Back to Blog
    Compliance

    TRAI/TCCCPR Compliance for AI Calling in India: A Practical Guide

    If your AI agent places commercial calls to Indian numbers, TCCCPR isn't optional. Here's what the rules actually demand, and how to enforce them in software rather than policy documents.

    What TCCCPR actually requires

    The Telecom Commercial Communications Customer Preference Regulations govern every commercial call and message to Indian numbers. The rules that matter most for AI calling: commercial calls may only be placed inside the 09:00–21:00 IST window; promotional calls must present a 140-series caller ID while service and transactional calls use 1600/1601-series (with BFSI and government senders under stricter mandates); and consent evidence is required for promotional contact.

    Commercial calls to +91 numbers must also originate on an India route, an Indian CLI can't be presented on calls terminating abroad. Most platforms leave all of this as an exercise for the customer.

    Policy as code, not a PDF

    Crawlii encodes the ruleset as an executable policy evaluated before every dial. Calling-window, series-for-purpose, sector detection, and route rules run automatically across AI Agent campaigns and pre-call automations alike, a non-compliant call never gets placed.

    Shadow mode first, then enforce

    Rolling out compliance shouldn't mean breaking your call volume overnight. Three enforcement modes per organization: off, shadow (evaluate and log every decision, block nothing, producing an audit trail while you migrate), and enforce (non-compliant calls are blocked pre-dial). Shadow mode is the safe on-ramp: weeks of evidence about what would have been blocked before you flip the switch.

    Tiered consent and the Feb-2025 rules

    • Explicit DLT-verified consent, OTP-verified on the DLT Consent Registrar, the only tier TCCCPR treats as explicit.
    • Inferred consent, WhatsApp replies, web forms, verbal agreements.
    • Service-context consent, implicit in an ongoing transaction, with a 7-day validity window.
    • 90-day re-consent cooldown, you can't seek fresh consent from someone who opted out within the last 90 days.
    • 7-day verifiable-inquiry window, under the Third Amendment, an inbound inquiry through a verifiable channel (call, web form, WhatsApp, API) counts as consent evidence for a callback.

    Opt-out that actually sticks

    A customer saying "stop" on WhatsApp is suppressed from voice calls and email too, one suppression list across every channel. Spoken opt-outs are detected on call transcripts, in English and Hindi ("mujhe call mat karo" works). And the system is fail-closed: if suppression status can't be verified, the call isn't placed. Every decision lands in a tamper-evident audit ledger with its rule evaluation and consent evidence attached.

    The honest boundary

    DLT registration itself and final legal sign-off remain the customer's responsibility, no vendor can automate that. What a platform can automate is everything around it: the rules, the evidence, and the record of every decision. Crawlii also ships entity registration and declaration tracking with a readiness checklist, so the paperwork you do need is organized before enforcement tightens.

    Frequently Asked Questions

    Do transactional/service calls need the same rules?

    Yes, the 09:00–21:00 window applies to promotional and service purposes, but service/transactional calls use 1600/1601-series caller IDs instead of 140-series, with BFSI and government under tighter mandates.

    What happens if our data source is wrong about consent?

    The engine is fail-closed, when consent or suppression status can't be verified, the call doesn't happen. Errors surface in the audit ledger rather than as silent violations.

    Does this cover WhatsApp and email too?

    The suppression list is cross-channel, an opt-out on any channel suppresses the contact everywhere, including automations.