Operators, Infrastructure Providers, And Network Programs
Keep network, customer, and rollout data controlled across a connected ecosystem
Telecom work crosses OEMs, managed-service partners, tower companies, circle teams, channel partners, regulators, and field sites. Subscriber extracts, design packs, site drawings, and audit responses leave the operator as a matter of routine, and a download or an email attachment can become a copy that outlives the work order it was created for.
Vaultize applies persistent rights to the document itself, with source-side encryption and customer-controlled keys, and is deployed on-premises, in private cloud, sovereign cloud, hosted, hybrid, or air-gapped environments, so a network or subscriber file can move while custody stays with the licensee.
Document exposure changes as subscriber, engineering, rollout, vendor, and regulatory files move between circle teams, OEMs, managed-service partners, tower companies, and field contractors. Select a column to inspect the handoff risk it represents.
Illustrative exposure pattern, not live security telemetry
Selected threat
Subscriber Data
Customer application forms, identity proofs, and usage extracts are exported for care, channel, and analytics work and can be retained afterwards.
Protected and controlledElevated or exposed risk
The file is often the last mile
Network Connectivity Does Not Equal Document Accountability
Element managers, OSS and BSS platforms, and vendor contracts govern the systems and the relationship around the network. The exposure changes when a subscriber extract, design pack, site package, or audit response is downloaded, forwarded, or retained outside those systems.
This is a practical risk view. It is not a determination of licence, regulatory, or contractual applicability or compliance, and it is not legal advice.
View the risk routeExpand full screen
Licence, Lawful Duties, And Subscriber Data
Scope depends on the licence, the authorisation, the service, and the record
Condition 37.2 of the Unified Licence agreement, in Chapter V of Part-I, provides that subject to the terms and conditions of the licence, the Licensee shall take all necessary steps to safeguard the privacy and confidentiality of any information about a third party and its business to whom it provides the Service and from whom it has acquired such information by virtue of the Service provided. Condition 37.3 adds that the Licensee shall take necessary steps to ensure that the Licensee and any person acting on its behalf observe confidentiality of customer information. Condition 39.19 records that the Licensor or its representatives will have access to the subscriber database.
Condition 39.5, in the Security Conditions chapter of the same agreement, provides that the Licensee shall be completely and totally responsible for security of their networks and shall have an organizational policy on security and security management, submitted to the Licensor within 90 calendar days. Condition 39.6 requires a network security audit once in a financial year. Condition 39.20 requires all commercial records and Call Detail Records, Exchange Detail Records, and IP Detail Records to be archived for at least two years for scrutiny by the Licensor for security reasons.
Section 22(1) of the Telecommunications Act, 2023, notified as Act No. 44 of 2023 in the Gazette of India of 24 December 2023, empowers the Central Government to make rules providing for measures to protect and ensure cyber security of telecommunication networks and services, and Section 22(3) allows any network or part of it to be declared Critical Telecommunication Infrastructure. Section 42(2) provides that whoever gains or attempts to gain unauthorised access to a telecommunication network or to data of an authorised entity, or transfers data of an authorised entity, shall be punishable with imprisonment which may extend to three years, or fine up to two crore rupees, or both. The Explanation records that data of an authorised entity includes call data records, internet protocol data records, traffic data, and subscriber data records.
The Telecommunications (Telecom Cyber Security) Rules, 2024, notified as G.S.R. 720(E) on 21 November 2024, require at Rule 7(1)(a) that a telecommunication entity report a security incident affecting its network or service to the Central Government within six hours of becoming aware of it, and at Rule 7(1)(b) that it furnish the number of users affected, the duration, the geographical area, the extent of impact, and the remedial measures within twenty-four hours. Rule 4(4)(a) requires a telecom cyber security policy covering safeguards, testing, risk assessment, rapid action, and forensic analysis, Rule 4(4)(h) requires a Security Operations Centre, and Rule 6 requires the appointment of a Chief Telecommunication Security Officer.
Section 8(5) of the Digital Personal Data Protection Act, 2023 requires a Data Fiduciary to protect personal data in its possession or under its control, including processing carried out on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach. The Schedule provides a penalty that may extend to two hundred and fifty crore rupees for breach of that obligation, as determined by the Board. Subscriber acquisition forms, identity proofs, care records, and channel extracts all carry personal data of this kind.
