Indian Shopify automation crosses three regulatory rails — GST e-invoicing, DPDPA 2023, and RBI's Payment Aggregator framework. Here is how they stack.
Under the GST regime administered by the Goods and Services Tax Network (GSTN), the e-invoicing requirement — that a taxable invoice must be reported to the Invoice Registration Portal (IRP) and receive an Invoice Reference Number (IRN) before it is legally valid — applies to businesses with aggregate turnover above ₹5 crore in any financial year from 2017-18 onward, effective from 1 August 2023 (Notification No. 10/2023 - Central Tax). This is a lowering from the original ₹500 crore threshold (October 2020) down through ₹100 crore, ₹50 crore, ₹20 crore, ₹10 crore, and now ₹5 crore, and the direction of travel is downward. Practical consequence for a Shopify seller: the WhatsApp automation is not the invoicing system. It cannot issue an IRN-bearing invoice on its own, and no BSP-provided template should attempt to. What it can do — and what a well-designed workflow does — is trigger the invoicing step by handing the order details to an e-invoicing solution that is IRP-registered (Zoho Books, ClearTax, TallyPrime, Vyapar, or the merchant's ERP). The WhatsApp message then confirms the invoice to the buyer with the IRN and QR code that the invoicing tool produces. Skipping this handoff — issuing a receipt-like message from WhatsApp without the IRN — creates a compliance gap that surfaces at GSTR-1 filing time when the invoice cannot be matched. For sellers below the ₹5 crore threshold, e-invoicing is not mandatory but GSTR-1 (monthly or quarterly under QRMP) and GSTR-3B are, and the same handoff logic applies: WhatsApp confirms, the accounting tool records.
The Digital Personal Data Protection Act 2023 (DPDPA), notified in August 2023, replaces the earlier data-protection regime that operated under Section 43A of the IT Act and the SPDI Rules 2011. The Ministry of Electronics and Information Technology (MeitY) published draft DPDPA Rules in January 2025 setting out operational specifics — consent notice format, data-principal rights (correction, erasure, grievance redressal), breach reporting to the Data Protection Board of India, and the criteria for Significant Data Fiduciary designation. As of publication the Board is being constituted and enforcement timelines are being staged, so operators should verify current status against the MeitY portal before finalising a compliance workflow. Structural obligations relevant to a Shopify + WhatsApp automation: (1) a clear consent notice at the point personal data is collected — the checkout page and any WhatsApp opt-in flow — that names the fiduciary, the purpose, and the retention period; (2) a documented lawful basis for each processing purpose (order fulfilment is contractual necessity; marketing messages require explicit consent under Section 6); (3) a mechanism for the data principal to withdraw consent, correct data, and request erasure — an opt-out reply on WhatsApp is part of this but not sufficient on its own; (4) breach-notification workflow within the timelines the final Rules set; (5) Data Protection Officer designation if the business qualifies as a Significant Data Fiduciary (thresholds to be finalised — high-volume processing of children's data and cross-border transfer are among the criteria expected). Two vendor-selection questions follow: does the BSP provide a Data Processing Agreement mapped to the DPDPA (not only GDPR), and does it document where WhatsApp Business Platform data is stored (Meta's data-centre geography, with India in the Meta APAC region)?
Shopify Payments — Shopify's native payment rail available in a growing list of countries — is not offered in India. Every Indian Shopify merchant therefore routes card, UPI, wallet, and net-banking payments through a third-party Payment Aggregator (PA) or Payment Gateway (PG). The Reserve Bank of India's PA/PG framework, first issued in March 2020 and amended through 2023-2024, requires that any entity holding merchant funds during settlement be RBI-authorised as a PA. The initial net-worth requirement is ₹15 crore, rising to ₹25 crore within three years of authorisation. Practical consequences for a Shopify merchant: (1) not every processor visible in the Shopify admin is currently RBI-authorised — the RBI publishes and periodically updates the list of authorised PAs on its website, and it should be consulted before onboarding; (2) an RBI enforcement action against a PA (there have been several since 2023 involving temporary settlement freezes) directly halts the merchant's cash flow; (3) UPI payments settled through NPCI's UPI rail are governed by NPCI operating circulars in addition to the RBI framework, and the effective per-transaction limits (₹1 lakh general, higher for specified categories) constrain what a WhatsApp bot can offer as a payment link. The WhatsApp automation itself is not a PA and cannot hold funds — the correct pattern is that the bot deep-links to the PA's checkout, the PA settles to the merchant, and the WhatsApp workflow confirms via the PA's webhook. Any BSP or WhatsApp automation that positions itself as receiving payments directly is misdescribing the flow.
