38. Repeal and Saving. Save as provided hereunder, The Telecom Commercial Communications Customer Preference Regulations, 2010 (6 of 2010) are hereby repealed. Notwithstanding the repeal of the Telecom Commercial Communications Customer Preference Regulations, 2010 (6 of 2010),
(a) anything done, or any action taken or purported to have been done under the said regulations shall be deemed to have been done or taken under the corresponding provisions of these regulations;
(b) the provisions contained in Regulations 2 to 13, 16 to 20, 21 and 22 of the Telecom Commercial Communications Customer Preference Regulations, 2010 (6 of 2010) shall remain in force until these regulations come into force in their entirety.
SCHEDULE I
Action Items for preparing Code of Practice for Entity(ies) (CoP-Entities)
1. Entity Registration Functionality:
(1) All entities with associated functions, who will be carrying out given functions for effective control of Unsolicited Commercial Communications being delivered through them, shall be declared by each Access Provider on their websites;
(2) any individual, business entity or legal entity may carry out one or more functions while keeping all records and execution of functions separately against each activity for internal audit by the access provider to ensure the effectiveness of Unsolicited Commercial Communications control to meet regulatory outcomes specified in the regulations;
(3) each functional entity shall be given unique identity by the access provider(s) to be used to authenticate and track the events;
2. Every Access Provider shall formulate structure and format for headers to be assigned Senders for the purpose of commercial communications via sending SMS or making voice calls to participants which shall include following
(1) SMS Header, SMS Header Root, SMS Header Branch for Senders sending Promotional SMS, Transactional SMS and Service SMS from 11-character alphanumeric strings which are not allocated or assigned by DoT for other purpose(s) or in accordance to directions of the Authority/ DoT;
(2) Calling Line Identity for Senders making Promotional Voice Calls, Transactional Voice Calls and Service Voice Calls from 140-level numbering series or any other numbering series directed by the Authority/DoT;
3. Every Access Provider shall formulate Code of Practice for Entities (CoP-Entities) involved from registered sender(s) to recipient(s) and
(1) CoP-Entities shall include at least following entities
(a) Header Registrar;
(b) Consent Registrar;
(c) Consent Template Registrar;
(d) Content Template Registrar;
(e) Content Template Verifier;
(f) Telemarketer Functional Entity Registrar for various functions prescribed in the relevant regulation(s);
(g) timeline(s) for implementation of the functionality referred in code of practice and operationalizing it;
(h) such other matters as the Authority may deem fit, from time to time;
(2) CoP-Entities shall also include at least following Distributed Ledger Nodes for the purpose of
(a) Header Register;
(b) Consent Register;
(c) Consent Template Register;
(d) Content Template Register;
(e) Content Template Verifier;
(f) Complaint Register;
(g) Preference Register;
(h) Telemarketer Scrubbing Function Register;
(i) Telemarketer Message Delivery Function Register;
(j) Telemarketer Voice Delivery Function Register;
(3) CoP-Entities shall include at least following
(a) implementation details for all functional entities;
(b) additional measures, as deemed fit by access provider(s), for functional entities required to ensure regulatory compliance;
(c) minimum standards of technical measures to effectively control the sending of unsolicited commercial electronic messages;
(d) technical mechanism to make available latest version of relevant and reliable data for an entity to carry out its desired function;
(e) such other matters as the Authority may deem fit, from time to time.
4. Every Access Provider shall carry out following functions
(1) Header Registration Function (HRF)
(a) assign header or Header root for SMS via Header Registration Functionality, on its own or through its agents, as per allocation and assignment principles and policies, to facilitate content provider or principal entity to get new headers;
(b) carry out pre-verifications of documents and credentials submitted by an individual, business entity or legal entity requesting for assigning of the header;
(c) bind with a mobile device and mobile number(s), in a secure and safe manner, which shall be used subsequently on regular intervals for logins to the sessions by the header assignee;
(d) carry out additional authentications in case of a request for headers to be issued to SEBI registered brokers or other entities specified by Authority by directions, orders or instructions issued from time to time;
(e) carry out additional authentications in case of a request for headers to be issued to government entities, corporate(s) or well-known brands, including specific directions, orders or instructions, if any, issued from time to time by the Authority;
(f) carry out additional checks for look-alike headers which may mislead to a common recipient of commercial communication, it may also include proximity checks, similarity after substring swaps specifically in case of government entities, corporate(s), well-known brands while assigning headers irrespective of current assignments of such headers, and to follow specific directions, orders or instructions, if any, issued from time to time by the Authority;
(2) Consent Registration Function (CRF)
(a) record consent via Customer Consent Acquisition Functionality on Consent Register, on its own or through its agents, to facilitate consent acquirers to record the consent taken from the customers in a robust manner which is immutable and non-repudiable and as specified by relevant regulations;
(b) Presenting content of consent acquisition template to the customer before taking consent;
(c) Taking agreement to the purpose of consent and details of sender;
(d) Authenticate customer giving the consent through OTP;
(e) record revocation of consent by the customer via revoke request in a robust manner which is immutable and non-repudiable and as specified by relevant regulations;
