Regulatory Updates

Regional compliance notes for global teams, covering enterprise communications, A2P SMS, real-name registration, data privacy, and sending restrictions.

North America Industry compliance

Canada eSIM switching fee scrutiny

This matters for product, compliance, channel, and operations teams that rely on Canadian line activation, self-serve switching, travel connectivity, OTP delivery, and account messaging. Canada’s CRTC has moved SIM and eSIM charges into the broader switching-barrier debate, meaning eSIM is now a compliance issue, not just an onboarding choice. The key dates are 12 June 2026, when the fee prohibition took effect, and 30 July 2026, the deadline in the show-cause proceeding. Exposure can include administrative monetary penalties reaching C$10 million for a first contravention.

Published:07/30/2026 Updated:07/30/2026
Other Data privacy

India telecom data ownership review

This matters to teams running SMS alerts, OTP, customer messaging, and CPaaS integrations in India because the compliance question is shifting from simple consent capture to end-to-end accountability for subscriber, traffic, location, device, and outsourced processing data. On 23 July 2026, TRAI opened a consultation on privacy, security, and ownership of telecom-sector data, on top of the new authorisation framework launched in late June. Any follow-on rules could reshape retention, data sharing, audit evidence, and vendor access design.

Published:07/29/2026 Updated:07/29/2026
Europe Sending restrictions

UK SMS Guidance Update Pending

This matters to growth, compliance, and messaging operations teams sending marketing SMS, account prompts, and cross-channel campaigns into the UK because the ICO is actively aligning PECR guidance with changes introduced by the Data (Use and Access) Act. Companies can no longer assume that legacy consent logic is enough. The ICO updated its direct marketing guidance on April 28, 2026 to reflect the Act’s commencement timetable, and it still lists updated PECR guidance for Summer 2026, which makes message classification, soft opt-in use, and opt-out mechanics immediate review items.

Published:07/21/2026 Updated:07/21/2026
Europe Industry compliance

UK Category 1 Messaging Controls Tighten

This matters for product, legal, and trust-and-safety teams running DMs, social messaging, customer chat, or account notifications in the UK because compliance is shifting beyond takedowns into identity options, user controls, complaints handling, and privacy impact assessments. On July 10, 2026, Ofcom opened its consultation on additional duties for Category 1 services, while its implementation timetable points to October 2026 for up-to-date risk assessment records, creating a near-term engineering and governance deadline for messaging features.

Published:07/15/2026 Updated:07/15/2026
Other A2P SMS regulations

Australia Unverified SMS Threading

For teams sending branded SMS, OTPs, billing alerts, and delivery notifications into Australia, the new risk is no longer limited to outright blocking. It now appears in the handset experience itself and can erode brand trust immediately. Australia’s ACMA launched phase one of the SMS Sender ID Register on July 1, 2026. Unregistered sender IDs are now relabeled as 「Unverified」 and grouped into a single thread, while international senders must route branded traffic through an approved Australian telecommunications provider.

Published:07/14/2026 Updated:07/14/2026
Europe Industry compliance

UK redraws teen messaging lines

For product, compliance, trust-and-safety, and messaging teams operating in the UK, the practical issue is that regulators are no longer looking only at platforms as a whole. They are isolating messaging-related functions such as direct messages from strangers, livestream interaction, and default protections for minors. In recent UK proposals, core messaging services such as WhatsApp and Signal remain outside the under-16 social media ban, but mixed platforms with social and messaging features are moving into a stricter compliance perimeter.

Published:07/13/2026 Updated:07/13/2026
Middle East Real-name registration

UAE eSIM KYC Tightens

This matters for teams selling travel eSIMs, supporting cross-border onboarding, or relying on SMS OTP fallback in the UAE. Compliance is no longer just about whether an activation works; it now affects whether the user can complete identity checks, keep service live, and receive verification traffic. The current compliance direction is moving from one-time subscriber verification toward stricter distributor accountability, stronger audit trails, and faster handling of suspicious or weakly verified activations.

Published:07/10/2026 Updated:07/10/2026
Southeast Asia Data privacy

Indonesia chat export scrutiny

This matters to product, legal, security, and CX teams running WhatsApp support, in-app messaging, account alerts, or SMS fallback flows in Indonesia. The main risk is no longer message delivery alone, but whether chat logs, MSISDNs, device identifiers, and ticket data can be transferred overseas, used for analytics, and retained with an auditable legal basis. In 2026, the combined effect of Indonesia personal data protection and electronic-system governance is turning messaging data handling into a core compliance control for cross-border communications businesses.

