Share 💬 💼
DPDP

WhatsApp Business & DPDPA Compliance — What Every Indian Business Must Know

📅 Mar 05, 2026
👤 Adv. Deepak Kumar
⏱️ 14 min read
📂 DPDP
WhatsApp Business & DPDPA Compliance — What Every Indian Business Must Know
Every Indian business using WhatsApp to message customers is now regulated under the DPDP Act 2023 — and most are already in violation. This guide covers the 6 obligations triggered by WhatsApp Business use, the 3 risk tiers of messaging, consent requirements, opt-out obligations, breach risks, and a practical 5-step fix.
DPDP Act 2023 + DPDP Rules 2025 — WhatsApp Business Compliance Guide

Over 500 million Indians use WhatsApp. And nearly every Indian business — from a neighbourhood kirana to a Series B startup — uses WhatsApp Business to send order confirmations, payment reminders, promotional offers, support messages, and appointment alerts. What almost none of them know is that every single one of those messages is regulated under the Digital Personal Data Protection Act, 2023. This guide explains exactly what the law requires, what you are doing wrong right now, and how to fix it before the May 2027 enforcement deadline.

⚠️ High-Risk Activity Alert

Sending marketing messages on WhatsApp Business without DPDPA-compliant consent is one of the highest-risk activities an Indian business can engage in right now. It combines three separate violations — no valid consent, no proper notice, and processing for an undisclosed purpose — each carrying penalties up to ₹50 crore. If your business sends bulk WhatsApp messages, read this guide in full.

Nov 2025
Rules notified — Board active
Nov 2026
Consent Manager registration opens
May 2027
All obligations enforceable — DEADLINE
📋 What This Guide Covers
  1. Why WhatsApp Business is a DPDPA compliance issue
  2. The three types of WhatsApp Business use — and their risk levels
  3. The 6 DPDPA obligations triggered by WhatsApp Business use
  4. Consent — the core problem with almost every Indian business
  5. WhatsApp's own policies and how they interact with DPDPA
  6. The Consent Manager and what it means for WhatsApp businesses
  7. Opt-out and withdrawal — what you are legally required to provide
  8. Breach risk — why WhatsApp is a data security exposure
  9. The most common violations Indian businesses make right now
  10. A practical 5-step WhatsApp compliance fix

1. Why WhatsApp Business Is a DPDPA Compliance Issue

WhatsApp Business is not just a messaging app. From a data protection perspective, it is a data processing tool. The moment you save a customer's phone number and send them a message, you have:

Collected personal data — a phone number is personal data under Section 2(t) of the DPDPA. It directly identifies an individual.
Processed it for a purpose — whether for marketing, transactional alerts, support, or updates, you are processing that data with intent.
Shared it with a Data Processor — WhatsApp (Meta Platforms) is a third party processing data on your behalf, making them your Data Processor under DPDPA.

All three of these actions are regulated under the DPDP Act. They require a lawful basis, proper notice, and in most cases — explicit, prior, informed consent from the individual.

The bottom line: If you use WhatsApp Business to contact customers — for any reason — you are a Data Fiduciary under the DPDP Act and you have legal obligations that most Indian businesses are currently not meeting. The enforcement deadline is May 2027. The penalties start at ₹50 crore per violation.

2. The Three Types of WhatsApp Business Use — and Their Risk Levels

Not all WhatsApp Business use carries the same legal risk. Understanding which category your business falls into determines which obligations apply most urgently.

📦
Type 1 — Transactional Messaging
Order confirmations • Delivery updates • Payment receipts • Appointment reminders
LOWER RISK
DPDPA position: Transactional messages may qualify as "legitimate use" under Section 7 — processing necessary to perform a contract or fulfil an order. However, you still need a privacy notice, a retention policy, and a mechanism for users to query or delete their data. Consent is not required if the processing is genuinely necessary for the service the customer asked for — but you must document why.
🔔
Type 2 — Service & Support Messaging
Complaint responses • Status updates • Policy changes • Account alerts
MEDIUM RISK
DPDPA position: Support and service messages can also fall under legitimate use if the customer initiated a service relationship. However, if you are proactively sending updates the customer did not request, or using the support channel to cross-sell, the lawful basis shifts. You need consent for any messaging that goes beyond what the customer originally agreed to when they shared their number.
📢
Type 3 — Marketing & Promotional Messaging
Offers • Discounts • New product launches • Festive campaigns • Bulk broadcasts
HIGHEST RISK
DPDPA position: Marketing messages have no legitimate use exemption. They require valid, specific, informed, prior consent — every time, for every purpose. Sending a Diwali discount blast to your entire contact list without explicit consent for marketing communications is a direct violation of Section 6 of the DPDP Act. This is the most common violation Indian businesses currently commit on WhatsApp.

