The Central government has prohibited telecom infrastructure providers, including cloud-hosted telecommunication network providers, mobile tower operators and satellite earth station gateway providers, from storing or sharing telecommunication network data outside India under a new authorisation framework notified by the Department of Telecommunications (DoT).
The notification, issued on 20 July, requires all telecommunication data, logs and information associated with telecom networks to be stored within India. The measure is part of the government's transition from the licensing regime to an authorisation-based regulatory framework under the Telecommunications Act, 2023.
Under the framework, every newly authorised entity must ensure that systems supporting its telecommunication network, along with all associated data, logs and information, remain within India. The rules also prohibit copies of such information from being routed, shared or made available outside the country.
"Every new authorised entity shall ensure that all systems of its telecommunication network and the data, logs and information associated with its telecommunication network shall be stored within India and no copies of such data, logs and information shall be routed, shared or made available outside India," the notification said.
Wider Compliance Powers
The framework empowers the Central government to inspect sites where telecommunication equipment and networks are deployed, including installations located at users' premises, to verify compliance with the rules.It also authorises the government to audit the processes and systems adopted by authorised entities. For this purpose, the Centre may appoint a designated agency to conduct compliance audits.
The notification further states that the government may dispense with prior notice if it considers immediate action necessary or expedient in the public interest. However, the designated agency cannot collect or require disclosure of information if doing so could harm the competitive position of either the user or the authorised entity.
Rollout Responsibility
The new rules place full responsibility on infrastructure providers to obtain all approvals and permissions required for deploying telecom networks. Delays in securing right-of-way permissions will not be accepted as a valid reason for failing to meet regulatory obligations.
"The non-availability of right of way or delays in obtaining right of way permission by the new authorised entity shall not be a cause or ground for non-compliance with any obligations under these rules," the framework stated.
Eligible Entities
The authorisation framework specifies the categories of entities that can seek approval under the Telecommunications Act, 2023. These include infrastructure providers, digital connectivity infrastructure providers, internet exchange point providers, satellite earth station gateway providers, cloud-hosted telecommunication network providers and national-level mobile number portability providers.
The latest framework forms part of the government's broader effort to replace the legacy telecom licensing regime with an authorisation-based system under the Telecommunications Act, 2023. |