(f) record sufficient contact information, valid for at least 30 days, required to revoke consent and present it to recipient to enable them to submit request for revoking consent;
(3) Content Template Registration Function (CTRF)
(a) to check content of the template being offered for registration as a transactional template and service message template;
(b) to identify fixed and variable portion(s) of the content in the offered transactional template and service message template with identification of type of content for each portion of variable part of the content, e.g. date format, numeric format, name of recipient, amount with currency; reference number, transaction identity;
(c) to estimate the total length of variable portion, viz. total length of fixed portion for a typical transactional message, service message for offered template;
(d) to de-register template or temporarily suspend use of template;
(e) to generate one-way hash for fixed portion of content of template and ways to extract fixed portion and variable portion(s) from actual message for carrying out pre and post checks of actual content of actual message offered for delivery or already delivered;
(f) to check content of the template being offered for registration as a promotional from perspective of content category;
(g) assigning unique template identity to registered template of content;
(4) Scrubbing function (SF)
(a) to process scrubbing as defined, in a secure and safe manner, using preferences and consent of customer(s) and category of content;
(b) provide details about preferred time slots and types of days for delivery;
(c) take necessary measures to protect Preference Register and Consent Register data during scrubbing, e.g. by Generating virtual identities and tokens for each number for the messages and voice calls and not disclosing real identities to any other entity than authorized to know it;
(d) make available relevant details of scrubbed list to corresponding OAPs and TAPs for carrying out reverse mapping of virtual identities to real identities for further delivery;
(e) to identify and report probable instances of request received for scrubbing of list of phone numbers collected through harvesting software or instances of dictionary attack to relevant entities authorized to take action;
(5) Content Verification Function (CVF)
(a) to identify the content type and category of messages to be delivered or already delivered via an automated tool or utility software;
(6) Delivery Function for Messages with Telecom Resource Connectivity to Access Provider (DF)
(a) deliver messages to OAP, in a secure and safe manner, during specified time slots and types of days of delivery in accordance to the preferences of the customer(s);
*[(b)] select OAP for particular customer(s) or messages and conveying to Scrubber for generating tokens for corresponding OAP to access information of list of messages which would be required to be delivered by it;
(7) Aggregation Function for Message to other Telemarketer for delivery function (AF)
(a) deliver messages to RTM having telecom resource connectivity with access provider(s), in a secure and safe manner;
(8) Voice Calling Function with Telecom Resource Connectivity (VCF)
(a) deliver voice calls to OAP, in a secure and safe manner, during specified time slots and types of days of delivery in accordance to the preferences of the customer(s);
(b) select OAP for particular customer(s) or voice calls and conveying selected OAPs to Scrubber for generating tokens for corresponding OAP to access information of list of messages which would be required to be delivered by it;
5. Every Access Provider shall set up following functional entities or may delegate roles to perform following functions
(1) Header Registrar (HR) to
(a) establish and maintain header register as distributed ledger to keep headers, in a secure and safe manner, and make accessible relevant information for identifying the assignee at the time of request to carry out various functions, e.g. scrubbing function from the registered telemarketers for scrubbing, delivery function from telemarketer;
(b) carry out Header Registration Function;
(c) keep record of headers throughout its lifecycle, i.e. free for assignment, assigned to an entity, withdrawn, surrendered, re-assigned etc.;
(d) keep record of header(s), header root(s) reserved for specific purpose;
(e) synchronize records, in real time, among all header ledgers available with participating nodes in Header Registration Functionality in an immutable and non-repudiable manner;
(f) maintain with minimum performance requirements as specified;
(g) perform any other function and keep relevant details required for carrying out pre and post checks for regulatory compliance;
(2) Consent Registrar (CR) to
(a) establish and maintain consent register as distributed ledger to keep consent, in a secure and safe manner, and make accessible relevant data for scrubbing function to the registered telemarketers for scrubbing;
(b) establish Customer Consent Acquisition Facility (CCAF), to record recipient's consent to receive commercial communications from the sender or consent acquirer;
(c) establish Customer Consent Verification Facility (CCVF) for the purpose of facilitating
(i) customers to verify, modify, renew or revoke their consent in respect of commercial communications, and
(ii) Access Providers to verify the consent in case of complaint;
(d) keep consent for each consent acquirer, in a manner that client data of entity is adequately protected;
(e) keep record of revocation of consent by the customer, whenever exercised, in an immutable and non-repudiable manner;
(f) synchronize records, in real time, among all consent ledgers available with participating nodes in Consent Acquisition Functionality in an immutable and non-repudiable manner;
(g) maintain with minimum performance requirements as specified;
(h) perform any other function and keep relevant details required for carrying out pre and post checks for regulatory compliance;
(3) Content Template Registrar (CTR) to
(a) carry out content template registration function;
(b) keep records of registered templates in immutable and non repudiable manner;
(c) maintain with minimum performance requirements as specified;
(d) perform any other function and keep relevant details required for carrying out pre and post checks for regulatory compliance;
