Skip to content

India

WhatsApp Opt-In and India’s DPDP Act: A Consent Checklist

What WhatsApp opt-in means under India’s DPDP Act and Rules: consent, notice, record-keeping and the May 2027 deadline, with example wording. Not legal advice.

On this page

TL;DR

  • WhatsApp’s rule first: you may message someone only if they gave you their number or username and opted in to hear from your business, and you must honour opt-outs (WhatsApp Business Messaging Policy).
  • The DPDP Act adds a second layer: a plain-language, itemised notice, consent that can be withdrawn as easily as it was given, security safeguards, breach reporting and retention limits for the personal data in your customer chats.
  • Timeline under the notified schedule: the DPDP Rules, 2025 were published on 13 November 2025; Consent Manager rules start in November 2026; notice, security, breach and retention rules apply from May 2027. MeitY has floated a 12-month window instead, so check before you rely on the date.
  • Who is who: your business is usually the Data Fiduciary for customer chats; a tool such as whatsappx.si is a Data Processor acting on your instructions under a contract.
  • This article is general information, not legal advice. Ask a lawyer who practises Indian data-protection law before you finalise your consent flow.

WhatsApp will not let your business message a person who has not agreed to hear from you, and India’s Digital Personal Data Protection Act, 2023 (DPDP Act) will soon require you to show how that person agreed, what you told them, and how they can change their mind. The two sets of rules overlap but are not the same. This guide explains both, with example wording and a record-keeping checklist.

What does WhatsApp require before you message someone?

WhatsApp’s rule is short and strict. Its Business Messaging Policy, updated 23 September 2026, says a business may only contact people on WhatsApp if "(a) they have given you their mobile phone number or username; and (b) you have received opt-in permission from the recipient" (WhatsApp Business Messaging Policy). Both conditions must be true. A number copied from a visiting card, a scraped list or a group member list does not count as opt-in.

Three further points from Meta’s own documents matter for Indian businesses:

  • Opt-outs must be honoured. If someone asks you to stop, you stop, whatever your consent record says.
  • Automation needs a human exit. You may use automated replies during the 24-hour customer service window, but you "must also have available prompt, clear, and direct escalation paths" to a person (WhatsApp Business Messaging Policy).
  • Bulk and automated blasts are prohibited on every WhatsApp product. WhatsApp states that its "products are not intended for bulk or automated messaging, both of which have always been a violation of our Terms of Service" (WhatsApp help centre). On the official WhatsApp Business Platform, template messages are "the only type of message that can be sent to WhatsApp users outside of a customer service window", and each template is reviewed first (Meta for Developers).

Consent is therefore not only a legal record. Messaging people "at scale in an unauthorized manner" is one of the reasons WhatsApp gives for limiting or removing a business’s access (WhatsApp Business Messaging Policy).

A number connected by QR code works as one of WhatsApp’s linked devices, the same feature WhatsApp Web uses (WhatsApp help centre). Treat it like your phone: use a brand-new WhatsApp number normally for 15–20 days before connecting it to any software; send 5–10 messages at a time, never bulk blasts; and message only people who opted in. Otherwise WhatsApp may restrict or block the number. Teams that need approved templates or higher volume should connect through the official WhatsApp Business Platform instead.

What does the DPDP Act require for customer chats?

The DPDP Act, 2023 was enacted on 11 August 2023 and is being brought into force through the Digital Personal Data Protection Rules, 2025, published as G.S.R. 846(E) on 13 November 2025 (Gazette of India; PIB explainer). A customer’s name, phone number, order details and chat content are all personal data, so a WhatsApp conversation with a customer is squarely inside the Act.

Once the relevant Rules apply, a business that decides why and how that data is processed must, among other things:

  • Give a notice (Rule 3) in "clear and plain language" with "an itemised description of such personal data" and "the specified purpose or purposes", explaining how to withdraw consent as easily as it was given, exercise rights and complain to the Data Protection Board.
  • Publish a contact point (Rule 9): the Data Protection Officer, where required, or a person who can answer questions about processing.
  • Handle rights requests (Rule 14): publish how a person asks for access, correction, updating or erasure, and respond within a published period not exceeding ninety days.
  • Keep security safeguards (Rule 6): at minimum encryption, masking or tokens; access controls; logs kept for one year; backups; and security clauses in processor contracts.
  • Report breaches (Rule 7): tell each affected person "without delay", notify the Board without delay, and file a detailed report "within seventy-two hours of becoming aware of the breach".
  • Limit retention (Rule 8): erase data once its purpose is served (with at least 48 hours’ notice, for the Third Schedule classes) and keep personal data, traffic data and logs "for a minimum period of one year" for Seventh Schedule purposes.
  • Protect children (Rule 10): obtain verifiable parental consent before processing a child’s data; an adult is a person who has turned 18.

