Using WhatsApp, Google Drive & Shared Folders Safely Under the DPDP Act, 2023

India’s Digital Personal Data Protection Act, 2023 (DPDP Act) does not outlaw the use of WhatsApp, Google Drive, network shared folders, or other cloud-based collaboration tools. Instead, it places the onus on the organization acting as the Data Fiduciary to ensure that personal data processed through these tools is handled lawfully, only for permitted purposes, and with adequate security safeguards.

The core message is simple: the platform is not the problem; misuse is. Whether an assessee uses WhatsApp, a cloud drive, or an internal shared folder, compliance is judged against the DPDP Act’s principles of purpose limitation, accountability, security, data minimisation, and breach management.

This article explains how WhatsApp, Google Drive, and shared network drives can be used in line with the DPDP Act, highlights key risks, and provides a practical compliance checklist—especially relevant for finance and accounting firms, but equally applicable to any data-driven organization.


DPDP Act’s Technology-Neutral Approach

The DPDP Act does not single out any specific application, messaging service, or storage provider. Rather, it:

  • Focuses on how personal data is collected, used, stored, and shared
  • Imposes duties on Data Fiduciaries even when they rely on Data Processors such as cloud providers
  • Requires reasonable security safeguards, not specific brands or tools

Key Insight
Compliance is evaluated against obligations such as lawful purpose, consent or legitimate use, security controls, and timely deletion—not against whether data was on WhatsApp or in Google Drive.


Use of WhatsApp for Personal Data: Risks and Controls

WhatsApp is commonly used for day-to-day business communication, including sending documents and screenshots. Under the DPDP Act, this is not banned, but it is high-risk if not managed carefully.

Typical Use Cases

  • Sending KYC documents (e.g., PAN, Aadhaar) from clients to firm staff
  • Sharing salary slips or HR-related information with employees
  • Exchanging bank details, financial statements, or tax computation files

Key DPDP Considerations

When an assessee’s team uses WhatsApp to handle personal data, the following obligations are crucial:

  • Legitimate and disclosed purpose only

    • Personal data should be transmitted only if it is necessary for a purpose already communicated to the Data Principal (client, employee, vendor, etc.) in line with Section 4 and Section 5(1).
  • Limit access to those who truly need it

    • WhatsApp groups with broad participation (e.g., all staff, large project teams) are rarely appropriate channels for sharing documents like KYC records or payroll data.
  • Avoid unnecessary retention

    • Personal data should not remain indefinitely in chat histories and media galleries. Data should be deleted when the purpose is complete, subject to any statutory retention requirements.
  • Implement security safeguards

    • Devices used to access WhatsApp (phones, desktops with WhatsApp Web) must have PINs/passwords, updated operating systems, and, ideally, device-level encryption.

Risk Illustration

Risk Example
An accounts executive forwards a client’s PAN card, Aadhaar copy, and salary slip to a WhatsApp group that includes multiple staff members who are not involved in that client’s assignment.

This can amount to an unauthorized disclosure of personal data, potentially triggering personal data breach obligations under Section 8(6) if it leads to or risks misuse.


Using Google Drive for Storing and Sharing Personal Data

Google Drive and similar cloud platforms (such as Microsoft OneDrive or Dropbox) are often used to store client and employee records. These tools can be compatible with the DPDP Act, provided that permissions and access configurations are properly managed.

Key DPDP Considerations

  • Principle of least privilege

    • Access must be granted only to the specific individuals who require the data for the relevant purpose. Generic “team-wide” access for convenience is risky.
  • Avoid public or broadly shared links

    • Settings such as “Anyone with the link” or “Public on the web” are usually incompatible with responsible handling of personal data unless the document is meant to be truly public (which will almost never be the case for KYC, payroll, or HR records).