Regulatory Updates
Regional compliance notes for global teams, covering enterprise communications, A2P SMS, real-name registration, data privacy, and sending restrictions.
Canada eSIM switching fee scrutiny
This matters for product, compliance, channel, and operations teams that rely on Canadian line activation, self-serve switching, travel connectivity, OTP delivery, and account messaging. Canada’s CRTC has moved SIM and eSIM charges into the broader switching-barrier debate, meaning eSIM is now a compliance issue, not just an onboarding choice. The key dates are 12 June 2026, when the fee prohibition took effect, and 30 July 2026, the deadline in the show-cause proceeding. Exposure can include administrative monetary penalties reaching C$10 million for a first contravention.
India telecom data ownership review
This matters to teams running SMS alerts, OTP, customer messaging, and CPaaS integrations in India because the compliance question is shifting from simple consent capture to end-to-end accountability for subscriber, traffic, location, device, and outsourced processing data. On 23 July 2026, TRAI opened a consultation on privacy, security, and ownership of telecom-sector data, on top of the new authorisation framework launched in late June. Any follow-on rules could reshape retention, data sharing, audit evidence, and vendor access design.
UK SMS Guidance Update Pending
This matters to growth, compliance, and messaging operations teams sending marketing SMS, account prompts, and cross-channel campaigns into the UK because the ICO is actively aligning PECR guidance with changes introduced by the Data (Use and Access) Act. Companies can no longer assume that legacy consent logic is enough. The ICO updated its direct marketing guidance on April 28, 2026 to reflect the Act’s commencement timetable, and it still lists updated PECR guidance for Summer 2026, which makes message classification, soft opt-in use, and opt-out mechanics immediate review items.
UK Category 1 Messaging Controls Tighten
This matters for product, legal, and trust-and-safety teams running DMs, social messaging, customer chat, or account notifications in the UK because compliance is shifting beyond takedowns into identity options, user controls, complaints handling, and privacy impact assessments. On July 10, 2026, Ofcom opened its consultation on additional duties for Category 1 services, while its implementation timetable points to October 2026 for up-to-date risk assessment records, creating a near-term engineering and governance deadline for messaging features.
Australia Unverified SMS Threading
For teams sending branded SMS, OTPs, billing alerts, and delivery notifications into Australia, the new risk is no longer limited to outright blocking. It now appears in the handset experience itself and can erode brand trust immediately. Australia’s ACMA launched phase one of the SMS Sender ID Register on July 1, 2026. Unregistered sender IDs are now relabeled as 「Unverified」 and grouped into a single thread, while international senders must route branded traffic through an approved Australian telecommunications provider.
UK redraws teen messaging lines
For product, compliance, trust-and-safety, and messaging teams operating in the UK, the practical issue is that regulators are no longer looking only at platforms as a whole. They are isolating messaging-related functions such as direct messages from strangers, livestream interaction, and default protections for minors. In recent UK proposals, core messaging services such as WhatsApp and Signal remain outside the under-16 social media ban, but mixed platforms with social and messaging features are moving into a stricter compliance perimeter.
UAE eSIM KYC Tightens
This matters for teams selling travel eSIMs, supporting cross-border onboarding, or relying on SMS OTP fallback in the UAE. Compliance is no longer just about whether an activation works; it now affects whether the user can complete identity checks, keep service live, and receive verification traffic. The current compliance direction is moving from one-time subscriber verification toward stricter distributor accountability, stronger audit trails, and faster handling of suspicious or weakly verified activations.
Indonesia chat export scrutiny
This matters to product, legal, security, and CX teams running WhatsApp support, in-app messaging, account alerts, or SMS fallback flows in Indonesia. The main risk is no longer message delivery alone, but whether chat logs, MSISDNs, device identifiers, and ticket data can be transferred overseas, used for analytics, and retained with an auditable legal basis. In 2026, the combined effect of Indonesia personal data protection and electronic-system governance is turning messaging data handling into a core compliance control for cross-border communications businesses.
