KYC and Identity Verification for eSIM Sales: Who Holds the Obligation

Navy ring chart titled KYC and Identity Verification for eSIM Sales, showing eSIM forecast at 42% of all SIM technologies by 2030.

Identity verification is the compliance question most new eSIM resellers worry about, and the one where the answer is most often “it depends on who holds the licence”. Many countries require a mobile subscriber’s identity to be registered somewhere. Far fewer push that obligation onto a reseller sitting outside the country.

This sets out how the obligation is typically structured, what varies between markets, the questions worth putting to your wholesale partner, and where the line sits between a proportionate answer and one that needs professional advice.

This is general guidance, not legal advice. Identity verification and SIM registration requirements vary by country, apply differently depending on where the licensed operator sits, and change. Nothing here should be relied on as a statement of the law in any market. Confirm the position for each country you sell into with your wholesale partner and, where the exposure is material, with a qualified adviser.

The shape of the problem

  • Many countries require the identity of a mobile subscriber to be registered somewhere in the chain.
  • For a reseller, that obligation usually sits with the licensed operator or your wholesale partner, not with you.
  • "Usually" is doing real work in that sentence, and it varies by market.
  • Your practical job is to establish who holds the obligation and get it in writing.
  • Separately, your payment processor will have its own identity requirements that have nothing to do with telecom law.

Who holds the obligation

The chain matters more than the rule, because the rule usually attaches to the licensed party.

LayerTypical positionWhat to confirm
Host operatorHolds the licence in the destination countryThat registration, where required, is handled at this level
Wholesale partnerHolds the agreements and issues profilesWhether they take responsibility for registration obligations, in writing
You, the resellerSell to the end customer under your brandWhether any market you sell into pushes an obligation to the seller
Payment processorHandles the transactionTheir own identity and anti-fraud requirements, which are separate

The middle two rows are where ambiguity lives. Establish the split explicitly rather than assuming it.

The roaming distinction usually works in your favour. Most travel eSIM products place the customer on a foreign profile roaming onto a local network, rather than issuing them a local subscription. Registration rules written for local subscribers frequently do not apply in the same way to inbound roamers. This is a large part of why the model works across many markets, and it is also exactly the kind of detail worth confirming rather than assuming.

The practical position for most travel eSIM resellers is that the licensed operator in the destination country, and the wholesale partner holding the agreement with them, are the parties on whom registration obligations fall. That is why reselling connectivity generally does not require you to hold a telecom licence, and why the identity question usually resolves upstream of you.

What makes this worth checking rather than assuming is that it is not uniform. Some markets regulate resale directly, some require verification at point of sale regardless of who sells, and a few take an interest in foreign sellers reaching their residents. Which of those applies is a question for your specific market list.

What actually varies between markets

DimensionWhat variesWhy it matters to you
Whether registration is requiredSome markets mandate subscriber registration; others do notDetermines whether the question arises at all
Who must registerLicensed operator, distributor, or point of saleDecides whether the obligation can reach you
Roaming versus local subscriptionRules often differ for a visitor roaming on a foreign profileMost travel eSIM sits in the roaming case, which is usually simpler
What counts as verificationName only, document check, or biometric in some marketsAffects the customer experience if it does reach you
Data retentionHow long identity records must be kept, and whereInteracts with data protection obligations
EnforcementWhether rules are actively enforced against foreign sellersPractical risk, distinct from the written requirement

The last row deserves honesty. There is a difference between what a regulation says and what is enforced against a small foreign seller, and any adviser will tell you the first is what you should plan around. But knowing whether your wholesale partner has had enforcement contact in a market is genuinely useful intelligence, and it is a fair question to ask.

Global travel eSIM retail spend

$10B$7.5B$5B$2.5B0 $3.3B~$5B~$10B 202520262028 forecast

Source: Kaleido Intelligence. A category approaching this scale attracts regulatory attention it previously avoided.

1question that decides most of this: who is the licensed party in your supply chain
~$5Bforecast travel eSIM retail spend in 2026
42%of all SIM technologies forecast to be eSIM by 2030

Sources: Kaleido Intelligence, 2026; GSMA Mobile Economy Report 2026.

Growth attracts attention. Travel eSIM retail spend is forecast to approach $5 billion in 2026 and close to $10 billion by 2028. Categories at that scale get looked at by regulators in a way that categories at a few hundred million do not. A position that is comfortable today is worth revisiting annually rather than treating as settled.

Questions worth asking, and decisions that are yours

Ask your wholesale partner

  • In which of my target markets is subscriber registration required?
  • Who discharges that obligation for profiles you issue?
  • Is that stated in the agreement, or is it custom and practice?
  • Are there markets where you require identity data from me?
  • What happens if a regulator asks about an end customer?
  • Have you had enforcement contact in any of these markets?

