Skip to content
Compliance September 11, 2026 12 min read

India Outbound Calling Compliance: TRAI (2026)

India's TCCCPR and DPDP rules for outbound calls: DLT registration, 1909 preferences, the 140, 1600 and 1601 series, and the 2025 auto-dialler change.

D
September 11, 2026

Quick answer

Outbound commercial calling in India is regulated by the Telecom Regulatory Authority of India (TRAI) under the Telecom Commercial Communications Customer Preference Regulations, 2018, heavily amended on 12 February 2025, while the Digital Personal Data Protection Act, 2023 governs the personal data behind the campaign. Consent is explicit, recorded on the operator-run distributed ledger rather than in your own CRM, and screening runs against the Preference Register that subscribers manage through the short code 1909 and the TRAI DND app, with granular choices by content category, mode, time band and day type. There is no single national calling window: TRAI blocks four of nine selectable time bands by default for every subscriber, which leaves 10:00 to 21:00 as the residual default-permitted window.

India has the most machinery of any outbound market in Asia, and it moved twice in the last eighteen months. February 2025 rewrote the auto-dialler rule, the consent lifetime and the complaint window, and through 2026 service and transactional voice calls have been migrating onto dedicated number series on fixed, sector-by-sector dates. If your Indian dialling plan predates those changes, it is out of date.

At a Glance

ItemPosition in India
RegulatorTelecom Regulatory Authority of India (TRAI), भारतीय दूरसंचार विनियामक प्राधिकरण. Numbering series are allocated by the Department of Telecommunications (DoT), दूरसंचार विभाग. Data protection sits with the Data Protection Board of India
Law and dateTelecom Commercial Communications Customer Preference Regulations, 2018 (6 of 2018), notified 19 July 2018; Second Amendment Regulations, 2025 (1 of 2025), 12 February 2025; Digital Personal Data Protection Act, 2023 (No. 22 of 2023), assented 11 August 2023; Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), gazetted 13 November 2025
Licence neededNo TRAI telemarketing licence. Registration with an Access Provider, recorded on the DLT platform, is mandatory, and since 2025 the registration process includes physical verification of the entity. An unregistered Sender may have all its telecom resources suspended or disconnected
Calling hours (time zone)Nine customer-selectable time bands, of which 00:00 to 06:00, 06:00 to 08:00, 08:00 to 10:00 and 21:00 to 24:00 are default OFF for every customer whether or not any preference is registered. The residual default-permitted window is therefore 10:00 to 21:00. No instrument names a time zone. Day types are selectable but none is blocked by default
Consent modelExplicit consent verified directly from the recipient and recorded by a Consent Registrar on a distributed ledger, or inferred consent. Since 2025, consent does not extend beyond the duration or discharge of the contract, and explicit consent used to justify a service or transaction message lasts seven days
Do Not Call listThe Preference Register, held as a distributed ledger, registered through short code 1909 by SMS, call, IVRS or USSD, or through the TRAI DND app. Checking is performed by a registered Scrubber, including verification of time bands and day types, not by the caller directly
Caller ID rulePromotional voice calls run on the 140 series; promotional auto-dialler and robocalls are 140 only. Service and transactional voice calls run on 1600 for Government and BFSI entities, with adoption mandatory on fixed dates from 1 January 2026, and on the 1601 series for other sectors from the Direction of 10 August 2026. SMS uses 11-character registered headers
Recording ruleNot published in TCCCPR. Neither the 2018 regulations nor the 2025 amendment contains a call-recording notice or consent duty or a retention period. That is a negative from those two instruments, and sectoral conduct rules from RBI or IRDAI were not examined
Data protection lawDigital Personal Data Protection Act, 2023, with the 2025 Rules commencing in tranches. Rule 4 on Consent Manager registration commences 13 November 2026; the operative notice, security, breach, retention, rights and transfer rules commence eighteen months after publication, in May 2027
PenaltiesDPDP penalties reach ₹250 crore for security failures and ₹200 crore for an unreported breach, with ₹50 crore for any other breach of the Act or Rules. Under TCCCPR the sanction that reaches a caller is suspension, blacklisting for at least one year on repeat header violations, and a restoration charge of ₹5,000 per telecom resource capped at ₹5 lakh, where each DID on a PRI or SIP trunk counts as a separate resource
Abandoned call limitNot published by TRAI. The regulations define an abandoned call and refer to limits provided in the regulations or Codes of Practice, but state no percentage. Any figure you are quoted comes from an operator Code of Practice, not from TRAI

