WhatsApp Marketing Under India’s DPDP Act: Consent, Compliance and the New Rules for Businesses

WhatsApp Marketing Under India’s DPDP Act: Consent, Compliance and the New Rules for Businesses

  • Loading...

WhatsApp has become one of the most powerful customer-engagement channels in India.

Get a callback

Banks send account updates. NBFCs communicate with borrowers. Hospitals share appointment information. E-commerce businesses announce offers. Educational institutions engage students and parents. Retailers use WhatsApp for promotions, abandoned-cart reminders, product launches and customer support.

But there is an important question businesses increasingly need to answer:

Just because an organisation has a customer’s mobile number, does that mean it can use that number for WhatsApp marketing?

Under India’s evolving privacy and commercial-communications framework, businesses should not treat the answer as an automatic yes.

The Digital Personal Data Protection Act, 2023 (DPDP Act) introduces a consent-centric framework for processing digital personal data. At the same time, commercial communications in India operate within the broader telecom regulatory framework administered by TRAI, while WhatsApp itself imposes opt-in and messaging requirements on businesses using its platform.

For enterprises, therefore, WhatsApp marketing is no longer simply a campaign-management problem.

It is increasingly a consent-governance problem.

1. Why WhatsApp Marketing Creates a DPDP Compliance Challenge

Consider a common scenario.

A customer applies for a loan through an NBFC’s website and provides:

  • Name
  • Mobile number
  • Email address
  • PAN
  • Income information
  • Employment details

The mobile number may have been collected primarily to:

  • verify the customer;
  • send an OTP;
  • process the application;
  • communicate the loan status; or
  • provide servicing information.

Three months later, the marketing team wants to send:

“You are eligible for our new personal loan offer. Apply now.”

Technically, the company already possesses the customer’s mobile number.

But possessing personal data and having an appropriate basis to process that data for a new purpose are different questions.

The key compliance question becomes:

What purpose was communicated when the mobile number was collected, and what valid basis does the organisation have for subsequently using it for promotional WhatsApp communication?

That distinction can fundamentally change how organisations design CRM, WhatsApp and consent-management architecture.

2. A Phone Number Is Personal Data

A mobile number that relates to an identifiable individual falls naturally within the concept of personal data under the DPDP framework.

When an organisation collects, stores, profiles, shares or uses that number to communicate with an individual, personal-data processing is involved.

WhatsApp marketing may additionally involve information such as:

  • customer’s name;
  • mobile number;
  • customer ID;
  • purchase history;
  • loan information;
  • demographic attributes;
  • location;
  • interests;
  • browsing activity;
  • campaign engagement;
  • CRM segments; and
  • behavioural profiles.

The compliance question therefore extends beyond sending the WhatsApp message itself.

Businesses should consider the entire lifecycle:

Collection → Purpose → Consent/Basis → Storage → Segmentation → Campaign → Delivery → Withdrawal → Suppression → Audit

3. Consent Under the DPDP Act

Where processing relies on consent, Section 6 of the DPDP Act establishes a high standard.

Consent is required to be:

  • free;
  • specific;
  • informed;
  • unconditional;
  • unambiguous; and
  • expressed through clear affirmative action.

It should also signify agreement to processing for the specified purpose, and only the personal data necessary for that purpose should be involved.

This matters enormously for marketing.

A broad statement such as:

“By submitting this form you agree to our Terms & Conditions.”

should not automatically be treated as equivalent to a clearly captured marketing preference.

A better approach is to make the purpose visible and understandable.

For example:

□ I agree to receive promotional offers and product updates from ABC Finance through WhatsApp.

The organisation can then retain evidence of that affirmative action.

4. Consent to Use a Service Is Not Automatically Consent to Marketing

This is one of the most important practical distinctions.

Imagine that a user provides a phone number to:

Purpose A

Receive an OTP.

The organisation should not simply assume that the same interaction establishes consent for:

Purpose B

Receive promotional WhatsApp campaigns.

Similarly, a customer giving a mobile number while purchasing insurance does not automatically mean every future promotional use of that number should be treated as covered.

