DoT notifies network authorisation rules, bars telecom data from leaving India
The Department of Telecommunications (DoT) notified the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026, on July 20. The rules took effect upon publication and replace the network-side licensing regime that operated under the Indian Telegraph …
Intelligence analysis by Llama

The new rules require all network data to stay in India, with no copy allowed to be routed, shared, or made available outside the country. Remote access to networks from outside India requires prior permission and a mirror system. Six authorisations cover the infrastructure layer of India's telecom networks, with fees falling almost entirely on Mobile Number Portability (MNP) providers.
Imagine you have a big network of roads and highways that connect different parts of the country. The new rules are like a set of traffic rules that ensure all the data that travels on these roads stays within the country. It's like having a mirror system that reflects what's happening on the roads, so that the authorities can keep an eye on things. This helps keep the data safe and secure.
Analysis
A New Era for Telecom in India
The Department of Telecommunications (DoT) has notified the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026, marking a significant shift in the country's telecom landscape. The rules, which took effect upon publication, replace the network-side licensing regime that operated under the Indian Telegraph Act, 1885.
The new rules introduce six authorisations that cover the infrastructure layer of India's telecom networks. These authorisations are non-exclusive, allowing multiple entities to hold the same authorisation for the same network in the same area. The rules also impose strict conditions on remote access to networks from outside India, requiring prior permission and a mirror system.
One of the most significant aspects of the new rules is the requirement that all network data stay in India. Rule 25(3) explicitly states that no copy of the data may be routed, shared, or made available outside India. This has significant implications for data security and the potential for data breaches.
The rules also introduce a new authorisation for cloud-hosted telecommunication network providers, which sell network functions three ways: housing an operator's equipment, supplying the equipment, or supplying the functionality an operator uses to deliver services. MNP providers, on the other hand, pay an annual authorisation fee of 1% of their adjusted gross revenue (AGR).
The new rules have been welcomed by some in the industry, who see them as a step towards greater transparency and accountability. However, others have expressed concerns about the potential impact on data security and the fees paid by MNP providers.
Remote Access and Data Security
The new rules impose strict conditions on remote access to networks from outside India. An entity providing remote access must obtain DoT permission first, which requires disclosure of the purpose, duration, the person accessing the network, and the specific Indian location involved. The permission also carries conditions, including the requirement to install technical systems at the approved Indian location, connected to the approved foreign location, letting DoT monitor a mirror image of what is available abroad.
The rules also require an audit trail of remote access activity to be retained in India for six months. This has significant implications for data security and the potential for data breaches.
Fees and Authorisations
The new rules introduce a new authorisation for cloud-hosted telecommunication network providers, which sell network functions three ways: housing an operator's equipment, supplying the equipment, or supplying the functionality an operator uses to deliver services. MNP providers, on the other hand, pay an annual authorisation fee of 1% of their adjusted gross revenue (AGR).
The rules also impose fees on other authorisations, including digital connectivity infrastructure providers, satellite earth station gateway providers, and internet exchange point (IXP) providers. However, these fees are significantly lower than those paid by MNP providers.
Conclusion
The new rules have significant implications for the Indian telecom industry, with potential impacts on data security, remote access, and the fees paid by MNP providers. While some in the industry have welcomed the new rules, others have expressed concerns about the potential impact on data security and the fees paid by MNP providers. As the industry adjusts to the new rules, it remains to be seen how they will shape the future of telecom in India.
Key points
- The Department of Telecommunications (DoT) has notified the Telecommunications (Authorisation for Telecommunication Network) Rules, 2026.
- The rules introduce six authorisations that cover the infrastructure layer of India's telecom networks.
- All network data must stay in India, with no copy allowed to be routed, shared, or made available outside the country.
- Remote access to networks from outside India requires prior permission and a mirror system.
- MNP providers pay an annual authorisation fee of 1% of their adjusted gross revenue (AGR).
The new rules could lead to greater transparency and accountability in the telecom industry, which could ultimately benefit consumers. Additionally, the rules could help to improve data security and reduce the risk of data breaches. However, the impact of the rules on MNP providers and the fees they pay is still unclear and may require further clarification.
The new rules could lead to increased costs for MNP providers, which could be passed on to consumers. Additionally, the rules could create new challenges for remote access and data security, which could have unintended consequences. However, the impact of the rules on data security and remote access is still unclear and may require further clarification.



