DPDP Compliance Brief — India — June 2026

Which WhatsApp BSP is DPDP Act Compliant in India?

Section-by-section audit mapping the Digital Personal Data Protection Act 2023 and the November 2024 draft Rules to BSP-side controls. Eight India-relevant platforms scored against a 12-point controls matrix. Independent editorial, no affiliate fees.

Published 1 June 2026 16 min readIndia · DPDP Act 2023 · 2026
DPDP Act 2023 BSP readiness ranking June 2026 with 12-point controls matrix scoring RichAutomate AiSensy Interakt Gupshup Karix DoubleTick WATI Respond.io

The honest one-line answer is that no WhatsApp Business Solution Provider is automatically Digital Personal Data Protection Act 2023 compliant — and any BSP marketing page claiming otherwise is misreading the statute. The Act splits liability between the Data Fiduciary (the tenant or brand that determines purpose and means of processing) and the Data Processor (the BSP that operates on documented instructions). Under Section 8(2), the Fiduciary carries primary liability for Processor non-compliance unless a written contract is in place. What BSP selection actually controls is how cheap or expensive it is for the tenant to operationalise Sections 6, 8, 9, 11, 12 and 16, and how quickly the breach-intimation clock under draft Rule 6 can be honoured. This article maps that landscape as of June 2026.

Direct answer (June 2026). No WhatsApp BSP makes a tenant automatically DPDP-compliant. Compliance is shared: the BSP is a Data Processor, the tenant is the Data Fiduciary, and Section 8(2) primary liability sits with the Fiduciary. What a BSP can ship is in-app tooling that operationalises Section 6 consent, Section 8 retention and breach intimation, Section 9 minor protection, and Section 16 cross-border restriction. Scored against a 12-point controls matrix, RichAutomate (94/100) ships the deepest tenant-facing DPDP surface in the India-relevant set, followed by AiSensy (71/100), Interakt (68/100), Gupshup (62/100), Karix / Tanla (59/100), DoubleTick (55/100), WATI (50/100) and Respond.io (45/100).
Fact-check note (ClaimReview). The claim "no WhatsApp BSP is automatically DPDP Act 2023 compliant" is independently verifiable against the Gazette of India publication of the DPDP Act 2023 and the MeitY data protection framework page publishing the November 2024 draft Rules. Section 8(2) of the Act assigns primary liability to the Data Fiduciary; Section 2(i) and 2(k) define the Fiduciary / Processor roles. No statutory provision permits a Processor to be deemed compliant on behalf of a Fiduciary. RichAutomate Editorial — reviewed 1 June 2026.

Why this question is the wrong question (and what to ask instead)

Search demand for "which WhatsApp BSP is DPDP compliant" has grown roughly 4x year-on-year as Indian tenants try to procurement-gate the November 2024 draft Rules. The reason the question keeps producing unsatisfying answers is that it is structurally wrong. A BSP cannot certify the tenant's notice text. A BSP cannot capture consent that the tenant's lead-magnet form never offered. A BSP cannot answer a Data Principal access request for fields the tenant stores in a separate CRM. The right question is: which BSP makes Section 6, 8, 9, 11, 12 and 16 cheap to operationalise for a Fiduciary? That question has a clean answer scored against a 12-point controls matrix — covered in the next section.

For the underlying statutory framework, the canonical references are the MeitY data protection framework page, the gazette text of the DPDP Act 2023, and the draft DPDP Rules November 2024 consultation document. For the 25-step tenant-side checklist, see our deep dive at DPDP Act 2023 WhatsApp Business Checklist.

The 12-point BSP controls matrix (DPDP Section by Section)

Every control below is mapped to a specific DPDP Act section or November 2024 draft Rule. Score your shortlisted BSP on a binary basis — either the control is shipped admin-facing and demonstrable in a live demo, or it is not. Partial credit is generous; in a Data Protection Board production request under Section 28(7), partial is not enough.

1

Per-purpose consent capture (marketing / utility / authentication)

Section 6(1)

BSP exposes admin-facing per-template consent gates that block delivery to Data Principals who did not opt in to that purpose. Pre-ticked boxes and bundled consents fail the "specific, informed, unconditional, unambiguous" test.

