The Department of Telecommunications (DoT) has introduced a new biometric-based user identification framework that changes how mobile connections are issued, replaced, updated and surrendered in India. Under the Telecommunications (User Identification) Rules, 2026, notified on August 21, users of notified mobile services must undergo live biometric verification at specified stages, bringing face, fingerprint or iris-based checks into the telecom identification process.

The new framework is part of a broader government effort to strengthen subscriber verification and curb fraudulent or misused mobile connections. The changes affect both consumers and telecom operators: users face additional identity checks for several SIM-related activities, while operators must build systems and processes capable of performing biometric verification and complying with expanded identification and re-verification requirements.

What Are The New DoT Biometric Rules?

The Telecommunications (User Identification) Rules, 2026 introduce “biometric identification” based on the live capture of a user’s face, fingerprint or iris. The requirement is designed to establish that the person seeking a telecom service is physically present and matches the identity being used for the connection.

The framework covers more than the purchase of a new SIM. Biometric verification can also apply when an existing subscriber wants to modify account information, replace a SIM or surrender a mobile connection.

Four Key Situations Requiring Verification

SIM/Account ActivityBiometric Verification
New mobile connectionRequired
SIM replacement or specified information updateRequired
Surrender/disconnection at user’s requestRequired
Government-directed re-verificationRequired when ordered
Biometric methodsFace, fingerprint or iris
Verification typeLive biometric capture

This represents a significant expansion of identity verification because the biometric check is tied to multiple stages of a mobile number’s lifecycle rather than being limited to initial activation.

What Changes For Mobile Users?

For consumers, the most visible change will be the greater reliance on physical biometric verification when carrying out certain SIM-related activities.

Someone buying a new connection will have to complete the applicable identification process before the SIM can be issued. Similarly, a person seeking a replacement SIM or certain changes to subscriber information may have to complete live biometric verification.

The rules also give the government a mechanism to require re-verification of existing subscribers. If a subscriber is directed to undergo re-verification and fails to complete the prescribed process, the rules provide for consequences that can include disconnection.

Aadhaar Users Face A Specific Requirement

The new framework is particularly significant for Aadhaar holders. According to analysis of the notified rules, Aadhaar holders are required to use Aadhaar-based electronic Know Your Customer (e-KYC) for identification rather than choosing another identification route.

That means the experience of obtaining or modifying a mobile connection can increasingly involve a combination of telecom records, government identity infrastructure and biometric verification.

For users, the practical impact can be summarized as follows:

  • New SIM activation will involve stronger identity verification.
  • SIM replacement may require a live biometric check.
  • Certain subscriber-information changes will require biometric verification.
  • Voluntary surrender of a number can also require biometric identification.
  • Government-directed re-verification can affect existing connections.
  • Aadhaar holders will use Aadhaar e-KYC under the new framework.
  • Failed or incomplete mandatory re-verification can ultimately put a connection at risk.

Why Is The Government Tightening SIM Verification?

Mobile numbers have become central to banking, UPI payments, digital identity, government services and online communication. That makes fraudulent SIM issuance particularly consequential.

The government has previously taken action against connections obtained using fake or forged documents. In a December 2024 disclosure, the Department of Telecommunications said its AI-based system had helped identify suspected mobile connections obtained using fake documents, with 78.33 lakh connections disconnected after re-verification. Another 6.78 lakh connections were disconnected based on reporting related to cybercrime.

The latest biometric framework builds on that wider KYC enforcement effort.

The Broader Anti-Fraud Push

DoT MeasureObjective
Biometric subscriber identificationEstablish physical identity of user
Re-verification of existing connectionsIdentify potentially problematic connections
Point-of-Sale verificationImprove accountability of SIM sellers
Biometric verification of PoS personnelPrevent misuse by agents
SIM-swap KYC controlsReduce unauthorized replacement
Limits on mobile connectionsRestrict excessive SIM ownership
Digital Intelligence PlatformImprove cross-operator verification

The government has also been tightening rules around the number of mobile connections associated with an individual. From August 24, 2026, telecom operators have been instructed to prevent subscribers who already hold nine mobile connections from obtaining additional numbers, with real-time verification systems expected to be implemented later.

What Changes For Telecom Operators?

The compliance burden will be substantially higher for telecom service providers because operators must integrate biometric verification into their customer-facing and backend systems.

Operators will need processes capable of securely capturing and verifying live biometric information while ensuring that subscriber records remain consistent across different activities.