All of this is from the Rules as published (Gazette of India). The PIB explainer puts penalties at up to Rs 250 crore for failing to maintain reasonable security safeguards, up to Rs 200 crore each for failing to notify a breach and for children’s-data violations, and up to Rs 50 crore for other violations (PIB).

When do the DPDP Rules apply?

Not all at once. Rule 1 sets a staggered start (Gazette of India):

ProvisionWhat it coversComes into force
Rules 1, 2 and 17 to 21Definitions, the Data Protection Board and its workingOn publication (13 November 2025)
Rule 4Consent Managers (which must be companies based in India)One year after publication (November 2026)
Rules 3, 5 to 16, 22 and 23Notice, security safeguards, breach intimation, retention, contact details, children’s data, rights and cross-border transferEighteen months after publication (May 2027)

Two cautions. On 28 January 2026 MeitY asked industry for views on cutting the compliance window from 18 to 12 months (Storyboard18); a tracker updated on 30 September 2026 still showed 13 May 2027 and no notified amendment (ConsentOS), but that could change. And WhatsApp’s opt-in rule applies today, whatever the DPDP timeline. Build your consent flow now so that it satisfies both.

Who is the Data Fiduciary and who is the Data Processor?

The PIB explainer defines a Data Fiduciary as "an entity that decides why and how personal data is processed" and a Data Processor as "any entity that processes personal data on behalf of a Data Fiduciary" (PIB). Applied to a team inbox:

  • Your business is the Data Fiduciary for the customers you chat with. You decide to collect numbers, reply, keep order history and send updates.
  • The software is a Data Processor for those chats. Under section 8 of the Act a Fiduciary may engage a Processor "only under a valid contract" and remains responsible for processing done on its behalf (India Code), so read the vendor’s terms and privacy policy and keep a copy.
  • Meta is also a processor for API-connected numbers. For the Cloud API, Meta "acts as a data processor/service provider on behalf of the business", and messages have "a maximum retention period of 30 days" on Meta’s side (Meta). Cloud API local storage can keep data at rest in a chosen country such as India (Meta local storage).

Your notice should therefore name the categories of recipient (your messaging software, Meta) rather than suggest the data never leaves your office.

What should an opt-in and a notice look like?

These are illustrative examples only; adapt them with your lawyer. The person should learn who will message them, about what, and how to stop.

Example opt-in on a checkout form (one tick-box):

☐ Yes, send me order updates and delivery messages from Example Traders on WhatsApp at the number above. I can reply STOP at any time.

Example in-chat opt-in when a customer messages you first:

Thanks for contacting Example Traders. May we send you updates about this order and occasional offers on WhatsApp? Reply YES to agree. Reply STOP anytime.

Example short DPDP notice (linked from the form or sent once in chat):

Who: Example Traders Pvt. Ltd., Pune. What we collect: your name, mobile number, delivery address and the messages you send us. Why: to deliver your order, answer queries and, if you opted in, send offers. Who sees it: our team, the messaging software we use, and Meta (WhatsApp). Your rights: withdraw consent, or ask to see, correct or erase your data, by writing to privacy@example.in; we reply within 30 days. Complaints: you may approach the Data Protection Board of India.

Keep marketing consent separate from service consent: someone who agreed to delivery updates has not agreed to festival offers.

Which numbers and deadlines should you remember?

ItemRequirementSource
Opt-inNumber or username shared and opt-in received, before any messageWhatsApp policy
Breach: affected personsInform "without delay"Rule 7
Breach: Data Protection BoardNotify without delay; detailed report within 72 hoursRule 7
Logs and processing recordsKeep for a minimum of one yearRules 6 and 8
Grievance responseWithin the published period, not more than 90 daysRule 14
ChildrenVerifiable parental consent; adult = 18 or aboveRule 10
Meta retention (Cloud API)Messages kept a maximum of 30 days on Meta’s sideMeta

Withdrawal must be as easy as giving consent (Rule 3) and rights requests must be answered in time (Rule 14); neither works without records. A workable minimum, kept in your own CRM or order system:

  1. Who: the mobile number (and username, if WhatsApp has issued one) and the name given.
  2. What: the exact wording agreed to, versioned, and which purposes (service, marketing, both).
  3. When and how: date, time and channel (web form, in-chat YES, signed form at the counter).
  4. Withdrawal: the opt-out date, and a flag that stops marketing immediately.
  5. Requests: a log of access, correction and erasure requests with the date you replied.

Check the list before every outbound message. If a contact is not in it with a live consent, do not message them.

Where does whatsappx.si fit?

whatsappx.si is a shared inbox: you scan a QR code to connect the WhatsApp you already have, and your whole team replies from one inbox. Keyword auto-replies are available today; AI replies are coming soon and are not available yet. You can also connect a number through the official WhatsApp Business Platform, and developers can use a REST API. In DPDP terms whatsappx.si is a processor for your customer chats.

