IndiaFocal.

India, in focus.

National

Government Drafts Wider Anti-Spam Rules Covering OTT, Messaging Apps

A draft framework would extend anti-spam obligations beyond calls and SMS to OTT platforms, messaging apps, social media and push notifications.

The government is working on a wider framework to curb unsolicited and promotional commercial communication, moving beyond phone calls and SMS to cover messaging applications, OTT platforms, social media, push notifications and other digital channels. The proposal is at a draft stage and has not yet been circulated for public feedback.

The draft builds on an earlier Department of Consumer Affairs initiative on unsolicited business communication, which flagged concerns such as calls from unregistered entities, weak consumer consent, unclear sender identity and ineffective opt-out mechanisms. The new draft retains those principles while extending them across digital platforms, and adds provisions on artificial intelligence, personal-data use and intermediary accountability.

Scope of the proposed rules

The guidelines would apply to businesses, entities that engage communication service providers, intended beneficiaries, named entities and communication platforms, operating alongside existing telecom, IT, data-protection and consumer-protection laws. Their definition of communication channels includes telecom services, OTT platforms, RCS, social media, messaging and calling applications, push notifications, and software and internet-based services. Foreign entities and platforms would also be covered where the recipient is in India.

For OTT platforms, messaging apps and social-media services, the draft could introduce compliance duties around consent verification, effective opt-outs, sender identification and grievance redressal. Businesses using these services may have to keep records of consumer permissions and follow-up requests. Adding users to promotional groups, channels or broadcast lists without explicit consent would be treated as a prohibited practice. How obligations are split among platforms, senders and beneficiaries would depend on the final guidelines.

Consent, opt-outs and follow-ups

Commercial communication would need to rest on explicit consent for a specific brand or beneficiary and product, or on a registered consumer preference. Consent is defined as freely given, specific, informed and unambiguous agreement, recorded digitally through a Digital Consent Acquisition mechanism or an equivalent system. This would separate consent for a particular business or product from general permission to receive commercial messages.

The draft bars communication that ignores a consumer's opt-out or breaches the applicable preference framework, and requires a clear, free and effective way to stop further contact. Opt-out requests would have to be implemented and confirmed without unreasonable delay. A cooling-off period after opting out is under consideration, with 45, 60 or 90 days still unresolved.

Repeated promotional contact after a single enquiry would be treated as unsolicited or unwarranted where there is no continuing relationship, engagement or fresh consent — a provision relevant to businesses that keep reaching out after an initial query.

AI disclosure and accountability

The draft proposes that commercial communication using AI-generated voice or text carry a clear disclosure at the start of the interaction. This differs from the telecom regulator's use of AI and machine learning to detect spam, which focuses on identifying and acting against suspicious communications.

Responsibility would not rest only with the entity that makes a call or sends a message. Senders, engaging entities, intended beneficiaries and named entities could all fall within scope, and the draft also addresses unauthorised employees or agents, spoofing, impersonation and misleading identification. Businesses could face greater oversight of third-party agencies, outsourced calling operations and digital intermediaries.

Grievance redressal and records

Each entity and platform would have to designate a nodal grievance officer, with complaints acknowledged within 24 hours and resolved within seven days, subject to shorter timelines under the telecom framework. Entities would also be expected to keep records of consent, opt-outs and sender identity, with a retention period still unresolved between 180 and 365 days. Periodic self-certification and coordination with existing mechanisms such as the National Consumer Helpline and telecom UCC systems are also proposed.

Existing regime

India's anti-spam rules are currently led by the telecom regulator's Telecom Commercial Communications Customer Preference Regulations, 2018, and later amendments, which provide for the Do Not Disturb system, consent-based communication, and registration of senders and telemarketers. Operators can act against entities sending unsolicited commercial communication. Recent measures bring automated and robocalls under closer scrutiny: application-to-person calls must be declared to telecom service providers, and undeclared calls may be treated as UCC. AI- and machine-learning-based spam detection and action against repeat offenders are also part of the framework, while commercial communication based on a customer's written or digital enquiry is subject to a seven-day limit. The Digital Personal Data Protection Act, 2023, provides a separate framework for the collection, processing and use of personal data relevant to such outreach.