DPDP and WhatsApp Marketing: Consent, Notice and Withdrawal
DPDP compliance for WhatsApp marketing in India requires businesses to rethink how customer numbers are collected, why they are used, how permission is recorded and how easily people can stop future communication. As of August 2026, the DPDP Act and Rules are in phased implementation, while Meta already requires WhatsApp opt-in and respect for opt-outs. Businesses should therefore build documented, purpose-specific consent, clear privacy notices and reliable withdrawal controls now rather than waiting for the remaining DPDP provisions to commence.
What Is the DPDP Position for WhatsApp Marketing in August 2026?
The Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 now form India's principal framework for digital personal data, but their commencement is phased.
The Government notified the Rules on 13 November 2025. The commencement notification provides that major provisions covering lawful processing, notice, consent, Data Fiduciary obligations and Data Principal rights come into force 18 months after 13 November 2025. Rule 3, which contains the detailed notice requirements, follows the same 18-month commencement schedule.
Practical timeline
Compliance Area | Position on 27 Aug 2026 |
DPDP Act and Rules notified | Yes |
Data Protection Board established | Yes |
18-month compliance transition | In progress |
Core DPDP consent provisions | Scheduled for 13 May 2027 |
Detailed Rule 3 notice requirements | Scheduled for 13 May 2027 |
Consent Manager provisions | Scheduled earlier, from 13 Nov 2026 |
WhatsApp customer opt-in requirement | Already applicable under Meta policy |
WhatsApp opt-out requests | Must already be respected |
This matters because businesses should not describe every future DPDP obligation as if it were already legally operative today.At the same time, waiting until May 2027 to clean up marketing consent would be poor operational planning.
Meta already requires businesses to have both the person's number and opt-in permission to receive subsequent WhatsApp messages or calls, and businesses must honour requests to stop communications.
1. What Counts as Valid Consent for WhatsApp Marketing Under DPDP?
Under the DPDP consent standard scheduled to apply after the transition period, consent must be free, specific, informed, unconditional and unambiguous, expressed through clear affirmative action and limited to the personal data necessary for the stated purpose. For WhatsApp marketing, businesses should therefore avoid vague permission such as “I agree to communications” and instead clearly state that the customer is agreeing to receive specific WhatsApp communication from the named business.
The important SEO and compliance phrase here is WhatsApp marketing consent in India. A mobile number appearing inside your CRM does not automatically equal permission to send promotional WhatsApp messages.
A strong consent record should answer:
Who consented? Identify the customer or Data Principal linked to the phone number.
Which business received consent? Permission should clearly relate to the business sending the communication.
Which channel was approved? If WhatsApp is going to be used, make that clear instead of relying only on generic “marketing communication” wording.
What was the purpose? State whether the person is agreeing to offers, product updates, appointment communication, order updates or another defined purpose.
How was consent given? Website checkbox, checkout, WhatsApp interaction, QR journey, form or another affirmative action.
When was it given? Retain a timestamp where technically possible.
What wording did the user see? Store the relevant consent version rather than merely maintaining a Boolean “opted in” field.
Meta's own best-practice guidance recommends obtaining opt-in that reflects the categories of messages being sent and says separate opt-in by message category can reduce the risk of unwanted communication.
2. What Should a WhatsApp Marketing Consent Notice Say?
A DPDP-aligned consent notice should make it clear what personal data the business will process, the specific purpose for using it and how the individual can exercise relevant rights or withdraw permission. The final Rule 3 requires notices to be independently understandable, written in clear language and to identify the personal data and specified purposes. Businesses should build this clarity directly into WhatsApp opt-in journeys instead of hiding it inside a broad privacy policy. A consent experience does not need to become a page of legal language.
It needs to be understandable.
For a WhatsApp marketing opt-in, communicate:
Business identity: Tell the user which business will message them.
Channel: Explicitly mention WhatsApp.
Purpose: State the kinds of communication they should expect.
Data involved: Explain what relevant personal information is being collected or used.
Frequency expectation: Where appropriate, indicate the general nature or frequency of marketing.
Withdrawal method: Tell the customer how they can stop promotional communication.
Privacy access: Provide access to more detailed privacy information where necessary.
Weak consent
“I agree to receive updates.”
This leaves several questions unanswered.
Updates from whom?
Through which channel?
Marketing updates or transaction updates?
Better structure
“I agree to receive relevant product offers and promotional updates from [Business] on WhatsApp. I can withdraw my preference at any time.”
The exact wording should be reviewed against the organisation's legal requirements and actual data practices rather than copied blindly from an example.
