All articles
Compliance

DPDP Readiness Checklist for Banks & NBFCs 2026: 40 Points

A DPDP readiness checklist maps every bank or NBFC channel, WhatsApp included, to consent, notice, security, breach and rights duties, with evidence for each.

RichAutomate Team
11 min read 1 view
DPDP Readiness Checklist for Banks & NBFCs 2026: 40 Points

A DPDP readiness checklist for a bank or NBFC maps every channel that touches customer personal data (core banking, apps, call centre, WhatsApp and vendors) against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and records evidence for each control. It covers notice, consent, purpose limitation, security safeguards, breach reporting, retention and erasure, data-principal rights and processor contracts, and WhatsApp needs its own line items because it is a high-volume, vendor-operated channel. This is general information, not legal advice; confirm specifics with counsel.

What “DPDP ready” means for a bank or NBFC

A regulated lender is DPDP ready when it can prove, with evidence rather than intent, that every processing activity has a defined purpose, a valid basis, reasonable safeguards and a named owner.

Banks of every kind (private, small finance, cooperative and regional rural), NBFCs, HFCs and fintech lenders are data fiduciaries because they decide why and how customer data is processed. Vendors acting on their instructions, such as CRM providers, collection agencies, call centres and WhatsApp Business Solution Providers (BSPs), are data processors; the fiduciary stays accountable for them.

The government may notify large fiduciaries as Significant Data Fiduciaries (SDFs). If notified, an SDF must appoint an India-based Data Protection Officer, engage an independent data auditor and run periodic Data Protection Impact Assessments (DPIAs).

For a bank, WhatsApp is a vendor-operated channel, so the BSP must be covered by a written data-processing contract.

DPDP timeline: the 2023 Act and the 2025 Rules

The DPDP Act was enacted in 2023. The DPDP Rules, 2025 were notified in November 2025, with most obligations phased in over roughly 18 months. Follow the phased timeline in the Rules and confirm current dates with counsel before fixing internal deadlines.

Treat 2026 as the build year. For the general baseline, start with our DPDP Act WhatsApp compliance checklist, then add the banking controls below.

DPDP vs RBI vs CERT-In: how the rules fit together

DPDP adds a personal-data lens on top of sector rules. Where RBI directions or other laws require you to keep, localise or report data, those duties generally continue. This table stays at principle level.

AreaWhat DPDP asksWhat RBI or CERT-In already asksWhat to do for WhatsApp
KYC dataCollect only what is needed; erase when purpose and legal retention endKYC directions require identity verification and record-keepingNever ask for or send full Aadhaar or PAN in chat
IT securityReasonable security safeguardsIT governance expectations: board oversight, access control, audit trailsMFA and role-based access on the inbox and BSP console
OutsourcingFiduciary stays accountable; processors only under contractOutsourcing of IT services: due diligence, contracts, audit rights, exit plansTreat the BSP as a material IT vendor
Digital lendingSpecific consent; easy withdrawalExplicit borrower consent, data minimisation, disclosure of lending partnersSeparate consent for loan offers; name who is messaging
Payment dataSecurity and storage limitationPayment-system data stored in IndiaKeep card details out of chat; mask to last 4 digits
Incident reportingIntimate the Board and affected principals as the Rules requireCERT-In: reportable cyber incidents within 6 hours; RBI incident reportingOne playbook with parallel clocks

For lending detail, see RBI digital lending rules for WhatsApp.

The 40-point DPDP readiness checklist

A DPDP readiness checklist is a list of controls, each with a definition of “ready” and the evidence an auditor or the Data Protection Board would expect. Score each control red, amber or green, with an owner and a date.

