DPDP Act Compliance for Email & WhatsApp Marketing: A Checklist for Indian D2C Brands
India’s digital commerce market relies heavily on email addresses, mobile numbers, purchase histories, browsing activity and customer preferences. For D2C brands, these details make it possible to send order updates, promotional emails, product recommendations and WhatsApp messages.
They also create responsibilities around how personal data is collected, used, stored and shared.
The Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 establish India’s framework for handling digital personal data. The final Rules were notified on November 14, 2025, with a phased commencement schedule.
For an Indian D2C company, this means Email Marketing and WhatsApp campaigns should be reviewed alongside data collection, consent, customer rights, vendor management and security practices.
Here is a practical checklist that brands can use when reviewing their marketing operations.
Start With the Data
Before changing your email campaigns, identify what customer information your business actually collects.
A typical D2C brand may collect:
- Name
- Email address
- Mobile number
- Delivery address
- Purchase history
- Product preferences
- Customer support conversations
- Website activity
- Marketing preferences
- Communication preferences
The DPDP framework concerns digital personal data and places obligations on organizations that determine the purpose and means of processing that data. For marketing teams, this makes a proper data inventory a useful starting point.
Create a simple internal record showing where each category of customer data comes from, why it is collected, where it is stored and which vendors can access it.
This exercise also helps identify old customer lists that may have been collected without a clear record of their original purpose.
Check Your Consent Process
Consent is one of the central areas D2C brands should review.
Under the DPDP framework, consent should be informed, specific and capable of being withdrawn. The 2025 Rules also require notices to be presented independently and in clear, understandable language. The notice must explain the personal data being processed and the specific purpose for processing.
For Email Marketing, examine every place where a customer can subscribe.
This may include:
- Website newsletter forms
- Checkout pages
- Pop-ups
- Landing pages
- Product registration forms
- Contests
- Lead-generation forms
- Mobile applications
Avoid treating a pre-ticked marketing checkbox as your preferred consent mechanism.
Your signup process should make it reasonably clear what the customer is agreeing to receive and how they can withdraw that consent.
Make Your Privacy Notice Clear
A privacy policy should not be treated as a document that sits unnoticed in the website footer.
The DPDP Rules require the notice to provide a clear account of the personal data being collected and the purpose for which it will be processed. The notice must also provide a way for individuals to access the relevant website or app and understand how they can withdraw consent and exercise their rights.
For a D2C brand, the notice should align with actual marketing operations.
If your company collects a mobile number for WhatsApp communication, the stated purpose should accurately reflect that use.
If an email address is collected for promotional communication, your documentation and customer-facing notice should account for that purpose.
Do not publish a generic privacy statement that bears little resemblance to the information your marketing systems actually process.
Review Your Email Marketing Platform
Most D2C brands use third-party platforms for Email Marketing, customer segmentation and automated communication.
Examples may include ecommerce platforms, email service providers, customer relationship systems and messaging providers.
Prepare a list of every vendor that receives customer data.
For each provider, record:
| Question | What to check |
| What data is shared? | Email, phone, name, purchase data |
| Why is it shared? | Email campaigns, transactional messages, analytics |
| Who can access it? | Internal staff and service providers |
| Where is it processed? | Relevant hosting and processing locations |
| How is it protected? | Security and access controls |
| How is data deleted? | Account and retention procedures |
| What happens after termination? | Deletion or return of information |
This vendor review is especially important for brands using several systems that exchange customer information automatically.
Treat WhatsApp Marketing Separately
WhatsApp is often handled differently from traditional email campaigns because the customer’s mobile number becomes the primary identifier.
A D2C brand should therefore document how a customer provides permission to receive promotional WhatsApp messages.
Keep records showing:
- When consent was obtained
- Where it was obtained
- What the customer agreed to receive
- Which phone number was associated with the consent
- Whether consent was later withdrawn
- When the customer was removed from marketing communication
A customer who provides a mobile number for order delivery does not automatically mean every future promotional use of that number should be assumed to be understood.
Marketing teams should distinguish operational communication from promotional communication in their internal processes.
Make Withdrawal Easy
The DPDP Rules specifically address mechanisms for withdrawing consent and state that the process should be as easy as the process used to give consent.
For Email Marketing, this generally means maintaining a functional unsubscribe mechanism.
