WhatsApp Business API

Is bulk WhatsApp marketing legal in India?

Webmaster 5 min read

Sending marketing messages on WhatsApp is not illegal in India. Sending them to people who did not agree to receive them is a different matter, and it exposes you to three separate rulebooks: India’s data protection law, Meta’s own platform policies, and — potentially in future — telecom regulation. The one that will actually stop your business is the second, because Meta can restrict your number tomorrow without any legal process at all.

Most articles on this treat it as one question. It is three.

Where does India’s data protection law stand?

The Digital Personal Data Protection Act was passed in 2023, but sat unimplemented until the DPDP Rules were notified on 13 November 2025. Since then it has been rolling out in phases.

MilestoneDateStatus
DPDP Rules notified13 November 2025Done
Data Protection Board constituted13 November 2025Operational
Consent Manager registration opens13 November 2026Approaching
Substantive obligations enforceable13 May 2027Ahead

The temptation is to read that final date as a deadline and do nothing until 2026 is over. That is a mistake for a practical reason: consent cannot be applied retrospectively. Every contact you add to a list between now and then either has a proper consent record or does not, and you cannot go back and create one. A business that starts recording consent properly today arrives at 2027 with a usable database. One that waits arrives with a large list it cannot lawfully use.

What does the law require of consent?

The standard is that consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. Each word does work.

  • Free — not extracted as the price of something unrelated.
  • Specific — for a stated purpose, not “communications” in general.
  • Informed — they knew who would contact them and about what.
  • Unconditional — not bundled into accepting terms of service.
  • Clear affirmative action — a tick they made, not a box already ticked.

Two consequences catch businesses out. A phone number collected for delivery is not consent for marketing, because the purpose was different. And “they messaged us first” is not a consent record — it permits a reply within the service window, not a marketing list entry.

Are we responsible, or is Meta?

You are. This is the most expensive misunderstanding in the area.

A Data Fiduciary under the Act is whoever determines the purpose and means of processing personal data. When your business collects a number, adds it to a list, decides what to send and when, and uses purchase history to target it, you are determining purpose and means. Meta provides the pipe. The obligations are yours.

The same applies down your channel. If dealers collect numbers on your behalf, the consent has to have been obtained for you and recorded — a common gap, and one worth auditing before a first campaign.

Do TRAI’s DND rules apply to WhatsApp?

Currently, no — and this is where most confusion sits.

TRAI’s commercial communication regulations, the DLT registration regime and the Do Not Disturb register govern SMS and voice calls. WhatsApp is classified as an over-the-top service, so it falls outside that framework. You do not register WhatsApp templates on DLT, and you are not required to screen a WhatsApp list against the preference register.

Two reasons not to relax about it. The Telecommunications Act 2023 gives the government authority to extend jurisdiction to OTT platforms, so the position may not hold. And screening against the register anyway is cheap, demonstrates good faith, and removes the people most likely to report you — which protects your quality rating.

Which rulebook will actually stop you?

Meta’s. Not the law, and not soon — now.

You can be entirely compliant with Indian law and still lose your WhatsApp account, because Meta enforces its own policies on its own timescale with no notice period. Blocks and reports lower your quality rating; a poor rating reduces how many people you may message; persistent problems restrict the number. There is no regulator to appeal to, and your customers are on the other side of that number.

The practical hierarchy for most businesses is therefore: Meta’s policies bite first and hardest, DPDP obligations bite later but carry financial penalties, and TRAI does not bite yet. We have written separately about what lowers a quality rating and what counts as valid opt-in.

What should you do now?

  1. Record consent against every contact — number, date, method, wording agreed, and whether it covered marketing or only transactional messages.
  2. Stop treating an enquiry as an opt-in. Ask separately.
  3. Audit lists collected by dealers or at exhibitions, which are usually the weakest.
  4. Make opting out easy and act on it immediately.
  5. Separate transactional from promotional in your data, not just in your templates.
  6. Do not buy lists. No consent exists, and it is the fastest route to a restricted number.

Last verified: 22 August 2026. This is a summary of a framework that is still being rolled out, not legal advice. Verify the current position with a qualified adviser before relying on it.

Common questions

Can we message customers who bought from us?

For matters relating to their purchase, generally yes. For promotion of other products, you need consent covering that purpose. The distinction between service and marketing communication is one worth being strict about internally.

What are the penalties under DPDP?

The Act provides for substantial financial penalties, imposed by the Data Protection Board. Since enforcement of the substantive obligations is phased, the immediate risk for most businesses remains platform enforcement rather than regulatory penalty — but that changes.

Does this apply if our customers are outside India?

The Act reaches processing outside India connected with offering goods or services to people in India. If you also message customers in Europe or the UK, GDPR applies to them separately and its consent standard is broadly comparable.

Our WhatsApp provider says they handle compliance. Is that enough?

No. A provider can supply tooling — consent fields, opt-out handling, audit logs — but the obligations sit with the business determining the purpose. Ask what their tooling does, and do not accept “we are compliant” as an answer covering you.

More on this: getting opt-in that holds up and what lowers your quality rating. For how we build on the platform, see WhatsApp Business API.

Webmaster

Keep reading

More on WhatsApp Business API

Tell us what you are building

We will tell you how we would approach it, and whether we are the right fit.

Call us for any enquiry 011 41771877

Start a conversation