DPDP Act Compliance for WhatsApp Bots & AI in India — 2027 Deadline Guide
← Back to Blog

🛡️ DPDP Act Compliance for WhatsApp Bots & AI in India — 2027 Deadline Guide

📅 Published July 10, 2026 ⏱️ 12 min read 🏷️ Compliance • Regulation

10 months from now, on May 13, 2027, India's Digital Personal Data Protection Act (DPDP) becomes fully enforceable. If your business runs a WhatsApp bot, an AI voice bot, or collects any customer data through forms, ads, or CRMs — you're a "Data Fiduciary" under this law, whether you know it or not.

Most Indian small and mid-size businesses are completely unprepared. This guide is what your future self will wish you'd read now.

⚠️ Why this matters — the numbers

Penalties are massive. Up to ₹250 crore per data breach. Up to ₹200 crore for failing to notify users of a breach. The Data Protection Board of India has been operational since November 14, 2025 and is actively building case pipelines.

78% of Indian SMBs already use WhatsApp for business. Almost none have proper DPDP consent flows. A single competitor complaint or disgruntled customer can trigger an audit.

What is the DPDP Act — in plain English

The Digital Personal Data Protection Act 2023 (with Rules notified in 2025) is India's version of GDPR — but purpose-built for the Indian digital economy. It governs how businesses collect, store, use, and share personal data of Indian residents.

"Personal data" includes ANY information that identifies an individual:

Your business is a "Data Fiduciary" under DPDP — the entity that decides why and how personal data is processed. That responsibility can't be outsourced. Even if you use Interakt, Wati, AiSensy, Gupshup, or any third-party WhatsApp platform, YOU are legally accountable for compliance, not them.

The Enforcement Timeline — What's Already Live, What's Coming

DONE

November 14, 2025 — Data Protection Board of India operational

The DPBI is the enforcement body. It can accept complaints, conduct audits, and impose penalties. It's been live and building infrastructure for over 8 months as of this writing.

Nov 26

November 14, 2026 — Consent Manager registration operational

Rule 4 becomes active. Consent Managers — independent bodies that let users manage all their consents in one place — must be registered with the DPBI. Businesses using Consent Managers must integrate with them.

May 27

May 13, 2027 — Full DPDP Act compliance deadline

Every business processing personal data of Indian residents must be fully compliant. After this date, the DPBI can impose penalties for violations. This is the hard deadline your business must plan around.

📊 The compliance timeline in real terms

10
Months until deadline
₹250 Cr
Max penalty per breach
78%
Indian SMBs on WhatsApp
1.4 B
Indians the Act protects

5 Ways WhatsApp Bots & AI Voice Bots Trigger DPDP Obligations

Most business owners assume "compliance" only affects large enterprises. Wrong. Here's how a simple WhatsApp bot triggers DPDP obligations:

1. Storing WhatsApp phone numbers

Every phone number in your WhatsApp Business inbox is personal data. Storing it in a CRM without valid consent = violation. Consent must be specific, informed, and free — a generic "By using WhatsApp you agree..." doesn't cut it.

2. Recording AI voice bot calls

Voice recordings are biometric personal data. Recording without explicit consent notice at the start of the call is illegal. "This call may be recorded for quality purposes" is INSUFFICIENT under DPDP — the notice must state the specific purpose, retention period, and user rights.

3. Using bot conversations for AI training

Feeding customer conversations back into your language model? That's a separate processing purpose from the original interaction. It requires separate opt-in consent + PII anonymization. Most SMBs do this without realising, thinking it's "just improving the bot."

4. Sharing lead data with third-party CRMs

Passing WhatsApp lead data to Zoho, HubSpot, Salesforce, or any external tool triggers a data transfer obligation. You must have a Data Processing Agreement (DPA) with each vendor + notify users which third parties receive their data.

5. Cross-border data transfer

If your AI vendor's servers are in the US (OpenAI, Anthropic, most SaaS tools), you're transferring Indian data internationally. DPDP allows this only if the destination country provides "adequate" protection. Currently, the government hasn't published its adequacy list — meaning many US-hosted services are in a legal grey zone.

The DPDP Compliance Checklist for Indian Businesses

Print this. Give it to whoever handles your website, WhatsApp, and CRM. Every checkbox = one legal risk closed.

