• Sun. Sep 20th, 2026

India Expands Anti-Spam Regulations to Require App Data Sharing, Drawing Truecaller’s Criticism

India has significantly expanded its national anti-spam framework, introducing stringent new mandates that require caller-ID and call-management applications to share user-generated spam reports directly with telecom operators. The regulatory shift, which bridges the gap between third-party applications and telecommunications infrastructure, has immediately drawn sharp pushback from industry players, most notably Truecaller, which has criticized the mandate as anti-competitive.

On Friday, the Telecom Regulatory Authority of India (TRAI), the country’s central telecommunications regulator, officially amended the rules governing commercial communications. Under the updated framework, any call-identification or call-management application that permits users to flag incoming calls as spam or junk is now legally mandated to forward those specific reports to a centralized, blockchain-based platform maintained by the nation’s telecom operators. This distributed ledger platform serves as the core infrastructure used across the industry to track commercial communications and enforce regulatory anti-spam measures.

According to statements from TRAI, the core objective of the policy change is to dramatically broaden the pool of spam intelligence available for regulatory enforcement and corrective action against malicious spammers. By connecting the decentralized data and crowd-sourced reports collected independently by mobile applications directly with the telecom industry’s official enforcement infrastructure, the regulator hopes to create a unified defense mechanism against escalating telemarketing fraud.

However, the directive has faced immediate commercial and philosophical resistance. Speaking to TechCrunch, popular Stockholm-based caller-ID platform Truecaller characterized the new data-sharing requirement as a "one-way exchange" that heavily favors telecom incumbents. The company argued that the rule is inherently "anti-competitive," asserting that it effectively forces call-management applications to surrender commercially valuable data and proprietary user insights to telecom operators without receiving a fair or balanced exchange of data in return.

The stakes are exceptionally high for Truecaller, given its massive footprint in the region. India represents Truecaller’s single largest market by a wide margin. The platform commands well over 350 million users within the country, contributing significantly to its global user base of more than 500 million monthly active users. To protect this vast network, Truecaller relies on a combination of community-sourced reports, automated detection algorithms, and various behavioral signals to accurately identify and intercept unwanted or malicious calls.

The introduction of these rules coincides with a period where India is grappling with unsolicited commercial communications and fraudulent calling campaigns at an unprecedented scale. In a comprehensive annual report published in February, Truecaller revealed that its users in India encountered approximately 42 billion spam calls over the course of 2025 alone. This staggering figure encompasses calls that were successfully blocked, interactively labeled, or simply ignored by recipients. Furthermore, the company reported that its internal defense mechanisms successfully blocked nearly 12 billion spam calls during that same annual period.

Tension between Truecaller and the Indian regulatory authorities is not a novel development, as the Swedish firm has previously clashed with TRAI over the optimal strategy for handling unwanted communications. The company had previously raised strong objections against regulatory restrictions that barred call-management apps from automatically applying spam labels to calls originating from certain government-designated number ranges. At the time, Truecaller argued that granting exemptions to specific number series created dangerous loopholes, potentially allowing unwanted promotional or commercial calls to bypass its filters entirely and reach unsuspecting consumers.

Despite these previous objections, the amendments released on Friday explicitly retain that specific restriction. The updated rules legally prohibit call-management applications from executing blanket blocks, generalized filtering, or automatic spam-tagging on calls originating from designated number series that are legally allocated for promotional, service, and transactional communications. Nevertheless, TRAI clarified that individual users retain the autonomous right to manually choose to block such communications directly on their personal devices if they so desire.

A spokesperson for Truecaller expressed ongoing frustration with the policy direction, noting that while user data and sentiment clearly demonstrate that commercial spam has skyrocketed as a result of granting what they perceive as a free pass to certain telemarketers, the company has nevertheless maintained full compliance with the directives since late last year.