Published:07/09/2026 Updated:07/09/2026
North America Data privacy

US Healthcare SMS Data Minimization

For healthcare providers, insurers, and CPaaS teams handling appointment reminders, lab notices, billing prompts, and MFA in North America, the real compliance issue is no longer just having a patient phone number. The operational test in 2026 is whether SMS content is limited to the minimum necessary data, with template fields, delivery logs, vendor access, and opt-out handling governed together. That directly affects complaints, BA/vendor oversight, and audit readiness.

Published:07/08/2026 Updated:07/08/2026
Africa Data privacy

Kenya SMS Consent Audit

This matters to growth, compliance, CRM, and messaging operations teams sending promotional SMS, reminders, or account alerts into East Africa. In Kenya, the real exposure is no longer just whether a message is promotional, but whether the sender can evidence consent, unsubscribe handling, list provenance, and processor accountability. The current compliance direction ties privacy, outsourcing, complaint handling, and customer-contact governance together, meaning weak list controls can now disrupt campaign approvals, vendor management, and dispute response.

Published:07/06/2026 Updated:07/06/2026
Other A2P SMS regulations

Korea Tightens International SMS Screening

For teams sending OTPs, billing alerts, account notifications, or promotional texts into South Korea, this matters because anti-fraud controls are increasingly tied to sender traceability and scrutiny of international traffic. The practical risk is no longer limited to lower delivery rates: filtering, complaint escalation, and channel instability can hit core user flows. In the current environment, businesses relying on generic templates, weak sender governance, or thin consent records should expect higher blocking risk and more operational friction.

Published:07/05/2026 Updated:07/05/2026
Europe Industry compliance

UK fee-base clash for messaging platforms

For product, legal, finance, and trust teams running WhatsApp support, in-app messaging, private messaging, or UGC-based communications in the UK, the issue is no longer just moderation headcount. Compliance exposure is now tied to global-revenue calculations, annual regulatory levies, and potentially very large penalties. In May 2026, Meta challenged Ofcom’s approach to calculating Online Safety Act fees and fines on a qualifying worldwide revenue basis, turning UK messaging compliance into a group-level governance and cost-allocation problem.

Published:07/04/2026 Updated:07/04/2026
Other Data privacy

Japan Tightens Business Chat Data Outsourcing

For teams running customer chat, account alerts, in-app messaging, or OTT workflows in Japan, the key issue is that responsibility does not shift to vendors once message data is outsourced, remotely accessed, or reused for model improvement. In 2026, the practical compliance focus is moving toward provable controls: vendor inventories, retention boundaries for chat logs, breach escalation paths, and user-facing disclosures for cross-border processing and secondary use.

Published:07/03/2026 Updated:07/03/2026
Europe Industry compliance

EU Messaging Incident Reporting Tightens

For teams running SMS alerts, OTP traffic, OTT messaging, or CPaaS services in Europe, the compliance issue is no longer limited to consent or content rules. Regulators are increasingly looking at resilience, supplier dependency, access control, and incident reporting discipline. As NIS2 implementation progresses across EU member states, messaging providers and enterprises using them should treat delivery outages, authentication failures, vendor incidents, and evidence retention as reportable operational compliance issues rather than routine support events.

Published:07/02/2026 Updated:07/02/2026
Southeast Asia Real-name registration

Philippines SIM Traceability Tightens

This matters to teams running OTP, account alerts, collections reminders, and branded messaging in Southeast Asia because the Philippines continues tying SIM registration, anti-fraud traceability, and number status management together. The practical issue is not only message content review. Numbers with incomplete registration, inconsistent identity data, or suspicious activity can face deactivation, review, or restrictions, which then hits delivery, user recovery flows, and complaint handling. For enterprises, sender governance increasingly depends on proving message purpose, consent path, and a verifiable relationship to the recipient.

Published:07/01/2026 Updated:07/01/2026
Other Real-name registration

Brazil Tightens Number Verification

This matters to teams running OTP, onboarding, billing alerts, and promotional messaging in Latin America because Brazil is increasingly linking subscriber identity, anti-fraud controls, and data-use limits into one compliance workflow. The practical shift is not a single new ban, but a higher expectation that brands can reconcile number source, consent record, use case, and vendor authorization. If those records do not line up, delivery performance, complaint handling, and third-party liability can all deteriorate at the same time.

Published:06/30/2026 Updated:06/30/2026
Southeast Asia Industry compliance

Malaysia Tightens OTT Controls

This matters to product, legal, trust and safety, and operations teams running chat, account messaging, or community features in Southeast Asia because platform liability in Malaysia is moving beyond reactive takedowns. Since June 1, 2026, services covered by the regime must block new accounts for users under 16 and roll out age verification for existing users, while a May legal notice to TikTok showed regulators are also testing response speed, moderation controls, and remediation duties for harmful AI-generated content.

