Identity verification is the compliance question most new eSIM resellers worry about, and the one where the answer is most often “it depends on who holds the licence”. Many countries require a mobile subscriber’s identity to be registered somewhere. Far fewer push that obligation onto a reseller sitting outside the country.
This sets out how the obligation is typically structured, what varies between markets, the questions worth putting to your wholesale partner, and where the line sits between a proportionate answer and one that needs professional advice.
The shape of the problem
- Many countries require the identity of a mobile subscriber to be registered somewhere in the chain.
- For a reseller, that obligation usually sits with the licensed operator or your wholesale partner, not with you.
- "Usually" is doing real work in that sentence, and it varies by market.
- Your practical job is to establish who holds the obligation and get it in writing.
- Separately, your payment processor will have its own identity requirements that have nothing to do with telecom law.
Who holds the obligation
The chain matters more than the rule, because the rule usually attaches to the licensed party.
| Layer | Typical position | What to confirm |
|---|---|---|
| Host operator | Holds the licence in the destination country | That registration, where required, is handled at this level |
| Wholesale partner | Holds the agreements and issues profiles | Whether they take responsibility for registration obligations, in writing |
| You, the reseller | Sell to the end customer under your brand | Whether any market you sell into pushes an obligation to the seller |
| Payment processor | Handles the transaction | Their own identity and anti-fraud requirements, which are separate |
The middle two rows are where ambiguity lives. Establish the split explicitly rather than assuming it.
The practical position for most travel eSIM resellers is that the licensed operator in the destination country, and the wholesale partner holding the agreement with them, are the parties on whom registration obligations fall. That is why reselling connectivity generally does not require you to hold a telecom licence, and why the identity question usually resolves upstream of you.
What makes this worth checking rather than assuming is that it is not uniform. Some markets regulate resale directly, some require verification at point of sale regardless of who sells, and a few take an interest in foreign sellers reaching their residents. Which of those applies is a question for your specific market list.
What actually varies between markets
| Dimension | What varies | Why it matters to you |
|---|---|---|
| Whether registration is required | Some markets mandate subscriber registration; others do not | Determines whether the question arises at all |
| Who must register | Licensed operator, distributor, or point of sale | Decides whether the obligation can reach you |
| Roaming versus local subscription | Rules often differ for a visitor roaming on a foreign profile | Most travel eSIM sits in the roaming case, which is usually simpler |
| What counts as verification | Name only, document check, or biometric in some markets | Affects the customer experience if it does reach you |
| Data retention | How long identity records must be kept, and where | Interacts with data protection obligations |
| Enforcement | Whether rules are actively enforced against foreign sellers | Practical risk, distinct from the written requirement |
The last row deserves honesty. There is a difference between what a regulation says and what is enforced against a small foreign seller, and any adviser will tell you the first is what you should plan around. But knowing whether your wholesale partner has had enforcement contact in a market is genuinely useful intelligence, and it is a fair question to ask.
Global travel eSIM retail spend
Source: Kaleido Intelligence. A category approaching this scale attracts regulatory attention it previously avoided.
Sources: Kaleido Intelligence, 2026; GSMA Mobile Economy Report 2026.
Questions worth asking, and decisions that are yours
Ask your wholesale partner
- In which of my target markets is subscriber registration required?
- Who discharges that obligation for profiles you issue?
- Is that stated in the agreement, or is it custom and practice?
- Are there markets where you require identity data from me?
- What happens if a regulator asks about an end customer?
- Have you had enforcement contact in any of these markets?
Decide on your own side
- What customer data you collect, and why
- How long you keep it and where it is stored
- What your privacy notice actually says
- Who can access order and identity records internally
- What you would provide in response to a lawful request
- Whether you need identity data at all for your model
The left column is a conversation with your partner and should end with something written into the agreement. A verbal assurance from a salesperson is not a compliance position, and the people who gave it will not be the ones answering a regulator.
The right column is entirely yours regardless of what your partner does. Even where you collect no identity documents, you hold names, email addresses, purchase records and often device information, all of which are personal data with their own obligations under whichever data protection regime applies to you.
A proportionate approach
List the markets you actually sell into
Not the two hundred countries on a coverage map, but the destinations that carry real volume. The compliance question is only worth answering properly for markets where you have customers.
Get the obligation split in writing
Ask your wholesale partner directly who discharges registration requirements for the profiles they issue, and get the answer in the agreement rather than in an email exchange with a salesperson.
Collect the minimum you need
Identity data you do not hold cannot be lost, misused or requested. If your model does not require it, not collecting it is both a compliance simplification and a data protection one.
Write the privacy notice to match reality
Whatever you do collect needs to be described accurately, with a stated purpose, retention period and basis. A notice copied from a template that does not describe your actual practice is worse than none.
Separate telecom rules from payment rules
Your processor will have identity and anti-fraud requirements that exist independently of any telecom regulation. Conflating the two leads to collecting data for the wrong reason or missing a requirement entirely.
Take advice where exposure is material
For a small operator in a handful of markets, partner confirmation is usually proportionate. If you are entering a heavily regulated market, operating at scale, or selling to enterprises with their own compliance requirements, get qualified advice for those specific markets.
Step three is the one that simplifies everything downstream. Identity data you never collected cannot be breached, cannot be requested, and does not need a retention policy. If your model works without it, and most travel eSIM models do, the cheapest compliance decision available is to not gather it in the first place.
Frequently asked questions
Get the compliance position in writing
eSIM Island can set out how registration obligations are handled for the markets you plan to sell into, alongside per-country wholesale rates. Tell us your target destinations and we will prepare a proposal.
Book a Free DemoOr explore the Reseller Program, API Integration and Business Roaming.
Leave a Reply