3. The 6 DPDPA Obligations Triggered by WhatsApp Business Use

Using WhatsApp Business with customer data activates the following obligations under the DPDP Act and Rules:

# Obligation What It Means for WhatsApp Use Legal Ref
1 Lawful Basis Every message type must have a documented lawful basis — consent or legitimate use. "They gave us their number" is not a lawful basis. S.4, S.6, S.7
2 Privacy Notice Before or at the time of collecting a phone number, the individual must be informed of the purpose, processor (WhatsApp/Meta), and their rights. S.5
3 Consent for Marketing Marketing messages require explicit, specific consent for that purpose — separate from service consent. Opt-in must be an affirmative act. S.6
4 Opt-Out / Withdrawal Every message must include a simple, friction-free way to stop receiving messages. Withdrawal must be honoured promptly — and permanently. S.6(4)
5 Data Processor Agreement WhatsApp (Meta) is your Data Processor. You must review Meta's Data Processing Terms and ensure they meet DPDPA Section 9 requirements. S.9
6 Data Retention & Deletion Phone numbers saved in WhatsApp Business must be deleted when the purpose ends or the individual withdraws consent. "I'll delete them later" is not a policy. S.8(7)

4. Consent — The Core Problem With Almost Every Indian Business

Here is the most common scenario playing out across Indian businesses right now:

"A customer places an order on our website or walks into our store. We take their phone number for the order. We save it in WhatsApp Business. We add them to our broadcast list. We send them a Holi offer, a monsoon sale, a new product launch. They never asked for any of this."

This is not just common practice. Under DPDPA, this is multiple simultaneous violations.

The DPDP Act requires that consent for marketing be:

Free
Not bundled with a service or product purchase
🎯
Specific
For WhatsApp marketing — not "communications generally"
💡
Informed
Person knows what they're opting into before they agree
👆
Affirmative
An active opt-in — not silence, not a pre-ticked box
🔄
Withdrawable
As easy to withdraw as it was to give — instantly and without friction

Practical example of valid WhatsApp marketing consent: At checkout (online or in-store), your customer sees a clearly worded checkbox: "I would like to receive offers, promotions, and updates from [Business Name] via WhatsApp. I understand I can unsubscribe at any time by replying STOP." The box is unticked by default. The customer actively ticks it. You record this with a timestamp. That is valid consent. Everything else is not.

5. WhatsApp's Own Policies and How They Interact With DPDPA

Many businesses assume that because WhatsApp Business allows them to send messages, they are legally covered. This is incorrect. WhatsApp's permissions and India's DPDPA are entirely separate legal frameworks.

Issue WhatsApp Policy DPDPA Requirement
Opt-in for messages WhatsApp requires businesses to get opt-in before sending template messages. But enforcement is inconsistent and largely self-reported. Legally mandatory. Absence of valid consent is a direct DPDPA violation regardless of WhatsApp's enforcement.
Data shared with Meta WhatsApp's terms allow Meta to use business messaging metadata for safety, spam prevention, and product improvement. You must disclose in your privacy notice that a third party (Meta) processes message metadata. Your customers must be informed.
Data storage location WhatsApp/Meta stores data on servers globally, including outside India. Cross-border transfers may be restricted once the Board notifies restricted countries under Section 16. Monitor this actively.
WhatsApp API (Business Platform) Businesses using the WhatsApp Business API (via BSPs) have more formal template and opt-in requirements. API users are Data Fiduciaries processing at scale. They face higher scrutiny and may be designated Significant Data Fiduciaries (SDFs).
Broadcast lists WhatsApp allows broadcast lists for accounts that have your number saved. No formal opt-in mechanism is enforced by WhatsApp. Having someone's number saved does not equal consent. Broadcast lists for marketing are illegal without documented prior consent under DPDPA.

