WhatsApp Compliance in India: DPDP Act, Meta Policy Updates, and WhatsApp Username Shift (2026)
DPDP Act, Meta messaging limits & WhatsApp usernames are reshaping compliance in India. Learn what changes, the enforcement timeline, and what you must do before May 2027.
WhatsApp compliance in India is no longer a legal checkbox.
It is now a three-way negotiation between Indian regulators, Meta’s automated enforcement systems, and a new user identity layer that could break customer records.
WhatsApp compliance for Indian businesses in 2026 sits across three layers: the DPDP Act (India's data protection law, with full enforcement beginning May 2027), Meta's WhatsApp Business Platform policies (messaging limits, quality ratings, consent requirements), and the new WhatsApp username rollout that the Indian government has ordered paused over cybersecurity concerns.
This guide covers all three aspects, including the timeline, what penalties look like, and what an Indian business using WhatsApp for customer communication needs to do before the deadlines hit.
TLDR: WhatsApp Compliance in India: DPDP Act, Meta Policy Updates, and WhatsApp Username Shift (2026)
The DPDP Act is partially live. Full enforcement, with penalties up to ₹250 crore per violation, begins in May 2027. Consent Manager registration opens in November 2026.
Meta’s frequency capping enforces a per-user marketing messaging limit, 6-hour quality rating evaluation cycles, and consent requirements independent of Indian law.
The Indian government has ordered Meta to pause the WhatsApp username rollout, citing fraud and impersonation risks. If usernames proceed, businesses need to migrate from phone-number-based identification to BSUID.
July 2026 Update: Indian Government Orders A Pause On WhatsApp Usernames
On June 29, 2026, WhatsApp began rolling out usernames globally, allowing users to chat without sharing phone numbers. Within three days, the Indian government issued a notice to Meta, warning that the feature could increase online fraud, phishing, impersonation, and digital arrest scams. India gave WhatsApp three days to explain the feature or face action under IT regulations, and directed Meta to pause the rollout in India until concerns are addressed.
Meta responded that WhatsApp usernames include multiple safeguards: phone number verification remains required, limits on contacting new users, systems to block username guessing, and automated detection of impersonation patterns. Meta also stated the feature is not yet live and would roll out slowly later in the year.
What this means for Indian businesses:
The username feature is not live in India as of July 2026. No immediate action required.
However, the underlying technical change (BSUID, or Business-Scoped User ID) is already live in WhatsApp API webhooks. Businesses should start storing BSUIDs alongside phone numbers now. Find the full technical breakdown of what changes here: WhatsApp Username Update 2026: What BSUID Means for Businesses.
If India allows usernames to proceed, some customers will stop sharing phone numbers. Businesses that rely solely on phone numbers for CRM records, chatbot identification, and conversation history will face broken customer records.
The government's concern about impersonation is relevant to businesses running WhatsApp AI chat agents. If scammers can create usernames that mimic your business, your customers may interact with fraudulent accounts. Verified business status (Blue Tick) becomes more important.
The WhatsApp username situation is evolving. This section will be updated as the government reviews Meta's response.
Three Compliance Layers Every Indian Business on WhatsApp Needs to Track
Most businesses think about WhatsApp compliance as one thing.
It's actually three independent layers, each with its own rules, timelines, and penalties. Getting one right doesn't protect you from the other two.
Layer
Who Enforces It
What It Covers
Penalty
DPDP Act 2023
Data Protection Board of India
Consent, data storage, breach notification, customer rights
Layer 1: The DPDP Act (What You Owe Your Customers)
The Digital Personal Data Protection Act, 2023 received presidential assent on August 11, 2023. The DPDP Rules were notified on November 13, 2025, converting the draft into binding law and activating a three-phase enforcement timeline.
What the DPDP Act requires from businesses using WhatsApp
Consent Before Collection: Collecting any personal data through a WhatsApp conversation (name, phone number, location, purchase intent), needs to be preceded by a clear, informed consent from the user. This applies to WhatsApp AI chat agents that capture lead details, too.
Purpose Limitation: Data collected for support queries cannot be repurposed for marketing without separate consent.
Data Retention Limits: Businesses cannot store customer conversation data indefinitely. Retention must be justified by a stated purpose.
Breach Notification: If customer data collected via WhatsApp is compromised, you must notify the Data Protection Board of India and affected Data Principals in the manner prescribed under Rule 7 of the DPDP Rules, 2025, including details of the breach, affected data categories, likely impact, and mitigation measures.
Right To Erasure: Customers can request deletion of their personal data collected via WhatsApp chats. This includes data captured by your WhatsApp AI chat agent.
What the DPDP Act does NOT require (common misconceptions)
It does not ban AI chatbots or AI voice agents. Meta banned AI providers from accessing or using the WhatsApp Business API to deploy general-purpose AI chatbots in India, but allows task-specific business agents to be built on the WhatsApp Business Solution platform.
It does not require on-premises data storage for all businesses. Data residency requirements apply to Significant Data Fiduciaries, not to every SMB.
It does not apply retroactively to data already collected, but legacy data must be supported by valid consent mechanisms by full enforcement (May 2027).
The DPDP Act is the legal framework. But Meta enforces a separate compliance layer on top of it, automatically, without any notice period or appeal process.
DPDP Enforcement Timeline: What Happens When
Date
What Happens
What It Means for Your Business
Aug 11, 2023
DPDP Act receives presidential assent
The law exists. Not yet enforced.
Nov 13-14, 2025
DPDP Rules notified; Data Protection Board established; penalty framework activated
Fines of up to ₹250 crore legally possible post government’s phased 18-month implementation period.
Oct 15, 2025 / Jan 15, 2026
Meta bans its general-purpose AI chatbot in India (new users Oct, all users Jan)
Task-specific business bots on WhatsApp API remain allowed. This is Meta's decision, not DPDP.
Nov 14, 2026
Consent Manager registration framework goes live; soft enforcement transitions to active supervision
Businesses expected to demonstrate valid consent mechanisms for all customer data, including legacy data.
Early 2027
Mandatory audits for Significant Data Fiduciaries
Large enterprises face audit requirements. Most SMBs are not classified as SDFs.
May 14, 2027
Full enforcement begins. No grace period.
All obligations active: consent, breach notification, data rights, retention limits. Penalties enforceable from day one.
Layer 2: Meta's WhatsApp Business Platform Rules (What Meta Enforces on You)
Messaging limits and per-user caps
Each WhatsApp user can receive a limited number of marketing messages per day across all businesses. If your message is the third marketing message that user receives that day, it won't be delivered (error 131049).
This cap is shared across every business messaging that user. You're not just competing with your own send frequency but with every other business messaging the same customer. We covered the full impact of this in Why More WhatsApp Broadcasts Are Hurting Your Business.
Quality ratings and evaluation cycles
Meta evaluates your WhatsApp number's quality rating in 6-hour cycles (updated from the previous 24- to 48-hour window).
Ratings operate on a Green/Yellow/Red system. A Red rating triggers messaging throttling. Sustained poor quality can result in a permanent number ban.
Since October 2025, quality limits are portfolio-level, meaning one poorly performing number can affect your entire WhatsApp Business Portfolio.
Template approval and consent requirements
Marketing message templates require Meta approval before sending.
Recipients must have opted in to receive marketing messages. Meta's consent requirements exist independently of the DPDP Act, meaning you need to satisfy both.
Understanding how WhatsApp API pricing in India changes with your template mix and vendor with the new per-conversation pricing.
Layer 3: WhatsApp Usernames and BSUID (What's Changed After June 2026)
Despite the Indian government's pause order, the technical infrastructure for WhatsApp usernames is already being deployed.
Start storing BSUIDs alongside phone numbers in your CRM and chat agent records. Don't replace phone numbers yet, but treat BSUID as the durable identifier going forward.
Ensure your WhatsApp AI chat agent can identify returning users by BSUID, not just phone numbers. If a customer switches to username-only communication, your bot should still recognise them.
Get Blue Tick (Meta Verified) status for your business WhatsApp number. If usernames create an impersonation risk, verified status is your defence.
Monitor the Indian government's response to Meta's username submission. The situation is actively evolving.
How DPDP Applies To WhatsApp AI Chat Agents
If you've deployed a WhatsApp AI chat agent for lead qualification, customer support, or bookings, the compliance requirements apply to every piece of data that agent collects. The AI doesn't exempt you from consent requirements.
Considerations:
Consent capture in the chat flow: Your AI agent should capture explicit consent before collecting personal data. This can be built into the conversation flow as a natural first step, not as a legal wall of text.
Data retention in the knowledge base: Conversation logs stored for training or quality review need a defined retention period. Storing everything indefinitely is a DPDP risk.
Customer data deletion requests: If a customer asks to be forgotten, can your platform delete their data from conversation history, CRM records, and AI training data? This needs to be technically possible, not just a policy statement.
Cross-channel data: if your AI platform unifies WhatsApp and voice data (like MyOperator's Business AI Operator), the consent and retention requirements apply across both channels, not just WhatsApp.
MyOperator's managed services include DPDP alignment, consent flow configuration, and data retention setup as part of all AI agent plans, so your team doesn't need to build the compliance layer from scratch.
Compliance Checklist: What to Do Before November 2026
Audit your WhatsApp data collection. Map every piece of personal data your WhatsApp chat agent, broadcasts, and manual conversations collect. Name, phone number, location, purchase intent, payment details.