#ControlWhat “ready” looks likeEvidence to keep
A. Governance and DPO
1Board-approved DPDP policyNamed executive owner; reviewed yearlyBoard minutes
2Accountable contact or DPOPublished contact; India-based DPO if notified as SDFAppointment letter
3Steering groupCompliance, IT, legal, business and CX on one trackerMinutes, tracker
4SDF assessmentDocumented view on notification, DPIA and audit planAssessment memo
5Role-based trainingBranch, call-centre and WhatsApp agents trainedTraining records
B. Data inventory and mapping
6Personal data inventoryCore banking, LOS, CRM, apps, WhatsApp and call recordings listedData register
7Channel data-flow mapsCRM, BSP, Meta and customer hops drawn and signed offApproved diagrams
8Purpose taggingEvery data element linked to a stated purposeData register
9Children's dataMinor accounts flagged; verifiable guardian consentProcess note
10Cross-border viewProcessing locations recorded against applicable restrictionsTransfer register
C. Notice and consent
11Plain-language noticeData, purposes, rights, withdrawal and complaint routes statedNotice versions
12Language coverageEnglish plus customers' regional languages where neededTranslations
13Valid consent captureClear affirmative action; no pre-ticked or bundled consentScreenshots, records
14Consent log per customerTimestamp, source, purpose, notice version, languageExportable log
15Easy withdrawalApp toggle, STOP keyword and branch request all workWithdrawal log
D. Purpose limitation and minimisation
16Legitimate-use registerConsent or legitimate-use basis set per activity, reviewed by counselRegister, legal note
17Service vs marketing splitSeparate consent flags for eachCRM field audit
18Minimum fieldsForms and chatbot flows ask only what each step needsForm review log
19Masking standardLast 4 digits only; no full Aadhaar or PANTemplate reviews
20Secondary-use gateCross-sell, analytics and model training checked against purposeApproval log
#ControlWhat “ready” looks likeEvidence to keep
E. Security safeguards
21EncryptionIn transit and at rest, with managed keysConfiguration evidence
22Access control and MFARole-based access and MFA on every console, including the WhatsApp inboxAccess reviews
23LoggingAccess and export logs kept as the Rules requireLog records
24Export controlBulk chat and contact exports restricted and alertedDLP rules, export logs
25Security testingVAPT on apps, webhooks and APIs; findings closedReports, tracker
F. Vendors and processors (including BSP)
26Processor registerEvery vendor touching personal data, with its roleVendor register
27Data-processing contractInstructions, security, sub-processors, breach notice, deletion, audit rightsSigned agreements
28Vendor diligenceSecurity questionnaire done; claims verifiedDiligence file
29Sub-processor visibilityBSP and onward processors documentedSub-processor list
30Exit and deletionData returned or deleted at contract endDeletion certificates
G. Breach response
31Unified incident planCovers DPDP, CERT-In and RBI reportingApproved plan
32Breach triageClear test for a personal data breachDecision tree
33Pre-approved noticesDrafts for the Board, customers, CERT-In and RBITemplate pack
3424x7 escalationDecision-makers reachable within the hourRoster, call-tree test
35Tabletop drillsIncludes a WhatsApp wrong-recipient scenarioDrill reports
H. Rights, grievance and retention
36Rights intakeAccess, correction, erasure and nomination via app, branch or WhatsAppRequest log
37Grievance SLAResolved within the Rules' timelineGrievance MIS
38Identity checkRequester verified before data is shared or changedProcedure
39Retention schedulePeriods reconciled with KYC and record-keeping lawsApproved schedule
40Erasure executionChat logs, exports and copies deleted on scheduleDeletion job logs

WhatsApp-specific line items for banks and NBFCs

WhatsApp now carries OTPs, alerts, EMI reminders, collections, onboarding and offers, combining high volume, third-party infrastructure and human agents.

Stop overpaying on WhatsApp

Get the DPDP WhatsApp checklist

A founder-led WhatsApp reply with the DPDP consent + audit-log checklist for WhatsApp Business messaging. India-hosted. No spam.

DPDP-compliant · India-hosted · 1-min reply

Opt-in capture and a consent log

Record every opt-in with timestamp, source (app, website, branch form, click-to-chat), purpose, language and notice version, in a per-customer log you can export. A screenshot of a sign-up form is not a consent log. See WhatsApp opt-in rules under DPDP.

Service messages are not marketing

OTPs, transaction alerts and EMI reminders serve different purposes from loan or card offers, so they need separate consent flags. Withdrawing marketing consent must never switch off fraud alerts.

