On this page
COMPLIANCE AND SECURITY
GDPR
The General Data Protection Regulation (GDPR) is the European Union's data protection law. It applies to any business, anywhere, that processes personal data of people in the EU, including their WhatsApp numbers and conversations. It requires a lawful basis for messaging (usually consent for marketing), records of that consent, honouring deletion and access requests, and a data processing agreement with every processor such as your CRM.
dpdp actdata processing agreementpiiopt in
Why it matters
Indian businesses with European customers, and any exporter or agency, are in scope. WhatsApp marketing without recorded consent is the typical breach. The vendor question matters too: your CRM processes the data on your behalf and must be bound by a DPA with EU-standard clauses.
In VGraple CRM
Consent is recorded per contact with source and time, deletion and export requests are handled from the contact record, personal fields are encrypted at rest, and a DPA with standard contractual clauses is available at /dpa. The security page lists sub-processors and data locations.