WhatsApp Business API

Is bulk WhatsApp marketing legal in India?

Editorial Team 5 min read

Sending marketing messages on WhatsApp is not illegal in India. Sending them to people who did not agree to receive them is a different matter, and it exposes you to three separate rulebooks: India’s data protection law, Meta’s own platform policies, and — potentially in future — telecom regulation.

The one that will actually stop your business is the second, because Meta can restrict your number tomorrow without any legal process at all.

Most articles treat this as one question. It is three, and they behave very differently.

Which rulebook will actually stop you?

Meta’s. Not the law, and not eventually — now.

You can be entirely compliant with Indian law and still lose your WhatsApp account, because Meta enforces its own policies on its own timescale with no notice period. Blocks and reports lower your quality rating. A poor rating reduces how many people you may message. Persistent problems restrict the number altogether.

There is no regulator to appeal to, and your customers are on the other side of that number. For most businesses the practical order is: platform rules bite first and hardest, data protection obligations bite later but carry real financial consequences, and telecom regulation does not bite yet.

We have written separately about what lowers a quality rating.

Where does India’s data protection law stand?

The Digital Personal Data Protection Act was passed in 2023. Its rules have since been notified, and the framework is being introduced in phases rather than all at once — the body that oversees it is already in place, while the substantive obligations on businesses come into force later.

Check the current position on the Ministry of Electronics and Information Technology’s own site rather than relying on any summary, including this one.

But the phasing matters far less than it appears to, for one reason: consent cannot be applied retrospectively.

Every contact added to your list from today onwards either has a proper consent record or does not, and you cannot go back afterwards and create one. A business that starts recording consent properly now arrives at full enforcement with a database it can use. One that waits arrives with a large list and no way to prove permission for any of it.

Re-permissioning a list is far harder than permissioning it in the first place. You have to contact people you may not be entitled to contact, in order to ask whether you may contact them.

What does the law require of consent?

Broadly, that it is free, specific, informed, unconditional and unambiguous, and given by a clear affirmative action. Each of those words does work.

  • Free — not extracted as the price of something unrelated.
  • Specific — for a stated purpose, not “communications” in general.
  • Informed — they knew who would contact them, and about what.
  • Unconditional — not bundled into accepting terms of service.
  • Clear affirmative action — a tick they made, not a box already ticked.

Two consequences catch businesses out repeatedly.

A number collected for delivery is not consent for marketing. The purpose was different, and purpose is the whole point of the word “specific”.

“They messaged us first” is not a consent record. It lets you reply within the service window. It does not put them on a marketing list.

Are we responsible, or is Meta?

You are. This is the most expensive misunderstanding in the area.

The obligation sits with whoever decides the purpose and means of processing personal data. When your business collects a number, adds it to a list, decides what to send and when, and uses purchase history to target it, that is you deciding. Meta provides the pipe.

The same applies down your channel. If dealers collect numbers on your behalf, the consent has to have been obtained for you, and recorded. This is a common gap and worth auditing before a first campaign — a dealer’s visitor book is not a consent record for the manufacturer.

Do the DND rules apply to WhatsApp?

Currently, no — and this is where most confusion sits.

The telecom regulator’s commercial communication rules, the DLT registration regime and the Do Not Disturb register govern SMS and voice calls. WhatsApp is treated as an over-the-top service and falls outside that framework. You do not register WhatsApp templates on DLT, and you are not required to screen a WhatsApp list against the preference register.

Two reasons not to relax about it. The position rests on a regulatory boundary the government has the power to move. And screening against the register anyway costs almost nothing, shows good faith, and removes the people most likely to report you — which protects the thing that actually matters, your quality rating.

What should you do now?

None of this depends on which phase the law is in, and all of it is harder to do retrospectively.

  1. Record consent against every contact — number, date, method, the wording they agreed to, and whether it covered marketing or only transactional messages.
  2. Stop treating an enquiry as an opt-in. Ask separately, and record the answer.
  3. Audit lists collected by dealers or at exhibitions. These are almost always the weakest, and usually the largest.
  4. Make opting out easy, and act on it immediately. Someone who wants to leave and cannot will report you instead.
  5. Separate transactional from promotional in your data, not just in your templates.
  6. Do not buy lists. No consent exists, and it is the fastest route to a restricted number.

Common questions

Can we message customers who bought from us?

For matters relating to their purchase, generally yes. For promotion of other products, you need consent covering that purpose. The distinction between service and marketing communication is worth being strict about internally, because Meta draws it too.

Does this apply if our customers are outside India?

The Indian framework reaches processing connected with offering goods or services to people in India. If you also message customers in Europe or the UK, their own rules apply separately, and the consent standard there is broadly comparable — so a process built properly for one tends to hold for the other.

Our WhatsApp provider says they handle compliance. Is that enough?

No. A provider can supply tooling — consent fields, opt-out handling, audit logs — but the obligation sits with the business deciding the purpose. Ask what the tooling actually does. Do not accept “we are compliant” as an answer that covers you.

How much consent detail do we really need to store?

Enough to reconstruct the moment later: who, when, by what method, and what they were told they were agreeing to. A tick box with no record of the wording beside it proves very little a year afterwards.

Is one opt-in enough for everything we send?

Not reliably. Consent is tied to purpose, so permission for order updates does not automatically extend to promotional campaigns. The practical approach is to be explicit about the categories when you ask, and to record which were agreed.

This is a general explanation for businesses considering WhatsApp marketing, not legal advice, and the framework is still being phased in. Confirm the current position before relying on it.

More on this: getting opt-in that holds up and what lowers your quality rating. For how we build on the platform, see WhatsApp Business API.

Editorial Team

The Concord Technosoft editorial team writes from the work - building software since 2006, and still running much of it. Everything here comes from systems we operate rather than projects we delivered. Where we cite a rule, a rate or a platform policy, we check it first and date it.

Keep reading

More on WhatsApp Business API

Tell us what you are building

We will tell you how we would approach it, and whether we are the right fit.