2

Notice version hash on every consent record

Section 6(3) + draft Rule 3

Every consent ledger entry stores a SHA-256 hash of the exact notice version shown to the Data Principal at capture time. Notice changes do not silently invalidate historical consent.

3

One-click withdrawal "comparable in ease" to giving consent

Section 6(4)

STOP / OPT OUT keyword on WhatsApp triggers withdrawal across all marketing purposes inside 200 ms, propagating to scheduler, campaigns, and flow runs. Confirmation sent back to the Data Principal.

4

Consent ledger with timestamp, channel, IP, notice hash

Section 6(8) + 28(7)

Production-grade consent storage that the Data Protection Board can demand under Section 28(7) — ISO-8601 IST timestamps, source channel, device fingerprint, notice version hash, consent text.

5

Configurable retention with automated erasure

Section 8(8) + draft Rule 5

Per-purpose retention defaults (marketing 24 months from last engagement; utility per GST/income-tax law; authentication 90 days) with scheduler-driven erasure at the schema level, not soft-delete flags.

6

Data subject rights endpoint (access, correction, erasure)

Section 11, 12

Tenant-facing path that returns machine-readable personal-data snapshot within 7 working days of a Data Principal request, plus correction and erasure that propagate to backups, analytics, S3, and third-party CRMs.

7

Breach intimation runbook with 72-hour SLA

Draft Rule 6(1)

Documented runbook with named on-call, Form-B-ready template, dual notification to Data Protection Board + affected Data Principals, and audit logs proving 72-hour SLA from awareness.

8

Verifiable parental consent for minors (under 18)

Section 9

Guardian-consent path for fintech / gaming / health / edtech verticals. Behavioural monitoring and targeted advertising disabled for any age-tagged minor cohort.

9

Data residency in India (default Mumbai ap-south-1)

Section 16 + draft Rule 12

Primary storage and processing in Indian AWS region. Cross-border processor list documented and signed off by the Fiduciary. No silent cross-border transfer.

10

Signed Data Processing Agreement (DPA)

Section 8(2)

BSP signs a DPA naming sub-processors, security obligations, breach-notification SLA back to the Fiduciary, audit-cooperation clause, and termination data-return / deletion path.

11

Security safeguards (AES-256 at rest, TLS 1.3 in transit, RBAC, audit logs)

Section 8(5) + Section 33 First Schedule

Encryption at rest, encryption in transit, role-based access, audit logging of every personal-data read, quarterly penetration tests. Failure here attaches the INR 250 crore penalty band.

12

Grievance officer published on privacy page + WhatsApp profile

Section 8(9), 13

BSP exposes a configuration surface where the tenant publishes grievance officer name, email, phone, and SLA on the privacy notice and WhatsApp Business profile. Every complaint tracked to closure with timestamps.

How eight India-relevant BSPs score (June 2026)

Read this row-by-row. The score is the count of 12 controls a BSP ships admin-facing as of June 2026, prorated to 100 with a small weighting for control criticality (consent ledger, breach SLA, and data residency carry a 1.5x weight). Higher is better but the score does not make a tenant compliant by itself — it only measures how cheap the BSP makes compliance to operationalise.
BSPScore / 100HQMeta tierDPDP postureVerdict
RichAutomate94IndiaCloud API v24.0 directFull in-app toolkit: consent ledger, per-purpose gates, configurable retention, one-tap delete, policy generator, penalty calculator, signed DPA, Mumbai ap-south-1 by defaultStrongest tenant-facing DPDP surface in the India-relevant set as of June 2026
AiSensy71GurugramTech Provider (BSP)Per-template consent gates, signed DPA, partial admin-facing retention controlsStrongest fixed-tier BSP for DPDP among 2020-vintage incumbents; consent ledger is partial
Interakt68BengaluruBSPPer-template consent, DPA, enterprise-parent compliance lineageStrong contract-layer posture; in-app tenant-facing tooling thinner than #1
Gupshup62Bengaluru / SFPremier BSPEnterprise DPA, security certifications, custom controls available on quoteSolid for enterprise tenants with negotiating power; SMBs get contract-layer only
Karix (Tanla)59HyderabadBSPEnterprise DPA, BFSI-tested security posture, carrier-grade infraDefensible for regulated BFSI; consumer-facing self-serve DPDP tooling thin
DoubleTick55MumbaiMeta Business PartnerContract-layer DPA, basic consent gatesAdequate for small-team broadcast; admin-facing DPDP surface limited
WATI50Hong Kong (Clare.ai)BSPContract-layer DPA, international privacy framework focusIndia DPDP posture is contract-layer; data residency configuration requires explicit setup
Respond.io45Kuala LumpurBSPContract-layer DPA, multi-channel privacy frameworkMulti-channel focus dilutes WhatsApp-specific DPDP depth; international vendor

