TRAI direction F.No. D-27/1/(2)/2024-QoS (E-13563) · 20 Aug 2024
Official title
Direction on regarding measures to curb misuse of Headers and Content Templates under Telecom Commercial Communications Customer Preference Regulations, 2018
Official record
Open source pageSummary
Check the official recordThe Telecom Regulatory Authority of India has issued a direction to all Access Providers to address the persistent misuse of Headers and Content Templates under the Telecom Commercial Communications Customer Preference Regulations, 2018. Access Providers are required to implement the 140xxx numbering series on the DLT platform by September 30, 2024. Effective September 1, 2024, traffic containing non-whitelisted URLs, APKs, OTT links, or call-back numbers is prohibited. From November 1, 2024, messages with undefined or mismatched telemarketer chains must be rejected. The direction mandates strict suspension protocols for senders and telemarketers involved in misuse, requires re-verification of all DLT-registered assets within 30 days, and prohibits linking a single content template to multiple headers.
What you must do
August 20, 2024
DIRECTION
Subject: Direction under section 13, read with sub clauses (i) and (v) of clause (b) of sub-section (1) of section 11, of the Telecom Regulatory Authority of India Act, 1997 (24 of 1997) regarding measures to curb misuse of Headers and Content Templates under Telecom Commercial Communications Customer Preference Regulations, 2018 (6 of 2018)
F.No. D-27/1/(2)/2024-QoS (E-13563) - Whereas the Telecom Regulatory Authority of India (hereinafter referred as the “Authority”), established under sub-section (1) of section 3 of the Telecom Regulatory Authority of India Act, 1997 (24 of 1997) (hereinafter referred to as “TRAI Act”), has been entrusted with discharge of certain functions, inter alia, to regulate the telecommunication services; ensure technical compatibility and effective inter-connection between different service providers; lay-down the standards of quality of service to be provided by the service providers and ensure the quality of service and conduct the periodical survey of such services provided by the service providers so as to protect the interest of the consumers of telecommunication service;
And whereas the Authority, in exercise of the powers conferred upon it under section 36, read with sub-clause (v) of clause (b) and clause (c) of sub-section (1) of section 11, of the TRAI Act, made the Telecom Commercial Communications Customer Preference Regulations, 2018 (6 of 2018) dated the 19th July, 2018 (hereinafter referred to as the “regulations”), to regulate unsolicited commercial communications;
And whereas regulation 17 of the regulations provides that the Authority may direct Access Providers to make changes, at any time, in the Code of Practice (hereinafter referred to as “CoPs”) and Access Providers shall incorporate such changes and submit revised CoPs within fifteen days from the date of direction issued in this regard;
And whereas the Authority, vide Direction No. RG-25/(6)/2022-QoS dated 16th February, 2023, directed the Access Providers to, inter alia, ensure re-verification of all Headers registered on DLT platform within thirty days from the date of issue of the direction and blocking of unverified headers; ensure re-verification of all Content Templates within sixty days of issue of the direction and blocking of unverified templates; and comply with the direction and forward updated status on actions taken, including updating of CoPs, within thirty days from date of issue of the said direction;
And whereas the Authority, vide Direction No. RG-25/(6)/2022-QoS dated 12th May, 2023, in continuation of the direction dated 16th February 2023, referred to in para 4 above, directed all the Access Providers to, inter alia, ensure the use of only whitelisted URLs/ Apks/ OTT links/ call back numbers in the content template; ensure that, in case of an URL containing both fixed and variable parts, the fixed part of URL is whitelisted; to monitor the use of Content Templates and stop their misuse; and update the Code of Practice accordingly within fifteen days and furnish compliance report of the direction within forty five days from date of issue of the said direction;
And whereas the Authority, vide another Direction No. RG-25/(6)/2022-QoS dated 16th February, 2023, directed all the Access Providers to, inter alia, ensure traceability of messages from Principal Entity (PE) to the recipient at all times in all modes of transmission by obtaining from the PE the complete chain of the telemarketers engaged by such PE, including the registered telemarketers used in the chain between PE and OAP, for transmission for each message; reject all messages where the chain of TMs is not defined or does not match; and bar all telemarketers, who are not registered on Distributed Ledger Technologies (hereinafter referred to as "DLT") platform from handling the content template, scrubbing and delivery of messages to Access Provider;
And whereas the Authority, vide Direction No. M-5/11/(1)/2022-QoS dated 4th May 2024 directed all the Access Providers to, inter alia, implement Distributed Ledger Technology (DLT) based Voice Solution for 140 level numbering series as per the regulations, including migration of telemarketers from existing platform and updating Codes of Practice, within 60 days from the date of issue of the said direction;
And whereas, to facilitate discussion and to ensure expeditious implementation/ compliance of the directions issued by the Authority –
(a) meetings were held between the Authority and the Access Providers on 15th June 2023, 03rd July 2023, 21st July 2023, 26th September 2023, 29th November 2023, 05th January 2024, 03rd April 2024, 04th May 2024, and 08th August 2024; (b) the Authority, vide letter dated 22nd March 2024, directed the Access Providers to resolve/ set right all cases of resembling/ look-alike Headers latest by 30th June 2024; (c) six working groups were formed on 10th April 2024, comprising of technical team members from each Access Providers, and meetings were convened by the Authority on 18th April 2024, 19th April 2024, 26th April 2024, 02nd May 2024, 04th May 2024, 16th May 2024, 17th May 2024, 29th May 2024, 08th June 2024, 22nd June 2024, 27th June 2024, and 12th July 2024;
(a) the directions referred to in para 4, 5, and 6 above have not been implemented, in entirety, till date; (b) many instances of misuse of headers and templates have been reported, however, Access Providers have not taken effective steps to prevent such misuse and trace the origination of the traffic when such incidences are reported; (c) Indian Cyber Crime Coordination Centre (hereinafter referred to as “I4C”) through its various reports, has brought to the notice of the Authority many cases of misuse of Entity ID, Header ID, and Content Template ID, and indicated the need to trace the Telemarketer who had sent messages using the compromised Headers, and further, I4C has also suggested to ensure traceability of messages by implementing the Telemarketers and Principal Entities chain binding; (d) in some cases, there is no correlation among the Entity Name, Headers and Content Templates, in many instances words like ‘disconnection’, ‘lottery’, ‘OTP’, etc. are used in the Content Templates which are not related to the business of the Senders and malicious APKs and URLs have also been found in some messages; (e) one Content Template has been linked to multiple headers and many similar or identical Content Templates are registered by the Access Providers; (f) registration of promotional Content Templates has been carried out in the service/ transactional category; (g) some Senders have registered a large number of Headers and Content Templates and many Content Templates contain a large number of variables; (h) in some cases, the Sender registers Headers with other Access Provider if any or all of its Headers are backlisted by an Access Provider; (i) Access Providers had temporarily blocked Headers which remained unused for a period of thirty (30) days in the month of October-2023 and November-2023, and citing technical challenges with DLT platform, sought relaxation for a period of three months; however, this activity has not been re-started till date; and (j) Access Providers have not fully implemented Distributed Ledger Technology (DLT) based voice solution for 140-level numbering series as per the regulations;
Key dates
Who is affected
Thresholds
If you do not comply