
Introduction
France’s decision to prohibit unsolicited telemarketing calls from August 2026 onwards marks a significant shift in the philosophy of consumer protection. Rather than requiring consumers to register their objection to marketing calls, the French approach reverses the presumption itself, businesses must obtain consent before making the call. The distinction is important because it determines where the burden lies. Under an opt-out model, the consumer must communicate that they do not wish to be contacted, whereas under an opt-in model, the business must establish that the consumer agreed to receive the communication in the first place.
For India, where mobile phones have become the primary channel for banking, commerce, insurance, financial services and everyday communication, the French approach raises an important regulatory question. India already has a telecom framework governing unsolicited commercial communication and is simultaneously moving towards a comprehensive data protection regime under the Digital Personal Data Protection Act, 2023 (“DPDP Act”). However, the two frameworks do not necessarily regulate the same aspect of a marketing call. While telecom regulation focuses on the communication itself, the DPDP Act primarily regulates the processing of personal data underlying that communication.
The result is a regulatory intersection in which a consumer may receive an unwanted call that raises questions under telecom law, data protection law, or both. The more fundamental question is therefore whether India’s existing framework places the burden of establishing consent sufficiently clearly upon the person making the call.
Consent Under the DPDP Act, 2023: Is “Yes” Really Required?
The DPDP Act is fundamentally structured around lawful and transparent processing of digital personal data. Section 6 provides that consent must be free, specific, informed, unconditional and unambiguous, accompanied by clear affirmative action and limited to the personal data necessary for the specified purpose. Section 5 of the Act further requires a Data Fiduciary to provide notice containing information concerning the personal data proposed to be processed and the purpose for which such processing is intended.
The Act also provides individuals with the ability to withdraw consent, with the withdrawal mechanism required to be as easy as the mechanism through which consent was given. These provisions establish a relatively strong conception of affirmative consent. However, the difficulty arises because the DPDP Act does not specifically prohibit a business from making a telemarketing call. Its focus is the processing of digital personal data, while India’s telecom framework separately regulates unsolicited commercial communication.
This creates an important distinction. A business may possess a telephone number and have a lawful basis for processing it, while still being subject to restrictions on whether and how it can use telecommunications services for commercial communication. Conversely, a call may satisfy certain telecom requirements while the manner in which the telephone number was originally collected or subsequently shared may raise separate data protection concerns.
Therefore, consent to process a telephone number should not automatically be equated with consent to receive marketing calls.
From a Telephone Number to a Marketing Profile
The privacy implications of telemarketing become more significant when a telephone number does not remain limited to the purpose for which it was initially provided. A person may provide their number while applying for a loan, purchasing a product or registering for a service, only to subsequently receive marketing communications concerning unrelated financial products, insurance policies or commercial offers.
This raises questions of purpose limitation and data minimisation. If a telephone number was originally collected for providing a particular service, its subsequent use for unrelated marketing may require a separate legal justification. The issue becomes even more complicated where numbers are obtained through lead-generation companies or other third-party databases. The individual may have no knowledge of how their number entered the marketing chain or which entities ultimately obtained access to it.
The problem is therefore not limited to the unwanted call itself. The call may reveal a much larger data-processing chain in which personal information has travelled between multiple entities without the individual having a clear understanding of how or why it was being used. This is precisely where data protection principles become relevant to what otherwise appears to be a simple telemarketing problem.
The Accountability Problem: Who Is Responsible When a Vendor Makes the Call?
Modern telemarketing campaigns are frequently outsourced. Banks, insurers, fintech companies and other businesses may engage lead generators, call centres, customer-engagement platforms and other third-party service providers. This creates an additional question of accountability when an allegedly unauthorised marketing call is made.
Section 8 of the DPDP Act places obligations upon Data Fiduciaries concerning the processing of personal data and requires appropriate safeguards while also establishing accountability for processing undertaken through Data Processors. Consequently, a business cannot necessarily avoid responsibility merely by stating that the call was made by an external agency.
The practical difficulty lies in tracing consent. Once a telephone number has passed from a Data Fiduciary to a Data Processor and potentially through several downstream marketing entities, determining when and how the original Data Principal consented may become difficult. A contractual assurance from a marketing vendor that “consent was obtained” may therefore be inadequate if the business cannot produce a verifiable record demonstrating what the individual actually consented to.
In a data protection framework increasingly centred on accountability, the relevant question is not merely whether a vendor claims to possess consent, but whether the business relying upon that consent can demonstrate its origin, scope and continuing validity.
The Indian Regulatory Gap: Two Frameworks, One Phone Call
India’s telecom regulations and the DPDP Act operate in overlapping but distinct spheres. TRAI’s framework governing commercial communications addresses issues such as unsolicited commercial communication and customer preferences, including the National Customer Preference Register (“NCPR”). The DPDP Act, in contrast, regulates the processing of digital personal data and imposes obligations upon Data Fiduciaries.
For the consumer, however, these distinctions disappear when the phone rings. The individual may not know whether the call is problematic because their number was obtained without a lawful basis, because a marketing preference was ignored, because the caller exceeded the purpose for which the number was collected, or because several of these issues occurred simultaneously.
This fragmentation can also make enforcement more complicated. A telecom complaint may address the unwanted communication itself, while a data protection complaint may concern the collection, sharing or processing of the telephone number. The two issues are connected, but the regulatory mechanisms and remedies are not necessarily identical.
The result is a situation where the consumer may have to determine which regulator has jurisdiction over which part of the same marketing activity.
AMLEGALS Remarks
France’s move towards an opt-in approach to telemarketing reflects a broader regulatory principle that consent should be affirmative, specific and demonstrable rather than assumed from silence or the mere possession of a telephone number. India has not adopted an identical approach. However, the DPDP Act’s consent architecture, together with the existing TRAI framework governing unsolicited commercial communication, provides the foundations for a more accountability-driven approach to telemarketing.
For Data Fiduciaries and businesses conducting outbound campaigns, the practical lesson is clear. Consent obtained somewhere within a chain of vendors may not be sufficient if the business cannot demonstrate its origin, scope and validity. Maintaining an auditable consent trail, distinguishing service communications from promotional communications and exercising greater oversight over Data Processors will therefore become increasingly important.
For any queries or feedback, feel free to connect with mridusha.guha@amlegals.com or Khilansha.mukhija@amlegals.com