Foundation (do first — 1-2 weeks)

Consent (the hardest part — 2-4 weeks)

Rights & Access (users must be able to act — 2 weeks)

Vendors & Data Transfers (ongoing)

Breach Response (in case of incident)

Specific Rules for WhatsApp Bots

Opt-in language that actually works

Non-compliant: "By messaging us on WhatsApp, you agree to our terms."

Compliant: "Message us on WhatsApp to receive [specific purpose: appointment reminders / order updates / support]. Your phone number will be stored to send these messages. You can reply STOP to opt out anytime, or request data deletion at privacy@yourbusiness.com. Full policy: yourbusiness.com/privacy"

Marketing broadcasts

Different consent from transactional messages. A user who consented to "order updates" has NOT consented to "promotional offers." Sending marketing to non-opted-in users = violation + Meta ban risk. Always keep opt-ins separated by purpose in your database.

Data retention defaults

Specific Rules for AI Voice Bots

Consent script requirements

Every AI voice call must start with a consent notice in the caller's preferred language. Since India has 22+ official languages, this typically means detecting language from area code / phone metadata or offering multi-language menus.

Model script (adapt to your business):

Bot: "Namaste. Yeh call [Company Name] ke AI assistant se hai. Aapki call record ki jayegi appointment booking ke liye. Data 30 din tak store hoga. Continue karne ke liye YES boliye, ya STOP boliye human se baat karne ke liye. Aapke rights aur privacy policy: [website URL]"

Voice data specifically

Voice recordings are especially sensitive because they include biometric information (voice patterns). Recommended practices:

What to Ask Every Vendor Before Signing

QuestionWhy it matters
Where do you store Indian user data?India-resident data is safest under DPDP
Will you sign a Data Processing Agreement (DPA)?Legally required for shared processing
How do you handle user data deletion requests?You need this within days, not weeks
Do you use my data to train your models?Big red flag if yes — separate consent needed
What's your breach notification SLA?Should be under 72 hours
Are you certified (SOC 2, ISO 27001)?Reduces your audit burden
Do you have India-registered legal entity?Easier legal recourse if things go wrong

How Appzur Builds DPDP-Compliance Into Every Bot

We built our WhatsApp platform (Akashvanni) and AI voice bots with DPDP in mind from day one. What every client gets:

We don't sell DPDP compliance as a premium add-on. It's baked into the base build. If a customer chooses a non-Appzur vendor, we help them audit that vendor's DPDP posture before signing.

Not sure if your current bot is DPDP-compliant?

Free 30-min audit: we'll review your existing WhatsApp bot, voice bot, or forms and give you a compliance gap report. No sales pitch — just honest findings.

Book a Free DPDP Audit →

Frequently Asked Questions

What are the penalties under India's DPDP Act?

Financial penalties up to ₹250 crore per breach for failure to prevent personal data breaches. Up to ₹200 crore for failure to notify affected users. Up to ₹150 crore for failure on children's data. Smaller violations up to ₹50 crore. The Data Protection Board sets penalty based on nature, gravity, and duration.

Does the DPDP Act apply if I'm a small business with only WhatsApp?

Yes. There's no size exemption. If you process personal data of Indian residents — including phone numbers on WhatsApp — you must comply by May 13, 2027.

Is my WhatsApp bot compliant if I use Interakt / Wati / AiSensy?

Not automatically. These platforms handle infrastructure. YOU remain the Data Fiduciary — legally responsible for consent, privacy notice, rights fulfilment, and vendor DPAs. Ask your provider for a signed DPA and India data residency confirmation.

Do I need to appoint a Data Protection Officer (DPO)?

Only if you're classified a Significant Data Fiduciary (SDF) — typically large enterprises or sensitive-sector businesses. SMBs don't need a formal DPO, but SHOULD appoint an internal privacy lead. It's cheap insurance.

Can I train AI on my customer WhatsApp conversations?

Only with explicit separate opt-in AND anonymization. Blanket AI training on customer chats without consent + PII removal is non-compliant. Get separate consent, strip PII, inform users.

The Bottom Line

You have 10 months. Most of your competitors are ignoring this. Business owners who use this period to build compliance-native bots will have a massive trust advantage after May 2027 — while non-compliant competitors face fines, forced shutdowns, and reputation damage.

Start with the checklist above. If you'd rather not think about any of this, work with a build partner (like us) that handles it end-to-end so you can focus on your business.

Kumar Abhinav is Solutions Architect & Co-Founder at Appzur. He builds DPDP-compliant AI voice bots, WhatsApp automation, and custom software for Indian businesses. See his full profile →