DPDP Consent for WhatsApp, SMS & Email Marketing: What Indian Marketers Must Change in 2026

Most Indian marketing teams already believe they have consent. They have a checkbox on a lead form, a DLT-registered header, a WhatsApp template that Meta approved, and an email list built over six years of webinars and trade shows. Under the Digital Personal Data Protection Act, 2023 (DPDP Act), most of that is not consent at all. It is a record that someone once gave you a phone number. This guide explains what DPDP consent for marketing actually requires, how it sits on top of the TRAI and WhatsApp rules you already follow, and what a marketing team needs to change before the substantive obligations commence on 13 May 2027.
Why DPDP consent for marketing is different from what you have
Before the DPDP Act, marketing consent in India was mostly a telecom problem. TRAI’s Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR) governed whether an SMS or call could reach a subscriber. Email had no dedicated law. Meta’s own WhatsApp Business Messaging Policy governed WhatsApp. As a result, “consent” meant three different things to three different teams.
The DPDP Act changes the question. Section 6 says consent must be free, specific, informed, unconditional and unambiguous, and it must be given through a clear affirmative action. Moreover, it must be limited to the specified purpose. That last phrase is what breaks most marketing databases. A phone number collected to deliver an order was collected for delivery, not for promotional messages. Consequently, sending a festive offer to that number is a new purpose, and it needs its own consent.
Section 7 lists “legitimate uses” where consent is not required, such as data a person volunteers for a specific purpose, or data needed to respond to a medical emergency. Marketing is not on that list. Therefore, DPDP consent for marketing is the only lawful basis for promotional WhatsApp, SMS or email, and that consent has to be provable.
The three-layer rule stack every Indian marketer now works under
It helps to picture the obligations as three stacked layers. Each layer can stop a message on its own, so compliance means clearing all three.
| Layer | Who enforces it | What it controls | What “consent” means there |
|---|---|---|---|
| DPDP Act 2023 + DPDP Rules 2025 | Data Protection Board of India | Whether you may process the phone number or email address for marketing at all | Free, specific, informed, unambiguous, affirmative, per purpose, withdrawable with equal ease |
| TRAI TCCCPR 2018 (amended Feb 2025) | TRAI via telecom operators and the DLT platform | Whether an SMS or voice call can be delivered on Indian mobile networks | Explicit consent registered on DLT, or inferred consent for the life of a contract |
| WhatsApp Business Messaging Policy | Meta, through quality ratings and messaging limits | Whether your WhatsApp Business account keeps its sending capacity | Opt-in obtained by the business, with a clear opt-out honoured everywhere |
Notice that DLT and Meta both push the legal responsibility back to you. TRAI’s framework records consent that you claim to hold, and Meta’s policy says the business is responsible for obtaining opt-in in a lawful way. In other words, the DPDP layer is the one that decides whether the other two layers are standing on anything.
How DPDP consent for marketing actually works
It is easier to design a compliant flow when you can see the whole lifecycle. Below is the sequence that Rule 3 of the DPDP Rules, 2025 and Section 6 of the Act together require, written as a system rather than as legal text.
Input: the notice
Consent starts with a notice, and Rule 3 is precise about what it must contain. The notice must be understandable on its own, without sending the reader to another document. It must include an itemised description of the personal data being collected, the specified purpose, and a specific description of the goods, services or uses the processing enables. Finally, it must give the link and other means through which the person can withdraw consent, exercise their rights, and complain to the Data Protection Board.
For a marketer, that means “I agree to receive communications” fails on three counts. It does not itemise the data, it does not specify the channel, and it does not explain how to stop. A compliant version reads more like: “Send me offers and product updates on WhatsApp (+91 number) and email (address). You can stop at any time by replying STOP or from your preference centre.”
Processing: capture and record
The person gives consent through a clear affirmative action, so pre-ticked boxes and silence do not count. A DPDP consent for marketing record then needs to store more than a boolean. At minimum, it should hold who consented, which purposes and channels they agreed to, the version of the notice they saw, the timestamp, and how the consent was captured. Rule 3 and Section 6 also require you to offer the notice in English or any of the 22 languages in the Eighth Schedule, which matters for regional campaigns.
