Is AI Voice Calling TRAI Compliant? Outbound Rules in India
Businesses running outbound call campaigns in India face a compliance question that their legal teams, vendors, and product managers often answer...
TL;DR: Yes, AI voice calling is legal in India, but only when run inside a specific compliance framework. The question of whether AI voice calling is TRAI compliant in India comes down to four things: telemarketer registration on the DLT platform, DND scrubbing, proper consent, and calling only within permitted hours. A compliant AI voice campaign follows the same rules as any outbound telemarketing call, with a few additional considerations for automated systems.
Key Takeaways:
- All outbound commercial voice calls in India, including AI-powered ones, must comply with TRAI's Telecom Commercial Communications Customer Preference Regulations (TCCCPR) 2018.
- Before dialing a single number, businesses must register as telemarketers on the Distributed Ledger Technology (DLT) platform and use 140-series numbers for promotional calls.
- Lead lists must be scrubbed against the National Do Not Call (NDNC) registry before every campaign run.
- The Digital Personal Data Protection (DPDP) Act 2023 adds a new consent layer on top of TRAI rules: explicit, purpose-specific consent is now required to collect and process a call recipient's personal data.
- Calls may only be placed between 9 AM and 9 PM. Hard system enforcement, not just policy, is the only reliable way to stay compliant at scale.
Businesses running outbound call campaigns in India face a compliance question that their legal teams, vendors, and product managers often answer differently. Some say AI calling is a grey area. Others say the rules only apply to human agents. Neither is accurate.
The rules that govern outbound telemarketing in India apply to the call itself, not the technology making it. An AI agent placing a promotional call is a commercial communication under TRAI's framework, full stop. What changes with AI is scale: a human team makes hundreds of calls a day; an AI system can make lakhs. At that volume, a compliance gap that would go unnoticed in a small campaign becomes a systemic problem very quickly.
This post covers exactly what the rules require, what a compliant workflow looks like in practice, and what to look for in a vendor before you trust them with your outbound campaigns.
Is AI Voice Calling TRAI Compliant in India? The Direct Answer

AI voice calling is TRAI compliant in India when it follows the TCCCPR 2018 framework. The regulation does not distinguish between a human caller and an automated one. What it regulates is the commercial communication: any call made for promotional, transactional, or service purposes.
Compliance requires four things before a call goes out: proper registration, clean numbers, valid consent, and correct timing. None of these are optional, and none have an AI exemption.
What the Rules Actually Require: TCCCPR 2018 and DPDP 2023

TRAI TCCCPR 2018: The Core Framework
TRAI's Telecom Commercial Communications Customer Preference Regulations, last updated in 2018, set the baseline rules for all outbound commercial calls in India.
Telemarketer registration on DLT. Any entity making commercial calls must register as a telemarketer on the government's Distributed Ledger Technology platform, including pre-approved message templates. Calling from unregistered headers is a direct TRAI violation.
140-series numbers for promotional calls. Promotional outbound calls must use numbers in the 140-series range. Regular 10-digit mobile or landline numbers cannot be used for cold commercial calling.
DND scrubbing. Before dialing, every lead list must be checked against the National Do Not Call registry. Calling a registered DND number can result in penalties and, for repeat offences, telemarketer blacklisting.
Calling-hour restrictions. Commercial calls may only be placed between 9 AM and 9 PM, local time, regardless of consent status.
Opt-out mechanism. Every campaign must have a working opt-out path. When a recipient asks to stop receiving calls, that preference must be honored and the number removed from future dials.
DPDP Act 2023: The New Consent Layer
India's Digital Personal Data Protection Act 2023 intersects with TRAI rules in ways many teams have not fully worked through. The DPDP Act governs how personal data, including a phone number, is collected, stored, and used. For outbound AI calling, this creates obligations on top of the TRAI framework.
Consent under DPDP must be explicit, informed, and purpose-specific. Broad terms-and-conditions consent does not automatically cover a specific promotional calling campaign. Businesses need to document what data they hold, why they are using it, and that the person has agreed to that specific use.
Data retention also matters. Storing lead data longer than necessary is a compliance risk under DPDP. AI calling platforms that log call recordings and personal identifiers need retention policies that align with both frameworks.
