GDPR + Corporate eSIM Data-Usage Reporting: The IT Compliance Checklist (2026)
Before shipping a corporate eSIM program to an EU-based workforce, IT + DPO sign-off requires clear answers on data residency, ICCID-to-employee mapping, retention windows, DSAR handling, and processor agreements. This is the 2026 IT compliance checklist — what to require in the contract, which questions materially differ between vendors, and why a partner-API eSIM is often the cleaner GDPR posture than the BYOD roaming baseline it replaces.
Summary
A corporate eSIM program is materially cleaner for GDPR posture than the BYOD roaming baseline it replaces — because the provider tracks ICCIDs, not personally-identifying data, and the corporate customer signs a DPA that governs exactly what happens to usage logs. This is the IT + DPO sign-off checklist for a 2026 rollout: what to require in the vendor contract, what materially differs between providers, and which specific compliance questions to close before the DPO green-lights the deployment.
Why partner-API eSIM is cleaner than the BYOD baseline
The counterintuitive framing: introducing a new vendor to the data-processing chain usually adds compliance surface area. Corporate eSIM is the opposite — it reduces the surface because it replaces something worse. Compare what data exists under each model:
| Data collected | BYOD (personal carrier) | Corporate eSIM (partner API) |
|---|---|---|
| Employee name / home address | Yes (billing account) | No (ICCID-scoped) |
| Phone number | Yes | No (data-only eSIM, no MSISDN) |
| Per-session location (cell-tower) | Yes (per-tower log) | Country-level only |
| Call/SMS metadata | Yes | No (data-only) |
| Data byte-count per session | Yes | Aggregated per-order |
| Retention window | 24+ months (carrier-controlled) | 12 months (contractually bounded) |
| Corporate customer signs DPA | No (employee-carrier relationship) | Yes |
| Corporate can compel deletion (DSAR) | No — employee must request from carrier | Yes — corporate-initiated via API |
The DPO's job under BYOD roaming is essentially impossible — the carrier's data-handling terms are between the carrier and the individual employee, and the corporation has no standing to control them. Under a corporate eSIM program, the DPO signs the DPA that governs the data lifecycle and has API-level control over deletion. This is why enterprise IT + compliance teams frequently end up championing a formal eSIM program even when the initial motivation was cost.
The 8-item DPO sign-off checklist
Before rolling out to production, the DPO should have written answers to these 8 questions from the vendor. Star each one on procurement's evaluation sheet:
- Data residency. Where is per-order usage log data physically stored? For EU employees, this must be EU/EEA or GDPR-adequate (UK, Switzerland). YonoSIM Business Scale ships an EU-region option (Frankfurt / eu-central-1).
- ICCID-to-employee mapping. Where does the linkage from ICCID → employee identity live? Correct answer: in the corporate customer's systems, NOT the vendor's. The vendor should have zero knowledge of the employee's name, personal email, phone number, or HR record.
- Sub-processors. Which downstream MVNO, hosting, or payment providers process the data? YonoSIM's DPA lists Stripe (payments), AWS (hosting), and the specific upstream MVNOs by region.
- Retention window. How long are usage logs held? 12 months is standard; anything longer requires justification. Automated deletion after retention should be verifiable in the vendor's DPA.
- DSAR SLA. On employee request for access or deletion, how quickly can the vendor comply? GDPR baseline is 30 days from request to fulfillment. Require this in the contract with a specific API endpoint or support workflow.
- Encryption at rest + in transit. AES-256 at rest, TLS 1.3 in transit. Standard, but verify — some smaller vendors still ship TLS 1.2 minimum.
- Breach notification. Contractual commitment to notify the corporate customer within 24 hours of a confirmed data breach. GDPR requires 72 hours to authorities — the 24-hour internal window gives your legal team time to coordinate.
- Audit rights. Corporate customer has the right to audit vendor's compliance (typically via SOC 2 Type II report on request, plus quarterly compliance attestation for Scale/Enterprise tiers).
Vendor comparison: compliance package specifically
| Requirement | Airalo for Teams | YonoSIM Business |
|---|---|---|
| DPA available for review | Post-NDA | On request, pre-contract |
| EU-region data storage | Yes | Yes — Scale tier ($25k+/mo) |
| SOC 2 Type II | Yes (post-NDA) | Yes (Scale + Enterprise) |
| Retention window (usage logs) | Not publicly disclosed | 12 months (standard) / custom (Enterprise) |
| DSAR SLA | 30 days (standard) | 30 days (contract) / self-serve API (Enterprise) |
| Breach notification window | Not publicly disclosed | 24 hours |
| Sub-processor list | Post-NDA | Public trust page + DPA |
| Compliance package review | Post-contract | Pre-contract (during sandbox) |
The functional gap is small — both vendors meet enterprise compliance baselines. The procurement-experience gap is real: YonoSIM's compliance package is available for DPO review during the sandbox phase, which lets legal validate terms before your team commits weeks to a specific vendor. Under Airalo, the DPA review typically happens after the Partner Agreement is signed, which creates a switching-cost cliff if the DPA turns out to have unacceptable terms.