Who Regulates Outbound Calling in India

TRAI made the Telecom Commercial Communications Customer Preference Regulations, 2018 under section 36 read with sections 11(1)(b)(v) and 11(1)(c) of the TRAI Act, 1997, notified on 19 July 2018. Numbering allocations come from the Department of Telecommunications, and TRAI issues Directions that turn a DoT allocation into an operational deadline. Personal data sits under a separate statute and a separate body, the Data Protection Board of India, and neither regime substitutes for the other.

There is no telemarketing licence to apply for. The duty is registration with an Access Provider, recorded on the distributed ledger platform. The 2025 amendment made the consequence blunt: no Sender who is not registered with any Access Provider may make a commercial communication, and if it does, all of its telecom resources may be suspended or disconnected. Every commercial communication must then travel on a registered header or on numbering resources from a special series assigned for commercial communication.

The 2025 amendment tightened the gate. Registration now includes physical verification of the entity. Registered Senders and telemarketers must self-certify their registration details, headers, content templates and consent templates annually, and failing to do so triggers automatic suspension. The delivery chain is capped at two telemarketers, one aggregator function and one delivery function, so long subcontracting chains no longer work. Suspension is portable too: when one Access Provider suspends or blacklists an entity and updates the ledger, every other Access Provider must stop its traffic within 24 hours and must not re-register it during the suspension.

Consent and Opt-Out

India separates explicit consent from inferred consent, and records the explicit kind outside your own systems. Explicit consent means consent verified directly from the recipient in a robust and verifiable manner and recorded by a Consent Registrar, on a Distributed Ledger for Consent maintained on permissioned and private networks. Your CRM record is evidence of your process; the ledger record is what counts.

February 2025 changed the shelf life of consent twice over. First, consent no longer outlives the relationship: a proviso now states that consent shall not extend beyond the duration or discharge of the contract between the Sender and the Recipient. Second, explicit consent used to justify a service or transaction-facing message is valid for seven days, or as TRAI later directs. TRAI's own explanatory note is explicit about why, saying the validity is limited to a maximum of seven days to prevent misuse of explicit consent so acquired. For commercial messages, consent may now also be clearly and reasonably inferred from the registered content template.

Consent acquisition itself is migrating to an operator-run Consent Registration Function. TRAI found that Senders and principal entities, banks included, had not onboarded that function, leaving infrastructure underused and non-compliant traffic proliferating, and directed a regulatory sandbox pilot with banks regulated by the Reserve Bank of India. Under the pilot, every recorded consent triggers a notification SMS from a 127xxx short code with a one-tap way to opt out, and if the customer opts out the consent is deleted from the ledger. Consumers can list their permissions by sending "My consents" to that short code and must be reminded fortnightly how to revoke. Bulk-uploaded legacy consent requires an online undertaking as to its genuineness and correctness.

The operational consequence is stated directly in the Direction: consent state is shared in real time so that entities rely exclusively on legitimate and active consent records and promptly discontinue outreach based on revoked or expired consents. A nightly export is not compliance. Separately, Access Providers must run the Customer Preference Registration Facility 24 hours a day, seven days a week and free of cost, through SMS or a call to 1909, IVRS, USSD, an approved mobile app and an OTP-authenticated web portal.

Do-Not-Call

India's do-not-call system is not a single opt-out list. It is a Preference Register held as a Distributed Ledger for Preference, where a subscriber's choices are granular by content category, by mode, by time band and by day type. Registration and change run through short code 1909 over SMS, voice, IVRS and USSD, or through the TRAI DND app.