Template hygiene

  • Mask account and card numbers to the last 4 digits, for example XXXX-1234.
  • Never include full Aadhaar or PAN in a template or agent reply.
  • Keep full balances and credit limits out of marketing templates.
  • Show phone numbers masked in reports, such as 91 98XXX XXXXX.

STOP honoured across channels

A STOP reply should suppress that purpose in CRM, SMS, email and dialler lists too, with the effective time logged.

Agent access and a role-based inbox

Agents should see only their own queue; collections staff should not see card disputes or KYC files. Enforce MFA, ban shared logins and review access quarterly.

Chat-log retention and deletion

Chats hold personal data, so they need a retention period and a deletion job reconciled with KYC and anti-money-laundering record-keeping. See our WhatsApp chat data retention policy guide.

The BSP as data processor

Data typically flows from your CRM through the BSP to Meta's Cloud API and the customer, with replies and status webhooks returning. Document each hop, and ask vendors in writing where data is hosted rather than assuming.

Mapping lender WhatsApp messages to purpose and basis

Legitimate use vs consent depends on the use case; confirm with counsel.

MessagePurposeLikely basisMinimisation rule
OTPAuthenticate login or paymentLegitimate use*Code and expiry only
Transaction alertReport a debit, credit or card useLegitimate use*Masked account, amount, merchant
EMI reminderFlag a due instalmentLegitimate use*Due date, amount, payment link
Overdue or collections nudgeRecover a past-due amountLegitimate use*, within RBI fair-practice expectationsBorrower only; no third parties
KYC re-verificationKeep KYC currentLegitimate use (legal obligation)*Secure link; no documents in open chat
Loan or card offer (marketing)Cross-sellOpt-in consentOpted-in contacts only; easy STOP; no balances
Feedback surveyImprove serviceConsent, unless counsel advises otherwiseShort; no account data

*Subject to counsel's review of the specific use case.

Collections and recovery on WhatsApp

RBI's fair-practice expectations on recovery apply on WhatsApp too: no harassment, contact only at reasonable hours, and no messaging third parties such as family or employers about the debt. Check current RBI directions and your recovery policy.

  • Message only the borrower's registered number, never referees or phone contacts.
  • Use approved, neutral templates; no threats or shaming.
  • Schedule sends within permitted hours and cap frequency per borrower.
  • Bind any collection agency using WhatsApp by contract and audit its logs.

Breach playbook for a WhatsApp incident

Rehearse three scenarios: a wrong-recipient send, a compromised agent login and a leaked chat or contact export.

  1. Contain. Revoke the session, rotate tokens and passwords, pause the affected campaign and preserve logs.
  2. Assess. Identify which customers and fields were exposed, for how long and to whom.
  3. Notify. Intimate the Data Protection Board and affected principals as the Rules require (the notified text contemplates prompt intimation plus a detailed report within 72 hours; confirm with counsel), CERT-In within 6 hours where reportable, and RBI where applicable.
  4. Learn. Fix the root cause, tighten templates or access, and record lessons.

For the clocks in detail, see CERT-In and DPDP breach notification for WhatsApp.

Penalties under the DPDP Act

Per the Act's schedule, penalties can go up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify the Board or affected principals of a breach. The Board fixes the amount case by case.

A 30-60-90 day DPDP readiness plan

  • Days 1–30: Discover. Name the owner and steering group, build the data inventory, draw the WhatsApp data flow, list processors and score all 40 controls.
  • Days 31–60: Fix. Rewrite the notice, split service and marketing consent, start the consent log, mask templates, sign BSP and agency contracts, and switch on MFA.
  • Days 61–90: Prove. Run a breach tabletop, test STOP and rights requests end to end, start deletion jobs and present the evidence pack to the board.

No software makes an institution DPDP compliant on its own; compliance comes from policy, contracts, process and evidence. Tools help with the WhatsApp layer: RichAutomate's WhatsApp Business API platform lets teams send Meta-approved templates, run broadcasts only to opted-in contacts, work from a shared team inbox and track delivery. Test any platform against controls 14, 15, 22, 24 and 27.

To pilot opt-in capture, masked templates and inbox roles before a wider rollout, start a RichAutomate free trial with 14 days and 100 free credits.

