Why hasn't TRAI built the consent system its spam rules promised?
A roundtable discussion on the Impact of the use of AI in spam prevention highlighted the missing consent system in the Telecom Commercial Communications Customer Preference Regulations (TCCCPR), 2018. The consent layer, meant to sit at the core of the Distributed Ledger …
Intelligence analysis by Llama

The consent system, which records customer consent for commercial messages, has not been implemented despite being provided for in the 2018 regulations. This has led to a system that relies on guessing what a person has agreed to, rather than checking against their actual consent.
Imagine you're getting lots of unwanted messages on your phone. You want to be able to say 'stop sending me these messages' and have it actually work. But right now, the system doesn't work that way. It's like trying to guess what you want to hear, rather than asking you directly. This is a problem because it means you might get messages you don't want, and it's also a problem for businesses because they might send messages to people who don't want them.
Analysis
The Missing Piece: Consent in the Telecom Regulations
The Telecom Commercial Communications Customer Preference Regulations (TCCCPR), 2018, set up the Distributed Ledger Technology (DLT) platform, a blockchain-based system that registers commercial senders and traces every message. However, the consent layer meant to sit at its core is still missing. This is the missing piece, as a speaker noted, and it has not been operationalized.
The Problem with Guessing
Without the consent layer, a message cannot be checked against what a person actually agreed to, so the system falls back on guessing. For most people, there is no display of what they consented to, because it is not yet implemented. This means that a message can be considered spam even if the recipient wanted it, and vice versa.
The Importance of Recipient Consent
A speaker argued that only the recipient can define spam. A spam message is not defined till it reaches the recipient, and the recipient decides that this is unwanted. If the recipient wanted the message, it was never spam. This is why a machine cannot make the call, as it would be asking the machine to make an indeterminate decision.
The Need for Specific Consent
Consent today is broad and often meaningless. A speaker noted that consent has been taken universally, even if a 1600 or 140 number is used. This means that a customer may agree to hear from a bank for transactional messages, but not for marketing messages. Consent should be tied to a specific purpose, so a message that falls outside that purpose is a breach.
The Earlier Consent System
The earlier consent system, the Digital Consent Acquisition (DCA) mechanism, was implemented but failed to take off. Businesses would not adopt it, because asking a customer to confirm again risked losing the consent. The worry was fatigue, as a speaker noted. A working system would let people revoke easily, and a person could see every business they had agreed to hear from and turn any of them off.
The Pilot and the Future
A pilot has been run, and it has worked, so it is possible to do it. Consent should stay with the customer’s operator, as it is a privacy risk if a person’s permission gets copied to companies that do not need it. The Digital Personal Data Protection (DPDP) Act’s rule that personal data should not spread further than it needs to supports this. Keeping it local means a customer’s choice stays with their own operator.
The Role of Consent Managers
The DPDP Act’s consent managers could help. Consent manager under DPDP is a specified entity. Nobody can act as the consent manager except the consent manager itself. However, this has to wait on the data-protection machinery. The consent manager will be first registered after the [Data Protection] Board comes into existence.
Key points
- The consent layer in the Telecom Commercial Communications Customer Preference Regulations (TCCCPR), 2018, has not been operationalized.
- The lack of a consent system has significant implications for consumer privacy and the effectiveness of spam prevention measures.
- A pilot has been run, and it has worked, so it is possible to do it.
- Consent should stay with the customer’s operator, as it is a privacy risk if a person’s permission gets copied to companies that do not need it.
- The Digital Personal Data Protection (DPDP) Act’s consent managers could help, but this has to wait on the data-protection machinery.
If the consent system is implemented, it could lead to a significant reduction in spam messages. This would be a win for consumers, who would have more control over the messages they receive. It would also be a win for businesses, who would be able to target their messages more effectively and avoid wasting resources on unwanted messages.
If the consent system is not implemented, it could lead to a continued increase in spam messages. This would be a problem for consumers, who would be bombarded with unwanted messages. It would also be a problem for businesses, who would struggle to reach their target audience effectively.