With the three regulatory rails accounted for, the WhatsApp Business Platform itself remains the largest variable operating cost. Meta prices business conversations in four categories — service (user-initiated), marketing (business-initiated promotional), utility (business-initiated transactional), and authentication (OTP) — and rates vary by country. India-specific per-conversation rates are on the WhatsApp Business Platform Pricing page (developers.facebook.com/docs/whatsapp/pricing) and should be checked at the time of planning because Meta revises them periodically. Two structural points for Indian sellers: first, the marketing category is by an order of magnitude the most expensive of the four, and Meta's category classifier can reclassify a marketing-adjacent utility template downward at review, which shifts unit economics. Second, the free-tier rule (a set number of service conversations free per business per month) has moved twice in the last two years and should not be modelled as permanent. For an Indian Shopify seller running under ₹5 crore turnover, a defensible planning number is to model the current Meta rate plus 30% headroom for category drift and rate revisions, and to route only high-margin categories through marketing conversations — order updates, delivery status, and abandoned-cart nudges fit utility templates, which are cheaper and pass classifier review consistently.
Set against the three rails above, the WhatsApp automation earns its keep on a specific and narrow set of tasks. Order confirmation with IRN, once the invoicing tool has produced one. Shipping updates from the courier webhook (Delhivery, Shiprocket, Xpressbees, Blue Dart) mapped to a utility template. Abandoned-cart nudges to buyers who have opted in via a DPDPA-compliant consent notice, capped by a per-buyer send frequency to avoid marketing-category cost drift. Return and RMA status where the return system has already been triggered. Post-delivery review request, tied to the courier's proof-of-delivery timestamp. What automation is not for: negotiation on custom orders, complex product questions where the correct answer varies by SKU, escalations from B2B buyers with GSTIN-specific pricing terms, and any conversation that includes health, legal, or financial advice. The rule of thumb is the same as in other markets: automate the questions where the correct answer does not vary by buyer; leave to a human agent the ones where it does. In the Indian context there is an additional test: does this message step touch GST, DPDPA, or RBI PA obligations? If yes, the automation triggers the handoff to the compliant system; it does not perform the action itself.
For an Indian Shopify seller between ₹50 lakh and ₹10 crore annual GMV, a defensible stack looks like this. Storefront: Shopify with region set to India and INR primary currency. Invoicing: an IRP-registered e-invoicing tool (Zoho Books, ClearTax, TallyPrime, Vyapar) integrated with Shopify via native app or middleware, so every order above the ₹5 crore turnover threshold auto-generates an IRN. Payments: an RBI-authorised Payment Aggregator (verify current status against the RBI website — Razorpay, Cashfree, PayU, and Instamojo have been on the authorised list) integrated as the Shopify payment provider, with UPI enabled as a rail via that PA. Messaging: WhatsApp Business Platform accessed through a Meta-approved BSP with a DPDPA-mapped Data Processing Agreement, utility templates for order/shipping/delivery updates, marketing templates only for consented promotional sends. Consent capture: DPDPA-compliant notice at checkout and at any WhatsApp opt-in surface, with the consent record stored on the customer profile in Shopify (custom field) and mirrored in the CRM. Analytics: Shopify Analytics plus Meta's own Business Manager for template performance, cross-referenced monthly against the BSP invoice for per-conversation cost tracking. This stack does not require a single 'AI everything' vendor. It requires each layer to be defensibly correct on its own regulatory rail, and the handoffs between layers to be documented.
Data + numbers referenced in this article are sourced from these public documents:
BossBot runs Indian Shopify WhatsApp workflows across the Meta Cloud API with utility-first templates, DPDPA-aligned consent capture, and handoff to your existing IRP-registered invoicing tool.
See BossBot for Indian Shopify storesNot ready to sign up yet? Try the free demo →