Durga Puja season does something strange to marketing calendars in Bengal.
Everyone wants to send something. New collection alerts. Puja discounts. “Shubho Mahalaya” greetings with a discount code slipped in right after. And the channel almost everyone reaches for first is WhatsApp, because open rates are high and it feels personal.
But before launching a campaign, businesses need to understand the WhatsApp Marketing Rules India 2026 landscape. Customer data, consent, promotional messaging and opt-outs involve the DPDP framework, while TRAI rules need to be understood separately from Meta’s own WhatsApp Business policies.
Here’s what businesses should know before the festive campaign begins.
First, What the DPDP Act Actually Means for You
The Digital Personal Data Protection Act, 2023 is India’s first real data privacy law. It got Presidential assent back in August 2023, but the operational rules — the DPDP Rules, 2025 — were only notified in November 2025. That matters, because the Act is being rolled out in phases, not all at once.
Here’s the simple version. Phase one, from November 2025, set up the Data Protection Board. Phase two, kicking in around November 2026, activates the consent manager framework. Full compliance across every provision isn’t required until mid-May 2027. So no, the entire law isn’t fully enforceable this instant — but that’s not a reason to relax. Several core obligations, especially around consent and notice, are already expected in practice, and the compliance runway is shorter than it looks.
What does this mean for a business sending Puja WhatsApp campaigns?
A customer’s phone number is personal data. So is their name, their purchase history, and anything else you’re using to personalise that festive message. Under DPDP, you’re a “Data Fiduciary” the moment you collect and use that information, and that role comes with obligations:
- You need clear, specific, informed consent before processing someone’s data for marketing
- That consent has to come with a plain-language notice — not buried in a 40-page privacy policy nobody reads
- Withdrawing consent has to be just as easy as giving it
- You can’t quietly repurpose a number collected for order updates into a marketing list without fresh consent
And the penalties aren’t symbolic. Violations can attract fines running into hundreds of crores, depending on severity. That’s not a number any business — big or small — wants attached to a festive sale campaign.
Now, TRAI — and the Myth That Confuses Everyone
This is where most business owners get genuinely confused, so let’s clear it up properly.
TRAI, the Telecom Regulatory Authority of India, governs commercial communication through the Telecom Commercial Communications Customer Preference Regulations, or TCCCPR 2018. It’s been amended a few times since — most recently in February 2025, with another round of changes under consultation in 2026. TCCCPR mandates something called DLT, or Distributed Ledger Technology registration, for anyone sending promotional SMS or making commercial calls. It also enforces the familiar rules — no promotional messages outside the 10 AM to 9 PM window, mandatory opt-out handling, and hefty penalties for spamming registered DND numbers.
Here’s the part that trips people up: TRAI’s DLT and TCCCPR framework applies to SMS and voice calls made over telecom networks. It does not apply to WhatsApp.
WhatsApp runs as an OTT — over-the-top — service, not a telecom network in the regulatory sense. So there’s no DLT registration step for WhatsApp marketing, no Sender ID approval process like you’d need for SMS, and no TRAI-mandated sending window specifically for WhatsApp messages.
That doesn’t mean WhatsApp is a free-for-all. It just means the rulebook is different — and it comes from Meta, not TRAI.
Meta’s Own Rules Are the Real Rulebook Here
If TRAI doesn’t govern WhatsApp marketing, Meta’s WhatsApp Business Messaging Policy does. And it’s stricter in some ways than anything TRAI has ever written for SMS.
The foundational rule: you cannot message someone on WhatsApp for marketing purposes without their prior opt-in. That opt-in has to be genuine — collected through your website, an SMS, an in-store form, a phone call with IVR confirmation, or on paper. Scraped numbers, purchased contact lists, or numbers pulled from an old billing sheet don’t count, no matter how tempting that “10,000 contacts, ₹500” bulk list looks right before Puja.
Once you have consent, every message you send falls into one of these categories, and Meta enforces the distinction strictly:
- Marketing — promotions, offers, product launches, festive sale announcements. Requires opt-in. Highest cost tier.
- Utility — order confirmations, shipping updates, appointment reminders. Must be strictly factual and tied to something the customer already did. No “also check out our Puja collection” tucked into a delivery update — Meta will reclassify it as Marketing the moment it smells promotional.
- Authentication — OTPs and login codes. No links, no media, nothing but the code.
- Service messages — free-form replies within the 24-hour window after a customer messages you first. Not templates, and not for cold outreach.
Mislabel a promotional festive blast as a “utility” update to dodge marketing costs, and Meta will catch it. Templates get re-categorised, delivery gets restricted, and your quality rating takes a hit that follows your number around.
Why Random Bulk Tools Are a Bad Bet This Puja Season
Every festive season, the same pattern repeats. Someone finds a cheap “WhatsApp bulk sender” tool online — often a modified app or browser script that isn’t connected to WhatsApp’s official infrastructure at all — and blasts a few thousand unopted numbers with a Puja discount banner.
It usually works for a day or two. Then it doesn’t.
WhatsApp’s detection systems track how people react to a business number — opens, replies, blocks, spam reports. Unofficial tools that push volume to unopted contacts get flagged fast, and Meta has actively pursued bans and even legal action against violators. In one recent year, WhatsApp banned over eight million accounts in India alone for policy violations, a meaningful share tied directly to unauthorised bulk sending. Once your number gets flagged, there’s often no appeal path and no way to recover your chat history or contacts. Given how much of a Puja campaign’s ROI depends on repeat customers recognising your number, that’s a brutal loss to take mid-season.
