Every fact web-verified against primary sources

The Lift Line

Every unanswered call from a number you do not recognise is a small tax that fraudsters have levied on everyone else. CNAP does not block the fraudster; it takes away the anonymity that made the fraud worth attempting.

Why This Editorial Matters for Your Exam

Digital consumer rights, telecom regulation and privacy are converging into a recurring GS2/GS3 theme, and CNAP is a clean case study in which a privacy-protective and a privacy-intrusive reading of the same measure are both defensible, exactly the kind of tension examiners want candidates to hold rather than resolve too quickly.

GS Paper 2: Government policies and interventions; consumer rights; e-governance; statutory and regulatory bodies.

GS Paper 3: Awareness in the field of IT; cyber security; money laundering and its prevention.

For Prelims, fix the CNAP and CLIR acronyms and TRAI’s role as the recommending regulator.

Concept Meaning Why UPSC tests it
CNAP (Calling Name Presentation) A service displaying the caller’s verified name, drawn from telecom KYC records, on the recipient’s device The core mechanism of this reform
CLIR (Calling Line Identification Restriction) The facility allowing a caller to withhold identity presentation The privacy opt-out, and the point at which the default question arises
TRAI Telecom Regulatory Authority of India, the sector regulator that recommended CNAP The institutional actor behind the reform
Purpose limitation The data-protection principle that data collected for one purpose should not be used for another The central safeguard this editorial argues must be legislated alongside CNAP

Background and Context

India’s telecom subscriber base is among the world’s largest, and its spam and fraud-call problem is correspondingly large: Truecaller recorded roughly 4,168 crore spam calls across 2025. TRAI recommended CNAP following a consultation process, the DoT framework was approved in October 2025, and a staged nationwide rollout was targeted from March 2026, beginning with 4G and 5G users. Successive interventions have taken a blocking approach: the Do Not Disturb registry, operator-side filtering obligations, and a substantial private market in third-party caller-identification apps that crowdsource spam labels. CNAP takes a different approach, using the KYC information telecom operators already collect at the point of subscriber verification to display a verified name to the recipient.

Approach Mechanism Limitation
Do Not Disturb registry Recipients opt out of marketing calls Poor compliance; ineffective against fraud calls, which never intended to comply
Third-party caller-ID apps Crowdsourced spam labelling Depends on private databases of uncertain provenance and accuracy
Operator-side filtering Network-level blocking of flagged numbers Reactive; fraudsters cycle numbers faster than blocking adapts
CNAP Displays verified KYC-derived name at call presentation Creates an identity-disclosure infrastructure with uses beyond spam

The Core Argument / Issue

Why blocking has failed, and what it cost

The blocking paradigm assumes a finite adversary who can be enumerated and excluded. Fraud calling does not work that way: numbers are cheap, cycled rapidly, and often spoofed. The predictable result is that blocking never catches up, and recipients adopt the only reliable defence available to them, which is to stop answering unknown numbers entirely. That adaptation is individually rational and collectively costly, since it degrades the phone network’s usefulness for every legitimate caller who happens to be unknown to the recipient.

Why identity disclosure is structurally different

Displaying a verified name does not block anything. What it does is remove the anonymity that makes high-volume fraudulent calling economically viable. A fraud operation depends on being unidentifiable both to the person it is defrauding and to anyone investigating afterward. Attaching a KYC-verified name to the call attacks both, and does so without requiring the network to correctly predict in advance which calls are fraudulent, which is the prediction problem blocking approaches keep failing.

The architectural objection, taken seriously

The concern is not that CNAP will fail; it is that it will work, and that a functioning nationwide identity-disclosure layer attached to the telephone network is a capability with obvious secondary applications. Identity infrastructures built for narrow purposes have historically expanded, and the expansion is typically incremental and individually reasonable at each step. The safeguard against this is not technical but legal: an express statutory purpose limitation confining CNAP-derived data to call presentation, enforceable independently of the executive’s own restraint.

The default question

CLIR lets a caller withhold their name. That is a genuine mitigation, but it is an opt-out. Under an opt-out design, the default is disclosure, and privacy is available only to those who know the facility exists and take the trouble to invoke it, a population that skews toward the already-informed. Data-protection principle generally favours privacy-by-default, and the question of whether CNAP’s default is correctly set deserves more scrutiny than it has received.

How to Think About This (Analytical Frame)

Distinguish an intervention that predicts bad behaviour from one that removes the conditions enabling it. Blocking-based approaches must correctly identify which calls are fraudulent, a prediction problem the adversary is actively working to defeat. Identity disclosure does not predict anything; it changes the payoff structure so that fraudulent calling is less attractive regardless of whether any particular call is detected. When evaluating any enforcement or regulatory design, ask whether it depends on winning a prediction contest against an adaptive adversary, since designs that do tend to degrade over time while designs that alter incentives tend not to.

The Diagram in Words

Picture the phone network as a doorway with no peephole. Currently, every knock is anonymous, so residents have learned to ignore knocking altogether, which frustrates the postman and the neighbour as much as the intruder. The blocking approach installs an ever-growing list of people not to admit, which the intruder defeats simply by using a different name each time. CNAP installs a peephole. It does not decide who may enter; it lets the resident see who is there, and, just as importantly, it means the intruder knows they can be seen. The remaining question is who else can look through the peephole, and what they are permitted to do with what they see.

Way Forward

  1. Legislate express purpose limitation confining CNAP-derived identity data to call presentation alone, enforceable independently of executive discretion.
  2. Reconsider the CLIR default, evaluating whether privacy-by-default would better align the system with data-protection principle without materially weakening its anti-fraud function.
  3. Establish independent oversight of access to the telecom KYC databases feeding CNAP, with published access logs and audit provisions.
  4. Build an accuracy-correction mechanism, since a system displaying verified names must have a fast, low-friction route for individuals to correct a wrong or outdated name.
  5. Evaluate outcomes on fraud incidence, not call volume, so the system’s success is measured against the harm it was built to address rather than against a proxy metric.

PYQ Linkage and Practice

UPSC has tested data protection, telecom regulation, cyber fraud and digital consumer rights across GS2 and GS3, and CNAP offers a specific, current instrument through which the privacy-versus-security trade-off can be examined concretely rather than abstractly.

Practice question: “An intervention that removes the conditions enabling harm is more durable than one that attempts to predict and block the harm itself.” Examine this claim with reference to India’s Calling Name Presentation rollout and the failure of blocking-based approaches to spam and fraud calling. (250 words, 15 marks)

Interview angle: CNAP draws caller names from telecom KYC records, which means the state and telecom operators are jointly deciding what name appears on every citizen’s phone screen. What safeguards would you build so that a system designed against spam does not become a general-purpose identity-disclosure infrastructure?

Sources: The Indian Express, Telecom Regulatory Authority of India, Department of Telecommunications

Source: Look Who's Calling: India Needs a Right to Know Who Is Contacting You — Ujiyari.com | Free UPSC & State PCS Editorial Analysis