Most eSIM resellers assume data protection is somebody else’s problem, on the reasonable grounds that they never collect identity documents. That assumption is wrong in a specific and important way: you hold personal data regardless, and some of it is more sensitive than the identity documents you avoided collecting.
This covers what you actually hold, why travel and usage records deserve more care than a contact list, how responsibility splits with your wholesale partner, and the practical steps that stand up to scrutiny from a regulator or a corporate procurement team.
Why this applies even to small operators
- You hold personal data whether or not you collect identity documents.
- Location and usage information is more sensitive than most operators realise.
- Selling into a jurisdiction can bring you within its rules regardless of where you are based.
- Your wholesale partner is a separate party processing the same customers' data.
- Business customers will ask you these questions in procurement, whatever a regulator does.
What you hold without meaning to
| Data you hold | Where it comes from | Why it is sensitive |
|---|---|---|
| Identity and contact | Checkout: name, email, sometimes phone | Standard personal data with standard obligations |
| Purchase history | Orders, destinations, dates | Reveals travel patterns, which is more than it appears |
| Device information | Compatibility checks, EID, device model | Device identifiers are personal data in many regimes |
| Usage data | Consumption, sometimes network and country | Can indicate where a person was and when |
| Payment metadata | Processor records, IP at purchase | Usually held by the processor, but you see fragments |
| Support correspondence | Tickets, chat logs | Frequently contains far more than the ticket needed |
The middle rows are the ones operators underestimate. A record of which countries someone bought data for, and when, is a travel history.
Sources: GSMA Intelligence; Juniper Research.
The device information row catches people out. An EID, device model or similar identifier is treated as personal data under a number of regimes when it can be linked to an individual, which in your systems it invariably can be because it sits against an order.
Global eSIM smartphone penetration
Source: GSMA Intelligence. Customer numbers roughly doubling each year means the volume of personal data you hold does too.
Volume matters here too. GSMA Intelligence expects eSIM smartphone penetration to reach around 10% globally by the end of 2026, roughly double a year earlier, and Juniper Research puts devices actively using an eSIM at around 1.5 billion during 2026. A growing business holds proportionally more data, and practices that were informal at a hundred customers become untenable at ten thousand.
Where your partner fits
Your wholesale partner processes the same customers you do, which makes the split of responsibility a question worth settling explicitly rather than assuming.
| Question | Why it matters | What to establish |
|---|---|---|
| Who decides how data is used? | Determines your role and your obligations | Whether you and your partner are independent or one acts for the other |
| What does your partner receive? | They process the same customers | Exactly which fields are passed, and why each is needed |
| Where is data stored? | Cross-border transfer rules may apply | Storage locations for your systems and theirs |
| How long is it kept? | Retention without purpose is hard to defend | A stated period per data type, applied automatically |
| Who can access it internally? | Support agents often see everything | Role-based access rather than blanket visibility |
| What happens on exit? | Leaving a provider raises deletion questions | Deletion or return terms in the agreement |
The storage location row is the one most often unanswered. Many resellers have never asked where their provider stores order and usage records, and it is a reasonable question with practical consequences if cross-border transfer rules apply to you. It is also the first thing a corporate buyer’s security review will ask.
What good practice looks like
Practical steps that hold up
- Collect only what the transaction needs
- A privacy notice that describes what you actually do
- Retention periods applied automatically, not manually
- Role-based access to order and support records
- A written process for data subject requests
- A record of which processors receive what
Common weak points
- A template privacy notice describing a different business
- Support tickets retained indefinitely with full chat history
- Every agent able to see every customer record
- Marketing lists built without a clear basis
- Usage data kept long after any operational need
- No idea where the wholesale partner stores anything
The support ticket item on the right deserves emphasis because it is nearly universal. Support tools retain everything by default, chat transcripts frequently contain more personal information than the issue required, and nobody ever goes back to delete them. It is one of the largest concentrations of unnecessary personal data in a typical small operator, and one of the easiest to fix.
A proportionate approach
Write down what you actually hold
List every place customer data sits: your store, your email platform, your support tool, your analytics, your provider dashboard. Most operators are surprised by the length of the list, and you cannot protect or minimise what you have not enumerated.
Delete what has no purpose
Data with no operational reason to exist is pure liability. Usage records from two years ago, support transcripts from resolved tickets and abandoned checkout details are the usual candidates.
Make the privacy notice describe reality
A template notice that describes a business you are not running is worse than none, because it is a public statement you are demonstrably not following. Write it after step one, not before.
Establish the split with your wholesale partner
They process the same customers. Establish which fields they receive, where they store them, how long they keep them, and what happens if you leave. This should be in the agreement, not in an email.
Restrict internal access
Support agents rarely need to see every customer\'s full history to resolve an activation problem. Role-based access is straightforward to configure and is one of the more visible signs of a serious operation during procurement review.
Prepare for the request you will eventually receive
A customer asking what you hold, or asking for deletion, should trigger a defined process rather than an improvised scramble. Write it down before you need it.
Step two is where most of the risk actually reduces. Data with no operational purpose cannot be used well, cannot be defended in an audit, and remains a liability in a breach. Deleting it is the cheapest improvement available and requires no legal input to justify.
Frequently asked questions
Know where your customer data sits
eSIM Island can set out exactly which fields we receive, where they are stored and how long they are retained, so you can answer procurement questions with confidence. Tell us about your business and we will provide the detail.
Book a Free DemoOr explore the Reseller Program, API Integration and Business Roaming.
Leave a Reply