Outbound calling and messaging built entire businesses in Indian B2B, mine included. Telecalling remains one of the highest-converting channels for SMB acquisition anywhere in this market. But the regulatory ground under outbound communication has shifted meaningfully, and a good number of marketing teams are still running campaigns designed for a compliance regime that no longer fully applies. This is not a minor operational footnote. Getting this wrong carries real financial and reputational cost, and getting it right is entirely achievable without giving up the channel.
Here is what actually matters, stripped of the legal jargon that usually makes this topic harder to act on than it needs to be.
The Telecom Regulatory Authority of India's regulations around Unsolicited Commercial Communications, enforced through the National Do Not Disturb registry, are the starting point. Any number registered on DND has opted out of promotional calls and SMS from entities not specifically authorised to reach them. The mechanics that matter operationally:
The operational reality for a B2B marketing team is that scraped or purchased contact lists, common practice a decade ago, are now a genuine compliance liability, not just a quality problem. If you cannot demonstrate a consent basis for a number, that number should not be in your outbound campaign, full stop.
Most compliance discussion around DND assumes a consumer marketing context, but B2B outbound has a meaningfully different profile that is worth understanding rather than assuming the consumer rules translate one-to-one. Business inquiries, where a prospect has actively filled a form, requested a callback, or engaged with content and provided contact details for follow-up, generally carry an implicit consent basis for a reasonable follow-up period, distinct from cold outreach to a number with no prior interaction. This is why lead capture forms, and the specificity of what they disclose about follow-up, matter more than most marketing teams treat them.
That said, "it's B2B, so different rules apply" is not a blanket exemption, and treating it as one is a common and risky misreading. The safest operating posture is to treat every outbound number as requiring a demonstrable consent basis, sourced from an inbound inquiry, an explicit opt-in, or an existing customer relationship, rather than relying on an assumed B2B carve-out.
The Digital Personal Data Protection Act adds a second layer on top of the telecom-specific rules: it governs how personal data, including phone numbers and contact details, is collected, processed, and used generally, not just for calls and SMS. For marketing teams, the practical implications are that consent needs to be specific about the purpose data was collected for — a number collected for "product updates" should not be repurposed for a separate promotional campaign without fresh consent — and that individuals have a right to withdraw consent, which needs an operational process behind it, not just a policy statement in a privacy page nobody enforces internally.
A practical compliance baseline I'd recommend: maintain a single, centrally managed consent record per contact, capturing what they consented to, when, and through what channel, rather than letting each team — sales, marketing, product — independently decide a contact is "fair game" because that team has some form of relationship with them. In practice, the businesses that get this wrong are rarely acting in bad faith. They simply have five disconnected systems each assuming someone else already checked consent, and nobody actually did.
WhatsApp Business API campaigns operate under Meta's own commerce and messaging policies in addition to Indian regulation, and these are, in practice, stricter than SMS in some respects. Template messages for marketing require explicit opt-in and pre-approval of message content, and unsolicited promotional messages to a number without opt-in risk both a poor customer experience and account-level penalties from Meta itself, independent of any regulatory action. Given how effective WhatsApp is as a channel for Indian B2B, this is worth building compliant infrastructure around properly rather than treating it as a looser, less regulated version of SMS.
None of this makes outbound a weaker channel. It makes it a more defensible one, run by a team that treats consent as core infrastructure rather than a legal afterthought bolted on when a complaint arrives.
In my experience, compliance failures in outbound marketing rarely originate from a deliberate policy decision to cut corners. They originate from a tele-calling floor incentivised purely on call volume and conversion, with no real-time visibility into which numbers on their list carry a weak or absent consent basis. A rep chasing a daily target will call every number on the list handed to them, and if that list was assembled by a lead-gen vendor with looser standards than your own compliance policy, the rep becomes the point of failure for a decision made two steps upstream, often without any awareness that the list itself was the problem. Fixing this requires compliance checks to happen at the list-building stage, before a number ever reaches a dialer, not as a post-hoc audit after complaints start arriving.
A large share of Indian B2B outbound campaigns run partly or fully through third-party telecalling agencies or lead-generation vendors, and it is a mistake to assume that outsourcing the activity outsources the compliance responsibility along with it. Regulatory and reputational accountability for how a campaign run in your brand's name treats consent sits with you, the brand, regardless of who dialled the number. Any vendor contract for outbound campaigns should include explicit, auditable requirements around consent sourcing and DND screening, with the right to audit their lists and processes, not just a boilerplate compliance clause nobody ever checks against in practice. I would treat a vendor's unwillingness to be audited on this as a disqualifying signal on its own, regardless of how attractive their pricing or lead volume looks.
The most durable fix is designing consent capture into your lead generation surfaces themselves — website forms, landing pages, in-app prompts — so that every new contact enters your system with a clear, specific, timestamped consent record attached from the moment of capture, rather than retrofitting consent tracking onto contacts who were already in your database before anyone thought carefully about this. A simple, clearly worded checkbox specifying exactly what kind of communication the contact is consenting to, rather than a vague "I agree to be contacted," both satisfies the regulatory bar more comfortably and, in my experience, produces a contact base that engages better with outbound because expectations were set honestly from the first interaction.
Most companies with several years of accumulated contact data have a legacy database where consent basis is inconsistent or undocumented for a meaningful share of records, collected before anyone was tracking this rigorously. Rather than treating this as a problem to quietly ignore, I would run a structured re-permission campaign — a clear, low-friction message to the legacy database asking contacts to confirm they are still comfortable being reached, with an easy path to opt out. Yes, this shrinks the addressable list. It also converts a liability into a genuinely clean, defensible asset, and in practice the contacts who actively re-confirm consent convert at meaningfully better rates than the larger, murkier list they were pulled from, because you are now reaching people who have told you directly they want to hear from you.
Back to all posts