What changed between 2024 and 2026 that re-ranked every BSP

Three regulatory events between mid-2024 and mid-2026 invalidated every BSP-compliance article published before December 2024:

  1. MeitY draft DPDP Rules (November 2024). The Ministry of Electronics & IT published the consultation draft on 3 November 2024. Draft Rule 3 prescribed notice format. Draft Rule 4 prescribed consent manager registration. Draft Rule 6 prescribed 72-hour breach intimation to the Data Protection Board. Draft Rule 12 prescribed Significant Data Fiduciary controls. The cumulative effect: tenant-facing in-app tooling is now expected, not optional. See our DPDP consent-manager deadline checklist.
  2. Meta India 1 January 2026 conversation-rate revision. While this is a pricing event rather than a regulatory one, it accelerated BSP-switching activity, which exposed how few BSPs could ship a clean migration without re-capturing consent. See our January 2026 rate-hike calculator.
  3. RBI / IRDAI parallel posture tightening. The Reserve Bank of India and the Insurance Regulatory and Development Authority of India both refreshed customer-protection circulars through 2025. For BFSI tenants, BSP DPDP posture now has to compose with the RBI and IRDAI sector-specific data handling rules. The consolidated reference is our India WhatsApp regulation pillar.

How to verify your current BSP is DPDP-ready (30-minute audit)

Run this in 30 minutes on a screen-share with your BSP's solutions team. If they cannot demonstrate all five live, treat that as a procurement red flag at your next renewal:

  1. Show me the consent ledger admin view. Filter by purpose, by date range, by withdrawn-status. Export to CSV. If the consent ledger only exists at the database level and not in the admin UI, the BSP is shipping you a Section 28(7) production problem.
  2. Trigger a STOP keyword on a marketing campaign and time the propagation. Section 6(4) requires withdrawal "comparable in ease" to giving consent. Propagation under 200 ms is the bar; under 5 seconds is acceptable; under 5 minutes is a problem; over 5 minutes fails.
  3. Request a signed DPA from an authorised signatory. Not a template, not a generic terms-of-service. A DPA naming sub-processors, security obligations, breach-notification SLA back to the Fiduciary, audit-cooperation clause, and termination data-return / deletion path.
  4. Ask for documented data residency. The BSP should be able to name the AWS / Azure / GCP region for primary storage. Indian regions (Mumbai ap-south-1, Hyderabad ap-south-2) are the cleanest defaults under Section 16. Cross-border processors should be enumerated in the DPA.
  5. Request the breach-intimation runbook. Named on-call, Form-B-ready template for Board notification, dual notification path to Data Principals, audit logs proving the 72-hour SLA from awareness under draft Rule 6(1).
If your BSP fails 3 or more of the 5 checks above, the Section 8(2) liability you carry as a Data Fiduciary is materially elevated. The November 2024 draft Rule 6 breach intimation timeline alone makes the answer obvious — you cannot honour a 72-hour clock with a BSP that takes a week to find your consent ledger.

Section 6 consent: the part most BSPs get partially right

Section 6(1) language is verbatim "free, specific, informed, unconditional and unambiguous with a clear affirmative action." Five common BSP failure modes:

  • Bundled marketing-plus-utility consent. A single "yes I agree to receive messages" opt-in fails the "specific" test. Marketing must be a separate consent from utility from authentication.
  • Pre-ticked import lists. Uploading a CSV of historical customers without per-contact consent provenance fails. Section 6 needs a clear affirmative action per Data Principal.
  • Implicit consent from Click-to-WhatsApp ads. The click is an interest signal, not a Section 6 consent. The first message must offer notice + capture consent before subsequent marketing.
  • Notice version not stored with consent record. If the notice text changes in March 2026 and a Data Principal complains in May 2026, the consent record needs to prove what they actually consented to.
  • Withdrawal that does not propagate to scheduler. A STOP keyword that opts out of future captures but leaves 10,000 queued messages in the scheduler is a Section 6(4) failure.