Decision layer: the check before every send
This is where most systems are weakest. Before a campaign goes out, something has to look up each recipient and confirm that active consent exists for that purpose and that channel. Additionally, the check has to be live, because Section 6(4) lets a person withdraw at any time, and Section 6(6) obliges you to stop processing within a reasonable time once they do.
Output: the message and its opt-out
The message itself must respect the layer it travels on. An SMS needs a DLT-registered header with the correct suffix, a registered template, and a promotional sender ID in the 140 series. A WhatsApp marketing message needs an approved template and an opt-out route. An email needs a working unsubscribe link. In each case, the opt-out must be at least as easy as the opt-in was, because Section 6(4) says withdrawal must be comparable in ease to the giving of consent.
Monitoring: withdrawal, refresh and evidence
Withdrawal has to flow back to the consent record and to every downstream system within a reasonable time. The evidence also has to survive, because Section 6(10) puts the burden of proving valid consent on the Data Fiduciary, not on the person. A screenshot of a form is not enough; you need the record itself.

A practical example
Consider a D2C skincare brand with 400,000 customers. It collects phone numbers at checkout, runs promotional SMS through a DLT-registered 140 header, and sends WhatsApp offers through a Business API provider. Under the DPDP Act, the brand collected the checkout number for order fulfilment, not for marketing. Because of that, the brand adds a separate, unticked box at checkout: “Send me offers on WhatsApp and SMS.” The consent record stores the purpose, the two channels, the notice version and a timestamp. Its campaign tool now queries that record before every send. When a customer replies STOP on WhatsApp, the withdrawal updates the record, and the next SMS campaign skips that number too, since both channels share the same purpose. The brand can then show the Board exactly when consent was given, what was shown, and when it was withdrawn.
What changes for each channel
DPDP consent for marketing on WhatsApp
Meta already requires opt-in, and its policy says businesses must respect opt-out requests whether they arrive on or off WhatsApp. DPDP consent for marketing on WhatsApp tightens two things. First, the opt-in itself must meet Rule 3, so a “Chat with us” button that silently enrols someone in promotions will not do. Second, marketing and service messages should be separate purposes with separate consent, which mirrors Meta’s own best-practice guidance to collect distinct opt-ins for order updates and offers. If you rely on click-to-WhatsApp ads, the consent should be captured in the first exchange, not assumed from the click.
SMS marketing consent under DPDP and TRAI
The February 2025 TCCCPR amendments made the telecom layer stricter. Promotional messages now carry a -P suffix, service messages -S, transactional -T and government messages -G. Promotional calls sit on the 140 series and service or transactional calls on the 160 series. TRAI also lowered the complaint threshold and added a 90-day cooling-off period before an opted-out subscriber can be approached again. In parallel, TRAI has been pushing Digital Consent Acquisition, where consent is collected through the 127 short code and stored in a registry the operators can read. As a result, the DLT consent record and the DPDP consent record should say the same thing, because a mismatch between them is the easiest thing for a regulator to find.
Email marketing consent under DPDP
Email is the channel with the fewest historical guardrails in India, and so it is where the largest legacy lists live. Under the DPDP Act, an email address is personal data, and a newsletter is a purpose. Lists built from business cards, event registrations or purchased databases have no DPDP consent for marketing behind them. There is no grandparent clause for old marketing lists in the Act, although Section 5(2) does allow you to serve a notice to people whose data you collected before the Act commenced. In practice, that means one re-permission campaign with a clear notice, after which you suppress the non-responders.
Legacy consent: the problem nobody wants to own
Every marketing team has a large database of contacts for whom it cannot prove DPDP consent for marketing. TRAI ran into the same wall with telecom consent, which is why it launched a pilot with the RBI in December 2025 to move legacy bank consents into the digital consent registry. The DPDP Act does not offer a similar migration. Section 5(2) lets you notify existing customers about the processing, but it does not manufacture consent that was never given.
The honest path is triage. Customers with a live contract can receive service messages under inferred consent on the telecom side, but not promotions. You can keep contacts who ticked a genuinely specific box in the past, provided you can show the box and the notice. Everyone else gets one re-permission message asking for DPDP consent for marketing, and then drops out of promotional segments. This shrinks lists, but it also removes the cohort that reports you, which is the same cohort that drags down WhatsApp quality ratings and triggers TRAI complaints.