3. Can a Business Use an Existing Customer Database for WhatsApp Marketing?
An existing phone-number database should not automatically be treated as a WhatsApp marketing list. Businesses need to understand why each number was originally collected, what communication the customer agreed to receive and whether WhatsApp marketing was within that expectation. Meta independently requires WhatsApp opt-in before business messaging. Where consent evidence is missing, businesses should avoid simply importing the database and treating every contact as marketable. This is one of the most important operational issues for Indian businesses.
A database may contain:
Website enquiries
Previous customers
Event attendees
Offline store customers
Download leads
Meta advertising leads
CRM imports
Old marketing lists
Partner-generated leads
Purchased or third-party lists
These sources do not carry identical consent.
Before using an existing database, classify contacts by:
Collection source: Where did the number originate?
Original purpose: Why did the customer provide it?
WhatsApp permission: Was WhatsApp communication explicitly expected?
Marketing permission: Did the customer agree to promotional communication?
Consent evidence: Can the business demonstrate when and how permission was obtained?
Current preference: Has the person subsequently opted out?
Data age: Is the information still relevant to the purpose for which it was collected?
A useful internal status model is:
Verified WhatsApp Marketing Opt-In → Eligible
Transactional / Service Permission Only → Do Not Treat as Marketing Consent
Unknown Consent → Review / Re-Permission
Opted Out → Suppress
Invalid / Unusable Data → Remove
This is much safer than uploading the complete CRM database into a WhatsApp broadcast campaign.
4. How Should Businesses Handle WhatsApp Consent Withdrawal?
DPDP provides that when consent is the basis of processing, the Data Principal must be able to withdraw it at any time, with comparable ease to how consent was originally given. Meta separately requires businesses to honour requests to discontinue or opt out of WhatsApp communication. A compliant operating model therefore needs a withdrawal mechanism that updates the customer's status across campaigns, CRM records and connected automation—not merely one campaign list.
This is where many marketing systems fail.
A customer sends:
STOP
or asks a sales agent:
“Please don't send promotional WhatsApp messages.”
The agent stops messaging them manually, but the number remains active in the marketing automation database.
The next broadcast reaches the same customer.
That is not a withdrawal system.
A better withdrawal workflow is:
Customer Opt-Out → Preference Recorded → Marketing Suppression Updated → Automations Checked → Future Marketing Stopped
Your system should consider:
WhatsApp replies: Recognise clear requests to stop marketing.
Agent-recorded requests: Allow employees to update customer preferences.
Website preferences: Synchronise changes made through account or privacy pages.
CRM suppression: Prevent the contact from being accidentally re-added.
Campaign tools: Exclude opted-out customers automatically.
Re-opt-in: Require a new affirmative action before promotional WhatsApp communication resumes.
The DPDP Act also places the burden on the Data Fiduciary to prove that valid notice and consent existed where the question arises in a proceeding. That makes consent evidence as important as the opt-in itself.
DPDP Consent and Meta WhatsApp Opt-In Are Not the Same Thing
This distinction deserves attention.DPDP governs the processing of digital personal data in India.Meta governs use of its WhatsApp Business Services.
Businesses operating WhatsApp business marketing therefore need to consider both layers.
Requirement | DPDP Framework | WhatsApp Policy |
Lawful personal-data processing | Yes | Not the primary function |
Clear purpose | Yes | Strongly relevant |
Consent standard | Defined by Act | Opt-in required |
WhatsApp-specific permission | Not platform-specific | Yes |
Respect withdrawal | Yes where consent applies | Yes |
Message-category expectations | Purpose-specific processing | Recommended opt-in by category |
Platform enforcement | No | Yes |
Legal/regulatory enforcement | DPDP framework | Separate from Meta enforcement |
Meta states that businesses may contact people on WhatsApp only when they have their number and opt-in permission, and that requests to stop or opt out must be respected whether made on or off WhatsApp.
This means legal compliance alone does not remove platform obligations.
What Should a DPDP-Ready WhatsApp Marketing Database Store?
For 2026 preparation, businesses should stop thinking of consent as a single checkbox.
Treat it as a data object.
Recommended consent fields include:
Customer/contact ID
WhatsApp number
Opt-in status
Consent source
Consent timestamp
Consent purpose
Message categories permitted
Consent-text/version reference
Privacy-notice version
Withdrawal status
Withdrawal date
Re-opt-in date where applicable
This creates an audit trail that can support both compliance and better campaign segmentation. It also prevents situations where a salesperson imports an old spreadsheet and accidentally reactivates customers who previously unsubscribed.
Build Separate Marketing and Service Preferences
An important operational improvement is separating different communication purposes. A customer who wants an order update does not necessarily want promotional broadcasts. A patient requesting an appointment does not automatically indicate interest in marketing campaigns. A property buyer requesting information about one project does not necessarily expect indefinite promotional messages about unrelated projects.
