--- layout: default title: "Data Retention in India" description: "A 2013 CIS post by Elonnai Hickok examining data retention mandates and practices in India, comparing them with European and US approaches, and presenting findings from RTI requests filed with BSNL and MTNL under the SAFEGUARDS project." authors: ["Elonnai Hickok"] categories: [Centre for Internet and Society, Elonnai Hickok] date: 2013-01-30 source: "Centre for Internet and Society" permalink: /elonnai/data-retention-in-india/ created: 2026-08-17 homepage_featured: true --- **"Data Retention in India"** is a policy post by [Elonnai Hickok](/elonnai/) published by the [Centre for Internet and Society](/cis/) on 30 January 2013. It examines data retention mandates imposed on Indian telecom and internet service providers under the ISP and UASL licence regimes, compares these with data retention and data preservation approaches in Europe and the United States, and presents findings from Right to Information (RTI) requests filed with BSNL and MTNL as part of the SAFEGUARDS initiative. ## Contents 1. [Article Details](#article-details) 2. [Full Text](#full-text) 3. [Context and Background](#context-and-background) 4. [External Link](#external-link) ## Article Details
📰 Published by:
Centre for Internet and Society
📅 Date:
30 January 2013
✍️ Author:
Elonnai Hickok
📄 Type:
Blog post
🔗 Original Link:
Read the original post
## Full Text

As part of its privacy research, the Centre for Internet and Society has been researching upon data retention mandates from the Government of India and data retention practices by service providers. Globally, data retention has become a contested practice with regards to privacy, as many governments require service providers to retain more data for extensive time periods, for security purposes. Many argue that the scope of the retention is becoming disproportional to the purpose of investigating crimes.


This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC.

The Debate around Data Retention

According to the EU, data retention "refers to the storage of traffic and location data resulting from electronic communications (not data on the content of the communications)".1

The debate around data retention has many sides, and walks a fine line of balancing necessity with proportionality. For example, some argue that the actual retention of data is not harmful, and at least some data retention is necessary to assist law enforcement in investigations. Following this argument, the abuse of information is not found in the retention of data, but instead is found by who accesses the data and how it is used. Others argue that any blanket or a priori data retention requirements are increasingly becoming disproportional and can lead to harm and misuse. When discussing data retention it is also important to take into consideration what type of data is being collected and by what standard is access being granted. Increasingly, governments are mandating that service providers retain communication metadata for law enforcement purposes. The type of authorisation required to access retained communication metadata varies from context to context. However, it is often lower than what is required for law enforcement to access the contents of communications. The retention and lower access standards to metadata is controversial because metadata can encompass a wide variety of information, including IP address, transaction records, and location information — all of which can reveal a great deal about an individual.2 Furthermore, the definition of metadata changes and evolves depending on the context and the type of information being generated by new technologies.

Data Retention vs. Data Preservation

Countries have taken different stances on what national standards for data retention by service providers should be. For example, in 2006 the EU passed the Data Retention Directive which requires European Internet Service Providers to retain telecom and Internet traffic data from customers' communications for at least six months and up to two years. The stored data can be accessed by authorised officials for law enforcement purposes.3 Despite the fact that the Directive pertains to the whole of Europe, in 2010 the German Federal Constitutional Court annulled the law that harmonised German law with the Data Retention Directive.4 Other European countries that have refused to adopt the Directive include the Czech Republic and Romania.5 Instead of mandating the retention of data, Germany, along with the US, mandates the 'preservation' of data. The difference being that the preservation of data takes place through a specified request by law enforcement, with an identified data set. In some cases, like the US, after submitting a request for preservation, law enforcement must obtain a court order or subpoena for further access to the preserved information.6

Data Retention in India

In India, the government has established a regime of data retention. Retention requirements for service providers are found in the ISP and UASL licences, which are grounded in the Indian Telegraph Act, 1885.