Key takeaway: WhatsApp allowing you to do something does not mean DPDPA allows it. The two operate independently. Your compliance obligation is to Indian law — not to WhatsApp's terms of service.

6. The Consent Manager and What It Means for WhatsApp Businesses

The DPDP Rules 2025 introduce a Consent Manager — a Board-registered entity that individuals can use to manage their consent across multiple Data Fiduciaries from a single interface. Registration for Consent Managers opens in November 2026.

What this means for WhatsApp Business users:

📱
Customers will be able to withdraw WhatsApp marketing consent through a Consent Manager
When an individual withdraws consent through the Consent Manager, you are legally obligated to stop messaging them within the prescribed period — even if they never directly told you to stop.
🔌
Your consent system must be able to receive and process withdrawal signals
This means your WhatsApp Business contact list management cannot be manual. You need a system that can receive a withdrawal signal and immediately suppress that contact from future marketing sends.
📋
Consent records must be structured and searchable
If a regulator or a Consent Manager sends a query about a specific individual's consent status, you must be able to produce a timestamped, verifiable record instantly. A spreadsheet of phone numbers is not a consent record.

7. Opt-Out and Withdrawal — What You Are Legally Required to Provide

Section 6(4) of the DPDP Act is unambiguous: withdrawing consent must be as easy as giving it. For WhatsApp Business, this creates specific practical requirements.

❌ What You Cannot Do (Current Common Practice)
  • Require customers to email you to opt-out of WhatsApp messages
  • Make them call a helpline to be removed from the broadcast list
  • Ignore or delay acting on "STOP" or "unsubscribe" replies
  • Tell them to "update their preferences on the website" without a direct link
  • Continue sending messages after a withdrawal request has been made
  • Re-add people who have opted out to new broadcast lists
✅ What You Must Provide
  • A STOP keyword or similar that immediately triggers opt-out when replied
  • Automatic removal from all broadcast lists and future sends
  • A permanent suppression list so opted-out contacts are never re-contacted for marketing
  • Acknowledgement of the opt-out sent to the customer within a reasonable time
  • A record of the withdrawal — timestamp, contact, method
  • Deletion of the contact's data if they also exercise their erasure right

8. Breach Risk — Why WhatsApp Is a Data Security Exposure

WhatsApp Business on a mobile device creates data security risks that most businesses have not considered. Your customer contact list is personal data — and its compromise is a notifiable data breach under DPDPA.

📵
Lost or stolen device
If your WhatsApp Business account is on an employee's phone and the phone is lost or stolen, every customer's number in that account is a compromised data breach. This must be reported to the Data Protection Board under Rule 6.
👤
Departing employee
When an employee with access to your WhatsApp Business account leaves the company, their access must be immediately revoked and the account must be transferred or deactivated. Failure to do this means a former employee continues to hold access to your customers' personal data.
💾
Chat backups
WhatsApp Business chat histories may be backed up to Google Drive or iCloud. These backups contain personal data. You must account for these in your data retention and deletion policy — they are not "off the books" simply because they are on a cloud service.
🔗
Third-party BSPs (WhatsApp Business API)
If you use a Business Solution Provider (BSP) to send WhatsApp campaigns, that BSP is your Data Processor. You need a Data Processing Agreement with them, and you are responsible if they suffer a breach involving your customers' data.

9. The Most Common DPDPA Violations on WhatsApp — Right Now

Based on standard Indian business practice, these are the violations happening at scale across the country today. Check how many apply to your business:

# Violation Estimated Prevalence Max Penalty
1 Sending marketing messages without prior explicit consent for WhatsApp communication ~90% of SMEs ₹50 Cr
2 No privacy notice given at the time of collecting the customer's phone number ~85% of SMEs ₹50 Cr
3 No easy opt-out mechanism — customers have no clear way to stop receiving WhatsApp messages ~80% of SMEs ₹50 Cr
4 No Data Processing Agreement with WhatsApp Business Solution Provider (BSP) used for campaigns ~95% of API users ₹50 Cr
5 No retention policy — phone numbers kept indefinitely with no deletion process for inactive contacts ~75% of SMEs ₹50 Cr
6 Sending promotional messages to purchased or rented contact lists — people who never gave their number to your business ~30% of SMEs ₹50–250 Cr

Note on purchased lists: Using a purchased or rented contact list for WhatsApp marketing is among the most severe violations possible under DPDPA. These contacts never gave your business their data, let alone consent. This exposes you not just to the maximum penalty scale but also to criminal liability for facilitating the unlawful use of another party's data.