The checking duty is discharged by a registered Scrubber rather than by you. Scrubbing is defined as comparing a target list of telephone numbers against preferences and consent, and a Scrubber is an entity registered with the Access Providers and authorised to perform that function. It verifies time bands and day types against each target number, must identify and report probable instances of requests received for scrubbing lists of phone numbers, and is designed to be privacy-preserving, generating virtual identities and tokens for each number rather than exposing the list.

Preferences must take effect fast: recorded or modified preferences are given effect in near real time, such that nothing is delivered or blocked contrary to a subscriber's preference after 24 hours. There is no mandated periodic re-scrub interval for a Sender's own list, because the duty is framed as scrubbing per campaign against a register that is never more than a day stale.

Two 2025 changes matter here. The complaint window doubled: a subscriber or recipient now has seven days from receipt to complain, where the 2018 text allowed three. And a new regulation 34A stops call-management applications from tagging, blocking, filtering or restricting incoming calls or messages that originate from the designated commercial number series or from Government, which protects the legitimate use of those series.

Calling Hours and Days

India does not publish a national calling window as a sentence. It publishes a table. Schedule-II lists nine time bands: 00:00 to 06:00, 06:00 to 08:00, 08:00 to 10:00, 10:00 to 12:00, 12:00 to 14:00, 14:00 to 16:00, 16:00 to 18:00, 18:00 to 21:00 and 21:00 to 24:00. Note-1 to that schedule states that bands (i), (ii), (iii) and (ix) shall be default OFF for all customers irrespective of the status of registration, including those who have registered no preference at all, unless the customer has registered a preference and switched them on.

Those four bands are 00:00 to 06:00, 06:00 to 08:00, 08:00 to 10:00 and 21:00 to 24:00. The arithmetic remainder, the window left permitted by default, is 10:00 to 21:00. TRAI nowhere writes "10:00 to 21:00" as a stated rule, so treat it as the consequence of the Note rather than as a quoted statutory window, and remember that a customer who has switched a band on has widened it for themselves. Day of week is also a customer preference: subscribers may block any weekday, public and national holidays, or all day types, but no day type is default OFF. No instrument names a time zone, so the zone you apply is a configuration decision rather than a regulator-sourced fact.

Frequency is complaint-driven. Where complaints against a Sender come from ten or more recipients over the last seven days, the originating Access Provider puts that Sender under a Usage Cap, valid until the investigation is complete or 30 days from the date the restriction took effect, whichever is earlier. The numeric value of the cap lives in operator Codes of Practice, not in the regulation.

Caller ID and Number Presentation

This is where an Indian campaign most often fails, because the correct number now depends on what kind of call you are making and who you are.

Promotional voice calls run from the 140 series, or any other series directed by TRAI or DoT. TRAI's 2025 explanatory memorandum goes further for automated dialling: promotional voice calls through auto-dialler or robocalls should be permitted through 140 series numbers only, while service and transactional voice calls through auto-dialler or robocalls should be permitted through 1600 or another series allotted for the purpose.

Service and transactional voice calls moved to the 1600 series on fixed dates. DoT conveyed its decision on 23 December 2024 to allocate 1600 exclusively for Government entities and the banking, financial services and insurance sector. TRAI's Direction of 19 November 2025 set the phases: commercial banks by 1 January 2026; large non-banking financial companies with asset size above ₹5,000 crore, payments banks and small finance banks by 1 February 2026; remaining non-banking financial companies, co-operative banks and regional rural banks by 1 March 2026. On the securities side, mutual funds and asset management companies by 15 February 2026 and Qualified Stockbrokers by 15 March 2026, with other SEBI-regulated intermediaries voluntary for the time being. Pension-side entities, central recordkeeping agencies and pension fund points of presence, by 15 February 2026. A further Direction of 16 December 2025 extended mandatory 1600 adoption to entities regulated by IRDAI; its internal phase dates are not published in the material reviewed here.

After those dates the number is the only lawful origin, and consent does not cure a wrong one. The Direction states that covered entities shall not be permitted to initiate any service or transactional voice call, even with the explicit or inferred consent of customers, from numbers other than those allocated under the 1600 series after the specified dates, and that a non-adopter generating a complaint is treated as an unregistered telemarketer.

