Your broadcast list, contact register, and order chat history are all personal data records under Section 3(a)(ii) of the DPDP Act.
Many small businesses maintain a WhatsApp broadcast list of 50–5000 customers. Under Section 3(a)(ii) of the DPDP Act, a digitised record containing personal data — including a phone contacts list — is fully covered by the Act, even if you never intended it to be a "database."
This means every WhatsApp seller who has saved customer contacts and sends them promotional messages is technically operating as a Data Fiduciary without a consent framework.
| No. | Record | Why it's covered |
|---|---|---|
| 01 | Broadcast list | Every customer on your list has "opted in" to receive messages — but without explicit DPDP consent, this is insufficient |
| 02 | Saved contacts | Phone numbers saved in your phone = personal data records |
| 03 | Order chat history | Messages containing names, addresses, preferences |
| 04 | Google Sheets order log | If you maintain a digital order register |
| 05 | WhatsApp groups | Group members' phone numbers are personal data |
| 06 | Voice messages about orders | If saved digitally, these are records |
Get explicit consent
Before adding someone to your broadcast list or saving their data, you need to send them a DPDP-compliant consent request in their language.
Make it easy to opt out
Every broadcast must include a way to request data erasure. "Reply STOP" alone is not sufficient — you need to delete their data, not just stop messaging.
Secure your contact list
Customer phone numbers saved in personal phone or unencrypted spreadsheet is a security risk. Use a compliant CRM.
Don't share data with third parties without consent
Sharing customer details with delivery partners or other vendors without their consent is a violation.
Find out in 2 minutes with our free checker.