Under India's Digital Personal Data Protection Act 2023, a business using 3xRetention is the Data Fiduciary for its customer data and 3xRetention is the Data Processor, acting only on that business's instructions. We provide the mechanisms you need to meet your obligations: consent capture and records, notice text, data principal rights handling, breach notification, and a Data Processing Agreement.
This page summarises the law in plain English. It is not legal advice. For decisions about your own business, speak to a lawyer who knows the DPDP Act.
The law
What is theDPDP Act?
India's first full data protection law. The Digital Personal Data Protection Act was passed in August 2023. It governs how businesses collect, use, store and delete digital personal data about individuals in India — and data collected on paper that is later digitised.
The Act sets the principles. The DPDP Rules, notified in November 2025, set out how they work in practice. Obligations are phasing in, and most of what the Act asks of businesses applies from 2027.
Penalties are set per breach and can reach ₹250 crore for failing to take reasonable security safeguards. The Data Protection Board of India hears complaints and decides penalties.
Roles
Who is responsiblefor what?
The Act gives the main duties to whoever decides why data is collected. When you use 3xRetention, that is you. We process the data on your behalf, under a contract, and only as you instruct.
DPDP Act roles when a business uses 3xRetention
Role under the Act
Who
What the role must do
Data Fiduciary
You — the business
Decide what is collected and why. Give notice and obtain consent. Honour access, correction, erasure and grievance requests. Keep reasonable security safeguards, including over your processors. Use a processor only under a valid contract. Tell the Board and affected customers about a breach. Erase data once its purpose is served.
Data Processor
3xRetention
Process data only on your instructions and under the Data Processing Agreement. Keep reasonable security safeguards. Tell you promptly about a breach affecting your data. Help you act on your customers' requests. Delete or return the data when the service ends, as you instruct.
Data Principal
Your customer
The individual the data is about. Can give or withdraw consent, ask to access, correct or erase their data, raise a grievance, and nominate someone to act for them.
Consent
How is consentcaptured and withdrawn?
Consent must be free, specific, informed, unconditional and unambiguous, and withdrawing it must be as easy as giving it. That is the Act's test, and it matches what WhatsApp already requires before a business can message someone.
3xRetention records each contact's opt-in against their record and checks for it before any outbound message goes out. Those records are what you show if a customer or the Board asks how consent was obtained.
When a customer withdraws consent, the withdrawal is recorded against the same contact. Because the opt-in check runs before every outbound message, further marketing to them stops on every flow — not just the one they replied to.
Notice
What must youtell your customers?
When you ask for consent, you must tell the customer, in clear and plain language: what personal data you collect, what you will use it for, how they can withdraw consent, how they can exercise their rights, and how they can complain to the Data Protection Board.
The notice must be understandable on its own, and customers can ask for it in English or any language in the Eighth Schedule of the Constitution. Here is the notice text we provide. Adapt it to what your business actually does before you use it.
Notice text you can adapt
Sample notice for WhatsApp customers
[Your business name] uses your name, phone number, and the messages and orders you share with us on WhatsApp to answer your questions, process your orders and payments, and send your invoices.
If you agree, we will also send you offers and reorder reminders. We use 3xRetention to manage these conversations on our behalf.
You can withdraw your consent at any time by [how to withdraw — e.g. replying STOP]. Withdrawing does not affect orders already placed.
To access, correct or erase your data, or to raise a complaint, contact [grievance contact name and email]. If you are not satisfied with our response, you can complain to the Data Protection Board of India.
Replace every [bracket] before use.
Rights
Your customers' rights,and how you handle each
The Act gives each of your customers five rights. The request comes to you; the mechanism to act on it is in 3xRetention.
(01)
SECTION 11
Access
A summary of the data you hold about them and how you use it. Their record and conversation history are in your account, and you can export them.
(02)
SECTION 12
Correction
Wrong or incomplete details are corrected or completed. You update the contact's record, and every flow uses the corrected version.
(03)
SECTION 12
Erasure
Their data is erased unless another law requires you to keep it. We delete it from what we hold for you, on your instruction.
