WhatsApp Opt-In and India’s DPDP Act: A Consent Checklist
What WhatsApp opt-in means under India’s DPDP Act and Rules: consent, notice, record-keeping and the May 2027 deadline, with example wording. Not legal advice.
On this page
TL;DR
- WhatsApp’s rule first: you may message someone only if they gave you their number or username and opted in to hear from your business, and you must honour opt-outs (WhatsApp Business Messaging Policy).
- The DPDP Act adds a second layer: a plain-language, itemised notice, consent that can be withdrawn as easily as it was given, security safeguards, breach reporting and retention limits for the personal data in your customer chats.
- Timeline under the notified schedule: the DPDP Rules, 2025 were published on 13 November 2025; Consent Manager rules start in November 2026; notice, security, breach and retention rules apply from May 2027. MeitY has floated a 12-month window instead, so check before you rely on the date.
- Who is who: your business is usually the Data Fiduciary for customer chats; a tool such as whatsappx.si is a Data Processor acting on your instructions under a contract.
- This article is general information, not legal advice. Ask a lawyer who practises Indian data-protection law before you finalise your consent flow.
WhatsApp will not let your business message a person who has not agreed to hear from you, and India’s Digital Personal Data Protection Act, 2023 (DPDP Act) will soon require you to show how that person agreed, what you told them, and how they can change their mind. The two sets of rules overlap but are not the same. This guide explains both, with example wording and a record-keeping checklist.
What does WhatsApp require before you message someone?
WhatsApp’s rule is short and strict. Its Business Messaging Policy, updated 23 September 2026, says a business may only contact people on WhatsApp if "(a) they have given you their mobile phone number or username; and (b) you have received opt-in permission from the recipient" (WhatsApp Business Messaging Policy). Both conditions must be true. A number copied from a visiting card, a scraped list or a group member list does not count as opt-in.
Three further points from Meta’s own documents matter for Indian businesses:
- Opt-outs must be honoured. If someone asks you to stop, you stop, whatever your consent record says.
- Automation needs a human exit. You may use automated replies during the 24-hour customer service window, but you "must also have available prompt, clear, and direct escalation paths" to a person (WhatsApp Business Messaging Policy).
- Bulk and automated blasts are prohibited on every WhatsApp product. WhatsApp states that its "products are not intended for bulk or automated messaging, both of which have always been a violation of our Terms of Service" (WhatsApp help centre). On the official WhatsApp Business Platform, template messages are "the only type of message that can be sent to WhatsApp users outside of a customer service window", and each template is reviewed first (Meta for Developers).
Consent is therefore not only a legal record. Messaging people "at scale in an unauthorized manner" is one of the reasons WhatsApp gives for limiting or removing a business’s access (WhatsApp Business Messaging Policy).
A number connected by QR code works as one of WhatsApp’s linked devices, the same feature WhatsApp Web uses (WhatsApp help centre). Treat it like your phone: use a brand-new WhatsApp number normally for 15–20 days before connecting it to any software; send 5–10 messages at a time, never bulk blasts; and message only people who opted in. Otherwise WhatsApp may restrict or block the number. Teams that need approved templates or higher volume should connect through the official WhatsApp Business Platform instead.
What does the DPDP Act require for customer chats?
The DPDP Act, 2023 was enacted on 11 August 2023 and is being brought into force through the Digital Personal Data Protection Rules, 2025, published as G.S.R. 846(E) on 13 November 2025 (Gazette of India; PIB explainer). A customer’s name, phone number, order details and chat content are all personal data, so a WhatsApp conversation with a customer is squarely inside the Act.
Once the relevant Rules apply, a business that decides why and how that data is processed must, among other things:
- Give a notice (Rule 3) in "clear and plain language" with "an itemised description of such personal data" and "the specified purpose or purposes", explaining how to withdraw consent as easily as it was given, exercise rights and complain to the Data Protection Board.
- Publish a contact point (Rule 9): the Data Protection Officer, where required, or a person who can answer questions about processing.
- Handle rights requests (Rule 14): publish how a person asks for access, correction, updating or erasure, and respond within a published period not exceeding ninety days.
- Keep security safeguards (Rule 6): at minimum encryption, masking or tokens; access controls; logs kept for one year; backups; and security clauses in processor contracts.
- Report breaches (Rule 7): tell each affected person "without delay", notify the Board without delay, and file a detailed report "within seventy-two hours of becoming aware of the breach".
- Limit retention (Rule 8): erase data once its purpose is served (with at least 48 hours’ notice, for the Third Schedule classes) and keep personal data, traffic data and logs "for a minimum period of one year" for Seventh Schedule purposes.
