India’s TRAI Advances Digital Consent Mechanism for Commercial SMS

On June 2, 2023, the Telecom Regulatory Authority of India (TRAI), under the Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR, 2018), mandated access service providers to build and deploy the Digital Consent Acquisition (DCA) mechanism. This mechanism aims to establish a unified digital workflow to capture, store, verify and revoke user consent records for receiving commercial communications.

Under the DCA framework, Principal Entities (PEs) must obtain user authorization for commercial communications through carrier-supported digital workflows. Carriers may verify corresponding consent records prior to delivering commercial messages. This mitigates risks where businesses previously collected authorizations independently via webpages, calls, paper forms, mobile applications or offline events, with inconsistent verification of authenticity and revocation capability.

TRAI stipulated that consent requests shall be sent using the unified 127xxx short code. Request SMS messages must clearly display the Principal Entity or brand name, purpose of consent and scope of authorization. Any URLs, APK download links, OTT links and callback numbers used in such messages must also be whitelisted items.

The DCA workflow shall support registration, maintenance and revocation of user consent. After authorization, users shall receive a confirmation message together with instructions on consent withdrawal. Access service providers shall also offer channels including SMS, IVR and online portals for users to register opt-out from all consent requests initiated by enterprises. For users who have declined or not responded to the same authorization request from the same entity, the enterprise shall not resubmit the identical request within 90 days, though users may voluntarily initiate authorization registration.

TRAI also clarified that upon DCA rollout, existing consents obtained through alternative channels will be invalid. Enterprises must re-obtain consent via the digital system. Accordingly, banks, insurers, financial institutions, e-commerce platforms and other entities sending commercial communications should audit their customer authorization records, SMS gateways, marketing automation tools and third-party agent arrangements to ensure alignment with DCA and DLT procedures.