The CERT-In Directions of 28 April 2022 require service providers, intermediaries, data centres, body corporate, and Government organisations to report the cyber incidents listed in Annexure I within six hours of noticing them or being brought to notice about them. Annexure I expressly includes unauthorised access of IT systems or data, data breach, and data leak. This duty runs alongside, and not instead of, the reporting duty under the Telecom Cyber Security Rules, 2024.
Regulator, Consumer, And Critical Infrastructure
Scope depends on the entity, the service, the notification, and the listing
Condition 39.7.1 of the Unified Licence agreement records that the Government, through the Designated Authority, will have the right to impose conditions for procurement of Telecommunication Equipment on grounds of the defence of India or national security, and that the Designated Authority for this purpose shall be the National Cyber Security Coordinator. It provides that with effect from 15th June 2021 the licensee shall only connect Trusted Products in its network, and shall seek permission from the Designated Authority for upgradation or expansion of the existing network using equipment not designated as Trusted Products. The condition is footnoted to DoT letter no. 20-271/2010 AS-I (Vol.-III) dated 10 March 2021.
Regulation 5 of the Telecom Commercial Communications Customer Preference Regulations, 2018, made by TRAI on 19 July 2018, requires every Access Provider to develop an ecosystem that provides a facility for subscribers to register preferences and maintains complete and accurate records of those preferences, provides a facility to record consents acquired by senders and maintains complete and accurate records of consent, and provides for revocation of consent with corresponding updates. Regulation 26 requires records of complaints against registered and unregistered senders to be maintained on a daily basis for each service area.
The Telecom Commercial Communications Customer Preference (Second Amendment) Regulations, 2025, dated 12 February 2025, insert a proviso that consent shall not extend beyond the duration or discharge of the contract between the Sender and the Recipient. The amendment also provides that a sender may re-acquire the consent of a customer who has revoked it only after ninety days from the date of revocation, and requires headers unused for ninety days to be temporarily deactivated. Purpose-bound and time-bound handling of customer data is written into the regulation rather than left to practice.
The Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018 apply to organisations whose systems are notified under Section 70 of the Information Technology Act, 2000. They require the Chief Information Security Officer to share information security audit reports, post-audit compliance reports, and IT security service level agreements with NCIIPC, and to establish a process for sharing logs of the protected system. Telecom infrastructure is a candidate for such notification, and a declaration of Critical Telecommunication Infrastructure under Section 22(3) of the Telecommunications Act, 2023 is a separate, parallel mechanism.
The SEBI (Listing Obligations and Disclosure Requirements) (Second Amendment) Regulations, 2023 inserted Regulation 27(2)(ba), under which details of cyber security incidents or breaches or loss of data or documents are to be disclosed along with the quarterly corporate governance report, as may be specified. Listed operators, tower companies, and equipment vendors sit inside that reporting obligation in addition to their sector-specific duties.
Global Vendors And Cross-Border Traffic
Scope depends on the entity, the market, the customer, and the data
Article 32 of Regulation (EU) 2016/679 requires the controller and the processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, and names pseudonymisation and encryption of personal data among them. Article 83(4) places infringements of Article 32 in the tier of administrative fines up to 10 million euro, or up to 2% of total worldwide annual turnover of the preceding financial year, whichever is higher. This reaches an Indian operator or vendor through European roaming, enterprise, and employee data.
Annex I to Directive (EU) 2022/2555 lists, under sector 8 Digital infrastructure, both Providers of public electronic communications networks and Providers of publicly available electronic communications services. Article 3(1)(c) treats such providers as essential entities where they qualify as medium-sized enterprises, and Article 3(1)(a) does the same for Annex I entities above that ceiling, with Article 3(2) placing the remainder among important entities. Article 21(2)(d) requires cybersecurity risk-management measures covering supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers, and Article 21(2)(h) requires policies and procedures regarding the use of cryptography and, where appropriate, encryption.
Article 23(4) of the same Directive requires an early warning within 24 hours of becoming aware of a significant incident, indicating whether it is suspected of being caused by unlawful or malicious acts or could have a cross-border impact, and an incident notification without undue delay and in any event within 72 hours, with an initial assessment of severity and impact and any indicators of compromise. Article 34 provides for administrative fines against essential entities of a maximum of at least EUR 10 000 000 or at least 2% of total worldwide annual turnover in the preceding financial year, whichever is higher.
