Data Retention (Telecom Data Retention)

Also known as: Communications data retention

Data retention is the legal obligation on electronic communications providers to store specified categories of traffic, location and subscriber metadata for a defined period so that competent authorities can access them for the investigation of serious crime. National regimes vary in scope and duration; retained data typically covers who communicated with whom, when, from where and by what means, but not the content of communications.

Categories: Identity and SubscriberRegulation and Compliance

Data Retention in context

Subscriber identifiers (IMSI, SUPI, MSISDN, IMEI) anchor authentication, charging and lawful interception. Any protocol that leaks a permanent identifier is treated as a privacy defect, which is why 5G introduced SUCI concealment on the air interface.

Telecom regulation is fragmenting across NIS2, the UK Telecoms Security Act, sector rules in the US, GCC and APAC, plus horizontal frameworks like GDPR and DORA.

To place Data Retention in the wider telecom-security picture, review GDPR, 2G, AAA, ADSL, AKA and Any-Time Interrogation (ATI) — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.