Businesses should think in terms of purpose-specific processing.

Instead of:

Customer → Mobile Number → Marketing

the architecture should look more like:

Customer → Mobile Number → Purpose → Preference/Consent → Channel → Communication

For example:

Purpose WhatsApp SMS Email
Account alerts Yes Yes Yes
Transaction updates Yes Yes Yes
Promotional offers Yes No Yes
Partner offers No No No

This provides considerably stronger consent governance.

5. Service Communication and Marketing Communication Should Be Separated

Not every WhatsApp message is necessarily marketing.

Consider two messages.

Message 1 — Service Communication

“Your loan EMI payment of ₹12,450 has been received successfully.”

Message 2 — Promotional Communication

“Get an additional ₹2 lakh personal loan at a special rate. Apply today.”

The purposes are different.

The first relates to servicing an existing transaction or relationship.

The second promotes another commercial opportunity.

TRAI itself distinguishes service messages from promotional commercial communications within its commercial-communications framework.

Businesses should therefore classify communication before sending it.

A useful internal classification could be:

Transactional → Service → Regulatory → Security → Marketing → Cross-sell → Third-party Marketing

Each category can then have different processing rules and consent checks.

6. The Biggest Mistake: Uploading the Entire CRM Database to WhatsApp

A common marketing workflow looks like this:

CRM → Export Customer Numbers → Upload → Create Campaign → Send

From a privacy-governance perspective, this can create significant problems.

Suppose a company has 500,000 customer records.

The marketing team decides to send a WhatsApp campaign to all 500,000 customers.

But the CRM does not reliably tell the campaign system:

  • who agreed to marketing;
  • what they agreed to;
  • when consent was obtained;
  • through which channel;
  • whether the customer later withdrew consent;
  • whether the consent covered WhatsApp;
  • which version of the notice was shown; or
  • whether another valid processing basis applies.

The organisation now has a consent-evidence problem.

Instead of asking:

“Do we have this customer’s mobile number?”

the system should be capable of asking:

“Are we permitted to use this mobile number for this particular purpose through this particular channel at this point in time?”

That is a fundamentally different architecture.

7. What Should Valid WhatsApp Marketing Consent Capture?

A mature implementation should not merely store:

Marketing Consent = YES

It should maintain enough context to demonstrate what actually happened.

A consent record might contain:

Field Example
Data Principal ID DP-983472
Mobile Number +91-98XXXXXX10
Purpose Promotional Offers
Channel WhatsApp
Consent Status Active
Consent Timestamp 14 Aug 2026, 11:32 AM
Consent Source Website
Notice Version v3.2
Language Hindi
Consent Method Checkbox
Withdrawal Status Not Withdrawn
Withdrawal Timestamp
Evidence ID CONS-892831

This creates an auditable trail rather than simply maintaining a phone-number database.

8. The Consent Notice Matters

Consent should not exist independently of the information presented to the individual.

The notice should clearly explain the relevant processing.

For WhatsApp marketing, organisations should consider communicating:

Who is collecting the information?

The customer should understand the identity of the organisation.

What information will be used?

For example, name and mobile number.

Why will it be used?

For example, offers, promotions or product recommendations.

Which communication channel will be used?

For example, WhatsApp.

How can consent be withdrawn?

The mechanism should be easy and accessible.

This allows the customer to make a meaningful choice rather than being presented with an obscure legal statement.

9. Withdrawal Must Be Operational, Not Merely Written Into the Privacy Policy

One of the most important requirements in the DPDP consent framework is that withdrawing consent should be as easy as giving it.

This has major implications for WhatsApp.

Suppose the customer sends:

STOP

or changes their communication preferences through a privacy centre.

The organisation should not merely record the request in a customer-support ticket.

The withdrawal should propagate through the relevant systems.

For example:

WhatsApp → Preference Management → Consent Platform → CRM → Campaign Engine → Suppression List

The customer’s status could change:

WhatsApp Marketing: ACTIVE

to

WhatsApp Marketing: WITHDRAWN

Future campaigns should then automatically exclude the customer where the withdrawn consent was the relevant processing basis.