(04)
SECTION 13
Grievance redressal
They can complain to you first, and to the Board after that. Every conversation is logged, so you can see exactly what was said.
(05)
SECTION 14
Nomination
They can name someone to exercise their rights if they die or cannot act. Verify the nominee, then handle the request the same way.
Retention
How long isdata kept?
While you use 3xRetention, your data is kept so the agent can work. The Act expects you to erase personal data once the purpose it was collected for is served, or when consent is withdrawn — and to make your processor do the same.
When you cancel, you can export everything first, and have it permanently deleted whenever you choose. You can also have a single customer's record deleted at any time.
Some records have their own legal clocks. GST invoices, for example, must be kept for the period tax law sets, and the Rules require certain processing logs to be kept for a minimum period. Deletion covers everything the law allows to be deleted.
Breach notification
What happens ifthere is a breach?
Under the Act, the duty to notify the Board and the affected customers is yours as the Data Fiduciary. Ours is to tell you fast, with the facts you need to do it.
Breach notification steps under the DPDP Act and Rules
Step
Who does it
When
Tell you about a breach affecting your data, with what happened and which data was affected
3xRetention
Promptly, once confirmed
Initial intimation to the Data Protection Board of India
You, as Data Fiduciary
Without delay after becoming aware
Detailed report to the Board — facts, cause, likely impact, steps taken, who was told
You, as Data Fiduciary
Within 72 hours of becoming aware, unless the Board allows longer
Tell each affected customer what happened, the likely consequences, what you are doing and what they can do
You, as Data Fiduciary
Without delay, in plain language
Cross-border
Does any dataleave India?
Your data is stored in India.
Two parts of the service involve other companies' systems: every WhatsApp message travels through Meta's WhatsApp Business Platform, and replies are generated using a third-party AI model provider. The processing location of each sub-processor is available on request, in writing, for your procurement review.
The Act allows personal data to be transferred outside India unless the government restricts a particular country, and sector rules — such as those that apply to regulated financial data — can be stricter. The full sub-processor list is on our Trust & Security page
Your DPA
Your Data ProcessingAgreement
The contract the Act requires between you and your processor. It records that we act only on your instructions, the safeguards we keep, how we help with your customers' requests, how and when we tell you about a breach, and what happens to your data when the service ends. You should not have to go through sales to read it.
Yes. The DPDP Act lets a Data Fiduciary use a Data Processor only under a valid contract. Our Data Processing Agreement is that contract: it records that we act only on your instructions, what safeguards we keep, and what happens to the data when the service ends.
You are. As the Data Fiduciary you decide why the data is collected and you hold the relationship with your customer, so the duty to give notice and obtain consent sits with you. 3xRetention records opt-ins against each contact and checks for one before any outbound message, which gives you the records to show it was done.
It covers personal data about individuals, whoever they buy for. The purchase manager of a distributor who messages you from their own WhatsApp number is an individual, and their name and number are personal data. Treat B2B contacts the same way you treat retail customers.
In phases. The DPDP Rules were notified in November 2025. A few provisions, including those setting up the Data Protection Board, applied straight away; most of the obligations on businesses apply 18 months after notification, which is May 2027. Building consent records and rights handling now is far easier than retrofitting them later.
Act on it. Erase their record unless another law requires you to keep it — GST invoices, for example — and stop further messages to them. In 3xRetention, deletion is carried out on your instruction across the data we hold for you. Keep a note of the request and when it was completed.
Book a demo
See it run on your own catalogue
Send us your product list and we will set the agent up on it before the call. You will watch it answer questions about your own products, not a generic demo account.Thirty minutes. No obligation.
A demo on your products, not ours
Pick a time that works. Share a catalogue, price list or website link when you book and we load it into the agent before we speak.
Before the call
You send a catalogue, price list or website link. We set the agent up on it.
On the call · 30 min
You ask it the questions your customers actually ask. We show you the segments and follow-ups it would run.
After
A written summary of what it would do for you, and what it would cost.