What WhatsApp Business Platform compliance actually requires in India
Running WhatsApp automation in India legitimately requires four things: documented opt-in from every recipient, pre-approved message templates for anything you initiate, a working opt-out that is honoured across every workflow, and — for promotional messaging — DLT registration under TRAI’s TCCCPA regulations, which is the sender’s obligation and not the agency’s. Most of what is sold as “WhatsApp marketing automation” in this market skips at least two of these, and the failure mode is not a fine. It is your number being permanently banned, with the conversation history attached to it.
This is the part of the work nobody writes about honestly, so here it is in full.
Official API only, and why the unofficial ones are not a shortcut
There are tools that drive WhatsApp by automating the desktop or web client rather than going through Meta’s Cloud API. They are cheaper, they need no business verification, and they will get the number banned. Meta detects the pattern and enforces against it, and there is no appeal worth the name because the terms were clear.
The official WhatsApp Business Platform requires business verification, which takes as long as it takes — that is on Meta’s timeline, not your agency’s, and any quote that promises a date for it is guessing.
Opt-in has to be documented, not assumed
“They gave us their number” is not opt-in. What is required is a record: the consent, when it was given, and through what. If Meta asks — and they do ask, usually when a quality rating drops — you need to produce it.
Built properly, consent is captured at the point of collection with a timestamp and a source, stored somewhere you can query. Retrofitting this onto a list you already have is not possible, which is worth knowing before you buy a list.
Templates, and the quality rating you did not know you had
Any message your business initiates outside a 24-hour customer service window has to use a template Meta approved in advance. Templates get rejected, usually for being more promotional than declared, and the approval cycle is part of the delivery timeline.
Behind this sits a quality rating on your number that moves with how recipients react. Blocks and reports drive it down; a low rating cuts your messaging limits and eventually stops you sending. This is the mechanism by which sending to people who did not ask destroys the channel — not a rule you break once, but a rating that degrades until the number is useless.
Opt-out has to actually work
Stop-word handling, a suppression list honoured by every workflow rather than the one that handled the request, and an audit log of what was sent to whom. The common failure is a suppression list that one workflow respects and another does not, which means the person who opted out keeps hearing from you through a different flow — the worst version, because it looks deliberate.
TRAI, TCCCPA, and DLT: yours, not ours
Promotional messaging in India also falls under TRAI’s Telecom Commercial Communications Customer Preference Regulations, with sender registration on the DLT platform, registered headers, and registered templates. These obligations sit with you as the sender. We build to them, and we will tell you what they require, but we cannot register on your behalf.
What we will not build
For completeness, because it is the honest end of this: we do not build unsolicited bulk messaging, and we do not build on unofficial APIs, whatever the instruction. Not because of a policy document — because it destroys the asset it is meant to exploit, and we would rather say so at scoping than hand over something that gets your number banned in month three.
If you want the compliant version, it is WhatsApp Business automation, and it typically takes two to three weeks once verification is through.
- WhatsApp Business Platform
- TRAI TCCCPA
- DLT registration
- messaging compliance