Is Your eSIM Data Actually Private

Is Your eSIM Data Actually Private? A Security Deep Dive

Peter Basil - BazTel
Peter
Is Your eSIM Data Actually Private

Most articles on eSIM privacy answer the wrong question. They tell you the profile is encrypted with AES-256, cite the GSMA spec, and stop there. That part is true. It’s also not where the real risk sits.

I’ve tested eSIMs across more than 30 countries. I also run the numbers side of a travel eSIM business, so I read provider privacy policies most travelers never open. Here’s the uncomfortable finding: eSIM cryptography isn’t the weak point. A 2025 academic study found that your traffic can quietly pass through a country you’ve never visited. A reseller you’ve never heard of can often see far more about your device than you’d expect.

This piece separates two layers. First, the cryptography, which genuinely works. Second, the business layer built around it, which doesn’t always deserve the same trust. Both matter if you’re asking whether your eSIM data is actually private.

The Part That’s Genuinely Secure: How eSIM Encryption Works

When you activate an eSIM, your device does more than download a file. It completes a cryptographic handshake with a server called an SM-DP+, short for Subscription Manager – Data Preparation Plus. This is the GSMA-standardized system that prepares, encrypts, and delivers your carrier profile.

A few things happen here that a physical SIM card never did:

  • Your profile is encrypted specifically for your device’s eUICC chip before it leaves the server. Intercepting it in transit wouldn’t make it usable anywhere else.
  • Your device and the SM-DP+ server authenticate each other first, using certificates issued by the GSMA’s own Certificate Issuer. This closes off most man-in-the-middle attacks.
  • Every provisioning message is cryptographically signature-chained. A replayed or substituted message simply fails verification.

This is defined under GSMA specification SGP.22. Every legitimate consumer eSIM provider has to comply with it to get profiles onto Apple, Samsung, and Google devices. So if your question is “can someone clone or intercept my eSIM profile mid-transfer,” the honest answer is: very unlikely, under normal conditions. This layer isn’t where I’d focus your worry.

The Part Nobody Talks About: Where Your Traffic Actually Goes

Here’s the finding that changed how I think about this topic. Researchers at Northeastern University published a paper called “eSIMplicity or eSIMplification? Privacy and Security Risks in the eSIM Ecosystem.” It was presented at the 2025 USENIX Security Symposium, one of the most respected venues in computer security research. The team purchased and tested eSIM profiles from 25 real travel providers, including several household names.

Their core finding wasn’t about broken encryption. It was about routing transparency. In many cases, a traveler’s public IP address didn’t match their actual physical location at all. Some profiles routed traffic through infrastructure in China or Hong Kong, regardless of where the customer stood, because the underlying network relies on centralized international gateways rather than local breakout points. One Ireland-based provider’s traffic was even observed exiting through a Chinese mobile network. A phone sitting in Europe appeared, digitally, to be in China.

That matters for two reasons. First, jurisdiction. Your traffic briefly falls under the legal and surveillance environment of whichever country it’s routed through, usually without any disclosure. Second, access. The same study found that some resellers can see subscriber identifiers, send commands to a device, and assign public IP addresses, all without meaningful notice to the end user. This industry is stacked with resellers of resellers. Most travelers have no idea how many hands their connection actually passes through.

None of this required breaking the encryption described above. This is a structural, business-layer problem. It isn’t a cryptographic one.

What an eSIM Provider Actually Collects About You

Separate from routing, there’s the data your provider gathers directly. This varies by company, but the typical categories look like this:

  • Purchase data — your email, payment details, and sometimes device identifiers like the IMEI or EID.
  • Activation data — which device installed the profile, a timestamp, and often an approximate location at the moment of activation.
  • Usage data — how much data you used, connection timestamps, and which underlying carrier network carried your traffic.
  • Advertising identifiers — on some travel eSIM apps, your Apple IDFA or Google Advertising ID. These enable cross-app tracking unless you’ve opted out in your device settings.

There’s good news too, and it rarely gets airtime. Most travel eSIMs don’t require in-store ID verification. That makes a purchase closer to anonymous than a postpaid contract SIM in many countries. Each new eSIM plan is also effectively a fresh subscriber identity, not a phone number you’ve held for a decade. That makes it structurally harder for any single party to build a long-term profile of your travel history.

eSIM vs Physical SIM: Which Is Actually More Private?

