Features Pricing Use cases Compare Blog

The DPDP Act and Your WhatsApp Contact List

14 min read

The short answer

The DPDP Act's obligations arrive in stages set by the DPDP Rules, 2025, not all at once, and the consent standard the Act sets — free, specific, informed, unconditional and unambiguous, given through a clear affirmative action — is what a stored WhatsApp contact list must be able to evidence. Meta's own opt-in rule is separate, and lighter.

A contacts screen showing a search bar and a row of filter controls above a table of entries, each row listing a name and phone number alongside a status badge, a source tag showing where the number originated, one or more tags, and a numeric lead score, with checkboxes down the left for selecting several rows and a green add-contact button above the column headers.

When do the DPDP obligations actually start applying?

Not on one date, and not on the date most people mean when they say "the DPDP Act." The Digital Personal Data Protection Act, 2023 received assent in 2023, but an Act of this kind does not take effect until the government notifies it — and the notification, when it finally came, split the obligations across three separate dates rather than switching the whole law on at once.

The Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 via publication in the Official Gazette on 14 November 2025 — the step that, under the Act's own commencement clause, actually starts each provision's clock. A first batch of provisions — the constitution of the Data Protection Board, a run of procedural and rule-making sections, and the Act's definitions — commenced immediately on notification. A second, narrow batch — the sub-section of Section 6 covering Consent Managers, and the Board's related power over them — follows roughly a year later, around 14 November 2026. The bulk of what a business actually experiences as "the DPDP Act" — Sections 3 to 10 (who it applies to, the grounds for processing, consent, and notice), Sections 11 to 17 (a Data Principal's rights), and the enforcement and cross-border sections from 28 to 34 — lands in the third batch, roughly eighteen months out, around 14 May 2027 (Ministry of Electronics and Information Technology, DPDP Rules 2025 enforcement timeline, read 4 September 2026; Shardul Amarchand Mangaldas & Co, "Enforcement of the DPDP Act and notification of the DPDP rules," read 4 September 2026). MeitY's own gazette PDF and its documents page both refused this session's request with a 403 while researching this piece; the dates above rest on independent legal-advisory readings of that notification rather than on the Gazette text itself.

The consent standard a WhatsApp sender has to meet is, for most businesses, not yet a live legal obligation — it is a countdown. That does not make the interval irrelevant. A contact list assembled today is the same contact list a business will be sending against once Section 6 is fully in force in 2027, and building the record now costs less than reconstructing it under a compliance deadline later.

What does the Act require a consent to look like?

Section 6(1) sets the standard in one sentence, and it is worth reading exactly as written, because every word in it does independent work: "The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose" (Section 6, Digital Personal Data Protection Act, 2023, read via IndianKanoon, 4 September 2026).

Five adjectives and one noun phrase, applied to a WhatsApp number:

Requirement What it rules out for a contact list
Free A number collected as a condition of using the product, with no real option to decline messaging
Specific One consent covering "service updates" cannot double as consent for promotional broadcasts
Informed The person was told what would be sent and why, before they said yes
Unconditional Saying no to messaging cannot mean losing something unrelated
Unambiguous, clear affirmative action A pre-ticked box, a default-on toggle, or silence does not count

Section 6(3) adds a procedural layer: the request for consent has to be presented in "clear and plain language," available in English or a language from the Eighth Schedule to the Constitution, and it has to name a contact — a Data Protection Officer or another authorised person — who can be reached about it. Section 6(4) gives the person the right to withdraw "at any time, with the ease of doing so being comparable to the ease with which such consent was given" — a standard that quietly rules out a system where opting in is one tap and opting out needs a support ticket.

Checked against the Act's own text on 4 September 2026.

Does an existing WhatsApp contact list need collecting again?

This is the question every other page dodges, and the honest answer is: it depends what the list was collected for, not whether it exists.

Section 4 gives a business two grounds for processing personal data — consent, or one of the "legitimate uses" set out in Section 7. The one that matters here is Section 7(a): processing is permitted "for the specified purpose for which the Data Principal has voluntarily provided her personal data to the Data Fiduciary, and in respect of which she has not indicated to the Data Fiduciary that she does not consent to the use of her personal data" (Section 7, Digital Personal Data Protection Act, 2023, read via dpdpa.com, 4 September 2026).

Read plainly, that clause covers a number a customer gave in order to receive an order confirmation, a delivery update, or a support reply — using it for exactly that purpose does not need a fresh Section 6 consent, because the person already volunteered it for that purpose and has not objected. It does not cover using the same number for a different purpose, and a broadcast marketing campaign is a different purpose from the service message the number was given for — Section 7(a)'s own wording is "the specified purpose," singular, not "any purpose this business later finds useful."

That is the gap almost every existing WhatsApp list actually has. Numbers collected at checkout, at signup, or through a support form were, in nearly every case, given for a service purpose. Reusing that same list for a broadcast campaign — the exact audience a campaign tool sends against — is the "specified purpose" test failing, not passing. Once Section 6 is fully in force, that gap needs a real, separate, Section 6-standard consent for the marketing use, collected on its own terms rather than inherited from the service relationship. Nothing about the eighteen-month runway changes what that consent has to look like when the clock runs out; it only changes when a business has to be able to produce it.

How is this different from what Meta asks of you?

Meta's own opt-in rule is not the DPDP Act, is not derived from it, and is already fully in force — it does not wait for a Gazette notification. Under WhatsApp's Business Messaging Policy, a business needs two things before it can message someone: the person has "given their mobile phone number," and the business has "opt-in permission from the recipient confirming that they wish to receive subsequent messages or calls from a particular business." Collecting that opt-in has to "clearly state that a person is opting in to receive communication from the business" and "clearly state the business's name that a person is opting in to receive messages from," collected by SMS, a website, IVR, in person, or on paper (Meta, WhatsApp Business Platform — getting opt-in, read 4 September 2026).

Checked against Meta's documentation on 4 September 2026.

Three commencement rungs for DPDP obligations running beside WhatsApp's own opt-in rule, already live and unaffected by any of them
Two clocks: the DPDP Act's staged commencement, and Meta's opt-in rule, which was never on the same schedule

Put the two rules side by side and the shape is a platform rule that is narrow, already active, and enforced by Meta refusing to deliver the message — against a statute that is broader, still arriving in stages, and enforced by a government Board after the fact. Meta's rule does not ask what the message is about, does not ask for a notice, and does not give the recipient a right to see or withdraw a record of their own consent. The DPDP Act asks for all three. A business running the WhatsApp Business API that has only ever satisfied Meta's bar — most businesses today — has cleared a real requirement, just not the one with the bigger fine attached.

How long must a business keep a record of consent?

Not the figure most compliance checklists quote. The specific "keep it for seven years" obligation that circulates in DPDP explainers is real, but it is written for a registered Consent Manager, not for an ordinary business sending WhatsApp messages. Part B of the First Schedule to the DPDP Rules, 2025 requires a Consent Manager to maintain its record of consents "for at least seven years, or for such longer period as the Data Principal and Consent Manager may agree upon or as may be required by law" (Part B, First Schedule, Digital Personal Data Protection Rules 2025, read via dpdpa.in, 4 September 2026).

An ordinary Data Fiduciary — the category almost every WhatsApp sender falls into — is not a Consent Manager and carries no matching seven-year retention duty in the Act. What it does carry is Section 8(7), and it points in roughly the opposite direction: personal data has to be erased "upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier," unless another law requires it to be kept. The Act's default posture toward an ordinary sender's records is delete when done, not retain for seven years — the seven-year figure belongs to a different, much narrower category of company that most WhatsApp senders will never become.

How quickly must you answer a request from a person on your list?

Rule 14(3) of the DPDP Rules, 2025 sets the ceiling: a Data Fiduciary and a Consent Manager must redress a grievance "within a reasonable period not exceeding ninety days," and Rule 14 also requires that timeline to be published rather than left implicit (Rule 14, Digital Personal Data Protection Rules 2025, read via dpdpa.com, 4 September 2026). A thirty-day figure circulates in some compliance material, borrowed from other Indian regimes with a shorter statutory window — it is not what this Rule says. Ninety days is the ceiling, not a target; publishing a shorter timeline and holding to it is what "reasonable" is doing in that sentence.

Who is a Consent Manager, and is your vendor one?