ISP Licence

According to the ISP Licence,7 there are eight categories of records that service providers are required to retain for security purposes that pertain to customer information or transactions. In some cases the licence has identified how long records must be maintained, and in other cases the licence only states that the records must be made available and provided. This language implies that records will be kept.

According to the ISP Licence, each ISP must maintain:

UASL Licence

According to the UASL Licence,8 there are twelve categories of records that ISPs are required to retain that pertain to customer information or transactions for security purposes. In some cases the licence has identified how long records must be maintained, and in other cases the licence only states that the information must be provided and made available when requested. This language implies that records will be kept.

According to the licence, service providers must maintain and make available:

RTI Request to BSNL and MTNL

On 10 September 2012, the Centre for Internet and Society sent an RTI to MTNL and BSNL with the following questions related to the respective data retention practices:

Does MTNL/BSNL store the following information/data:

If it does store data then:

BSNL Response

BSNL replied by stating that it stores at least three types of information including:

  1. IP session information — connection start/end time, bytes in and out (three years offline).
  2. MAC address of the modem/router/device (three years offline).
  3. Bill copies for postpaid and recharge/top-up billing details for prepaid. Billing information of postpaid Broadband are available in the CDR system under ITPC; prepaid voucher details are retained for the last six months.

MTNL Response

MTNL replied by stating that it stores several types of information including:

  1. Text message details (to and from cell number, timestamps) in the form of CDRs (one year).
  2. Call detail records including inbound and outbound phone numbers and call duration (one year).
  3. Bill copies for postpaid (one year).
  4. Recharge details for prepaid (three months).
  5. Location of the mobile number if it has used the MTNL GSM/3G CDMA network (one year).

It is interesting that BSNL stores information that is beyond the required time period required in both the ISP and the UASL licences. The responses to the RTI showed that each service provider also stores different types of information. This could or could not be the actual case, as each question could have been interpreted differently by the responding officer.

Conclusion

The responses to the RTI from BSNL and MTNL are a step towards understanding data retention practices in India, but there are still many aspects about data retention in India which are unclear including:

Having answers to these questions would be useful for determining if the Indian data retention regime is proportional and effective. It would also be useful in determining if it would be meaningful to maintain a regime of data retention or switch over to a more targeted regime of data preservation.

Though it can be simple to say that a regime of data preservation is the most optimal choice as it gives the individual the greatest amount of immediate privacy protection, a regime of data preservation would mean that all records would be treated like an interception, where the police or security agencies would need to prove that a crime was going to take place or is in the process of taking place and then request the ISP to begin retaining specific records. This approach to solving crime would mean that the police would never use retained data or historical data as part of an investigation, whether to solve a case or to take the case to the next level. Whether Indian law enforcement is at a point where it is able to concisely identify a threat and then begin an investigation is a hard call to make. It is also important to note that though preservation of data can reduce the risk to individual privacy, as it is not possible for law enforcement to track individuals based on their historical data and access large amounts of data about an individual, preservation does not mean that there is no possibility for abuse. Other factors must also be considered, such as:

These factors must be enforced through the application of penalties for abuse of the system. These factors can also be applied not only to a data retention regime, but equally to a data preservation regime, and are focused on preventing the actual abuse of data once retained. That said, before an argument for either data retention or data preservation can be made for India, it is important to understand more about data retention practices in India, the use of retained data by Indian law enforcement, and the access controls in place.