(4) Content Format and Type Verifiers (CFTV) to
(a) carry out content verification;
(b) keep records with all relevant details for future references;
(5) Telemarketers for Scrubbing function (TM-SF) to
(a) carry out scrubbing;
*[(b)] keep record of all numbers scrubbed for complaints resolution;
*[(c)] maintain with minimum performance requirements as specified;
*[(d)] perform any other function and keep relevant details required for carrying out pre and post checks for regulatory compliance;
(6) Telemarketers for Delivery Function of Messages with telecom resource connectivity to AP (TM-DF) to
(a) carry out delivery function
(b) insert its Unique identity with delivery processing reference number along with identity through which scrubbing was carried out;
(c) authenticate source of the messages submitted for delivery by header assignee or by aggregator and ensure their identity is part of content of message for traceability;
(d) maintain with minimum performance requirements as specified;
(e) perform any other function and keep other relevant details which may be required for carrying out pre and post checks for regulatory compliance;
(7) Telemarketers for Aggregation Function for messages to other Telemarketer for delivery function (TM-AF) to
(a) carry out aggregation function;
(b) keep record of all numbers aggregated for complaints resolution and traceability;
(c) authenticate source of the messages submitted for delivery by header assignee or by aggregator and ensure their identity is part of content of message for traceability;
(d) maintain with minimum performance requirements as specified;
(e) perform any other function and keep other relevant details which may be required for carrying out pre and post checks for regulatory compliance;
(8) Telemarketer for voice calling function with Telecom Resource Connectivity for voice calls to Access Provider (TM-VCF) to
(a) to carry out voice calling function;
(b) take necessary measures to protect Preference Register and Consent Register data during voice calling, e.g. using virtual identities to make voice calls on a secure Internet Protocol (IP) based Virtual Private Networks (VPN) with OAP and not disclosing real identities to any other entities than authorized to know it;
(c) take initiatives to enable calling name display (CNAM) based on Intelligent Network or ISDN based protocols, enhanced calling name (eCNAM) functionality as defined in 3GPP technical specifications TS 24.196 for providing services to terminating user with the name associated with the originating user and optionally delivering metadata about that originating user;
(d) maintain with minimum performance requirements as specified;
(e) perform any other function and keep other relevant details which may be required for carrying out pre and post checks for regulatory compliance;
6. Every Access Provider shall ensure that
(1) content of any commercial communication sent by the sender(s) shall be categorized and compared with the list of preference(s) of the recipient and/or purpose of consent given by the recipient to the sender for the purpose of scrubbing and for this purpose access provider shall ensure that
(a) any commercial communication through its network takes place only using registered content template(s) for transaction and/ or content template(s) for promotion;
(b) Unique Identity for registered template of content shall be assigned to the sender(s) at the time of registration of content template;
(c) Following Label shall be prefixed by the access provider to the text of commercial communication
(i) Label <Transactional> in case of Transactional Message;
(ii) Label <Service> in case of Service Message;
(iii) Label <Promotional> in case of Promotional Message;
(d) Every Access Provider shall suffix relevant information required to revoke the consent to the text of promotional message;
(e) Content template shall be recorded on Distributed Ledger for Content Template (DL-CT) in an immutable and non repudiable manner;
(2) commercial communication is sent to the particular telephone number(s) in the target list of telephone numbers provided by the sender, to whom he wishes to send commercial communication only after scrubbing the target list and scrubbing includes
(a) verification of preference(s) by comparing the target telephone numbers, category of content with the list of telephone numbers and preference(s) of category of content by the target recipient customer in the Distributed Ledger for Preference (DL-Preference); and
(b) verification of consent(s) by comparing the target telephone number(s), category of content with the list of telephone numbers and consent(s) given by the recipient to the sender in the Distributed Ledger for Consent (DL-Consent); and
(c) verification of time band(s) by comparing the target telephone number(s), type of target time band for delivery with the list of telephone numbers and preference(s) of time band(s) of target recipient customer in Distributed Ledger for Preference (DL-Preference); and
(d) verification of type of day(s) by comparing the target telephone number(s), type of target day(s) for delivery with the list of telephone numbers and preference(s) of type of day(s) of target recipient customer in Distributed Ledger for Preference (DL-Preference);
(e) output of scrubbed list is a positive match of verifications in either of 2(a) or 2(b) as consent given by the recipient to the sender(s) shall override choice of preference(s) made by the recipient customer and positive match of verifications in 2(c) or 2(d);
7. Every Access Provider shall formulate
(1) Message Sequence Charts for messages with parameter details and time sequence to provide details about the process between two entities and action taken by particular entity;
(2) Flow Charts to provide details about the process between two entities and action taken
SCHEDULE II
Code of Practice for Process of registration, modification or deregistration of Preferences, recording consent and revocation of consent
1. Procedure for registration or change of preference of Categories of content for Commercial Communications:
*[(1)] Customer can opt-out for any or all of following Commercial Communications Content category(ies) of content:
| Commercial Communications Category to be blocked or opted out |
IVRS: Call to 1909 and press at prompt to block |
SMS: Send SMS to 1909 following text |
USSD: Dial USSD String |
| All CC Categories (to be blocked) except transactional type of commercial communications |
0 |
FULLY BLOCK |
*1909*0# |
| All CC Categories (to be blocked) except transactional and service type of commercial communications |
50 |
BLOCK PROMO |
*1909*50# |
| (i) Banking/Insurance/Financial products/ credit cards, |
1 |
BLOCK 1 |
*1909*1# |
| (ii) Real Estate, |
2 |
BLOCK 2 |
*1909*2# |
| (iii) Education, |
3 |
BLOCK 3 |
*1909*3# |
| (iv) Health, |
4 |
BLOCK 4 |
*1909*4# |
| (v) Consumer goods and automobiles, |
5 |
BLOCK 5 |
*1909*5# |
| (vi) Communication/Broadcasting/ Entertainment/IT, |
6 |
BLOCK 6 |
*1909*6# |
| (vii) Tourism and Leisure, |
7 |
BLOCK 7 |
*1909*7# |
| (viii) Food and Beverages; |
8 |
BLOCK 8 |
*1909*8# |
Note-1: In case of communication with customer executive of Customer Care Center of access provider, preference to opt-out may be communicated;
Note-2: Customer to be communicated with confirmation and final status along with options to unblock;
Note-3: FULLY BLOCK option shall put the customer in Fully Blocked state and block service as well as promotional types of commercial communications for all categories of content, mode, time band and day types;
Note-4: BLOCK PROMO option shall block only promotional types of commercial communications for all categories of content, mode, time band and day types except service and transaction type of commercial communications;
Provided that the Authority may, from time to time, add or remove number of category(ies), or sub category(ies) for content;
*[(2)] Customer can opt-in for any or all of following Commercial Communications Content category(ies) of content:
| UCC Category to be unblocked or opted in |
IVRS: Call to 1909 and press at prompt to unblock |
SMS to 1909 following text |
USSD send |
| All UCC Categories (to be unblocked) |
90 |
UNBLOCK ALL |
*#1909*90# |
| All UCC Categories (to be unblocked) except Promotional |
51 |
UNBLOCK SERVICE |
*#1909*51# |
| (i) Banking/Insurance/Financial products/credit cards, |
91 |
UNBLOCK 91 |
*#1909*91# |
| (ii) Real Estate, |
92 |
UNBLOCK 92 |
*#1909*92# |
| (iii) Education, |
93 |
UNBLOCK 93 |
*#1909*93# |
| (iv) Health, |
94 |
UNBLOCK 94 |
*#1909*94# |
| (v) Consumer goods and automobiles, |
95 |
UNBLOCK 95 |
*#1909*95# |
| (vi) Communication/Broadcasting/ Entertainment/IT, |
96 |
UNBLOCK 96 |
*#1909*96# |
| (vii) Tourism and Leisure, |
97 |
UNBLOCK 97 |
*#1909*97# |
| (viii) Food and Beverages; |
98 |
UNBLOCK 98 |
*#1909*98# |
Note-1: In case of communication with customer executive of Customer Care Center of access provider, preference to opt-in may be communicated;
Note-2: Customer to be communicated with confirmation and final status along with options to block
Note-3: UNBLOCK ALL option shall unblock all categories of content, mode, time band and day types with default options;
Note-4: UNBLOCK 51 shall restore service type of commercial communications for all categories of content, mode, time band and day types as per the previous state of the customer while he exercised block option last time or with the default options as the case may be while promotional type of commercial communications shall remain in blocked state;
Provided that the Authority may, from time to time, add or remove number of category(ies), or sub category(ies) for content;
2. Procedure for registration of preference or change of preference of Mode for Commercial Communications
(1) Customer can opt-out of any or all of following category(ies) of mode(s) of communication:
| UCC Mode of Communication [Choices for Preference(s)] |
IVRS: Call to 1909 and press at prompt to block |
SMS: Send SMS to 1909 following text |
USSD: Dial USSD String |
| All Categories of Mode (to be blocked) |
10 |
BLOCK 10 |
*1909*10# |
| (i) Voice Call, |
11 |
BLOCK 11 |
*1909*11# |
| (ii) SMS, |
12 |
BLOCK 12 |
*1909*12# |
| (iii) Auto Dialer Call (With Pre-recorded Announcement), |
13 |
BLOCK 13 |
*1909*13# |
| (iv) Auto Dialer Call (With Connectivity to live agent), |
14 |
BLOCK 14 |
*1909*14# |
| (v) Robo-Calls, |
15 |
BLOCK 15 |
*1909*15# |
Note-1: In case of communication with customer executive of Customer Care Center of access provider, preference to opt-out may be communicated;
Note-2: Customer to be communicated with confirmation and final status along with options to unblock;
Note-3: BLOCK 10 option shall block all categories of modes except transactional type commercial communications while saving the status of customer for categories of time band and day types;
Provided that the Authority may, from time to time, add or remove number of category(ies), or sub category(ies) for mode;
(2) Customer can opt-in for any or all of following category(ies) of mode(s) of communication:
| UCC Mode of Communication [Choices for Preference(s)] |
IVRS: Call to 1909 and press at prompt to block |
SMS: Send SMS to 1909 following text |
USSD: Dial USSD String |
| All Categories of Mode (to be unblocked) |
80 |
UNBLOCK 80 |
*1909*80# |
| (i) Voice Call, |
81 |
UNBLOCK 81 |
*1909*81# |
| (ii) SMS, |
82 |
UNBLOCK 82 |
*1909*82# |
| (iii) Auto Dialer Call (With Prerecorded A nnouncement), |
83 |
UNBLOCK 83 |
*1909*83# |
| (iv) Auto Dialer Call (With Connectivity to live agent), |
84 |
UNBLOCK 84 |
*1909*84# |
| (v) Robo-Calls, |
85 |
UNBLOCK 85 |
*1909*85# |
Note-1: In case of communication with customer executive of Customer Care Center of access provider, preference to opt-in may be communicated;
Note-2: Customer to be communicated with confirmation and final status along with options to block;
Note-3: UNBLOCK 80 option shall restore all categories of modes for categories of time band and day types as per the previous status of customer when he exercised block option last time or as per the default options as the case maybe;
Provided that the Authority may, from time to time, add or remove number of category(ies), or sub category(ies) for modes;
3. Procedure for registration or change of preference of Time band(s) for Commercial Communications
(1) Customer can opt-out of any or all of following time bands for receiving of commercial communications:
| UCC Time band for Communication [Choices for Preference(s)] |
IVRS: Call to 1909 and press at prompt to block |
SMS: Send SMS to 1909 following text |
USSD: Dial USSD String |
| All Time Bands (to be blocked) |
20 |
BLOCK 20 |
*1909*20# |
| (i) 00:00 Hrs to 06:00 Hrs, |
21 |
BLOCK 21 |
*1909*11# |
| (ii) 06:00 Hrs to 08:00 Hrs, |
22 |
BLOCK 22 |
*1909*22# |
| (iii) 08:00 Hrs to 10:00 Hrs, |
23 |
BLOCK 23 |
*1909*23# |
| (iv) 10:00 Hrs to 12:00 Hrs, |
24 |
BLOCK 24 |
*1909*24# |
| (v) 12:00 Hrs to 14:00 Hrs, |
25 |
BLOCK 25 |
*1909*25# |
| (vi) 14:00 Hrs to 16:00 Hrs, |
26 |
BLOCK 26 |
*1909*26# |
| (vii) 16:00 Hrs to 18:00 Hrs, |
27 |
BLOCK 27 |
*1909*27# |
| (viii) 18:00 Hrs to 21:00 Hrs, |
28 |
BLOCK 28 |
*1909*28# |
| (ix) 21:00 Hrs to 24:00 Hrs, |
29 |
BLOCK 29 |
*1909*29# |
Note-1: Time Bands (i), (ii), (iii) and (ix) shall be default OFF for all customers irrespective of the status of registration of customer i.e. for all customers including those who have not registered any type of preference(s), anytime unless customer has registered its preference(s) and switched ON;
Note-2: In case of communication with customer executive of Customer Care Center of access provider, preference to opt-out may be communicated;
Note-3: Customer to be communicated with confirmation and final status along with options to unblock;
Note-4: BLOCK 20 option shall block all categories of modes while saving current status of customer for categories of content, time band and day types, however transactional type of commercial communications may not be blocked;
Provided that the Authority may, from time to time, add or remove number of category(ies), or sub category(ies) for time band;
(2) Customer can opt-in for any or all of following time band(s):
| UCC Time band for Communication [Choices for Preference(s)] |
IVRS: Call to 1909 and press at prompt to block |
SMS: Send SMS to 1909 following text |
USSD: Dial USSD String |
| All Time Bands (to be unblocked) |
70 |
UNBLOCK 70 |
*1909*70# |
| (i) 00:00 Hrs to 06:00 Hrs, |
71 |
UNBLOCK 71 |
*1909*71# |
| (ii) 06:00 Hrs to 08:00 Hrs, |
72 |
UNBLOCK 72 |
*1909*72# |
| (iii) 08:00 Hrs to 10:00 Hrs, |
73 |
UNBLOCK 73 |
*1909*73# |
| (iv) 10:00 Hrs to 12:00 Hrs, |
74 |
UNBLOCK 74 |
*1909*74# |
| (v) 12:00 Hrs to 14:00 Hrs, |
75 |
UNBLOCK 75 |
*1909*75# |
| (vi) 14:00 Hrs to 16:00 Hrs, |
76 |
UNBLOCK 76 |
*1909*76# |
| (vii) 16:00 Hrs to 18:00 Hrs, |
77 |
UNBLOCK 77 |
*1909*77# |
| (viii) 18:00 Hrs to 21:00 Hrs, |
78 |
UNBLOCK 78 |
*1909*78# |
| (ix) 21:00 Hrs to 24:00 Hrs, |
79 |
UNBLOCK 79 |
*1909*79# |
Note-1: In case of communication with customer executive of Customer Care Center of access provider, preference to opt-out may be communicated;
Note-2: Customer to be communicated with confirmation and final status along with options to block;
Note-3: UNBLOCK 70 shall restore all categories of time bands for the customer in which he was before he exercised option to block last time, if any, otherwise as per the default options;
Provided that the Authority may, from time to time, add or remove number of category(ies), or sub category(ies) for time band;
4. Procedure for registration or change of preference of Day Type(s) for Commercial Communications
(1) Customer can opt-out of any or all of following day type(s):
| UCC Day Type(s) for receiving Communication [Choices for Preference(s)] |
IVRS: Call to 1909 and press at prompt to block |
SMS: Send SMS to 1909 following text |
USSD: Dial USSD String |
| All Day Type(s) (to be blocked) |
30 |
BLOCK 30 |
*1909*30# |
| (i) Monday |
31 |
BLOCK 31 |
*1909*31# |
| (ii) Tuesday |
32 |
BLOCK 32 |
*1909*32# |
| (iii) Wednesday |
33 |
BLOCK 33 |
*1909*33# |
| (iv) Thursday |
34 |
BLOCK 34 |
*1909*34# |
| (v) Friday |
35 |
BLOCK 35 |
*1909*35# |
| (vi) Sat urday |
36 |
BLOCK 36 |
*1909*36# |
| (vii) Sunday |
37 |
BLOCK 37 |
*1909*37# |
| (viii) Public Holiday and National Holiday |
38 |
BLOCK 38 |
*1909*38# |
Note-1: Time Bands (i), (ii), (iii) and (ix) shall be default OFF for all customers irrespective of the status of registration of customer i.e. for all customers including those who have not registered any type of preference(s), anytime unless customer has registered its preference(s) and switched ON;
Note-2: In case of communication with customer executive of Customer Care Center of access provider, preference to opt-in may be communicated;
Note-3: Customer to be communicated with confirmation and final status along with options to unblock;
Note-4: BLOCK 30 option shall block all categories of types of days while saving the status of customer for categories of time band and day types, however transactional type of commercial communications may not be blocked;
Provided that the Authority may, from time to time, add or remove number of category(ies), or sub category(ies) for day type(s);
(2) Customer can opt-in for any or all of following day type(s):
| Day Type(s) for receiving Commercial Communication [Choices for Preference(s)] |
IVRS: Call to 1909 and press at prompt to block |
SMS: Send SMS to 1909 following text |
USSD: Dial USSD String |
| All Day Type(s) (to be unblocked) |
60 |
UNBLOCK 60 |
*1909*60# |
| (i) Monday |
61 |
UNBLOCK 61 |
*1909*61# |
| (ii) Tuesday |
62 |
UNBLOCK 62 |
*1909*62# |
| (iii) Wednesday |
63 |
UNBLOCK 63 |
*1909*63# |
| (iv) Thursday |
64 |
UNBLOCK 64 |
*1909*64# |
| (v) Friday |
65 |
UNBLOCK 65 |
*1909*65# |
| (vi) Saturday |
66 |
UNBLOCK 66 |
*1909*66# |
| (vii) Sunday |
67 |
UNBLOCK 67 |
*1909*67# |
| (viii) Public Holiday and National Holiday |
68 |
UNBLOCK 68 |
*1909*68# |
Note-1: In case of communication with customer executive of Customer Care Center of access provider, preference to opt-in may be communicated;
Note-2: Customer to be communicated with confirmation and final status along with options to block;
Note-3: UNBLOCK 60 shall restore all categories of types of day for the customer in which he was before he exercised option to block last time, if any, otherwise as per the default options;
Provided that the Authority may, from time to time, add or remove number of category(ies), or sub category(ies) for day type(s);
5. Recording preferences on Distributed Ledger for Preferences (DL-Preferences)
(1) Access Provider shall automate its internal systems and develop appropriate APIs to interact with DLPreferences;
