A DPDP readiness checklist for a bank or NBFC maps every channel that touches customer personal data (core banking, apps, call centre, WhatsApp and vendors) against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and records evidence for each control. It covers notice, consent, purpose limitation, security safeguards, breach reporting, retention and erasure, data-principal rights and processor contracts, and WhatsApp needs its own line items because it is a high-volume, vendor-operated channel. This is general information, not legal advice; confirm specifics with counsel.
What “DPDP ready” means for a bank or NBFC
A regulated lender is DPDP ready when it can prove, with evidence rather than intent, that every processing activity has a defined purpose, a valid basis, reasonable safeguards and a named owner.
Banks of every kind (private, small finance, cooperative and regional rural), NBFCs, HFCs and fintech lenders are data fiduciaries because they decide why and how customer data is processed. Vendors acting on their instructions, such as CRM providers, collection agencies, call centres and WhatsApp Business Solution Providers (BSPs), are data processors; the fiduciary stays accountable for them.
The government may notify large fiduciaries as Significant Data Fiduciaries (SDFs). If notified, an SDF must appoint an India-based Data Protection Officer, engage an independent data auditor and run periodic Data Protection Impact Assessments (DPIAs).
For a bank, WhatsApp is a vendor-operated channel, so the BSP must be covered by a written data-processing contract.
DPDP timeline: the 2023 Act and the 2025 Rules
The DPDP Act was enacted in 2023. The DPDP Rules, 2025 were notified in November 2025, with most obligations phased in over roughly 18 months. Follow the phased timeline in the Rules and confirm current dates with counsel before fixing internal deadlines.
Treat 2026 as the build year. For the general baseline, start with our DPDP Act WhatsApp compliance checklist, then add the banking controls below.
DPDP vs RBI vs CERT-In: how the rules fit together
DPDP adds a personal-data lens on top of sector rules. Where RBI directions or other laws require you to keep, localise or report data, those duties generally continue. This table stays at principle level.
| Area | What DPDP asks | What RBI or CERT-In already asks | What to do for WhatsApp |
|---|---|---|---|
| KYC data | Collect only what is needed; erase when purpose and legal retention end | KYC directions require identity verification and record-keeping | Never ask for or send full Aadhaar or PAN in chat |
| IT security | Reasonable security safeguards | IT governance expectations: board oversight, access control, audit trails | MFA and role-based access on the inbox and BSP console |
| Outsourcing | Fiduciary stays accountable; processors only under contract | Outsourcing of IT services: due diligence, contracts, audit rights, exit plans | Treat the BSP as a material IT vendor |
| Digital lending | Specific consent; easy withdrawal | Explicit borrower consent, data minimisation, disclosure of lending partners | Separate consent for loan offers; name who is messaging |
| Payment data | Security and storage limitation | Payment-system data stored in India | Keep card details out of chat; mask to last 4 digits |
| Incident reporting | Intimate the Board and affected principals as the Rules require | CERT-In: reportable cyber incidents within 6 hours; RBI incident reporting | One playbook with parallel clocks |
For lending detail, see RBI digital lending rules for WhatsApp.
The 40-point DPDP readiness checklist
A DPDP readiness checklist is a list of controls, each with a definition of “ready” and the evidence an auditor or the Data Protection Board would expect. Score each control red, amber or green, with an owner and a date.
