Why Compliance Matters More Than Ever for eSIM Partners
If you're distributing or reselling eSIMs — whether you run a travel brand, an MVNO, or a B2B connectivity platform — you sit at the intersection of three overlapping regulatory frameworks: GDPR data-protection law, eKYC identity-verification obligations, and telecom log-retention rules. Each one carries its own penalties, timelines, and documentation requirements.
The stakes are not theoretical. Since GDPR enforcement began in earnest, European data protection authorities have issued fines totalling over €4.5 billion across all sectors as of early 2026, according to the GDPR Enforcement Tracker maintained by CMS Law. Telecom companies have been among the most-fined categories, with violations ranging from unlawful data retention to insufficient identity verification at the point of sale.
Quotable stat: The Irish Data Protection Commission alone issued fines exceeding €1.3 billion in 2023, underscoring that even a single supervisory authority can impose life-altering penalties on a mid-size business.
For eSIM partners specifically, the compliance picture is complicated by the fact that eSIM provisioning involves multiple data controllers — the end user, the reseller, the eSIM platform, and the underlying network operator — each with distinct obligations. This guide unpacks what you actually need to do, jurisdiction by jurisdiction, and how to build a compliance architecture that scales.
What Is eKYC, and Does It Apply to eSIM Resellers?
eKYC (electronic Know Your Customer) is the digital process by which a business verifies the identity of a customer before providing a regulated product or service. For eSIM partners, eKYC obligations arise primarily from two sources: national telecom registration laws and anti-money-laundering (AML) directives.
Not every country requires SIM or eSIM registration — but a growing majority do. The GSMA's SIM Registration Guidelines document more than 150 countries that impose some form of subscriber identity registration, and that number has risen sharply since 2020 as governments tighten prepaid SIM rules to combat fraud and terrorism financing.
Which countries require eKYC for eSIM activation?
The requirement varies significantly by region:
| Region | Registration Requirement | Typical Document Required | Real-Time Verification? |
|---|---|---|---|
| European Union | Varies by member state; Germany, France, Italy require ID | National ID or passport | No (most accept self-declaration + document upload) |
| United Kingdom | Not mandatory for prepaid (post-Brexit) | None mandated, but operators may request | No |
| Australia | Mandatory (Telecommunications Act 1997) | Government-issued photo ID | Yes (via Document Verification Service) |
| India | Mandatory (TRAI regulations) | Aadhaar or passport | Yes (Aadhaar-based biometric) |
| Saudi Arabia | Mandatory | National ID / Iqama | Yes |
| United States | Not federally mandated for prepaid | None, but AML rules apply above $3,000 | No |
| Japan | Mandatory | My Number Card or passport | No (upload-based) |
| UAE | Mandatory | Emirates ID | Yes |
Key takeaway for partners: If your eSIM activates on a network in any of the countries above, the eKYC obligation typically falls on the licensed network operator, not the reseller. However, if you collect identity data on behalf of the operator (as many white-label platforms do), you become a data processor under GDPR and must have a Data Processing Agreement (DPA) in place.
What does a compliant eKYC flow look like?
A minimal compliant eKYC flow for an eSIM reseller operating in a registration-required market should include:
- Identity document capture — photograph of passport, national ID, or driver's license
- Liveness check — a selfie or short video to confirm the document belongs to the person presenting it
- Data minimization — collect only what the regulation requires; do not store document images longer than necessary
- Audit trail — log the verification outcome (pass/fail), timestamp, and the verification provider used, without storing raw biometric data unnecessarily
- Consent capture — if you process data beyond what's strictly required for compliance, capture explicit, granular consent
Third-party eKYC providers (such as identity-verification platforms integrated via API) can handle steps 1–2. Your responsibility is ensuring the DPA with that provider meets GDPR Article 28 requirements and that data flows outside the EEA are covered by Standard Contractual Clauses (SCCs) or an adequacy decision.
How Does GDPR Apply to eSIM Distribution Partners?
