
10 Oct 2026
DPDP AI calling consent reaches an important milestone on 13 November 2026, but this is not when every AI calling privacy obligation takes effect. The statutory Consent Manager framework becomes operational under the scheduled provisions, while the core consent, notice and processing obligations are scheduled for 13 May 2027.
For admissions offices, BPOs, contact centres and sales teams, the distinction matters. Permission to make a call does not automatically authorise recording, transcribing, storing or reusing the personal data collected.
This guide explains the implementation timeline, lawful processing grounds, call-recording safeguards and practical compliance preparation.
India's Digital Personal Data Protection Act, 2023 regulates specified processing of digital personal data.
AI voice systems may process:
These records can qualify as personal data when they relate to identifiable individuals and meet the Act's application conditions.
The organisation determining the purpose and means of processing is the Data Fiduciary. A vendor processing information on its behalf may be a Data Processor.
Businesses exploring DPDP compliance for AI voice agents in India should distinguish lawful communication from lawful personal-data processing.
DPDP AI calling consent is only one part of that wider responsibility.
The MeitY Gazette commencement notification and DPDP Rules, 2025 establish a phased implementation schedule.
Effective date | Legal provisions | Business implications |
| 13 November 2025 | Specified foundational and institutional provisions | Initial regulatory framework |
| 13 November 2026 | Section 6(9), Section 27(1)(d) and Rule 4 | Statutory Consent Manager registration and oversight |
| 13 May 2027 | Sections 3–5, most of Section 6, Sections 7–17 and other specified provisions; Rules 3, 5–16, 22–23 | Main consent, notice, processing, security, retention and rights obligations |
A statutory Consent Manager is a Board-registered entity through which individuals can give, manage, review and withdraw consent.
It is not simply a checkbox inside a CRM.
Key takeaway: November 2026 primarily concerns the statutory Consent Manager framework, not a universal AI-call recording deadline.
Businesses should prepare their DPDP AI calling consent processes before May 2027 without ignoring existing telecommunications obligations.
The Telecom Regulatory Authority of India regulates commercial communications through the Telecom Commercial Communications Customer Preference Regulations (TCCCPR) and subsequent amendments.
The DPDP framework addresses how digital personal data is processed.
Compliance area | TRAI framework | DPDP framework |
| Primary concern | Permitted commercial communications | Lawful personal-data processing |
| Example | Can this promotional call be made? | Can the transcript be stored and analysed? |
| Consent focus | Applicable calling permissions and preferences | Consent or another recognised processing ground |
| Operational controls | Telecom registration and applicable restrictions | Notices, safeguards, retention and individual rights |
| Can one replace the other? | No | No |
For example, a university admissions office might be permitted to contact someone about an enquiry. That permission does not automatically extend to unrelated profiling or AI model training.
The TRAI regulations register also lists a Third Amendment dated 18 September 2026. Businesses should review the applicable final provisions for their calling category.
DPDP AI calling consent and telecom permissions must therefore be evaluated separately.
Sections 4, 6 and 7 of the DPDP Act recognise processing based on consent or specifically enumerated certain legitimate uses.
Section 7(a) may permit processing for a specified purpose when an individual voluntarily provides personal information and the statutory conditions are satisfied.
For example, an applicant sharing their phone number to request university counselling may permit processing connected to responding to that request.
However, unrelated marketing or model training requires a separate lawful-ground assessment.
Section 6 describes consent as free, specific, informed, unconditional and unambiguous, demonstrated through clear affirmative action.
Businesses should:
DPDP AI calling consent should be purpose-specific, not a universal verbal approval imposed on every call regardless of circumstances.
Not automatically.
A generic announcement discloses possible recording. It does not necessarily explain the purposes of processing or establish valid consent.
For call recording consent India DPDP readiness, distinguish these activities:
Each intended use requires an appropriate lawful basis.
Rule 3 of the DPDP Rules prescribes notice information, including personal-data descriptions, processing purposes and applicable rights mechanisms.
Effective DPDP AI calling consent requires more than a recording disclaimer when consent is the processing ground.
Strong AI call recording privacy India practices require controls throughout the data lifecycle.
