LI for eSIM-Only MVNOs: Unique Challenges and Practical Solutions

eSIM MVNO - lawful interception compliance illustration

The eSIM MVNO business model introduces distinct lawful interception challenges compared to traditional MVNOs. eSIM-only MVNOs represent a growing segment of the telecommunications market. By eliminating the physical SIM card entirely, these operators can offer fully digital onboarding, instant activation, and seamless profile management — all of which appeal to tech-savvy consumers and digital-first brands. However, the eSIM-only model introduces specific challenges for lawful interception that go beyond those faced by traditional MVNOs. The dynamic nature of eSIM profiles, the ease of profile switching, and the absence of physical identity verification touchpoints all create complexities that must be addressed for regulatory compliance.

This article examines the unique LI challenges faced by eSIM-only MVNOs and provides practical solutions for addressing them within the current regulatory and technical frameworks.

The eSIM MVNO Compliance Challenge

eSIM-only MVNOs operate without physical SIM cards. Subscribers download an operator profile directly to their device’s embedded UICC through the GSMA RSP (Remote SIM Provisioning) architecture. The entire customer journey — from registration through activation to service management — is digital. This model eliminates the logistics of SIM card manufacturing, distribution, and physical retail, enabling a leaner, more scalable business operation.

From a lawful interception perspective, the eSIM-only model shares many characteristics with traditional eSIM deployments but amplifies certain challenges. The complete absence of physical SIM distribution means that there are no physical touchpoints at which identity verification can occur. The ease of profile management means that subscribers can activate, deactivate, and switch profiles with minimal friction. And the digital-first customer base may be more technically sophisticated and more likely to use privacy-enhancing technologies.

Identity Verification and KYC Challenges

Know Your Customer (KYC) requirements vary by jurisdiction, but in many European markets, operators must verify the identity of their subscribers before activating service. For eSIM-only MVNOs, this verification must be performed entirely through digital channels — there is no opportunity for in-person identity document checks at a retail location. Digital identity verification methods include video identification, electronic identity document verification, eID authentication, and bank account verification.

The quality of identity verification directly affects the effectiveness of lawful interception. If a subscriber’s identity is not reliably established, law enforcement may be unable to associate an interception order with the correct subscriber. eSIM-only MVNOs must implement robust digital KYC processes that meet the standards required by their regulatory framework and that provide a reliable link between the subscriber’s real-world identity and their network identity (IMSI, MSISDN).

Some jurisdictions have specific requirements for digital identity verification that operators must comply with. Germany’s TKG, for example, requires identity verification for prepaid services and specifies acceptable methods for digital verification. eSIM-only MVNOs must ensure that their digital KYC processes meet these specific national requirements.

Profile Lifecycle Management

In an eSIM-only MVNO, the profile lifecycle — download, installation, activation, deactivation, and deletion — is managed entirely through digital processes. Each stage of this lifecycle has implications for lawful interception. When a new profile is downloaded and activated, the subscriber becomes visible on the network with a new set of identifiers. When a profile is deactivated or deleted, the subscriber disappears from the network. These transitions must be tracked by the LI system to ensure that interceptions can be maintained or adjusted as the target’s profile status changes.

The LI system must integrate with the MVNO’s eSIM management platform — specifically the SM-DP+ and the provisioning systems — to receive real-time notifications of profile lifecycle events. This integration enables the LI system to detect when a target activates or deactivates a profile and to update the interception configuration accordingly. Without this integration, the LI system may lose track of the target during profile transitions, creating gaps in interception coverage.

eSIM-only MVNOs should also consider the implications of profile portability. A subscriber may download profiles from multiple eSIM-only MVNOs on the same device, switching between them as needed. The MVNO can only intercept communications on its own profile — when the subscriber switches to a different MVNO’s profile, the original MVNO loses visibility. Coordinating interceptions across multiple eSIM-only MVNOs requires law enforcement to issue separate orders to each operator, which can be operationally challenging.

Target Identification in an eSIM-Only Environment

Target identification for eSIM-only MVNOs follows the same general principles as for other operators, but with some specific nuances. MSISDN-based targeting is straightforward if the target retains the same number. However, eSIM-only MVNOs may offer services that facilitate frequent number changes — virtual numbers, temporary numbers, or multi-number services — that complicate MSISDN-based targeting.

