HomeBlogsUncategorizedTRAI Compliance for Outbound Calls & Business Messaging in India: Your 2026 Checklist

TRAI Compliance for Outbound Calls & Business Messaging in India: Your 2026 Checklist

If your business dials customers or sends them a single promotional SMS, RCS card or WhatsApp message, you are operating inside one of the strictest commercial-communication regimes in the world. TRAI compliance for outbound calling is no longer a box your telecom vendor quietly ticks on your behalf — in 2026, the liability sits squarely with you, the sender.
The rules tightened sharply with the Second Amendment to the TCCCPR in February 2025 and a draft Third Amendment is now working its way through consultation. Enforcement is faster, penalties are steeper and the old “we didn’t know” defence is gone. This guide breaks down exactly what you need to have in place — voice and messaging — and ends with a checklist you can action today.

What TRAI compliance for outbound calling actually governs

TRAI — the Telecom Regulatory Authority of India — controls how businesses reach customers over telecom networks through the Telecom Commercial Communications Customer Preference Regulations (TCCCPR), first notified in 2018. This is the backbone of UCC regulation in India, where UCC stands for Unsolicited Commercial Communication — the “spam” the framework exists to stamp out.
The regulation applies the moment a call or message is commercial: promoting a product, service, or offer. You cannot escape it by labelling a promotional message as “engagement” or hiding it under a generic service tag. If it sells, it’s regulated.

Two ideas sit at the centre of every obligation that follows:

• Registration. Businesses (Principal Entities), their telemarketers, sender identities and message templates must be registered on the blockchain-based DLT (Distributed Ledger Technology) platform before anything goes out.

• Consent and preference. Recipients control what they receive. Promotional contact requires explicit, documented consent and no promotional call or message may reach a number registered on the DND (Do Not Disturb) list, formally the National Customer Preference Register (NCPR).

The 2025–2026 shifts you can’t afford to miss

The regulatory ground moved under everyone’s feet in the last 18 months. Three changes matter most.
The Second Amendment (12 February 2025) rewrote the enforcement playbook. It cut complaint-processing timelines dramatically, lowered the complaint threshold that triggers action against a sender from ten to five and capped the validity of explicit consent for commercial transactions at just seven days. It also mandated AI and ML-based spam-detection systems across every access provider, and critically gave TRAI the power to act directly against a sender or telemarketer rather than routing everything through the telecom operator first.

Standardised sender identifiers arrived alongside it. SMS headers now carry a clear category prefix — P for promotional, S for service, T for transactional and G for government — so operators (and their AI filters) can instantly classify traffic.

The draft Third Amendment (13 March 2026) signals where things are heading. It proposes advance declaration of Application-to-Person (A2P) automated voice calls, a possible termination charge on A2P automated calls to disincentivise bulk robo-dialling, mandatory AI/ML detection of suspected spammers with KYC re-verification and a regulatory sandbox for testing new anti-spam tools. Consultation closed in April 2026 and a final rule is expected during the year. Treat these as the direction of travel and build for them now.

The takeaway is simple: enforcement in 2026 arrives faster and hits harder than at any point since 2018.
OBD compliance in India: the outbound calling rules
OBD — outbound dialling — is where most contact centres get caught out. OBD compliance in India rests on four pillars.

1. Use the correct number series. Every commercial voice call must originate from the right registered series. Promotional and telemarketing calls, including auto-dialler and robocall traffic, must route through the 140-series. Transactional and service calls — think BFSI alerts and account updates — must use the 160-series (the 1600 numbering). Mixing them up isn’t a technicality; using the wrong series is treated as an unregistered-telemarketer violation.

2. Scrub against DND before every promotional campaign. DND registrations change daily, so a list that was clean last month is not clean today. Scrub your contact list against the NCPR before each promotional run. Businesses relying on third-party or purchased lead lists carry the highest risk here, because those numbers may have opted into DND after the list was sold.

3. Hold valid, current consent. For promotional outbound calling you need explicit consent, ideally captured through TRAI’s Digital Consent Acquisition (DCA) framework so the record is verifiable and portable across operators. Remember the seven-day validity cap on explicit consent for commercial transactions — consent is not a one-time formality you collect and forget.

4. Treat AI voice agents exactly like human agents. TRAI draws no distinction between a Voice AI bot and a human placing a commercial call. Every obligation — registered number series, DND scrubbing, valid consent, auditable logs — applies identically. Because AI agents operate at scale, a single misconfigured workflow can generate violations at machine speed.

Penalties for getting OBD wrong are per-call, not per-campaign. A single non-compliant blast can multiply into a large number of individual violations, with financial penalties running into lakhs and, for repeat offenders, the very real prospect of suspension from the DLT platform — which blocks all your commercial communication, transactional traffic included.

DLT compliance for RCS, WhatsApp and SMS

Here is where a lot of Indian businesses get the wrong advice. DLT compliance is not a single rulebook that covers every channel identically. Let’s be precise.
SMS runs entirely on DLT. Every commercial SMS must pass through a TRAI-approved DLT platform. That means:
• Principal Entity registration — your business is verified on the ledger.
• Header (Sender ID) approval — your six-character sender ID is registered and mapped to a category.
• Template registration — the message content is pre-approved; you cannot send free-form promotional copy.
• Consent binding — the PE ID and Template ID travel with every API request, or the message fails scrubbing at the operator.

Practical rules that trip people up: promotional SMS is confined to a daytime window (broadly 10:00 AM–9:00 PM IST) and dropped, not queued, outside it; call-to-action URLs must be whitelisted full links, never shorteners; and headers left unused for around 90 days are automatically deactivated.
RCS Business Messaging is not governed by SMS DLT headers, but it is not a free channel either. RCS runs through its own onboarding via Google and telecom operators, with verified sender branding and template-style content controls. The disciplines mirror DLT — verified sender, pre-approved content, documented consent and TRAI has signalled tighter integration of RCS into the wider anti-spam framework. If you’ve done DLT for SMS, the logic will feel familiar.

WhatsApp sits outside TRAI’s DLT framework entirely. It operates on Meta’s global infrastructure under Meta’s Business Messaging Policy, which is why “DLT for WhatsApp” is one of the most persistent myths in Indian B2B messaging. What WhatsApp does require is just as strict in practice: a WhatsApp Business API account through an approved BSP, documented opt-in from every recipient, pre-approved message templates in Meta’s categories (Marketing, Utility, Authentication, Service), and a healthy quality rating — because block-and-report rates directly throttle your ability to send.

The strategic point for 2026: whether the channel is SMS, RCS or WhatsApp, the underlying obligations converge — verified sender, approved content and provable consent. TRAI’s roadmap points toward unified, cross-channel consent and detection, so building one clean consent and template discipline now future-proofs all three channels.

Consent-based messaging and the DPDP overlap

Consent-based messaging is the thread that runs through every rule above and in 2026 it has a second layer: the Digital Personal Data Protection (DPDP) Act, 2023.
TRAI governs the telecom channel; DPDP governs the personal data behind it. You can be perfectly DLT-registered and still fall foul of DPDP if your consent isn’t collected properly. DPDP demands consent that is free, specific, informed and unambiguous — burying opt-in inside fine-print terms and conditions does not meet the standard. It also requires purpose limitation and deletion of data once the stated purpose is fulfilled.

For outbound calling and messaging, that means: capture consent for a clearly stated purpose, keep timestamped records of exactly what the customer agreed to, honour withdrawal immediately and don’t retain recordings or contact data beyond the purpose you collected them for. Enforcement of DPDP’s penalty provisions is being phased in, but the substantive consent obligations are already live — the businesses that wait for the final penalty notification are the ones building risk.

Your 2026 TRAI compliance checklist

Work through this before your next campaign.

Registration & identity
• Principal Entity registered on a TRAI-approved DLT platform
• Voice: outbound numbers registered on the correct series — 140 for promotional, 160 for transactional/service
• SMS: headers (Sender IDs) approved and mapped to the right category (P/S/T/G)
• SMS: every template pre-registered and approved
• RCS: sender onboarded and verified via Google/operator; templates approved
• WhatsApp: Business API live through an approved BSP with approved templates

Consent
• Explicit, purpose-specific consent captured (ideally via DCA) for all promotional contact
• Consent records stored with timestamp and exact wording
• Explicit-consent validity tracked against the seven-day commercial cap
• One-click opt-out / STOP honoured immediately across every channel

Pre-send hygiene
• Contact list scrubbed against DND/NCPR before every promotional run
• Promotional sends scheduled inside the permitted daytime window
• CTA URLs whitelisted (full links, no shorteners); no promotional content mixed into service/transactional templates
• Third-party lead lists re-scrubbed, never trusted as “clean”

Operations & audit
• AI voice agents held to the same standard as human agents
• Auditable call and message logs retained
• Data retention aligned with DPDP purpose limitation
• A process to track TRAI amendments — the Third Amendment is coming

Compliance is an infrastructure decision, not a policy memo

The businesses that struggle with TRAI compliance for outbound calling are the ones treating it as paperwork bolted on after the fact. The ones that thrive bake it into the platform: number series, DND scrubbing, template registration, and consent capture handled automatically on every call and message, with logs ready for audit.
That’s the model ExpressIVR is built on. Our cloud contact centre and CPaaS platform ships with DLT-aware messaging, correct number-series routing for OBD, DND scrubbing, and consent-managed voice, SMS, RCS, and WhatsApp — so compliance runs in the background while your team focuses on the conversation.
Want to see how compliant outbound calling and messaging works end to end? Talk to the ExpressIVR team and we’ll walk you through it.
________________________________________
This article is a practical overview of the regulatory landscape as of 2026 and is not legal advice. Confirm your specific obligations with a qualified advisor and refer to TRAI’s published regulations at trai.gov.in for the authoritative text.


Leave a Reply

Your email address will not be published. Required fields are marked *

× How can I help you?