  • Helps: one place to see and reply to every conversation; roles so agents see only their assigned chats; per-workspace data separation; Meta credentials encrypted at rest; HTTPS throughout; keyword auto-replies you can switch off, with a human always able to reply; templates that sync with Meta for official-API numbers; and a REST API plus outbound webhooks for incoming messages, so you can copy chats into your own records.
  • Does not do: it is not a consent manager, it does not write your notice or decide your purposes, and it does not offer bulk broadcast campaigns. If you are the Fiduciary, those duties stay with you.

List whatsappx.si (and Meta, for API numbers) among the recipients in your notice, and read our privacy policy and terms as part of your contract review.

  • Every contact you message has shared their number and opted in to your business by name.
  • Service and marketing consent are collected and recorded separately.
  • Your notice is in plain language, itemises the data, states the purposes, names recipient categories and gives a contact point.
  • Withdrawing consent is as easy as giving it (for example, replying STOP), and opt-outs are applied the same day.
  • A rights-request process exists with a published response time of 90 days or less, and records are kept for at least one year.
  • A breach plan names who informs affected persons and who files the 72-hour report to the Board.
  • Automated replies always offer a route to a human.
  • You send in small batches, never bulk, and a new number is used normally for 15–20 days before you connect it.
  • November 2026 and May 2027 are in your diary, and you will check whether MeitY shortens the window.

Sources

  1. WhatsApp Business Messaging Policy (Meta) — accessed 3 October 2026
  2. WhatsApp help centre: Unauthorised use of automated or bulk messaging — accessed 3 October 2026
  3. WhatsApp help centre: About linked devices — accessed 3 October 2026
  4. Message templates overview (Meta for Developers) — accessed 3 October 2026
  5. Digital Personal Data Protection Rules, 2025 — Gazette of India G.S.R. 846(E), 13 November 2025 — accessed 3 October 2026
  6. PIB explainer: DPDP Rules, 2025 notified (17 November 2025) — accessed 3 October 2026
  7. India Code: Digital Personal Data Protection Act, 2023 — accessed 3 October 2026
  8. Storyboard18: MeitY seeks industry views on a 12-month DPDP compliance timeline (28 January 2026) — accessed 3 October 2026
  9. ConsentOS: DPDP compliance timeline (updated 30 September 2026) — accessed 3 October 2026
  10. Meta: WhatsApp Cloud API data privacy and security — accessed 3 October 2026
  11. Meta: WhatsApp Cloud API local storage — accessed 3 October 2026

Frequently asked questions

Does the DPDP Act apply to WhatsApp chats my business stores?
Yes. A customer’s name, phone number and the content of a chat are personal data, and your business decides why it is processed, which makes you the Data Fiduciary. The Rules on notice, security, breach reporting and retention come into force eighteen months after 13 November 2025 under the notified schedule (Gazette of India), so plan for May 2027 unless MeitY shortens it.
Do I need customer opt-in before sending WhatsApp messages in India?
Yes, today and regardless of the DPDP timeline. WhatsApp’s Business Messaging Policy allows you to contact a person only if they gave you their number or username and you received opt-in permission, and you must honour opt-outs (WhatsApp policy). WhatsApp says it may limit or remove access for messaging people at scale in an unauthorized manner.
Is a WhatsApp group member list a valid opt-in?
No. Being in a group means the person agreed to that group, not to receiving direct business messages from you. WhatsApp requires both that the person shared their number with you and that they opted in to your business. Under the DPDP Act you would also need to have given them a notice covering that purpose. Collect a separate, recorded opt-in first.
Is whatsappx.si a Data Fiduciary or a Data Processor under the DPDP Act?
For the customer chats you run through it, whatsappx.si acts as a Data Processor on your instructions, and your business is the Data Fiduciary. For your own account, billing and website data, whatsappx.si is a Fiduciary. Section 8 of the Act requires a valid contract between Fiduciary and Processor, so review our terms and privacy policy as part of your compliance file. This is general information, not legal advice.
What happens if WhatsApp blocks my number even though I had consent?
Restrictions are decided by WhatsApp and Meta, not by your software vendor. whatsappx.si is not affiliated with WhatsApp or Meta, is not responsible for account restrictions and cannot restore an account; any appeal is between you and Meta. Reduce the risk by messaging only opted-in contacts, sending 5–10 messages at a time rather than in bulk, and using a new number normally for 15–20 days before connecting it.
What is the difference between WhatsApp opt-in and DPDP consent?
WhatsApp opt-in is a platform rule: the person agrees to receive messages from your business on WhatsApp. DPDP consent is a legal basis for processing their personal data for specified purposes, and it must follow a plain-language notice and be as easy to withdraw as to give. One well-designed form can capture both, but keep marketing and service purposes separate and record exactly what the person agreed to.