← All articles
WhatsApp Business API

DPDP and WhatsApp Marketing: Consent, Notice and Withdrawal

27 Aug 2026

Approx 11 min read

Chethan Kumar

Founder & CEO, Emovur

Table of contents

Share

DPDP compliance for WhatsApp marketing in India requires businesses to rethink how customer numbers are collected, why they are used, how permission is recorded and how easily people can stop future communication. As of August 2026, the DPDP Act and Rules are in phased implementation, while Meta already requires WhatsApp opt-in and respect for opt-outs. Businesses should therefore build documented, purpose-specific consent, clear privacy notices and reliable withdrawal controls now rather than waiting for the remaining DPDP provisions to commence.

What Is the DPDP Position for WhatsApp Marketing in August 2026?

The Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 now form India's principal framework for digital personal data, but their commencement is phased.

The Government notified the Rules on 13 November 2025. The commencement notification provides that major provisions covering lawful processing, notice, consent, Data Fiduciary obligations and Data Principal rights come into force 18 months after 13 November 2025. Rule 3, which contains the detailed notice requirements, follows the same 18-month commencement schedule.

Practical timeline

Compliance Area

Position on 27 Aug 2026

DPDP Act and Rules notified

Yes

Data Protection Board established

Yes

18-month compliance transition

In progress

Core DPDP consent provisions

Scheduled for 13 May 2027

Detailed Rule 3 notice requirements

Scheduled for 13 May 2027

Consent Manager provisions

Scheduled earlier, from 13 Nov 2026

WhatsApp customer opt-in requirement

Already applicable under Meta policy

WhatsApp opt-out requests

Must already be respected

This matters because businesses should not describe every future DPDP obligation as if it were already legally operative today.At the same time, waiting until May 2027 to clean up marketing consent would be poor operational planning.

Meta already requires businesses to have both the person's number and opt-in permission to receive subsequent WhatsApp messages or calls, and businesses must honour requests to stop communications.

Under the DPDP consent standard scheduled to apply after the transition period, consent must be free, specific, informed, unconditional and unambiguous, expressed through clear affirmative action and limited to the personal data necessary for the stated purpose. For WhatsApp marketing, businesses should therefore avoid vague permission such as “I agree to communications” and instead clearly state that the customer is agreeing to receive specific WhatsApp communication from the named business.

The important SEO and compliance phrase here is WhatsApp marketing consent in India. A mobile number appearing inside your CRM does not automatically equal permission to send promotional WhatsApp messages.

  • Who consented? Identify the customer or Data Principal linked to the phone number.

  • Which business received consent? Permission should clearly relate to the business sending the communication.

  • Which channel was approved? If WhatsApp is going to be used, make that clear instead of relying only on generic “marketing communication” wording.

  • What was the purpose? State whether the person is agreeing to offers, product updates, appointment communication, order updates or another defined purpose.

  • How was consent given? Website checkbox, checkout, WhatsApp interaction, QR journey, form or another affirmative action.

  • When was it given? Retain a timestamp where technically possible.

  • What wording did the user see? Store the relevant consent version rather than merely maintaining a Boolean “opted in” field.

Meta's own best-practice guidance recommends obtaining opt-in that reflects the categories of messages being sent and says separate opt-in by message category can reduce the risk of unwanted communication.

A DPDP-aligned consent notice should make it clear what personal data the business will process, the specific purpose for using it and how the individual can exercise relevant rights or withdraw permission. The final Rule 3 requires notices to be independently understandable, written in clear language and to identify the personal data and specified purposes. Businesses should build this clarity directly into WhatsApp opt-in journeys instead of hiding it inside a broad privacy policy. A consent experience does not need to become a page of legal language.

It needs to be understandable.

For a WhatsApp marketing opt-in, communicate:

  • Business identity: Tell the user which business will message them.

  • Channel: Explicitly mention WhatsApp.

  • Purpose: State the kinds of communication they should expect.

  • Data involved: Explain what relevant personal information is being collected or used.

  • Frequency expectation: Where appropriate, indicate the general nature or frequency of marketing.

  • Withdrawal method: Tell the customer how they can stop promotional communication.

  • Privacy access: Provide access to more detailed privacy information where necessary.

“I agree to receive updates.”

This leaves several questions unanswered.

Updates from whom?

Through which channel?

Marketing updates or transaction updates?

Better structure

“I agree to receive relevant product offers and promotional updates from [Business] on WhatsApp. I can withdraw my preference at any time.”

The exact wording should be reviewed against the organisation's legal requirements and actual data practices rather than copied blindly from an example.

