Is Legacy Consent Valid in India in 2026?
Conditionally, yes. TRAI's TCCCPR Third Amendment, introduced on 18 September 2026, expands the definition of consent to include legacy consents already available with entities, and the framework is being amended to enable their recognition and digitisation. The condition is strict: legacy consents "shall be considered valid only where they have been obtained through verifiable means and are subsequently registered on the Digital Platform of the TSPs".
This is one of the few genuinely permissive changes in the amendment, and it is also the one most likely to be misread as easier than it is. Recognition is not automatic. It depends on two tests, and most brands can pass neither without work: proving how the consent was obtained, and registering it on operator infrastructure.
This guide summarises TRAI Press Release No. 119 of 2026 and the amendments it describes. It is not legal advice. Before you change a consent flow, a dialer configuration or a contract, confirm your own obligations against the text of the Telecom Commercial Communication Customer Preference (Third Amendment) Regulations, 2026 or with counsel. Where the press release does not state a detail, this guide says so rather than filling the gap.
Why Did TRAI Recognise Legacy Consent in 2026?
Because the previous framework left a large body of real customer permission with no way to be used. Indian businesses had been collecting consent for years through their own forms, apps, contracts and onboarding flows, while the regulatory route to valid consent ran through operator-side registration. The result was a mismatch: a brand could hold genuine permission from a customer and still have no compliant basis to act on it.
TRAI listed expanding the scope of explicit consent to accommodate legacy consents among the issues its consultation set out to address, alongside AI and ML based detection, the complaint mechanism, the appeal route, sender and telemarketer accountability, A2P calling and header safeguards. The amendment resolves the mismatch by letting pre-existing consent count, provided it can be evidenced and brought onto the platform.
What Are the Two Conditions for Legacy Consent in 2026?
Obtained through verifiable means, and subsequently registered on the Digital Platform of the TSPs. Both must hold. A consent that was captured properly but never registered does not qualify, and a consent registered without a verifiable capture record does not qualify either.
| Condition | What the press release says | What it asks of a brand |
|---|---|---|
| Verifiable means | Legacy consents are valid only where "they have been obtained through verifiable means" | Evidence of how each consent was captured, not just that it exists. |
| Registration | And "are subsequently registered on the Digital Platform of the TSPs" | Getting the records onto operator infrastructure, which is a process question for your TSP. |
| Scope | The consent definition is "expanded to include legacy consents already available with the entities" | It applies to consent you already hold, not to consent you can reconstruct. |
| Mechanism | "The framework is being amended to enable the recognition and digitization of such legacy consents" | The route exists in principle; the operational detail sits with the regulation and your operator. |
What Counts as Verifiable Means in 2026?
The press release does not define the term, and that matters enough to state plainly rather than fill in. What it does establish is the direction of the test: the question is how the consent was obtained, which means the evidence has to describe the act of consenting rather than merely record a conclusion.
Applied to how Indian businesses actually hold consent, that separates records that carry their own evidence from records that depend on somebody's word. A database column reading "opted in: yes" is a conclusion. A stored submission with a timestamp, the wording the customer agreed to, and the channel it came through is closer to evidence of the act.
| How consent was captured | Does it carry its own evidence? | What to check in 2026 |
|---|---|---|
| Web form with stored submission and timestamp | Usually yes | Confirm the raw submission and consent wording are retained, not just the contact record. |
| App onboarding with logged acceptance | Usually yes | Check the log ties the user, the timestamp and the version of the wording. |
| Signed contract or form with a consent clause | Often yes | Make sure the document is retrievable and linked to the phone number, not filed by customer name alone. |
| Double opt-in email or SMS confirmation | Usually yes | Retain the confirmation event, not just the resulting status. |
| CRM checkbox ticked by a staff member | No | Records a conclusion, not the customer's act. Treat as unevidenced. |
| Verbal consent noted on a call | Not by itself | Unless there is a retained recording or logged confirmation, there is no record of the act. |
| Consent inferred from a past purchase | No | A transaction is not a consent to commercial communication. |
| Imported or purchased list | No | No consent was obtained by you, verifiably or otherwise. |
How Should a CRM Owner Approach This in 2026?