RichAutomate ships per-purpose consent gates, notice version hashing, withdrawal propagation under 200 ms, and full consent-ledger export for Section 28(7) production. The implementation is documented in our DPDP consent management feature and the verification path is at DPDP readiness self-check.

Section 16 cross-border transfer: the part that quietly breaks WATI and Respond.io

Section 16 of the DPDP Act 2023 empowers the Central Government to restrict transfer of personal data to specified countries, and draft Rule 12 (November 2024) prescribes additional Significant Data Fiduciary controls. The practical reading: default to Indian AWS regions, document every cross-border processor, and avoid silent transfer of personal data outside India.

This is where international-headquartered BSPs introduce friction. WATI (Hong Kong-headquartered Clare.ai) and Respond.io (Kuala Lumpur-headquartered) both default to non-Indian processing regions unless the tenant explicitly configures Indian residency — and that configuration is not always available on the lower paid tiers. Brevo (Paris-headquartered) routes through EU regions by default. India-headquartered BSPs (RichAutomate, AiSensy, Interakt, DoubleTick, Gupshup, Karix) default to Indian regions, which is the cleanest Section 16 posture by construction. For pricing context across the full set, see our Top 11 WhatsApp marketing software India 2026 ranking and the 4-way comparison at Wati vs AiSensy vs Interakt vs RichAutomate.

Section 9 minor protection: the part fintech, edtech and gaming tenants miss

Section 9 requires verifiable parental consent before processing the personal data of any individual under 18, and Section 9(2) prohibits tracking, behavioural monitoring, or targeted advertising directed at children. For tenants in fintech, edtech, gaming, health, and consumer apps with under-18 cohorts, BSP support for guardian-consent flows and minor-cohort exclusion from retargeting is operationally non-trivial.

Most BSPs ship Section 9 support as a custom flow that the tenant has to build — which is fine, except that the burden of proof in a Data Protection Board investigation sits with the Fiduciary. RichAutomate ships a verifiable parental consent path as a flow template, plus an age-tagged cohort exclusion gate on campaign sends. For vertical-specific guidance, see our WhatsApp for edtech India 2026 pillar.

The 72-hour breach intimation SLA (draft Rule 6) and why it forces BSP selection

Draft Rule 6(1) from the November 2024 consultation reads verbatim: "Every Data Fiduciary shall, on becoming aware of any personal data breach, give intimation of such breach to the Board, without delay, and in any event within seventy-two hours of such awareness." The clock starts on awareness, not on confirmation. The first 24 hours are typically lost to triage; the next 24 to root-cause and scope; the final 24 to draft and submit. A BSP that takes a week to produce affected-Data-Principal lists makes the SLA structurally impossible to honour.

Concretely, the BSP needs to ship: (1) audit logs of every personal-data read with timestamps, (2) ability to scope a breach to affected Data Principals in single-digit hours, (3) a pre-approved Meta utility template for Data Principal intimation that does not need fresh template review, and (4) Form-B-ready data for Board submission. The 30-minute audit in the previous section is designed to expose whether your BSP can clear this bar.

What to do this quarter (Q2 / Q3 2026)

Whether your current BSP is on this list or not, three actions belong on the Q2 / Q3 2026 calendar:

  1. Run the 30-minute audit on your current BSP. If they pass all 5 live, you are well-positioned for the draft Rule 6 SLA. If they fail 3 or more, gate it on next renewal.
  2. Score every BSP shortlist against the 12-point controls matrix. Use the matrix in the section above. Apply a 1.5x weight to consent ledger, breach SLA, and data residency.
  3. Refresh your Section 6 notice and consent capture flow. Tenant-side work, but the BSP needs to support notice version hashing for it to be defensible in a Section 28(7) request. The 25-step playbook is at DPDP Act 2023 WhatsApp Business Checklist.

What to do next

If you are evaluating BSP DPDP posture today, the fastest way to validate this audit against your own controls map is a short call with the RichAutomate compliance team. We will score your current BSP live against the 12-point matrix, walk you through the 30-minute verification audit, and model the Section 8(2) liability delta if you stayed put versus switched. Book a 30-minute DPDP fit call, or message us on WhatsApp at +91 74349 01027. For the tenant-side companion deep-dive, read the 25-step DPDP Act 2023 checklist.

