TikJoy

WhatsApp Opt-In and GDPR: Consent You Can Prove

TikJoy Editorial TeamAugust 31, 20267 min read

A WhatsApp opt-in is only worth what you can prove about it. Under the GDPR the burden sits on you: not to argue that the customer probably agreed, but to show when they agreed, to what, in what words, and how they could have refused. Most opt-ins collected in the wild fail that test not because the customer objected, but because nobody stored the evidence โ€” and a consent you cannot evidence is, in practice, a consent you do not have.

This guide covers the two rulebooks that apply at once, what makes a WhatsApp consent valid, how to design the checkbox and the confirmation step, what your consent record must contain, and why legitimate interest is not an escape route in Europe. It is general information, not legal advice โ€” have your own flow reviewed by counsel.

Two rulebooks apply at the same time

Meta's policy requires businesses to obtain opt-in before sending business-initiated messages, to make clear that messages will arrive on WhatsApp, and to state what kind of messages to expect. Consent can be collected on any channel โ€” a web form, a checkout, an in-store QR code, a phone call โ€” as long as the user actively agrees. Meta does not prescribe a storage format; it holds you responsible for having obtained it.

Data protection law is stricter and independent. In the EU, GDPR Article 4(11) defines consent as freely given, specific, informed and unambiguous, expressed through a statement or a clear affirmative action. Article 7(1) requires the controller to be able to demonstrate it. Article 7(2) requires the request to be distinguishable from other matters and in plain language. Article 7(3) requires withdrawal to be as easy as giving it.

Passing one rulebook does not pass the other. Meta may never audit your consent log; a supervisory authority responding to a single complaint will ask for exactly that record.

What makes a WhatsApp consent valid

It names the channel. "Sign up for updates" does not authorise WhatsApp. The request must say the messages arrive on WhatsApp, because consent must be specific to the processing it authorises.

It is separate from other channels. A single checkbox covering email, SMS and WhatsApp bundles three distinct purposes into one act. Split them, and let the user take one without the others.

It is separate from the contract. Consent to marketing cannot be a condition of buying, registering, or downloading. Bundled into terms of service, it is not freely given.

It is affirmative. Pre-ticked boxes, opt-out-by-silence, and "by continuing you agree" are not clear affirmative action. Neither is a checkbox whose label points only to a privacy policy the user must read to discover what they agreed to.

It is granular where the message types differ. Order updates and promotional campaigns are not the same purpose. Per-category consent costs one extra checkbox and is the difference between one channel being suspended and the rest surviving.

Double opt-in, and why it is about evidence

Double opt-in means the initial agreement is confirmed through a second, independent step โ€” typically a message the user must answer to activate the subscription. The GDPR does not mandate it. It matters because it manufactures evidence you would otherwise lack: proof that the number belongs to the person who consented, and a timestamped confirmation originating from the device itself.

The failure mode it prevents is mundane. Someone mistypes a digit, or a competitor enters your number in a form. Without confirmation you have a consent record pointing at a person who never gave it, and a complaint that you cannot rebut with the record you hold.

Where the opt-in was collected on WhatsApp itself โ€” the user messaged you first and asked for updates โ€” the confirmation is inherent, and a second round trip only adds friction.

What the record must contain

Assume you will one day have to produce a single line proving one person's consent. That line should carry the identifier consented against (the phone number), the timestamp, the collection point (which form, which page, which store), the exact wording shown at the time, the version of the privacy notice in force, and the outcome of any confirmation step.

The wording is the part teams forget, and the part that decides the case. A consent gathered under text you have since changed can only be defended if you can retrieve the text as it stood. Version your consent strings and store the version identifier with each record, rather than a link to the current live page.

Withdrawal belongs in the same record. Log the opt-out, the timestamp, and the channel it arrived on, and honour a STOP reply or an equivalent instruction as immediately as a form submission โ€” the ease-of-withdrawal requirement in Article 7(3) is about the user's effort, not yours.

Legitimate interest is not the shortcut

The recurring temptation is to skip consent and rely on legitimate interest under Article 6(1)(f), on the theory that existing customers expect to hear from you. In Europe this argument is weak for electronic direct marketing, because the ePrivacy regime imposes a consent requirement of its own on top of the GDPR, and it is narrow.

