v1.0.0 launch

GDPR + Corporate eSIM Data-Usage Reporting: The IT Compliance Checklist (2026)

Before shipping a corporate eSIM program to an EU-based workforce, IT + DPO sign-off requires clear answers on data residency, ICCID-to-employee mapping, retention windows, DSAR handling, and processor agreements. This is the 2026 IT compliance checklist — what to require in the contract, which questions materially differ between vendors, and why a partner-API eSIM is often the cleaner GDPR posture than the BYOD roaming baseline it replaces.

By · Founder, YonoSIMLinkedIn ↗·Published August 10, 2026·10 min read

Summary

A corporate eSIM program is materially cleaner for GDPR posture than the BYOD roaming baseline it replaces — because the provider tracks ICCIDs, not personally-identifying data, and the corporate customer signs a DPA that governs exactly what happens to usage logs. This is the IT + DPO sign-off checklist for a 2026 rollout: what to require in the vendor contract, what materially differs between providers, and which specific compliance questions to close before the DPO green-lights the deployment.

Why partner-API eSIM is cleaner than the BYOD baseline

The counterintuitive framing: introducing a new vendor to the data-processing chain usually adds compliance surface area. Corporate eSIM is the opposite — it reduces the surface because it replaces something worse. Compare what data exists under each model:

Data collectedBYOD (personal carrier)Corporate eSIM (partner API)
Employee name / home addressYes (billing account)No (ICCID-scoped)
Phone numberYesNo (data-only eSIM, no MSISDN)
Per-session location (cell-tower)Yes (per-tower log)Country-level only
Call/SMS metadataYesNo (data-only)
Data byte-count per sessionYesAggregated per-order
Retention window24+ months (carrier-controlled)12 months (contractually bounded)
Corporate customer signs DPANo (employee-carrier relationship)Yes
Corporate can compel deletion (DSAR)No — employee must request from carrierYes — corporate-initiated via API

The DPO's job under BYOD roaming is essentially impossible — the carrier's data-handling terms are between the carrier and the individual employee, and the corporation has no standing to control them. Under a corporate eSIM program, the DPO signs the DPA that governs the data lifecycle and has API-level control over deletion. This is why enterprise IT + compliance teams frequently end up championing a formal eSIM program even when the initial motivation was cost.

The 8-item DPO sign-off checklist

Before rolling out to production, the DPO should have written answers to these 8 questions from the vendor. Star each one on procurement's evaluation sheet:

  1. Data residency. Where is per-order usage log data physically stored? For EU employees, this must be EU/EEA or GDPR-adequate (UK, Switzerland). YonoSIM Business Scale ships an EU-region option (Frankfurt / eu-central-1).
  2. ICCID-to-employee mapping. Where does the linkage from ICCID → employee identity live? Correct answer: in the corporate customer's systems, NOT the vendor's. The vendor should have zero knowledge of the employee's name, personal email, phone number, or HR record.
  3. Sub-processors. Which downstream MVNO, hosting, or payment providers process the data? YonoSIM's DPA lists Stripe (payments), AWS (hosting), and the specific upstream MVNOs by region.
  4. Retention window. How long are usage logs held? 12 months is standard; anything longer requires justification. Automated deletion after retention should be verifiable in the vendor's DPA.
  5. DSAR SLA. On employee request for access or deletion, how quickly can the vendor comply? GDPR baseline is 30 days from request to fulfillment. Require this in the contract with a specific API endpoint or support workflow.
  6. Encryption at rest + in transit. AES-256 at rest, TLS 1.3 in transit. Standard, but verify — some smaller vendors still ship TLS 1.2 minimum.
  7. Breach notification. Contractual commitment to notify the corporate customer within 24 hours of a confirmed data breach. GDPR requires 72 hours to authorities — the 24-hour internal window gives your legal team time to coordinate.
  8. Audit rights. Corporate customer has the right to audit vendor's compliance (typically via SOC 2 Type II report on request, plus quarterly compliance attestation for Scale/Enterprise tiers).

Vendor comparison: compliance package specifically

RequirementAiralo for TeamsYonoSIM Business
DPA available for reviewPost-NDAOn request, pre-contract
EU-region data storageYesYes — Scale tier ($25k+/mo)
SOC 2 Type IIYes (post-NDA)Yes (Scale + Enterprise)
Retention window (usage logs)Not publicly disclosed12 months (standard) / custom (Enterprise)
DSAR SLA30 days (standard)30 days (contract) / self-serve API (Enterprise)
Breach notification windowNot publicly disclosed24 hours
Sub-processor listPost-NDAPublic trust page + DPA
Compliance package reviewPost-contractPre-contract (during sandbox)

The functional gap is small — both vendors meet enterprise compliance baselines. The procurement-experience gap is real: YonoSIM's compliance package is available for DPO review during the sandbox phase, which lets legal validate terms before your team commits weeks to a specific vendor. Under Airalo, the DPA review typically happens after the Partner Agreement is signed, which creates a switching-cost cliff if the DPA turns out to have unacceptable terms.