The consent record your CRM does not have
Most CRMs store a single “marketing opt-in” flag. The DPDP Act needs a record with more dimensions, and this is where teams usually discover that their tools cannot hold it. Our guide on DPDP compliance for Zoho, Salesforce and HubSpot users goes into the CRM side in depth. For marketing specifically, the fields below are the minimum.
| Field | Why the DPDP Act needs it | Typical gap in marketing tools |
|---|---|---|
| Purpose (marketing, service, research) | Section 6 limits consent to the specified purpose | One flag covers everything |
| Channel (WhatsApp, SMS, email, voice) | Rule 3 requires the notice to describe the use enabled | Channel preference stored separately from consent |
| Notice version shown | Section 6(10) puts the burden of proof on you | Not stored at all |
| Capture method, timestamp, source | Proves a clear affirmative action | Import date only |
| Withdrawal timestamp and channel | Section 6(4) and 6(6): stop within a reasonable time | Unsubscribe lives in the email tool, not the record |
| Language of the notice | Section 5 allows any of the 22 scheduled languages | English only |
The consent artefact is the structured form of this record, and it is what a Consent Manager registered under the Rules will eventually exchange with you. Building the record now means you will not have to rebuild it when Consent Managers go live.

ProtectComply Consent Management versus the usual alternatives
Marketing teams typically try one of three approaches: keep consent inside each channel tool, build a custom consent table in the CRM, or adopt a dedicated consent management layer. ProtectComply’s Consent Management module is the third kind. It captures per-purpose consent through a hosted preference centre, a cookie banner and an embeddable widget, stores every record with provenance such as capture IP, user-agent and fingerprint, and gates withdrawal behind an OTP so that stopping is as easy as starting. It also translates notice text into all 22 scheduled languages. The comparison below is deliberately even-handed, because each approach fits a different organisation.
Comparison: channel tools, CRM tables and ProtectComply
| Criterion | Consent inside each channel tool | Custom table in CRM | ProtectComply Consent Management |
|---|---|---|---|
| Per-purpose, per-channel consent | Rarely; usually one flag per tool | Possible, needs design work | Enforced; bundled consent is rejected at write time |
| Rule 3 notice content and versioning | Not tracked | Manual | Notice version stored with each record |
| Withdrawal as easy as consent | Per tool, inconsistent | Depends on build | OTP-gated withdrawal from the preference centre |
| Evidence for Section 6(10) | Export logs from several vendors | Only if provenance is captured | Provenance captured per record, audit trail shared across modules |
| 22-language notices | Manual translation | Manual translation | Auto-translated |
| Link to RoPA and retention | None | None unless built | Consent purposes link to RoPA entries and retention policies |
| Implementation effort | Low | High, ongoing | Medium; one script tag plus integration to campaign tools |
| Cost pattern | Hidden in channel fees | Engineering time | Subscription per module |
A small team with one channel can live with the first option for a while. A large enterprise with its own data platform may prefer to build. The middle, which is most Indian marketers, generally does better with a layer that already encodes the rules and connects to the rest of a DPDP programme. Our comparison of consent management platforms in India covers the wider market if you are evaluating vendors.
Pros and cons of a dedicated DPDP marketing consent layer
The advantages are concrete. You capture DPDP consent for marketing once and every channel reads it, so a WhatsApp STOP suppresses the SMS campaign too. The record exists for the burden of proof, so an audit request becomes an export rather than a scramble. Notice versioning means you can show exactly what someone saw. Furthermore, the same audit trail feeds grievance handling and rights requests, which matters because a marketing complaint often arrives as a Section 13 grievance.
There are real limitations too. A consent layer does not fix the telecom side; you still need DLT headers, templates and the correct number series, and the DLT consent record must be kept in step. It also cannot cleanse a legacy list; the re-permission campaign is still yours to run. Finally, integration is where projects slip. If the campaign tool does not query the consent record before every send, the layer becomes another silo. Budget for that integration before you budget for the licence.