3. Can a Business Use an Existing Customer Database for WhatsApp Marketing?

An existing phone-number database should not automatically be treated as a WhatsApp marketing list. Businesses need to understand why each number was originally collected, what communication the customer agreed to receive and whether WhatsApp marketing was within that expectation. Meta independently requires WhatsApp opt-in before business messaging. Where consent evidence is missing, businesses should avoid simply importing the database and treating every contact as marketable. This is one of the most important operational issues for Indian businesses.

A database may contain:

  • Website enquiries

  • Previous customers

  • Event attendees

  • Offline store customers

  • Download leads

  • Meta advertising leads

  • CRM imports

  • Old marketing lists

  • Partner-generated leads

  • Purchased or third-party lists

These sources do not carry identical consent.

Before using an existing database, classify contacts by:

  • Collection source: Where did the number originate?

  • Original purpose: Why did the customer provide it?

  • WhatsApp permission: Was WhatsApp communication explicitly expected?

  • Marketing permission: Did the customer agree to promotional communication?

  • Consent evidence: Can the business demonstrate when and how permission was obtained?

  • Current preference: Has the person subsequently opted out?

  • Data age: Is the information still relevant to the purpose for which it was collected?

A useful internal status model is:

Verified WhatsApp Marketing Opt-In → Eligible

Transactional / Service Permission Only → Do Not Treat as Marketing Consent

Unknown Consent → Review / Re-Permission

Opted Out → Suppress

Invalid / Unusable Data → Remove

This is much safer than uploading the complete CRM database into a WhatsApp broadcast campaign.

DPDP provides that when consent is the basis of processing, the Data Principal must be able to withdraw it at any time, with comparable ease to how consent was originally given. Meta separately requires businesses to honour requests to discontinue or opt out of WhatsApp communication. A compliant operating model therefore needs a withdrawal mechanism that updates the customer's status across campaigns, CRM records and connected automation—not merely one campaign list.

This is where many marketing systems fail.

A customer sends:

STOP

or asks a sales agent:

“Please don't send promotional WhatsApp messages.”

The agent stops messaging them manually, but the number remains active in the marketing automation database.

The next broadcast reaches the same customer.

That is not a withdrawal system.

A better withdrawal workflow is:

Customer Opt-Out → Preference Recorded → Marketing Suppression Updated → Automations Checked → Future Marketing Stopped

Your system should consider:

  • WhatsApp replies: Recognise clear requests to stop marketing.

  • Agent-recorded requests: Allow employees to update customer preferences.

  • Website preferences: Synchronise changes made through account or privacy pages.

  • CRM suppression: Prevent the contact from being accidentally re-added.

  • Campaign tools: Exclude opted-out customers automatically.

  • Re-opt-in: Require a new affirmative action before promotional WhatsApp communication resumes.

The DPDP Act also places the burden on the Data Fiduciary to prove that valid notice and consent existed where the question arises in a proceeding. That makes consent evidence as important as the opt-in itself.

This distinction deserves attention.DPDP governs the processing of digital personal data in India.Meta governs use of its WhatsApp Business Services.

Businesses operating WhatsApp business marketing therefore need to consider both layers.

Requirement

DPDP Framework

WhatsApp Policy

Lawful personal-data processing

Yes

Not the primary function

Clear purpose

Yes

Strongly relevant

Consent standard

Defined by Act

Opt-in required

WhatsApp-specific permission

Not platform-specific

Yes

Respect withdrawal

Yes where consent applies

Yes

Message-category expectations

Purpose-specific processing

Recommended opt-in by category

Platform enforcement

No

Yes

Legal/regulatory enforcement

DPDP framework

Separate from Meta enforcement

Meta states that businesses may contact people on WhatsApp only when they have their number and opt-in permission, and that requests to stop or opt out must be respected whether made on or off WhatsApp.

This means legal compliance alone does not remove platform obligations.

What Should a DPDP-Ready WhatsApp Marketing Database Store?

For 2026 preparation, businesses should stop thinking of consent as a single checkbox.

Treat it as a data object.

  • Customer/contact ID

  • WhatsApp number

  • Opt-in status

  • Consent source

  • Consent timestamp

  • Consent purpose

  • Message categories permitted

  • Consent-text/version reference

  • Privacy-notice version

  • Withdrawal status

  • Withdrawal date

  • Re-opt-in date where applicable

This creates an audit trail that can support both compliance and better campaign segmentation. It also prevents situations where a salesperson imports an old spreadsheet and accidentally reactivates customers who previously unsubscribed.

