TRAI Compliance for AI Calling in India — What Every Business Needs to Know
TRAI Compliance for AI Calling in India — What Every Business Needs to Know
On this page
AI calling is transforming how Indian businesses handle sales outreach, order confirmations, lead qualification, and customer support. But voice calling in India is a regulated activity — and the rules got significantly stricter in 2025. If your business makes commercial calls at scale, understanding TRAI AI calling compliance in India isn't optional. Non-compliance can get your telecom resources suspended for 15 days on the first violation, disconnected and blacklisted for a year on repeat violations, and expose you to overlapping penalties under India's data protection law.
This guide breaks down the regulatory framework in plain language: what DLT registration is, how DND scrubbing works, when you're allowed to call, what the DPDP Act means for your lead data, and how the right AI calling platform handles all of it for you.
The Regulatory Landscape: TCCCPR and TRAI
Commercial communication in India is governed by the Telecom Commercial Communications Customer Preference Regulations (TCCCPR), 2018, issued by the Telecom Regulatory Authority of India (TRAI). The framework exists to curb Unsolicited Commercial Communication (UCC) — spam — while allowing legitimate businesses to reach customers who have consented or opted in.
In February 2025, TRAI notified major amendments to TCCCPR that tightened nearly every part of the framework: stricter sender registration (including physical verification and biometric authentication for telemarketers), a lower complaint threshold for action against spammers, mandatory use of designated number series, and harder-hitting enforcement. If your compliance understanding predates 2025, it's out of date.
Here's what the framework means in practice for any business using AI calling.
1. DLT Registration: Your Licence to Communicate Commercially
What it is: TCCCPR mandates that every business sending commercial communication — called a Principal Entity (PE) or Sender — must register on the Distributed Ledger Technology (DLT) platform operated by telecom access providers (Jio, Airtel, Vi, BSNL). DLT is a blockchain-based registry that records who is allowed to send commercial communication, under what headers, and with whose consent.
What registration involves:
Entity registration: Your business registers with an access provider, providing legal entity details. Post the 2025 amendments, verification requirements are stricter — including physical verification and biometric authentication for telemarketers.
Header registration: Commercial communication can only originate from registered headers/identifiers assigned to your entity.
Designated number series: Businesses can no longer use normal 10-digit numbers for telemarketing. Promotional calls must use the 140 series; transactional and service calls use the newly designated 1600 series. This lets customers identify the type of call from the caller ID itself.
Consent registration: TCCCPR provides for a Digital Consent Acquisition (DCA) facility, where customer consent to receive communication from your brand is verified via OTP and recorded on the DLT platform.
Why it matters for AI calling: Every outbound AI call your platform places is commercial communication in the eyes of TRAI. If your calls originate from unregistered numbers or an unregistered entity, you're classified as an Unregistered Telemarketer (UTM) — and access providers are required to act against UTMs, including usage caps and disconnection.
2. DND Scrubbing: Never Call a Number That Opted Out
What it is: Indian consumers can register their preferences to block commercial communication — fully or by category (real estate, health, education, etc.). This is commonly known as DND (Do Not Disturb). Before any promotional calling campaign, your calling list must be scrubbed against the DND registry — every number checked against current preferences, and blocked numbers removed.
Key nuances:
DND preferences are dynamic. A number that was callable last month may have opted out since. Scrubbing must happen close to the time of calling, not once when the lead was acquired.
The 2025 amendments made complaints easier and enforcement faster: customers can now complain about spam within 7 days (up from 3), complaints with bare-minimum details are treated as valid, and access providers must act against unregistered senders within 5 days (down from 30).
The action threshold for spammers was lowered from 10 complaints in 7 days to 5 complaints in 10 days — meaning fewer complaints now trigger enforcement.
The important distinction: DND primarily restricts promotional communication. Transactional and service calls — like confirming an order the customer just placed — operate under different consent rules (inferred consent from an existing customer relationship). But the 2025 amendments tightened this too: service-call consent is limited to the duration of your relationship with the customer, and consent to complete a transaction is valid for only 7 days. Misusing "service call" routes to push promotional content is explicitly targeted by the amended rules.
3. Calling Hours: When You're Allowed to Dial
Promotional calls in India are restricted to daytime hours — the long-standing permitted window is 9 AM to 9 PM. Calls outside this window to consumers are a violation, regardless of consent. Customers can additionally register preferences for specific time bands and days on which they're willing to receive commercial communication, which access providers must honour.
For AI calling, this is a systems problem: your dialer must enforce time-window rules automatically, including queuing logic. An order placed at 11 PM shouldn't trigger a promotional call until the window reopens — and your platform should handle that without manual intervention.