10. The Dangerous Gap Between CRM and Consent Systems

Many enterprises already operate:

  • Salesforce;
  • HubSpot;
  • Zoho;
  • Microsoft Dynamics;
  • custom CRM systems;
  • marketing automation platforms;
  • WhatsApp Business APIs;
  • call-centre applications; and
  • customer data platforms.

The problem is rarely the absence of customer data.

The problem is that these systems often do not maintain a centralised, purpose-specific consent state.

One system may say:

Customer = Active

Another:

WhatsApp = Available

Another:

Campaign Eligible = Yes

while the privacy system says:

Marketing Consent = Withdrawn

Without integration, the organisation can still contact the customer.

This is why consent needs to become an enterprise control layer, rather than merely a checkbox on a website.

11. Consent Validation Before Sending a WhatsApp Campaign

A stronger architecture introduces a validation step before communication.

Instead of:

CRM → WhatsApp

use:

CRM → Consent Validation → WhatsApp

Before sending a promotional message, the campaign engine can query:

Does Customer X currently have the appropriate permission for Purpose Y through Channel Z?

For example:

Customer: 9876543210
Purpose: Personal Loan Marketing
Channel: WhatsApp

Consent Status: ACTIVE

Result → Communication Allowed

Alternatively:

Customer: 9876543210
Purpose: Personal Loan Marketing
Channel: WhatsApp

Consent Status: WITHDRAWN

Result → Communication Blocked

This moves privacy controls from documentation into the technology layer.

12. Retrospective Consent: What About Existing Customer Databases?

This can be one of the hardest implementation challenges.

A business may already have millions of customer mobile numbers collected over many years.

But it may not have reliable records showing:

  • the purpose originally communicated;
  • whether marketing consent was captured;
  • which channels were selected;
  • the exact consent language;
  • the timestamp;
  • notice version; or
  • evidence of affirmative action.

Businesses should not solve this merely by changing the CRM field:

Consent = YES

Instead, organisations need a structured legacy-data and retrospective-consent strategy, considering the applicable legal basis and regulatory requirements.

The organisation may need to classify existing records into groups such as:

Verified consent

Reliable evidence exists.

Consent unclear

Some evidence exists but purpose/channel information is incomplete.

No evidence

Marketing permission cannot be reliably demonstrated.

Withdrawn

The individual has already opted out.

Such classification dramatically improves campaign governance.

13. TRAI Rules Also Matter

DPDP should not be analysed in isolation.

India already regulates commercial communications through TRAI’s Telecom Commercial Communications Customer Preference Regulations (TCCCPR), 2018 and related directions/frameworks.

TRAI describes consent as voluntary permission given by a customer to a sender to receive commercial communication relating to a specific purpose, product or service.

For commercial communications, TRAI’s framework includes requirements around sender/Principal Entity registration, headers, content templates and, where applicable, consent templates and customer consent.

TRAI also operates mechanisms through which customers can manage communication preferences and report unsolicited commercial communications.

Therefore, organisations should not assume:

DPDP compliant = automatically compliant with every commercial-communication requirement.

The relevant requirements should be evaluated together.

14. TRAI’s Movement Toward Verifiable Digital Consent Is Important

A particularly important development for enterprises is the regulatory movement toward digitally verifiable consent.

In June 2025, TRAI announced a pilot project for digital consent management in partnership with the RBI and selected banks.

TRAI highlighted a recurring problem: businesses sometimes claim that consumers previously consented to commercial communications, while the consent may have been collected through offline or otherwise difficult-to-verify mechanisms.

The digital-consent approach is intended to make consent records more secure and verifiable.

This points toward an important future principle:

Consent should not merely exist. Consent should be provable.

For enterprise systems, that means evidence and auditability should be designed into the architecture.

15. WhatsApp’s Own Opt-In Requirements Cannot Be Ignored

Privacy law is only one layer.

Businesses using WhatsApp also need to consider the platform’s own business messaging requirements.