IMSI-based targeting is tied to the specific profile. Each eSIM profile has its own IMSI, and if the target obtains a new profile (even from the same MVNO), the IMSI will change. The LI system must be capable of tracking profile replacements and updating the interception configuration with the new IMSI.

IMEI-based targeting provides device-level identification that is independent of the eSIM profile. This can be particularly valuable in the eSIM-only context, as the IMEI remains constant even when profiles are changed. However, IMEI-based interception may capture communications from all profiles on the device, not just the target MVNO’s profile, which raises questions about the scope of the interception and the handling of communications associated with other operators.

Technical Solutions

eSIM-only MVNOs should implement several technical measures to address the LI challenges specific to their model. First, integrate the LI system with the eSIM management platform to receive real-time profile lifecycle notifications. This is the foundation for maintaining interception continuity across profile changes. Second, implement multi-identifier correlation in the LI system, enabling the system to track a target across different MSISDNs, IMSIs, and IP addresses associated with different profiles. Third, ensure that the LI system can generate IRI events for profile management activities, providing law enforcement with visibility into the target’s profile behaviour.

Fourth, implement automated processes for updating interception configurations when profile changes occur. Manual reconfiguration is too slow for the dynamic eSIM environment, where profile changes can happen in seconds. The LI system should detect a profile change, identify the new identifiers, and update the interception configuration automatically, with appropriate logging and notification to the LI operations team.

Fifth, ensure that your digital KYC processes produce reliable identity information that can be used to support law enforcement identification of targets. The quality of your subscriber data directly affects the effectiveness of lawful interception and your ability to respond to law enforcement requests for subscriber information.

Regulatory Engagement

eSIM-only MVNOs should engage proactively with their national regulator to discuss the specific LI challenges of the eSIM-only model. Regulators may not yet have fully considered the implications of eSIM-only operations for lawful interception, and proactive engagement demonstrates good faith compliance while also helping to shape realistic regulatory expectations. Operators should document their approach to LI compliance in the eSIM-only context, including any limitations and the measures they are taking to address them.

Conclusion

eSIM-only MVNOs face unique LI challenges related to digital identity verification, profile lifecycle management, target identification, and the dynamic nature of the eSIM environment. These challenges are addressable through a combination of technical integration, automated processes, robust KYC procedures, and proactive regulatory engagement. By building LI considerations into the design of their eSIM-only operations from the outset, MVNOs can achieve compliance while maintaining the operational agility and digital-first experience that define their business model.

Operational Considerations

Beyond the technical infrastructure, eSIM-only MVNOs must establish operational processes that account for the specific characteristics of their business model. Staff training should cover the eSIM lifecycle and its implications for LI, including how profile downloads, activations, deactivations, and deletions affect active interceptions. The LI operations team must understand the relationship between the eSIM management platform and the LI system and must be able to troubleshoot issues that arise at the intersection of these systems.

Incident response procedures should address eSIM-specific scenarios, such as a target rapidly cycling through multiple profiles, a mass profile event affecting LI system performance, or a failure in the integration between the eSIM management platform and the LI system. These scenarios are unique to the eSIM environment and require specific response procedures that traditional LI incident response plans may not cover.

Documentation is particularly important for eSIM-only MVNOs, given the novelty of the business model and the evolving regulatory landscape. Maintain comprehensive documentation of your eSIM LI architecture, processes, and testing results. This documentation demonstrates compliance to regulators and provides a foundation for responding to questions about how your LI capability addresses the specific challenges of the eSIM-only model. As the regulatory framework for eSIM evolves, well-documented operators will be better positioned to adapt to new requirements and to demonstrate that they have taken a thoughtful, proactive approach to compliance.

The relationship between the eSIM-only MVNO and its host MNO also requires specific attention in the eSIM context. The MNO’s network may see eSIM profile events differently from traditional SIM events, and the interception mechanisms may need to account for these differences. eSIM-only MVNOs should work closely with their host MNOs to ensure that the LI arrangements cover the full range of eSIM-specific scenarios and that the interception capability is validated through comprehensive testing that includes eSIM profile lifecycle events alongside traditional interception scenarios.

The eSIM MVNO market is growing rapidly, and regulatory requirements are evolving accordingly. Every eSIM MVNO must ensure their LI infrastructure can handle the unique identification challenges of remote SIM provisioning.

Related Articles

For further reading on related topics, explore these articles:

External Resources

The following external resources provide additional context and official documentation:

Scroll to Top
ICS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.