Build Separate Marketing and Service Preferences

An important operational improvement is separating different communication purposes. A customer who wants an order update does not necessarily want promotional broadcasts. A patient requesting an appointment does not automatically indicate interest in marketing campaigns. A property buyer requesting information about one project does not necessarily expect indefinite promotional messages about unrelated projects.

A better preference architecture can distinguish:

  • Transactional updates

  • Service communication

  • Appointment communication

  • Product recommendations

  • Promotional offers

  • Event announcements

  • Sales follow-up

Meta's policy encourages businesses to obtain opt-ins covering the different message categories they intend to send. Purpose separation also aligns more naturally with the DPDP concept of consent for a specified purpose.

A Practical DPDP + WhatsApp Marketing Workflow

A compliant marketing process should begin before the first broadcast.

Stage

Control

Lead collection

Explain why the number is collected

WhatsApp opt-in

Capture affirmative permission

Notice

State business, purpose and relevant data use

Consent record

Store source, date, purpose and version

Segmentation

Send only relevant communication

Campaign

Use approved WhatsApp messaging processes

Customer response

Capture preference changes

Withdrawal

Suppress future marketing

Re-opt-in

Require affirmative permission again

Audit

Regularly review consent quality and old data

Businesses implementing the communication layer can evaluate WhatsApp Business API capabilities separately. This article's purpose is the consent and privacy operating model, not platform selection.

Four Questions Businesses Ask About DPDP and WhatsApp Marketing

DPDP establishes consent as one basis for processing personal data, alongside certain legitimate uses defined by the Act. However, businesses should not assume a non-consent DPDP basis automatically permits promotional WhatsApp messaging because Meta independently requires WhatsApp opt-in. As of August 2026, the principal DPDP consent provisions are scheduled to commence on 13 May 2027, while Meta's opt-in policy applies today.

Not automatically. A website enquiry shows that the user contacted the business for a particular purpose, but that does not necessarily establish permission for unrelated promotional WhatsApp campaigns. Businesses should evaluate what the user was told at collection and what they affirmatively agreed to receive. If WhatsApp marketing is intended, the opt-in experience should make that purpose and channel clear.

Businesses should maintain reliable consent records. The DPDP Act provides that where consent is relied upon and a question arises, the Data Fiduciary must be able to prove that the required notice was provided and consent obtained. Operationally, storing the source, time, purpose and consent version also helps prevent incorrect campaign inclusion and makes opt-out management more reliable.

What happens when someone opts out of WhatsApp marketing?

Future promotional WhatsApp messaging to that person should stop unless they later provide a valid new opt-in. Meta expressly requires businesses to honour requests to discontinue or opt out, including requests made outside WhatsApp. A robust system should update the customer's preference centrally so CRM imports, broadcasts and automated workflows cannot unintentionally add the person back to marketing campaigns.

Frequently Asked Questions

Can businesses send WhatsApp marketing to previous customers?

Previous purchase history alone should not automatically be treated as permission for indefinite promotional WhatsApp communication. Review the original collection purpose, consent record and current Meta opt-in requirements.

A privacy policy can provide supporting information, but relying only on a long privacy policy may not create the clear, specific affirmative consent contemplated by DPDP or the explicit WhatsApp opt-in required by Meta.

Businesses should design preference systems to distinguish communication purposes where practical. A customer may want transaction or service information while no longer wanting promotional communication.

Can a business buy a database and use it for WhatsApp campaigns?

A purchased number list should not be assumed to contain valid WhatsApp opt-in for your business. Meta requires the recipient to have opted in to receive messages from the business contacting them.

Prepare Before the DPDP Transition Ends

The key date for many core DPDP obligations is 13 May 2027, but the operational work should happen earlier.

Businesses using WhatsApp marketing should use the transition period to:

  • Audit existing customer databases.

  • Separate marketing and transactional permissions.

  • Rewrite vague consent language.

  • Record the source and purpose of WhatsApp opt-ins.

  • Create reliable opt-out suppression.

  • Synchronise consent across CRM and marketing systems.

  • Review old customer lists before future broadcasts.

  • Train marketing and sales teams not to treat every phone number as promotional consent.

For companies implementing WhatsApp communication infrastructure, Emovur's WhatsApp Business API can be evaluated separately from the privacy and legal requirements governing how customer data and marketing permissions are managed.

Check Setup Requirements — but build consent, notice and withdrawal into the customer journey before scaling WhatsApp marketing.

This article provides general compliance information and is not a substitute for legal advice tailored to a specific organisation or use case.

Emovur blog CTA

Grow your business with Emovur

Discover practical WhatsApp growth playbooks, automation ideas, and high-conversion campaign strategies.

Explore Emovur