US Healthcare SMS Data Minimization
For healthcare providers, insurers, and CPaaS teams handling appointment reminders, lab notices, billing prompts, and MFA in North America, the real compliance issue is no longer just having a patient phone number. The operational test in 2026 is whether SMS content is limited to the minimum necessary data, with template fields, delivery logs, vendor access, and opt-out handling governed together. That directly affects complaints, BA/vendor oversight, and audit readiness.
Kenya SMS Consent Audit
This matters to growth, compliance, CRM, and messaging operations teams sending promotional SMS, reminders, or account alerts into East Africa. In Kenya, the real exposure is no longer just whether a message is promotional, but whether the sender can evidence consent, unsubscribe handling, list provenance, and processor accountability. The current compliance direction ties privacy, outsourcing, complaint handling, and customer-contact governance together, meaning weak list controls can now disrupt campaign approvals, vendor management, and dispute response.
Korea Tightens International SMS Screening
For teams sending OTPs, billing alerts, account notifications, or promotional texts into South Korea, this matters because anti-fraud controls are increasingly tied to sender traceability and scrutiny of international traffic. The practical risk is no longer limited to lower delivery rates: filtering, complaint escalation, and channel instability can hit core user flows. In the current environment, businesses relying on generic templates, weak sender governance, or thin consent records should expect higher blocking risk and more operational friction.
UK fee-base clash for messaging platforms
For product, legal, finance, and trust teams running WhatsApp support, in-app messaging, private messaging, or UGC-based communications in the UK, the issue is no longer just moderation headcount. Compliance exposure is now tied to global-revenue calculations, annual regulatory levies, and potentially very large penalties. In May 2026, Meta challenged Ofcom’s approach to calculating Online Safety Act fees and fines on a qualifying worldwide revenue basis, turning UK messaging compliance into a group-level governance and cost-allocation problem.
Japan Tightens Business Chat Data Outsourcing
For teams running customer chat, account alerts, in-app messaging, or OTT workflows in Japan, the key issue is that responsibility does not shift to vendors once message data is outsourced, remotely accessed, or reused for model improvement. In 2026, the practical compliance focus is moving toward provable controls: vendor inventories, retention boundaries for chat logs, breach escalation paths, and user-facing disclosures for cross-border processing and secondary use.
EU Messaging Incident Reporting Tightens
For teams running SMS alerts, OTP traffic, OTT messaging, or CPaaS services in Europe, the compliance issue is no longer limited to consent or content rules. Regulators are increasingly looking at resilience, supplier dependency, access control, and incident reporting discipline. As NIS2 implementation progresses across EU member states, messaging providers and enterprises using them should treat delivery outages, authentication failures, vendor incidents, and evidence retention as reportable operational compliance issues rather than routine support events.
Philippines SIM Traceability Tightens
This matters to teams running OTP, account alerts, collections reminders, and branded messaging in Southeast Asia because the Philippines continues tying SIM registration, anti-fraud traceability, and number status management together. The practical issue is not only message content review. Numbers with incomplete registration, inconsistent identity data, or suspicious activity can face deactivation, review, or restrictions, which then hits delivery, user recovery flows, and complaint handling. For enterprises, sender governance increasingly depends on proving message purpose, consent path, and a verifiable relationship to the recipient.
Brazil Tightens Number Verification
This matters to teams running OTP, onboarding, billing alerts, and promotional messaging in Latin America because Brazil is increasingly linking subscriber identity, anti-fraud controls, and data-use limits into one compliance workflow. The practical shift is not a single new ban, but a higher expectation that brands can reconcile number source, consent record, use case, and vendor authorization. If those records do not line up, delivery performance, complaint handling, and third-party liability can all deteriorate at the same time.
Malaysia Tightens OTT Controls
This matters to product, legal, trust and safety, and operations teams running chat, account messaging, or community features in Southeast Asia because platform liability in Malaysia is moving beyond reactive takedowns. Since June 1, 2026, services covered by the regime must block new accounts for users under 16 and roll out age verification for existing users, while a May legal notice to TikTok showed regulators are also testing response speed, moderation controls, and remediation duties for harmful AI-generated content.
