India’s 2026 Biometric SIM Rules, Explained

India's Telecommunications (User Identification) Rules, 2026 create a biometric user-identification process for mobile connections. The final rules reach every SIM form factor, including eSIMs, iSIMs and virtual SIMs, used for the notified wireless access and mobile internet telephony services. They require identification at four defined events, not continuous biometric checking. Final rules, retrieved 25 August 2026.

Two nearby systems need to stay separate. A named cross-operator Biometric Identity Verification System, or BIVS, appeared in the 2025 draft but was removed before notification. A 17 August 2026 Department of Telecommunications circular separately directs operators to use the Digital Intelligence Platform, or DIP, to enforce existing limits on how many mobile connections a person may hold. Draft rules, retrieved 25 August 2026; DIP circular, retrieved 25 August 2026.

Final rules commenced
21 AUG 2026
https://egazette.gov.in/WriteReadData/2026/275657.pdf | Rule 1(2) | Retrieved 25 August 2026
Identification events
4
https://egazette.gov.in/WriteReadData/2026/275657.pdf | Rules 3, 6, 7 and 9
Infrastructure window
3 MONTHS
https://egazette.gov.in/WriteReadData/2026/275657.pdf | Rule 10(6)
Possible extension
UP TO 3 MONTHS
https://egazette.gov.in/WriteReadData/2026/275657.pdf | Rule 10(6) proviso

DRAFT LANGUAGE IS NOT FINAL LAW
The 2025 draft is useful for identifying what changed. Its BIVS architecture, unique cross-operator user ID, periodic reverification clause and draft-specific triggers are not operative requirements. The final Gazette text controls. Draft; final rules.

At a glance

Draft BIVS, final rules and DIP are three different systems. The final rules omit the draft named BIVS and instead retain per-operator records; the DIP representative-image check is a separate connection-cap direction.

Three-column comparison separating India’s unenacted 2025 draft BIVS, the final 2026 per-operator SIM identity rules, and the separate DIP connection-cap circular.
Draft BIVS, final rules and DIP are three different systemsCunicula
Data behind this diagram
India SIM identity instruments and implementation boundaries
India SIM identity instruments and implementation boundaries
InstrumentRecord or systemBiometric functionStatus
2025 draft rulesNamed BIVS with a unique cross-operator user IDProposed real-time biometric verification and information exchangeNot enacted in this form
2026 final rulesPer-operator customer application form and subscriber data recordIdentification at four defined account eventsIn force from 21 August 2026
17 August 2026 DIP circularDIP grouping for existing mobile-connection-cap enforcementRepresentative-image check during enrolment for people at the capSeparate direction with a 30 November real-time target

Three instruments, three different functions

Draft BIVS, final user-identification rules and separate DIP circular
Draft BIVS, final user-identification rules and separate DIP circular
InstrumentRecord or systemBiometric functionCurrent status
2025 draft rulesNamed BIVS with a unique user ID and cross-operator user informationProposed real-time biometric identity verification and information exchangeNot enacted in this form
2026 final rulesEach operator keeps its own customer application form and subscriber data record; later storage orders remain possibleIdentification at enrolment, specified updates, user-requested disconnection and directed reverificationIn force from 21 August 2026; infrastructure window applies
17 August 2026 DIP circularDIP groups subscriber records across operators and service areas for connection-cap enforcementRepresentative images are supplied for people already at the connection cap and checked during enrolmentSeparate direction; daily exchange first, real-time target by 30 November 2026

The four final-rule identification events

  1. New enrolment. Before a new connection or SIM is issued, the operator must identify the user through electronic KYC or the permitted digital KYC route. Rules 3 to 5, retrieved 25 August 2026.
  2. Specified updates. A replacement SIM, a change to name, gender or date of birth, and a change of user each trigger the procedures in Rule 6. User transfers are limited to specified relatives, legal heirs and any later portal-defined class. Business connections require the new end user to complete biometric identification within the portal's time limit. Rule 6, retrieved 25 August 2026.
  3. User-requested disconnection. The user's biometric identity and other due-diligence information must match the operator's subscriber data record before disconnection. Rule 9, retrieved 25 August 2026.
  4. Directed reverification. If the government finds that an operator provided a connection in violation of these rules, it may order the connection suspended and require fresh identification. Operators must also reverify when required by government orders for proper and bona fide use. Failure to complete an ordered fresh identification within the specified period can lead to a government direction to disconnect. Rule 7, retrieved 25 August 2026.

The final text does not retain the draft's separate periodic-reverification provision. It also drops the draft's express mobile-number-porting and prepaid-to-postpaid triggers. A carrier may still have obligations under other instruments, but those events are not listed as standalone triggers in these final rules. Draft Rules 9 and 12; final Rules 3, 6, 7 and 9.

e-KYC, D-KYC and accessibility

For an Aadhaar holder, e-KYC is the required route unless the narrow inability exception applies. The person authenticates through a live face, fingerprint or iris check as directed by the government, and the operator receives e-KYC data from UIDAI. The operator stores and processes that data, including the Aadhaar number, in the customer application form and the subscriber data record, together with the user's name, gender, date of birth, live facial image and any portal-specified data. Rules 2, 3 and 4, retrieved 25 August 2026.

D-KYC is available to a person without Aadhaar and to an Aadhaar holder who cannot complete live face, fingerprint or iris authentication because of impairment, disfigurement, injury or amputation. The operator captures a live facial image and electronic images of original identity and address documents, checks that the live image matches both the person and the photograph in those documents, and records which D-KYC category applies. If live face capture itself is not possible for the specified physical reasons, the operator must use an accessible alternative based on other available biometric information. The rules also require technical and organisational assistance to make the process accessible. Rules 3(3), 5 and 10(4), retrieved 25 August 2026.

