Back to Blog
Legal Compliance

DPDP Act WhatsApp Marketing Compliance Guide India 2026: Stay Legal

July 15, 2026 14 min read

The Digital Personal Data Protection Act 2023 (DPDP Act) fundamentally changes how Indian businesses can collect and use phone numbers for WhatsApp marketing. Violations carry penalties up to ₹250 crore. This guide covers everything you need to stay compliant.

Critical: DPDP Act Enforcement Started

The DPDP Act became enforceable in phases starting May 2027. Businesses sending WhatsApp marketing messages must comply immediately. Non-compliance exposes you to penalties and consumer complaints to the Data Protection Board.

What is the DPDP Act?

The Digital Personal Data Protection Act 2023 is India's first comprehensive data privacy law. It gives citizens control over their personal data (including phone numbers) and sets strict rules for how businesses can collect, store, and use that data.

For WhatsApp marketing, the most important sections are:

  • Section 6: Explicit consent required for processing personal data
  • Section 7: Businesses must allow users to withdraw consent easily
  • Section 8: Data must be stored in India (data localization)
  • Section 33: Penalties up to ₹250 crore for violations

DPDP Is Not the Only Law: IT Rules 2021 & WhatsApp Terms

Three separate frameworks govern WhatsApp marketing in India — and each has its own enforcement channel:

1. DPDP Act 2023 (Data Protection Board)

Governs consent, purpose limitation, data retention, and security. Requires data breach notification to the Data Protection Board within 72 hours. Penalties up to ₹250 crore per violation.

2. IT Act 2000 & IT Rules 2021 (MeitY / TRAI)

Prohibits unsolicited commercial communication. Sender identity must be clearly disclosed, every message needs an opt-out, and repeat violations can lead to telecom operator blacklisting under TRAI's DND framework and fines up to ₹25 lakh.

3. WhatsApp Business & Commerce Policies (Meta)

Even if you satisfy Indian law, WhatsApp bans numbers for spam. No scraping, no purchased lists, no modified apps (GB WhatsApp), no excessive sending speed. High block/report rates trigger automatic restrictions — a permanently banned number cannot be recovered, and you lose all chat history.

Transactional vs Marketing Messages: When Consent Is Required

Message TypeConsent Required?Examples
TransactionalNo separate consentOrder confirmations, shipping updates, payment receipts, OTP codes
InformationalRecommendedAccount updates, policy changes, service announcements
MarketingYes, mandatoryPromotional offers, abandoned cart, product launches, discount codes

Watch the purpose-limitation trap: a COD confirmation is transactional — but appending a promotional offer to that same message turns it into marketing and requires separate consent. Consent for "order updates" never covers promotions.

Consent Requirements for WhatsApp Marketing

Under DPDP Act Section 6, consent for WhatsApp marketing must be:

1. Explicit (Not Implied)

User must take a clear action to opt-in. Pre-checked boxes, assumed consent, or "by using our service" clauses are not valid.

✓ Valid Consent

Unchecked checkbox: "I agree to receive WhatsApp marketing"

✗ Invalid Consent

Pre-checked checkbox or "By proceeding, you agree..."

2. Freely Given (Not Coerced)

Consent cannot be a condition for providing a service. Users must be able to say no without penalty.

✓ Valid

"Would you like updates?" with clear yes/no options

✗ Invalid

"Accept marketing to complete purchase"

3. Specific (Purpose-Bound)

Consent for transactional messages (order updates) does NOT extend to promotional messages. You need separate consent for marketing.

✓ Valid

Two separate checkboxes: one for order updates, one for marketing

✗ Invalid

Single checkbox: "I agree to all communications"

4. Documented (Auditable Proof)

You must maintain timestamped records of when and how consent was obtained, including IP address and source page.