GDPR applies to any organization that processes the personal data of EU residents, regardless of where the organization itself is based. If you sell eSIMs to travelers heading to European destinations like Germany or France, you are processing personal data of EU residents and GDPR applies to you — even if your company is incorporated in the US, Australia, or Singapore.
Under GDPR, eSIM partners typically wear one or both of two hats:
- Data Controller: You determine the purposes and means of processing (e.g., you decide to collect an email address for order confirmation). You bear primary responsibility for compliance.
- Data Processor: You process data on behalf of another controller (e.g., you run identity verification on behalf of the network operator). You must follow the controller's instructions and can only act within the scope of the DPA.
What lawful basis should eSIM partners rely on?
The six lawful bases under GDPR Article 6 are not equally appropriate for every processing activity. For eSIM partners, the most relevant are:
- Contract performance (Art. 6(1)(b)): Processing an email address to deliver an eSIM QR code is necessary to perform the contract. This is the cleanest basis for core order fulfillment.
- Legal obligation (Art. 6(1)(c)): Processing identity documents to comply with a national SIM registration law falls here. You don't need separate consent.
- Legitimate interests (Art. 6(1)(f)): Fraud prevention, security logging, and basic analytics can often rely on this basis — but you must document a Legitimate Interests Assessment (LIA).
- Consent (Art. 6(1)(a)): Required for marketing emails, behavioral analytics, and any processing that isn't strictly necessary. Consent must be freely given, specific, informed, and unambiguous — pre-ticked boxes don't qualify.
A common compliance mistake is defaulting to consent for everything. This actually creates more risk, because consent can be withdrawn at any time, triggering erasure obligations. Use the narrowest, most appropriate basis for each processing activity.
What data minimization means in practice
GDPR's data minimization principle (Article 5(1)(c)) requires that you collect only personal data that is adequate, relevant, and limited to what is necessary for the stated purpose. For eSIM partners, this means:
- Don't collect date of birth unless a regulation requires it
- Don't store passport images after the verification check is complete (store the outcome, not the raw scan)
- Don't log IP addresses in perpetuity — set a defined retention window
- Don't require a physical address for a digital-only product unless required by local law
This principle intersects directly with log retention, which we cover in the next section.
What Are the Log Retention Requirements for eSIM Platforms?
Log retention is one of the most misunderstood compliance areas for eSIM operators. "Logs" in this context means any records generated by your platform: authentication logs, API call logs, activation event logs, payment transaction logs, and customer support interaction logs. Each type may have a different mandatory retention period under applicable law.
Telecom-specific data retention obligations in the EU were dramatically reshaped after the Court of Justice of the EU (CJEU) struck down the EU Data Retention Directive in 2014 (Joined Cases C-293/12 and C-594/12, Digital Rights Ireland). The Court found blanket, indiscriminate retention of communications metadata incompatible with the EU Charter of Fundamental Rights. Subsequent CJEU rulings (including La Quadrature du Net, C-511/18, 2020) have further restricted member states' ability to mandate general retention, confining it to targeted retention for serious crime and national security.
What this means for partners in 2026:
| Log Type | Typical Retention Period | Legal Basis |
|---|---|---|
| Transaction / payment records | 5–7 years | Tax law, AML regulations |
| Identity verification outcomes | Duration of contract + 1–3 years | National telecom law (where applicable) |
| Authentication / access logs | 90 days – 12 months | Legitimate interests (security) |
| API call logs (no personal data) | 30–90 days | Operational necessity |
| Customer support tickets | Duration of contract + 2 years | Contract / legitimate interests |
| Marketing consent records | Until consent withdrawn + 3 years | GDPR Art. 7(1) accountability |
How do national laws differ across key markets?
Despite the CJEU's rulings, several EU member states maintain national data retention laws for telecom operators, justified on national security grounds. Partners distributing eSIMs on networks in those countries should be aware:
- Germany: The Telekommunikationsgesetz (TKG) has seen its retention provisions repeatedly challenged. As of 2026, a blanket retention obligation for traffic data is suspended following the Federal Administrative Court's referral to the CJEU. Operators are advised to retain only what is operationally necessary.