Section 64.2010(a) of Title 47 of the Code of Federal Regulations requires telecommunications carriers to take reasonable measures to discover and protect against attempts to gain unauthorized access to customer proprietary network information. Section 64.2009(c) requires all carriers to maintain a record of all instances where CPNI was disclosed or provided to third parties, or where third parties were allowed access to CPNI, and to retain that record for a minimum of one year. These rules bind US carriers; an Indian operator or vendor meets them through US customers, subsidiaries, or carrier contracts.
Section 64.2011 of the same Title requires a telecommunications carrier to notify law enforcement of a breach of its customers' CPNI, and provides that as soon as practicable, and in no event later than seven business days after reasonable determination of the breach, the carrier shall electronically notify the United States Secret Service and the Federal Bureau of Investigation through a central reporting facility. The carrier may not notify customers or disclose the breach publicly until seven full business days have passed after that notification, subject to the urgency exceptions in the rule. Section 64.2011(d) requires carriers to maintain a record of any breaches discovered and of the notifications made, including a detailed description of the CPNI that was the subject of the breach, and to retain that record for a minimum of 2 years.
Ranked by business exposure
Priority Telecom Records
Swipe the wheel or tap a record class.Drag, scroll, click, or use the arrow keys to move between record classes without changing the layout.
Swipe or tapDrag or scroll01 / 05
Subscriber
Design
Rollout
Vendor
Evidence
Subscriber And Customer Records
01
Personal data · licence confidentiality · third-party retention
Subscriber And Customer Records
01
Leak scenario
Customer acquisition forms, identity proofs, usage extracts, and care transcripts are exported for a channel partner, an analytics vendor, or a collections agency, and the extract stays on the recipient's storage long after the campaign or the case is closed.
02
Common stopping point
OSS and BSS access controls, contracts, and encryption in transit protect the platform and the transfer. None of them necessarily governs the exported spreadsheet once it is on a partner's laptop, nor allows the operator to withdraw it later.
03
Stronger practice
Treat every subscriber extract as its own release decision: name the recipient, bound the permitted use and the period to the campaign or the case, keep forwarding visible and revocable, and retain an attributable record of who opened which extract.
04
Cost of inaction
Condition 37.2 of the Unified Licence requires the Licensee to take all necessary steps to safeguard the privacy and confidentiality of information about a third party acquired by virtue of the Service, and Condition 37.3 extends that to any person acting on its behalf. Section 8(5) of the DPDP Act, 2023 requires reasonable security safeguards including for processing carried out on the fiduciary's behalf by a processor, and its Schedule provides a penalty that may extend to two hundred and fifty crore rupees.
Operational risk map only, and not legal advice. Licence, regulatory, and contractual scope depends on the entity, the authorisation, the service, and the current instrument. Linked official sources are authoritative. File controls support confidentiality and security obligations as part of a wider network, identity, personnel, governance, and incident-response program; they do not satisfy licence conditions or lawful-interception duties, and they do not establish compliance by themselves.
Operational risk map only, and not legal advice. Licence, regulatory, and contractual scope depends on the entity, the authorisation, the service, and the current instrument. Linked official sources are authoritative. File controls support confidentiality and security obligations as part of a wider network, identity, personnel, governance, and incident-response program; they do not satisfy licence conditions or lawful-interception duties, and they do not establish compliance by themselves.
Documented industry incidents
The Cost Is Real
Exposure of telecom subscriber and network data has already reached a written reply in the Lok Sabha and multi-million dollar settlements with a national regulator. In each case a government or a regulator put the facts on the record.
One FTP server
held the data CERT-In flagged
Case 01
The File Server Was The Exposure
Case date
Reported by CERT-In on 20.05.2024; answered in the Lok Sabha on 24 July 2024
Case location
Department of Telecommunications, Ministry of Communications, Government of India
Lok Sabha Unstarred Question No. 432, titled Data Breach in BSNL, asked whether the Government had taken cognizance of a data breach involving critical data including International Mobile Subscriber Identity numbers, SIM card information, Home Location Register details, DP Card Data, and snapshots of BSNL's SOLARIS servers. The written reply records that the Indian Computer Emergency Response Team reported possible intrusion and Data Breach at BSNL on 20.05.2024, and that on analysis it was found that one File Transfer Protocol server was having the data similar to the sample data shared by CERT-In. The reply states that no breach into the Home Location Register of the telecom network was reported by the Equipment Manufacturer, and hence no service outage occurred in BSNL's network.
