The Department of Telecommunications (DoT) has introduced a new biometric-based user identification framework that changes how mobile connections are issued, replaced, updated and surrendered in India. Under the Telecommunications (User Identification) Rules, 2026, notified on August 21, users of notified mobile services must undergo live biometric verification at specified stages, bringing face, fingerprint or iris-based checks into the telecom identification process.
The new framework is part of a broader government effort to strengthen subscriber verification and curb fraudulent or misused mobile connections. The changes affect both consumers and telecom operators: users face additional identity checks for several SIM-related activities, while operators must build systems and processes capable of performing biometric verification and complying with expanded identification and re-verification requirements.
What Are The New DoT Biometric Rules?
The Telecommunications (User Identification) Rules, 2026 introduce “biometric identification” based on the live capture of a user’s face, fingerprint or iris. The requirement is designed to establish that the person seeking a telecom service is physically present and matches the identity being used for the connection.
The framework covers more than the purchase of a new SIM. Biometric verification can also apply when an existing subscriber wants to modify account information, replace a SIM or surrender a mobile connection.
Four Key Situations Requiring Verification
| SIM/Account Activity | Biometric Verification |
|---|---|
| New mobile connection | Required |
| SIM replacement or specified information update | Required |
| Surrender/disconnection at user’s request | Required |
| Government-directed re-verification | Required when ordered |
| Biometric methods | Face, fingerprint or iris |
| Verification type | Live biometric capture |
This represents a significant expansion of identity verification because the biometric check is tied to multiple stages of a mobile number’s lifecycle rather than being limited to initial activation.
What Changes For Mobile Users?
For consumers, the most visible change will be the greater reliance on physical biometric verification when carrying out certain SIM-related activities.
Someone buying a new connection will have to complete the applicable identification process before the SIM can be issued. Similarly, a person seeking a replacement SIM or certain changes to subscriber information may have to complete live biometric verification.
The rules also give the government a mechanism to require re-verification of existing subscribers. If a subscriber is directed to undergo re-verification and fails to complete the prescribed process, the rules provide for consequences that can include disconnection.
Aadhaar Users Face A Specific Requirement
The new framework is particularly significant for Aadhaar holders. According to analysis of the notified rules, Aadhaar holders are required to use Aadhaar-based electronic Know Your Customer (e-KYC) for identification rather than choosing another identification route.
That means the experience of obtaining or modifying a mobile connection can increasingly involve a combination of telecom records, government identity infrastructure and biometric verification.
For users, the practical impact can be summarized as follows:
- New SIM activation will involve stronger identity verification.
- SIM replacement may require a live biometric check.
- Certain subscriber-information changes will require biometric verification.
- Voluntary surrender of a number can also require biometric identification.
- Government-directed re-verification can affect existing connections.
- Aadhaar holders will use Aadhaar e-KYC under the new framework.
- Failed or incomplete mandatory re-verification can ultimately put a connection at risk.
Why Is The Government Tightening SIM Verification?
Mobile numbers have become central to banking, UPI payments, digital identity, government services and online communication. That makes fraudulent SIM issuance particularly consequential.
The government has previously taken action against connections obtained using fake or forged documents. In a December 2024 disclosure, the Department of Telecommunications said its AI-based system had helped identify suspected mobile connections obtained using fake documents, with 78.33 lakh connections disconnected after re-verification. Another 6.78 lakh connections were disconnected based on reporting related to cybercrime.
The latest biometric framework builds on that wider KYC enforcement effort.
The Broader Anti-Fraud Push
| DoT Measure | Objective |
|---|---|
| Biometric subscriber identification | Establish physical identity of user |
| Re-verification of existing connections | Identify potentially problematic connections |
| Point-of-Sale verification | Improve accountability of SIM sellers |
| Biometric verification of PoS personnel | Prevent misuse by agents |
| SIM-swap KYC controls | Reduce unauthorized replacement |
| Limits on mobile connections | Restrict excessive SIM ownership |
| Digital Intelligence Platform | Improve cross-operator verification |
The government has also been tightening rules around the number of mobile connections associated with an individual. From August 24, 2026, telecom operators have been instructed to prevent subscribers who already hold nine mobile connections from obtaining additional numbers, with real-time verification systems expected to be implemented later.
What Changes For Telecom Operators?
The compliance burden will be substantially higher for telecom service providers because operators must integrate biometric verification into their customer-facing and backend systems.
Operators will need processes capable of securely capturing and verifying live biometric information while ensuring that subscriber records remain consistent across different activities.
