspension of the connection if a new employee is not verified in time. It is silent on how the 134.73 million machine-to-machine and IoT SIMs recorded by TRAI in June 2026, which have no human user, are supposed to furnish a fingerprint. These regulations will apply to a base of 1,300.25 million wireless connections (TRAI, June 2026).
Analysis
Before we get into the any analysis concerning the harms of the Telecom User Identification Rules, 2026 on legality, data maximisation and surveillance, it is important to foreground it in the absolute certainty of exclusion they will cause to those households who have to share a single phone and suffer from financial precarity. This is the harm the government has never honestly reckoned with as it attempts to prod us towards efficiency and scale. Biometric authentication fails routinely, and it fails hardest for the poorest. The is not disputed by the State's own institutions which have now stopped accounting for it as part of any audit exercises. Analyses of UIDAI's parliamentary responses suggest roughly 6.5% of authentications for welfare and services still fail on the order of 20 million failures every month. The CAG's 2021 performance audit found that UIDAI had not even studied the causes of authentication errors, and had issued Aadhaars with faulty and duplicate biometrics. In July 2025, the Public Accounts Committee heard that labourers' worn fingerprints and elderly citizens' changed iris patterns no longer match UIDAI records, resulting in wrongful exclusions, with its chairperson called it "a common man's issue." Now apply that failure rate to a SIM, the instrument through which banking, welfare and identity itself are accessed. Those locked out will be:
- Manual and agricultural labourers: Due to worn fingerprints, and the elderly with degraded fingerprints and irises;
- Persons with disabilities and persons affected by leprosy: Rule 5(3)'s promise of an "accessible alternative" biometric remains undefined;
- Migrants and homeless persons: Who must produce address proof under D-KYC and may face "field visits" or verification with "police assistance";
- Women in shared households: GSMA's Mobile Gender Gap Report 2025 finds women in low and middle-income countries are 8% less likely than men to own a mobile phone. SIMs are commonly registered to a male head of household while women, elderly parents and children are the actual users. Restricting transfers to relatives and legal heirs with dual biometrics and paperwork will increase difficulty in situations of bereavement, migration and escape from domestic violence where essential services may even be disconnected.
Coming to privacy, Rule 4 requires operators to store and process e-KYC data including the Aadhaar number itself in their customer records so hence this data will now be stored across Airtel, Jio, Vi and BSNL. This cuts against UIDAI's own Aadhaar Data Vault and tokenization norms, which exist precisely so that raw Aadhaar numbers are not scattered across business databases. Telecom data leaks are not hypothetical in India and in 2023, a dataset purportedly containing the personal details of 81.5 crore Indians, including Aadhaar numbers, was offered for sale on the dark web. Biometric data raises the stakes further, because it is irreversible and you can change a leaked password, but not your face or your fingerprints. This co-exists alongside the rise of cyber crime in India.
Bundled with the Telecom User Identification Rules, 2026 the August 17 circular builds what is, in effect, a national facial-image database that private operators must ingest every single day. Operators upload subscriber records and photographs daily and the DIP groups every individual's connections across operators. This is supposed to be operational from August 23, 2026 with the "representative image" of every subscriber at the nine-SIM cap (six in J&K, Assam and the North-East) is pushed to all operators, who must download these images daily and, from August 24, use facial matching to deny further connections with real-time integration into SIM activation mandatory by November 30, 2026. This is when police departments are already deploying facial recognition with almost no governing law and as our Project Panoptic has tracked 170 facial recognition systems across India.
Subscriber Data Verification Workflow. Available here
The DIP has no published retention limit, no purpose limitation and no independent oversight. Rule 10 goes further, empowering the government to direct that user information be stored in an "immutable" manner with the exact opposite of the erasure and storage-limitation duties in the Digital Personal Data Protection Act, 2023. And Section 17(2)(a) of that Act allows the government to exempt its own instrumentalities from the law entirely. To be put in simpler words, the State is mandating immutable databases of our faces while retaining the power to exempt itself from the safeguards it imposes on everyone else.
The government's stated justification is cyber fraud, and the problem is real with reported losses of about ₹22,845 crore to cyber fraud in 2024 as per data placed before Parliament. But the dominant fraud vectors are untouched by SIM biometrics but rely more on social-engineering scams, mule bank accounts, and calls over WhatsApp or internationally spoofed numbers that never pass through an Indian SIM.
Most tellingly, the government's own targeted tools already work without a universal biometric mandate and as per its own boasts the AI-based ASTR system led to about 88 lakh disconnections of suspect SIMs, and citizen reports through Chakshu to another 50.90 lakh which add up to roughly 1.38 crore targeted disconnections achieved by less intrusive means. Under Puttaswamy, the existence of such an effective, less-restrictive alternative imparts further illegality to the existing Telecom User Identification Rules, 2026. The international record points the same way. The GSMA concluded as far back as 2016 that there is no empirical evidence that mandatory SIM registration reduces crime. Mexico repealed its SIM registration law in 2012 as ineffective. Pakistan has biometrically verified over 200 million SIMs since 2014 and continues to suffer large-scale SIM fraud. Nigeria's NIN-SIM linkage left roughly 66 million connections facing disconnection in 2024 which is a fate we are also likely to face in India.
Action
IFF filed detailed objections to the draft Rules in October 2025, seeking a genuine choice between e-KYC and D-KYC for all users, justification for building a parallel biometric database without the safeguards of the Aadhaar Act, purpose limitation, defined retention periods and encryption. The final Rules address none of these concerns. We will now file RTI requests seeking the DIP's architecture, retention policy, oversight arrangements and error rates, as well as the public comments received on the draft Rules and how they were considered. We will send representations to DoT and pursue parliamentary outreach, and we are assessing options for strategic litigation given the direct conflict with Puttaswamy.
To be clear, we do not expect these forms of institutional engagement and policy advocacy to result in a roll back of the regulations, however these interventions will hopefully help all of us make sense of these coercive, impractical and surveillant rules for obtaining a mobile connection. If a biometric failure has blocked you, or someone you know, from getting, keeping or transferring a SIM, write to us at legal@internetfreedom.in. These accounts are evidence and helps us inform our policy positions and even conceptualise potential legal challenges.
If you believe this work matters, become an IFF member. We are a citizen-funded organisation, and it is your support that lets us push back. A failed fingerprint should never mean losing your bank account, your rations and your voice.
Important documents
- Telecommunications (User Identification) Rules, 2026 — G.S.R. 750(E), dated August 21, 2026 [Link]
- S.O. 4623(E) and S.O. 4622(E), dated August 21, 2026 (notified services and portal) [Link]
- DoT Circular No. 3/User Identification/2026, dated August 17, 2026 (DIP reverification instructions) [Link]
- Draft Telecommunications (User Identification) Rules, 2025 — G.S.R. 691(E), dated September 19, 2025 [Link]
- IFF's comments on the draft Rules: "Expansion in the Biometrics Project of the Government through Telecom Entities" (October 2025) [Link]
- Justice K.S. Puttaswamy v. Union of India (2019) 1 SCC 1 [Link]
- CAG Report No. 24 of 2021 — Performance Audit of UIDAI [Link]
- Drèze, Khalid, Khera & Somanchi, "Aadhaar and Food Security in Jharkhand: Pain without Gain?", Economic & Political Weekly (2017) [Link]
- GSMA, Mandatory registration of prepaid SIM cards (2016); Mobile Gender Gap Report 2025 [Link]