August 2026 opened the door to everyone else. DoT allocated the 1601 series exclusively for service and transactional voice calls by entities outside BFSI and Government, and TRAI's Direction of 10 August 2026 set Phase-I to cover utilities, meaning electricity distribution, water, city gas and LPG, together with logistics and courier services, with onboarding within ninety days from the date of that letter. The numbers are assigned only as ten-digit numbers, and the Direction states that under no circumstances shall those resources be used for promotional voice calls.

For messaging, headers are 11-character alphanumeric strings registered on the ledger, and since 2025 the header must also declare its traffic type through a suffix of -P for promotional, -S for service, -T for transactional and -G for government. Headers that have not been used for ninety days are temporarily deactivated, so a dormant brand header is not a header you can rely on for a seasonal campaign.

Call Recording and Notices

Neither the 2018 regulations nor the 2025 amendment contains a call-recording notice duty, a consent duty for recording, or a retention period for recordings. The only mention of recorded calls in either document is a stakeholder comment about the possibility of scrubbing the contents of pre-recorded calls. That is a negative from the two instruments read and does not rule out a duty elsewhere in Indian law; sectoral conduct rules from the Reserve Bank of India or IRDAI were not examined here.

What does apply is the general data-protection position. A recording of an identifiable person is personal data, so the DPDP consent standard and the erasure duty described below reach it. Announce recording, keep the announcement in the language of the call, and set a retention period you can justify to a customer and to a sectoral regulator.

Messaging Rules for SMS and WhatsApp

SMS is governed by the same regime as voice and is in some ways stricter, because content is pre-registered. Traffic must run on a registered header carrying the correct traffic-type suffix, using registered content templates, from an entity registered on the ledger with an Access Provider. Consent for commercial messages may now be inferred from the registered content template, which is a concession on evidence rather than a relaxation of registration.

Enforcement on headers is severe and ecosystem-wide. Where a header is misused, traffic is suspended by all Access Providers immediately, and stays suspended until the Sender files a complaint with the law enforcement agencies under the relevant laws. Repeat violations result in blacklisting of the Sender across all Access Providers for a minimum period of one year.

TCCCPR does not address WhatsApp or other over-the-top channels, which sit outside the header and numbering machinery. The DPDP consent and withdrawal duties still reach the personal data behind such a campaign, and the platform's own business messaging policies apply commercially. Treat over-the-top messaging as governed by data-protection law and contract rather than by TCCCPR, and confirm before assuming a TCCCPR consent covers it.

Data Protection and Retention

The Digital Personal Data Protection Act, 2023 received assent on 11 August 2023. Its consent standard is demanding: consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose. Withdrawal must be as easy as giving, with the ease of withdrawal comparable to the ease with which consent was given.

One duty deserves the attention of any multilingual operation. The notice and every consent request must be available in English or any language specified in the Eighth Schedule to the Constitution. If you dial in Hindi, Tamil, Bengali or Marathi, the consent artefact must exist in a language the person can actually read.

Erasure is triggered by the earlier of withdrawal of consent or the point at which it is reasonable to assume the specified purpose is no longer being served, unless retention is legally required, and the Data Fiduciary must cause its processors to erase too. Cross-border transfer works as a blacklist rather than an adequacy whitelist: the Central Government may by notification restrict transfer to a named country or territory, and the Rules add a condition about making data available to a foreign State or its agencies. Whether any country has been notified as restricted is not published in the material reviewed.

Timing is the point most often missed. The Digital Personal Data Protection Rules, 2025 were gazetted on 13 November 2025, but they commence in three tranches. Rules 1, 2 and 17 to 21 commenced on publication. Rule 4, on Consent Manager registration, commences one year after publication, that is 13 November 2026, and requires a Consent Manager to be a company incorporated in India with net worth of not less than ₹2 crore. Rules 3 and 5 to 16, plus 22 and 23, commence eighteen months after publication, which falls in May 2027. Notice content, security safeguards, breach reporting, retention, data-principal rights and the cross-border condition therefore are not yet in force as at September 2026.