(2) Access Provider shall record preferences on DL-Preferences within 15 minutes for requests received from all modes;
(3) These revised preferences shall be available, in real time, for considerations by entities for scrubbing process for new list of telephone numbers under process, however, earlier messages or voice calls which have already been scrubbed and have validity may be delivered;
6. Every Access Provider shall establish, maintain and operate Distributed Ledger(s) for Preference (DL-Preference) with requisite functions, process and interfaces
(1) to record choices of preference(s) exercised by the customer in the Distribute Ledger for Preferences (DLPreferences) in an immutable and non repudiable manner;
(2) to record, at least, following details of the customer who has registered its preference(s):
(a) telephone number in the international numbering format as referred in the National Numbering Plan;
*[(b)] Location Routing Number (LRN), as assigned by DoT to the access provider, of current serving network of the customer and changes in LRN of the new serving network, in case customer is being ported-in during Mobile Number Portability;
*[(c)] lifetime history, with date(s) and time stamp(s), of choices exercised by the customer for registering his preference(s) and subsequent changes to it made by the customer from time to time;
*[(d)] changes in the subscription of telephone number, during the process of opening and closing of subscription;
*[(e)] unique registration number issued at the time of registration of preference(s);
(3) to interact and exchange information with other relevant entities, responsible to carry out functions for regulatory compliance(s), in a safe and secure manner;
(4) to support any other functionalities as may be required to carry out functions for regulatory compliance(s);
7. Every Access Provider shall establish facility for revoking the consent by its customers and shall make necessary arrangements
(1) to receive request, from the customer, for revoking the consent, if any, given by the recipient to the sender or to the consent acquirer for the purpose of receiving a commercial communication message or voice call;
(2) to provide modes, free of cost, to the customer, as per his choice, to revoke consent either by
(i) sending SMS to short code 1909 with Label <Revoke> and <Sender ID> or to telephone number mentioned in the message or during the voice call received from the sender(s); or
(ii) calling on 1909 or number mentioned for revoking the consent during the voice call received from the sender(s); or
(iii) calling on customer care number; or
(iv) Interactive Voice Response System (IVRS); or
(v) Mobile app developed in this regard either by the Authority or by any other person or entity and approved by the Authority; or
(vi) Web portal with authentication through OTP; or
(vii) Any other means as may be notified by the Authority from time to time.
(3) to remove the recipient's contact information (telephone number to which the message was sent) from the consent record(s) corresponding to the sender for all purposes requiring explicit consent except in case specific purpose(s) is indicated by the customer during revocation of consent from the consent register within 1 business day;
(4) to duly acknowledge the customer's request to revoke the consent with unique reference number;
(5) to ensure that any person who receives request to revoke consent must not disclose the customer's personal information to others without his consent;
(6) to fetch details of the consent including its purpose(s), details about day and time when it was taken, and details about sender(s) or consent acquirer(s) who has or have taken the consent;
8. Every Access Provider shall establish, maintain and operate Distributed Ledger(s) for Consent (DL-Consent) with requisite functions, process and interfaces
(1) to record consent given by the customer to sender(s) or consent acquirer(s) in the Distribute Ledger for Consent (DL-Consent) in an immutable and non repudiable manner;
(2) to record, at least, following details of the consent
(a) telephone number of customer in international numbering format as referred in National Numbering Plan;
(b) Header of Sender(s) or Consent Acquirer(s) against which consent is taken;
(c) Day & Time when consent was taken;
(d) Validity period of consent;
(e) Type and purpose(s) of consent;
(3) to make consent data accessible for other entities in safe and secure manner;
(4) to keep record of revocation of consent by the customer with specific purpose(s), if any, in an immutable and non-repudiable manner;
(5) to interact and exchange information with other relevant entities, responsible to carry out functions for regulatory compliance(s), in a safe and secure manner;
(6) to support any other functionalities as may be required to carry out functions for regulatory compliance(s);
9. Every Access Provider shall specify
(1) Entity and process for generation of One Time Password (OTP) for different purposes and its validity period;
(2) Entity and process for verification of OTP received from the customer or for verification of entity carrying out activity under Code(s) of Practice for Entities;
10. Every Access Provider shall formulate
(1) Message Sequence Charts for messages with parameter details and time sequence to provide details about the process between two entities and action taken by particular entity;
(2) Flow Charts to provide details about the process between two entities and action taken;
SCHEDULE III
List of Action items for Code of Practice for Complaint Handling (CoP-Complaints)
1. Every Access Provider shall formulate Code of Practice for Complaint handling (CoP-Complaints) and shall prescribe role, responsibilities of entities involved in examining, investigating and resolving complaints;
2. CoP-Complaints shall also include details about
(1) Complaint registration through voice call
(a) Procedure for a customer to make a call to 1909 for registering his complaint.
(b) Procedure and role of the customer care executive to interact with the customer about the details like particulars of telemarketer, the telephone number from which the unsolicited commercial communication has originated the date, time and brief description of such unsolicited commercial communication.
