WhatsApp Marketing Under the DPDP Act: How to Manage Consent and Drive Engagement

    Learn how the DPDP Act changes WhatsApp marketing in India, from consent capture to enforcement, and build a DPDP-ready customer engagement workflow now.

    OneConsentBlog
    8 min read
    Tuesday, 22 September 2026
    WhatsApp Marketing Under the DPDP Act

    Enterprises running WhatsApp marketing in India have built a familiar workflow over the past several years. Customer data flows into a CRM, marketing teams segment that data, and a campaign goes out to a large list of numbers in one send. Then came the Digital Personal Data Protection Act, 2023 (DPDP Act), and the DPDP Rules, 2025, notified on 13 November 2025. Together, they add a step before that campaign goes live.

    Storing a customer's phone number in a CRM is not the same as clearing that customer for every WhatsApp campaign a business wants to run. Under the DPDP Act, marketing teams need visibility into why the data was collected and what purpose was communicated to the customer. They also need to know what ground for processing supports the campaign, and whether the customer's current preference allows that specific communication.

    WhatsApp is where this shift becomes visible first. Indian businesses already send order updates and promotional offers through the same number, often in the same conversation thread. That overlap is why purpose tracking and consent management move out of the privacy notice and into daily campaign operations.

    WhatsApp marketing under the DPDP Act requires businesses to move from database-driven campaign lists to purpose-aware, consent-checked audiences, supported by clear notices, accurate consent records, working withdrawal mechanisms and evidence that can be produced when required.

    From Database Marketing to Consent-Aware Campaign Execution

    A common enterprise WhatsApp workflow follows a straightforward sequence: marketing collects customer data, uploads it as an audience, and segments it by attributes such as location or purchase history before sending the campaign. Marketing teams could rely on this because the constraint was technical, such as list size or API throughput.

    The DPDP Act introduces a second constraint that applies earlier in the sequence: eligibility. A DPDP-ready workflow looks closer to the following steps.

    1. Collect data at the point of interaction, whether that is a website, an app, a store or a call centre.

    2. Inform the customer through a clear notice about what the data will be used for.

    3. Capture consent, or identify another applicable ground for processing under the Act.

    4. Record the purpose alongside the consent.

    5. Validate that the intended campaign matches the recorded purpose and the customer's current preference.

    6. Activate the campaign only for the audience that passes this check.

    7. Monitor preference changes on an ongoing basis.

    Consider a retailer with five million customer profiles in its CRM. Five million is the size of the database, not the size of the audience eligible for a promotional WhatsApp campaign, which is typically smaller once purpose and preference get applied correctly. Marketing operations should be able to answer a short set of questions before a campaign goes live:

    • What the data was originally collected for

    • What communication preference the customer has set

    • Whether the planned campaign matches the recorded purpose

    • Whether the customer has withdrawn consent since the last send

    • Whether the most recent preference is reflected in the platform sending the message

    • Whether the business can show how each customer became eligible, if asked at a later date

    The question marketing teams have traditionally asked is how many customers are in the database. The DPDP Act reframes it: how many customers are eligible for this campaign, on this channel, for this purpose. Consent becomes an active eligibility signal, one that campaign platforms read at the point of audience activation, not a field captured once and left unreviewed for years.

    Related reading: Omnichannel Consent Management: Capturing Consent Across POS, WhatsApp, Web & App

    Where WhatsApp Consent Workflows Break Down

    Preparing WhatsApp marketing for the DPDP Act is not a one-department job. Marketing, technology, legal, compliance and data teams all have a hand in it, because consent and preference signals need to stay connected to the systems that collect customer data, build audiences and activate campaigns.

    One question tends to bring these teams into the same conversation: how long it takes a changed WhatsApp preference to reach the system that sends the next campaign. Preference updates and campaign audiences often live in separate systems, refreshed on different schedules, and a customer's latest choice can miss the audience a campaign uses. CIO, CMO and Legal usually end up closing that gap together. It is an integration and governance problem, not one that belongs to a single team.

    What Happens When a Customer Withdraws Consent

    Consent withdrawal deserves its own place in a WhatsApp marketing workflow. It is where enterprise processes most often break down in practice. The sequence usually looks like this:

    Customer opts in → Consent recorded → Audience activated → Customer withdraws or changes preference → Consent status updated → Future campaigns suppressed

    Each step in that chain needs to reach the next system that depends on it. The CRM and campaign platform need the updated permission status, the customer needs to drop out of campaigns tied to that purpose, and the business needs a retained record of the withdrawal as evidence.