| # | Control | What “ready” looks like | Evidence to keep |
|---|---|---|---|
| A. Governance and DPO | |||
| 1 | Board-approved DPDP policy | Named executive owner; reviewed yearly | Board minutes |
| 2 | Accountable contact or DPO | Published contact; India-based DPO if notified as SDF | Appointment letter |
| 3 | Steering group | Compliance, IT, legal, business and CX on one tracker | Minutes, tracker |
| 4 | SDF assessment | Documented view on notification, DPIA and audit plan | Assessment memo |
| 5 | Role-based training | Branch, call-centre and WhatsApp agents trained | Training records |
| B. Data inventory and mapping | |||
| 6 | Personal data inventory | Core banking, LOS, CRM, apps, WhatsApp and call recordings listed | Data register |
| 7 | Channel data-flow maps | CRM, BSP, Meta and customer hops drawn and signed off | Approved diagrams |
| 8 | Purpose tagging | Every data element linked to a stated purpose | Data register |
| 9 | Children's data | Minor accounts flagged; verifiable guardian consent | Process note |
| 10 | Cross-border view | Processing locations recorded against applicable restrictions | Transfer register |
| C. Notice and consent | |||
| 11 | Plain-language notice | Data, purposes, rights, withdrawal and complaint routes stated | Notice versions |
| 12 | Language coverage | English plus customers' regional languages where needed | Translations |
| 13 | Valid consent capture | Clear affirmative action; no pre-ticked or bundled consent | Screenshots, records |
| 14 | Consent log per customer | Timestamp, source, purpose, notice version, language | Exportable log |
| 15 | Easy withdrawal | App toggle, STOP keyword and branch request all work | Withdrawal log |
| D. Purpose limitation and minimisation | |||
| 16 | Legitimate-use register | Consent or legitimate-use basis set per activity, reviewed by counsel | Register, legal note |
| 17 | Service vs marketing split | Separate consent flags for each | CRM field audit |
| 18 | Minimum fields | Forms and chatbot flows ask only what each step needs | Form review log |
| 19 | Masking standard | Last 4 digits only; no full Aadhaar or PAN | Template reviews |
| 20 | Secondary-use gate | Cross-sell, analytics and model training checked against purpose | Approval log |
| # | Control | What “ready” looks like | Evidence to keep |
|---|---|---|---|
| E. Security safeguards | |||
| 21 | Encryption | In transit and at rest, with managed keys | Configuration evidence |
| 22 | Access control and MFA | Role-based access and MFA on every console, including the WhatsApp inbox | Access reviews |
| 23 | Logging | Access and export logs kept as the Rules require | Log records |
| 24 | Export control | Bulk chat and contact exports restricted and alerted | DLP rules, export logs |
| 25 | Security testing | VAPT on apps, webhooks and APIs; findings closed | Reports, tracker |
| F. Vendors and processors (including BSP) | |||
| 26 | Processor register | Every vendor touching personal data, with its role | Vendor register |
| 27 | Data-processing contract | Instructions, security, sub-processors, breach notice, deletion, audit rights | Signed agreements |
| 28 | Vendor diligence | Security questionnaire done; claims verified | Diligence file |
| 29 | Sub-processor visibility | BSP and onward processors documented | Sub-processor list |
| 30 | Exit and deletion | Data returned or deleted at contract end | Deletion certificates |
| G. Breach response | |||
| 31 | Unified incident plan | Covers DPDP, CERT-In and RBI reporting | Approved plan |
| 32 | Breach triage | Clear test for a personal data breach | Decision tree |
| 33 | Pre-approved notices | Drafts for the Board, customers, CERT-In and RBI | Template pack |
| 34 | 24x7 escalation | Decision-makers reachable within the hour | Roster, call-tree test |
| 35 | Tabletop drills | Includes a WhatsApp wrong-recipient scenario | Drill reports |
| H. Rights, grievance and retention | |||
| 36 | Rights intake | Access, correction, erasure and nomination via app, branch or WhatsApp | Request log |
| 37 | Grievance SLA | Resolved within the Rules' timeline | Grievance MIS |
| 38 | Identity check | Requester verified before data is shared or changed | Procedure |
| 39 | Retention schedule | Periods reconciled with KYC and record-keeping laws | Approved schedule |
| 40 | Erasure execution | Chat logs, exports and copies deleted on schedule | Deletion job logs |
WhatsApp-specific line items for banks and NBFCs
WhatsApp now carries OTPs, alerts, EMI reminders, collections, onboarding and offers, combining high volume, third-party infrastructure and human agents.
Get the DPDP WhatsApp checklist
A founder-led WhatsApp reply with the DPDP consent + audit-log checklist for WhatsApp Business messaging. India-hosted. No spam.
Opt-in capture and a consent log
Record every opt-in with timestamp, source (app, website, branch form, click-to-chat), purpose, language and notice version, in a per-customer log you can export. A screenshot of a sign-up form is not a consent log. See WhatsApp opt-in rules under DPDP.
Service messages are not marketing
OTPs, transaction alerts and EMI reminders serve different purposes from loan or card offers, so they need separate consent flags. Withdrawing marketing consent must never switch off fraud alerts.
Template hygiene
- Mask account and card numbers to the last 4 digits, for example XXXX-1234.
- Never include full Aadhaar or PAN in a template or agent reply.
- Keep full balances and credit limits out of marketing templates.
- Show phone numbers masked in reports, such as 91 98XXX XXXXX.
STOP honoured across channels
A STOP reply should suppress that purpose in CRM, SMS, email and dialler lists too, with the effective time logged.
Agent access and a role-based inbox
Agents should see only their own queue; collections staff should not see card disputes or KYC files. Enforce MFA, ban shared logins and review access quarterly.
Chat-log retention and deletion
Chats hold personal data, so they need a retention period and a deletion job reconciled with KYC and anti-money-laundering record-keeping. See our WhatsApp chat data retention policy guide.
The BSP as data processor
Data typically flows from your CRM through the BSP to Meta's Cloud API and the customer, with replies and status webhooks returning. Document each hop, and ask vendors in writing where data is hosted rather than assuming.
