India Won't Give You a SIM Without Your Biometrics
India has made your face a condition for having a phone number. Under the new Telecommunications (User Identification) Rules, 2026, a shop can no longer hand you a SIM card without a biometric check, and the same check is now required to switch a number off. Your phone line is tied to your identity at both ends: the moment you get it and the moment you drop it. Operators have three months, extendable to six, to switch the systems on.
What the rules require
Getting a new SIM now runs through one of two paths, and both put your identity on file:
- Aadhaar holders are checked through UIDAI's authentication system (e-KYC), tying the number to the national ID.
- Everyone else goes through digital KYC: a live face capture, scans of original identity documents and, if the operator thinks it necessary, a field visit or a police check.
- Disconnecting a number also requires biometric verification, so you cannot quietly walk away from a line either.
- Operators must run an alert system that notifies users of SIM or account changes.
The stated goal is to cut fake SIMs, identity theft and fraud. The side effect is a country of well over a billion connections where every number is bound to a verified face.
The database they dropped, and the one they kept
The first draft went further. It proposed a Biometric Identity Verification System: a single, cross-industry biometric database that would have given every telecom customer a unique ID. After privacy objections, that central database was abandoned. But the government did not walk away from aggregation entirely. In its place came the Digital Intelligence Platform, which from 23 August pulls subscriber data and photos from every operator to find people holding more than the permitted number of connections nationwide.
So the most extreme idea, one master biometric file, was dropped, yet a platform that reaches across all carriers to match faces to numbers still went live. Civil-society groups, including the Internet Freedom Foundation, called it an unnecessary parallel collection of biometric data without the safeguards written into India's Aadhaar law.
Why it matters beyond India
A phone number is the key to almost everything else: bank logins, two-factor codes, messaging, government services. Once obtaining and cancelling one both demand your biometrics, the state and the carriers hold a live map of who is behind every line. India is not alone in this direction, and its rules are a template other governments watch closely. The lesson is not that fraud does not matter, but that "prove who you are" quietly becomes "prove it with your body", and biometrics, unlike a password, cannot be reissued if the data leaks. And the biometric data these systems collect is exactly what keeps leaking: we recently counted 88 breaches at identity-verification services alone.