TRAI consultation material discussing OTT communication platforms notes that WhatsApp requires business users to obtain opt-in consent before sending commercial communications.

Consequently, organisations running WhatsApp campaigns potentially need to think across multiple layers:

Layer 1 — DPDP

Is processing of the individual’s personal data lawful and appropriately governed?

Layer 2 — Commercial Communication Rules

Are applicable TRAI/TCCCPR requirements satisfied?

Layer 3 — WhatsApp Platform Requirements

Does the campaign comply with the platform’s opt-in and messaging requirements?

Layer 4 — Internal Governance

Can the organisation prove who approved the campaign and why each recipient was eligible?

16. Third-Party Lead Databases Create Even Greater Risk

Suppose a marketing agency approaches a company and says:

“We have 100,000 verified WhatsApp leads in your target market.”

This should immediately trigger compliance questions.

The company should ask:

  • Where were the numbers collected?
  • What notice was shown?
  • What exactly did individuals agree to?
  • Did consent identify the organisation that will contact them?
  • What purpose was stated?
  • Did consent cover WhatsApp?
  • Can the agency provide evidence?
  • Has anyone subsequently withdrawn?
  • Was the data lawfully shared?
  • How old is the consent?

Buying or receiving a phone-number list does not automatically create a compliant marketing audience.

17. Agency and Partner Marketing Needs Governance Too

Another common situation involves partners.

Imagine:

Bank → Marketing Agency → WhatsApp Provider → Customer

Multiple organisations may interact with the same personal data.

The enterprise should clearly establish:

  • who determines the purpose;
  • who processes data on whose behalf;
  • what information is shared;
  • what the processor is permitted to do;
  • retention requirements;
  • deletion obligations;
  • security responsibilities; and
  • what happens when consent is withdrawn.

A withdrawal received through one channel should not remain trapped there while other processors continue marketing.

18. Consent Should Be Granular

One universal checkbox is often inadequate for sophisticated organisations.

A better preference centre could allow customers to choose:

Communication Type

  • Service updates
  • Product announcements
  • Promotional offers
  • Surveys
  • Partner offers

Channel

  • WhatsApp
  • SMS
  • Email
  • Phone

Product

  • Loans
  • Credit cards
  • Insurance
  • Investments

This creates a preference structure that can be enforced technically.

For example:

WhatsApp + Loans + Promotions = YES
WhatsApp + Insurance + Promotions = NO
Email + Product Updates = YES
Partner Marketing = NO

The marketing system can then operate against the customer’s actual preferences.

19. What Happens When a Customer Withdraws Consent?

Suppose a customer withdraws WhatsApp marketing consent today.

The organisation should consider a workflow such as:

Step 1: Receive withdrawal request.

Step 2: Authenticate or reliably identify the customer where appropriate.

Step 3: Locate the relevant consent record.

Step 4: Change its status to withdrawn.

Step 5: Record timestamp and source.

Step 6: Update connected CRM and campaign systems.

Step 7: Add the customer to the appropriate suppression mechanism.

Step 8: Communicate the change to relevant processors.

Step 9: Prevent future processing based on the withdrawn consent unless another lawful basis applies.

Step 10: Maintain appropriate evidence of the withdrawal.

Automation is important because manual processes can leave gaps between systems.

20. WhatsApp Marketing Architecture for DPDP Readiness

A mature architecture could look like:

Website / Mobile App / Branch / CRM
                 ↓
          Consent Collection
                 ↓
          Consent Management
                 ↓
      Purpose + Channel Mapping
                 ↓
        Consent Validation API
                 ↓
 CRM / Campaign / Marketing Platform
                 ↓
          WhatsApp Business
                 ↓
              Customer
                 ↓
      Withdrawal / Preference Change
                 ↓
          Consent Management
                 ↓
     CRM + Suppression Synchronisation

The critical component is the consent validation layer.

Marketing systems should not independently decide whether personal data can be used for a campaign.

They should consume the organisation’s current consent and preference state.

21. Example: NBFC WhatsApp Marketing

Consider an NBFC with one million customers.

It wants to promote pre-approved loans through WhatsApp.