- France: The Code des postes et des communications électroniques requires operators to retain certain connection data for 12 months for law enforcement purposes, subject to judicial oversight.
- United Kingdom (post-Brexit): The Investigatory Powers Act 2016 (IPA) requires "communication service providers" to retain communications data for up to 12 months. The UK ICO has published guidance on IPA obligations for businesses. Note that UK GDPR (retained EU law) still applies alongside the IPA.
- Australia: The Telecommunications (Interception and Access) Act 1979 mandates a 2-year retention period for metadata (not content), covering subscriber information, source/destination of communications, date/time/duration, and location data.
For partners serving travelers across multiple regions — say, someone buying an eSIM for Australia or the United Kingdom — the safest approach is to build your data architecture around the most stringent applicable requirement and document why each retention period is set as it is.
How Should Partners Structure Their Data Processing Agreements?
A Data Processing Agreement (DPA) is a legally binding contract between a data controller and a data processor, required under GDPR Article 28. If you're a reseller who passes customer data (even just an email and device EID) to an eSIM platform, you need a DPA in place before that data flows.
A compliant DPA must specify, at minimum:
- Subject matter and duration of the processing
- Nature and purpose of the processing
- Type of personal data and categories of data subjects
- Obligations and rights of the controller
- Processor obligations: process only on documented instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organizational security measures (Article 32); assist the controller with data subject rights requests; delete or return data at contract end; provide all information necessary to demonstrate compliance; allow and contribute to audits
Sub-processors (e.g., your eKYC provider, your cloud hosting provider) must be listed in the DPA or in an appendix. The controller must approve new sub-processors, and the sub-processor must be bound by the same obligations as the processor.
What security measures satisfy Article 32?
Article 32 requires "appropriate technical and organizational measures" — a deliberately flexible standard. For eSIM platforms, the following measures are widely considered baseline in 2026:
- Encryption at rest and in transit (AES-256 / TLS 1.3 minimum)
- Pseudonymization of personal data where possible (e.g., replace email with a hashed token in logs)
- Access controls with role-based permissions and multi-factor authentication
- Regular penetration testing and vulnerability assessments
- Incident response plan with a documented 72-hour breach notification process (GDPR Article 33)
- Data Protection Impact Assessment (DPIA) for high-risk processing (e.g., large-scale biometric eKYC)
What Are Partners' Obligations Around Data Subject Rights?
GDPR grants individuals eight rights over their personal data. For eSIM partners, the most operationally significant are:
Right of Access (Article 15)
A customer can request a copy of all personal data you hold about them. You have one month to respond (extendable by two months for complex requests). Your platform must be able to export all data associated with a given customer — order history, logs, consent records, support tickets — in a portable format.
Right to Erasure (Article 17)
The "right to be forgotten." Customers can request deletion of their data if it's no longer necessary for the original purpose, if consent is withdrawn, or if they object to processing. Important exception: you are not required to delete data you're legally obligated to retain (e.g., transaction records required by tax law). Document these exceptions clearly in your privacy policy.
Right to Data Portability (Article 20)
Where processing is based on consent or contract and carried out by automated means, customers can request their data in a machine-readable format (JSON, CSV) for transfer to another provider. This is increasingly relevant as eSIM platforms compete on data portability.
Right to Object (Article 21)
Customers can object to processing based on legitimate interests at any time. If they do, you must stop processing unless you can demonstrate compelling legitimate grounds that override their interests.
How Do Cross-Border Data Transfers Affect eSIM Partners?
If your eSIM platform routes data outside the European Economic Area (EEA) — for example, to a US-based cloud provider, an eKYC vendor in India, or a network operations center in Singapore — you must ensure the transfer is covered by one of GDPR's transfer mechanisms.
The three main mechanisms in 2026 are:
-
Adequacy decisions: The European Commission has recognized a list of countries as providing adequate protection, including the UK (currently under review), Japan, South Korea, and (under the EU-US Data Privacy Framework) the United States. If your sub-processor is in an adequacy country, no additional mechanism is needed.
