On this page
COMPLIANCE AND SECURITY
DPDP Act (India)
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India's data protection law. It requires businesses (data fiduciaries) to process personal data only for a lawful purpose with the individual's consent or another recognised ground, to give clear notice, to honour requests for correction and erasure, to protect the data, and to report breaches, with penalties of up to Rs 250 crore per breach category.
gdprpiiopt inencryption at rest
Why it matters
WhatsApp numbers, names and conversations are personal data. The Act's consent rules match Meta's opt-in rules almost exactly, so a business that collects and records WhatsApp consent properly is most of the way to compliance. Rules under the Act have been phased in, so the obligations are now practical rather than theoretical.
In VGraple CRM
Consent source and time are stored per contact, notices can be linked from forms and widgets, erasure is a contact-level action, personal fields are encrypted at rest, roles limit who sees what, and the audit log records access. The security page and DPA describe the controls.