When they do commence, two retention numbers matter. Rule 8(3) sets a floor: a Data Fiduciary retains the personal data, associated traffic data and other processing logs for a minimum of one year from the date of processing, then erases them unless another law requires longer. The Third Schedule sets a ceiling of three years since last contact for named classes, being e-commerce entities with not less than two crore registered users in India and online gaming intermediaries with not less than fifty lakh registered users, with forty-eight hours of advance warning before erasure. Contact-centre operators are not a listed class. Breach notification runs to affected individuals without delay, to the Board without delay for a first description, and within seventy-two hours for the full report.

Penalties and Enforcement

The DPDP schedule of penalties is the largest exposure on paper: up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failing to notify a breach, up to ₹200 crore for breaching children's-data obligations, up to ₹150 crore for Significant Data Fiduciary obligations, up to ₹10,000 for breach of a Data Principal's duties, and up to ₹50 crore for breach of any other provision of the Act or the rules.

TCCCPR works differently. Its financial disincentives fall on Access Providers rather than on you, ranging from ₹1,000 per count for some reporting failures to ₹2 lakh for misreporting, rising to ₹5 lakh for a second consecutive month and ₹10 lakh for each month after that. The 2025 amendment added a ceiling in new regulation 28A: the total payable under regulations 27 and 28 together may not exceed ₹50 lakh per calendar month per licensed service area.

The sanction that reaches a dialler is the loss of resources. Suspension and blacklisting propagate across all Access Providers within 24 hours. On a successful representation, resources are restored on payment of a restoration charge of ₹5,000 per telecom resource, capped at ₹5 lakh in total. For anyone running a SIP trunk, the decisive sentence is that in the case of PRI or SIP trunks, each DID number is treated as a separate telecom resource, so a suspension across a large DID pool is expensive to unwind. Access Providers also hold a discretionary power to impose financial disincentives on registered Senders and telemarketers or to forfeit their security deposit; no schedule of amounts for that power is published.

What Changed in 2025 and 2026

The Second Amendment Regulations of 12 February 2025 are the centre of gravity. They came into force thirty days after gazette publication, with four provisions taking sixty days. The headline for a dialler team is the auto-dialler rule. The 2018 text prohibited a registered Sender from initiating calls with an auto-dialler that may result in silent or abandoned calls, subject to a proviso for Senders that had notified their Access Provider and kept abandoned calls within limits. The 2025 amendment substituted that regulation entirely with a notification duty: every Sender shall notify the Originating Access Provider, in advance, about the use of an auto-dialler or robocalls as well as the intended objective of such calls, in writing. The prohibition became a disclosure, which changes the paperwork more than it relaxes the risk, because complaint-triggered caps and resource suspension remain.

The same amendment doubled the complaint window from three days to seven, limited explicit consent on service and transaction messages to seven days, ended consent at the discharge of the contract, added physical verification at registration and annual self-certification with automatic suspension on failure, propagated suspension across operators within 24 hours, introduced the -P, -S, -T and -G header suffixes and ninety-day header dormancy, created regulation 34A against call-blocking applications, and capped financial disincentives at ₹50 lakh per month per licensed service area.

Through the rest of the period the Directions did the work: restoring disconnected resources on 7 April 2025, the consent sandbox with banks on 13 June 2025, misuse of headers and content templates on 18 November 2025, the 1600 series deadlines on 19 November 2025 with IRDAI entities added on 16 December 2025, the performance monitoring report on 27 January 2026, the location routing number amendment on 16 February 2026, machine-learning based detection intelligence shared between operators on 27 February 2026, and the 1601 series on 10 August 2026. The DPDP Rules were gazetted in between, on 13 November 2025, with staged commencement.

How the Platform Supports Each Rule

DialerBee provides compliance-supporting controls that help you meet the obligations above. India does not ship as a jurisdiction pack, so calling hours, do-not-call handling and consent are configured per tenant. The legal responsibility stays with the registered Sender.