5 Valid Methods to Get Consent

1

Opt-In Checkbox at Checkout

Add an unchecked checkbox on your order form: "Send me WhatsApp updates on new products and offers"

Record: User ID, timestamp, IP address, checkbox state

2

Keyword Opt-In via WhatsApp

Ask customers to send "JOIN" or "SUBSCRIBE" to your WhatsApp number to receive marketing messages

Record: Phone number, opt-in keyword, timestamp

3

Double Opt-In Confirmation

After user provides phone number, send one-time confirmation message: "Reply YES to receive offers"

Record: Initial form submission + confirmation reply timestamp

4

QR Code Opt-In

Display QR code in-store or on packaging that opens WhatsApp chat with pre-filled "JOIN" message

Record: Scan source, phone number, send timestamp

5

Landing Page Form

Dedicated signup page where users enter phone number specifically to receive WhatsApp marketing

Record: Form submission timestamp, IP, referral source

What You CANNOT Do (Common Violations)

Buy Contact Lists

Purchased phone number lists have no verifiable consent chain. Illegal under DPDP Act Section 6.

Scrape WhatsApp Groups

Extracting phone numbers from WhatsApp groups without explicit marketing consent is illegal.

Use Transactional Consent for Marketing

Just because someone placed an order doesn't mean you can send them promotional messages.

Ignore Opt-Out Requests

Users who reply "STOP" or "UNSUBSCRIBE" must be removed immediately (within 24 hours).

Store Data Outside India

Phone numbers and consent records must be stored on servers physically located in India.

Legal vs Illegal: Common Scenarios

ScenarioLegal?Why
Order confirmation to a customer who just boughtYesTransactional — no separate consent needed
Offers to someone who ticked "I agree to receive WhatsApp offers"YesExplicit consent with clear purpose
Diwali greetings to your entire phone bookNoFestival greetings from a business are still unsolicited commercial messages
Messaging numbers bought from a lead-gen companyNoNo direct consent — violates DPDP Act, IT Rules, and WhatsApp policies
Adding everyone who ever called you to a broadcast listNoA phone call is not marketing consent — separate opt-in required

Sample Consent Language (Copy-Paste Ready)

"I agree to receive promotional offers, product updates, and marketing messages from [Your Business Name] on WhatsApp. I understand I can opt out anytime by replying STOP."

Use plain language, never legal jargon. Pair it with an unchecked checkbox and a link to your privacy policy.

Opt-Out Requirements

DPDP Act Section 7 requires that withdrawing consent must be "as easy as giving it". For WhatsApp marketing:

Required Opt-Out Methods

  • Include opt-out in every message: "Reply STOP to unsubscribe"
  • One-click unsubscribe: User should only need to reply "STOP" once
  • Process within 24 hours: Remove user from all marketing lists immediately
  • Send confirmation: "You've been unsubscribed. Reply JOIN to opt back in"
  • Log the request: Record opt-out timestamp for compliance audits

Record Keeping Requirements

You must maintain the following records for at least 3 years:

Record TypeRequired DataRetention
Consent ProofTimestamp, IP address, consent method, form version3+ years
Opt-Out RequestsUnsubscribe timestamp, method (STOP reply, form, etc)3+ years
Message LogsMessage sent timestamp, recipient, template ID, delivery status1 year
Privacy PolicyUser acceptance records, policy version, timestamp3+ years

Retention also has an expiry side: delete data of contacts inactive for 2-3 years (or the shorter period stated in your privacy policy), delete a contact's data within 30 days of a deletion request, and on opt-out keep only the opt-out record itself — so the number is never accidentally re-added.

Do You Need a Data Protection Officer?