Implement consent capture. Build explicit consent into your chat flows before qualification questions. Document the consent mechanism.
Set data retention policies. Define how long you store conversation logs, lead data, and AI training data. Delete what you don't need.
Prepare for data deletion requests. Ensure your platform can delete a specific customer's data across conversation history, CRM, and AI training sets.
Store BSUIDs alongside phone numbers. Start now, even though usernames are not live in India. When they are, you'll need this already in place.
Check your WhatsApp quality rating. A Red rating doesn't just throttle messages; it signals to Meta that your account has compliance issues.
Get Meta Verified (Blue Tick). If usernames create impersonation risk, verified status is your protection.
Review your AI chat agent's knowledge base for outdated information. An AI agent giving incorrect policy or pricing information creates a compliance risk on top of a customer experience problem.
Share this WhatsApp compliance checklist with your team:
Conclusion: WhatsApp Compliance Is Not A One-Time Checkbox
The important shift is not that India has a new data law. It is that WhatsApp has become regulated infrastructure: Indian regulators govern customer data, Meta governs platform behaviour, and BSUID governs digital identity.
Businesses that treat these as separate teams—legal, marketing, and engineering—will struggle with fragmented systems and inconsistent customer records. Businesses that design consent, messaging, identity, and AI workflows as one communication architecture will be the ones that scale without repeatedly rebuilding their stack.
If you're running AI agents on WhatsApp, that means consent flows in the conversation flow design, retention limits within the platform configuration, and BSUID readiness in your chatbot-CRM setup.
MyOperator's managed services handle this as part of every AI agent deployment.
[ { "question": "When does the DPDP Act fully apply to Indian businesses using WhatsApp?", "answer": "Full enforcement of the DPDP Act begins May 14, 2027. However, the Data Protection Board is already established, and the penalty framework (up to ₹250 crore per violation) is technically active from November 2025. The Consent Manager registration framework opens in November 2026, so businesses should treat 2026 as the preparation year, not the compliance year." }, { "question": "Are AI chatbots or AI chat agents allowed on WhatsApp in India?", "answer": "Yes. Businesses in India can use AI-powered chatbots on the WhatsApp Business Platform. However, Meta’s January 2026 policy update restricts general-purpose AI providers from using the WhatsApp Business API to distribute standalone AI assistants whose primary function is an open-ended AI chat experience.", "bullets": [ "Customer support", "Lead qualification", "Bookings", "Order management", "FAQ automation" ] }, { "question": "What is the WhatsApp per-user marketing message cap?", "answer": "Each WhatsApp user can receive a limited number of marketing messages per day across all businesses combined (approximately 2, based on third-party research). If your marketing message is sent after the user’s limit is exhausted for that day, it fails with error code 131049. This is Meta's enforcement, not driven by DPDP or the BSUID update. You're competing for Meta’s frequency cap with every other business messaging the same customer." }, { "question": "What is BSUID and do I need to worry about it now?", "answer": "BSUID (Business-Scoped User ID) is a unique identifier Meta assigns to each user-business pair in WhatsApp API interactions. It's already live in WhatsApp Business API webhook payloads from June 2026. When WhatsApp usernames roll out in India, some users may stop sharing their phone numbers, making BSUID the only reliable identifier. Start storing BSUIDs alongside phone numbers now, so your CRM and AI agent flows don't break when the switch happens." }, { "question": "Has India banned WhatsApp usernames?", "answer": "Not permanently. As of July 2026, the Indian government has ordered Meta to pause the username rollout in India and explain the feature's cybersecurity safeguards. The feature is not currently live in India. Meta has submitted a response which the government is reviewing, and the outcome will determine whether WhatsApp usernames proceed, are modified, or are blocked in India." }, { "question": "What consent does a WhatsApp AI chat agent need to collect customer data?", "answer": "Under the DPDP Act, you need clear, informed consent before collecting personal data (name, phone number, location, purchase intent). This should be captured as a natural step in the conversation flow. Meta also requires opt-in consent independently for marketing messages. You need to satisfy both requirements." }, { "question": "How does MyOperator handle WhatsApp compliance for Indian businesses?", "answer": "MyOperator's managed services (included on all Business AI Operator plans) cover various DPDP and Meta compliance needs. The compliance layer is built into the deployment, not as a separate project for your team.", "bullets": [ "DPDP consent flow configuration", "Meta quality rating monitoring", "Template approval management", "BSUID migration support", "Data retention setup" ] }
]
Aman Dasgupta
Aman Dasgupta is a Senior Content Marketer at MyOperator – India’s Business AI Operator. Known for his data and stats-packed storytelling, he combines analytics with narrative depth to drive clarity and business value. His expertise spans customer experience, AI adoption, cloud telephony, and marketing intelligence.