Published:06/29/2026 Updated:06/29/2026
Other Industry compliance

Turkey eSIM Access Limits

This matters for travel eSIM sellers, cross-border onboarding teams, and product owners who rely on SMS or OTT messaging for first-login and support flows. A May 2026 industry update reiterated that Turkey continues to restrict access to major international eSIM provider websites and apps inside the country, turning eSIM compliance into a pre-arrival delivery problem rather than a simple checkout issue. If users have not downloaded and activated the profile before landing, activation, customer support, and fallback verification can all break at the worst point in the journey.

Published:06/28/2026 Updated:06/28/2026
North America Data privacy

US geofence warrant case raises telecom data stakes

For product, legal, and privacy teams running SMS verification, account security, in-app messaging, or mobile apps in North America, this case matters because it could reset the rules on bulk access to precise location data and the retention logic behind related logs. On April 27, 2026, the US Supreme Court heard Chatrie v. United States, a case asking whether a geofence warrant that compels disclosure of all devices in a defined place and time is constitutional. The outcome could reshape disclosure workflows, data minimization, and law-enforcement response playbooks.

Published:06/26/2026 Updated:06/26/2026
Other Industry compliance

India’s Temporary Telegram Block

This matters to product, compliance, and operations teams using Telegram or other OTT channels in India for support, community operations, education notices, or user engagement because service availability can now be disrupted on short notice for public-order or anti-fraud reasons. In mid-June 2026, India imposed a temporary nationwide restriction on Telegram and kept some feature limits in place until June 30, signaling that OTT messaging access itself is becoming an operational compliance variable, not just a policy debate.

Published:06/22/2026 Updated:06/22/2026
Europe Industry compliance

EU Forces WhatsApp AI Access Reversal

This matters to product, legal, and channel teams using WhatsApp in Europe for customer support, alerts, conversational commerce, or AI integrations because the WhatsApp Business API is now being treated as a regulated route to consumers, not just a commercial API. In June 2026, the European Commission imposed interim measures requiring Meta to restore free access terms for rival general-purpose AI assistants while the antitrust case continues, putting platform access, pricing barriers, and exclusion risk at the center of OTT messaging compliance.

Published:06/20/2026 Updated:06/20/2026
Other Real-name registration

Mexico mobile line registration deadline

For teams running OTP login, account alerts, callback workflows, travel SIM, or eSIM distribution in Mexico, this matters because line-level identity binding is becoming an operational prerequisite rather than a back-office issue. Mexico’s current framework requires mobile numbers to be linked to a CURP for individuals or an RFC for companies by June 30, 2026. Lines that are not registered may keep the number but lose service, while newly sold lines must be registered before normal activation, changing onboarding, KYC, support, and churn risk assumptions.

Published:06/18/2026 Updated:06/18/2026
Other Industry compliance

India OTT Spam Scope Fight

This matters for teams running both telecom messaging and app-based outreach in India because the compliance perimeter may expand from carrier SMS and calls to OTT communications such as WhatsApp and Telegram. Between April and June 2026, Indian operators and internet platforms publicly disputed whether TRAI should bring OTT messaging and voice into anti-spam controls. No final rule is in force yet, but the direction of travel is clear enough that enterprises should review consent evidence, complaint workflows, sender governance, and abuse-monitoring records now.

Published:06/17/2026 Updated:06/17/2026
Other Data privacy

India digital consent for commercial messaging

For teams sending promotional SMS, loan outreach, callback campaigns, or loyalty messages in India, the current shift matters because consent can no longer live only inside an internal CRM log. The debate in mid-June 2026 shows the market moving toward carrier-verifiable, revocable, and auditable consent controls. In practice, compliance is expanding from spam filtering to operational questions such as how consent is captured, how revocation is passed downstream, and what evidence an enterprise can produce when a message flow is challenged.

Published:06/17/2026 Updated:06/17/2026
North America Data privacy

US FCC Location-Data Penalty Power Upheld

For legal, privacy, and operations teams running SMS, voice alerts, number-based authentication, or mobile engagement in North America, this matters because U.S. telecom privacy enforcement did not lose one of its main penalty tools. On June 4, 2026, the U.S. Supreme Court upheld the FCC’s ability to pursue privacy fines through its administrative process, rejecting procedural arguments raised by AT&T and Verizon in a case tied to more than $100 million in penalties over customer location-data practices.

