Confidential Dispatch

Is WhatsApp Business DPDP-compliant for collecting customer data?

4 min readUpdated 2026-07-04
On this page
  1. 01Who’s responsible — you or WhatsApp?
  2. 02Where WhatsApp Business leaves gaps
  3. 03“They messaged me first” isn’t consent to market to them
  4. 04How to use WhatsApp Business more compliantly
  5. 05FAQ
At a glance

WhatsApp Business is a messaging channel, not a compliance layer — so on its own it’s neither compliant nor not. Under India’s DPDP Act, if you collect customer data over WhatsApp, you are the Data Fiduciary and the duties are yours: a clear notice of purpose, specific consent (a real opt-in, not “they messaged us first”), collecting only what you need, securing it, and being able to prove the consent. WhatsApp acts as your service provider for that data, so you also need the right processor terms in place. The convenience is real; the compliance work doesn’t come built in.

Educational resource only. This explains how the DPDP Act applies when you collect customer data over WhatsApp Business under India’s Digital Personal Data Protection Act, 2023 (DPDP Act); it is not formal legal advice, and DPDP compliance is an organisation-wide obligation broader than any single channel.

The situation

For millions of Indian businesses, WhatsApp is the intake channel — enquiries, order details, documents, follow-ups, broadcasts. It’s where customers already are. But a chat thread is also a growing store of personal data, and the DPDP Act treats it the same as any other collection. The channel’s ease can quietly outrun the compliance basics.

Who’s responsible — you or WhatsApp?

You are. You’re the Data Fiduciary for the customer data you collect; WhatsApp is your service provider handling it on your behalf. The business decides why and how it’s collecting customer data over WhatsApp, so the DPDP duties sit with the business, not the platform. WhatsApp (and its parent) is a processor in that flow — which means you rely on it under service terms, and you should be satisfied those terms cover how your customers’ data is handled.

That split matters: you can’t point at WhatsApp if consent, notice, or security is missing. Meeting those is your job, whatever channel you chose.

Where WhatsApp Business leaves gaps

WhatsApp is built for conversations, not for structured notice, purpose-bound consent, or a clean consent record — so those are on you to add. Typical gaps:

  • No notice at capture. There’s no built-in way to present a clear purpose notice (Section 5) before a customer shares data in chat.
  • Consent is muddy. A customer messaging you, or being added to a broadcast list, isn’t specific consent for every use (Section 6) — especially not for marketing.
  • Records are scattered. Proving what someone consented to, and when, from a thread of messages is hard; the burden of proof is still yours.
  • Chats accumulate. Personal data and documents pile up in threads with no natural retention limit or deletion routine.
  • Sensitive documents in transit. People send Aadhaar, PAN and statements over chat as images — convenient, but weak on minimisation and control over where copies end up.

“They messaged me first” isn’t consent to market to them

A customer contacting you for one thing is not open-ended permission to use their number for another. This is the most common WhatsApp mistake. If someone messages to ask about a product, that’s consent for that conversation — not to be added to a promotional broadcast list. Marketing is a separate purpose, and it needs its own specific opt-in.

The clean pattern is an explicit opt-in you can evidence: a clear ask (“Can we message you offers on WhatsApp?”) with a recorded yes, separate from the enquiry itself — and an easy way to opt out later, honoured promptly.

How to use WhatsApp Business more compliantly

You can keep using WhatsApp — the fix is to wrap the basics around it. Practically:

  1. Show a purpose notice at the start of the relationship — pinned message, or a linked notice — stating what you collect, why, and how to opt out.
  2. Take a real opt-in for each purpose, and log it — support conversations and marketing are different consents.
  3. Don’t collect sensitive documents in chat where you can avoid it; if you must, minimise and mask (e.g. masked Aadhaar) and move them to secure storage, not the open chat.
  4. Set retention — don’t keep chat data and documents indefinitely; clear what you no longer need.
  5. Honour withdrawal and deletion — make opting out and asking for erasure easy, and act on it.
  6. Check your processor terms — be satisfied WhatsApp’s business terms cover how your customers’ data is processed.

FAQ

Is WhatsApp Business allowed for customer data under the DPDP Act?

Yes — it’s a channel, and the duties are yours. You need a purpose notice, specific consent, minimisation, security, a consent record, and an easy opt-out.

Is a customer messaging me first enough consent to send offers?

No. That’s consent for that conversation, not for marketing. Promotional messaging needs its own specific opt-in you can evidence.

Who is liable if customer data leaks from WhatsApp — me or WhatsApp?

You remain the accountable Data Fiduciary. WhatsApp is your service provider; you can’t transfer your responsibility to it by choosing it as a channel.

Is it safe to collect Aadhaar or documents over WhatsApp?

It’s a weak fit — documents sit as images in chats with little control. Minimise, mask where possible, and prefer secured storage over leaving them in the thread.

Reviewed by Confidential Dispatch Editorial Team
Last updated 4 July 2026
Not legal advice.

Collecting personal data from your own customers?

These are the rights your business has to honour. See where you stand with a two-minute self-check — no sign-up, no data stored.

Run the compliance self-check →