Over 500 million Indians use WhatsApp. And nearly every Indian business — from a neighbourhood kirana to a Series B startup — uses WhatsApp Business to send order confirmations, payment reminders, promotional offers, support messages, and appointment alerts. What almost none of them know is that every single one of those messages is regulated under the Digital Personal Data Protection Act, 2023. This guide explains exactly what the law requires, what you are doing wrong right now, and how to fix it before the May 2027 enforcement deadline.
Sending marketing messages on WhatsApp Business without DPDPA-compliant consent is one of the highest-risk activities an Indian business can engage in right now. It combines three separate violations — no valid consent, no proper notice, and processing for an undisclosed purpose — each carrying penalties up to ₹50 crore. If your business sends bulk WhatsApp messages, read this guide in full.
- Why WhatsApp Business is a DPDPA compliance issue
- The three types of WhatsApp Business use — and their risk levels
- The 6 DPDPA obligations triggered by WhatsApp Business use
- Consent — the core problem with almost every Indian business
- WhatsApp's own policies and how they interact with DPDPA
- The Consent Manager and what it means for WhatsApp businesses
- Opt-out and withdrawal — what you are legally required to provide
- Breach risk — why WhatsApp is a data security exposure
- The most common violations Indian businesses make right now
- A practical 5-step WhatsApp compliance fix
1. Why WhatsApp Business Is a DPDPA Compliance Issue
WhatsApp Business is not just a messaging app. From a data protection perspective, it is a data processing tool. The moment you save a customer's phone number and send them a message, you have:
All three of these actions are regulated under the DPDP Act. They require a lawful basis, proper notice, and in most cases — explicit, prior, informed consent from the individual.
The bottom line: If you use WhatsApp Business to contact customers — for any reason — you are a Data Fiduciary under the DPDP Act and you have legal obligations that most Indian businesses are currently not meeting. The enforcement deadline is May 2027. The penalties start at ₹50 crore per violation.
2. The Three Types of WhatsApp Business Use — and Their Risk Levels
Not all WhatsApp Business use carries the same legal risk. Understanding which category your business falls into determines which obligations apply most urgently.
3. The 6 DPDPA Obligations Triggered by WhatsApp Business Use
Using WhatsApp Business with customer data activates the following obligations under the DPDP Act and Rules:
| # | Obligation | What It Means for WhatsApp Use | Legal Ref |
|---|---|---|---|
| 1 | Lawful Basis | Every message type must have a documented lawful basis — consent or legitimate use. "They gave us their number" is not a lawful basis. | S.4, S.6, S.7 |
| 2 | Privacy Notice | Before or at the time of collecting a phone number, the individual must be informed of the purpose, processor (WhatsApp/Meta), and their rights. | S.5 |
| 3 | Consent for Marketing | Marketing messages require explicit, specific consent for that purpose — separate from service consent. Opt-in must be an affirmative act. | S.6 |
| 4 | Opt-Out / Withdrawal | Every message must include a simple, friction-free way to stop receiving messages. Withdrawal must be honoured promptly — and permanently. | S.6(4) |
| 5 | Data Processor Agreement | WhatsApp (Meta) is your Data Processor. You must review Meta's Data Processing Terms and ensure they meet DPDPA Section 9 requirements. | S.9 |
| 6 | Data Retention & Deletion | Phone numbers saved in WhatsApp Business must be deleted when the purpose ends or the individual withdraws consent. "I'll delete them later" is not a policy. | S.8(7) |
4. Consent — The Core Problem With Almost Every Indian Business
Here is the most common scenario playing out across Indian businesses right now:
"A customer places an order on our website or walks into our store. We take their phone number for the order. We save it in WhatsApp Business. We add them to our broadcast list. We send them a Holi offer, a monsoon sale, a new product launch. They never asked for any of this."
This is not just common practice. Under DPDPA, this is multiple simultaneous violations.
The DPDP Act requires that consent for marketing be:
Practical example of valid WhatsApp marketing consent: At checkout (online or in-store), your customer sees a clearly worded checkbox: "I would like to receive offers, promotions, and updates from [Business Name] via WhatsApp. I understand I can unsubscribe at any time by replying STOP." The box is unticked by default. The customer actively ticks it. You record this with a timestamp. That is valid consent. Everything else is not.