As a data project with a triage step at the front. The instinct is to treat the whole database as one question, but the useful first move is to sort the records by how they were captured, because that determines whether a record is a candidate at all.
- Segment by capture method, not by recency. Age is irrelevant to the test. How the consent was obtained is the whole question.
- Find out what your systems actually retained. Many Indian stacks keep the opt-in status and discard the submission that produced it, which leaves you with a conclusion and no evidence.
- Separate the evidenced from the unevidenced. Be honest in this step. A large unevidenced segment is better known now than discovered during an enforcement question.
- Ask your TSP about the registration route. Registration on the Digital Platform is an operator process, and the press release does not describe its mechanics.
- Plan re-consent for the unevidenced segment. Where no verifiable record exists, the realistic path is to obtain fresh consent rather than to argue for the old one.
- Fix capture going forward. Every new consent should produce a retained artefact: the wording, the timestamp, the channel and the identifier it was given against.
It does not define verifiable means, does not describe the registration process on the TSP Digital Platform, does not state a deadline for registering legacy consents, and does not say what happens to unregistered legacy consents in the interim. It also publishes no retention requirement for the underlying evidence. These are questions for the regulation text, your telecom provider, or counsel.
How Does Legacy Consent Differ From the Inquiry Basis in 2026?
They are separate bases with different lifespans, and conflating them is a common error. Consent, once validly held and registered, is not time limited in the way the inquiry basis is. The inquiry basis under the same amendment permits commercial communication for only seven days from the date of a customer inquiry, and requires the inquiry to be made in writing or digitally and kept in verifiable form.
That difference shapes sensible process. A form fill gives you seven days. Consent gives you an ongoing basis. The practical move for most Indian teams is to use the seven day window to ask for consent explicitly, so a short-lived basis converts into a durable one. Our seven day rule guide covers that mechanic, and the full amendment guide places both inside the wider framework.
Notice also that both provisions use the same word. Verifiable form for an inquiry, verifiable means for a consent. Whatever the regulation settles on as evidence, a business that retains the artefact behind every customer action satisfies both tests, and one that stores only outcomes satisfies neither.
What Are the Common Mistakes in 2026?
- Assuming old consent is grandfathered. Recognition is conditional on verifiable capture and registration on the TSP Digital Platform.
- Treating registration as the only step. Registering a consent you cannot evidence does not satisfy the verifiable means condition.
- Mistaking a status field for evidence. "Opted in: yes" records a conclusion. The test concerns how the consent was obtained.
- Reading a purchase as consent. A transaction is not permission for commercial communication.
- Confusing consent with the inquiry basis. One is ongoing, the other expires after seven days.
- Waiting for a definition before starting. Segmenting your database by capture method is useful regardless of how verifiable means is finally defined.
- Skipping the uncomfortable count. Knowing how much of your list is unevidenced is the point of the exercise.
Key Takeaways for 2026
Legacy consent recognition is real and useful, and it is conditional in a way that turns a policy change into a data project.
- TRAI's TCCCPR Third Amendment, introduced 18 September 2026, expands the definition of consent to include legacy consents already held by entities.
- Legacy consents are valid only where obtained through verifiable means and subsequently registered on the Digital Platform of the TSPs.
- Both conditions must hold. Good capture without registration does not qualify, and registration without evidence of capture does not either.
- The press release does not define verifiable means, describe the registration process, or set a deadline.
- The test is about how consent was obtained, so stored artefacts count and status fields do not.
- Segment your database by capture method rather than by age, and plan re-consent for the unevidenced segment.
- Consent and the seven day inquiry basis are separate. Use the inquiry window to ask for consent explicitly.
Distk works with Indian CRM and marketing owners on exactly this triage: sorting a database by how consent was actually captured, identifying which segments carry evidence, and fixing capture so every new consent produces a record that would survive a question. If you hold a large legacy list, that audit is where we would start.
Sources
- TRAI Press Release No. 119 of 2026, "TRAI Strengthens Framework for Curbing Unsolicited Commercial Communications through Technology-Driven Enforcement and Enhanced Consumer Protection", 18 September 2026. Every rule, date, number and quotation in this guide comes from that press release.
- TRAI press release listing, which carries the dated entry and the source PDF.