(c) Procedure and role of the customer care executive to register the customer complaint and acknowledge the complaint by providing a unique complaint number.
(2) Complaint Registration through SMS
(a) Format for making complaints in which a customer may register his complaint pertaining to receipt of unsolicited commercial communication.
*[(b)] Details to be provided by the complainant e.g. Unsolicited Commercial Communications with date on which it was received along with content of received message and in case of voice call, brief of content of communication etc.
(3) Complaint registration through a mobile app
(a) Functioning of intelligent and intuitive mobile app(s) for devices with different operating systems and helping customer to identify and report suspected sources of spam and also making use of it by the customer to make complaints;
(b) Ways and means which can be used to enhance mobile App and other modes for the customer to help him to identify probable source of spam in an intelligent manner and offers to select source of messages and voice calls against which complaint is to be made;
(c) Ways and means which can be used by the customer to compose complaint on behalf of recipient in a convenient manner and quickly;
(d) App which helps user of app to keep track of complaints made earlier for the app user;
(e) Ways and means to Increase adoption of App to quickly detect spam participate to actively report to lead to larger set of information helpful to curb menace of Unsolicited Commercial Communications;
(4) Complaint registration through Web Portal
(a) Procedure for the customer to make complaints by visiting website of access provider and register his complaint.
(b) Procedure for filling form and design it for the purpose of filing complaint with all relevant details required to investigate complaint and take appropriate action;
(c) Procedure for authentication process to ensure that complaint is made by recipient;
(d) Procedure to generate and communicate Reference number to the customer which may be used to check status of complaint;
3. Every Access Provider shall formulate
(1) Message Sequence Charts for messages with parameter details and time sequence to provide details about the process between two entities and action taken by particular entity;
(2) Flow Charts to provide details about the process between two entities and action taken;
SCHEDULE IV
Action Items for preparing Code of Practice for Unsolicited Commercial Communications Detection (CoP-UCC_Detect)
1. Every Access Provider shall establish, maintain and operate following system, functions and processes to detect sender(s) who are sending Unsolicited Commercial Communications in bulk and not complying with the regulation(s), and act to curb such activities
(1) System which have intelligence at least following functionalities
(a) identifying sender(s) on basis of signature(s);
(b) deploying honeypot(s) and using information collected by it;
(c) evolving signature(s) by learning over time;
(d) interface to exchange information with similar system(s) established by other access provider(s) to evolve signature(s), detecting sender using Sender Information (SI);
(e) considering inputs available from DL-Complaints about complaints and reports and analyze them;
(f) considering inputs available, if any, from any other network element(s) of the access provider system(s);
(2) provide ways and means for resolving complaint(s) by sharing information related to telephone number(s) of sender(s) against which complaint is made;
2. Every Access Provider shall formulate codes of practice (CoP-UCC_Detect) for system, functions and process prescribed as following
(1) implementation details for detecting Unsolicited Commercial Communications related to suspicious unregistered telemarketing activity using Signature solution, deploying honeypots and other technical measures;
(2) minimum standards of technical measures to share intelligence information, rules, criteria to detect suspected sources of spam;
(3) approaches to detect and identify unregistered Unsolicited Commercial Communications sender(s), who are camouflaging themselves by fragmenting their activity across multiple phone numbers;
(4) approaches for deployment of honeypots to capture Unsolicited Commercial Communications voice call(s);
(5) approaches to detect and identify source(s) of dictionary attacks;
(6) timeline(s) for implementation of the functionality referred in code of practice and operationalizing it;
(7) such other matters as the Authority may deem fit, from time to time.
3. Report of entities found to be engaged in making or causing to make silent calls, robocalls, abandoned calls or using telephone directory harvesting software to make Unsolicited Commercial Communications, as and when came to notice of the access provider, or as provided for in the regulations for the registered sender(s) with the access providers, on basis of following criteria
(a) Ratio of Abandon Calls to total attempted calls for a registered entity exceeding 3% over a period of 24 Hours by an entity using Auto Dialer for Commercial Communications calls;
(b) Ratio of Silent Calls to total attempted calls for a registered entity exceeding 1% over a period of 24 hour by an entity using Auto Dialer for Commercial Communications Calls;
(c) Entity(ies) found to be using telephone number harvesting software for sending Unsolicited Commercial Communications are barred to use their network;
SCHEDULE V
Action Items for preparing Code of Practice for Periodic Monthly Reporting (CoP-PMR)
1. Maintaining records of complaints on daily basis for each service area
(a) total number of complaints received on each day, from its customers as Terminating Access Provider, in each service area, against any registered sender;
(b) total number of complaints transferred on each day, to Originating Access Provider(s) including itself, in each service area, against any registered sender;
(c) total number of complaints to be resolved as an Originating Access Provider, according to the date of receipt of complaints;
(d) total number of complaints rejected on account of insufficient details for further examination, according to the date of receipt of complaint;
(e) total number of complaints to be resolved as an Originating Access Provider, according to the date of occurrence of unsolicited commercial communication;
(f) total number of senders against whom complaints were reported under clause (c);
(g) total number of complaints out of reported complaints under clause (f), after completion of investigation, found to be valid complaint(s);
(h) total number of senders out of reported senders under clause (f), found to be non-compliant as per the provisions provided for in these regulations or Code(s) of Practice;
(i) total number of senders out of reported senders under clause (h), who were put under restricted limits of usage provided for in Code(s) of Practice, as an interim measure to control unsolicited commercial communications during the investigation phase;
(j) numbers of commercial communications sent by each sender, reported under clause(i);