Score your BSP against the 12-point matrix

Bring your current BSP. We score it live.

30-minute screen-share. We run the 12-point controls audit on your live BSP admin, identify the 3 highest-blast-radius gaps, and model the Section 8(2) liability delta. No sales pitch.

Frequently asked questions

Is any WhatsApp BSP automatically DPDP Act 2023 compliant?

No. The Digital Personal Data Protection Act 2023 splits liability between the Data Fiduciary (the brand or tenant that determines purpose and means) and the Data Processor (the BSP that operates on instructions). No BSP can ship a product that makes the tenant compliant by default — Section 8(2) holds the Fiduciary primarily liable, and Section 6 consent capture must happen at the tenant collection surface. What a BSP can do is ship in-app tooling that makes Section 6, 8, 9, 11, 12 and 16 cheap to operationalise. As of June 2026, RichAutomate ships the deepest tenant-facing toolkit among India-relevant BSPs.

Which BSP has the strongest DPDP Section 6 consent posture?

Section 6(1) requires consent that is free, specific, informed, unconditional and unambiguous, with a clear affirmative action. The BSP needs to support per-purpose consent capture (marketing separate from utility separate from authentication), a notice version hash on every record, and one-click withdrawal that propagates to scheduler and flow runs in under 200 ms. RichAutomate ships this end-to-end. AiSensy and Interakt expose per-template consent gates. WATI, Gupshup, Karix, DoubleTick and Respond.io rely largely on contract-layer DPAs without admin-facing consent ledgers.

What does the November 2024 draft DPDP Rules change for BSP selection?

The Ministry of Electronics and IT draft Rules from November 2024 shifted the compliance posture from "contract-level DPA is sufficient" toward "tenant-facing in-app tooling is expected." Specifically: draft Rule 3 prescribes notice format with mandatory elements; draft Rule 4 prescribes consent manager registration; draft Rule 6 mandates breach intimation within 72 hours of awareness; draft Rule 12 prescribes Significant Data Fiduciary controls. A BSP without admin-facing consent, retention, deletion and breach-detection controls now ships its tenants a larger audit and breach blast-radius.

How do I verify my current BSP is DPDP-ready?

Run the 12-point controls audit in this article. The fast version: (1) ask your BSP to show you the consent ledger admin view in the product; (2) trigger a test STOP keyword on a marketing campaign and time the propagation; (3) request a DPDP Data Processing Agreement signed by an authorised signatory; (4) ask for documented data residency (Mumbai ap-south-1 is the cleanest default); (5) request a breach-intimation runbook with a 72-hour SLA. A BSP that cannot demonstrate all five in 30 minutes is not DPDP-ready in 2026.

Is the DPDP Act 2023 actually enforceable yet in June 2026?

The DPDP Act 2023 received Presidential assent on 11 August 2023 and was published in the Gazette of India. The Ministry of Electronics and IT released draft Rules in November 2024 for stakeholder consultation. As of June 2026, the Act is law but operational enforcement is staged as the Data Protection Board is constituted and the Rules are notified. Sensible operators are treating DPDP as live and building infrastructure now — Section 33 First Schedule penalties scale to INR 250 crore for breach of security safeguards, which makes wait-and-see economically irrational.

Should I switch BSPs purely on DPDP posture in 2026?

Only if your current BSP cannot demonstrate the five quick-verify items in question 4 above. For most tenants, the higher-impact move is to use the November 2024 draft Rules as a procurement gate on your next renewal — score every shortlisted BSP against the 12-point controls matrix in this article. RichAutomate ships migration as part of onboarding at no additional charge from AiSensy, Interakt, WATI, DoubleTick, Brevo, Gupshup and Karix; the cutover is a Meta-side BSP-change request that typically completes in 24 to 72 hours with zero downtime.

12 controls, Section-by-Section

Mapped directly to DPDP Sections 6, 8, 9, 10, 16 and November 2024 draft Rules 3, 4, 6, 12. Live demo-able.

Signed DPA + breach runbook

Authorised-signatory DPA naming sub-processors, plus a Form-B-ready breach intimation runbook with 72-hour SLA.

Mumbai ap-south-1 by default

Primary storage in Indian AWS region. Cross-border processors documented. Section 16 posture clean by construction.