10 months from now, on May 13, 2027, India's Digital Personal Data Protection Act (DPDP) becomes fully enforceable. If your business runs a WhatsApp bot, an AI voice bot, or collects any customer data through forms, ads, or CRMs — you're a "Data Fiduciary" under this law, whether you know it or not.
Most Indian small and mid-size businesses are completely unprepared. This guide is what your future self will wish you'd read now.
⚠️ Why this matters — the numbers
Penalties are massive. Up to ₹250 crore per data breach. Up to ₹200 crore for failing to notify users of a breach. The Data Protection Board of India has been operational since November 14, 2025 and is actively building case pipelines.
78% of Indian SMBs already use WhatsApp for business. Almost none have proper DPDP consent flows. A single competitor complaint or disgruntled customer can trigger an audit.
What is the DPDP Act — in plain English
The Digital Personal Data Protection Act 2023 (with Rules notified in 2025) is India's version of GDPR — but purpose-built for the Indian digital economy. It governs how businesses collect, store, use, and share personal data of Indian residents.
"Personal data" includes ANY information that identifies an individual:
- Name, phone number, email address
- WhatsApp phone number (yes, even if they messaged you first)
- Voice recordings from AI bot calls
- Website form submissions, live chat transcripts
- IP address, device ID, cookies
- Payment details, addresses, KYC documents
- Chatbot conversation history
Your business is a "Data Fiduciary" under DPDP — the entity that decides why and how personal data is processed. That responsibility can't be outsourced. Even if you use Interakt, Wati, AiSensy, Gupshup, or any third-party WhatsApp platform, YOU are legally accountable for compliance, not them.
The Enforcement Timeline — What's Already Live, What's Coming
November 14, 2025 — Data Protection Board of India operational
The DPBI is the enforcement body. It can accept complaints, conduct audits, and impose penalties. It's been live and building infrastructure for over 8 months as of this writing.
November 14, 2026 — Consent Manager registration operational
Rule 4 becomes active. Consent Managers — independent bodies that let users manage all their consents in one place — must be registered with the DPBI. Businesses using Consent Managers must integrate with them.
May 13, 2027 — Full DPDP Act compliance deadline
Every business processing personal data of Indian residents must be fully compliant. After this date, the DPBI can impose penalties for violations. This is the hard deadline your business must plan around.
📊 The compliance timeline in real terms
5 Ways WhatsApp Bots & AI Voice Bots Trigger DPDP Obligations
Most business owners assume "compliance" only affects large enterprises. Wrong. Here's how a simple WhatsApp bot triggers DPDP obligations:
1. Storing WhatsApp phone numbers
Every phone number in your WhatsApp Business inbox is personal data. Storing it in a CRM without valid consent = violation. Consent must be specific, informed, and free — a generic "By using WhatsApp you agree..." doesn't cut it.
2. Recording AI voice bot calls
Voice recordings are biometric personal data. Recording without explicit consent notice at the start of the call is illegal. "This call may be recorded for quality purposes" is INSUFFICIENT under DPDP — the notice must state the specific purpose, retention period, and user rights.
3. Using bot conversations for AI training
Feeding customer conversations back into your language model? That's a separate processing purpose from the original interaction. It requires separate opt-in consent + PII anonymization. Most SMBs do this without realising, thinking it's "just improving the bot."
4. Sharing lead data with third-party CRMs
Passing WhatsApp lead data to Zoho, HubSpot, Salesforce, or any external tool triggers a data transfer obligation. You must have a Data Processing Agreement (DPA) with each vendor + notify users which third parties receive their data.
5. Cross-border data transfer
If your AI vendor's servers are in the US (OpenAI, Anthropic, most SaaS tools), you're transferring Indian data internationally. DPDP allows this only if the destination country provides "adequate" protection. Currently, the government hasn't published its adequacy list — meaning many US-hosted services are in a legal grey zone.
The DPDP Compliance Checklist for Indian Businesses
Print this. Give it to whoever handles your website, WhatsApp, and CRM. Every checkbox = one legal risk closed.
Foundation (do first — 1-2 weeks)
- Appoint an internal privacy lead. Not required by law for SMBs, but signals seriousness. Can be founder, ops head, or CTO.
- Map your data flows. Document what personal data you collect, from whom, where it's stored, who has access, and how long you keep it.
- Publish a DPDP-aligned Privacy Policy on your website. Must be in English + at least one regional language. Must list specific purposes, retention, third-party sharing, and user rights.
- Publish a Consent Notice that appears wherever you collect data (WhatsApp opt-in, forms, voice bot intro).
Consent (the hardest part — 2-4 weeks)
- Rewrite WhatsApp opt-in language. Must be clear, specific, and separate from other terms. Store proof of consent with timestamp.
- Add voice consent script at the start of every AI bot call. Example: "This call will be recorded for [specific purpose]. Say YES to continue, or say STOP to speak to a human."
- Add form consent checkboxes — separate checkboxes for (a) service delivery, (b) marketing, (c) AI training. Unchecked by default.
- Build a consent log — a database of who consented to what, when, and via which channel.
Rights & Access (users must be able to act — 2 weeks)
- Build a data access flow. Users can request a copy of what data you hold on them. Must respond within reasonable time.
- Build a data deletion flow. Users can request full deletion. Must actually delete (not just deactivate).
- Build a consent withdrawal flow. Users can revoke consent for one purpose (e.g., marketing) while keeping others (e.g., service delivery).
- Publish a grievance email (e.g., privacy@yourbusiness.com) monitored by the privacy lead.
Vendors & Data Transfers (ongoing)
- Sign a Data Processing Agreement (DPA) with every vendor touching personal data — CRM, WhatsApp platform, voice bot provider, hosting company, email tool.