-
Standard Contractual Clauses (SCCs): The 2021 SCCs (updated to reflect the Schrems II ruling) are the most common mechanism for transfers to non-adequate countries. They must be incorporated into your DPA with the sub-processor.
-
Binding Corporate Rules (BCRs): Relevant for large corporate groups with intra-group transfers. Not typically applicable to eSIM resellers.
The European Commission's adequacy decision page is the authoritative reference for current adequacy status — check it before onboarding any new sub-processor.
For partners selling eSIMs in regions like the Middle East and North Africa or Asia, where data may be processed by local network operators in non-EEA, non-adequate countries, SCCs are typically the required mechanism. Ensure your DPA template includes the appropriate SCC module (Module 2 for controller-to-processor transfers).
Building a Compliance Checklist: The Practical Partner Roadmap
Compliance isn't a one-time project — it's an ongoing operational discipline. The following checklist is a practical starting point for eSIM distribution partners building or auditing their compliance posture.
Data Governance Foundations
- Maintain a Record of Processing Activities (RoPA) under GDPR Article 30 — mandatory for organizations processing personal data at scale
- Appoint a Data Protection Officer (DPO) if you process special category data at scale, or if you're a public authority (most eSIM partners don't need a formal DPO, but a designated privacy lead is best practice)
- Publish a Privacy Policy that accurately describes all processing activities, lawful bases, retention periods, and data subject rights
- Conduct a DPIA before launching any high-risk processing (large-scale eKYC, behavioral profiling, cross-border transfers to high-risk countries)
eKYC Compliance
- Identify which markets require subscriber registration and map your eKYC obligations per country
- Ensure your eKYC provider is bound by a compliant DPA and that SCCs cover any data flowing outside the EEA
- Implement data minimization: store verification outcomes, not raw document images, beyond the minimum necessary period
- Test your eKYC flow against the liveness and document authenticity requirements of each target market
Log Retention
- Define and document retention periods for every log type (see table above)
- Implement automated deletion or anonymization at the end of each retention period
- Ensure logs containing personal data are encrypted and access-controlled
- Review national retention laws annually — this is a fast-moving area
Data Subject Rights
- Build a Data Subject Access Request (DSAR) workflow that can respond within one month
- Implement a deletion workflow that respects both erasure requests and mandatory retention obligations
- Test portability exports quarterly to ensure completeness and accuracy
Incident Response
- Maintain a breach register and a documented 72-hour notification process to your lead supervisory authority
- Conduct annual tabletop exercises simulating a data breach scenario
- Ensure your DPA requires sub-processors to notify you of breaches within 24 hours (giving you time to meet the 72-hour deadline)
How Does the EU AI Act Affect eKYC for eSIM Partners?
The EU AI Act, which entered into force in August 2024 and is being phased in through 2026–2027, classifies certain AI-based identity verification systems as high-risk AI. If your eKYC provider uses AI for biometric verification, facial recognition, or document authenticity assessment, that system may be subject to the AI Act's requirements for high-risk systems — including conformity assessments, technical documentation, and human oversight.
This is an emerging area, but partners should ask their eKYC providers for a statement of AI Act compliance status before the high-risk provisions become fully enforceable in August 2026.
Thinking about privacy beyond compliance
Compliance is the floor, not the ceiling. Travelers increasingly care about how their data is handled — and a transparent, privacy-respecting eSIM experience is a genuine competitive differentiator. Before you fly, it's worth reviewing your own travel privacy settings on iOS and Android to understand what data your devices generate — the same principles apply to how eSIM platforms should handle customer data.
For partners managing family accounts or multi-user plans, the intersection of parental controls and data governance adds another layer: see the guidance on family travel data management for practical context on how data minimization applies to dependent user profiles.
If you're building a travel brand that distributes eSIMs, the case study on launching a travel brand in 6 weeks covers the operational KPIs you'll need to track alongside compliance metrics.
