Opt-in is a policy requirement enforced by Meta, layered on top of whatever data-protection law applies in the user's country (GDPR in Europe, for example). The business — not Meta, and not the BSP — is responsible for obtaining and documenting it.
What valid opt-in looks like. The user must actively agree, the request must name WhatsApp as the channel, and it should say what kinds of messages to expect. Common collection points include website checkboxes, checkout flows, click-to-WhatsApp ads, QR codes, and a message from the user that clearly requests updates. Pre-checked boxes and consent buried in general terms fall short of both Meta policy and most privacy laws.
Why it is self-enforcing. WhatsApp gives users one-tap tools to block or report a business, and those signals feed quality ratings that govern template status and messaging limits. Messaging people who never asked does not just risk policy action — it measurably degrades deliverability for your whole account.
Granularity and revocation. Best practice is per-category consent (order updates versus promotions) and an easy, honored opt-out such as a STOP keyword.
Why it matters for brands
Opt-in quality determines channel health: consented audiences block less, reply more, and keep quality ratings high. Treat the opt-in moment as marketing — explain the value of the channel — and WhatsApp becomes an owned audience rather than a compliance risk.