Mapping lender WhatsApp messages to purpose and basis
Legitimate use vs consent depends on the use case; confirm with counsel.
| Message | Purpose | Likely basis | Minimisation rule |
|---|---|---|---|
| OTP | Authenticate login or payment | Legitimate use* | Code and expiry only |
| Transaction alert | Report a debit, credit or card use | Legitimate use* | Masked account, amount, merchant |
| EMI reminder | Flag a due instalment | Legitimate use* | Due date, amount, payment link |
| Overdue or collections nudge | Recover a past-due amount | Legitimate use*, within RBI fair-practice expectations | Borrower only; no third parties |
| KYC re-verification | Keep KYC current | Legitimate use (legal obligation)* | Secure link; no documents in open chat |
| Loan or card offer (marketing) | Cross-sell | Opt-in consent | Opted-in contacts only; easy STOP; no balances |
| Feedback survey | Improve service | Consent, unless counsel advises otherwise | Short; no account data |
*Subject to counsel's review of the specific use case.
Collections and recovery on WhatsApp
RBI's fair-practice expectations on recovery apply on WhatsApp too: no harassment, contact only at reasonable hours, and no messaging third parties such as family or employers about the debt. Check current RBI directions and your recovery policy.
- Message only the borrower's registered number, never referees or phone contacts.
- Use approved, neutral templates; no threats or shaming.
- Schedule sends within permitted hours and cap frequency per borrower.
- Bind any collection agency using WhatsApp by contract and audit its logs.
Breach playbook for a WhatsApp incident
Rehearse three scenarios: a wrong-recipient send, a compromised agent login and a leaked chat or contact export.
- Contain. Revoke the session, rotate tokens and passwords, pause the affected campaign and preserve logs.
- Assess. Identify which customers and fields were exposed, for how long and to whom.
- Notify. Intimate the Data Protection Board and affected principals as the Rules require (the notified text contemplates prompt intimation plus a detailed report within 72 hours; confirm with counsel), CERT-In within 6 hours where reportable, and RBI where applicable.
- Learn. Fix the root cause, tighten templates or access, and record lessons.
For the clocks in detail, see CERT-In and DPDP breach notification for WhatsApp.
Penalties under the DPDP Act
Per the Act's schedule, penalties can go up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify the Board or affected principals of a breach. The Board fixes the amount case by case.
A 30-60-90 day DPDP readiness plan
- Days 1–30: Discover. Name the owner and steering group, build the data inventory, draw the WhatsApp data flow, list processors and score all 40 controls.
- Days 31–60: Fix. Rewrite the notice, split service and marketing consent, start the consent log, mask templates, sign BSP and agency contracts, and switch on MFA.
- Days 61–90: Prove. Run a breach tabletop, test STOP and rights requests end to end, start deletion jobs and present the evidence pack to the board.
No software makes an institution DPDP compliant on its own; compliance comes from policy, contracts, process and evidence. Tools help with the WhatsApp layer: RichAutomate's WhatsApp Business API platform lets teams send Meta-approved templates, run broadcasts only to opted-in contacts, work from a shared team inbox and track delivery. Test any platform against controls 14, 15, 22, 24 and 27.
To pilot opt-in capture, masked templates and inbox roles before a wider rollout, start a RichAutomate free trial with 14 days and 100 free credits.
Frequently asked questions
What is a DPDP readiness checklist for banks?
A DPDP readiness checklist for banks is a structured list of controls that maps every channel handling customer personal data, including WhatsApp, against the DPDP Act, 2023 and the DPDP Rules, 2025. Each control defines what “ready” looks like and the evidence to keep.
Do banks need customer consent to send WhatsApp messages under DPDP?
It depends on the purpose. Marketing messages such as loan or card offers generally need specific opt-in consent. Service messages such as OTPs and transaction alerts may fall under a legitimate use, but that depends on the use case, so confirm with counsel. Meta's policy also requires opt-in before a business messages a user.
Are NBFCs covered by the DPDP Act?
Yes. NBFCs, HFCs and fintech lenders that decide how customer personal data is processed are data fiduciaries. Large NBFCs may also be notified as Significant Data Fiduciaries, which would add duties such as an India-based DPO, independent data audits and DPIAs.
What are the DPDP penalties for a bank or NBFC?
Per the Act's schedule, penalties can go up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to notify a personal data breach. The Data Protection Board decides the amount case by case.
Is the WhatsApp BSP a data processor under DPDP?
Generally yes. A Business Solution Provider processes customer data on the bank's instructions, so it acts as a data processor and should sign a written data-processing contract covering security, sub-processors, breach notice and deletion. The bank stays accountable as the data fiduciary.