FAQ
Does GDPR apply to eSIM resellers based outside the EU?
Yes. GDPR has extraterritorial scope under Article 3(2): it applies to any organization outside the EU that offers goods or services to EU residents, or that monitors the behavior of EU residents. If you sell eSIMs to customers traveling to EU destinations, GDPR applies to you regardless of where your company is incorporated. You may also need to appoint an EU representative under Article 27 if you don't have an establishment in the EEA.
How long should an eSIM platform retain customer data?
There is no single universal answer — retention periods depend on the type of data and the applicable legal basis. Transaction and payment records typically must be retained for 5–7 years under tax and AML law. Identity verification outcomes may be required for the duration of the customer relationship plus 1–3 years under national telecom laws. Authentication and access logs are generally retained for 90 days to 12 months for security purposes. Document your specific retention schedule in your privacy policy and RoPA, and implement automated deletion at the end of each period.
What is the difference between a data controller and a data processor for an eSIM partner?
A data controller determines the purposes and means of processing personal data — for example, an eSIM reseller that decides to collect a customer's email for order fulfillment. A data processor processes data on behalf of the controller — for example, a cloud platform that hosts the reseller's customer database. Many eSIM partners are simultaneously controllers (for their own customer relationships) and processors (when handling data on behalf of a network operator). Each role carries distinct GDPR obligations, and a Data Processing Agreement is required between controllers and processors.
Is eKYC mandatory for all eSIM activations?
No. eKYC requirements depend entirely on the country where the eSIM activates and the regulations of the underlying network operator. Countries like Australia, India, Saudi Arabia, and Japan mandate subscriber identity registration, meaning some form of identity verification is required. Many European countries and the United States do not have a blanket mandatory registration requirement for prepaid eSIMs, though operators may impose their own verification requirements for fraud prevention. Always check the specific requirements for each market you serve.
What happens if a partner suffers a data breach?
Under GDPR Article 33, you must notify your lead supervisory authority within 72 hours of becoming aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms. If the breach is likely to result in a high risk to individuals (e.g., identity documents exposed), you must also notify affected individuals directly under Article 34. Failure to notify within the 72-hour window is itself a GDPR violation and can attract fines independently of the breach itself. Ensure your DPAs require sub-processors to notify you within 24 hours of a breach to give you adequate time to meet your own deadline.
Do log retention rules conflict with GDPR's data minimization principle?
Yes, there is inherent tension — and resolving it is one of the core compliance challenges for eSIM platforms. The key is to distinguish between logs you are legally required to retain (covered by a legal obligation lawful basis) and logs you retain for operational or commercial reasons (which must be justified under legitimate interests or another basis, and minimized accordingly). Implement tiered retention: keep legally required logs for their mandated period, anonymize or delete operational logs on a shorter cycle, and document the rationale for every retention period in your RoPA.
What are Standard Contractual Clauses and when do eSIM partners need them?
Standard Contractual Clauses (SCCs) are pre-approved contractual terms issued by the European Commission that provide a legal mechanism for transferring personal data from the EEA to countries that don't have an adequacy decision. eSIM partners need SCCs when they share personal data with sub-processors (such as eKYC providers, cloud hosts, or analytics platforms) located in non-adequate countries. The current SCCs were updated in 2021 following the Schrems II ruling and include four modules covering different transfer scenarios — most eSIM partners will use Module 2 (controller to processor) or Module 3 (processor to processor).
How should partners prepare for the EU AI Act's impact on eKYC systems?
Partners should ask their eKYC providers to confirm whether their identity verification system uses AI for biometric matching or document authenticity assessment, and if so, whether it has been classified as a high-risk AI system under the EU AI Act. High-risk AI systems must meet requirements including conformity assessments, technical documentation, human oversight mechanisms, and registration in the EU database of high-risk AI systems. The high-risk provisions of the AI Act are being phased in through 2026–2027, so now is the time to request compliance documentation from your eKYC provider rather than scrambling at the deadline.