The practical implication: a business might pass the TRAI DLT and DND checks but still face DPDP exposure if the underlying data collection was not properly consented to at the point of capture.
Sector Overlays: BFSI and Insurance
For businesses in banking, lending, or insurance, additional layers apply. The RBI has guidelines on borrower contact, particularly for collections calls, covering frequency limits, time restrictions, and escalation rules that go beyond TRAI's promotional call rules. IRDAI has comparable expectations for insurance companies.
If your campaign is a personal loan offer, a credit card sales call, or an insurance renewal reminder, the base TRAI framework is necessary but not sufficient.
What a Compliant AI Voice Workflow Looks Like in Practice

| Rule | What It Means | How to Comply |
|---|---|---|
| Telemarketer DLT registration | Your entity must be registered; call headers must be pre-approved | Register on the DLT platform; use only approved 140-series headers |
| DND scrubbing | No calls to numbers on the national registry | Scrub lead lists before every campaign; allow client-uploaded internal DND lists too |
| Consent | Recipient must have agreed to commercial contact from your category | Capture consent at lead source; document it with timestamp and purpose |
| Calling hours | 9 AM to 9 PM only | Hard-enforce in the dialer system, not just in policy |
| Opt-out | Recipient can stop calls at any time | Build opt-out handling into the call flow; write the preference back to the lead record |
| DPDP data handling | Personal data used only for the consented purpose; not stored beyond need | Align data retention policies; use masked identifiers in storage |
| BFSI/Insurance overlay | Frequency limits, tone, and escalation rules from RBI/IRDAI | Configure campaign rules per sector; build dispute-escalation paths into the agent |
The calling-hours rule deserves emphasis. A policy note saying "don't call before 9 AM" is not enough when a campaign runs autonomously at scale. The only reliable control is a hard system block: the dialer cannot place a call outside the permitted window regardless of campaign configuration.
DND scrubbing is also not a one-time exercise. Lead lists change, new numbers are added, and registry statuses update. Scrubbing must happen before each campaign run, not just at onboarding.
How to Evaluate a Vendor for Compliance

When a vendor says their platform is "TRAI compliant," that phrase covers a lot of ground. Here are the specific questions worth asking:
Do they use 140-series numbers? Some platforms use regular mobile or landline numbers for outbound campaigns, which is non-compliant for promotional calls.
How is DND scrubbing handled? Ask whether it runs automatically before every campaign, whether clients can upload internal DND lists, and how recently the registry integration was tested.
Is the calling window enforced at the system level? The answer should be a hard dialer block. Out-of-window calls should be technically impossible, not just discouraged.
How is consent tracked? For DPDP purposes, consent records need a timestamp and a purpose.
Do they handle sector-specific rules? For BFSI or insurance, ask about RBI collections guidelines, frequency caps, and warm-transfer paths for dispute escalation.
What certifications do they hold? ISO 27001, SOC 2 Type II, and DPDP compliance together give a more complete picture than TRAI registration alone.
A serious platform handles all of this in production infrastructure, not in slide decks. SquadStack's AI voice agent platform enforces calling-window restrictions as hard system blocks, runs DND scrubbing against both the TRAI registry and client-uploaded lists, uses 140-series numbers for outbound campaigns, and carries ISO 27001, ISO 27701, SOC 2 Type II, DPDP, and TRAI compliance certifications. The compliance layer is built into the dialer, the call flow, and the QA stack.
This architecture matters at the volumes SquadStack operates at: 50 lakh+ AI calls daily across 60+ large consumer brands including Kotak Mahindra Bank, AngelOne, PhonePe, and Eureka Forbes. At that scale, a compliance gap runs thousands of times before anyone notices, which is why the controls are built into infrastructure rather than left to manual configuration.
For teams evaluating AI outbound calling platforms, the AI dialer page covers how SquadStack's dialing architecture manages cadence, retry logic, and compliance windows in more detail.