A Consent Manager is a specific, registered entity under the Act — not a generic term for any software that stores an opt-in flag, and not what a WhatsApp business platform is. Part A of the First Schedule sets the bar for registration deliberately high: the applicant has to be a company incorporated in India, with "adequate technical, operational and financial capacity," sound governance, and — the condition worth naming — "the net worth of the applicant is not less than two crore rupees" (Part A, First Schedule, Digital Personal Data Protection Rules 2025, read via dpdpa.in, 4 September 2026). Registration under this framework is itself gated on Rule 4 becoming operational, which is the roughly one-year milestone from the previous section — meaning there is, as of this writing, no live register of Consent Managers a vendor could actually belong to.

A CRM, a WhatsApp sending tool, or a marketing platform is a Data Fiduciary (or its processor) with respect to the numbers it stores, not a Consent Manager acting on a person's behalf across multiple businesses — that is a different role, built for a person to manage their consents to many companies through one interface, and it comes with its own registration, net worth, and audit obligations that an ordinary software vendor has neither sought nor met. This product is one such vendor, not a Consent Manager, which is a distinction worth being plain about on its own about page rather than leaving a customer to assume otherwise. If a vendor's marketing describes itself as a "Consent Manager" in the Act's sense without holding that registration, the description is doing more work than the product is licensed to do.

What does a compliant opt-in record contain in practice?

The Act does not hand over a form template, but Sections 6 and 7 together describe what a record has to be able to answer when asked. Four fields recur across every clause discussed above:

  • The specified purpose the number was collected for — service messages, a marketing broadcast, or both stated separately.
  • The notice given before or alongside the consent request — what data, for what purpose, and how to complain to the Board.
  • The affirmative act itself — a timestamped opt-in, not a default state, with enough detail to show it was specific to this purpose.
  • A working withdrawal path that does not require more effort than the original opt-in did.

A contacts screen built around these questions ends up looking less like a phone book and more like a small audit trail per person — where a number came from, what it was collected for, and what has happened to it since.

A contacts table listing entries with phone numbers, status badges, source tags, and lead-score columns, with bulk-selection checkboxes above a green add-contact button
A seeded demo workspace's contacts screen, recording source and status alongside the number itself

Tagging a contact's source and status is not the same as holding a Section 6 consent record, and no CRM should be mistaken for one on the strength of a "source" column — but a system that already tracks where a number came from is closer to the record the Act asks for than a flat list of numbers with no provenance at all.

Does it matter where your messaging data is stored?

The Act cares less about the server's location than most residency conversations assume, and more about who processes the data and for what purpose — Section 3(b)'s extraterritorial reach means an Indian customer's data is covered by the Act regardless of where the sending business or its vendor sits. Where the data actually lives still matters for other reasons: which country's courts and investigators can compel access to it, and what a business can honestly write in its own privacy notice.

WabaCRM's answer to that second question is a paragraph, not a pitch: the servers this product runs on are in Mumbai — confirmed by measuring first-hop network latency rather than trusting a hosting provider's registered address, which turned out to point the wrong continent entirely. The point for this piece is narrower: server location answers "where," and the DPDP Act's consent and notice sections answer "under what standard" — a business can get the first one right and still owe the second.

Where should an Indian business start on consent?

Not with a vendor contract, and not by waiting for May 2027. Three things are gradable today, before any provision is enforceable:

  1. Split "service" from "marketing" in the contact list itself. Section 7(a)'s purpose test means these are already two different legal grounds, whatever the CRM's tags call them.
  2. Write down, for each source of numbers, what purpose they were collected for. A support-form number and a signup-form number are not interchangeable audiences for a broadcast, even if both currently sit in the same table.
  3. Check what an opt-in flow actually asks for against Section 6(1)'s five words — free, specific, informed, unconditional, unambiguous — rather than against Meta's lighter bar alone, since the two are not the same test and only one of them is graded by a government Board.

None of this requires new software. A shared inbox that already separates numbers by source and status, and a campaign tool that already treats broadcast audiences as a stored filter rather than the whole contact table, gives a business most of the plumbing Section 6 will eventually ask it to prove it has. What it does not give a business is the consent itself — that has to be asked for, on its own terms, before the eighteen months run out. Businesses researching the adjacent DLT registration requirement, a separate telecom-regulator obligation with its own deadlines, can find that covered on its own terms in DLT registration for the WhatsApp Business API; this piece has deliberately stayed off that ground, because the two regulators, and the two sets of consequences for getting them wrong, do not overlap. The same goes for Meta's own business verification paperwork, a different checklist again from anything in this piece and covered separately in what Meta actually asks Indian businesses to submit.