Decide on your own side

  • What customer data you collect, and why
  • How long you keep it and where it is stored
  • What your privacy notice actually says
  • Who can access order and identity records internally
  • What you would provide in response to a lawful request
  • Whether you need identity data at all for your model

The left column is a conversation with your partner and should end with something written into the agreement. A verbal assurance from a salesperson is not a compliance position, and the people who gave it will not be the ones answering a regulator.

The right column is entirely yours regardless of what your partner does. Even where you collect no identity documents, you hold names, email addresses, purchase records and often device information, all of which are personal data with their own obligations under whichever data protection regime applies to you.

A proportionate approach

  1. List the markets you actually sell into

    Not the two hundred countries on a coverage map, but the destinations that carry real volume. The compliance question is only worth answering properly for markets where you have customers.

  2. Get the obligation split in writing

    Ask your wholesale partner directly who discharges registration requirements for the profiles they issue, and get the answer in the agreement rather than in an email exchange with a salesperson.

  3. Collect the minimum you need

    Identity data you do not hold cannot be lost, misused or requested. If your model does not require it, not collecting it is both a compliance simplification and a data protection one.

  4. Write the privacy notice to match reality

    Whatever you do collect needs to be described accurately, with a stated purpose, retention period and basis. A notice copied from a template that does not describe your actual practice is worse than none.

  5. Separate telecom rules from payment rules

    Your processor will have identity and anti-fraud requirements that exist independently of any telecom regulation. Conflating the two leads to collecting data for the wrong reason or missing a requirement entirely.

  6. Take advice where exposure is material

    For a small operator in a handful of markets, partner confirmation is usually proportionate. If you are entering a heavily regulated market, operating at scale, or selling to enterprises with their own compliance requirements, get qualified advice for those specific markets.

Step three is the one that simplifies everything downstream. Identity data you never collected cannot be breached, cannot be requested, and does not need a retention policy. If your model works without it, and most travel eSIM models do, the cheapest compliance decision available is to not gather it in the first place.

Frequently asked questions

Usually not directly, because registration obligations generally attach to the licensed operator and the wholesale partner holding the agreement with them. But this varies by market, some countries regulate resale or require verification at point of sale, and the position should be confirmed with your partner for each market you sell into rather than assumed.
A significant number of countries require subscriber identity to be registered in some form, and the specifics differ considerably in who must register, what counts as verification and how long records are kept. Because these rules change and are applied differently to inbound roamers than to local subscribers, get a current position for your specific markets rather than relying on a general list.
Usually not. Most travel eSIM products place the customer on a foreign profile roaming onto a local network rather than issuing a local subscription, and registration rules written for local subscribers frequently do not apply the same way to inbound roamers. This distinction underpins much of how the model works, and is worth confirming per market.
That depends on the market and on your agreement, which is precisely why the split should be written into the contract rather than left as custom and practice. Ask your wholesale partner directly who discharges registration obligations for the profiles they issue, and what happens if a regulator makes an enquiry about an end customer.
In which of your target markets registration is required, who discharges it for profiles they issue, whether that is stated in the agreement, whether they require identity data from you in any market, what happens if a regulator asks about an end customer, and whether they have had enforcement contact anywhere relevant.
No, and conflating them causes problems. Telecom subscriber registration and payment processor identity requirements exist for different reasons under different rules. Your processor will have its own anti-fraud and identity obligations regardless of any telecom regulation, and satisfying one does not satisfy the other.
Only if you have a specific reason to. Data you do not hold cannot be breached, misused or requested, and it needs no retention policy. Most travel eSIM models function without identity documents. If a particular market genuinely requires verification at point of sale, that is a reason; general caution is not.
You will still hold names, email addresses, purchase records and often device information, all of which are personal data. Whichever regime applies to you will require a lawful basis, an accurate privacy notice, a retention period, access controls and a response process for data subject requests. This applies regardless of telecom rules.
Often, and enterprise buyers may impose requirements of their own that exceed anything a regulator asks for, particularly around data location, retention and access. Corporate procurement processes frequently include security and data protection review, so expect to answer those questions in writing when selling to larger organisations.
When your exposure is material: entering a heavily regulated market, operating at meaningful scale, selling to enterprises with their own compliance requirements, or where your partner cannot give a clear written position. For a small operator in a few markets with clear partner confirmation, that confirmation is usually proportionate.

Get the compliance position in writing

eSIM Island can set out how registration obligations are handled for the markets you plan to sell into, alongside per-country wholesale rates. Tell us your target destinations and we will prepare a proposal.

Book a Free Demo

Or explore the Reseller Program, API Integration and Business Roaming.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>