India orders spam-reporting apps to hand user data to telecoms, and Truecaller is not happy about it

India’s telecom regulator just handed telecom operators something valuable: a direct pipeline to the spam-report data that apps like Truecaller have spent years building from their users. Whether that actually helps users is a much harder question to answer.

According to TechCrunch, the Telecom Regulatory Authority of India (TRAI) amended its commercial communications rules, making it mandatory for caller-ID and call-management apps to send user spam reports to a blockchain-based platform maintained by telecom operators. The platform already tracks commercial communications and enforces anti-spam rules. TRAI’s stated goal is to connect the spam signals collected by apps with the enforcement systems run by operators, broadening the pool of data available to act against spammers.

Truecaller, the Stockholm-based company with more than 350 million active users in India alone, is calling the requirement a “one-way exchange” that is “anti-competitive.” That’s a pointed complaint. The company has built its core product around community spam reports, automated detection, and proprietary reputation signals. Forcing it to feed that data into a telecom-controlled platform, without any reciprocal data flow back, looks less like a public safety measure and more like a regulatory transfer of commercial value from a private app to the operators who also happen to be its competitors in the spam-management space.

The scale of the problem TRAI is trying to address is real. Truecaller reported that its Indian users encountered around 42 billion spam calls in 2025, with nearly 12 billion blocked outright. But big numbers don’t automatically justify broad data-sharing rules, especially when the privacy details remain vague. Kazim Rizvi from New Delhi-based policy think tank The Dialogue told TechCrunch that sharing a specific user spam report is fundamentally different from sharing the datasets, signals, and analytical systems behind spam detection. The rules, as written, don’t clearly specify which of those an app must hand over.

That ambiguity matters enormously for users. Are they being told their individual reports will be shared with operators? Are they consenting to that? What can operators do with that data afterward? TRAI has not answered those questions, and it also hasn’t said whether the rules apply to spam-detection features built into Android and iOS dialers, which would pull Google and Apple into the same compliance framework.

The amendments also bring AI-powered calling under TRAI’s application-to-person framework. Robocalls and calls using artificial or prerecorded voices must now be declared to telecom operators in advance, and undeclared automated calls will be treated as spam. Operators can also charge up to 5 paise per minute on such calls. But experts point out that the definition is broad enough to sweep in contact center software and click-to-call services where a human is still involved, which could create compliance headaches far beyond the spam problem the rules are meant to fix.

This is not the first time Truecaller and TRAI have clashed. The company previously pushed back against rules that prevented it from automatically labeling calls from certain government-designated number ranges as spam. Those restrictions remain in place. So the pattern here is consistent: TRAI is pulling spam enforcement tighter around the operators it directly regulates, while pushing the apps that users actually trust into a supporting, data-supplying role. Whether that benefits users, or just the telecoms, is the question regulators still haven’t answered.