Industry analysts are already analyzing the broader legal, technical, and operational ramifications of the new regulatory architecture. Sumeysh Srivastava, a partner at New Delhi-based consulting firm The Quantum Hub who leads its telecom-regulation policy work, observed that the latest policy change effectively bridges two distinct technological layers within the digital ecosystem. Traditionally, telecom operators provide the foundational network infrastructure and manage the blockchain-based anti-spam system, whereas caller-ID applications operate independently on top of that network layer to identify, analyze, and filter calls for individual end-users.

Srivastava noted to TechCrunch that this structural bridge raises notable technical and jurisdictional questions. These include determining the precise reporting standards that third-party applications will be forced to follow, as well as figuring out how effectively the mandate can be enforced against commercial technology companies that do not hold traditional telecommunications licenses themselves.

An earlier draft of the policy published in March had proposed leveraging India’s broader Information Technology laws to establish and enforce the necessary compliance mechanisms. However, Srivastava pointed out that the newly released official announcement remained conspicuously silent on whether that specific enforcement mechanism had been retained in the final iteration of the rules.

Further complicating the regulatory landscape is ambiguity surrounding the exact scope of information that applications will be obligated to hand over. Kazim Rizvi, the founding director of New Delhi-based policy think tank The Dialogue, explained to TechCrunch that forcing an app to transmit a discrete, individual spam report generated by a user is materially different from compelling it to surrender its broader internal datasets, proprietary reputation signals, or complex analytical systems. Rizvi emphasized that the new rules will ultimately require explicit legal clarity regarding what specific categories of information must be transmitted, how end-users must be properly notified or asked for explicit consent, and how that sensitive data can subsequently be retained and utilized by telecom operators.

When approached for clarification, TRAI declined to respond to specific inquiries from TechCrunch regarding the exact nature of the information apps will be mandated to share, nor did they clarify whether the rule would extend to native spam-reporting features embedded directly into major smartphone operating systems and built-in system dialers like Android and iOS.

New rules for AI-powered calls

Beyond the data-sharing mandates for caller-ID apps, the comprehensive regulatory amendments also target the explosive growth of automated software and artificial intelligence voice agents being leveraged to place outbound calls. Under the updated framework, any calls initiated automatically by systems without a human operator directly dialing the digits will now formally fall under TRAI’s application-to-person (A2P) regulatory framework. This sweeping definition explicitly includes robocalls, as well as communications utilizing prerecorded audio or fully synthetic artificial voices.

Moving forward, corporate entities and organizations utilizing such automated systems are legally required to formally declare their deployment of these technologies, along with the specific phone numbers involved, to their respective telecom operators in advance. TRAI has explicitly warned that any A2P calls made without prior declaration will be automatically classified and treated as illegal spam.

Srivastava noted that the critical legal test under the new framework will focus primarily on the methodology of how a call is initiated, rather than simply evaluating whether the conversation utilizes an AI-generated voice. This distinction introduces a degree of regulatory uncertainty surrounding hybrid, AI-assisted calls where software may handle aspects of the outreach but a human is still involved in the initiation process.

Satya N. Gupta, a former additional secretary at TRAI, offered additional perspective to TechCrunch, explaining that the newly minted rules do not fundamentally restrict commercial enterprises from leveraging artificial intelligence or other advanced automated calling technologies. Instead, the framework establishes a disclosure regime, making it mandatory for businesses to transparently declare their usage of such tools to the underlying telecom carriers.

As part of the restructured A2P framework, telecom operators will also be legally permitted to levy a termination charge of up to 5 paise, equivalent to approximately 0.052 cents, per minute on qualifying A2P calls. However, the regulations provide exemptions for calls executed through specific designated number ranges.

Rizvi cautioned that the breadth of the new definitions could introduce unintended consequences for standard enterprise operations. He noted that the updated classification could potentially encompass routine calls placed using business software even when a human employee remains actively involved in the conversation, such as standard outbound outreach from contact centers and click-to-call digital services. Without clearer statutory distinctions, Rizvi warned, the newly expanded A2P category risks becoming significantly broader than the specific regulatory harms it was originally designed to address.

By Nana Wu

Leave a Reply

Your email address will not be published. Required fields are marked *