This is particularly important for SIM replacement and information updates. A replacement request can no longer be treated simply as a customer-service transaction; it becomes part of a more stringent identity-verification chain.

Operators Must Also Strengthen Their Distribution Networks

DoT has already imposed stronger requirements on telecom operators’ Points of Sale, including verification of franchisees, distributors and agents involved in enrolling customers and issuing SIM cards.

Earlier DoT measures included biometric verification of PoS personnel, physical verification of business and residential addresses, and measures to blacklist PoS entities that provide false or forged information.

This means the new biometric subscriber framework operates alongside an increasingly controlled SIM-distribution ecosystem.

How The New Process Could Affect Customers

For most users, the biggest change will be additional friction at telecom service points.

A routine SIM replacement that previously depended primarily on document or electronic verification could now require a live biometric interaction. Users who have difficulty providing a usable fingerprint may therefore depend more heavily on alternative biometric methods such as facial or iris verification, where available.

The issue is particularly relevant for elderly users, people with worn fingerprints and individuals whose biometric capture may be difficult because of disability or other circumstances.

DoT has previously recognized that some users can face difficulties with fingerprint authentication and had directed telecom operators to provide iris-based authentication at appropriate service points.

Convenience Versus Security

User ConsiderationPotential Effect
Stronger identity matchingLower risk of fraudulent SIM issuance
Live biometric captureMore verification steps
SIM replacementPotentially greater transaction time
Re-verificationExisting users may need to take action
Biometric failureCould require an alternative verification method
Aadhaar-based e-KYCMore standardized digital identification
Privacy concernsGreater sensitivity around biometric information

The central policy trade-off is therefore straightforward: stronger identity assurance may reduce certain forms of telecom fraud, but it also increases the amount of personal verification required from legitimate users.

Privacy And Exclusion Concerns

The biometric requirement has prompted concerns from digital-rights advocates over privacy, proportionality and potential exclusion.

Internet Freedom Foundation has argued that mandatory live biometric identification creates risks for users whose fingerprints or other biometric characteristics are difficult to authenticate. It has also raised questions around data retention, system architecture, oversight and error rates.

These concerns are significant because mobile connectivity is increasingly essential for access to financial services, government benefits, authentication systems and digital communication.

A biometric failure that once meant an unsuccessful authentication attempt could become more consequential when a mobile connection itself depends on successful verification or re-verification.

The implementation details will therefore matter as much as the underlying rule. Clear procedures for failed biometric authentication, alternative verification, data protection and grievance redressal could determine how smoothly the framework works in practice.

What Users Should Do Now

Most existing subscribers do not need to immediately replace their SIM cards simply because the new rules have been notified. The practical impact will depend on when and how a particular subscriber is required to undergo re-verification.

However, users should keep their telecom account information accurate and respond to legitimate re-verification requests from their operator or DoT.

Consumers should also be cautious about unsolicited calls or messages asking them to provide biometric information, OTPs or personal documents. A stronger verification regime could itself create opportunities for scammers to impersonate telecom representatives.

A useful rule remains: never share an OTP or sensitive authentication information with an unknown caller, even if the caller claims that a SIM will be blocked without immediate action.

The Bigger Picture

India’s telecom identification system is moving toward a more tightly controlled, digitally integrated model in which subscriber identity, SIM issuance, replacement and re-verification are increasingly connected. Biometric identification is the latest step in that progression, following stronger KYC requirements, Point-of-Sale controls, SIM-swap safeguards and limits on the number of connections a subscriber can hold.

For telecom operators, the rules will increase compliance and technology requirements. For consumers, they could make some SIM-related services more secure but also less frictionless. The long-term success of the framework will depend on whether it can reduce fraudulent connections without creating significant barriers for legitimate subscribers or exposing sensitive biometric information to unnecessary risks.

Looking Ahead

The immediate focus will be on implementation. Telecom operators will need to ensure that biometric verification is available at appropriate service points and that their systems can handle new SIM issuance, replacement, information updates and government-directed re-verification. Regulators will also need to monitor authentication failures, customer complaints and the effectiveness of the new framework against fraudulent connections.

The bigger test will be whether stronger identity verification produces measurable improvements in telecom security while maintaining accessibility and privacy. As mobile numbers become increasingly linked to banking, payments and government services, the consequences of both fraudulent identity use and failed legitimate authentication will continue to grow. The DoT’s biometric mandate therefore represents not just a change in how SIM cards are issued, but a broader shift toward identity-centric telecom regulation.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.