4. What Non-Compliance Actually Costs
The 2025 framework introduced a graded, escalating enforcement structure. Verified consequences include:
Suspension: A sender found in repeated violation has outgoing services of all telecom resources barred for 15 days on the first regulatory-threshold violation.
Blacklisting: Subsequent violations lead to disconnection of all telecom resources across all access providers for one year, plus blacklisting. For a business that runs on calling, this is existential.
Financial disincentives: TRAI's regime imposes graded financial disincentives of ₹2 lakh, ₹5 lakh, and ₹10 lakh for first, second, and subsequent instances of violations respectively, along with per-instance penalties for other failures under the framework.
DPDP exposure on top: Because consent violations often breach both TCCCPR and the DPDP Act, businesses can face double penalties for the same underlying failure — and DPDP penalties go up to ₹250 crore.
5. DPDP Basics: Your Lead Data Is Regulated Too
The Digital Personal Data Protection Act, 2023 (DPDP) governs how you collect, store, and use personal data — including every phone number in your calling list and every call recording your AI agent produces. For AI calling operations, the essentials:
Lawful consent: You need valid consent (or a legitimate ground) to process a person's data for the purpose you're using it. A number scraped from a directory and cold-called for promotions is a consent problem under both DPDP and TCCCPR.
Purpose limitation: Data collected for order fulfilment shouldn't be silently repurposed for promotional campaigns.
Storage and security: Call recordings, transcripts, and lead databases are personal data. You're accountable for how they're stored, who accesses them, and how long they're retained.
Data principal rights: Customers can seek erasure and correction of their data — your systems need to be able to honour that.
Your TRAI AI Calling Compliance Checklist
Before launching any AI calling campaign in India, verify:
Entity registered on DLT with your access provider, with verification requirements completed
Correct number series in use — 140 series for promotional calls, 1600 series for transactional/service calls; no plain 10-digit numbers for telemarketing
Consent trail exists for every contact — explicit consent for promotional calls, valid inferred consent for transactional/service calls
DND scrubbing performed against current preference data before every promotional campaign, not just at list creation
Calling hours enforced in the dialer — promotional calls only within the permitted daytime window (9 AM–9 PM), with customer time-band preferences honoured
Complaint monitoring in place — track UCC complaints against your headers/numbers; the action threshold is now just 5 complaints in 10 days
DPDP data practices documented — consent records, retention policy for recordings and transcripts, access controls, and a process for erasure requests
Vendor accountability confirmed — your AI calling platform should contractually and technically own DLT, scrubbing, and time-window compliance
How Pineyard.ai Handles Compliance for You
Compliance shouldn't require your ops team to become telecom lawyers. Pineyard.ai builds TRAI compliance into the platform itself, so every client campaign runs clean by default:
DLT compliance, handled. Pineyard manages DLT-compliant calling infrastructure and registered number series for client campaigns, so your calls originate from compliant identifiers — not flagged 10-digit numbers.
Automatic DND scrubbing. Promotional calling lists are scrubbed against current DND preference data before dialing. Opted-out numbers never enter the queue.
Calling hours enforced by the system. Pineyard's dialer enforces permitted calling windows automatically. Orders and leads that come in overnight are queued and called when the window opens — no manual list management, no accidental 10 PM calls.
Data handling aligned with DPDP. Call data, recordings, and lead information are stored and processed with DPDP obligations in mind, giving you a defensible data posture alongside telecom compliance.
The result: your team focuses on conversions, confirmations, and customer experience — while the regulatory guardrails run silently underneath every call.
The Bottom Line
TRAI's 2025 amendments made one thing clear: the era of grey-zone telecalling in India is over. Registration is verified, complaints trigger action faster, penalties escalate quickly, and DPDP adds a second layer of accountability on the data side. Businesses that treat compliance as an afterthought risk losing the very telecom resources their revenue depends on.
The smarter path is choosing infrastructure where compliance is native — so scale and safety aren't in tension.
Book a free demo at pineyard.ai
Keep reading
IVR vs AI Voice Agents — Why Press-1-for-Sales Is Costing Indian Businesses Customers
IVR vs AI Voice Agents — Why Press-1-for-Sales Is Costing Indian Businesses Customers
Festival Season Lead Surge — How Indian Businesses Handle 3X Enquiry Volume Without Hiring Extra Staff
Festival Season Lead Surge — How Indian Businesses Handle 3X Enquiry Volume Without Hiring Extra Staff
How Hospitals and Clinics in India Are Reducing No-Shows With AI Appointment Reminder Calls
How Hospitals and Clinics in India Are Reducing No-Shows With AI Appointment Reminder Calls
Turn every lead into revenue. Automatically.
AI voice agents that pick up every inbound, qualify the lead, and book the meeting — in under 800ms, across 20+ languages.