India Forces Truecaller to Hand Spam Data to Telcos
TRAI finalised the Telecom Commercial Communications Customer Preference (Third Amendment) Regulations, 2026 on September 18, requiring caller-ID and call-management apps to funnel user-submitted spam reports into a blockchain-based enforcement platform run by telecom operators.

Truecaller, which counts India as its largest market with over 350 million of its 500 million-plus global monthly users, called it a “one-way exchange” that is “anti-competitive,” arguing the rule transfers commercially valuable, crowdsourced data to telecom operators with nothing given back in return.

Why Regulators Want the Data Merged

The scale driving this is enormous: Truecaller’s own February report found Indian users encountered roughly 42 billion spam calls in 2025, of which the app blocked nearly 12 billion. TRAI’s logic is that apps hold large pools of community-flagged numbers that telecom networks cannot see, while operators control subscriber records, sender registration, and traffic-pattern data that apps cannot see.

Merging the two turns an app-level nuisance report into a network-level enforcement signal, a number reported as spam by thousands of Truecaller users can now be cross-referenced against the actual telecom account behind it, rather than sitting siloed in one company’s database.

The same amendment folds AI-generated and automated voice calls into India’s existing application-to-person framework: businesses must declare such calls and their numbers to telecom operators in advance, or the calls get classified as spam automatically. TRAI also introduced a 15-day appellate window for wrongly closed spam complaints, after data showed access providers had closed roughly 80% of complaints against registered telemarketers as invalid between January and June 2026.

The App-vs-OS Question This Raises

Sumeysh Srivastava of The Quantum Hub flagged the real implementation problem to TechCrunch: TRAI is applying telecom regulation to independent software companies, a jurisdictional stretch with no clean precedent. That tension points to two different models for where spam detection should actually live.

Apple’s approach bakes call screening into iOS itself, an OS-level feature every user gets by default, no third-party app or data-sharing mandate required. Samsung and Google are reportedly moving the same direction with AI scam-call alerts built into Android. India’s rule instead regulates the app layer, forcing a third-party developer to share proprietary data with infrastructure operators it competes against for the same user attention.

A telecom-operator-run OS feature would sidestep Truecaller’s anti-competitive objection entirely, but it would also hand carriers a monopoly over spam detection that today’s competitive app market currently checks. Truecaller’s own household-level family plan shows the app is still trying to compete on features even as regulators push its core data asset toward mandatory sharing.

What Nigeria, Europe, and Others Could Take From This

Nigeria’s NCC already runs a Do-Not-Disturb registry and mandates SIM-NIN linkage, the identity layer, but has no equivalent data bridge connecting app-level spam reports to network enforcement the way TRAI’s DLT platform now does. A similar rule would let Nigerian carriers act on numbers flagged en masse by Truecaller or local caller-ID apps rather than relying solely on subscriber complaints filed directly with operators.

The EU faces a structurally different problem: GDPR’s stricter consent architecture, which already shapes how India’s own DPDPA diverges from European data rules, makes an Indian-style mandatory one-way data transfer from a private app to telecom operators considerably harder to justify without explicit user consent baked in from the start, exactly the gap policy experts say TRAI’s own notification has yet to close.

Any jurisdiction copying this model needs to answer the consent question TRAI has not: does a user who reports a number as spam consent to that report being routed to a telecom-run enforcement ledger, or does the regulator simply assume it.

Follow us on Bluesky, LinkedIn, X, and Telegram to Get Instant Updates