രാജ്യത്ത് ഭക്ഷ്യസുരക്ഷാ പരിശോധന കർശനമാക്കുന്നുകണ്ടെയ്നർ നീക്കത്തിൽ കൊച്ചിൻ തുറമുഖത്തിന് റിക്കാർഡ് കുതിപ്പ്പഴയ സ്വർണം മാറ്റിവാങ്ങാൻ വൻ തിരക്ക്ബ്രിക്സ് ഉച്ചകോടിക്ക് ഒരുങ്ങി ദില്ലി; അംഗരാജ്യങ്ങളുടെ പ്രധാന സെഷൻ ശനിയാഴ്ചവികസന പദ്ധതികളുടെ ഏകോപനത്തിന് ‘റൗണ്ട് ടേബിൾ കോൺഫറൻസ്’ സംഘടിപ്പിക്കാൻ കേരളം

Why Consent Verification Responsibility Should Rest With the TAP

By Rahul Vatts, Group Chief Regulatory Officer and Director – Corporate Affairs, Bharti Airtel

An unwanted promotional message generally reaches a customer because the sender assumes that the necessary permission was obtained during an earlier interaction.

The customer could have provided consent while opening an account, registering for a service, downloading an application or completing a form. However, promotional communication may continue long after that original interaction, leaving the customer to question why such messages are still being delivered.

Consent should not be treated as permanent.

Customer preferences continually evolve. People may develop new interests, stop using products, switch service providers or decide that they no longer wish to receive communication from a specific company. Consent granted during a previous interaction may, therefore, not represent what the customer wants today.

This raises an important question should consent given at one point continue to remain valid for promotional communication without taking the customer’s current intent into consideration?

This question is central to India’s ongoing efforts to deal with spam.

India has steadily reinforced the regulatory framework governing commercial communication. The Telecom Commercial Communications Customer Preference Regulations (TCCCPR), Distributed Ledger Technology (DLT), registration requirements for entities, template-verification mechanisms and the Digital Consent Acquisition (DCA) framework have collectively created a comprehensive anti-spam regulatory ecosystem.

The regulatory foundation has already been established. The challenge now is to ensure that consent is enforced at the most appropriate stage of the messaging process.

Under the proposed DCA framework, consent acquisition, recording and validation largely occur upstream. Originating Access Providers (OAPs) and other participants in the messaging ecosystem play a central role in onboarding enterprises, maintaining consent records and enabling messages to originate.

However, these entities do not manage the continuing relationship with the customer who eventually receives the message.

That responsibility rests with the Terminating Access Provider (TAP) the customer’s telecom operator.

The TAP provides services directly to the subscriber, manages customer preferences, handles spam complaints and reports, and bears the responsibility of maintaining customer trust. When subscribers receive unwanted communication, they contact their own operator for assistance.

Despite carrying this responsibility, the TAP does not control the consent-verification mechanism that determines whether a commercial message should be delivered to the subscriber.

This results in a disconnect within the existing framework. The entities responsible for acquiring and maintaining consent may remain separate from the customer relationship, while the operator expected to protect the customer has limited authority over the consent records governing message delivery.

Consent acquisition and consent enforcement are consequently positioned at different levels of the ecosystem.

The impact of this separation can be observed in the DLT ecosystem. Of the 32,095 blacklisted entities currently identified on the platform, nearly 87 percent are associated with only two OAP-only telecom operators. One operator accounts for approximately 53 percent of the blacklisted entities, while another accounts for around 34 percent.

In the quarter ended March 2026, nearly 40 percent of all blacklisted templates were linked to a single operator.

These figures indicate a structural concern when consent verification is separated from the customer relationship, enforcement can depend on records that may not reflect the subscriber’s current preferences.

Consent captures customer intent at a particular point in time and should be capable of changing whenever that intent changes. In an increasingly digital economy, consent must operate as a dynamic choice rather than remain a static historical record.

A TAP-led approach to consent management should therefore be considered. Under a TAP-led DCA framework, the subscriber’s telecom operator would capture, validate, store and enforce customer consent. Before allowing a commercial message to reach the subscriber, the TAP would verify that consent against the customer’s current preferences and consent status.

This model would deliver several benefits.

First, it would bring authority and accountability into alignment. The operator responsible for protecting the customer would also have the authority to determine whether a commercial communication should be delivered. This would address the present separation between the entity maintaining consent and the operator responsible for customer protection.

Second, it would enable consent to be enforced in real time. Rather than relying exclusively on historical records, the verification process could consider current customer preferences, consent revocations, complaint history and ongoing engagement.

Third, it would strengthen data governance by allowing sensitive consent information to remain within the ecosystem closest to the subscriber. This would reduce the unnecessary duplication of consent records across different intermediaries and support stronger confidentiality and oversight.

Fourth, it would provide customer-facing operators with greater operational agility. They could deploy new user controls, security features and protection mechanisms more quickly while preserving interoperability through common industry standards.

Most importantly, a TAP-led model would position consent closer to the customer.

India has already established a strong foundation for controlling spam. Existing measures have significantly reduced the misuse of telecom resources and created a robust compliance ecosystem.

However, fraudulent communication methods continue to evolve. The focus must now extend beyond verifying consent when it is acquired to enforcing it when a commercial message is about to be delivered.

India has demonstrated its ability to develop world-class digital infrastructure. The next step is to unite customer protection, consent enforcement and accountability within a unified framework.

As digital communication continues to expand, customer trust will increasingly depend on whether consent reflects what a subscriber wants now, rather than what the subscriber may have agreed to previously.

Meaningful consent should ultimately be determined not only when it is collected, but also when a message is delivered.

X
Top