Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
October 13, 2025
No Result
View All Result
Concur News

Home » Retailers Face Check for Collecting Phone Numbers Under New Data Law

Retailers Face Check for Collecting Phone Numbers Under New Data Law

August 27, 2025
in Global, News
Reading Time: 3 mins read
Retailers Face Check for Collecting Phone Numbers Under New Data Law
Share on LinkedinShare on Whatsapp

Shoppers Asked to Speak Numbers Aloud

Mumbai: Enterprise retailers may soon face trouble under India’s new data protection law. Many stores currently ask shoppers to share their Phone Numbers at billing counters for loyalty schemes or digital receipts. But saying Phone Numbers aloud in public exposes personal details. This practice goes against the rule that businesses must safeguard customer data.

Impact of the Digital Personal Data Protection Act

The new Digital Personal Data Protection Act will make businesses change how they handle customer information such as mobile numbers, which they often use as identifiers. This may affect loyalty programmes that rely on phone numbers as the main link with customers.

Simple Changes Can Improve Privacy

“Small process tweaks, such as replacing oral disclosure of mobile numbers with keypad entry, can significantly improve privacy safeguards. The law mandates that customers must be told why their data is collected, how long it will be stored, and when it will be deleted. Implied consent will no longer be valid every consent must be explicit,” said S Chandrasekhar, head of digital and cyber practice at K and S Partners, an intellectual property law firm.

Consent Foundation

Alternatives to Mobile Numbers

The law will stop businesses from denying services if customers refuse to share a phone number, unless the service absolutely requires it such as mobile recharges or Digi Yatra. Stores must give other options like email receipts or printed bills. Visitor entry systems must clearly state why they collect phone numbers and assure users that they will not reuse or sell the data.

Bringing India Closer to Global Standards

“The broader intent is not to disrupt business but to enforce accountability, ensuring data is used only for the stated purpose and then deleted,” said Chandrasekhar. He explained that these rules bring India closer to global data protection standards like the GDPR, showing the growing value of personal data in today’s businesses.

Wider Scope Beyond Retail

The rules will not just affect large retailers. They will also cover visitor management systems and housing societies that routinely collect mobile numbers. These groups will need to adopt secure, system based methods for collecting and storing data.

Rules for Storage and Deletion

Under the DPDP Act 2023, organisations can keep personal data like phone numbers only as long as they need it for the original purpose. They may store it for up to three years after the last user interaction or as specified in the rules. Once the purpose ends or the customer withdraws consent, the business must delete the data. Organisations also need to set up safeguards to stop any misuse, unauthorised use, or leakage of customer numbers.


Also read: Canada Updates Rules on Biometric Technology Usage

Tags: Data breachData privacyData ProtectionPrivacy

Related Posts

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns
India

FIFA Flags Risks in NSE’s Mutual Fund Platform: Data Security & Operational Concerns

September 8, 2025
Affordability Meets Privacy Risks in ChatGPT Go
India

Affordability Meets Privacy Risks in ChatGPT Go

September 3, 2025
Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw
Global

Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw

September 1, 2025
Raghuveer
Interview

Interview with Dr. Raghuveer Kaur, DPO at Cateina Technologies, on DPDPA, GRC, and Building Scalable Privacy Frameworks

August 29, 2025

RECOMMENDED NEWS

China Regulates Facial Recognition Technology

China Regulates Facial Recognition Technology

7 months ago
Edelson Lechtzin LLP Looks Into Data Breach Impacting Nevro Corp. Customers

Edelson Lechtzin LLP Looks Into Data Breach Impacting Nevro Corp. Customers

6 months ago
86% of Indian Firms Embrace Generative AI, Surpassing Global Trends

86% of Indian Firms Embrace Generative AI, Surpassing Global Trends

6 months ago
mission bell

Levi & Korsinsky Investigates Mission Bell Mfg, Inc. Data Breach

6 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR google Hack Hacked Industry Interview Law Meity penalty Personal data Press Release Privacy privacy rights RBI SPAM Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager