On September 18, 2026, the Telecom Regulatory Authority of India finalised the Telecom Commercial Communications Customer Preference (Third Amendment) Regulations, 2026. The rules amend the 2018 framework governing spam calls and messages. They follow a draft published on March 13, a comment window that closed on April 19, counter-comments on May 4 and an open house on June 3, according to MediaNama's report. Several provisions are good policy. The restriction on caller-ID apps is not.
The strongest case for the rules
The regulator's logic deserves a fair hearing. Spam in India is a scale problem: TechCrunch reports that users encountered roughly 42 billion spam calls in 2025. Enforcement machinery sits with telecom operators, who hold the registration data for senders. Feeding app-collected reports into the operators' blockchain-based platform for commercial communications widens the pool of evidence available for action against spammers. Pricing automated bulk calls at up to 5 paise a minute, in line with commercial SMS rates, makes robocalling less free. And a formal appeal route for wrongly closed complaints, with a 15-day window for the consumer and 15 days for the telco to respond, fixes a real accountability gap.
What the rules actually do
According to MediaNama, the finalised amendments:
- Bar call-management apps such as Truecaller from tagging, blocking or filtering calls from the 140xx, 1600xx and 1601xx series, and require them to share user spam reports with the operators' DLT platform rather than keeping them in-app.
- Add a Regulation 21A requiring the receiving telecom provider to flag suspected spam using AI/ML and share that information with the sending provider within two hours.
- Allow charges of up to 5 paise a minute on application-to-person calls, with pre-declaration to operators.
- Require suspension of accounts for header or content-template misuse immediately and no later than six hours after discovery, with notice to the sender within 48 hours.
- Give consumers 15 days to appeal a wrongly closed complaint.
The pricing, appeal and suspension provisions target the supply of spam and make senders accountable. That is where regulation belongs.
Where the design goes wrong
The app restriction works the other way. Those number series are designated for commercial calls, and the premise is that they are registered and therefore trustworthy. But registration is not the same as consent. A registered sender can still call a person who has opted out, and the person who receives the call is the best judge of whether it was wanted. Stopping an app from labelling or filtering those calls removes a user's tool exactly where the regulator has decided the sender deserves the benefit of the doubt.
The data-sharing mandate raises a second concern. TechCrunch reports that Truecaller called the requirement a one-way exchange that is anti-competitive: the company's crowdsourced reports flow to operators, with nothing coming back. It says India accounts for over 350 million of Truecaller's more than 500 million monthly active users, and that the app blocked nearly 12 billion spam calls in 2025. Whatever one thinks of the company's incentives, those figures suggest the app is doing a large share of the filtering the regulation is meant to achieve. TechCrunch also notes that policy experts see ambiguity over which data must be transmitted, how user consent works and how the rules would be enforced against entities that are not telecom licensees.
The consent question matters as well. A user who flags a call inside an app does so under that app's terms. Redirecting the report into a telco-maintained platform, rather than letting it stay with the service the user chose, changes who holds that data without the user necessarily having agreed.
The AI flagging provision needs guardrails
Regulation 21A rests on the sound idea that operators, who see network traffic, should detect spam. As the rules were described at finalisation, AI flags alone cannot trigger action against a number. That safeguard is important and should be kept. False positives in number-level blocking hit legitimate businesses, from banks sending fraud alerts to clinics confirming appointments. A two-hour sharing deadline is workable; a two-hour deadline for disruptive action on model output alone would not be. The regulator should publish how flags are validated, how many are overturned and how a wrongly flagged sender gets relief.
A proportionate alternative
The proportionate fix is narrow. Keep the 5 paise pricing, the six-hour suspension rule and the appeal right. Let apps continue to tag and filter calls from the commercial series, since users can override a label at will. Make the data-sharing obligation reciprocal and consent-based: apps share aggregated or user-approved reports, and operators return the sender-registration status the apps need to label accurately. Publish flagging error rates so the public can test whether the system works.
TRAI's consultation drew 29 comments and 3 counter-comments, from operators, industry bodies, technology firms and financial institutions, per its consultation page. The final text shows the operators' enforcement model prevailed over the app-based one. The better regulatory outcome is a layered system in which network-level enforcement and user-level choice reinforce each other. A country that receives tens of billions of spam calls a year cannot afford to disable one of its most widely used defences.