Traditional approach

CRM identifies eligible customers.

Marketing exports phone numbers.

Numbers are uploaded to WhatsApp campaign software.

Campaign sent.

Privacy-by-design approach

CRM identifies commercially eligible customers.

Consent platform checks each customer’s purpose and channel permissions.

Withdrawn/ineligible customers are suppressed.

Eligible audience is generated.

WhatsApp campaign is triggered.

Campaign evidence is recorded.

Future withdrawals automatically update campaign eligibility.

This introduces an important distinction:

Commercially Eligible ≠ Consent Eligible

A customer can qualify for a loan but still be ineligible for a particular marketing communication.

22. Example: Healthcare Organisation

Consider a diagnostic company.

A patient provides a phone number to receive:

  • appointment confirmation;
  • test status; and
  • diagnostic reports.

Later, the marketing team wants to send:

“Book our Full Body Health Package at 30% off.”

The original processing purpose may have been healthcare-service delivery rather than promotional marketing.

Healthcare organisations should therefore distinguish operational patient communications from promotional campaigns and evaluate the appropriate processing basis accordingly.

This is especially important because customer trust can be damaged even where a technically sophisticated marketing campaign performs well commercially.

23. Example: E-Commerce

An e-commerce customer provides a mobile number while checking out.

The company may need the number for:

  • OTP;
  • order confirmation;
  • shipping updates; and
  • delivery coordination.

That does not mean the organisation should treat the same interaction as unlimited permission for future marketing.

A mature checkout journey could separately offer:

Receive personalised offers and product updates on WhatsApp

□ Yes, keep me updated

The customer’s choice is then recorded separately from the transaction itself.

24. Seven Controls Every Enterprise Should Implement

1. Purpose-Specific Consent

Know exactly what the customer agreed to.

2. Channel-Level Preferences

Separate WhatsApp, SMS, email and voice preferences where appropriate.

3. Consent Evidence

Maintain timestamps, notice versions, sources and affirmative-action records.

4. Central Consent Repository

Avoid conflicting consent states across CRM and marketing applications.

5. Real-Time Validation

Check consent before triggering relevant marketing communications.

6. Automated Withdrawal

Propagate opt-outs across integrated systems.

7. Auditability

Be capable of demonstrating:

Who consented, when, how, for what purpose, through which channel, against which notice, and whether that consent was subsequently withdrawn.

25. WhatsApp Marketing DPDP Readiness Checklist

Before launching a WhatsApp marketing campaign, ask:

Data

  • Where did the mobile number come from?
  • Why was it originally collected?
  • Is its source documented?

Consent / Processing Basis

  • What is the applicable basis for this processing?
  • If relying on consent, was it affirmative?
  • Was the purpose clearly communicated?
  • Does it cover the proposed WhatsApp use?

Evidence

  • Can we demonstrate when consent was captured?
  • Can we retrieve the relevant notice?
  • Can we show which version the customer saw?

Campaign

  • Is this transactional, service or promotional?
  • Is the audience being checked against current preferences?
  • Are withdrawn customers suppressed?

Third Parties

  • Is an agency involved?
  • Is a WhatsApp/BSP provider involved?
  • Are appropriate processor and contractual controls in place?

Withdrawal

  • Can the customer easily opt out?
  • Does withdrawal propagate to all relevant systems?

Regulatory

  • Have applicable TRAI/TCCCPR obligations been considered?
  • Have applicable WhatsApp Business messaging requirements been checked?

If several of these questions cannot be answered, the organisation may have a consent-governance gap.

26. Moving From “Opt-Out” Marketing to Consent Governance

Historically, many marketing systems have operated around suppression:

Send communication unless the customer opts out.

Privacy-by-design architecture asks a more fundamental question:

Why is this individual eligible to receive this communication in the first place?

That requires marketing technology to understand:

Identity + Purpose + Channel + Preference + Consent Status + Evidence

The result is not merely better compliance.

It can improve:

  • customer trust;
  • campaign quality;
  • preference accuracy;
  • audit readiness;
  • data governance; and
  • marketing database hygiene.