How we measure success with DPDP consent for marketing
ProtectComply does not publish customer performance figures, so treat this DPDP consent for marketing scorecard as an evaluation framework rather than a benchmark. These are the measures a marketing and compliance team can track together, and each maps to a specific obligation.
| Measure | What it tells you | Obligation it evidences |
|---|---|---|
| Share of promotional sends with a matching active consent record | Whether the per-send check is actually wired in | Section 6, Section 6(10) |
| Median time from withdrawal to suppression across all channels | Whether “reasonable time” is minutes or weeks | Section 6(6) |
| Notice completeness score against Rule 3 items | Whether your forms would survive a Board review | Rule 3 |
| Consent records with full provenance | Whether you can prove, not just assert, consent | Section 6(10) |
| DLT-to-DPDP consent mismatch rate | Whether the telecom and data-protection records agree | TCCCPR plus DPDP |
| WhatsApp quality rating and TRAI complaint count | External signal that opt-ins are genuine | Meta policy, TCCCPR complaint thresholds |
What to change before 13 May 2027
The Ministry of Electronics and IT notified the DPDP Rules on 13 November 2025 with staggered commencement. The Board and Consent Manager registration provisions come first, and the substantive obligations on Data Fiduciaries, including Sections 5 and 6 and the penalty schedule, commence on 13 May 2027. Our DPDP Rules 2025 timeline tracks each date. For DPDP consent for marketing, the practical sequence is: rewrite every notice to Rule 3, split purposes and channels, build the consent record, wire the per-send check, run the re-permission campaign, and reconcile with DLT. Penalties for failing the security safeguards obligation run to ₹250 crore, and other contraventions up to ₹50 crore, so the cost of waiting is not abstract. The penalty schedule explained sets out each tier.
Frequently asked questions
Is a DLT-registered consent template enough for DPDP compliance?
No. DLT registration satisfies TRAI’s TCCCPR framework for SMS delivery. The DPDP Act separately requires that consent be free, specific, informed and unambiguous, given through a notice that meets Rule 3, and provable by you. The two records should match, but one does not replace the other.
Can I send WhatsApp offers to customers who bought from me?
Only if they consented to marketing as a purpose. A purchase gives you consent to process data for the purchase. Promotional messages are a different specified purpose under Section 6, so they need a separate, affirmative opt-in, which also aligns with Meta’s opt-in policy.
Do I need consent for transactional and service messages?
Order confirmations, OTPs and delivery updates are processing for the purpose the customer volunteered their data for, and they generally fall under Section 7 legitimate uses. On the telecom side, transactional and service messages use the -T and -S suffixes and the 160 series. Marketing content cannot be tucked into a service message.
What happens to my old email list?
Section 5(2) lets you send a notice to people whose data you collected before the Act commenced, but it does not create consent. If you cannot show a specific, affirmative opt-in for marketing, run a single re-permission campaign and suppress everyone who does not respond.
How quickly must I stop after someone withdraws consent?
Section 6(6) says within a reasonable time, and withdrawal must be as easy as giving consent under Section 6(4). Operationally, that means a STOP on any channel should suppress the person across every channel tied to that purpose, ideally within minutes rather than at the next list refresh.
Does the notice have to be in regional languages?
Section 5 requires the notice to be available in English or any language listed in the Eighth Schedule of the Constitution, at the person’s option. For regional campaigns, that means the consent notice should be offered in the language the campaign runs in.
What are the penalties for marketing without valid consent?
The DPDP Act’s schedule sets penalties up to ₹250 crore for failing to take reasonable security safeguards and up to ₹50 crore for other contraventions of the Act or Rules. TRAI’s framework adds telecom-side consequences such as header suspension and disconnection for repeated complaints.
Talk to us about marketing consent
If your campaign tools cannot answer “show me the DPDP consent for marketing behind this send,” you have the problem this article describes. ProtectComply’s Consent Management module captures per-purpose, per-channel consent, stores it with provenance, and makes withdrawal as easy as opt-in, with notices in all 22 scheduled languages. Contact the team for a walkthrough against your current WhatsApp, SMS and email stack, or start with the Section 5 notice and consent primer.
Reviewed by Dinkar Singh, Chief Data Privacy Officer and Co-Founder, ProtectComply. Legal references: Digital Personal Data Protection Act, 2023; Digital Personal Data Protection Rules, 2025 (G.S.R. 843(E), 13 November 2025); TRAI Telecom Commercial Communications Customer Preference (Amendment) Regulations, 2025; WhatsApp Business Messaging Policy. This article is general information, not legal advice.