5. WhatsApp's Own Policies and How They Interact With DPDPA
Many businesses assume that because WhatsApp Business allows them to send messages, they are legally covered. This is incorrect. WhatsApp's permissions and India's DPDPA are entirely separate legal frameworks.
| Issue | WhatsApp Policy | DPDPA Requirement |
|---|---|---|
| Opt-in for messages | WhatsApp requires businesses to get opt-in before sending template messages. But enforcement is inconsistent and largely self-reported. | Legally mandatory. Absence of valid consent is a direct DPDPA violation regardless of WhatsApp's enforcement. |
| Data shared with Meta | WhatsApp's terms allow Meta to use business messaging metadata for safety, spam prevention, and product improvement. | You must disclose in your privacy notice that a third party (Meta) processes message metadata. Your customers must be informed. |
| Data storage location | WhatsApp/Meta stores data on servers globally, including outside India. | Cross-border transfers may be restricted once the Board notifies restricted countries under Section 16. Monitor this actively. |
| WhatsApp API (Business Platform) | Businesses using the WhatsApp Business API (via BSPs) have more formal template and opt-in requirements. | API users are Data Fiduciaries processing at scale. They face higher scrutiny and may be designated Significant Data Fiduciaries (SDFs). |
| Broadcast lists | WhatsApp allows broadcast lists for accounts that have your number saved. No formal opt-in mechanism is enforced by WhatsApp. | Having someone's number saved does not equal consent. Broadcast lists for marketing are illegal without documented prior consent under DPDPA. |
Key takeaway: WhatsApp allowing you to do something does not mean DPDPA allows it. The two operate independently. Your compliance obligation is to Indian law — not to WhatsApp's terms of service.
6. The Consent Manager and What It Means for WhatsApp Businesses
The DPDP Rules 2025 introduce a Consent Manager — a Board-registered entity that individuals can use to manage their consent across multiple Data Fiduciaries from a single interface. Registration for Consent Managers opens in November 2026.
What this means for WhatsApp Business users:
7. Opt-Out and Withdrawal — What You Are Legally Required to Provide
Section 6(4) of the DPDP Act is unambiguous: withdrawing consent must be as easy as giving it. For WhatsApp Business, this creates specific practical requirements.
8. Breach Risk — Why WhatsApp Is a Data Security Exposure
WhatsApp Business on a mobile device creates data security risks that most businesses have not considered. Your customer contact list is personal data — and its compromise is a notifiable data breach under DPDPA.
9. The Most Common DPDPA Violations on WhatsApp — Right Now
Based on standard Indian business practice, these are the violations happening at scale across the country today. Check how many apply to your business:
| # | Violation | Estimated Prevalence | Max Penalty |
|---|---|---|---|
| 1 | Sending marketing messages without prior explicit consent for WhatsApp communication | ~90% of SMEs | ₹50 Cr |
| 2 | No privacy notice given at the time of collecting the customer's phone number | ~85% of SMEs | ₹50 Cr |
| 3 | No easy opt-out mechanism — customers have no clear way to stop receiving WhatsApp messages | ~80% of SMEs | ₹50 Cr |
| 4 | No Data Processing Agreement with WhatsApp Business Solution Provider (BSP) used for campaigns | ~95% of API users | ₹50 Cr |
| 5 | No retention policy — phone numbers kept indefinitely with no deletion process for inactive contacts | ~75% of SMEs | ₹50 Cr |
| 6 | Sending promotional messages to purchased or rented contact lists — people who never gave their number to your business | ~30% of SMEs | ₹50–250 Cr |
Note on purchased lists: Using a purchased or rented contact list for WhatsApp marketing is among the most severe violations possible under DPDPA. These contacts never gave your business their data, let alone consent. This exposes you not just to the maximum penalty scale but also to criminal liability for facilitating the unlawful use of another party's data.
10. A Practical 5-Step WhatsApp Compliance Fix
The good news: WhatsApp Business compliance is achievable for every Indian business — without replacing your existing setup. Here is the practical action plan, in priority order:
notice, purpose failures
notification obligations
for all DPDPA obligations
compliance — start today
Make Your WhatsApp Business DPDPA-Compliant — Before Your Competitors Do
The five steps above are straightforward — but doing them correctly requires legally sound consent notices, a properly structured privacy policy that names WhatsApp as a processor, a BSP agreement that meets Section 9 standards, and a consent record-keeping system that will hold up under Board scrutiny.
Our team has worked with over 300 Indian businesses on DPDPA compliance. We offer a WhatsApp Business Compliance Package that covers every legal document you need — consent notices, privacy policy update, BSP DPA template, opt-out process documentation, and a breach response plan — all customised to your specific business and delivered in 10 working days.