Free workbook · 8 sections · DPDP Act 2023 + Rules 2025

DPDP Act 2023 Audit Workbook for WhatsApp Business · India 2026

The fillable, deeper audit instrument that follows our 47-point readiness checklist. Map Sections 5, 6, 7, 8, 11 and 16 onto your real WhatsApp stack — compute a 0–100 risk score, get section-by-section remediation, and print the result for your board.

80+ audit checkpoints DPDP section citations Interactive + print-to-PDF
Preview · 2 of 8 sections visible
  1. Section 1 of 8

    Data inventory — what personal data does your WhatsApp send and receive?

    DPDP Act 2023 · Section 2(t) (definition of personal data) + Section 8(4) (accuracy and inventory)

    A Data Fiduciary cannot protect what it has not mapped. This first sheet inventories every personal-data attribute that flows in and out of your WhatsApp Business stack — Cloud API, BSP, CRM, analytics, backups. Tick everything that is collected, transmitted or stored, even transiently. Anything ticked is in scope for the DPDP Act.

    • Full name of the customer or lead
    • WhatsApp / mobile phone number
    • Email address
    • Postal / shipping address
    • + 11 more checkpoints in the unlocked workbook
  2. Section 2 of 8

    Lawful basis — under which DPDP ground do you process each category?

    DPDP Act 2023 · Section 4 (grounds for processing) · Section 6 (consent) · Section 7 (certain legitimate uses)

    Section 4 of the DPDP Act permits processing only under two grounds: (a) consent of the Data Principal under Section 6, or (b) certain legitimate uses listed under Section 7 (voluntary provision of data, employment, medical emergency, public-interest functions, etc.). Map every personal-data category in your WhatsApp stack to a single, defensible ground.

    • Marketing messages (promotions, offers) — grounded in:
    • Utility / transactional updates (order, delivery, OTP) — grounded in:
    • Customer support replies inside the 24h window — grounded in:
    • Analytics, segmentation, ML / AI training — grounded in:
    • + 2 more checkpoints in the unlocked workbook
6 more sections locked
Free · DPDP-compliant

Unlock the fillable audit workbook

8 sections · 80+ audit checkpoints · DPDP section citations · 0–100 risk score with section-level remediation. Interactive web version + print-to-PDF.

No spam · Single-use consent · India-hosted · Educational use only — not legal advice

Why a DPDP audit, not just a checklist?

The Digital Personal Data Protection Act 2023 carries financial penalties up to ₹250 crore per breach class. Indian SMBs running WhatsApp Cloud API are almost all Data Fiduciaries under the Act — a name, a phone number, an address is enough to trigger the full obligation set.

A flat checklist (yes / no across 47 points) is a fast scan. An audit workbook is the deeper instrument your compliance officer, lawyer or auditor will actually act on — it forces you to answer specific questions, maps each answer to a DPDP section, and produces a risk-banded output you can take to the board.

This workbook is intentionally fillable. The interactive web version saves your answers locally so you can resume, print-to-PDF when done, and share the result internally without ever uploading sensitive data to a third party.

Inside the 8 sections

Each section maps to one or more DPDP Act 2023 clauses and produces a Low / Medium / High risk band.

Section 1

Data inventory — what personal data does your WhatsApp send and receive?

DPDP Act 2023 · Section 2(t) (definition of personal data) + Section 8(4) (accuracy and inventory)

A Data Fiduciary cannot protect what it has not mapped. This first sheet inventories every personal-data attribute that flows in and out of your WhatsApp Business stack — Cloud API

Section 2

Lawful basis — under which DPDP ground do you process each category?

DPDP Act 2023 · Section 4 (grounds for processing) · Section 6 (consent) · Section 7 (certain legitimate uses)

Section 4 of the DPDP Act permits processing only under two grounds: (a) consent of the Data Principal under Section 6, or (b) certain legitimate uses listed under Section 7 (volun

Section 3

Consent audit — is your WhatsApp opt-in valid under Section 6?

DPDP Act 2023 · Section 6(1) (consent must be free, specific, informed, unconditional, unambiguous with a clear affirmative action) · Section 6(4) (ease of withdrawal)

Section 6(1) sets six cumulative tests for valid consent: free, specific, informed, unconditional, unambiguous, with a clear affirmative action. Section 6(4) requires that withdraw

Section 4

Notice audit — does your privacy notice meet Section 5?

DPDP Act 2023 · Section 5 (notice) · DPDP Rules 2025 · Rule 3 (form and contents of notice)

Section 5 of the DPDP Act requires that, on or before requesting consent, the Data Fiduciary serves a notice in clear and plain language describing the personal data, the specified

Section 5

Data Principal rights — access, correction, erasure, grievance

DPDP Act 2023 · Section 11 (right to access information) · Section 12 (right to correction and erasure) · Section 13 (right of grievance redressal)

Sections 11–13 give every Data Principal four enforceable rights: access a summary of personal data being processed, correct or update it, erase it where retention is no longer nec

Section 6

Cross-border transfer — is your US / EU vendor stack DPDP-compliant?