This is the comparison most articles skip. It doesn’t have a clean winner.

A physical SIM tied to your home carrier and identity document creates one persistent identifier. It follows you across every trip and every login. An eSIM used for travel is more disposable by design. You install and delete profiles per destination, which limits how much any single provider learns about your overall travel history.

But a physical SIM has one real advantage: the chain of custody is simple. You know exactly who issued it and who’s billing you. Travel eSIM reseller chains, as the Northeastern study documented, are murkier. Murkier usually means less accountability if something goes wrong with your data.

The realistic takeaway: eSIMs aren’t inherently more or less private than physical SIMs. They just shift where the risk sits. Instead of one carrier you signed a contract with, it’s a chain of resellers and network partners you likely never see.

Can eSIMs Be Tracked? Separating Fact From SIM-Specific Myth

Short answer: your location can be estimated from cellular connectivity. But that’s true of physical SIMs too. It isn’t an eSIM-specific weakness.

Two mechanisms matter here. The first is ordinary network-level location approximation. Any carrier can do this based on which cell towers your device connects to. It exists regardless of SIM format, and carriers use it for billing, lawful interception, and network management. The second is IMSI catchers, sometimes called Stingrays. These devices impersonate real cell towers to harvest nearby device identifiers. They work against eSIMs and physical SIMs identically, because both broadcast an IMSI to the network on connection.

For the average tourist checking maps and messaging friends, this tracking risk hasn’t really changed. For journalists, activists, or anyone with a higher threat model, the SIM format matters less than you’d think. GPS permissions, app-level location access, and which networks you connect through carry more weight than whether the card is physical or embedded.

A Practical Checklist Before You Buy a Travel eSIM

Given the routing findings above, here’s what I actually check now. This applies whether I’m buying an eSIM or reviewing one on the provider side:

  1. Read the privacy policy for routing disclosures, not just data collection. Most policies mention what they collect. Few mention where your traffic physically travels.
  2. Check who operates the underlying network, not just the brand on the app. A reseller’s privacy posture is only as good as the carriers behind it.
  3. Look for a clean installation method. Manual QR-code emails and third-party scanning apps add another link to the reseller chain. A direct install through the provider’s own app removes one intermediary.
  4. Turn off ad tracking identifiers before installing any travel eSIM app. Use Limit Ad Tracking on iOS, or opt out of interest-based ads on Android.
  5. Delete unused profiles after your trip instead of leaving them installed indefinitely.

At BazTel, we handle activation through a one-click, no-QR-code install rather than routing you through third-party scanning tools. Convenience is part of that decision. Fewer intermediaries touching your activation data is the other part. It’s one input, not the whole answer — the routing checks above still matter, regardless of which eSIM plan you choose.

Frequently Asked Questions

Is eSIM data encrypted?

Yes. Profile delivery uses AES-256 and RSA-2048 style encryption under the GSMA’s SGP.22 standard. It also uses mutual authentication between your device and the provisioning server. This part of the system is well audited and hard to break under normal conditions.

Can an eSIM be cloned or hacked remotely?

Not through the standard provisioning process. Each profile is cryptographically bound to your specific eUICC chip. Isolated eUICC vulnerabilities have been responsibly disclosed and patched before, which is normal for any widely deployed security standard. Exploiting one takes far more than intercepting network traffic.

Does an eSIM reveal my location to my provider?

Your provider can typically see an approximate location at activation, plus ongoing connection timestamps. This matches what any mobile carrier can already see. It isn’t unique to eSIM technology.

Is eSIM more private than a physical SIM?

It depends on your use case. eSIMs limit how much any single provider learns over time, since profiles are more disposable. But travel eSIM reseller chains can be less transparent than a direct carrier contract. Neither format is a clean privacy upgrade over the other.

Should I worry about eSIM apps routing my traffic through other countries?

It’s worth checking, especially for sensitive travel. A 2025 Northeastern University study found this happens more often than providers disclose. For typical browsing and messaging, though, the practical impact for most travelers is limited.

Peter

Blog Author

Peter

I'm Peter, the founder of BazTel. I built this company at the intersection of two things I know well: finance and travel. Before starting BazTel, I worked in investment analytics at State Street, one of the world's largest custodian banks, and later at TCorp, the New South Wales Government's investment…

eSIM Specialist