Rule 6 and Rule 8 of the DPDP Rules address security safeguards and specified retention requirements.
Rule 8(3) includes minimum one-year preservation requirements for specified processing data and logs for Seventh Schedule purposes, subject to its conditions. This is not a universal 12-month maximum for call recordings.
For related technical and privacy considerations, explore Sicada.ai's privacy and compliance guide for voice and document AI.
Under Section 6, withdrawal must be comparably easy to giving consent.
Where processing depends on withdrawn consent, the Data Fiduciary must cease the affected processing within a reasonable time and cause relevant processors to stop, unless continued processing is otherwise authorised or required by law.
Businesses should also prepare processes for applicable Data Principal rights:
DPDP AI calling consent records should connect the individual, authorised purposes, withdrawal status and affected systems.
This makes DPDP consent management an operational requirement rather than simply a disclosure exercise once the relevant provisions apply.
Under Section 8, a Data Fiduciary retains statutory responsibilities for processing undertaken on its behalf.
Participant | Responsibility to assess |
| Client business | Purposes, lawful grounds, privacy notices and governance |
| AI vendor | Contractual processing, security and permitted data uses |
| Telephony provider | Applicable telecom services and requirements |
| Other processors | Hosting, transcription, CRM handling and safeguards |
Actual roles depend on the arrangement, not just contractual labels.
Sicada.ai's Privacy Policy discusses customer content, recording responsibilities and data handling. Its Terms and Conditions address telephony-related responsibilities.
Organisations should verify contractual arrangements, vendor controls and actual platform settings before deployment.
DPDP AI calling consent does not automatically become valid simply because an AI technology provider manages the conversation.
Illustrative wording only. Assumes consent is the applicable legal basis and requires legal review.
“Hello, I am an AI assistant calling on behalf of ABC Admissions regarding your course enquiry.
With your permission, we would like to record and transcribe this conversation to document your enquiry and support your counselling request.
Our privacy notice is available at Sicada website.
Do you agree to recording and transcription for these purposes?”
If consent is refused, processing that depends on that consent should not proceed. A non-recorded alternative or human assistance may be offered where feasible.
The system must also handle the initial consent exchange lawfully.
Preparing DPDP AI calling consent requires coordination across departments.
Readiness action | Responsible team |
| Classify calls against applicable TRAI rules | Sales / Operations |
| Map recordings, transcripts and CRM transfers | IT / Operations |
| Document permitted processing grounds | Legal / Compliance |
| Review privacy notices and call scripts | Legal |
| Capture consent decisions and withdrawal requests | Product / IT |
| Configure security and access controls | IT / Security |
| Establish retention and deletion procedures | Compliance / IT |
| Review AI vendor and telephony agreements | Procurement / Legal |
| Test refusals, rights requests and escalation | QA / Support |
| Complete regulatory review before deployment | Legal / Leadership |
These controls are especially relevant for Indian BPOs using AI voice agents, admissions teams and outbound sales departments.
No. The DPDP Act recognises consent and certain specified legitimate uses. The applicable ground depends on the processing purpose and statutory conditions.
Only where an applicable lawful ground covers that processing and other requirements are satisfied. Permission to answer an enquiry does not automatically authorise unrelated training.
The Act does not impose a universal India-only storage rule. Section 16 and Rule 15 establish a conditional cross-border transfer framework, subject to applicable restrictions.
No. It primarily concerns statutory Consent Managers. The wider processing framework is scheduled for 13 May 2027.
DPDP AI calling consent involves more than asking permission to record a conversation. Organisations need to establish lawful processing purposes, appropriate disclosures, recording safeguards, retention rules and practical withdrawal procedures.
The November 2026 milestone concerns statutory Consent Managers, while the broader DPDP processing obligations are scheduled for May 2027.
Admissions departments, BPOs and sales teams should evaluate both calling permissions and subsequent data handling.
A compliant workflow depends on the full lifecycle of customer information, not one statement at the beginning of a call.
Review Your AI Calling and Data-Handling Workflow
Assess your consent procedures, AI calling configurations, recording controls and vendor responsibilities before expanding automated communications.
Products
Resources
Others
All rights reserved. Powered by Edysor