Footnotes

  1. European Commission – Press Release. Commission Takes Germany to Court Requesting that Fines be Imposed. 31 May 2012. Available at: bit.ly/14qXW6o. Last accessed: 21 January 2013.
  2. Draft International Principles on Communications Surveillance and Human Rights: bit.ly/UpGA3D
  3. European Commission – Press Release. Commission Takes Germany to Court Requesting that Fines be Imposed. 31 May 2012. Available at: bit.ly/14qXW6o. Last accessed: 21 January 2013.
  4. European Commission – Press Release. Commission Takes Germany to Court Requesting that Fines be Imposed. 31 May 2012. Available at: bit.ly/14qXW6o. Last accessed: 21 January 2013.
  5. Tiffen, S. Sweden passes controversial data retention directive. DW. 22 March 2012. Available at: bit.ly/WOfzaX. Last accessed: 21 January 2013.
  6. Kristina, R. The European Union's Data Retention Directive and the United States' Data Preservation Laws: Finding the Better Model. 5 Shidler J.L. Com. & Tech. 13 (2009). Available at: bit.ly/VoQxQ9. Last accessed: 21 January 2013.
  7. Government of India. Ministry of Communications & IT, Department of Telecommunications. Licence Agreement for Provision of Internet Services.
  8. Government of India. Ministry of Communications & IT, Department of Telecommunications. Licence Agreement for Provision of Unified Access Services after Migration from CMTS. Amended 3 December 2009.
{% include back-to-top.html %} ## Context and Background In January 2013, the Centre for Internet and Society (CIS) published Elonnai Hickok's examination of data retention practices in India, situating the domestic regime within a wider international debate about how long communications providers should be required to hold on to customer data and communications metadata. The piece was produced under the SAFEGUARDS project, a collaboration between CIS, Privacy International and IDRC, and it built on the organisation's parallel work on the Draft International Principles on Communications Surveillance and Human Rights. The article opened by framing the global debate around two competing positions. One held that retaining data was not inherently harmful, since some retention assists law enforcement, and that any risk of abuse arises from how retained data is subsequently accessed and used rather than from the act of retention itself. The opposing position argued that blanket or a priori retention requirements are inherently disproportionate, regardless of downstream safeguards, because they compel providers to hold sensitive information on every user rather than targeting specific individuals under investigation. A significant part of the analysis focused on drawing a distinction between data retention and data preservation as regulatory models. The European Union's 2006 Data Retention Directive required internet service providers across the bloc to retain traffic and location data for a minimum of six months, up to a maximum of two years. However, this uniform approach fractured in practice, most notably when Germany's Federal Constitutional Court struck down the domestic law implementing the Directive in 2010, and other member states, including the Czech Republic and Romania, declined to adopt it. Germany and the United States instead followed a preservation model, in which providers are required to hold specific, identified data only after a targeted law enforcement request, with US authorities additionally needing a court order or subpoena for actual access. The article then turned to the Indian context, where retention obligations are embedded in the licence conditions governing internet service providers (ISPs) and Unified Access Service Licence (UASL) holders, both of which trace their legal basis to the Indian Telegraph Act, 1885. The piece catalogued eight categories of records mandated under the ISP licence and twelve categories under the UASL licence, spanning subscriber lists, call detail records, location data, network diagrams and audit trails of remote access activity, several of which required real-time availability to telecom authorities or retention periods ranging from six months to a year. To test how these licence obligations translated into actual provider practice, CIS filed Right to Information (RTI) requests with BSNL and MTNL on 10 September 2012, asking each operator to detail what categories of data it stored and for how long. The responses revealed inconsistencies: BSNL reported retaining IP session information and MAC addresses for three years offline, exceeding the licence-mandated minimums, while MTNL reported shorter retention windows for similar categories, such as one year for call detail records and text message data, and just three months for prepaid recharge details. The piece concluded that these RTI responses, while informative, left several structural questions unanswered, including what precisely constitutes a "commercial record," how much data is retained in aggregate, what retention costs providers and the public, and how frequently law enforcement actually accesses retained records. Hickok argued that resolving these open questions was necessary before India could meaningfully decide whether to retain its current data retention regime or shift toward a more narrowly targeted data preservation model, and she proposed a set of accountability safeguards, such as legitimacy and proportionality requirements, purpose limitation, restricted sharing, and mandatory deletion of irrelevant records, that could apply under either regime. ## External Link - [Data Retention in India](https://cis-india.org/internet-governance/blog/data-retention-in-india) on CIS website {% include navbox-elonnai.html %}