The specific policy language other Fortune 500s ship
Sample corporate policy clauses from three anonymized Fortune 500 rollouts (2024–2026):
## International connectivity policy (excerpt) Data provisioning: All international business trips of 1+ days receive a company-provisioned eSIM issued at booking confirmation through the [TMC] integration with [YonoSIM Business]. Personal carrier international roaming (Verizon TravelPass, AT&T Day Pass, etc.) is not reimbursable for trips where an eSIM has been issued. Data quota: 5 GB per 7-day period (standard); 10 GB per 7-day period for Sales, Field Services, and Customer Success roles. Overages fire an approval workflow via Slack via the 'order.data.low' webhook at 80% quota; top-up decisions are made within 15 minutes to preserve traveler productivity. Data privacy: Usage data is stored in EU-region infrastructure under the terms of the Data Processing Agreement with [vendor]. Individual employee identity is not shared with the vendor — mapping from eSIM to employee is maintained only in corporate systems. Data subject access requests are handled per the DSAR procedure in the Employee Privacy Notice with a 30-day SLA. Retention: Usage logs are retained for 12 months for billing reconciliation and fraud investigation, then automatically deleted. Employees may request earlier deletion via the DSAR procedure.
FAQ
QIs a corporate eSIM GDPR-compliant by default?
AA partner-API corporate eSIM is materially cleaner than the BYOD roaming baseline it replaces, but 'compliant' depends on the specific processing agreement you sign. What matters: (1) data residency — usage logs stored in EU-region infrastructure for EU employees, (2) ICCID-scoped identity — the provider tracks the ICCID assignment, not the employee's personal identity, (3) documented retention windows for usage logs, (4) DSAR (data subject access request) handling procedure, (5) processor agreement (DPA) covering both provider ↔ corporate customer and any sub-processors. All five are standard-issue items in a Scale-tier vendor contract; verify all five during procurement.
QWhat data does an eSIM provider actually collect about an employee?
AUnder a partner-API model like YonoSIM, the provider stores per-order: ICCID, plan SKU, country/region, activation timestamp, usage-byte counters, refund state. The provider does NOT store the employee's name, email address (unless the partner passes it in metadata for delivery routing), personal identity, or location beyond country-level. The mapping from ICCID → employee lives in your corporate systems, not the provider's. This is the key privacy advantage over BYOD roaming, where the personal carrier records every session tied to the employee's personal identity + line number.
QWhat retention window should we require in the contract?
AStandard operational retention is 12 months for usage-logs (needed for billing reconciliation + fraud investigation). Set a hard cap in the DPA and require automated deletion after that window, unless a specific legal-hold or ongoing dispute exists. For DSAR handling: 30-day response window from request to fulfillment is the GDPR baseline; require the vendor to complete deletion + written confirmation inside that window. YonoSIM's DPA (available on Growth tier and up) ships with 12-month standard retention + 30-day DSAR SLA.
QHow does data residency work for a global program?
AThe regulatory requirement is that usage data for EU-employee eSIMs be processed and stored in EU or GDPR-adequate jurisdictions (Switzerland, UK, etc.). Under YonoSIM, the EU-region option (Scale tier) routes API calls, webhook deliveries, and log storage through Frankfurt (AWS eu-central-1) with no cross-region replication. Employees in APAC or Americas can route through their own regional infrastructure. The mapping to region is set per-API-key, not per-order, so your integration doesn't need per-employee routing logic.
QWhat about DSAR (data subject access request) handling?
AThe employee has the right to request access to their data, correction, and deletion. Because the eSIM provider doesn't hold personally-identifying data (only ICCID + usage), the DSAR flow is: (1) employee requests via your HRIS/support, (2) your team looks up the ICCID(s) issued to that employee's trip history, (3) you request deletion from the vendor via a documented API endpoint or support ticket, (4) vendor deletes usage logs for the requested ICCIDs and confirms in writing. The 30-day GDPR window is comfortably achievable — YonoSIM ships a self-serve DELETE /v1/orders/:id/gdpr endpoint on Enterprise tier.
QIs BYOD roaming better or worse for GDPR posture?
AMaterially worse in most cases. Under BYOD, the employee's personal carrier records every session (data, calls, SMS, location) tied to their personal identity, phone number, and home address. That data lives at the carrier for the carrier's retention period (often 24+ months), is subject to that carrier's DPA (which the corporate customer is not party to), and creates a per-employee data trail the corporate customer cannot compel deletion of. A dedicated corporate eSIM with ICCID-scoped identity and a corporate-signed DPA is a cleaner posture — the DPO can actually control what happens to the data.
Bottom line
A corporate eSIM program is cleaner for GDPR posture than the BYOD roaming baseline it replaces — the vendor holds only ICCID-scoped data, retention is contractually bounded, and the corporate DPO has API-level control over deletion. The 8-item sign-off checklist above is what procurement should require in any vendor comparison. YonoSIM Business is the only major vendor that makes the compliance package available for DPO review during the sandbox phase — which is often the single procurement-experience decider between vendors that are otherwise functionally equivalent. Enterprise sandbox at yonosim.com/developers (24-hour turnaround); compliance package on request.
Back to the Corporate travel hub for the full buyer's guide. Vendor cost + feature comparison is in the Airalo for Teams alternative spoke.