Every Meta quotation on this page was read from Meta's own documentation on 4 September 2026. Meta changes that documentation without notice; the linked pages are authoritative and this one is not.

Questions people also ask

Does the DPDP Act apply to a business outside India messaging Indian customers?

Yes. Section 3(b) of the Act extends it to "processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India." A business does not need an Indian office or an Indian server for the Act to reach it — it needs an Indian customer on the other end of the WhatsApp thread. Where a business is actually incorporated, and where it hosts the conversation, are separate questions from whether the Act applies to the conversation itself; residency of the data and residency of the law are not the same test.

Is a WhatsApp opt-in enough to satisfy Indian data protection law?

Not on its own. Meta's opt-in rule asks for a phone number plus a permission that names the business and states a person is opting in to receive messages from it — a lighter, platform-level bar. Section 6(1) of the DPDP Act asks for consent that is "free, specific, informed, unconditional and unambiguous with a clear affirmative action," tied to a stated purpose, with a notice and a working way to withdraw. A WhatsApp opt-in can be the affirmative action the Act wants, but only if the record behind it also carries the purpose, the notice, and the withdrawal path — most opt-in flows built for Meta's rule alone do not, and [what Meta's own opt-in rule actually requires](/blog/whatsapp-opt-in-requirements) is a narrower, separate question from what follows.

What are the penalties for messaging without valid consent?

Under Section 33, the Data Protection Board sets a monetary penalty from the Schedule after an inquiry, weighing the breach's gravity, duration, repetition, and the type of data involved. The Schedule ties its largest figures to specific failures — up to ₹250 crore for a security-safeguards failure and up to ₹200 crore for not notifying a breach — and reserves a residuary entry, up to ₹50 crore, for a contravention with no separate line item, which is where an ordinary consent or notice failure sits. Nothing here is a fixed per-message fine; it is a case-by-case penalty the Board decides.

Does deleting a contact satisfy an erasure request?

Only if every copy goes with it. Section 8(7) requires a Data Fiduciary to "erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier." A shared inbox that stores raw inbound webhook payloads before parsing them, and keeps message logs for export, is very often holding that same person's data in more than one table. Removing the contact record and leaving the payload or the log row behind is a partial erasure that reads as complete from the screen a business actually looks at.

Do I need a data protection officer to run WhatsApp campaigns?

Generally no. Section 10(2)(a) requires a Data Protection Officer only for a Significant Data Fiduciary — a category the Central Government designates, based on the volume and sensitivity of data processed — and requires that officer to be based in India and answerable to the board of directors. An ordinary business sending WhatsApp campaigns instead needs what Section 6(3) already asks every Data Fiduciary for: a named contact, a Data Protection Officer or otherwise, who can respond to a Data Principal's communication. A title is not the requirement; a reachable person is.

Can consent be bundled into terms and conditions at signup?

Not validly, if it is buried or defaulted-in. Section 6(1) requires a clear affirmative action, and Section 6(2) says any part of a consent that breaches the Act's conditions is "invalid to the extent of such infringement" — so a marketing permission folded into a general terms-of-service tick-box does not automatically fail everything, but the marketing clause itself typically does, because it was never a specific, standalone affirmative act. The safer reading of Section 6 is that a signup checkbox can carry consent to the service itself; a separate purpose, like broadcast messaging, needs its own separate ask.

Keep reading

Your customers are already on WhatsApp

Free for your first 1,000 contacts, with no time limit and no card. Setting up the workspace takes minutes; connecting a number takes as long as Meta's own review of it.

Sign up with your company email address. No sales call, no onboarding fee, nothing to schedule.

Why this is safe to point your customer list at

Payments are processed by Razorpay on their own checkout — your card details are never entered on, or stored by, WabaCRM. Every inbound WhatsApp webhook is checked against its signature before it is trusted.

Tech Provider is a Meta platform access tier — not a partnership, a reseller agreement or an endorsement.