- Protect children (Rule 10): obtain verifiable parental consent before processing a child’s data; an adult is a person who has turned 18.
All of this is from the Rules as published (Gazette of India). The PIB explainer puts penalties at up to Rs 250 crore for failing to maintain reasonable security safeguards, up to Rs 200 crore each for failing to notify a breach and for children’s-data violations, and up to Rs 50 crore for other violations (PIB).
When do the DPDP Rules apply?
Not all at once. Rule 1 sets a staggered start (Gazette of India):
| Provision | What it covers | Comes into force |
|---|---|---|
| Rules 1, 2 and 17 to 21 | Definitions, the Data Protection Board and its working | On publication (13 November 2025) |
| Rule 4 | Consent Managers (which must be companies based in India) | One year after publication (November 2026) |
| Rules 3, 5 to 16, 22 and 23 | Notice, security safeguards, breach intimation, retention, contact details, children’s data, rights and cross-border transfer | Eighteen months after publication (May 2027) |
Two cautions. On 28 January 2026 MeitY asked industry for views on cutting the compliance window from 18 to 12 months (Storyboard18); a tracker updated on 30 September 2026 still showed 13 May 2027 and no notified amendment (ConsentOS), but that could change. And WhatsApp’s opt-in rule applies today, whatever the DPDP timeline. Build your consent flow now so that it satisfies both.
Who is the Data Fiduciary and who is the Data Processor?
The PIB explainer defines a Data Fiduciary as "an entity that decides why and how personal data is processed" and a Data Processor as "any entity that processes personal data on behalf of a Data Fiduciary" (PIB). Applied to a team inbox:
- Your business is the Data Fiduciary for the customers you chat with. You decide to collect numbers, reply, keep order history and send updates.
- The software is a Data Processor for those chats. Under section 8 of the Act a Fiduciary may engage a Processor "only under a valid contract" and remains responsible for processing done on its behalf (India Code), so read the vendor’s terms and privacy policy and keep a copy.
- Meta is also a processor for API-connected numbers. For the Cloud API, Meta "acts as a data processor/service provider on behalf of the business", and messages have "a maximum retention period of 30 days" on Meta’s side (Meta). Cloud API local storage can keep data at rest in a chosen country such as India (Meta local storage).
Your notice should therefore name the categories of recipient (your messaging software, Meta) rather than suggest the data never leaves your office.
What should an opt-in and a notice look like?
These are illustrative examples only; adapt them with your lawyer. The person should learn who will message them, about what, and how to stop.
Example opt-in on a checkout form (one tick-box):
☐ Yes, send me order updates and delivery messages from Example Traders on WhatsApp at the number above. I can reply STOP at any time.
Example in-chat opt-in when a customer messages you first:
Thanks for contacting Example Traders. May we send you updates about this order and occasional offers on WhatsApp? Reply YES to agree. Reply STOP anytime.
Example short DPDP notice (linked from the form or sent once in chat):
Who: Example Traders Pvt. Ltd., Pune. What we collect: your name, mobile number, delivery address and the messages you send us. Why: to deliver your order, answer queries and, if you opted in, send offers. Who sees it: our team, the messaging software we use, and Meta (WhatsApp). Your rights: withdraw consent, or ask to see, correct or erase your data, by writing to privacy@example.in; we reply within 30 days. Complaints: you may approach the Data Protection Board of India.
Keep marketing consent separate from service consent: someone who agreed to delivery updates has not agreed to festival offers.
Which numbers and deadlines should you remember?
| Item | Requirement | Source |
|---|---|---|
| Opt-in | Number or username shared and opt-in received, before any message | WhatsApp policy |
| Breach: affected persons | Inform "without delay" | Rule 7 |
| Breach: Data Protection Board | Notify without delay; detailed report within 72 hours | Rule 7 |
| Logs and processing records | Keep for a minimum of one year | Rules 6 and 8 |
| Grievance response | Within the published period, not more than 90 days | Rule 14 |
| Children | Verifiable parental consent; adult = 18 or above | Rule 10 |
| Meta retention (Cloud API) | Messages kept a maximum of 30 days on Meta’s side | Meta |
How should you keep consent records?
Withdrawal must be as easy as giving consent (Rule 3) and rights requests must be answered in time (Rule 14); neither works without records. A workable minimum, kept in your own CRM or order system:
- Who: the mobile number (and username, if WhatsApp has issued one) and the name given.
- What: the exact wording agreed to, versioned, and which purposes (service, marketing, both).
