Moneycontrol PRO
Loans
Loans
HomeTechnologyMC Explainer: Why the draft telecom cybersecurity rules are raising red flags

MC Explainer: Why the draft telecom cybersecurity rules are raising red flags

Draft rules blur the line between telecom networks and online services, say experts.

July 22, 2025 / 13:26 IST
The draft telecom cybersecurity rules were released on June 24 for public consultation

On June 24, 2025, the Central government introduced the draft Telecom Cybersecurity (Amendment) Rules, 2025.

While the government says the amendments are meant to curb cyber frauds and improve security of telecom networks, industry voices say that the approach could do more harm than good.

One of the central concerns experts are flagging about the draft is that it appears to extend regulatory powers over digital platforms in a manner that exceeds the legal scope of India’s telecom law.

With the consultation deadline set to end on July 24, here is a deeper look at what the draft rules say and what experts say are its key concerns.

What do the new rules propose?

There are three main proposals:

  • A new regulated category — TIUEs : The rules define a new kind of entity called a Telecommunication Identifier User Entity (TIUE). These are any digital platforms like apps and websites that use telecom services such as OTPs or mobile numbers to identify users or deliver services.

Under the new rules, TIUEs will have to comply with several obligations typically imposed on licensed telecom players.

  • Mandatory mobile number checks via a central platform: A new Mobile Number Validation (MNV) Platform will be set up by the government. TIUEs must use this platform to verify that a mobile number being used matches the telecom operator’s user database, the rules say.

The fee for each validation request is Rs 3 for private companies and Rs 1.50 for requests made on government direction, the draft rules say.

  • IMEI tracking and resale restrictions: Manufacturers must prevent the reuse of tampered or previously used IMEI numbers, the draft rules also propose. Used device resellers will also need to verify IMEI numbers through a government-run database before any sale, paying Rs 10 per device for the check.
Why are these rules drawing criticism?

While the government says the proposed changes are aimed at curbing cyber fraud, critics argue the rules risk expanding telecom regulation into the digital ecosystem without clear boundaries.

Experts say the rules bring online platforms under telecom-style regulation simply because they use phone numbers or OTPs, even though these platforms are already covered under IT laws.

“The government wants to tackle cyber fraud, but the rules now extend telecom-related obligations to digital platforms,” said Shahana Chatterji, Partner at Shardul Amarchand Mangaldas.

Chatterji, Uppal, Microsoft's director for government affairs John Khiangte, telecom expert Parag Kar and others were speaking at a stakeholder consultation on the draft hosted by CCAOI on July 21.

What could be the impact on businesses?

Platforms that use mobile numbers for user login or verification will now need to verify each number through the MNV platform, adding costs and technical overhead.

Do the rules go beyond what the law allows?

Some experts believe so. They point out that the Telecommunications Act, 2023 — the parent law under which these rules are framed — does not mention or authorise the creation of a new category like TIUEs.

“The entity called a TIUE does not emanate from the Act,” said Parag Kar, a telecom veteran. “You can’t regulate something that doesn’t exist in the law. If the rules are allowed to go this far, where does it stop?”

What about user privacy?

The draft rules do not clearly outline how consent, data protection, or access control will be managed in the MNV process. “All I have to do as an OTT player is pay a fee and get to use the MNV? That’s a problem,” said Uppal. “The system might be used by rogue players, exactly what it’s trying to prevent," he added.

How do these rules interact with existing laws?

Experts pointed out that many of the functions, such as dealing with cyber fraud, identity misuse, and user data protection are already addressed under the IT Act, CERT-In rules, and other sectoral regulations.

“The Telecommunications Act was never supposed to deal with these issues,” said Uppal, adding, “We are now seeing an unnecessary overlap between telecom regulation and digital platform governance.”

What happens next?

The Department of Telecommunications is accepting feedback on the draft till July 24, 2025. Industry stakeholders are expected to press for tighter scope, privacy safeguards, and cost relief for smaller entities.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Aihik Sur covers tech policy, drones, space tech among other beats at Moneycontrol
first published: Jul 22, 2025 01:26 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347