Is Call Recording Legal in India? What Businesses Must Know
In short: A participant may record their own call under long-standing Indian law, but a business recording customer calls now needs purpose-specific consent, a stated reason, secure storage and deletion once that purpose ends, under the DPDP Act and its 2025 Rules.
Short version: recording a call you are part of has been lawful in India for decades. Recording your customers as a business is a different question, and the answer changed recently. Most of the advice online still describes the pre-2023 position.
This is general information, not legal advice. Data-protection obligations depend on your size, sector and what you do with the recordings. Take proper advice before rolling out recording across a team.
The old rule: one-party consent
India follows one-party consent. Any participant in a call may record it without telling the others. This traces back to the Supreme Court’s decision in R.M. Malkani v State of Maharashtra (1973) and it has not been overturned.
Two things that were never allowed, and still are not:
- Recording a call you are not part of. Intercepting other people’s conversations is unlawful, and the Telecommunications Act 2023 restates this.
- Using a recording for something the law forbids — blackmail, harassment, publishing private conversations.
So an individual recording their own call is on firm ground. That is where most articles stop, and where businesses get into trouble.
What changed: the DPDP Act
A recorded customer call is personal data. Once your business processes personal data, the Digital Personal Data Protection Act 2023 applies, and its Rules were notified by MeitY in November 2025.
For a business recording customer calls, that means in practice:
- Tell the customer. “This call is being recorded” before the conversation starts, not buried in terms.
- Say why. Purpose-specific consent: quality training is a different purpose from dispute evidence, and you cannot quietly reuse one for the other.
- Let them decline without punishing them for it.
- Keep a consent record, timestamped, so you can show what was agreed and when.
- Store it securely, with access limited to people who need it.
- Delete it when the stated purpose is finished. Keeping recordings indefinitely “just in case” is exactly what the Act is aimed at.
Penalties under the DPDP framework run high, up to ₹250 crore for the most serious failures by significant data fiduciaries. A five-person shop is not the target of that number, but the obligations themselves apply broadly.
The separate rule about who you may call at all
Recording is one regulation. Calling is another, and businesses routinely confuse them.
TRAI’s Telecom Commercial Communications Customer Preference Regulations (TCCCPR 2018, amended February 2025) govern unsolicited commercial communication:
- Customers can register on the DND / NCPR registry, either blocking all commercial calls or specific categories such as banking, real estate, education or health.
- Promotional calls must use the 140 series; transactional and service calls use 1600.
- Unregistered entities sending unsolicited commercial communication face fines up to ₹50,000 per violation. Registered telemarketers face graded penalties from ₹1,000 for a first offence.
Calling your own existing customers about their own business with you is service communication, not telemarketing. Cold-calling a purchased list is where businesses cross the line, and a bought database is no defence.
Where Android sits, practically
Worth knowing before you plan around it: Android has progressively restricted third-party call recording. Since Android 10, and more firmly since Android 11, ordinary apps cannot reliably record calls. Recorders still on the Play Store generally work only on some manufacturers’ phones, or not at all.
This is why teams that genuinely need recording use cloud telephony (FreJun, Exotel, MyOperator and similar): the call travels through the provider’s network, so recording happens server-side and is not subject to the handset restriction.
RMDialer does not record calls. It tracks what happened on them — who was called, whether it connected, how long it lasted and what came of it — which is what most businesses actually need, and which carries far lighter obligations than storing recordings of customer conversations.
A workable checklist
If you are going to record:
- [ ] An announcement at the start of every recorded call
- [ ] A stated purpose, in plain words
- [ ] A way for the customer to say no
- [ ] Timestamped consent records
- [ ] Access limited to the people who need it
- [ ] A retention period, and actual deletion when it ends
- [ ] DND / NCPR screening before any promotional calling
- [ ] Written advice if you are in a regulated sector
If that list looks heavy, it is worth asking what you wanted recordings for. If the honest answer is “to know what the team is doing”, call tracking answers that without any of it.
- crm
- team
- reporting