Published:06/16/2026 Updated:06/16/2026
Europe A2P SMS regulations

Ireland SMS Sender ID Registry Push

This matters for SMS operations, compliance, and integration teams sending OTPs, billing alerts, delivery notices, or branded messages to Irish mobile users because Sender ID status is moving from a routing detail to a consumer-facing trust signal. ComReg launched the SMS Sender ID Registry on June 4, 2025 and said the 「Likely Scam」 modification phase begins on July 3, 2025. Unregistered or weakly substantiated Sender IDs can therefore create higher filtering, labeling, and delivery-risk exposure for A2P traffic into Ireland.

Published:06/03/2026 Updated:06/03/2026
Europe A2P SMS regulations

Spain Tightens Alias Blocking for SMS

For teams sending branded SMS, OTPs, billing alerts, or RCS notifications to Spanish numbers, the key shift is that sender aliases are no longer just a routing setting but a regulated registry and blocking issue. In March 2026, Spain’s CNMC formalized the Alias Register and confirmed that from June 7, 2026, operators must block messages using unregistered aliases, messages sent by non-authorized providers, and messages from foreign entities not registered in Spain, subject to limited roaming exceptions.

Published:06/01/2026 Updated:06/01/2026
Other A2P SMS regulations

Hong Kong SMS sender scheme expands

This matters for SMS operations, product integration, and compliance teams sending OTPs, billing alerts, service messages, and membership notifications to Hong Kong users. Hong Kong’s SMS Sender Registration Scheme is no longer just a public-awareness measure; it is increasingly part of sender authenticity, anti-scam controls, and delivery trust. In May 2026, OFCA refreshed scheme materials and sender lists, signaling continued operationalization. Brands still using unregistered or inconsistent sender IDs should expect lower user trust, higher complaint exposure, and greater scrutiny from carriers and local partners.

Published:05/31/2026 Updated:05/31/2026
North America Industry compliance

Canada Tightens Liability for Outsourced Telemarketing

This matters to marketing, compliance, and vendor-management teams running outbound calls, text-led lead generation, and customer contact into North America because Canadian enforcement is continuing to push liability upstream to the brand and outsourcing chain, not only the frontline sender. In March 2026, the CRTC issued a notice of violation against iTalk Global Communications and highlighted internal do-not-call retention and identification obligations. For cross-border messaging and contact programs, outsourcing no longer functions as a practical compliance shield.

Published:05/30/2026 Updated:05/30/2026
Europe Industry compliance

EU DMA Pushes Device Transfer and eSIM Interoperability

This matters for product, compliance, and integration teams running OTT messaging, account alerts, companion apps, and connected-device services in Europe because the DMA is no longer just about chat interoperability. In April and May 2026, the European Commission tied interoperability to concrete implementation milestones covering device transfer, notification access, and eSIM transfer, with some measures scheduled around June 1, 2026. For communications providers, switching friction is becoming a compliance, retention, and technical integration issue at the same time.

Published:05/29/2026 Updated:05/29/2026
Other A2P SMS regulations

Australia Tightens Cross-Border Sender ID Access

For teams sending OTPs, billing alerts, delivery notifications, and customer-service texts into Australia, the key issue is no longer just whether a sender ID is registered. From July 1, 2026, cross-border A2P delivery also depends on whether the offshore messaging chain is connected to an approved Australian participation model. ACMA’s recent guidance makes clear that international brands and message providers must work through certified or participating Australian providers, or branded traffic may be relabeled as 「Unverified」 and lose sender identity at the point of delivery.

Published:05/28/2026 Updated:05/28/2026
Other A2P SMS regulations

Australia SMS Sender ID Downgrade Nears

This matters for SMS operations, product, and compliance teams sending OTPs, billing alerts, delivery updates, and support messages into Australia because the consequence of non-compliance is now operationally concrete. From July 1, 2026, branded SMS sent with an unregistered sender ID will be overwritten as “Unverified” and grouped into a shared thread with other unregistered traffic. ACMA’s May 2026 reminder shows the regime has moved from policy design to implementation, with immediate implications for deliverability, brand recognition, and customer trust.

Published:05/27/2026 Updated:05/27/2026
Europe A2P SMS regulations

UK A2P Scam-Control Rules

This matters for SMS operations, compliance, and technical integration teams that send OTPs, billing alerts, delivery notices, or support messages into the UK. Ofcom is moving anti-scam controls from post-incident handling into the A2P messaging stack itself. In 2026, the regulator continued advancing its mobile messaging scam framework, proposing baseline obligations for mobile operators and business messaging aggregators across KYC, sender ID validation, ongoing traffic monitoring, incident handling, and data protection. Ofcom says it plans to publish a final decision in summer 2026, which could reshape onboarding and routing requirements for UK-bound business messaging.

Published:05/26/2026 Updated:05/26/2026

Need compliance guidance?

Contact us for enterprise communication compliance guidance and implementation paths for your target markets.

Get in Touch