Indian ruleControl that supports it
Bands outside 10:00 to 21:00 are OFF by defaultCalling windows configured per tenant and applied before the call is originated
Day-type preferences, including public holidaysCalling windows and campaign schedules held in configuration, not in a spreadsheet
Explicit consent with a seven-day life on service messagesConsent created, updated and revoked as auditable records, with the consent date held on the record
Rely only on active consent, never on a stale exportA revocation takes effect on the next attempt, not the next list refresh
Scrubbing against preferences before each campaignYour do-not-call list is imported once, then searched and checked on every attempt
Right number series per call type, 140, 1600 or 1601Caller-ID pools owned exclusively per tenant, mapped per campaign with verified ownership
Numbers held on your own operator relationshipsNumbers provisioned through your own carriers under BYOC, held in per-tenant pools
Advance notification of auto-dialler use and its objectiveCampaign modes and pacing set per campaign, with an audit trail on every rule override
Registered SMS headers and content templatesSMS sent under your own sender IDs from a reviewed template library
Consent notices in a language the person readsLanguage-aware AI across 11 languages, with UCS-2 aware SMS segment counting
Retention floors and erasure on withdrawalRecording with configurable retention, signed-URL playback, legal hold and per-tenant isolation

India Outbound Compliance Checklist

  • Register as a Sender with an Access Provider on the DLT platform, and complete the physical verification step.
  • Diarise your annual self-certification; missing it triggers automatic suspension of your registration, headers and templates.
  • Keep the delivery chain to no more than two telemarketers, one aggregator and one delivery function.
  • Notify your Originating Access Provider in writing, in advance, of any auto-dialler or robocall use and its intended objective.
  • Send promotional voice traffic only from the 140 series, and never from 1600 or 1601.
  • Move service and transactional calls onto 1600 or 1601 by the date that applies to your sector, and treat consent as no cure for a wrong series.
  • Scrub every target list against the Preference Register through a registered Scrubber before each campaign, including time-band and day-type checks.
  • Restrict dialling to 10:00 to 21:00 unless a customer has switched an additional band on.
  • Expire explicit consent on service and transaction messages after seven days, and end all consent when the underlying contract ends.
  • Rely on live consent state rather than on an overnight export, and stop outreach on a revoked or expired record.
  • Keep SMS headers active, since ninety days of disuse deactivates them, and carry the correct traffic-type suffix.
  • Publish consent notices in English or an Eighth Schedule language matching the language you dial in.
  • Plan for the DPDP Rules commencing in May 2027, with Consent Manager registration from 13 November 2026.
  • Count every DID on your PRI or SIP trunks as a separate telecom resource when you assess suspension and restoration risk.

Sources

  1. Telecom Commercial Communications Customer Preference Regulations, 2018 (6 of 2018), notified 19 July 2018. TRAI regulation PDF
  2. Telecom Commercial Communications Customer Preference (Second Amendment) Regulations, 2025 (1 of 2025), 12 February 2025, with explanatory memorandum. TRAI amendment PDF
  3. TRAI Direction of 13 June 2025 establishing the regulatory sandbox pilot for the Consent Registration Function. TRAI Direction PDF
  4. TRAI Direction of 19 November 2025 on phase-wise mandatory adoption of the 1600 numbering series, with Annexure-I dates. TRAI Direction PDF
  5. TRAI Direction of 10 August 2026 allocating and operationalising the 1601 numbering series. TRAI Direction PDF
  6. TRAI index of Directions, including 7 April 2025, 18 November 2025, 16 December 2025, 27 January 2026, 16 February 2026 and 27 February 2026. TRAI Directions index
  7. TRAI page on unsolicited commercial communication, linking the DND application and short code 1909. TRAI consumer initiatives
  8. Digital Personal Data Protection Act, 2023 (No. 22 of 2023), Gazette of India Extraordinary, 11 August 2023. MeitY gazette PDF
  9. Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), gazetted 13 November 2025. MeitY gazette PDF

Frequently Asked Questions

What are the legal calling hours in India?