For WhatsApp communication, your operational process should make it straightforward to record a customer’s request to stop promotional messages.
The important part is what happens after the request.
Your suppression or opt-out information needs to reach the systems that control campaign delivery. Removing someone from one mailing list while leaving them active in another system can result in another marketing message being sent.
Maintain a Consent Record
Consent should be something your business can demonstrate through records.
A useful consent record can include:
| Record | Example |
| Customer identifier | Email or mobile number |
| Consent date | Date and time |
| Source | Website checkout or signup form |
| Purpose | Promotional email |
| Consent status | Active or withdrawn |
| Withdrawal date | If applicable |
| System | Marketing platform |
The exact implementation should be reviewed with qualified legal and privacy professionals based on your business structure and processing activities.
For marketing teams, the practical lesson is straightforward. Do not rely on memory or scattered spreadsheets to determine whether a customer agreed to receive marketing communication.
Review Old Customer Lists
Many D2C companies have accumulated customer records over several years.
These lists may contain:
- Former subscribers
- Old leads
- Previous customers
- Imported contacts
- Event registrations
- Competition entries
- Contacts collected through partner campaigns
Before importing every old contact into a new Email Marketing platform, establish where the information came from and what purpose applied when it was collected.
A large database is useful only when the business can understand its origin and manage it properly.
Protect Customer Information
The DPDP Rules include requirements relating to reasonable security safeguards. The Rules refer to measures such as encryption, access controls, logging, monitoring and other security practices appropriate to protecting personal data.
For a D2C marketing team, security begins with basic account discipline.
Use individual staff accounts where available. Remove access when employees leave. Restrict administrative permissions. Protect API keys and integrations. Review connected applications periodically.
Marketing databases should not become an overlooked repository of customer information simply because they are managed by the marketing department.
Prepare for Customer Rights Requests
Customers have rights under the DPDP framework, including rights concerning access to information about personal data, correction and erasure, among other rights specified by the Act. The Rules establish further procedures around these rights.
Your customer support and marketing teams should know where such requests go and who handles them.
Create an internal process covering:
- Receiving the request
- Verifying the requester where required
- Identifying relevant systems
- Coordinating with vendors
- Updating or deleting appropriate records
- Recording the action taken
A clear process is considerably easier to manage than handling each request as an isolated incident.
The D2C Compliance Checklist
Use this checklist as a starting point for reviewing your Email Marketing and WhatsApp operations:
| Compliance area | Status to verify |
| Customer data inventory completed | ☐ |
| Marketing data sources documented | ☐ |
| Consent mechanism reviewed | ☐ |
| Privacy notice updated | ☐ |
| Email unsubscribe process tested | ☐ |
| WhatsApp opt-out process documented | ☐ |
| Consent records maintained | ☐ |
| Old customer lists reviewed | ☐ |
| Marketing vendors identified | ☐ |
| Data access restricted | ☐ |
| Customer rights process established | ☐ |
| Data retention practices reviewed | ☐ |
| Security controls reviewed | ☐ |
| Incident response process documented | ☐ |
A Practical Compliance Routine
DPDP compliance should not be treated as a one-time website update.
Marketing databases change. New tools are connected. New campaigns are launched. Customer information moves between systems.
A sensible D2C brand should periodically review its signup forms, consent records, privacy notices, email lists, WhatsApp workflows, vendor access and customer-rights procedures.
The Ministry of Electronics and Information Technology has published the final DPDP Rules and an enforcement timeline, with provisions coming into force in phases.
That phased approach gives businesses time to review their processes, but it is still wise to begin the operational work early.
A Cleaner Marketing System
For Indian D2C brands, DPDP compliance reaches far beyond the unsubscribe button at the bottom of an email.
It affects how customer information enters the business, how consent is obtained, how data moves between marketing platforms, how promotional messages are sent and how customers can exercise their rights.
A well-organized Email Marketing operation should make these processes clear.
Product Siddha can help D2C businesses review their digital marketing systems, customer data processes and marketing workflows so that growth activities are supported by a more disciplined approach to customer information.
The DPDP Act and Rules involve legal requirements that can depend on the nature of a business’s processing activities. Brands should obtain advice from a qualified privacy or legal professional when determining their specific compliance obligations.