The final rules do not say that every user must supply face, fingerprints and iris together. They define alternative biometric authentication modes and a narrower D-KYC exception. The actual user-facing flow can also depend on later government directions and portal implementation. Final Rules 3 to 5.

What operators store and what the point of sale cannot keep

The operator's subscriber data record is a named record in the final rules. It links the enrolled user to the mobile connection and stores the information created at enrolment and later updates, with timestamps. Under e-KYC this includes the live facial image and other defined user information. Under D-KYC it includes captured document images and verification data. Rules 2, 4, 5 and 6, retrieved 25 August 2026.

If user information or biometric information is collected by or presented to a point of sale, the operator must ensure it is transmitted securely to the operator's own systems and that the point of sale stores none of it in physical or electronic form. Operators must follow applicable data-protection and security law, but the rules do not state a specific retention period for these records. Rule 8(4), retrieved 25 August 2026.

Rule 10 also lets the government issue later orders for individual or collective storage in a secure, confidential, non-repudiable and immutable manner. That is an enabling power. It does not itself establish the named BIVS from the draft or reproduce the draft's unique cross-operator user ID. Rule 10(3), retrieved 25 August 2026; draft Rule 6, retrieved 25 August 2026.

Confirmation alerts can pause or reverse account actions

The final rules define confirmation alerts, but they operate when a government order specifies the process. After a biometric identification, the operator sends an alert through each of the user's existing connections asking the user to confirm that the enrolment, update or disconnection request was really made by that user. A negative response can suspend the new connection, suspend a replacement SIM, restore previous subscriber details, hold an update, or reverse or hold a requested disconnection. Rule 10, retrieved 25 August 2026.

The portal is the DoT's Telecom eServices Portal, notified under final Rule 11 for digital implementation of these rules. A separate 21 August 2026 order notifies wireless access services and internet telephony through mobile user terminals as the services subject to these identification measures. Those two notifications set the portal and the service scope; neither is the Digital Intelligence Platform. S.O. 4622(E), portal notification; S.O. 4623(E), notified-services order.

The separate DIP connection-cap process

The DoT circular concerns an existing cap on mobile connections: nine per person in most of India and six in Jammu and Kashmir, Assam and the North East service areas. It says operators upload subscriber data records to DIP, where records are grouped across operators and service areas on a best-effort basis. DIP circular, retrieved 25 August 2026.

From 23 August 2026, the circular says DIP makes representative images available for subscribers already at the cap. Operators must download the data daily. From 24 August they must use the representative image during new enrolment to detect a person applying beyond the cap and deny the connection. The circular allows a temporary next-day process and sets 30 November 2026 as the real-time target. During that temporary process, a connection activated beyond the cap for a day must be suspended until the issue is resolved. Circular paragraph 2(iii) and 2(iv), retrieved 25 August 2026.

The circular does not publish a face-matching algorithm, confidence threshold, image-retention period or appeal procedure. It should therefore be described as a representative-image check, not as a fully specified facial-recognition system. It is also not evidence that the draft BIVS architecture became part of the final rules. DIP circular; final rules.

What this changes for private-phone and eSIM choices

An eSIM changes the delivery format, not the final rule's identity scope. The definition expressly includes eSIMs and iSIMs. A travel or data service may use different upstream providers or jurisdictional processes, so compare the actual enrolment and carrier chain in our no-KYC eSIM comparison rather than assuming the embedded format avoids local rules.

A privacy-focused handset can reduce account crossover, app telemetry and device exposure, but it cannot override a carrier's legal identification duty. The private phone stack guide separates device controls from carrier identity, payment and number-reuse exposure.

For a normal user, the practical reading is narrower than the draft suggested: expect biometric identification at defined account events, operator-held identity records and possible portal alerts. Do not assume that a shared BIVS was enacted. Treat the DIP image check as a separate connection-cap control.

This article describes the published instruments as retrieved on the dates shown. Provider implementation, later government orders and court decisions may change how a particular case is handled.

Sources

Frequently Asked Questions

When do India’s 2026 biometric SIM rules require user identification?

The final rules apply biometric user identification to new enrolment, specified subscriber-detail or user changes, a user-requested disconnection, and government-directed reverification. Source: https://egazette.gov.in/WriteReadData/2026/275657.pdf. Retrieved 25 August 2026.

Did India enact the draft Biometric Identity Verification System?

No. The named Biometric Identity Verification System, cross-operator unique user ID, and real-time information-sharing provisions appeared in the 2025 draft but were omitted from the 2026 final rules. Sources: https://egazette.gov.in/WriteReadData/2025/266292.pdf and https://egazette.gov.in/WriteReadData/2026/275657.pdf. Retrieved 25 August 2026.

Is the DoT Digital Intelligence Platform circular the same as the final rules?

No. The 17 August 2026 DoT circular is a separate implementation direction for enforcing the existing mobile-connection cap through the Digital Intelligence Platform. It adds representative-image checks and a real-time target, but does not recreate the draft BIVS in the final rules. Source: https://www.dot.gov.in/static/uploads/2026/08/6d4fa4522c106536260492e8ae32a61f.pdf. Retrieved 25 August 2026.

Do the final rules require every user to authenticate with face, fingerprints, and iris?

No. The final e-KYC route uses live face, fingerprint, or iris authentication. D-KYC is available for a person without Aadhaar and for an Aadhaar holder unable to authenticate biometrically for specified physical reasons. An accessible alternative must be used when live face capture is not possible. Source: https://egazette.gov.in/WriteReadData/2026/275657.pdf. Retrieved 25 August 2026.