Turkey eSIM Access Limits
This matters for travel eSIM sellers, cross-border onboarding teams, and product owners who rely on SMS or OTT messaging for first-login and support flows. A May 2026 industry update reiterated that Turkey continues to restrict access to major international eSIM provider websites and apps inside the country, turning eSIM compliance into a pre-arrival delivery problem rather than a simple checkout issue. If users have not downloaded and activated the profile before landing, activation, customer support, and fallback verification can all break at the worst point in the journey.
US geofence warrant case raises telecom data stakes
For product, legal, and privacy teams running SMS verification, account security, in-app messaging, or mobile apps in North America, this case matters because it could reset the rules on bulk access to precise location data and the retention logic behind related logs. On April 27, 2026, the US Supreme Court heard Chatrie v. United States, a case asking whether a geofence warrant that compels disclosure of all devices in a defined place and time is constitutional. The outcome could reshape disclosure workflows, data minimization, and law-enforcement response playbooks.
India’s Temporary Telegram Block
This matters to product, compliance, and operations teams using Telegram or other OTT channels in India for support, community operations, education notices, or user engagement because service availability can now be disrupted on short notice for public-order or anti-fraud reasons. In mid-June 2026, India imposed a temporary nationwide restriction on Telegram and kept some feature limits in place until June 30, signaling that OTT messaging access itself is becoming an operational compliance variable, not just a policy debate.
EU Forces WhatsApp AI Access Reversal
This matters to product, legal, and channel teams using WhatsApp in Europe for customer support, alerts, conversational commerce, or AI integrations because the WhatsApp Business API is now being treated as a regulated route to consumers, not just a commercial API. In June 2026, the European Commission imposed interim measures requiring Meta to restore free access terms for rival general-purpose AI assistants while the antitrust case continues, putting platform access, pricing barriers, and exclusion risk at the center of OTT messaging compliance.
Mexico mobile line registration deadline
For teams running OTP login, account alerts, callback workflows, travel SIM, or eSIM distribution in Mexico, this matters because line-level identity binding is becoming an operational prerequisite rather than a back-office issue. Mexico’s current framework requires mobile numbers to be linked to a CURP for individuals or an RFC for companies by June 30, 2026. Lines that are not registered may keep the number but lose service, while newly sold lines must be registered before normal activation, changing onboarding, KYC, support, and churn risk assumptions.
India OTT Spam Scope Fight
This matters for teams running both telecom messaging and app-based outreach in India because the compliance perimeter may expand from carrier SMS and calls to OTT communications such as WhatsApp and Telegram. Between April and June 2026, Indian operators and internet platforms publicly disputed whether TRAI should bring OTT messaging and voice into anti-spam controls. No final rule is in force yet, but the direction of travel is clear enough that enterprises should review consent evidence, complaint workflows, sender governance, and abuse-monitoring records now.
India digital consent for commercial messaging
For teams sending promotional SMS, loan outreach, callback campaigns, or loyalty messages in India, the current shift matters because consent can no longer live only inside an internal CRM log. The debate in mid-June 2026 shows the market moving toward carrier-verifiable, revocable, and auditable consent controls. In practice, compliance is expanding from spam filtering to operational questions such as how consent is captured, how revocation is passed downstream, and what evidence an enterprise can produce when a message flow is challenged.
US FCC Location-Data Penalty Power Upheld
For legal, privacy, and operations teams running SMS, voice alerts, number-based authentication, or mobile engagement in North America, this matters because U.S. telecom privacy enforcement did not lose one of its main penalty tools. On June 4, 2026, the U.S. Supreme Court upheld the FCC’s ability to pursue privacy fines through its administrative process, rejecting procedural arguments raised by AT&T and Verizon in a case tied to more than $100 million in penalties over customer location-data practices.