This is particularly important for SIM replacement and information updates. A replacement request can no longer be treated simply as a customer-service transaction; it becomes part of a more stringent identity-verification chain.
Operators Must Also Strengthen Their Distribution Networks
DoT has already imposed stronger requirements on telecom operators’ Points of Sale, including verification of franchisees, distributors and agents involved in enrolling customers and issuing SIM cards.
Earlier DoT measures included biometric verification of PoS personnel, physical verification of business and residential addresses, and measures to blacklist PoS entities that provide false or forged information.
This means the new biometric subscriber framework operates alongside an increasingly controlled SIM-distribution ecosystem.
How The New Process Could Affect Customers
For most users, the biggest change will be additional friction at telecom service points.
A routine SIM replacement that previously depended primarily on document or electronic verification could now require a live biometric interaction. Users who have difficulty providing a usable fingerprint may therefore depend more heavily on alternative biometric methods such as facial or iris verification, where available.
The issue is particularly relevant for elderly users, people with worn fingerprints and individuals whose biometric capture may be difficult because of disability or other circumstances.
DoT has previously recognized that some users can face difficulties with fingerprint authentication and had directed telecom operators to provide iris-based authentication at appropriate service points.
Convenience Versus Security
| User Consideration | Potential Effect |
|---|---|
| Stronger identity matching | Lower risk of fraudulent SIM issuance |
| Live biometric capture | More verification steps |
| SIM replacement | Potentially greater transaction time |
| Re-verification | Existing users may need to take action |
| Biometric failure | Could require an alternative verification method |
| Aadhaar-based e-KYC | More standardized digital identification |
| Privacy concerns | Greater sensitivity around biometric information |
The central policy trade-off is therefore straightforward: stronger identity assurance may reduce certain forms of telecom fraud, but it also increases the amount of personal verification required from legitimate users.
Privacy And Exclusion Concerns
The biometric requirement has prompted concerns from digital-rights advocates over privacy, proportionality and potential exclusion.
Internet Freedom Foundation has argued that mandatory live biometric identification creates risks for users whose fingerprints or other biometric characteristics are difficult to authenticate. It has also raised questions around data retention, system architecture, oversight and error rates.
These concerns are significant because mobile connectivity is increasingly essential for access to financial services, government benefits, authentication systems and digital communication.
A biometric failure that once meant an unsuccessful authentication attempt could become more consequential when a mobile connection itself depends on successful verification or re-verification.
The implementation details will therefore matter as much as the underlying rule. Clear procedures for failed biometric authentication, alternative verification, data protection and grievance redressal could determine how smoothly the framework works in practice.
What Users Should Do Now
Most existing subscribers do not need to immediately replace their SIM cards simply because the new rules have been notified. The practical impact will depend on when and how a particular subscriber is required to undergo re-verification.
However, users should keep their telecom account information accurate and respond to legitimate re-verification requests from their operator or DoT.
Consumers should also be cautious about unsolicited calls or messages asking them to provide biometric information, OTPs or personal documents. A stronger verification regime could itself create opportunities for scammers to impersonate telecom representatives.
A useful rule remains: never share an OTP or sensitive authentication information with an unknown caller, even if the caller claims that a SIM will be blocked without immediate action.
The Bigger Picture
India’s telecom identification system is moving toward a more tightly controlled, digitally integrated model in which subscriber identity, SIM issuance, replacement and re-verification are increasingly connected. Biometric identification is the latest step in that progression, following stronger KYC requirements, Point-of-Sale controls, SIM-swap safeguards and limits on the number of connections a subscriber can hold.
For telecom operators, the rules will increase compliance and technology requirements. For consumers, they could make some SIM-related services more secure but also less frictionless. The long-term success of the framework will depend on whether it can reduce fraudulent connections without creating significant barriers for legitimate subscribers or exposing sensitive biometric information to unnecessary risks.
Looking Ahead
The immediate focus will be on implementation. Telecom operators will need to ensure that biometric verification is available at appropriate service points and that their systems can handle new SIM issuance, replacement, information updates and government-directed re-verification. Regulators will also need to monitor authentication failures, customer complaints and the effectiveness of the new framework against fraudulent connections.
The bigger test will be whether stronger identity verification produces measurable improvements in telecom security while maintaining accessibility and privacy. As mobile numbers become increasingly linked to banking, payments and government services, the consequences of both fraudulent identity use and failed legitimate authentication will continue to grow. The DoT’s biometric mandate therefore represents not just a change in how SIM cards are issued, but a broader shift toward identity-centric telecom regulation.
Get the day’s top stories in your inbox
One concise email. No spam, unsubscribe anytime.