The specific policy language other Fortune 500s ship

Sample corporate policy clauses from three anonymized Fortune 500 rollouts (2024–2026):

## International connectivity policy (excerpt)

Data provisioning: All international business trips of 1+ days
receive a company-provisioned eSIM issued at booking confirmation
through the [TMC] integration with [YonoSIM Business]. Personal
carrier international roaming (Verizon TravelPass, AT&T Day Pass,
etc.) is not reimbursable for trips where an eSIM has been issued.

Data quota: 5 GB per 7-day period (standard); 10 GB per 7-day
period for Sales, Field Services, and Customer Success roles.
Overages fire an approval workflow via Slack via the
'order.data.low' webhook at 80% quota; top-up decisions are made
within 15 minutes to preserve traveler productivity.

Data privacy: Usage data is stored in EU-region infrastructure
under the terms of the Data Processing Agreement with [vendor].
Individual employee identity is not shared with the vendor —
mapping from eSIM to employee is maintained only in corporate
systems. Data subject access requests are handled per the DSAR
procedure in the Employee Privacy Notice with a 30-day SLA.

Retention: Usage logs are retained for 12 months for billing
reconciliation and fraud investigation, then automatically deleted.
Employees may request earlier deletion via the DSAR procedure.

FAQ

QIs a corporate eSIM GDPR-compliant by default?

AA partner-API corporate eSIM is materially cleaner than the BYOD roaming baseline it replaces, but 'compliant' depends on the specific processing agreement you sign. What matters: (1) data residency — usage logs stored in EU-region infrastructure for EU employees, (2) ICCID-scoped identity — the provider tracks the ICCID assignment, not the employee's personal identity, (3) documented retention windows for usage logs, (4) DSAR (data subject access request) handling procedure, (5) processor agreement (DPA) covering both provider ↔ corporate customer and any sub-processors. All five are standard-issue items in a Scale-tier vendor contract; verify all five during procurement.

QWhat data does an eSIM provider actually collect about an employee?

AUnder a partner-API model like YonoSIM, the provider stores per-order: ICCID, plan SKU, country/region, activation timestamp, usage-byte counters, refund state. The provider does NOT store the employee's name, email address (unless the partner passes it in metadata for delivery routing), personal identity, or location beyond country-level. The mapping from ICCID → employee lives in your corporate systems, not the provider's. This is the key privacy advantage over BYOD roaming, where the personal carrier records every session tied to the employee's personal identity + line number.

QWhat retention window should we require in the contract?

AStandard operational retention is 12 months for usage-logs (needed for billing reconciliation + fraud investigation). Set a hard cap in the DPA and require automated deletion after that window, unless a specific legal-hold or ongoing dispute exists. For DSAR handling: 30-day response window from request to fulfillment is the GDPR baseline; require the vendor to complete deletion + written confirmation inside that window. YonoSIM's DPA (available on Growth tier and up) ships with 12-month standard retention + 30-day DSAR SLA.

QHow does data residency work for a global program?

AThe regulatory requirement is that usage data for EU-employee eSIMs be processed and stored in EU or GDPR-adequate jurisdictions (Switzerland, UK, etc.). Under YonoSIM, the EU-region option (Scale tier) routes API calls, webhook deliveries, and log storage through Frankfurt (AWS eu-central-1) with no cross-region replication. Employees in APAC or Americas can route through their own regional infrastructure. The mapping to region is set per-API-key, not per-order, so your integration doesn't need per-employee routing logic.

QWhat about DSAR (data subject access request) handling?

AThe employee has the right to request access to their data, correction, and deletion. Because the eSIM provider doesn't hold personally-identifying data (only ICCID + usage), the DSAR flow is: (1) employee requests via your HRIS/support, (2) your team looks up the ICCID(s) issued to that employee's trip history, (3) you request deletion from the vendor via a documented API endpoint or support ticket, (4) vendor deletes usage logs for the requested ICCIDs and confirms in writing. The 30-day GDPR window is comfortably achievable — YonoSIM ships a self-serve DELETE /v1/orders/:id/gdpr endpoint on Enterprise tier.

QIs BYOD roaming better or worse for GDPR posture?

AMaterially worse in most cases. Under BYOD, the employee's personal carrier records every session (data, calls, SMS, location) tied to their personal identity, phone number, and home address. That data lives at the carrier for the carrier's retention period (often 24+ months), is subject to that carrier's DPA (which the corporate customer is not party to), and creates a per-employee data trail the corporate customer cannot compel deletion of. A dedicated corporate eSIM with ICCID-scoped identity and a corporate-signed DPA is a cleaner posture — the DPO can actually control what happens to the data.

Bottom line

A corporate eSIM program is cleaner for GDPR posture than the BYOD roaming baseline it replaces — the vendor holds only ICCID-scoped data, retention is contractually bounded, and the corporate DPO has API-level control over deletion. The 8-item sign-off checklist above is what procurement should require in any vendor comparison. YonoSIM Business is the only major vendor that makes the compliance package available for DPO review during the sandbox phase — which is often the single procurement-experience decider between vendors that are otherwise functionally equivalent. Enterprise sandbox at yonosim.com/developers (24-hour turnaround); compliance package on request.

Back to the Corporate travel hub for the full buyer's guide. Vendor cost + feature comparison is in the Airalo for Teams alternative spoke.