10. A Practical 5-Step WhatsApp Compliance Fix

The good news: WhatsApp Business compliance is achievable for every Indian business — without replacing your existing setup. Here is the practical action plan, in priority order:

1
Audit your existing contact list
Go through every contact in your WhatsApp Business account. For each one: can you produce documented evidence that they specifically consented to receive WhatsApp marketing from you? If not — stop marketing to them immediately. You can still message them for genuine transactional purposes (their existing order, their ongoing service), but you cannot send promotions until you have valid consent.
2
Build a compliant opt-in process
Add a specific, unticked WhatsApp marketing opt-in checkbox to every customer touchpoint — your website checkout, your in-store order form, your service inquiry form. The language must clearly state that they are opting in to WhatsApp messages from your business, what kind of messages they will receive, and how to stop them. Record the consent with a timestamp and the version of the notice shown.
3
Add STOP instructions to every marketing message
Every promotional or marketing message sent via WhatsApp must include an opt-out instruction — for example, "Reply STOP to unsubscribe." When someone replies STOP, they must be immediately removed from all broadcast lists and never contacted for marketing again. Build this process into your workflow before your next campaign goes out.
4
Update your privacy notice and policy
Your privacy notice must now explicitly state that you use WhatsApp Business to communicate with customers, that WhatsApp (Meta Platforms) is a Data Processor, the types of messages you send, and how customers can withdraw consent. If you use a BSP for WhatsApp API campaigns, that entity must also be listed as a sub-processor.
5
Put a Data Processing Agreement in place with your BSP
If you use any third-party service to send WhatsApp messages at scale — a CRM, a BSP, a marketing automation tool — you need a Data Processing Agreement (DPA) with that vendor. This document must specify the purpose of processing, security obligations, breach notification timelines, and deletion requirements. If your BSP does not have a DPDPA-ready DPA, contact us — we can draft one.
📋 WhatsApp Business DPDPA Quick Reference
₹50Cr
Per violation — consent,
notice, purpose failures
₹200Cr
For breach of data security
notification obligations
May 2027
Final enforcement deadline
for all DPDPA obligations
5 Steps
To WhatsApp Business
compliance — start today

Make Your WhatsApp Business DPDPA-Compliant — Before Your Competitors Do

The five steps above are straightforward — but doing them correctly requires legally sound consent notices, a properly structured privacy policy that names WhatsApp as a processor, a BSP agreement that meets Section 9 standards, and a consent record-keeping system that will hold up under Board scrutiny.

Our team has worked with over 300 Indian businesses on DPDPA compliance. We offer a WhatsApp Business Compliance Package that covers every legal document you need — consent notices, privacy policy update, BSP DPA template, opt-out process documentation, and a breach response plan — all customised to your specific business and delivered in 10 working days.

AD
Adv. Deepak Kumar
IP & Legal Expert · Vakil Help Desk
Our editorial team comprises experienced IP advocates, DPDPA compliance specialists, and legal professionals dedicated to making India's legal landscape accessible to every business. We cover trademark law, patent filing, copyright protection, and DPDP Act 2023 compliance.
Found this helpful? Share it →
💼 LinkedIn

Need Expert Help with DPDP?

Our team of advocates and compliance specialists are ready to help. Free consultation — response within 2 hours.

⚡ Get Free Consultation →
📋 Table of Contents
    Free Consultation
    Get expert advice on DPDP matters. We respond within 2 hours.
    Book Free Call → 💬 WhatsApp Us
    DPDPA Deadline
    Days to May 2027 enforcement
    Get Compliant Now →
    Get Free Consultation
    Call Now WhatsApp