DPDP Act WhatsApp Marketing Compliance Guide India 2026: Stay Legal
The Digital Personal Data Protection Act 2023 (DPDP Act) fundamentally changes how Indian businesses can collect and use phone numbers for WhatsApp marketing. Violations carry penalties up to ₹250 crore. This guide covers everything you need to stay compliant.
Critical: DPDP Act Enforcement Started
The DPDP Act became enforceable in phases starting May 2027. Businesses sending WhatsApp marketing messages must comply immediately. Non-compliance exposes you to penalties and consumer complaints to the Data Protection Board.
What is the DPDP Act?
The Digital Personal Data Protection Act 2023 is India's first comprehensive data privacy law. It gives citizens control over their personal data (including phone numbers) and sets strict rules for how businesses can collect, store, and use that data.
For WhatsApp marketing, the most important sections are:
- →Section 6: Explicit consent required for processing personal data
- →Section 7: Businesses must allow users to withdraw consent easily
- →Section 8: Data must be stored in India (data localization)
- →Section 33: Penalties up to ₹250 crore for violations
DPDP Is Not the Only Law: IT Rules 2021 & WhatsApp Terms
Three separate frameworks govern WhatsApp marketing in India — and each has its own enforcement channel:
1. DPDP Act 2023 (Data Protection Board)
Governs consent, purpose limitation, data retention, and security. Requires data breach notification to the Data Protection Board within 72 hours. Penalties up to ₹250 crore per violation.
2. IT Act 2000 & IT Rules 2021 (MeitY / TRAI)
Prohibits unsolicited commercial communication. Sender identity must be clearly disclosed, every message needs an opt-out, and repeat violations can lead to telecom operator blacklisting under TRAI's DND framework and fines up to ₹25 lakh.
3. WhatsApp Business & Commerce Policies (Meta)
Even if you satisfy Indian law, WhatsApp bans numbers for spam. No scraping, no purchased lists, no modified apps (GB WhatsApp), no excessive sending speed. High block/report rates trigger automatic restrictions — a permanently banned number cannot be recovered, and you lose all chat history.
Transactional vs Marketing Messages: When Consent Is Required
| Message Type | Consent Required? | Examples |
|---|---|---|
| Transactional | No separate consent | Order confirmations, shipping updates, payment receipts, OTP codes |
| Informational | Recommended | Account updates, policy changes, service announcements |
| Marketing | Yes, mandatory | Promotional offers, abandoned cart, product launches, discount codes |
Watch the purpose-limitation trap: a COD confirmation is transactional — but appending a promotional offer to that same message turns it into marketing and requires separate consent. Consent for "order updates" never covers promotions.
Consent Requirements for WhatsApp Marketing
Under DPDP Act Section 6, consent for WhatsApp marketing must be:
1. Explicit (Not Implied)
User must take a clear action to opt-in. Pre-checked boxes, assumed consent, or "by using our service" clauses are not valid.
✓ Valid Consent
Unchecked checkbox: "I agree to receive WhatsApp marketing"
✗ Invalid Consent
Pre-checked checkbox or "By proceeding, you agree..."
2. Freely Given (Not Coerced)
Consent cannot be a condition for providing a service. Users must be able to say no without penalty.
✓ Valid
"Would you like updates?" with clear yes/no options
✗ Invalid
"Accept marketing to complete purchase"
3. Specific (Purpose-Bound)
Consent for transactional messages (order updates) does NOT extend to promotional messages. You need separate consent for marketing.
✓ Valid
Two separate checkboxes: one for order updates, one for marketing
✗ Invalid
Single checkbox: "I agree to all communications"
4. Documented (Auditable Proof)
You must maintain timestamped records of when and how consent was obtained, including IP address and source page.