There is no single stated national window. Schedule-II of the 2018 regulations lists nine selectable time bands, and Note-1 makes four of them default OFF for every customer whether or not any preference is registered: 00:00 to 06:00, 06:00 to 08:00, 08:00 to 10:00 and 21:00 to 24:00. The remainder, 10:00 to 21:00, is what is permitted by default. No instrument names a time zone, and day types are selectable by the customer with none blocked by default.

Did India ban auto-diallers?

Not any more. The 2018 text prohibited a registered Sender from initiating calls with an auto-dialler that may result in silent or abandoned calls, subject to a proviso for Senders who had notified their Access Provider. The Second Amendment of 12 February 2025 substituted that regulation entirely with a notification duty: every Sender must notify the Originating Access Provider in advance, in writing, about the use of an auto-dialler or robocalls and the intended objective of such calls.

What is the abandoned call limit in India?

TRAI does not publish one. The regulations define an abandoned call as an outgoing call where the sender does not connect the call to a live agent after it is established and answered, and refer to limits provided for in the regulations or in Codes of Practice, but they state no percentage. Any figure you are quoted comes from an operator Code of Practice rather than from TRAI, so confirm it with your Access Provider.

What are the 140, 1600 and 1601 number series?

The 140 series carries promotional voice calls, and promotional auto-dialler or robocalls are permitted through 140 numbers only. The 1600 series carries service and transactional voice calls for Government and BFSI entities, mandatory on fixed dates from 1 January 2026 for commercial banks through to 15 March 2026 for Qualified Stockbrokers. The 1601 series was allocated on 10 August 2026 for service and transactional calls by other sectors, with Phase-I covering utilities and logistics or courier services and ninety days to onboard.

How does the Do Not Call system work in India?

Subscribers register preferences on the Preference Register, held as a distributed ledger, through short code 1909 by SMS, call, IVRS or USSD, or through the TRAI DND app. Preferences are granular by content category, mode, time band and day type, and take effect in near real time with nothing delivered contrary to a preference after 24 hours. Checking is performed by a registered Scrubber that verifies time bands and day types, not by the caller directly.

How long does consent last in India?

Since February 2025, consent does not extend beyond the duration or discharge of the contract between the Sender and the Recipient. Explicit consent used to justify a service or transaction-facing message is valid for seven days, or as TRAI later directs, and TRAI's explanatory note says the limit exists to prevent misuse of explicit consent. For commercial messages, consent may also be clearly and reasonably inferred from the registered content template.

Is the DPDP Act in force for contact centres yet?

Partly. The Act received assent on 11 August 2023 and the Rules were gazetted on 13 November 2025, but the Rules commence in three tranches. Rules 1, 2 and 17 to 21 commenced on publication, rule 4 on Consent Manager registration commences on 13 November 2026, and rules 3 and 5 to 16 plus 22 and 23 commence eighteen months after publication, in May 2027. Notice content, security, breach reporting, retention, data-principal rights and the cross-border condition are therefore not yet in force.

What happens if my numbers are suspended under TCCCPR?

Suspension propagates: once one Access Provider suspends or blacklists an entity and updates the ledger, every other Access Provider must stop its traffic within 24 hours and may not re-register it during the suspension. On a successful representation, resources are restored on payment of ₹5,000 per telecom resource, capped at ₹5 lakh. For PRI or SIP trunks each DID number counts as a separate telecom resource, so a large pool is expensive to restore. Repeat header violations bring at least a one-year blacklisting across all Access Providers.

Related Reading

Disclaimer: This article is general information, not legal advice. DialerBee does not provide legal advice or guarantee regulatory compliance. Several points above are recorded as not published because no source could be located, and that is not the same as permission. Confirm current requirements with the Telecom Regulatory Authority of India, your Access Provider, your sectoral regulator, and qualified local counsel.

Ready to see DialerBee in action?

Book a 15-minute live demo, or start a free trial and dial today — no slides, no commitment.

14-day free trial · no credit card · 11 languages · BYOC · compliance-supporting controls