27. How a Consent Management Platform Can Help

For enterprises managing thousands or millions of customers, spreadsheet-based consent management quickly becomes impractical.

A Consent Management Platform (CMP) can act as a control layer between customer-facing systems and downstream marketing applications.

For example, Digital Anumati can support an enterprise consent architecture where consent and privacy preferences are captured and governed across digital and enterprise touchpoints.

A typical implementation can connect:

Website / App / CRM / ERP / Offline Touchpoints

to

Digital Anumati Consent Management

and then integrate with:

WhatsApp / SMS / Email / CRM / Marketing Platforms

The objective is to enable organisations to manage capabilities such as:

  • purpose-specific consent;
  • channel preferences;
  • consent history;
  • withdrawal;
  • retrospective consent;
  • multilingual consent journeys;
  • API-based consent validation;
  • immutable/auditable consent records;
  • Data Principal Rights workflows; and
  • enterprise system integration.

The important architectural principle is simple:

Before personal data is activated for marketing, the system should be capable of validating whether the intended processing is permitted.

28. From Marketing Database to Consent-Aware Customer Database

The DPDP era can require organisations to rethink what a “customer database” actually represents.

The old model was:

Customer → Contact Information

The emerging model is:

Customer → Personal Data → Purpose → Consent/Basis → Preference → Processing Activity → Evidence

This distinction becomes especially important for channels such as WhatsApp because communication is immediate, personal and highly scalable.

Sending one inappropriate message is a customer-service issue.

Automatically sending millions of messages without effective purpose and consent governance becomes an enterprise privacy-risk issue.

Conclusion

WhatsApp marketing under India’s DPDP framework should not be reduced to adding an “I agree” checkbox.

The larger challenge is creating an architecture capable of answering, for every relevant communication:

Who is the customer?

Where did their data come from?

Why was it collected?

What processing are we proposing now?

What permission or other lawful basis supports that processing?

Which channel is being used?

Has the customer’s preference changed?

Can we prove the answer?

For businesses operating at scale, this means connecting consent management, CRM, marketing automation and communication channels rather than managing them as isolated systems.

The future of WhatsApp marketing in India is therefore not simply about sending more messages.

It is about sending the right communication, to the right individual, for the right purpose, backed by demonstrable governance.

Frequently Asked Questions

Is WhatsApp marketing illegal under the DPDP Act?

No. The DPDP Act does not create a blanket prohibition on WhatsApp marketing. Organisations need to ensure that the underlying processing of personal data has an appropriate legal basis and complies with applicable DPDP requirements, while also considering TRAI and platform-specific requirements.

Is having a customer’s phone number enough to send marketing messages?

Not necessarily. Having possession of a mobile number does not by itself establish that the organisation can use it for every subsequent purpose.

Should WhatsApp marketing consent be separate?

Where consent is the basis being relied upon, organisations should design consent so that the individual understands the specified purpose. Channel-level preferences can provide additional clarity and control.

Can existing customers receive promotional WhatsApp messages?

Existing customer status alone should not be treated as universal permission for every type of marketing processing. Organisations should assess the original collection purpose, applicable legal basis, customer preferences and relevant commercial-communication requirements.

What happens if a customer withdraws consent?

Where consent is withdrawn, the DPDP framework requires consequential processing based on that consent to cease, subject to processing required or authorised under applicable law. Businesses therefore need withdrawal mechanisms connected to downstream systems.

How should businesses prove marketing consent?

Maintain auditable evidence such as the purpose, consent status, timestamp, collection source, notice version, channel, affirmative action and withdrawal history.

Can a Consent Management Platform integrate with WhatsApp?

Yes. A CMP can sit between customer-data systems and communication platforms so that consent or preference status can be validated before relevant communications are triggered.

Disclaimer: This article is intended for general informational and technology-compliance awareness purposes and does not constitute legal advice. Organisations should assess their specific processing activities under the DPDP Act, applicable Rules, TRAI regulations and other applicable laws with qualified legal and privacy professionals.

Appointment