A better preference architecture can distinguish:
Transactional updates
Service communication
Appointment communication
Product recommendations
Promotional offers
Event announcements
Sales follow-up
Meta's policy encourages businesses to obtain opt-ins covering the different message categories they intend to send. Purpose separation also aligns more naturally with the DPDP concept of consent for a specified purpose.
A Practical DPDP + WhatsApp Marketing Workflow
A compliant marketing process should begin before the first broadcast.
Stage | Control |
Lead collection | Explain why the number is collected |
WhatsApp opt-in | Capture affirmative permission |
Notice | State business, purpose and relevant data use |
Consent record | Store source, date, purpose and version |
Segmentation | Send only relevant communication |
Campaign | Use approved WhatsApp messaging processes |
Customer response | Capture preference changes |
Withdrawal | Suppress future marketing |
Re-opt-in | Require affirmative permission again |
Audit | Regularly review consent quality and old data |
Businesses implementing the communication layer can evaluate WhatsApp Business API capabilities separately. This article's purpose is the consent and privacy operating model, not platform selection.
Four Questions Businesses Ask About DPDP and WhatsApp Marketing
Does DPDP require consent for WhatsApp marketing in India?
DPDP establishes consent as one basis for processing personal data, alongside certain legitimate uses defined by the Act. However, businesses should not assume a non-consent DPDP basis automatically permits promotional WhatsApp messaging because Meta independently requires WhatsApp opt-in. As of August 2026, the principal DPDP consent provisions are scheduled to commence on 13 May 2027, while Meta's opt-in policy applies today.
Is a website enquiry enough consent for WhatsApp marketing?
Not automatically. A website enquiry shows that the user contacted the business for a particular purpose, but that does not necessarily establish permission for unrelated promotional WhatsApp campaigns. Businesses should evaluate what the user was told at collection and what they affirmatively agreed to receive. If WhatsApp marketing is intended, the opt-in experience should make that purpose and channel clear.
Do businesses need to keep proof of WhatsApp consent?
Businesses should maintain reliable consent records. The DPDP Act provides that where consent is relied upon and a question arises, the Data Fiduciary must be able to prove that the required notice was provided and consent obtained. Operationally, storing the source, time, purpose and consent version also helps prevent incorrect campaign inclusion and makes opt-out management more reliable.
What happens when someone opts out of WhatsApp marketing?
Future promotional WhatsApp messaging to that person should stop unless they later provide a valid new opt-in. Meta expressly requires businesses to honour requests to discontinue or opt out, including requests made outside WhatsApp. A robust system should update the customer's preference centrally so CRM imports, broadcasts and automated workflows cannot unintentionally add the person back to marketing campaigns.
Frequently Asked Questions
Can businesses send WhatsApp marketing to previous customers?
Previous purchase history alone should not automatically be treated as permission for indefinite promotional WhatsApp communication. Review the original collection purpose, consent record and current Meta opt-in requirements.
Can WhatsApp marketing consent be included in a privacy policy?
A privacy policy can provide supporting information, but relying only on a long privacy policy may not create the clear, specific affirmative consent contemplated by DPDP or the explicit WhatsApp opt-in required by Meta.
Can a user withdraw only marketing consent but keep service messages?
Businesses should design preference systems to distinguish communication purposes where practical. A customer may want transaction or service information while no longer wanting promotional communication.
Can a business buy a database and use it for WhatsApp campaigns?
A purchased number list should not be assumed to contain valid WhatsApp opt-in for your business. Meta requires the recipient to have opted in to receive messages from the business contacting them.
Prepare Before the DPDP Transition Ends
The key date for many core DPDP obligations is 13 May 2027, but the operational work should happen earlier.
Businesses using WhatsApp marketing should use the transition period to:
Audit existing customer databases.
Separate marketing and transactional permissions.
Rewrite vague consent language.
Record the source and purpose of WhatsApp opt-ins.
Create reliable opt-out suppression.
Synchronise consent across CRM and marketing systems.
Review old customer lists before future broadcasts.
Train marketing and sales teams not to treat every phone number as promotional consent.
For companies implementing WhatsApp communication infrastructure, Emovur's WhatsApp Business API can be evaluated separately from the privacy and legal requirements governing how customer data and marketing permissions are managed.
Check Setup Requirements — but build consent, notice and withdrawal into the customer journey before scaling WhatsApp marketing.
This article provides general compliance information and is not a substitute for legal advice tailored to a specific organisation or use case.

Grow your business with Emovur
Discover practical WhatsApp growth playbooks, automation ideas, and high-conversion campaign strategies.
Explore Emovur