Understanding MVNO lawful interception responsibilities is essential before entering any market. One of the most common — and most consequential — questions in the MVNO business model is who bears the legal responsibility for lawful interception. The answer seems straightforward at first glance, but in practice it is layered with complexity. The legal obligation, the technical capability, the contractual arrangements, and the practical execution often involve both the MVNO and the host MNO, and the boundaries between their respective responsibilities can be unclear, contested, or simply unaddressed in the commercial agreements that govern their relationship.
This article provides a detailed examination of the legal, technical, and contractual dimensions of LI responsibility in the MVNO-MNO relationship, drawing on the regulatory frameworks of major European markets and the practical experience of operators navigating these issues.
MVNO Lawful Interception Responsibilities
In European telecommunications regulation, the obligation to support lawful interception attaches to the entity that is registered or notified as a provider of public electronic communications services. This is the fundamental principle: if you are registered with the national regulatory authority as a service provider, you bear the legal responsibility for ensuring that lawful interceptions can be carried out on your subscribers’ communications.
For MVNOs that hold their own regulatory registration — which is the case for most MVNOs operating in European markets — this means that the LI obligation rests with the MVNO, not with the host MNO. The fact that the MVNO uses the MNO’s network infrastructure does not transfer the obligation. The regulator looks at who provides the service to the end user, and that provider is responsible for compliance.
This principle is consistently applied across European jurisdictions, though the specific legal provisions vary. In Germany, the TKG assigns interception obligations to the provider of the publicly available telecommunications service. In the Netherlands, the Telecommunicatiewet places the obligation on the provider of the public electronic communications service. In France, the CPCE requires operators declared with ARCEP to maintain interception capabilities. The specific language differs, but the outcome is the same: the MVNO bears the obligation.
There are limited exceptions. Some jurisdictions allow or recognise arrangements where the MNO performs interception on behalf of the MVNO, but even in these cases, the MVNO typically retains ultimate legal responsibility for ensuring that the interception is performed correctly. The MVNO cannot simply point to the MNO and claim that compliance is the MNO’s problem.
The Technical Reality: Capability Resides with the MNO
While the legal obligation rests with the MVNO, the technical capability to intercept communications often resides with the host MNO. This is because the MVNO’s subscribers communicate over the MNO’s radio access network, and their traffic traverses the MNO’s core network infrastructure. The interception points — the network elements where traffic can be captured and duplicated — are typically within the MNO’s domain.
This creates a fundamental tension: the entity with the obligation (the MVNO) does not have the capability, and the entity with the capability (the MNO) does not have the obligation. Resolving this tension requires either the MVNO to acquire its own technical capability (by deploying its own core network elements and interception infrastructure), or the MNO to provide interception services to the MVNO as part of the wholesale arrangement.
The appropriate solution depends on the MVNO’s architecture. Full MVNOs that operate their own core network have direct control over the interception points and can deploy their own LI systems. Light MVNOs and resellers that rely entirely on the MNO’s infrastructure must depend on the MNO for interception capability, which requires formal agreements and technical arrangements.
The Contractual Dimension
The contract between the MVNO and the MNO is the primary mechanism for bridging the gap between obligation and capability. A well-drafted MVNO agreement will include specific provisions addressing lawful interception, covering the responsibilities of each party, the services that the MNO will provide, the response times and service levels, the technical interfaces and data formats, the cost allocation, and the liability for non-compliance.
In practice, many MVNO agreements are silent on lawful interception or address it only in general terms. This is a significant risk for the MVNO. If the agreement does not explicitly require the MNO to provide interception services, the MVNO may find itself unable to comply with its legal obligations and unable to compel the MNO to assist. Negotiating clear, comprehensive LI provisions should be a priority in any MVNO agreement negotiation.
Key provisions that should be included in the agreement are the scope of interception services provided by the MNO, activation timelines that meet regulatory requirements, data formats and delivery mechanisms for IRI and CC, processes for handling urgent and emergency interception requests, confidentiality obligations for all parties, audit rights enabling the MVNO to verify compliance, liability allocation for failures in the interception process, and procedures for regulatory changes requiring updates to the LI capability.