    Withdrawal works best as an operational signal that travels across the marketing technology stack, from the system that recorded it to every system capable of sending a message. Left parked as a customer-service ticket, it leaves campaign platforms unaware that anything changed, and the customer keeps receiving messages they explicitly declined.

    DPDP is one part of a wider set of applicable requirements for WhatsApp communication, not the only one. TRAI's Telecom Commercial Communications Customer Preference Regulations (TCCCPR) have been amended repeatedly, most recently through 2025 and 2026, and continue to evolve alongside WhatsApp's own Business Policy on consent and opt-in. Businesses should verify the current requirements for their specific communication channel and use case, and treat DPDP as one layer within that wider picture.

    Connecting Consent Enforcement to Your WhatsApp Marketing Stack

    An enterprise-ready WhatsApp marketing workflow connects customer touchpoints, a consent and preference layer, customer data platforms, an eligibility check, campaign activation and a monitoring layer, in that order.

    Customer touchpoints generate data continuously across several channels:

    • Website and mobile app

    • Point of sale and physical stores

    • Loyalty programme

    • Call centre

    That data flows into a consent and preference layer that records purpose, consent, preference status, withdrawal and an audit trail of every change, then into customer data platforms such as the CRM and CDP. Every campaign runs through an eligibility check first, confirming the customer still qualifies for that purpose on that channel. Only the customers who clear that check enter the campaign, on WhatsApp, SMS, email or push. A monitoring layer then keeps consent history, suppression lists and audit records for later reference.

    An enterprise consent management platform connects customer choices to every downstream system in this kind of workflow. OneConsent is built to capture consent at each touchpoint and manage preferences centrally. It also keeps a verifiable consent history, so those signals can be applied wherever audiences get activated, across WhatsApp and other customer-engagement channels. For campaign teams, that turns consent management into an enforcement capability they can rely on at the point of activation, instead of a one-time capture exercise reviewed only during an audit.

    WhatsApp Marketing Checklist for DPDP Readiness

    Before launching a campaign, marketing operations teams can work through the following.

    Before the campaign:

    • Confirm the purpose of the communication is defined precisely.

    • Review the relevant notice and consent requirements for that purpose.

    • Confirm the original data source for each contact in the audience.

    • Check that the current customer preference is available in the sending platform.

    • Verify that consent status is current, not historical.

    • Suppress withdrawn or ineligible customers before the campaign is built.

    • Check applicable vendor and platform requirements, including WhatsApp's own policies.

    • Confirm the campaign audience can be traced back to its eligibility criteria.

    After the campaign:

    • Process preference changes promptly.

    • Reflect opt-outs and withdrawals across every downstream system.

    • Retain consent records for future reference.

    • Keep campaign and audience records available for internal review.

    Conclusion

    DPDP changes more than the wording of privacy notices. It reaches into how enterprises collect, store and use customer data across every channel. WhatsApp will likely show that shift first, given its scale in India.

    For WhatsApp marketing teams, the practical takeaway is straightforward. A CRM full of customer data is not the same as a CRM full of marketable data. In practice, that plays out as a sequence: collect, inform, obtain consent, record purpose, validate eligibility, activate, and respect the customer's choice at every step after that.

    Organisations that start this review early, before the phased timelines force the issue, get more time to find gaps in existing customer records, integrations and campaign workflows. A new consent framework does not reach backward to cover data collected before it existed. Organisations that wait may need to review existing records, establish the applicable processing basis for each one, and, where required, seek fresh consent before using that data again, which is considerably more work than building the habit early.

    Preparing Your WhatsApp Marketing Workflow for DPDP Compliance

    If your WhatsApp marketing programme still runs on CRM exports instead of real-time eligibility checks, the fix is to connect consent capture, preference management and campaign enforcement across your existing stack. That is what OneConsent is built for: centralised consent records, purpose and preference tracked at every customer touchpoint, and eligibility enforced at the point of activation. Learn more about OneConsent platform and book a live demo to see how consent enforcement can work across your WhatsApp, SMS and email channels.

    Frequently Asked Questions

    Have more questions?

    Search our full DPDP knowledge base for more answers.

    See it live

    See OneConsent in action

    Get a personalised walkthrough of how OneConsent helps your teams stay DPDPA compliant.

    • 30-minute walkthrough
    • DPDPA-ready by design
    • Tailored to your stack