Frequently asked questions

What is a DPDP readiness checklist for banks?

A DPDP readiness checklist for banks is a structured list of controls that maps every channel handling customer personal data, including WhatsApp, against the DPDP Act, 2023 and the DPDP Rules, 2025. Each control defines what “ready” looks like and the evidence to keep.

Do banks need customer consent to send WhatsApp messages under DPDP?

It depends on the purpose. Marketing messages such as loan or card offers generally need specific opt-in consent. Service messages such as OTPs and transaction alerts may fall under a legitimate use, but that depends on the use case, so confirm with counsel. Meta's policy also requires opt-in before a business messages a user.

Are NBFCs covered by the DPDP Act?

Yes. NBFCs, HFCs and fintech lenders that decide how customer personal data is processed are data fiduciaries. Large NBFCs may also be notified as Significant Data Fiduciaries, which would add duties such as an India-based DPO, independent data audits and DPIAs.

What are the DPDP penalties for a bank or NBFC?

Per the Act's schedule, penalties can go up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify a personal data breach. The Data Protection Board decides the amount case by case.

Is the WhatsApp BSP a data processor under DPDP?

Generally yes. A Business Solution Provider processes customer data on the bank's instructions, so it acts as a data processor and should sign a written data-processing contract covering security, sub-processors, breach notice and deletion. The bank stays accountable as the data fiduciary.

Ready to ship this?

Get the DPDP WhatsApp checklist

A founder-led WhatsApp reply with the DPDP consent + audit-log checklist for WhatsApp Business messaging. India-hosted. No spam.

DPDP-compliant · India-hosted · 1-min reply
Tagged
DPDP ActDPDP Rules 2025Banking complianceNBFCBFSIData protectionRBIWhatsApp Business API
Written by
RichAutomate Team
Editorial team at RichAutomate. We build the WhatsApp Business automation platform Indian D2C brands, fintechs, and agencies use to ship campaigns and flows on the official Meta Cloud API.
FAQ

Frequently asked questions

What is a DPDP readiness checklist for banks?
A DPDP readiness checklist for banks is a structured list of controls that maps every channel handling customer personal data, including WhatsApp, against the DPDP Act, 2023 and the DPDP Rules, 2025. Each control defines what “ready” looks like and the evidence to keep.
Do banks need customer consent to send WhatsApp messages under DPDP?
It depends on the purpose. Marketing messages such as loan or card offers generally need specific opt-in consent. Service messages such as OTPs and transaction alerts may fall under a legitimate use, but that depends on the use case, so confirm with counsel. Meta's policy also requires opt-in before a business messages a user.
Are NBFCs covered by the DPDP Act?
Yes. NBFCs, HFCs and fintech lenders that decide how customer personal data is processed are data fiduciaries. Large NBFCs may also be notified as Significant Data Fiduciaries, which would add duties such as an India-based DPO, independent data audits and DPIAs.
What are the DPDP penalties for a bank or NBFC?
Per the Act's schedule, penalties can go up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify a personal data breach. The Data Protection Board decides the amount case by case.
Is the WhatsApp BSP a data processor under DPDP?
Generally yes. A Business Solution Provider processes customer data on the bank's instructions, so it acts as a data processor and should sign a written data-processing contract covering security, sub-processors, breach notice and deletion. The bank stays accountable as the data fiduciary.
RichAutomate · WhatsApp BSP for India 2026

Ship WhatsApp campaigns + flows on a transparent, compliance-ready BSP.

₹0 platform fee. DPDP audit log included. Visual flow builder. Multi-tenant from day one.

Start free trial
Want this for your brand?

Get a free 24-hour BSP audit

Send us your last invoice. We line-item it against Meta's published rates and benchmark against three alternatives.

Limited Spots Available

Get a Free
Automation Audit

Stop leaving revenue on the table. Get a custom roadmap to automate your growth.