5 Valid Methods to Get Consent
Opt-In Checkbox at Checkout
Add an unchecked checkbox on your order form: "Send me WhatsApp updates on new products and offers"
Record: User ID, timestamp, IP address, checkbox state
Keyword Opt-In via WhatsApp
Ask customers to send "JOIN" or "SUBSCRIBE" to your WhatsApp number to receive marketing messages
Record: Phone number, opt-in keyword, timestamp
Double Opt-In Confirmation
After user provides phone number, send one-time confirmation message: "Reply YES to receive offers"
Record: Initial form submission + confirmation reply timestamp
QR Code Opt-In
Display QR code in-store or on packaging that opens WhatsApp chat with pre-filled "JOIN" message
Record: Scan source, phone number, send timestamp
Landing Page Form
Dedicated signup page where users enter phone number specifically to receive WhatsApp marketing
Record: Form submission timestamp, IP, referral source
What You CANNOT Do (Common Violations)
Buy Contact Lists
Purchased phone number lists have no verifiable consent chain. Illegal under DPDP Act Section 6.
Scrape WhatsApp Groups
Extracting phone numbers from WhatsApp groups without explicit marketing consent is illegal.
Use Transactional Consent for Marketing
Just because someone placed an order doesn't mean you can send them promotional messages.
Ignore Opt-Out Requests
Users who reply "STOP" or "UNSUBSCRIBE" must be removed immediately (within 24 hours).
Store Data Outside India
Phone numbers and consent records must be stored on servers physically located in India.
Legal vs Illegal: Common Scenarios
| Scenario | Legal? | Why |
|---|---|---|
| Order confirmation to a customer who just bought | Yes | Transactional — no separate consent needed |
| Offers to someone who ticked "I agree to receive WhatsApp offers" | Yes | Explicit consent with clear purpose |
| Diwali greetings to your entire phone book | No | Festival greetings from a business are still unsolicited commercial messages |
| Messaging numbers bought from a lead-gen company | No | No direct consent — violates DPDP Act, IT Rules, and WhatsApp policies |
| Adding everyone who ever called you to a broadcast list | No | A phone call is not marketing consent — separate opt-in required |
Sample Consent Language (Copy-Paste Ready)
"I agree to receive promotional offers, product updates, and marketing messages from [Your Business Name] on WhatsApp. I understand I can opt out anytime by replying STOP."
Use plain language, never legal jargon. Pair it with an unchecked checkbox and a link to your privacy policy.
Opt-Out Requirements
DPDP Act Section 7 requires that withdrawing consent must be "as easy as giving it". For WhatsApp marketing:
Required Opt-Out Methods
- Include opt-out in every message: "Reply STOP to unsubscribe"
- One-click unsubscribe: User should only need to reply "STOP" once
- Process within 24 hours: Remove user from all marketing lists immediately
- Send confirmation: "You've been unsubscribed. Reply JOIN to opt back in"
- Log the request: Record opt-out timestamp for compliance audits
Record Keeping Requirements
You must maintain the following records for at least 3 years:
| Record Type | Required Data | Retention |
|---|---|---|
| Consent Proof | Timestamp, IP address, consent method, form version | 3+ years |
| Opt-Out Requests | Unsubscribe timestamp, method (STOP reply, form, etc) | 3+ years |
| Message Logs | Message sent timestamp, recipient, template ID, delivery status | 1 year |
| Privacy Policy | User acceptance records, policy version, timestamp | 3+ years |
Retention also has an expiry side: delete data of contacts inactive for 2-3 years (or the shorter period stated in your privacy policy), delete a contact's data within 30 days of a deletion request, and on opt-out keep only the opt-out record itself — so the number is never accidentally re-added.
Do You Need a Data Protection Officer?
