WhatsApp Opt-In: What Counts as Consent, With Compliant Examples
What counts as valid WhatsApp opt-in consent: the touchpoints that produce it, wording you can copy, opt-out handling, and the records that prove it.
Consent is the foundation the whole channel stands on: it decides whether your campaigns get read or reported, whether your number stays healthy, and whether your marketing is defensible under data protection law. Yet most opt-in guidance online stops at “get permission” without saying what permission actually looks like.
This guide is the concrete version: the touchpoints that produce consent that holds up, wording you can copy for each one, the handling of opt-outs, and the four records that prove everything. It ends with what happens when consent is missing - on the platform, in the law, and here.
What opt-in actually means
Opt-in means the contact knowingly agreed to receive marketing messages from your business, on WhatsApp, on this number. Three words in that sentence do all the work.
Knowingly - the person understood they were signing up for WhatsApp messages. A checkbox for order updates is not consent for festival promotions; context and wording have to match what you will actually send.
Agreed - they took an action: ticked a box, scanned a code, replied to a message. Silence, inactivity, and “they gave me their number for something else” are not agreement.
From your business - consent is not transferable. Someone agreeing to hear from a shop they visited agreed to hear from that shop, not from you, and not from whoever bought a copy of the list.
All three have to be true at once. Two out of three is how businesses end up with a list they cannot defend.
Touchpoints that produce real consent
Five collection points cover nearly every legitimate business, and each has one job: make the agreement visible and recorded.
Website and store forms. A phone field plus an unticked checkbox with plain wording. The form timestamp is your record.
Checkout. A line on the billing step - online or at the counter - offering updates or offers. Separate from the receipt-delivery consent: order updates and marketing are two different agreements.
QR signup at the counter. A card or poster that opens a short form or a WhatsApp chat. The person scans it themselves; the scan is the action, and the timestamp is the record.
Inside the WhatsApp chat. Someone messages you first - a support question, an enquiry - and your reply asks whether they would like updates. Their YES reply is consent, captured in the chat history, from a number you know is live.
Paper and in-person signups. A sheet at events or reception with the wording printed above the column. Lower-tech, but a photographed sheet with dates is a record.
Notice what all five have in common: the customer does something deliberate, in a context where the WhatsApp ask is obvious, and a timestamped record exists. That is the whole standard.
What never counts as consent
Four patterns show up again and again, and none of them survive contact with a complaint, a regulator, or a platform review:
- Purchased lists, whatever the seller claims. The contacts agreed to nothing, certainly not to you. This is prohibited outright under the Automate Acceptable Use Policy - accounts that message purchased lists are terminated.
- Scraped or traded contacts from directories, groups, or forwarded spreadsheets. Same as above, with worse deliverability.
- Numbers collected for another purpose - a delivery phone number is a delivery phone number until the person agrees to more.
- Pre-ticked boxes and buried wording. A consent nobody noticed is not consent; the checkbox starts empty and the wording sits where a person actually reads.
If you have inherited a list with an unclear history, the honest fix is a re-permission campaign - one message asking people to opt in again, with non-responders removed. It shrinks the list and saves the number.
What the law says, in plain language
This is a practical summary, not legal advice - for decisions with real exposure, ask a lawyer who knows your market.
Data protection laws converged on the same core, whether it is India’s DPDP Act, the EU’s GDPR, or the frameworks in between - and in the United States, the FCC’s guidance on unwanted texts shows the same consent expectation for marketing messaging: you need a lawful basis to message someone; the purpose has to match what they were told; and withdrawal has to be as easy as signup. For WhatsApp marketing, that translates into the standard this guide describes - a clear ask, matching wording, an easy exit, and records.
Two practical consequences are worth naming. Consent given for one channel does not automatically cover another - an email signup is not an SMS or WhatsApp signup unless the wording said so. And consent has a shelf life: a list collected in one business, or before a change in what you send, may need refreshing through re-permission.
Compliant opt-in wording you can copy
Wording is where most consent quietly fails - too vague, too buried, or promising something the campaigns do not deliver. These five do the job at the touchpoints above; swap the bracketed parts for your details.
Website form checkbox:
[ ] Send me WhatsApp updates and offers from [Business] (about [2-4 messages a month]). Reply STOP anytime to opt out.
Checkout line (online or at the counter):
Want your receipt and offers on WhatsApp? Tick to agree: [ ]. Offers only, about twice a month, STOP to leave.
QR counter card:
Scan to get [Business] offers on WhatsApp. About 2 messages a month. You can leave anytime by replying STOP.
In-chat agreement (after an inbound enquiry):
Glad we could help! Would you like occasional updates from us on WhatsApp - new arrivals and offers, a few times a month? Reply YES and you are in; reply NO and we will not message you about this.
Event sheet header:
Sign up for WhatsApp updates from [Business]: offers and news, about [2-4] messages a month. Your number is used only for this. Opt out anytime with STOP.
The pattern across all five: say what will be sent, roughly how often, name the business, and show the exit. Frequency honesty matters more than it looks - most spam complaints are frequency complaints, and wording that promised “a few times a month” sets the expectation your number survives on.
Handling opt-outs
The exit has to work as smoothly as the entrance, because a difficult exit converts a quiet unsubscribe into an angry block report - and blocks weigh heavier than opt-outs on every platform.
The standard: any clear signal ends messaging the same day. STOP and its variants, a plain-language “remove me”, a message to support - all count. No reasons requested, no retention offers mid-flow, no “are you sure” loops.
Once opted out, the number moves to a suppression list that every future import checks against, so a stale spreadsheet cannot accidentally resurrect them in next quarter’s campaign. A suppressed contact returns only by opting in again - a new action, a new record, their choice. In Automate, opt-out handling is built into the platform: contacts who opt out are excluded from subsequent imports and campaigns without manual bookkeeping.
Keeping the records that prove it
Consent that cannot be shown is, functionally, consent that did not happen. The proof takes four facts per contact, and every collection point above can produce them:
- The number - which contact.
- The source - which touchpoint: website form, checkout, QR card, in-chat.
- The timestamp - when they agreed.
- The wording - what exactly they saw when they did.
Store them with the contact record rather than in a separate folder, and export them with the list if you change tools - the migration question to ask any platform is whether those four columns come with you. They do here.
When a contact questions a message, or a platform reviews the account, or a regulator writes to you, the conversation ends differently when you can produce a timestamped yes with the exact wording beside it. That document is what opt-in compliance actually is.
When consent is missing
Three systems react, in rising order of consequence.
The audience reacts first: blocks and reports, the signals the restricted-numbers guide describes - and the fastest route to a number that cannot deliver.
The law reacts next. Messaging without a lawful basis sits badly under the DPDP Act, the GDPR and their equivalents, with penalties that scale with scale, and “the list vendor said it was fine” has never been a defense.
We react as well: purchased and scraped lists are the one behavior the Acceptable Use Policy treats as terminal, because they endanger every account that uses them.
None of this is a reason to avoid WhatsApp marketing - it is the reason the channel works. A list of people who said yes, messaged sensibly, is the highest-performing marketing asset most businesses own. Build it at the counter and the checkout, word the ask honestly, keep the four records, and the consent question becomes a formality. The campaign playbook shows what to do with the list once you have it, and the plans show what it costs to run it on infrastructure that is yours alone.