Conclusion
AI voice calling is not a compliance grey area in India. The rules are clear: register on DLT, scrub DND, use 140-series numbers, call only between 9 AM and 9 PM, and honor opt-outs. The DPDP Act 2023 adds explicit data consent obligations on top. For BFSI and insurance, sector-specific rules from RBI and IRDAI run alongside TRAI's framework.
The question for any business running outbound AI voice campaigns is not whether rules apply. It is whether the platform enforces those rules at the infrastructure level, not just the policy level.
If you want to see how a TRAI-compliant AI voice campaign runs in practice, schedule a demo with SquadStack.
FAQ
Q: Which AI voice calling platform is best for TRAI-compliant outbound sales in India?
Look for a platform that enforces TRAI rules at the infrastructure level: hard calling-hour blocks, automated DND scrubbing, 140-series number provisioning, and DLT-registered headers. SquadStack is built for Indian-market outbound at scale and holds ISO 27001, SOC 2 Type II, DPDP, and TRAI compliance certifications, making it a strong fit for regulated industries like BFSI and insurance.
Q: Can AI voice bots handle TRAI-compliant collections calls in India?
Yes, provided the platform enforces RBI-specific rules on top of TRAI's base framework. This means respecting frequency limits, building dispute-escalation paths into the call flow, and handling opt-outs immediately. A voice AI platform without these controls should not be running collections campaigns for a regulated lender.
Q: What is the penalty for calling a DND number in India?
TRAI can levy financial penalties against registered telemarketers for DND violations. Repeated violations can lead to deregistration from the DLT platform, which effectively blocks the entity from making any further commercial calls. Consumers can also file complaints through the DND app or TRAI's portal.
Q: Does the DPDP Act 2023 change anything for AI voice calling campaigns?
Yes. The DPDP Act requires that personal data used in a campaign, including the lead's phone number and any data collected during the call, must be processed only for the purpose the person consented to. Broad consent captured at lead acquisition does not automatically cover every downstream use. Businesses need documented, purpose-specific consent and clear data retention limits.
Q: What is a 140-series number and why does it matter for outbound calls?
TRAI requires that promotional and transactional outbound calls use numbers in the 140-series range rather than regular 10-digit mobile or landline numbers. This helps call recipients identify commercial calls and gives TRAI a way to trace and regulate commercial communication traffic. Using a regular number for promotional calling is a direct TRAI violation.
Q: What is DLT registration and how does a business get it?
DLT stands for Distributed Ledger Technology, the platform TRAI mandates for telemarketer registration. A business must register its entity, calling headers, and message templates on the DLT platform before running any commercial voice campaign. Telecom operators and approved third-party platforms facilitate the registration process.
Q: How often should DND scrubbing happen in an AI calling campaign?
Before every campaign run, not just at setup. Lead lists change, new numbers are added to the registry, and a number that was clean at onboarding might be on the registry three months later. Automated, pre-campaign scrubbing is the only way to stay consistently compliant.
Q: Are transactional calls treated differently from promotional calls under TRAI?
Yes. TRAI distinguishes between promotional communications (selling a product or service) and transactional communications (a service update, an OTP, a delivery notification). Transactional calls have a lighter consent requirement, but they must still use registered headers and comply with calling-hour rules. Misclassifying a promotional call as transactional to avoid consent requirements is a common compliance error.
Q: What happens during a TRAI audit of an outbound calling campaign?
TRAI can request records of telemarketer registration, DLT-registered headers, DND scrubbing logs, and consumer complaint responses. A business without clean documentation of these, even if the calls themselves were compliant, faces the same risks as one that was actively non-compliant. Good AI calling platforms maintain audit-ready logs automatically.
Q: How does SquadStack handle TRAI compliance in production?
SquadStack enforces calling-hour restrictions as a hard system block: no call can be placed outside the 9 AM to 9 PM window regardless of campaign configuration. Lead lists are scrubbed against the TRAI DND registry and client-uploaded internal DND lists before dialing. Only 140-series numbers are used for outbound campaigns. Consent gating and opt-out handling are built into the call flow itself, not managed manually. The platform holds TRAI, DPDP, ISO 27001, ISO 27701, and SOC 2 Type II certifications. For more on how the outbound architecture is set up, see SquadStack's AI voice agent for sales automation and voice bots in India pages.