A formal DPO is mandatory only for Significant Data Fiduciaries — businesses processing personal data of roughly 50,000+ individuals or handling sensitive (financial, health, biometric) data. SDFs must also run a Data Protection Impact Assessment before large-scale campaigns. Most SMBs fall below that threshold, but every business still must:
- Appoint a grievance contact (can be the owner) and publish the contact details in your privacy policy and WhatsApp Business profile — data-related requests must get a response within 30 days
- Keep a consent register — even a spreadsheet with name, number, consent date, consent text, and withdrawal date satisfies the documentation burden
- Have a breach response plan — the DPDP Act requires notifying the Data Protection Board within 72 hours of a breach
- Audit your tools: your WhatsApp marketing tool is your data processor, but you remain liable. Verify where data is stored (Indian servers preferred), whether a data processing agreement exists, and whether it can delete customer data on request
- Train your team: one employee uploading your customer list to an unapproved tool is a reportable data breach
Industry-Specific Compliance Notes
Healthcare & Clinics
Patient data is sensitive personal data — higher protection standards apply. Get explicit consent even for appointment reminders, never share patient data with third parties, and follow medical advertising guidelines (no unverified claims).
Financial Services & Insurance
Financial data needs enhanced security and consent. Follow IRDAI rules for insurance marketing, include SEBI/RBI risk disclaimers where required, and never send misleading loan or investment offers.
Real Estate
Include your RERA registration number in property marketing messages and avoid false claims about timelines or amenities — RERA advertising rules apply to WhatsApp broadcasts too.
Penalties for Violations
DPDP Act Section 33: Financial Penalties
- ₹50 crore: Processing data without consent
- ₹200 crore: Data breach due to failure to implement reasonable security safeguards
- ₹250 crore: Failure to prevent children's data violations
- ₹10,000/day: Non-compliance with Data Protection Board notices
Plus reputation damage, customer complaints, and enforcement costs.
The Act structures these as two tiers: Schedule 1 penalties (up to ₹50 crore) cover failures like missing security safeguards, not notifying breaches, and ignoring data principal requests. Schedule 2 penalties (up to ₹250 crore per instance) cover consent and retention violations. Because penalties are per instance, a broadcast to a purchased list of 5,000 numbers is 5,000 separate violations — and three enforcement channels (Data Protection Board, TRAI DND blacklisting, WhatsApp bans) can act simultaneously.
Real Enforcement Actions in India
- Edu-tech company fined ₹12 lakh (2024): sent unsolicited WhatsApp messages to numbers scraped from job portals — penalised under IT Rules for commercial messaging without consent.
- NBFC number permanently banned (2025): pushed loan offers via unofficial bulk tools. WhatsApp banned the business number after repeated reports — 15,000+ customer chat histories lost.
- Real estate portal breach case (ongoing): customer WhatsApp numbers leaked from a listing platform; Data Protection Board investigating with potential penalty up to ₹250 crore.
DPDP Compliance Checklist
Consent is explicit, freely given, and documented
Checkbox opt-in, keyword opt-in, or double opt-in with timestamp
Separate consent for marketing vs transactional messages
Two checkboxes or two separate opt-in flows
Privacy policy published and accessible
On website, linked from opt-in forms, plain language
One-click opt-out in every marketing message
"Reply STOP to unsubscribe" at end of messages
Opt-out requests processed within 24 hours
Automated removal from marketing lists
Data stored on servers in India
Use Indian cloud providers or India data centers
Consent and opt-out records maintained for 3+ years
Auditable logs with timestamps, IP addresses, sources
No purchased contact lists used
All contacts have verifiable first-party consent
How WhatSender Helps with Compliance
WhatSender includes built-in DPDP compliance features:
- Automatic consent tracking: Records when and how each contact opted in
- Built-in opt-out handling: Auto-removes users who reply "STOP"
- India data storage: All data hosted on Indian servers (AWS Mumbai)
- Audit logs: Complete message history with timestamps for 3+ years
- Privacy policy templates: Customizable templates for WhatsApp marketing
Send WhatsApp Marketing the Compliant Way
WhatSender handles DPDP compliance automatically with consent tracking, opt-out management, and India data storage. Start free.
Get Started Free