Why the Customer’s Operator Must Hold the Keys to Consent
Lucknow : An unwanted promotional message usually reaches a customer on the assumption that permission to send it was granted at some point in the past.
The customer may have provided that consent while opening an account, registering for a service, downloading an application or completing a form. However, the communication can continue long after the original interaction, leaving the customer wondering why promotional messages are still being received.
Consent should not be considered permanent.
Customer preferences evolve continuously. People develop new interests, discontinue products, change service providers or decide that they no longer want to receive communication from a particular company. Permission provided during an earlier interaction may therefore not represent what the customer wants today.
This leads to an important question should consent provided once remain valid for promotional communication without any consideration of the customer’s current intent?
This question is central to India’s continuing efforts to address spam.
India has steadily strengthened the regulatory architecture governing commercial communication. The Telecom Commercial Communications Customer Preference Regulations (TCCCPR), Distributed Ledger Technology (DLT), registration requirements for entities, template-verification mechanisms and the Digital Consent Acquisition (DCA) framework have together created a comprehensive anti-spam regulatory ecosystem.
The regulatory foundation is already in place the challenge now is to ensure that consent is enforced at the most appropriate point in the messaging process.
Under the proposed DCA framework, the acquisition, recording and validation of consent largely happen upstream. Originating Access Providers (OAPs) and other participants in the messaging ecosystem play a central role in onboarding enterprises, maintaining consent records and enabling message origination.
However, these entities are not responsible for managing the continuing relationship with the customer who ultimately receives the message.
That responsibility lies with the Terminating Access Provider (TAP)—the customer’s own telecom operator.
The TAP provides services directly to the subscriber, manages customer preferences, handles spam reports and complaints, and carries the responsibility of maintaining customer trust. When subscribers receive unwanted communication, they approach their own operator for assistance.
Despite bearing this responsibility, the TAP does not control the consent-verification mechanism that determines whether a commercial message is delivered to the subscriber.
This creates a disconnect within the current framework; the entities responsible for acquiring and maintaining consent can remain removed from the customer relationship, while the operator expected to protect the customer has limited authority over the consent records governing message delivery.
Consent acquisition and consent enforcement are therefore separated at different levels of the ecosystem.
The consequences of this separation are visible in the DLT ecosystem. Of the 32,095 blacklisted entities currently identified on the platform, nearly 87 percent are associated with only two OAP-only telecom operators. One operator accounts for approximately 53 percent of the blacklisted entities, while another accounts for around 34 percent.
In the quarter ended March 2026, nearly 40 percent of all blacklisted templates were associated with a single operator.
These figures point to a structural concern when consent verification is separated from the customer relationship, enforcement can depend on records that may not capture the subscriber’s current preferences.
Consent reflects customer intent at a particular point in time it should be capable of changing when that intent changes. In an increasingly digital economy, consent must function as a dynamic choice rather than a static historical record.
A TAP-led approach to consent management should therefore be considered under a TAP-led DCA framework, the subscriber’s telecom operator would capture, validate, store and enforce customer consent. Before allowing a commercial message to reach the subscriber, the TAP would verify the consent against the customer’s present preferences and consent status.
This model would offer several benefits.
First, it would align accountability with authority. The operator responsible for protecting the customer would also have the authority to decide whether a commercial communication should be delivered; this would also address the existing separation between the entity maintaining consent and the operator responsible for customer protection.
Second, consent could be enforced in real time. Instead of relying exclusively on historical records, the verification process could consider present customer preferences, revocations, complaint history and ongoing engagement.
Third, it would improve data governance and sensitive consent information could remain within the ecosystem closest to the subscriber. This would reduce unnecessary replication of consent records across different intermediaries and support stronger confidentiality and oversight.
Fourth, it would provide customer-facing operators with greater operational agility; they could introduce new user controls, security features and protection mechanisms more quickly while preserving interoperability through common industry standards.
Most importantly, a TAP-led model would place consent closer to the customer.
India has already developed a strong foundation for controlling spam. Existing measures have significantly reduced the misuse of telecom resources and established a robust compliance ecosystem.
However, fraudulent communication methods continue to evolve. The focus must now extend beyond checking consent when it is acquired to enforcing it when a commercial message is about to be delivered.
India has demonstrated its ability to create world-class digital infrastructure. The next step is to bring customer protection, consent enforcement and accountability together within a unified framework.
As digital communication expands, customer trust will increasingly depend on whether consent reflects what a subscriber wants now, rather than what the subscriber may have agreed to in the past.
Meaningful consent should ultimately be determined not only when it is collected, but also when a message is delivered.
( By Rahul Vatts, Group Chief Regulatory Officer and Director – Corporate Affairs, Bharti Airtel)
---------------------------------------------
(Report by R.L.Pandey)
----------------------------------------------
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)