WhatsApp Marketing and India's DPDP Act: A Practical Compliance Guide for Businesses
- 22 Aug, 2026
WhatsApp Marketing and India's DPDP Act: A Practical Compliance Guide for Businesses
Why this matters more than it did two years ago
For most of the last decade, Indian businesses collected phone numbers freely and messaged them freely. The Digital Personal Data Protection Act, 2023 changed the framework. Phone numbers are personal data, a WhatsApp marketing list is a database of personal data, and processing it now carries obligations around consent, notice, purpose and deletion that did not previously exist in enforceable form.
This is not a reason for alarm. Most of what compliance requires is what good WhatsApp practice already looked like, because Meta's own policies have demanded explicit opt-in for years. The businesses at risk are the ones buying contact lists, scraping numbers, and broadcasting to people who never asked. If that is not you, the work ahead is mostly documentation rather than transformation.
This article is general information for business owners, not legal advice. For obligations specific to your business, consult a qualified professional.
- A phone number is personal data, so your WhatsApp list is subject to the DPDP framework.
- Consent must be free, specific, informed and unambiguous, with a clear notice explaining the purpose.
- Purchased and scraped lists cannot be made compliant retrospectively; they should not be used.
- You must be able to act on withdrawal of consent, and to delete data when the purpose ends.
- Keep records of who consented, when, and to what, because the burden of proof sits with you.
The core ideas in plain language
You are the data fiduciary. If you decide why and how customer data gets processed, the obligations sit with you, not with your marketing agency or your CRM vendor. Delegating the work does not delegate the responsibility.
Consent must be real. Free, specific, informed, unambiguous, and given by a clear affirmative action. A pre-ticked box is not consent. Consent buried in a wall of terms is not specific. Consent to receive an order update is not consent to receive weekly promotional offers.
Notice comes with consent. At or before collection, tell the person what data you are collecting, what you will use it for, how they can withdraw consent, and how they can complain. Plain language, and available in English plus other languages listed in the Constitution's Eighth Schedule where relevant to your customers.
Purpose limitation. Use the data for the purpose you stated. A number given for a delivery update is not automatically available for a festival sale campaign.
Withdrawal must be as easy as giving. If someone opted in with one tap, they should be able to opt out with roughly the same effort, and it must take effect promptly.
Deletion when the purpose ends. Once the purpose is served or consent is withdrawn, the data should be erased unless another legal obligation requires you to keep it.
Breach notification. A personal data breach must be reported to the Data Protection Board and to affected individuals. Practically, this means you need to know what data you hold and where, before something goes wrong.
What this looks like for a WhatsApp list
Collecting opt-in correctly
Wherever you collect a number, add an explicit, unticked consent action with a short notice beside it. On a website form: a checkbox saying you would like to receive updates and offers on WhatsApp, with a line naming your business and linking your privacy policy. At checkout: the same, separated from the transactional necessity of the delivery number. In-store: a written or digital record rather than someone typing numbers from a register.
The strongest form of opt-in is the customer messaging you first, because it is unambiguous and self-documenting. Click-to-WhatsApp ads, a QR code at your counter, and a website button all produce this naturally. It is also the version Meta prefers, which makes it doubly worth building your list this way.
Separating transactional from promotional
An order confirmation, a delivery update, an appointment reminder and a payment receipt serve the purpose the customer engaged you for. A discount announcement is a different purpose. Collect the two consents separately, label your contacts accordingly, and keep promotional broadcasts to the promotional list. This one distinction resolves the majority of practical compliance questions in day-to-day operation.
Handling withdrawal
Every promotional message should carry a simple way to stop. When someone opts out, the contact must be marked immediately and excluded from future campaigns automatically, not manually at the next broadcast. Then keep the transactional relationship intact if it still applies, since someone who stops promotional messages has not necessarily cancelled their order updates.
Deleting on request
You need a way to find everything you hold about one person and remove it. In a WhatsApp CRM that means the contact, their labels, their chat history and their entry in any exported list. If you cannot do this within a reasonable time, that is a gap worth closing before someone asks.
The practices to stop immediately
Purchased databases. A list bought from a broker has no valid consent, cannot acquire one retrospectively, and exposes you to both regulatory risk and immediate blocks that damage your WhatsApp quality rating. There is no compliant way to use it.