A formal DPO is mandatory only for Significant Data Fiduciaries — businesses processing personal data of roughly 50,000+ individuals or handling sensitive (financial, health, biometric) data. SDFs must also run a Data Protection Impact Assessment before large-scale campaigns. Most SMBs fall below that threshold, but every business still must:

  • Appoint a grievance contact (can be the owner) and publish the contact details in your privacy policy and WhatsApp Business profile — data-related requests must get a response within 30 days
  • Keep a consent register — even a spreadsheet with name, number, consent date, consent text, and withdrawal date satisfies the documentation burden
  • Have a breach response plan — the DPDP Act requires notifying the Data Protection Board within 72 hours of a breach
  • Audit your tools: your WhatsApp marketing tool is your data processor, but you remain liable. Verify where data is stored (Indian servers preferred), whether a data processing agreement exists, and whether it can delete customer data on request
  • Train your team: one employee uploading your customer list to an unapproved tool is a reportable data breach

Industry-Specific Compliance Notes

Healthcare & Clinics

Patient data is sensitive personal data — higher protection standards apply. Get explicit consent even for appointment reminders, never share patient data with third parties, and follow medical advertising guidelines (no unverified claims).

Financial Services & Insurance

Financial data needs enhanced security and consent. Follow IRDAI rules for insurance marketing, include SEBI/RBI risk disclaimers where required, and never send misleading loan or investment offers.

Real Estate

Include your RERA registration number in property marketing messages and avoid false claims about timelines or amenities — RERA advertising rules apply to WhatsApp broadcasts too.

Penalties for Violations

DPDP Act Section 33: Financial Penalties

  • ₹50 crore: Processing data without consent
  • ₹200 crore: Data breach due to failure to implement reasonable security safeguards
  • ₹250 crore: Failure to prevent children's data violations
  • ₹10,000/day: Non-compliance with Data Protection Board notices

Plus reputation damage, customer complaints, and enforcement costs.

The Act structures these as two tiers: Schedule 1 penalties (up to ₹50 crore) cover failures like missing security safeguards, not notifying breaches, and ignoring data principal requests. Schedule 2 penalties (up to ₹250 crore per instance) cover consent and retention violations. Because penalties are per instance, a broadcast to a purchased list of 5,000 numbers is 5,000 separate violations — and three enforcement channels (Data Protection Board, TRAI DND blacklisting, WhatsApp bans) can act simultaneously.

Real Enforcement Actions in India

  • Edu-tech company fined ₹12 lakh (2024): sent unsolicited WhatsApp messages to numbers scraped from job portals — penalised under IT Rules for commercial messaging without consent.
  • NBFC number permanently banned (2025): pushed loan offers via unofficial bulk tools. WhatsApp banned the business number after repeated reports — 15,000+ customer chat histories lost.
  • Real estate portal breach case (ongoing): customer WhatsApp numbers leaked from a listing platform; Data Protection Board investigating with potential penalty up to ₹250 crore.

DPDP Compliance Checklist

Consent is explicit, freely given, and documented

Checkbox opt-in, keyword opt-in, or double opt-in with timestamp

Separate consent for marketing vs transactional messages

Two checkboxes or two separate opt-in flows

Privacy policy published and accessible

On website, linked from opt-in forms, plain language

One-click opt-out in every marketing message

"Reply STOP to unsubscribe" at end of messages

Opt-out requests processed within 24 hours

Automated removal from marketing lists

Data stored on servers in India

Use Indian cloud providers or India data centers

Consent and opt-out records maintained for 3+ years

Auditable logs with timestamps, IP addresses, sources

No purchased contact lists used

All contacts have verifiable first-party consent

How WhatSender Helps with Compliance

WhatSender includes built-in DPDP compliance features:

  • Automatic consent tracking: Records when and how each contact opted in
  • Built-in opt-out handling: Auto-removes users who reply "STOP"
  • India data storage: All data hosted on Indian servers (AWS Mumbai)
  • Audit logs: Complete message history with timestamps for 3+ years
  • Privacy policy templates: Customizable templates for WhatsApp marketing

Send WhatsApp Marketing the Compliant Way

WhatSender handles DPDP compliance automatically with consent tracking, opt-out management, and India data storage. Start free.

Get Started Free

Related Articles