- Verify India data residency where possible. Ask each vendor: "Where are Indian user data stored?" — get it in writing.
- Audit AI vendors specifically. If you use OpenAI, Anthropic, Google Gemini directly — verify their data processing policy.
Breach Response (in case of incident)
- Draft a breach response playbook. Who calls whom, in what order, within what timeframe.
- Notify affected users promptly — recommended within 72 hours (aligns with GDPR standard).
- Report to the Data Protection Board of India if the breach is significant.
Specific Rules for WhatsApp Bots
Opt-in language that actually works
Non-compliant: "By messaging us on WhatsApp, you agree to our terms."
Compliant: "Message us on WhatsApp to receive [specific purpose: appointment reminders / order updates / support]. Your phone number will be stored to send these messages. You can reply STOP to opt out anytime, or request data deletion at privacy@yourbusiness.com. Full policy: yourbusiness.com/privacy"
Marketing broadcasts
Different consent from transactional messages. A user who consented to "order updates" has NOT consented to "promotional offers." Sending marketing to non-opted-in users = violation + Meta ban risk. Always keep opt-ins separated by purpose in your database.
Data retention defaults
- Active chat context: 30-90 days
- Order history: As long as service relationship + 7 years for financial records
- Marketing consent records: Until withdrawal + 1 year for audit trail
- Bot training data: Anonymize immediately, delete raw after use
Specific Rules for AI Voice Bots
Consent script requirements
Every AI voice call must start with a consent notice in the caller's preferred language. Since India has 22+ official languages, this typically means detecting language from area code / phone metadata or offering multi-language menus.
Model script (adapt to your business):
Bot: "Namaste. Yeh call [Company Name] ke AI assistant se hai. Aapki call record ki jayegi appointment booking ke liye. Data 30 din tak store hoga. Continue karne ke liye YES boliye, ya STOP boliye human se baat karne ke liye. Aapke rights aur privacy policy: [website URL]"
Voice data specifically
Voice recordings are especially sensitive because they include biometric information (voice patterns). Recommended practices:
- Transcribe → delete audio within 24 hours (unless legally required to retain)
- Anonymize transcripts before AI training (remove names, phone numbers, addresses)
- Never store voice recordings alongside PII in the same database — separate systems, separate access controls
- Encrypt at rest and in transit
What to Ask Every Vendor Before Signing
| Question | Why it matters |
|---|---|
| Where do you store Indian user data? | India-resident data is safest under DPDP |
| Will you sign a Data Processing Agreement (DPA)? | Legally required for shared processing |
| How do you handle user data deletion requests? | You need this within days, not weeks |
| Do you use my data to train your models? | Big red flag if yes — separate consent needed |
| What's your breach notification SLA? | Should be under 72 hours |
| Are you certified (SOC 2, ISO 27001)? | Reduces your audit burden |
| Do you have India-registered legal entity? | Easier legal recourse if things go wrong |
How Appzur Builds DPDP-Compliance Into Every Bot
We built our WhatsApp platform (Akashvanni) and AI voice bots with DPDP in mind from day one. What every client gets:
- India data residency by default — servers in Mumbai and Delhi
- Consent flow templates in Hindi, English, and 18 Indian languages
- Deletion API endpoints so user rights requests can be automated
- Audit-ready consent logs — timestamped, exportable, immutable
- DPA available on request to every client — no extra cost
- Default 30-day voice retention with client-configurable settings
- PII anonymization pipeline for any AI training use case
We don't sell DPDP compliance as a premium add-on. It's baked into the base build. If a customer chooses a non-Appzur vendor, we help them audit that vendor's DPDP posture before signing.
Not sure if your current bot is DPDP-compliant?
Free 30-min audit: we'll review your existing WhatsApp bot, voice bot, or forms and give you a compliance gap report. No sales pitch — just honest findings.
Book a Free DPDP Audit →Frequently Asked Questions
What are the penalties under India's DPDP Act?
Financial penalties up to ₹250 crore per breach for failure to prevent personal data breaches. Up to ₹200 crore for failure to notify affected users. Up to ₹150 crore for failure on children's data. Smaller violations up to ₹50 crore. The Data Protection Board sets penalty based on nature, gravity, and duration.
Does the DPDP Act apply if I'm a small business with only WhatsApp?
Yes. There's no size exemption. If you process personal data of Indian residents — including phone numbers on WhatsApp — you must comply by May 13, 2027.
Is my WhatsApp bot compliant if I use Interakt / Wati / AiSensy?
Not automatically. These platforms handle infrastructure. YOU remain the Data Fiduciary — legally responsible for consent, privacy notice, rights fulfilment, and vendor DPAs. Ask your provider for a signed DPA and India data residency confirmation.
Do I need to appoint a Data Protection Officer (DPO)?
Only if you're classified a Significant Data Fiduciary (SDF) — typically large enterprises or sensitive-sector businesses. SMBs don't need a formal DPO, but SHOULD appoint an internal privacy lead. It's cheap insurance.
Can I train AI on my customer WhatsApp conversations?
Only with explicit separate opt-in AND anonymization. Blanket AI training on customer chats without consent + PII removal is non-compliant. Get separate consent, strip PII, inform users.
The Bottom Line
You have 10 months. Most of your competitors are ignoring this. Business owners who use this period to build compliance-native bots will have a massive trust advantage after May 2027 — while non-compliant competitors face fines, forced shutdowns, and reputation damage.
Start with the checklist above. If you'd rather not think about any of this, work with a build partner (like us) that handles it end-to-end so you can focus on your business.
Kumar Abhinav is Solutions Architect & Co-Founder at Appzur. He builds DPDP-compliant AI voice bots, WhatsApp automation, and custom software for Indian businesses. See his full profile →