Scraped numbers. Numbers harvested from directories, groups or public listings were never given to you for this purpose.
Consent by silence. "If you do not reply STOP, we will keep messaging you" is not consent under any reading.
Bundled consent. Forcing agreement to marketing as a condition of buying, when marketing is not necessary to provide what was bought.
Indefinite retention. Keeping a contact from a 2019 enquiry that went nowhere serves no stated purpose. Set a retention period and apply it.
Children's data
The framework places significant restrictions on processing children's data, including requirements around verifiable parental consent and prohibitions on behavioural advertising directed at children. If your business serves children, tuition centres, play schools, paediatric clinics, toy retailers, treat this as a specific area to get right, and collect the parent's number and the parent's consent rather than the child's.
A practical checklist
- Audit where every number in your list came from, and remove anything you cannot account for.
- Add explicit, unticked consent with a short notice at every collection point.
- Separate transactional and promotional consent, and label contacts accordingly.
- Publish a privacy policy in plain language covering what you collect, why, how long, and how to withdraw or complain.
- Name someone responsible for privacy questions and publish a contact route for them.
- Make opt-out one step, and make exclusion from future campaigns automatic.
- Set retention periods by data type and actually apply them.
- Keep consent records: who, when, through which form, and for what purpose.
- Check what your vendors do with the data, and put it in the contract.
- Have a plan for a breach: who is told, how quickly, and by whom.
Where the platform helps and where it does not
A WhatsApp CRM built on the official API gives you the mechanics: opt-in captured at source, consent status stored against each contact, automatic exclusion of opted-out contacts from broadcasts, labels that separate transactional from promotional audiences, an exportable record of consent, and controlled access so that customer data is not sitting on an employee's personal phone.
What it cannot do is make the decisions for you. Which purposes you state, how long you keep data, what your privacy policy says, and whether you resist the temptation to import a purchased list, these remain yours. ZupiChat provides the mechanics from Rs. 999 a month with a 14-day free trial, and the honest position is that the platform makes compliance practical rather than automatic.
The commercial argument, which is the stronger one
Set the law aside for a moment. A list built on genuine opt-in outperforms a purchased one by a wide margin on every metric that matters: delivery, read rate, response rate, and conversion. It also protects your WhatsApp quality rating, which determines how many people you can reach at all. Businesses that broadcast to unwilling recipients accumulate blocks and spam reports, watch their rating fall, and eventually find they cannot reach even their good customers reliably.
Compliance and effectiveness point in the same direction here, which is unusual and worth taking advantage of. Build the list properly, message people who want to hear from you, and the regulatory question mostly answers itself.
Frequently Asked Questions
Does India's DPDP Act apply to WhatsApp marketing?
Yes. A phone number is personal data, so a WhatsApp marketing list falls within the framework. If you decide why and how that data is processed, you carry the obligations around consent, notice, purpose limitation, withdrawal and deletion, regardless of whether an agency or a CRM vendor does the operational work on your behalf.
What counts as valid consent for WhatsApp marketing in India?
Consent must be free, specific, informed and unambiguous, given by a clear affirmative action, and accompanied by a notice explaining what you collect, why, and how to withdraw. Pre-ticked boxes, silence, and consent bundled into unrelated terms do not qualify. The customer messaging you first is the strongest and most self-documenting form.
Can I message a purchased contact list on WhatsApp?
No. A purchased or scraped list has no valid consent and cannot acquire it retrospectively. Beyond the regulatory exposure, it produces immediate blocks and spam reports that damage your WhatsApp quality rating, which reduces how many people you can reach in future, including customers who genuinely wanted to hear from you.
Do order updates and delivery notifications need separate consent from offers?
They serve different purposes, so treat them separately. A number given for delivery updates was not given for promotional campaigns. Collect the two consents distinctly, label contacts accordingly, and send promotional broadcasts only to the promotional list. Someone who opts out of offers may still expect their order updates to continue.
What should I do if a customer asks me to delete their data?
Be able to find everything you hold about that person, the contact record, labels, chat history and any exported lists, and remove it within a reasonable time unless another legal obligation requires retention. If your current setup makes that impossible, close the gap before a request arrives rather than after.
ZupiChat is built and maintained by Codelith Lab, a software company in Pune building websites, mobile apps and AI automation for Indian businesses.