Is DLT registration required for the WhatsApp Business API?
The short answer
No. DLT registration is not required to send messages through the WhatsApp Business API. DLT is TRAI's registration system for commercial SMS and voice calls carried by Indian telecom operators; WhatsApp messages travel over Meta's platform and are governed by Meta's WhatsApp Business Messaging Policy instead. Checked against TRAI's TCCCPR, 2018 on 22 August 2026.
Is DLT registration required for the WhatsApp Business API?
No. There is no DLT registration for WhatsApp — no Principal Entity ID, no registered header, no content template on an operator's portal, no Do Not Disturb scrub. That machinery is not Meta's: it belongs to India's telecom operators, and it governs the SMS and voice traffic crossing their networks.
The mistake costs in a boring way: businesses file for a registration they will never use, or hold a launch open waiting for an approval that was never coming.
Checked against TRAI's Telecom Commercial Communications Customer Preference Regulations, 2018 and its own guidance to senders on 22 August 2026. If the platform itself is new to you, start with the WhatsApp Business API explained end to end.
- Is DLT registration required for the WhatsApp Business API?
- What is DLT registration, and what does it cover?
- Why is WhatsApp outside the DLT framework?
- What has to be registered for SMS, and what for WhatsApp?
- Why do so many people think DLT applies to WhatsApp?
- When does DLT still apply to a business that uses WhatsApp?
- What actually governs WhatsApp marketing in India?
- Where does India's data protection law fit in?
- Could TRAI bring WhatsApp under the DLT rules later?
What is DLT registration, and what does it cover?
DLT stands for distributed ledger technology. The registration system sits inside TRAI's Telecom Commercial Communications Customer Preference Regulations, 2018 — the TCCCPR.
Regulation 13 is where the ledger comes from: access providers must adopt DLT "with permissioned and private DLT networks" to run regulatory pre-checks on commercial communication offered for delivery. An access provider, in the regulation's own definition, "includes the Basic Telephone Service Provider, Cellular Mobile Telephone Service Provider, Unified Access Service Provider, Universal Access Service Provider and Virtual Network Operator (VNO)" (regulation text).
TRAI wrote the rule; the telephone companies run the portals — so a business registering on DLT registers with an operator, not a regulator.
TRAI's own advice to senders sets out four steps: register as a Principal Entity, register a header — "Alphanumeric string of Max. 11 characters" — register content templates, and register customer consents. It mentions WhatsApp nowhere.
Why is WhatsApp outside the DLT framework?
Because every enforcement point in the regulation is something an operator does to traffic on its own network, and a WhatsApp message never appears there in a form an operator can act on.

The TCCCPR defines a commercial communication as "any voice call or message using telecommunication services" whose primary purpose is to advertise or solicit business, and Regulation 10 puts the duty on the carrier: "Every Access Provider shall ensure that no commercial communication takes place through its network(s) except by using header(s) assigned to the registered Sender(s)."
A header is the sender ID in an SMS, and a WhatsApp message has no such field to assign or inspect — it carries a phone number and a display name Meta reviews. The Do Not Disturb check happens inside the operator's platform, and a WhatsApp send never enters it.
Legal commentary agrees. Writing in SCC Online on 29 July 2026, Ishaan Uday states that WhatsApp "shall be classified as 'an over the top service' meaning it shall sit outside Telecom Regulatory Authority of India (TRAI) and subsequently not attract the Do Not Disturb (DND) requirement by TRAI" (analysis).
What has to be registered for SMS, and what for WhatsApp?
| Commercial SMS in India | WhatsApp Business Platform | |
|---|---|---|
| Governing rule | TRAI's TCCCPR, 2018 | Meta's WhatsApp Business Messaging Policy |
| Register the business | Yes — as a Principal Entity, on an operator's DLT portal | No — you open a WhatsApp Business Account with Meta |
| Register the sender identity | Yes — a header, "Alphanumeric string of Max. 11 characters" | No — a phone number and a display name Meta reviews |
| Register the wording | Yes — content templates, fixed and variable parts | Yes — message templates, reviewed by Meta, "up to 24 hours" |
| Free-form messages | No — the wording must match a registered content template | Allowed for 24 hours after the customer messages you |
| Do Not Disturb | Yes — the operator applies the customer's registered preference | No such register applies |
| Opening volume cap | Not part of DLT registration | 250 unique people messaged outside a service window, per moving 24 hours, per portfolio |
| Consent | Required, through a registered consent template | Required by Meta; you keep the record, and there is no registry |
Read down the right-hand column and the real answer appears. The obligations do not disappear on WhatsApp — they move, to Meta and to a data protection statute.
Why do so many people think DLT applies to WhatsApp?
Because of who sold them WhatsApp.
A great many Indian messaging vendors sell SMS and WhatsApp out of one CPaaS product, and several arrived at WhatsApp from bulk SMS. Onboarding in that shape had to be built around DLT, because for SMS it is not optional: an unregistered header is a message the operator simply blocks. When WhatsApp joined the product line, the compliance page and the intake form came with it.
Read that as inheritance rather than deception. The form asks for a Principal Entity ID because the form was written for SMS, and DLT is tedious enough that a business fresh out of it reasonably assumes the next channel charges the same toll. The result is the same either way: a step nobody needs, treated as a prerequisite.
When does DLT still apply to a business that uses WhatsApp?
Whenever that business also sends SMS or makes outbound commercial calls, which most of them do.
If your platform falls back to SMS when a WhatsApp message goes undelivered, that SMS is commercial communication on an operator's network and needs a registered header and content template — as does an OTP by SMS, and any outbound telemarketing call.
Registration is per channel, not per company. A DLT registration does nothing for your WhatsApp, and having none holds your WhatsApp back not at all.
What actually governs WhatsApp marketing in India?
Two rulebooks, and neither is TRAI's.
The first is Meta's WhatsApp Business Messaging Policy, short and absolute on consent: "You may only contact people on WhatsApp if: (a) they have given you their mobile phone number; and (b) you have received opt-in permission from the recipient confirming that they wish to receive subsequent messages or calls from you" (policy). It also requires you to respect any request to opt out, on or off WhatsApp.
Meta's developer documentation adds what the opt-in must say: businesses "must clearly state that a person is opting in to receive communication from the business" and "must clearly state the business's name". The method is yours — "It is up to businesses to determine the method of opt-in" (opt-in requirements). There is no portal to file it with, and that missing portal is what makes people assume a step has been skipped.

The second rulebook is approval and volume. Meta's documentation states that "Template messages are the only type of message that can be sent to WhatsApp users outside of a customer service window", and that "Review can take up to 24 hours". Your display name is reviewed too, and the green tick is a fourth thing again — what it actually is, and who Meta gives one to.
Volume is earned rather than granted. Meta starts newly created business portfolios at a messaging limit of 250 — defined as "the maximum number of unique WhatsApp user phone numbers your business can deliver messages to, outside of a customer service window, within a moving 24-hour period", and shared across every number in the portfolio (messaging limits).
That cap is the rule behind why a new number cannot broadcast to a whole list on day one. It rises through 2,000, 10,000, 100,000 and unlimited on Meta's assessment of quality and usage, not on any application you can file. Meta also bills for messages, separately from the software you send them through: ours is priced by contacts, not agents.
Where does India's data protection law fit in?
Above both — and it is the question most often skipped while people chase the one that does not exist. Meta's own policy points at it, requiring opt-in "in a manner that complies with laws applicable to your communications".
The Digital Personal Data Protection Act, 2023 governs the personal data a business processes, including the numbers it messages, whatever channel carries them. Section 6(1) sets the standard: consent "shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action" (section text). Enrolling people by default and offering a way out afterwards is, in Ishaan Uday's phrase, "passive consent, not affirmative".
The rules arrived in stages. Shardul Amarchand Mangaldas records that MeitY published the Digital Personal Data Protection Rules, 2025 on 14 November 2025, and that "the substantive provisions of the DPDP Act and DPDP Rules come into force in 18 months, i.e., 14 May 2027" (Shahana Chatterji and Kirti Mahapatra, 21 November 2025).
None of this is legal advice, this page included. The point is where the questions live: an Indian sender's obligations are a Meta-policy question and a data protection question, not a telecom-registration one.
Could TRAI bring WhatsApp under the DLT rules later?
It is being asked for, and the asking is the clearest evidence of the current answer.
India's telecom operators have pushed hardest. Responding to the Second Amendment to the TCCCPR — released 12 February 2025 — COAI complained that it "does not bring OTT Communication Service Providers under the ambit of this Regulation, nor does it address the UCC issues at its source" (Light Reading, 17 February 2025). The industry that would most like WhatsApp inside the framework says plainly that it is outside.
What happens next is contested, and worth stating carefully rather than flattening. TRAI issued a draft Third Amendment for consultation on 13 March 2026; its consultation page now records the window as closed, with 29 comments and 3 counter-comments filed by Airtel, Jio, Vodafone Idea, BSNL, COAI, GSMA, IAMAI, Truecaller and Amazon among others (TRAI consultation).
The Internet and Mobile Association of India objected that the amendments "attempt to regulate the functionality of OTT platforms, even though these do not fall within the scope of telecommunication services", and that a proposed mandate for those platforms to share data with access providers "amounts to unconstitutional expropriation of valuable proprietary data" (Indian Broadcasting World, 29 April 2026).
Read the scope carefully, because "reaches OTT" and "registers OTT senders" are not the same proposal. On the published summaries, the platform-facing duties are data sharing and a bar on third-party apps blocking commercial number series; the sender-facing duty is pre-declaring application-to-person voice traffic. None of that is a header or a content template for a WhatsApp message.
That distinction is drawn from summaries of the draft rather than from the draft's own text — TRAI publishes it as a PDF this review could not extract — so treat it as the current reading, not as a quotation.
Nothing in force on 22 August 2026 requires DLT registration for WhatsApp, and no final Third Amendment could be found notified in the Gazette as of that date. A TCCCPR regulation takes effect thirty days after Gazette publication, so a change here would be visible before it bound anyone.
It would also invert this page rather than merely date it, which is why it is re-checked before every revision.
Every quotation attributed to Meta was re-read in Meta's own documentation on 22 August 2026, and every regulatory quotation was read from the linked text the same day. Two absences are deliberate. The draft Third Amendment is described from published summaries, not quoted, because TRAI publishes it as a PDF this review could not extract — so no sentence here is attributed to the draft itself. And no penalty figure appears anywhere on this page: the rupee amounts circulating for DPDP breaches trace to vendor blogs rather than to the statute. The linked sources are authoritative and this page is not; none of it is legal advice.
Questions people also ask
Do I need DLT registration to send WhatsApp marketing messages in India?
Does the WhatsApp Business API need TRAI approval?
I use SMS as a fallback when WhatsApp is undelivered. Does DLT apply then?
What replaces DLT content template registration on WhatsApp?
Could TRAI bring WhatsApp under the DLT rules in future?
- dlt
- trai
- india
- compliance
- opt-in