DPDP Act 2023 · Section 16 (transfer of personal data outside India — restricted-country notification regime) · sectoral overlays (RBI · IRDAI · SEBI residency)

Section 16 of the DPDP Act permits transfer of personal data to any country EXCEPT those specifically restricted by Central Government notification (i.e. a negative-list regime). S

Section 7

Significant Data Fiduciary test — do you meet the Section 10 threshold?

DPDP Act 2023 · Section 10 (Significant Data Fiduciary obligations) · Section 10(1) (criteria — volume, sensitivity, risk to Data Principals, electoral democracy, security, public order)

Section 10 of the DPDP Act empowers the Central Government to notify a Data Fiduciary as a Significant Data Fiduciary (SDF) based on six criteria: volume and sensitivity of persona

Section 8

Breach response — do you have a 72-hour notification plan under Section 8(6)?

DPDP Act 2023 · Section 8(6) (notification of personal data breach to the Board and to affected Data Principals) · DPDP Rules 2025 · Rule 6 (form, manner and timing of breach intimation — without delay, in any case within 72 hours unless extended)

Section 8(6) requires a Data Fiduciary to notify the Data Protection Board AND affected Data Principals in case of a personal-data breach. The DPDP Rules 2025 (Rule 6) align this w

Pair this with

Frequently asked questions

How is this workbook different from your 47-point DPDP readiness checklist?+

The 47-point checklist at /lead-magnets/dpdp-readiness-checklist is a flat yes/no list — a fast first scan. This workbook is the deeper fillable audit instrument that maps your specific WhatsApp stack to DPDP Sections 5, 6, 7, 8, 11 and 16, computes a 0–100 risk score and produces section-level remediation. The two are designed to be used together: scan first, then audit.

Which DPDP Act 2023 sections does the workbook cover?+

Section 2(t) and 8(4) for the data inventory; Section 4 grounds for processing with Section 6 (consent) and Section 7 (certain legitimate uses); Section 6(1) and 6(4) for the consent audit; Section 5 with Rule 3 of the DPDP Rules 2025 for the notice audit; Sections 11, 12, 13 and 14 for Data Principal rights; Section 16 for cross-border transfer; Section 10 for the Significant Data Fiduciary test; and Section 8(6) with Rule 6 of the DPDP Rules 2025 for the 72-hour breach response.

Is the workbook a legal document I can submit to the Data Protection Board?+

No. The workbook is an educational audit instrument that helps you and your team understand DPDP obligations against your real WhatsApp Business stack. It is not legal advice and is not a substitute for review by qualified Indian counsel or an independent data auditor (Section 10(2)(c) of the DPDP Act). Use it to surface gaps and brief your lawyer or DPO.

Does the workbook save my answers?+

Yes — the interactive web version saves answers to your browser localStorage so you can resume the audit across sessions. Nothing is sent to RichAutomate servers from the workbook itself (only the lead form on this page submits to our backend). Print to PDF or "Save as PDF" any time to keep an offline copy.

What is the 72-hour breach notification rule the workbook tests?+

Section 8(6) of the DPDP Act 2023 requires the Data Fiduciary to notify the Data Protection Board and affected Data Principals in case of a personal-data breach. Rule 6 of the DPDP Rules 2025 specifies "without delay, in any case within 72 hours of becoming aware" unless the Board grants an extension. The workbook tests whether your incident-response plan, detection capability, notification templates and forensic capability are ready to hit that clock.

Who classifies as a Significant Data Fiduciary under Section 10?+

The Central Government may notify a Data Fiduciary as Significant under Section 10 based on six criteria: volume and sensitivity of personal data processed, risk to Data Principal rights, potential impact on India's sovereignty and integrity, risk to electoral democracy, security of the State, and public order. The workbook flags your likely SDF exposure based on volume (50 lakh+), sensitivity (KYC / health / financial / children), and automated decisioning.

Can I store Indian customer data on AWS US-East or OpenAI for WhatsApp AI replies?+

Section 16 of the DPDP Act 2023 permits cross-border transfer to any country EXCEPT those specifically restricted by Central Government notification (negative-list regime). Sectoral regulators (RBI for payment data, IRDAI for insurance, SEBI for securities, MeitY for health) may impose stricter India-only residency. Section 6 of the workbook walks you through this layered analysis, including AI / LLM vendors.

What is the founder's name behind this workbook?+

The workbook is published by RichAutomate Editorial · India DPDP Compliance Desk. RichAutomate is an Indian WhatsApp Business SaaS focused on DPDP-compliant messaging for Indian SMBs. For commercial enquiries write to [email protected].

Ready to ship DPDP-compliant WhatsApp?

Audit your stack with the workbook. Close the gaps with RichAutomate — granular consent capture, STOP keyword automation, 30-day erasure SLA, 72-hour breach templates and audit-ready logs.

Authored by RichAutomate Editorial · India DPDP Compliance Desk · Published 2026-05-21. Educational use only · not legal advice · consult qualified Indian counsel before relying on this audit in regulatory proceedings. DPDP Act 2023 references retrieved from the official Gazette of India and DPDP Rules 2025 notifications.