India

DoT Scraps Central Biometric Database Plan After Privacy Concerns, Keeps Other Telecom Checks

By GS Team
22 Aug 20264 mins read
TukuTouch Logo
India's DoT scrapped plans for a central biometric database (BIVS) for telecom users, replacing it with e-KYC and D-KYC. This move, amid privacy concerns, avoids creating a parallel biometric repository. New rules mandate stringent identity verification, including live facial capture, and introduce user alerts for SIM requests. Cross-company checks for suspicious connections remain via the Digital Intelligence Platform, tightening SIM verification while prioritizing data protection.

Summarized by AI; it may make mistakes. Check important info

DoT Scraps Central Biometric Database Plan After Privacy Concerns, Keeps Other Telecom Checks
AI Image

The Department of Telecommunications (DoT) has dropped its plan to create a central biometric database for telecom users, which would have allowed operators to match a customer's identity against records held by other companies. The proposal was initially floated to strengthen verification and curb identity-related fraud, duplicate or suspicious connections, but was removed from the final Telecommunications (User Identification) Rules, 2026 amid concerns over the creation of a parallel repository of sensitive biometric data.

The final rules, notified on August 21, replace the proposed Biometric Identity Verification System (BIVS) with e-KYC and D-KYC-based verification. The DoT has not immediately disclosed its reasons for scrapping the BIVS proposal.

Why Did DoT Propose BIVS?

The BIVS was proposed in the draft Telecommunications (User Identification) Rules, 2025, published on September 19 last year.

The idea was to create a common verification system under which each telecom user could be assigned a unique identity reference. Telecom companies could then check a person's biometric identity against records across the industry rather than relying only on their own subscriber database.

The proposed mechanism would have given the government and authorised telecom entities an additional tool to identify duplicate identities, detect suspicious or fraudulent SIM registrations and strengthen compliance with Section 3(7) of the Telecommunications Act, 2023.

That provision requires entities providing telecommunication services to identify users through verifiable biometric-based identification.

In effect, BIVS was aimed at preventing a person from potentially using different identities or manipulating records across multiple telecom companies, while creating a common framework for biometric verification.

Why Has The Central Database Been Dropped?

The final rules notified on August 21 do not include the BIVS.

While the DoT has not publicly explained why the proposal was dropped, the decision follows criticism over privacy and data-protection concerns surrounding the creation of a new central biometric repository.

In October 2025, the Internet Freedom Foundation (IFF) criticised the proposal, arguing that the system amounted to a parallel collection of biometric information by the DoT in addition to the data already collected through Aadhaar by the UIDAI.

The digital rights organisation also questioned why another central repository was required and raised concerns about the safeguards that would govern the storage and use of biometric information.

Unlike Aadhaar data, which is governed by specific statutory provisions under the Aadhaar Act, 2016, critics had argued that the draft BIVS framework did not clearly spell out comparable protections for the proposed database.

The DoT has been approached for its official reasons behind dropping the BIVS proposal, but no immediate response was available.

e-KYC And D-KYC To Replace Cross-Industry Biometric Matching

The final rules now rely on e-KYC and D-KYC instead of the proposed cross-industry biometric matching system.

For Aadhaar holders, Rule 4 provides for e-KYC through the UIDAI's authentication facility.

For others, D-KYC under Rule 5 may involve capturing a live facial image and electronic images of original identity and address documents. Alternative methods must be provided where a person cannot undergo live facial capture because of impairment, disfigurement or injury.

Additional verification can include field visits or police assistance for checking a user's identity or address.

The rules apply to telecom operators including Airtel, Jio, Vodafone Idea and BSNL. They came into force immediately, although operators have been given three months to establish the required systems, with a possible extension of up to six months.

Government Still Tightens SIM Verification

Dropping the BIVS does not mean the government has abandoned cross-company checks on telecom subscribers.

The DoT has separately introduced a mechanism through its Digital Intelligence Platform to identify people holding more than the permitted number of mobile connections. Subscriber data and photographs from telecom companies will be used to detect possible violations of the prescribed limits.

A person can generally hold up to nine mobile connections nationwide, while the limit is six in Jammu and Kashmir, Assam and the North-East.

Photo-based checks under the separate system are scheduled to begin from August 23.

New Alerts For SIM Requests And Disconnections

The final rules also introduce an alert mechanism under Rule 10.

Users can be alerted when a new connection, SIM-related request, subscriber update or disconnection request is initiated in their name, allowing them to confirm whether they authorised it.

Telecom entities must also report failures of biometric identification to the government.

In another change from the draft rules, biometric identification is now required before a connection is disconnected, extending verification beyond enrolment and subscriber-detail updates.

The final framework therefore takes a different approach: it retains stringent identity checks and cross-company monitoring for suspicious connections, while abandoning the proposal to build a single central biometric database containing telecom users' biometric identities.