What The Government Recorded
The reply sets out the remedial measures taken: access passwords to all similar FTP servers have been changed, and instructions to maintain air-gap for End Points have been issued. It further records that an Inter Ministerial Committee has been constituted to conduct an audit of the telecom networks and suggest remedial measures for prevention of data breaches in the telecom networks. The exposure named in the reply is a file server holding an accessible copy of telecom data, not the production network element itself.
Publicly documented incidents. The organizations named are not represented as Vaultize customers, and no claim is made that Vaultize would have prevented these events. Dates, locations, roles, figures, and consequences follow the linked primary sources; undisclosed parties are identified as redacted or not disclosed. Individuals are named only where the linked official document names them; the individuals named here are the Minister who gave the written reply and the Bureau Chief who signed the consent decrees, not the parties. The first case is an Indian Government record; the second and third are United States regulatory settlements, included because no concluded Indian enforcement document specific to an operator was found at this evidence standard.
A deliberate control trail
Make The Release Decision Reviewable
Use the file-level route as part of a broader network, vendor-risk, privacy, and security program. The objective is a clear answer to what was released, to whom, under what conditions, and what activity followed.
Controlled document route
A concise record around a telecom exchange
ProgrammePartyUseExpiryEventsPreservation
01
Classify The Record
Identify the subscriber, engineering, rollout, vendor, and regulatory files that carry personal data or network detail before external access. Discover & Classify can apply content and context rules across endpoints and repositories, including detection of PII, so the classification reflects the programme, the circle, and the sensitivity rather than a generic file type.
02
Define Permitted Use
Decide who can view, edit, print, copy, forward, or download each document before it leaves, and apply the organization's approved identity and approval process for OEMs, managed-service partners, tower companies, contractors, and channel partners.
03
Open A Bounded Exchange
Release the file or the workspace to named users and groups under expiry, watermarking, and access conditions bound to the work order or the evaluation round, subject to the organization's policy and technical environment. Governed sharing can replace ad hoc FTP, SFTP, and MFT routes where the delivered payload otherwise arrives uncontrolled.
04
Protect The Message, Not Only The Attachment
Where a subscriber extract or a design note travels by email, protect the body alongside the attachment, keep each recipient's access verifiable, and retain the ability to revoke downstream forwards after the message has been sent.
05
Preserve, Trace, And Withdraw
Keep release, access, policy-change, and revocation evidence available to security, vendor-risk, privacy, and audit teams, retain immutable versions of regulatory and incident evidence, and require multi-stakeholder approval before any permanent deletion.
Common network routes
Start Where Telecom Files Change Hands
Telecom information moves from planning through procurement, rollout, operations, customer service, and audit. The map shows where file-level control must remain connected as documents cross each handoff.
Telecom network and service lifecycleFour priority control points
01
OEM And Partner Exchange
Release tender packs, specifications, and integration documents to named vendor teams under expiry and usage conditions, and withdraw access at award or at contract exit instead of relying on a contractual duty to delete.
Access ends when the contract does
02
Rollout And Field Distribution
Send site packages, drawings, and acceptance evidence to tower companies and field crews through governed links with MFA, watermarking, and per-recipient activity records, without file-size or file-type friction.
Control beyond the site perimeter
03
Subscriber Data Release
Protect the email body and its attachments when customer records reach care, collections, channel, or analytics recipients, keep each access verifiable, and retain the ability to expire or revoke a forwarded message.
Purpose-bound customer data
04
Regulatory And Incident Evidence
Maintain immutable versions of audit responses, incident timelines, and log extracts under the organisation's own custody, and require multi-stakeholder approval before any permanent purge.
Evidence stays recoverable
Bring one network route
Make One Telecom Release Reviewable
Walk through the records, recipients, permitted use, and evidence a responsible security, vendor-risk, and privacy team can verify.