There’s a data angle too, and it loops right back to DPDP. Unofficial tools don’t run through WhatsApp’s secure infrastructure. There’s no guaranteed encryption, no consent audit trail, and no way to prove — if a customer complains or a regulator asks — that you actually had permission to message that number. Under DPDP, that absence of a consent record isn’t a minor gap. It’s exactly the kind of thing that turns a routine complaint into a real compliance problem.
What a Proper Setup Actually Looks Like
The alternative isn’t complicated. It just requires going through the front door instead of a shortcut.
- Use the official WhatsApp Business API through an approved BSP (Business Solution Provider) — not a modified app, not a scraping tool, not a “cracked” automation script
- Capture and store consent properly — timestamped, tied to the specific number, ideally noting what category of messages the customer agreed to receive
- Submit your festive templates for approval before the campaign goes live, and label them honestly — Marketing content stays Marketing, even if it costs more to send
- Respect the opt-out the moment someone asks, across every channel, not just WhatsApp
- Keep your consent records — under DPDP, being able to show how and when consent was obtained isn’t optional paperwork; it’s your actual defence if questioned
None of this requires exotic technology. Most legitimate BSPs handle template submission, consent logging, and quality monitoring as standard features, precisely because so many businesses have already been burned skipping this step.
A Quick Pre-Puja Compliance Checklist
- Contact list built entirely from opted-in numbers — no purchased or scraped lists
- WhatsApp Business API live through a verified BSP, not an unofficial tool
- Festive promotional templates submitted and approved under the Marketing category
- Consent notices written in plain language, not buried in fine print
- Opt-out mechanism tested and working across every template
- Consent and message records stored and retrievable, in case they’re ever needed
- Order and delivery updates kept strictly factual — no promotional language mixed into Utility templates
Planning your Durga Puja WhatsApp campaign? Set it up right the first time — through an official WhatsApp Business API partner, with proper consent capture — so a festive sale doesn’t turn into a banned number two weeks before Ashtami.
Disclaimer
This article is for informational purposes only and does not constitute legal or regulatory advice. While the information regarding the Digital Personal Data Protection (DPDP) Act, DPDP Rules 2025, TRAI regulations, and Meta’s policies is accurate as of the date of publication, these frameworks are subject to ongoing updates. Businesses should consult with qualified legal counsel and work with verified WhatsApp Business Solution Providers (BSPs) to ensure their specific data collection and marketing practices remain compliant.
Frequently Asked Questions
Does DLT registration apply to WhatsApp marketing?
No. DLT and TCCCPR apply to SMS and voice calls over telecom networks. WhatsApp is an OTT platform and follows Meta's own Business Messaging Policy instead.
Can I message old customers who never explicitly opted in to WhatsApp marketing?
Not for marketing content. If they've interacted with you recently, service replies within the 24-hour window are fine. But cold marketing messages to non-opted contacts violate both Meta's policy and, quite possibly, DPDP consent requirements.
Is the DPDP Act fully enforceable right now?
It's being rolled out in phases through 2025–2027. Some obligations are already active; full enforcement lands by mid-May 2027. Waiting for the last deadline before building proper consent practices is a risky bet, not a compliance strategy.
What's the actual risk of using a cheap bulk WhatsApp tool for Puja campaigns?
Permanent number bans, loss of chat history and contacts, no recourse with Meta, and — separately — potential DPDP exposure if you can't demonstrate valid consent for the numbers you messaged.
If a customer initiates a chat with us during Puja, does that mean we can send them marketing messages later?
No. A customer initiating a chat opens a 24-hour "service" window for free-form replies. It does not act as a blanket opt-in for future promotional campaigns. You still need explicit, recorded consent to send them Marketing templates after that 24-hour window closes.
Do I need a separate opt-in specifically for WhatsApp, or does my website's general Terms and Conditions cover it?
Under the DPDP Rules 2025 and Meta’s policies, consent must be specific, informed, and itemized. Hiding a WhatsApp marketing opt-in inside a generic, multi-page Terms and Conditions document violates the DPDP’s "clear notice" requirement. You need a dedicated, clear opt-in mechanism (like an unchecked checkbox) specifically for WhatsApp communications.
What happens if a customer opts out on WhatsApp, but we still have their number on our SMS list?
Consent is channel-specific unless stated otherwise, but you must honor the withdrawal immediately for the channel requested. If they reply "STOP" on WhatsApp, you must cease WhatsApp marketing immediately. Under DPDP, making the opt-out process difficult or ignoring it across integrated systems is a direct compliance violation.
Are Marketing templates priced differently from Utility templates during the festive season?
Yes. Meta charges different rates based on the conversation category, and Marketing conversations are the most expensive tier. Attempting to misclassify a promotional Puja message as a "Utility" update to save money will result in Meta rejecting or reclassifying the template, and potentially restricting your sending limits.
Reference Links
- Official DPDP Framework: Ministry of Electronics and Information Technology (MeitY) — DPDP Act & Rules Updates
- WhatsApp Official Guidelines: WhatsApp Business Messaging Policy
- TRAI Commercial Communication Rules: Telecom Regulatory Authority of India — TCCCPR 2018 framework

