All NotesCivil LawConsumer Protection Act

Consumer Protection Act

Unsolicited and Unwarranted Business Communications: Consumer Protection Against the Uninvited Pitch

The promotional call at dinner, the loan SMS from a ten-digit number, the chat-app blast from a brand the consumer never met: unsolicited commercial communication is the most universal consumer grievance in India, and its regulation sits at the junction of telecom law (TRAI) and consumer law (the Act and the CCPA's draft guidelines). This note explains the consumer-protection issues, the TRAI framework and its limits, the 2024 draft guidelines and their September 2026 successor, and the remedies that exist today.

1. The Consumer-Protection Issues

  • Privacy and intrusion: the uninvited pitch converts the consumer's attention and personal number into the seller's free inputs; where the number or profile was obtained from a prior transaction, the 2019 Act's unfair-practice clause on disclosure of personal information given in confidence is directly engaged.
  • Consent as the dividing line: communication the consumer invited is service; communication he did not is imposition, and everything in this field turns on whether valid, specific, revocable consent existed and was honoured.
  • The fraud gradient: the same channels carry marketing, mis-selling and outright scam, loan and lottery frauds, phishing, digital-arrest calls, so the regulation of commercial communication is also the first fence of fraud prevention.
  • The migration problem: as telecom-side enforcement tightened, volume migrated to WhatsApp, RCS and social platforms, and to ordinary ten-digit numbers, outside the registered-telemarketer architecture, the gap the consumer-law drafts exist to close.

2. The TRAI Framework and Its Limits

The operative machinery is TRAI's Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR): consumer preference registration (the DND regime, fully or category-wise blocking promotional traffic); registered senders with identifiable headers and registered content templates on distributed-ledger (DLT) systems; a digital consent framework in which consent is recorded, purpose-bound and revocable; complaint routes (1909 and the DND app) with graded penalties on telemarketers and access providers, and disconnection and blacklisting for unregistered senders; and successive tightenings (including the 2024 2025 amendments) on message traceability, header and URL whitelisting and promotional-call hours. Its limits are structural: TCCCPR binds telecom resources, so the unregistered individual number, and the internet-based message, the chat app, the social DM, the email, sit outside its registered architecture, and enforcement reaches the telemarketer faster than the business whose product is being sold. Those two gaps, the OTT channel and the principal's liability, are precisely what consumer law is positioned to fill.

3. The Consumer-Law Drafts: 2024 and 2026

  • The 2024 draft: the Department of Consumer Affairs' draft Guidelines for Prevention and Regulation of Unsolicited and Unwarranted Business Communication, 2024 (released for comment in June 2024) proposed the two working definitions, unsolicited: a commercial communication made without the recipient's consent or registered preference; unwarranted: one outside the scope of the consent given or the prescribed norms (hours, frequency, purpose), and the decisive mapping: any such communication would constitute an unfair trade practice and a violation of consumer rights, with liability on the maker of the call, the sender, and the business whose goods or services are promoted, every mode of communication covered. The draft was consulted on but not finalised.
  • The September 2026 draft: the CCPA's proposed Guidelines for Prevention and Regulation of Pesky, Promotional and Unsolicited Commercial Communications, 2026 carry the design forward: commercial communication defined across text, voice, image, video and files, on telecom networks and internet-based services alike, OTT messaging, RCS, social media; liability reaching senders, intermediaries and the businesses whose names the messages carry, including unregistered senders on ordinary numbers; transactional messages (OTPs, alerts, confirmations) and government communications exempt; and, distinctively, mandatory upfront disclosure of AI-generated or synthetic voices and text in promotional communication, audible in calls, visible in messages. As a draft, it binds no one yet; as policy, it marks where the field is going.

4. Remedies Today, and the Converging Design

Pending finalisation, the consumer is not remediless. The TRAI route: DND registration, the 1909/DND-app complaint against registered-network spam, with penalties and disconnection on the telecom side. The consumer-law route: the business that obtained the consumer's details in a transaction and turned them into marketing engages the unfair-practice clauses (including the personal-information clause), the harassing pursuit of a consumer is conduct the Commissions weigh in compensation, and the CCPA's class powers reach the campaign, not merely the call. The data-protection layer: the Digital Personal Data Protection Act's consent, purpose-limitation and withdrawal principles govern the number's use as personal data, adding a third regulator to the field. The converging design is visible across all three: consent, recorded, specific, revocable, as the only licence to communicate commercially, identification of the sender and the principal, honest hours and content, and liability that follows the beneficiary of the message, not only its carrier.

⚠ Key point

The uninvited commercial communication is regulated on two rails. TRAI's TCCCPR: DND preferences, registered senders and DLT consent, complaints and telecom-side penalties, limited to telecom resources and telemarketers. Consumer law: the 2024 draft (unsolicited = without consent or preference; unwarranted = outside consent's scope) and the September 2026 draft extending to OTT and social channels with AI-disclosure duties, both mapping the spam to unfair trade practice and rights violation with liability on the promoted business, neither yet final. Today's remedies: the DND machinery, the unfair-practice and personal-information clauses, the CCPA's class powers, and the data-protection consent regime.

5. Related Topics and Provisions

  • Unfair trade practice (Topic 16): the personal-information clause and the mapping's destination
  • Emerging CCPA guidelines (Topic 82): the field in one place
  • Dark patterns (Topics 77 to 81): the sibling regulation of digital manipulation
  • Consumer rights under Section 2(9) (Topic 23): the privacy face of the rights charter