Models of LI Responsibility Allocation
Several models for allocating LI responsibility between the MVNO and MNO are used in practice. The first is the MNO-performed model, where the MNO performs interception on behalf of the MVNO. The MNO receives the interception order (either directly from law enforcement or via the MVNO), activates the intercept on its network, and delivers the intercepted data to law enforcement. The MVNO provides administrative support and coordinates with law enforcement. This model is common for light MVNOs and resellers and requires a comprehensive agreement with the MNO and validated technical arrangements.
The second model is the MVNO-performed model, where the MVNO deploys its own LI infrastructure — including a mediation function and handover interfaces — and performs interception independently. This model requires the MVNO to have sufficient network infrastructure (typically its own core network elements) to serve as interception points. It gives the MVNO full control over the interception process but requires significant technical investment.
The third model is a hybrid approach, where certain aspects of interception are handled by the MNO and others by the MVNO. For example, the MNO might handle the technical capture of CC from the network, while the MVNO handles IRI generation from its own subscriber management systems and delivers both to law enforcement through its own mediation platform. This model requires close technical coordination between the MVNO and MNO but can provide a practical balance between capability and control.
Regulatory Expectations and Enforcement
Regulators across Europe have become increasingly attentive to the LI compliance of MVNOs. As the MVNO market has grown and diversified, regulators have recognised that MVNOs cannot be overlooked in the enforcement of interception obligations. Several national regulators have issued specific guidance or requirements addressed to MVNOs, making clear that the MVNO’s dependency on the MNO does not diminish the MVNO’s responsibility for compliance.
In enforcement actions, regulators and law enforcement agencies will hold the MVNO responsible for any failure to comply with a valid interception order, regardless of whether the failure was caused by the MVNO’s own systems or by the MNO’s failure to provide the agreed interception services. The MVNO may have contractual recourse against the MNO, but this does not protect the MVNO from regulatory sanctions or criminal liability.
This underscores the importance of ensuring that the MVNO-MNO arrangement for lawful interception is robust, tested, and documented. An arrangement that works on paper but has not been validated through testing and operational experience provides a false sense of security.
Practical Recommendations
For MVNOs, the practical recommendations are clear. Accept that the legal responsibility for lawful interception is yours, regardless of your network architecture or your relationship with the MNO. Review your wholesale agreement and ensure that LI is comprehensively addressed, with clear responsibilities, service levels, and technical specifications. If you rely on the MNO for interception, validate the arrangement through end-to-end testing with the national technical authority. Maintain your own documentation, audit trails, and operational procedures, even if the MNO performs the technical interception. And invest in understanding the LI landscape in your market, so that you can engage knowledgeably with regulators, law enforcement, and your MNO partner.
Conclusion
The question of MVNO versus MNO responsibility for lawful interception has a clear legal answer — the MVNO bears the obligation — but a complex practical reality. Bridging the gap between legal obligation and technical capability requires careful contractual arrangements, validated technical solutions, and proactive engagement with regulators. MVNOs that approach this challenge systematically, with clear agreements and tested infrastructure, will be well positioned to meet their obligations. Those that leave it unaddressed will discover the consequences at the worst possible time — when a law enforcement agency presents an interception order and expects it to be executed.
For MNOs that host MVNOs, the recommendation is equally straightforward: recognise that your MVNO partners have legal obligations that depend on your technical cooperation, and build this cooperation into your wholesale offering. Providing clear, well-defined LI services to your MVNO partners protects both parties — the MVNO can meet its legal obligations, and the MNO avoids the reputational and practical complications that arise when an MVNO on its network fails to comply with an interception order. A collaborative approach to LI compliance serves the interests of the entire ecosystem — operators, regulators, and law enforcement alike.
The question of MVNO lawful interception responsibility is ultimately a legal one that varies by jurisdiction. Operators must obtain clear legal advice on their MVNO lawful interception obligations in each market.
Related Articles
For further reading on related topics, explore these articles:
- The MVNO LI Checklist: Everything You Need Before Going Live
- How to Handle LI When Your Core Network Is Outsourced or Hosted
- Roaming and Lawful Interception: What Happens When the Target Is Abroad?
External Resources
The following external resources provide additional context and official documentation:



