India Tightens Grip on Caller-ID Apps
TRAI's amended rules force caller-ID apps to feed spam reports into a telecom blockchain, drawing accusations of anti-competitive data transfer from Truecaller.
India's telecom regulator has expanded its anti-spam framework in a way that directly touches the millions of people who rely on caller-ID apps to screen unwanted calls. The change compels those apps to hand over user-generated spam reports to a blockchain platform run by telecom operators, a move one major app maker says unfairly shifts valuable data from its own systems to the carriers.
For Truecaller, India is not a side market. It is the company's largest, with well over 350 million of its more than 500 million monthly active users. That scale means any regulatory shift in how spam data is collected and shared has outsized consequences for both the company and the users who depend on its filtering.
TRAI Expands Its Anti-Spam Net
On Friday, the Telecom Regulatory Authority of India, or TRAI, amended the rules governing commercial communications. Under the new framework, caller-ID and call-management apps that allow users to flag calls as spam or junk must now send those reports to a blockchain-based platform maintained by telecom operators. That platform tracks commercial communications and enforces anti-spam rules.
TRAI said the change is meant to broaden the pool of spam reports available for action against spammers. The idea is to connect the reports apps collect with the telecom industry's existing enforcement infrastructure, potentially giving regulators and operators a richer set of signals to act on.
The regulator has been building out this enforcement layer over time, and the latest amendment extends its reach into the app ecosystem that sits on top of the network. The blockchain platform serves as the central record for commercial communications, and spam reports from apps are now meant to feed into it.
Truecaller Pushes Back on Data Transfer
Truecaller told TechCrunch it views the requirement as a "one-way exchange" that is "anti-competitive." The Stockholm-based company argues the rule transfers commercially valuable data from call-management apps like itself to telecom operators.
"While our data and user sentiment clearly show that spam has skyrocketed due to this free pass to spammers, we have been compliant with this since late last year," a Truecaller spokesperson said.
The friction between Truecaller and Indian regulators is not new. The company previously objected to restrictions that prevented call-management apps from automatically labeling calls from certain government-designated number ranges as spam. Truecaller argued that exemption could let unwanted calls slip past its filters.
The amendments introduced on Friday retain that restriction. Call-management apps are barred from blanket blocking, filtering, or spam-tagging calls from designated number series used for promotional, service, and transactional communications. However, individual users can still choose to block such calls on their own devices, according to the regulator.
Truecaller's objection centers on what it sees as an uneven flow of value. Its system relies on community reports alongside automated detection and other signals to identify and block spam calls. Requiring those reports to be handed to a telecom-run platform, without a reciprocal flow of data back to the apps, is the core of the company's complaint.
Scale of India's Spam Problem
The regulatory push comes as India confronts spam and fraudulent calls on a massive scale. In a report published in February, Truecaller said its users in India encountered around 42 billion spam calls in 2025. That figure includes calls that were blocked, labeled, or ignored. The company also stated that it blocked nearly 12 billion spam calls during the year.
Those numbers help explain why TRAI is eager to pull more spam signals into its enforcement system. If apps are already collecting reports at that volume, routing them into the operator-run blockchain platform could, in theory, give regulators a more complete picture of where spam is coming from and how it is evolving.
- Well over 350 million of Truecaller's more than 500 million monthly active users are in India.
- Truecaller users in India encountered around 42 billion spam calls in 2025, according to the company's February report.
- Truecaller said it blocked nearly 12 billion spam calls during 2025.
The disparity between the 42 billion calls encountered and the nearly 12 billion blocked illustrates how much spam still reaches users even with detection systems in place. That gap is part of what regulators are trying to close by broadening the pool of reports available for enforcement.
Questions Over Enforcement and Standards
Sumeysh Srivastava, a partner at New Delhi-based consulting firm The Quantum Hub, who leads its telecom-regulation policy work, said the latest change bridges two distinct layers. Telecom operators provide the underlying network and run the blockchain-based anti-spam system, while caller-ID apps operate on top of the network to identify and filter calls.
That raises technical and jurisdictional questions, Srivastava told TechCrunch. Among them: what reporting standards apps will have to follow, and how the requirement will be enforced against companies that are not themselves telecom operators. A March draft proposed using India's IT laws to enforce the requirement. However, Srivastava pointed out that the new announcement did not say whether that enforcement mechanism was retained in the final rules.
The uncertainty extends to how much information the apps will actually have to provide. Kazim Rizvi, founding director of New Delhi-based policy think tank The Dialogue, told TechCrunch that requiring an app to transmit a specific spam report made by a user is materially different from requiring it to share the broader datasets, reputation signals, or analytical systems it uses to identify suspicious calls.
The rules will need clarity on what information must be transmitted, how users are notified or asked for consent, and how that data can subsequently be retained and used, Rizvi said. TRAI did not respond to TechCrunch's questions about what information apps would be required to share and whether the rule would also apply to spam-reporting features built into smartphone operating systems and dialers such as Android and iOS.
AI Voice Agents Fall Under A2P Rules
The amendments also address the growing use of software and AI voice agents to make calls. Calls made automatically, without a person directly dialing the number, will now fall under TRAI's application-to-person, or A2P, framework. That includes robocalls and calls using prerecorded or artificial voices.
Companies using such systems will have to declare their use and the phone numbers involved to their telecom operators in advance. Undeclared A2P calls will be treated as spam, TRAI said. According to Srivastava, the key test is how a call is initiated, rather than simply whether it uses an AI-generated voice. That leaves some uncertainty around AI-assisted calls that involve human initiation.
Satya N. Gupta, a former additional secretary at TRAI, told TechCrunch that the new rules do not restrict businesses from using AI or other automated calling technologies. Instead, they require those businesses to disclose their use to telecom operators.
Telecom operators will also be allowed to levy a termination charge of up to 5 paise (about 0.052 cents) per minute on A2P calls. However, calls made using certain designated number ranges will be exempt. Rizvi told TechCrunch that the new definition could also cover calls made using software even when a person is still involved, such as calls from contact centers and click-to-call services. "Without that distinction, the A2P category risks becoming broader than the regulatory harm it is intended to address," he said.
What the Consent and Data Rules Leave Open
For users, the practical question is what happens to the report they file when they mark a call as spam. Under the amended framework, that report may now travel to a blockchain platform maintained by telecom operators, rather than staying within the app that collected it.
How users are notified or asked for consent is among the issues Rizvi said the rules will need to clarify. The same applies to how long that data can be retained and what it can be used for after it is transmitted. None of those specifics were spelled out in the announcement as described by the experts who spoke to TechCrunch.
There is also the unresolved matter of scope. TRAI did not answer whether the requirement would apply to spam-reporting features built into smartphone operating systems and dialers such as Android and iOS. If those built-in tools fall outside the rule, the reporting pool feeding the operator platform could be narrower than the regulator intends.
For call-management apps, the compliance burden is compounded by the continued restriction on auto-labeling calls from designated number series. Those apps cannot blanket block or spam-tag calls from promotional, service, and transactional ranges, though individual users retain the ability to block such calls on their own devices.
What This Could Mean for Users and Apps
The amendments put caller-ID apps in an awkward position. They must send spam reports to a telecom-run platform while remaining barred from automatically labeling certain government-designated number ranges. For Truecaller, which derives much of its value from the community reports its users generate, the requirement to hand those reports to operators without a clear reciprocal flow is the source of its anti-competitive complaint.
For Indian consumers, the stakes are twofold. On one side, a broader pool of spam reports feeding the enforcement system could, in theory, lead to stronger action against the calls that generated around 42 billion encounters in 2025. On the other, the lack of clarity on consent, data retention, and how broadly the rules apply to operating-system-level dialers means users may not yet know how their own spam reports are being used or shared.
The A2P changes could also shape the calls people receive. Businesses using robocalls or AI-generated voices must now declare their use and numbers in advance, and undeclared calls will be treated as spam. The termination charge of up to 5 paise per minute on A2P calls, with exemptions for certain number ranges, adds a cost dimension that could influence how companies structure automated outreach.
How regulators resolve the open questions around reporting standards, enforcement, and the line between AI-initiated and human-initiated calls will determine whether the framework works as intended or becomes, as Rizvi warned, broader than the harm it targets. For now, the rules shift more of the spam-reporting pipeline toward telecom operators and leave app makers and users watching for the details that have yet to be filled in.
Sources
- TechCrunch Original source
Continue Reading
Four Kernel Flaws, Public Exploits, One Fix
A researcher published working local-root exploits for four Linux kernel bugs fixed weeks earlier, flagging a patching race for older systems.
Click2Shell Turns Admin Clicks Into Theme Installs
A new WordPress core flaw lets a crafted link silently install a theme, and researchers chained it to full code execution.
One Week, Nine Flaws, No Easy Fix
SecurityWeek's roundup covers a ransomware sentencing, a zero-click AI plugin flaw, and a critical SAP bug under active scrutiny.