DPDP Compliance for Telecom Operators: Call Data Records and Retention
Telecom sits between licence conditions that mandate long retention of call records and a statute that expects erasure once purpose is served — here is how to reconcile them.
Call detail records are collected under more than one basis
Call data records — who called whom, when, for how long, from which cell tower — are generated as a byproduct of providing telecom service, and their retention is heavily shaped by longstanding telecom licence conditions around law-enforcement access and network security, independent of anything DPDP itself specifies. That licence-driven retention sits comfortably within the Section 7 legitimate-use ground for compliance with law, meaning a subscriber's consent withdrawal for marketing purposes does not touch the operator's obligation to retain CDRs for the licence-mandated period.
Where CDRs or location data are additionally used for internal purposes — network optimisation analytics, churn prediction, cross-sell targeting — that secondary use needs its own lawful basis and notice, separate from the mandatory retention itself, since a subscriber has not consented to marketing use simply because the record exists for regulatory reasons.
SIM KYC data has its own long paper trail
SIM issuance requires identity and address verification, generating a KYC record that persists for the life of the connection and often beyond, again largely driven by licence and security requirements rather than by ordinary consent. That record includes photographs and identity document copies that deserve strong access controls, given how directly they can be misused for identity fraud if exposed.
Porting a number between operators moves that KYC history along with it, which means the receiving operator becomes a fresh point of accountability for data that originated with a different fiduciary, and the porting process should be explicit about what history transfers and what is discarded.
Law enforcement access sits on the legitimate-use ground
Requests from law enforcement or courts for call records or subscriber data are processed under Section 7's ground for compliance with law or court orders, which does not require the subscriber's consent and, by its nature, is not something the subscriber is notified about in advance. That does not remove the operator's obligation to satisfy itself that a request is validly made through the proper legal channel before disclosing data, since the legitimate-use ground covers lawful process, not any request that merely claims urgency.
Reconciling retention mandates with the erasure duty
Section 8(7)'s erasure-on-purpose-served principle can look, at first glance, to be in tension with licence conditions requiring years of CDR retention — but the resolution is straightforward: where a specific retention period is mandated by law, that mandate itself defines when the purpose is served, and erasure obligations kick in once that mandated window closes, not before. The discipline this requires is operational: an operator needs an actual deletion process at the end of the mandated period, not indefinite retention on the assumption that “we're allowed to keep it that long” quietly becomes “we'll keep it forever.”
Marketing and value-added-service data that rides alongside the core CDR pipeline — call for data top-up offers, personalised plan recommendations — is not covered by the same licence mandate and should be erased on ordinary consent-withdrawal or account-closure timelines, kept clearly separate from the regulatory-retention data set.
Where to go next
The Retention Planner is particularly useful here for drawing a clear line between data held under a mandated regulatory period and data held for ordinary business purposes, since the two need entirely different erasure triggers. The Evidence Tracker can help document that the mandated-period deletion process is actually running, which is the kind of proof a Board inquiry would ask for.