- When and how: date, time and channel (web form, in-chat YES, signed form at the counter).
- Withdrawal: the opt-out date, and a flag that stops marketing immediately.
- Requests: a log of access, correction and erasure requests with the date you replied.
Check the list before every outbound message. If a contact is not in it with a live consent, do not message them.
Where does whatsappx.si fit?
whatsappx.si is a shared inbox: you scan a QR code to connect the WhatsApp you already have, and your whole team replies from one inbox. Keyword auto-replies are available today; AI replies are coming soon and are not available yet. You can also connect a number through the official WhatsApp Business Platform, and developers can use a REST API. In DPDP terms whatsappx.si is a processor for your customer chats.
- Helps: one place to see and reply to every conversation; roles so agents see only their assigned chats; per-workspace data separation; Meta credentials encrypted at rest; HTTPS throughout; keyword auto-replies you can switch off, with a human always able to reply; templates that sync with Meta for official-API numbers; and a REST API plus outbound webhooks for incoming messages, so you can copy chats into your own records.
- Does not do: it is not a consent manager, it does not write your notice or decide your purposes, and it does not offer bulk broadcast campaigns. If you are the Fiduciary, those duties stay with you.
List whatsappx.si (and Meta, for API numbers) among the recipients in your notice, and read our privacy policy and terms as part of your contract review.
What should your WhatsApp consent checklist include?
- Every contact you message has shared their number and opted in to your business by name.
- Service and marketing consent are collected and recorded separately.
- Your notice is in plain language, itemises the data, states the purposes, names recipient categories and gives a contact point.
- Withdrawing consent is as easy as giving it (for example, replying STOP), and opt-outs are applied the same day.
- A rights-request process exists with a published response time of 90 days or less, and records are kept for at least one year.
- A breach plan names who informs affected persons and who files the 72-hour report to the Board.
- Automated replies always offer a route to a human.
- You send in small batches, never bulk, and a new number is used normally for 15–20 days before you connect it.
- November 2026 and May 2027 are in your diary, and you will check whether MeitY shortens the window.
Sources
- WhatsApp Business Messaging Policy (Meta) — accessed 3 October 2026
- WhatsApp help centre: Unauthorised use of automated or bulk messaging — accessed 3 October 2026
- WhatsApp help centre: About linked devices — accessed 3 October 2026
- Message templates overview (Meta for Developers) — accessed 3 October 2026
- Digital Personal Data Protection Rules, 2025 — Gazette of India G.S.R. 846(E), 13 November 2025 — accessed 3 October 2026
- PIB explainer: DPDP Rules, 2025 notified (17 November 2025) — accessed 3 October 2026
- India Code: Digital Personal Data Protection Act, 2023 — accessed 3 October 2026
- Storyboard18: MeitY seeks industry views on a 12-month DPDP compliance timeline (28 January 2026) — accessed 3 October 2026
- ConsentOS: DPDP compliance timeline (updated 30 September 2026) — accessed 3 October 2026
- Meta: WhatsApp Cloud API data privacy and security — accessed 3 October 2026
- Meta: WhatsApp Cloud API local storage — accessed 3 October 2026
Frequently asked questions
Does the DPDP Act apply to WhatsApp chats my business stores?
Do I need customer opt-in before sending WhatsApp messages in India?
Is a WhatsApp group member list a valid opt-in?
Is whatsappx.si a Data Fiduciary or a Data Processor under the DPDP Act?
What happens if WhatsApp blocks my number even though I had consent?
What is the difference between WhatsApp opt-in and DPDP consent?
Keep reading
Blog
Can a WhatsApp Business Number Get Banned? How to Stay Safe
Why WhatsApp restricts or bans business numbers, what its policies require, how quality rating and messaging limits work, and what to do if you are blocked.
Blog
QR Linking vs the Official WhatsApp Business Platform
Two ways to bring a WhatsApp number into a team inbox: link it by QR code or connect it through Meta’s Cloud API. What each means and how to choose.
Glossary
Opt-in
Opt-in is a person’s permission to receive WhatsApp messages from your business. Meta requires it before you message anyone, and opt-outs must be honored.
Glossary
Customer service window
The customer service window is a 24-hour timer on the WhatsApp Business Platform that opens when a user messages or calls you and allows free-form replies.
Legal
Privacy Policy
How whatsappx.si collects, uses and protects personal data when you use the website and the shared WhatsApp inbox web app.
Feature
Shared inbox
Answer customer WhatsApp chats as a team: one shared inbox with search, assignment, unread counts and live updates. Connect by QR code or the official API.