Article 13 of Directive 2002/58/EC allows a limited "soft opt-in": a business that obtained contact details in the context of a sale may market its own similar products, provided the customer can object easily at collection and in every subsequent message. Member states implement this differently, and the exception is usually written around email. Extending it to a channel as intrusive as WhatsApp is an argument you would be making for the first time, in front of a regulator, about a message the recipient already complained about.

Italian enforcement illustrates how little room there is. In a decision of 23 October 2025, the Garante rejected a company's attempt to justify promotional emails on legitimate interest, restated that promotional communications cannot be sent without prior consent, confirmed that the soft-spam exception applies only to existing customers for similar products, and added that public registries are not a legitimate source for building marketing lists. The company escaped a fine only because the conduct was old, involved two emails, and came from a micro-enterprise โ€” the finding of unlawfulness stood regardless.

When collecting WhatsApp opt-in is the wrong move

If your only planned use is transactional โ€” order confirmations, delivery updates, appointment reminders to people who booked โ€” a broad marketing opt-in is over-collection. Ask for what the messages actually are, and do not acquire a marketing consent you have no campaign for. Unused consent still ages, still has to be documented, and still has to be deleted on request.

It is also the wrong move when the opt-in is bought rather than earned. Purchased lists, scraped numbers, and consent gathered by a partner "on your behalf" without proof you can inspect are the single most common route to an enforcement file. If you cannot see the wording the person agreed to, you do not have a consent โ€” you have a phone number.

And if your volume genuinely does not justify a consent management layer, resist the temptation to hand-roll one in a spreadsheet: run utility messaging to people who transacted with you, and add marketing consent when there is a campaign to justify it.

A flow that survives scrutiny

Put a dedicated, unticked checkbox on the form, worded in the first person and naming WhatsApp explicitly. Store the number, the timestamp, the source, and the version identifier of the exact wording. Send a confirmation message that states what the person will receive and how to stop. Log the reply. Offer STOP in every campaign, process it automatically, and reflect it in the same record. Review the wording once a year and bump the version rather than editing in place.

None of this is expensive to build. It is expensive to retrofit, because the records you did not keep cannot be reconstructed later โ€” which is the whole reason to design the collection point before the first campaign rather than after the first complaint. The WhatsApp Business API marketing guide covers what you can do once the consent side is sound.

TikJoy runs its concierge on the official WhatsApp Business API, which is the layer where every rule above applies: the opt-in, the record, and the withdrawal are the brand's, not the platform's. See how the WhatsApp AI Concierge works.

Frequently asked questions

Do I need consent to send WhatsApp marketing messages in the EU?

Yes, on two independent grounds. Meta's policy requires opt-in before any business-initiated message, naming WhatsApp as the channel and stating what messages to expect. Separately, EU data protection and ePrivacy rules require prior consent for electronic direct marketing, and GDPR Article 7(1) requires you to be able to demonstrate that consent, not merely assert it.

Can one checkbox cover email, SMS and WhatsApp?

No. Consent must be specific to the processing it authorises, so a single box bundling three channels collapses three distinct purposes into one act. Split them and let the user accept one without the others. The request must also be distinguishable from other matters under Article 7(2), which rules out consent buried inside terms of service.

Is double opt-in required by the GDPR?

It is not mandated. Its value is evidentiary: a confirmation step proves the number belongs to the person who consented and produces a timestamped confirmation from the device itself. That closes the common failure mode of a mistyped or third-party number, where your record names someone who never consented. Where the user messaged you first to ask for updates, the confirmation is already inherent.

Can I rely on legitimate interest instead of consent?

For electronic direct marketing in Europe this is a weak position. Article 13 of Directive 2002/58/EC allows only a narrow soft opt-in, for contact details obtained in the context of a sale, for the seller's own similar products, with an easy objection at collection and in every message. In a decision of 23 October 2025 the Italian Garante rejected a legitimate-interest justification for promotional emails and confirmed the exception reaches only existing customers for similar products.

What must a WhatsApp consent record contain?

Enough to defend one contact in isolation: the phone number, the timestamp, the collection point, the exact wording displayed at the time, the version of the privacy notice then in force, and the outcome of any confirmation step. Version your consent strings and store the version identifier per record rather than a link to the current page, and log withdrawals in the same place.

TikJoy Editorial Team โ€” TikJoy's editorial team writes about performance UGC, WhatsApp marketing and creator-driven growth, based on what we build and observe with brands using the platform.

Ready to turn customers into creators?

Try TikJoy for free โ€” integrate TikTok and WhatsApp in seconds and reward your community with JoyBack wallet rewards (no purchase required).