(k) total number of entities other than sender(s), after completion of investigation, found to be not compliant to the provisions provided for in these regulations or Code(s) of Practice and actions taken against them;
(1) report total number of complaints on a day, for any sender, reported under clause(h);
2. Maintain records of complaints, from its customers and received from Terminating Access Provider(s), against unregistered sender(s) for sending unsolicited commercial communications on daily basis for each service area
(a) total number of complaints received on each day, from its customers as Terminating Access Provider, in each service area, against any unregistered sender;
(b) total number of complaints transferred on each day, to Originating Access Provider(s) including itself, in each service area, against any unregistered sender;
(c) total number of complaints to be resolved as an Originating Access Provider, according to the date of receipt of complaints;
(d) total number of complaints rejected on account of insufficient details for further examination, according to the date of receipt of complaint;
(e) total number of complaints to be resolved as an Originating Access Provider, according to the date of occurrence of unsolicited commercial communication;
(f) total number of senders against whom complaints were reported under clause (e);
(g) total number of complaints out of reported complaints under clause(e), after completion of investigation, found to be valid complaint(s);
(h) total number of senders, under clause(f) against whom complaints were found to be valid;
(i) total number of senders out of reported senders under clause(h), who were put under usage cap, as an interim measure to control unsolicited commercial communications during the investigation phase;
(j) total number of senders out of reported senders under clause (i), who were put under Usage Cap or disconnected, after conclusion of the investigation with following breakup
(i) number of senders who were given warning against first instance of violations;
(ii) number of senders found to violating second time;
(iii) number of senders found to be violating third or more number of times;
(k) numbers of commercial communications sent by each sender, reported under clause(h);
(l) total number of outgoing communications made by the sender(s), reported under clause(f) and exceeding the restriction limits from the deemed date of imposition of such restrictions;
SCHEDULE VI
List of key activities (but not an exhaustive list) for preparation of migration plan
(1) Introducing Distributed Ledger (DL) for registration of entities (DL-Entities);
(a) To register entities declared by access provider or access provider(s) together for various functions and registers like
(i) Header Register;
(ii) Consent Register;
(iii) Consent Template Register;
(iv) Content Template Register;
(v) Content Template Verifier;
(vi) Complaint Register;
(vii) Preference Register;
(viii) Telemarketer Scrubbing Function Register;
(ix) Telemarketer Message Delivery Function Register;
(x) Telemarketer Voice Delivery Function Register;
(b) Deadline(s) for registering entities with DL-Entities
(i) Header Register;
(ii) Consent Register;
(iii) Consent Template Register;
(iv) Content Template Register;
(v) Content Template Verifier;
(vi) Complaint Register;
(vii) Preference Register;
(viii) At least one entity for Telemarketer Scrubbing Function;
(ix) At least one entity for Telemarketer Message Delivery Function Register;
(x) At least one entity for Telemarketer Voice Delivery Function Register;
(2) Registration of existing assignee of Headers with Header Registrar;
(a) stop assigning headers without verification of identity and scope of senders;
(b) register existing assignee of headers after verification of identity and scope documents of Unsolicited Commercial Communications sender(s) and bind to phone number(s);
(c) assign or reassign current owner of header(s) considering at least following:
(i) Whether headeris not assigned to any other sender(s);
(ii) Whether header is matching with brand name of a company;
(iii) Whether header is look alike with other popular header(s) and may mislead recipients;
(iv) Any other reason or fact which is important to consider before assigning header;
(d) use temporary header(s), during migration phase, for all earlier assigned headers;
(e) fixing deadline for working of temporary headers;
(3) Start assigning new headers
(a) assign headers after due diligence, verification of identity and scope documents of Unsolicited Commercial Communications sender(s) and bind to phone number(s);
(b) consider reason(s) and fact(s) which are important to be considered before assigning headers and do not mislead recipients;
(c) consider headers which may be required to be reserved for central and state government entities and also for statutory bodies;
(4) Develop mobile app for devices which may be required for senders during login to sessions for various activities like scrubbing, submission of messages to delivery, making voice calls etc.;
(5) Introduce telemarketer with scrubbing function, separate from telemarketer with delivery function
(6) Scrubbing envisaged in final form to be achieved in phased manner
(i) Initially, using data from existing register for customers' preferences;
(ii) subsequently, using records of DL-Preferences;
(iii) then using records of DL for Header Register;
(iv) then introducing virtual identities and tokens among entities to access real identities;
(v) then using records of DL for consent;
(7) Introduce DL for Complaints;
(8) Register existing consents on Consent Register;
(a) Register existing consents with consent registrar in robust manner to make it non-repudiable;
(b) stop taking consent not in accordance to these regulations;
(c) fix deadline for expiry of consent not registered with consent registrar;
(9) Register new consents on consent register as prescribed in relevant regulations or schedule or directions
(a) Develop Application Programme Interfaces (APIs) for Senders to recording consent with user agent or application client available on a mobile device or enterprise system;
(b) Broadening of installation and active base of consent acquisition application client;
(10) Make consent system ready to become part of scrubbing for all cases;
(11) Migration of existing registers with TRAI;
(a) Migrate NCPR data to DL-Preferences and have observer node for TRAI;
(b) Migrate Telemarketer registration module data of National Telemarketer Register (NTR) to DL-Entities and have observer node for TRAI;
(c) Migrate complaint module data to DL-Complaints and have observer node for TRAI;
(12) Introduce observer node of DL-Consents and observer nodes of rest of registers envisaged in the relevant regulations;
(13) Enhance signature solution capabilities and exchange intelligence information, rule, criteria and other relevant information among access providers to detect and identify suspicious Unregistered Telemarketing Activities more effectively and efficiently;
(14) Deploy honeypots to detect and identify suspicious Unsolicited Commercial Communications Voice calls by capturing relevant information;