Ireland SMS Sender ID Registry Push
This matters for SMS operations, compliance, and integration teams sending OTPs, billing alerts, delivery notices, or branded messages to Irish mobile users because Sender ID status is moving from a routing detail to a consumer-facing trust signal. ComReg launched the SMS Sender ID Registry on June 4, 2025 and said the 「Likely Scam」 modification phase begins on July 3, 2025. Unregistered or weakly substantiated Sender IDs can therefore create higher filtering, labeling, and delivery-risk exposure for A2P traffic into Ireland.
Spain Tightens Alias Blocking for SMS
For teams sending branded SMS, OTPs, billing alerts, or RCS notifications to Spanish numbers, the key shift is that sender aliases are no longer just a routing setting but a regulated registry and blocking issue. In March 2026, Spain’s CNMC formalized the Alias Register and confirmed that from June 7, 2026, operators must block messages using unregistered aliases, messages sent by non-authorized providers, and messages from foreign entities not registered in Spain, subject to limited roaming exceptions.
Hong Kong SMS sender scheme expands
This matters for SMS operations, product integration, and compliance teams sending OTPs, billing alerts, service messages, and membership notifications to Hong Kong users. Hong Kong’s SMS Sender Registration Scheme is no longer just a public-awareness measure; it is increasingly part of sender authenticity, anti-scam controls, and delivery trust. In May 2026, OFCA refreshed scheme materials and sender lists, signaling continued operationalization. Brands still using unregistered or inconsistent sender IDs should expect lower user trust, higher complaint exposure, and greater scrutiny from carriers and local partners.
Canada Tightens Liability for Outsourced Telemarketing
This matters to marketing, compliance, and vendor-management teams running outbound calls, text-led lead generation, and customer contact into North America because Canadian enforcement is continuing to push liability upstream to the brand and outsourcing chain, not only the frontline sender. In March 2026, the CRTC issued a notice of violation against iTalk Global Communications and highlighted internal do-not-call retention and identification obligations. For cross-border messaging and contact programs, outsourcing no longer functions as a practical compliance shield.
EU DMA Pushes Device Transfer and eSIM Interoperability
This matters for product, compliance, and integration teams running OTT messaging, account alerts, companion apps, and connected-device services in Europe because the DMA is no longer just about chat interoperability. In April and May 2026, the European Commission tied interoperability to concrete implementation milestones covering device transfer, notification access, and eSIM transfer, with some measures scheduled around June 1, 2026. For communications providers, switching friction is becoming a compliance, retention, and technical integration issue at the same time.
Australia Tightens Cross-Border Sender ID Access
For teams sending OTPs, billing alerts, delivery notifications, and customer-service texts into Australia, the key issue is no longer just whether a sender ID is registered. From July 1, 2026, cross-border A2P delivery also depends on whether the offshore messaging chain is connected to an approved Australian participation model. ACMA’s recent guidance makes clear that international brands and message providers must work through certified or participating Australian providers, or branded traffic may be relabeled as 「Unverified」 and lose sender identity at the point of delivery.
Australia SMS Sender ID Downgrade Nears
This matters for SMS operations, product, and compliance teams sending OTPs, billing alerts, delivery updates, and support messages into Australia because the consequence of non-compliance is now operationally concrete. From July 1, 2026, branded SMS sent with an unregistered sender ID will be overwritten as “Unverified” and grouped into a shared thread with other unregistered traffic. ACMA’s May 2026 reminder shows the regime has moved from policy design to implementation, with immediate implications for deliverability, brand recognition, and customer trust.
UK A2P Scam-Control Rules
This matters for SMS operations, compliance, and technical integration teams that send OTPs, billing alerts, delivery notices, or support messages into the UK. Ofcom is moving anti-scam controls from post-incident handling into the A2P messaging stack itself. In 2026, the regulator continued advancing its mobile messaging scam framework, proposing baseline obligations for mobile operators and business messaging aggregators across KYC, sender ID validation, ongoing traffic monitoring, incident handling, and data protection. Ofcom says it plans to publish a final decision in summer 2026, which could reshape onboarding and routing requirements for UK-bound business messaging.
Need compliance guidance?
Contact us for enterprise communication compliance guidance and implementation paths for your target markets.
Get in Touch