Scope, and an Honest Caveat
This is a practical operational guide, not legal advice. The Digital Personal Data Protection Act (DPDP) and its rules carry real penalties, and how they apply depends on your business. If you process significant volumes of personal data, get advice from a qualified practitioner.
What this article covers is the part most WhatsApp guidance skips: what DPDP means for the way you actually collect numbers, send messages, and store conversations.
How DPDP Differs From "WhatsApp Opt-In"
Meta's own policies already require opt-in before messaging. Teams therefore assume that satisfying WhatsApp satisfies the law. It does not, because DPDP asks for different things:
- Meta cares that the person agreed to be messaged.
- DPDP cares that you can demonstrate valid consent for a specified purpose, that you collected no more than you needed, that you can delete it on request, and that you told the person all of this in clear language.
The practical gap: a business can be fully compliant with WhatsApp's opt-in rules and still be unable to answer "when did this person consent, to what, and how do I prove it" — which is the question that matters under DPDP.
What DPDP Requires, in Operational Terms
1. Consent must be specific, informed and recorded
A pre-ticked box or a buried line in your terms is not consent. You need a clear affirmative action, tied to a stated purpose, in plain language.
What to do: at every point you collect a number — website form, checkout, QR code, in-store — state what you will send and why. Then store the evidence: timestamp, the exact wording shown, the source, and the purposes agreed. This is the record you need to produce later.
"Purpose" matters: consent to receive order updates is not consent to receive marketing. If you want both, ask for both, separately.
2. Notice in clear language
At or before collection, tell people what you collect, why, how to withdraw consent, and how to complain. It has to be understandable — and available in English and, on request, the languages in the Eighth Schedule of the Constitution.
3. Withdrawal must be as easy as consent
If a tap opted them in, a tap must opt them out. In practice: an opt-out option in marketing messages, honoured immediately and permanently, plus a route to withdraw consent entirely.
Withdrawal should stop marketing but does not necessarily block transactional messages the person still needs — separate your consent purposes so you can honour this precisely rather than all-or-nothing.
4. Purpose limitation and data minimisation
Collect what you need for the stated purpose, and use it only for that. Two habits to break: gathering fields "in case they are useful later", and reusing a support-only contact list for a marketing campaign. The second is a common and material violation.
5. Erasure on request, and retention limits
People can ask you to delete their data, and you must be able to do it — including conversation history. You should also delete data once its purpose is served rather than keeping conversations indefinitely by default.
What to do: know how to find and delete one person's data across contacts, conversations and exports. Test it. Many teams discover their process only when a request arrives.
6. Breach notification
Personal data breaches must be reported to the Data Protection Board and affected people. Know who decides and who reports before you need to.
7. Children's data
Processing data of under-18s requires verifiable parental consent, and behavioural advertising to children is prohibited. Relevant if you are in education, gaming, or youth retail.
WhatsApp-Specific Practicalities
- Your provider is a data processor. You remain the Data Fiduciary — accountable for what happens to the data. Check your provider's terms, security posture and sub-processors, and where data is stored.
- Template categories align with consent purposes. Utility templates for transactional messages, marketing templates for promotion, sent only to people who consented to marketing. Getting this right serves both Meta's rules and DPDP.
- Imported lists are the highest-risk thing you can do. A purchased or scraped list has no consent record, and no amount of careful sending fixes that. It is also the fastest route to a ban — see number restriction recovery.
- Conversation history is personal data. Retention and deletion policies apply to your inbox, not just your CRM.
- Exports leak. A contacts CSV in someone's downloads folder is a breach waiting to happen. Control who can export.
A Practical Checklist
- Every collection point states purpose in plain language, with separate marketing consent
- Consent records store timestamp, wording, source and purposes
- A privacy notice exists, is linked at collection, and is readable
- Opt-out appears in marketing messages and is honoured immediately
- You can delete one individual's data across contacts and conversations, and have tested it
- Retention periods are defined, per data type, rather than "forever"
- Marketing sends draw only from marketing-consented segments
- Provider terms, storage location and sub-processors reviewed
- Export permissions restricted to people who need them
- A named person owns breach response
- No purchased, scraped or otherwise unconsented lists anywhere in the system
How Tenreply Helps
Custom fields can record consent source, timestamp and purposes on each contact, so the evidence lives with the record. Tags and segments let you separate marketing-consented contacts from transactional-only ones so a campaign cannot accidentally include the wrong people. Contacts and conversations can be exported and deleted per individual for access and erasure requests, and role-based access limits who can export. See our security page and privacy policy for how we handle data as a processor.
Frequently Asked Questions
Does DPDP apply to a small business?
Yes — it applies to processing digital personal data, with some obligations scaled for Significant Data Fiduciaries. Size reduces some requirements; it does not exempt you from consent, notice and erasure.
Is WhatsApp opt-in enough for DPDP?
No. Meta's opt-in requirement overlaps with DPDP consent but does not satisfy it — DPDP additionally requires purpose specificity, notice, demonstrable records, erasure and retention limits.
Do I need consent for transactional messages like order updates?
You need a lawful basis and a clearly stated purpose. Order updates for a purchase the person made are far more defensible than promotional messages, but they should still be covered by the purpose you stated at collection.
How long can I keep WhatsApp conversation history?
As long as the stated purpose requires, and no longer by default. Define a retention period per data type and apply it — indefinite retention of everything is the pattern DPDP is aimed at.
What about customers outside India?
Other regimes may apply — see our GDPR guide for EU contacts. The good news is that the underlying practices largely overlap.
Start With Consent Records
If you do one thing, make it this: record timestamp, wording, source and purpose at every point you collect a number, and separate marketing consent from transactional. Almost every other DPDP obligation becomes straightforward once that record exists — and it happens to make your messaging perform better too, because you stop sending to people who never asked. Related reading: the opt-in guide and WhatsApp marketing rules in India.