Secure & Confidential

Continue reading

All articles
Vertical

Best WhatsApp Business API for Chit Fund Companies 2026

The best WhatsApp Business API for a registered chit fund company in 2026 logs every installment reminder and auction notice immutably, sends only approved templates, and keeps a subscriber-wise audit trail. Compliance-first buyer guide: Chit Funds Act record-keeping, DPDP consent, the enrollment Flow architecture, and why RichAutomate charges 0 platform fee.

Read article
Compliance

Is Bulk WhatsApp Sending Legal in India 2026? Rules + Risk

Yes — bulk WhatsApp is legal in India only via the official API with opt-in; unofficial sender apps risk a permanent number ban.

Read article
Compliance

Do You Need DLT Registration for WhatsApp Business API in India?

Answer-first 2026 guide: no, DLT registration is not required for the WhatsApp Business API. DLT is TRAI TCCCPR framework for SMS and voice; WhatsApp is a Meta OTT service governed by Meta Business Messaging Policy and the DPDP Act instead. Covers why DLT does not apply, who actually regulates WhatsApp, whether existing SMS DLT carries over, opt-in and consent requirements, fine and ban risk, and how WhatsApp template approval differs from DLT template registration. RichAutomate flat pricing: Rs 0 platform/setup/monthly, Client Pay Rs 0.10 per message with Meta billed direct, SaaS Pay Rs 1.50 marketing / Rs 0.50 utility, 14-day trial plus 100 credits. All regulatory specifics hedged; verify as of 2026. Operational guidance, not legal advice.

Read article
Compliance

WhatsApp and India's Digital Competition Bill / CCI Gatekeeper Regime 2026

A forward-looking scenario guide to India's proposed Digital Competition Bill and the CCI ex-ante digital-markets regime for businesses that run on WhatsApp. Explains what an ex-ante gatekeeper regime is, why large Meta services are likely — but not confirmed — in scope, and the kinds of obligations it could bring: anti-self-preferencing, data-portability and interoperability mandates. The heart of the piece is a no-regrets hedging checklist: export your contact list and consent ledger, keep conversation history outside the app, stay multi-channel-ready, and own your customer data — moves that pay off whether the bill passes, passes differently or stalls. Includes a likely-obligations table, a DMA-vs-India-DCB-vs-status-quo comparison, and the competition-law-portability x DPDP data-rights intersection. Distinct from our Telecom Act and DPDP blogs: this is the competition / ex-ante-platform-regulation angle, governed by the CCI, not TRAI or the DPDP authority. The bill is proposed and evolving as of 2026 — every specific is hedged and illustrative. General information, not legal advice.

Read article
Compliance

CERT-In + DPDP Breach Rules 2026: WhatsApp Business Playbook

When customer data leaks out of a WhatsApp stack, two clocks start at once: CERT-In's 6-hour incident-reporting direction and the DPDP Act's duty to notify the Data Protection Board and every affected user. This playbook for founders and the person who is de-facto CISO puts both regimes side by side — CERT-In 2022 directions (6-hour reporting, 180-day in-India log retention, covered-incident annexure) vs DPDP Section 8(6) breach duties (Board + affected-principal notice, penalty schedule up to ₹250 crore — verify current rules) — explains why WhatsApp-first businesses are exposed (phone numbers, chat history and opt-in records are all personal data; the vectors are leaked API tokens, wandering CSV exports, compromised team logins and BSP-side incidents), translates the reportable-incident annexure into WhatsApp scenarios, lays out a rehearsable 6-hour runbook from detect-and-timestamp through contain (rotate tokens, revoke sessions), scope, CERT-In report, DPDP intimation and customer comms — including an honest utility-template breach notice sent on WhatsApp itself — solves the one-incident-three-documents convergence problem with a master incident-doc template, gives a prevention checklist (token hygiene, 2FA, role-based access, audit logs, data minimisation, retention windows), and lists the breach-SLA questions to put to any BSP before signing. Not legal advice; verify current directions and rules.

Read article
Compliance

WhatsApp for Digital Lending India 2026: RBI-Compliant Comms

RBI Digital Lending Directions mapped to WhatsApp: KFS delivery, the D-7/D-3/D-0 EMI pathway and conduct-limited recovery with guardrails baked in.

Read article
DPDP Readiness Checklist for Banks & NBFCs 2026: 40 Points