WhatsApp opt-in: the rules that keep your account live
What counts as consent, why a pre-checked box does not, and the record of method, timestamp and category that holds up when a complaint arrives.
· 6 min read
Consent is a deliverability mechanism, not a formality
It is natural to file consent under legal housekeeping: something to satisfy before the real work of messaging starts. That framing badly understates what consent does mechanically on this channel.
WhatsApp decides how many people a business is allowed to message based on how recipients react to the messages it already sent. Blocks and reports drive a quality rating down; a lowered rating restricts how many conversations the business can start. Every one of those negative signals begins with a message somebody did not want. Consent is the only thing that predicts, before the send, whether a recipient will react badly.
Seen that way, consent is not overhead sitting on top of outreach. It is the input that determines whether the number doing the outreach still works next month. A business with a small, properly consented list can message reliably for years. A business with a large, poorly sourced one can lose the channel in a fortnight, and losing it takes the transactional messages down with the promotional ones — the confirmations and reminders customers actually depend on run through the same number.
What actually counts as opt-in
Valid opt-in has a few properties, and each one rules out a common shortcut. It must be an affirmative act by the person: they do something, rather than fail to prevent something. It must be clear about what they are agreeing to receive, which means naming the business and the kind of messages. It must be specific about the channel, so agreeing to email is not agreeing to WhatsApp. And it must be recorded, because consent you cannot evidence is functionally the same as consent you never obtained when a complaint lands.
The mechanism can be almost anything that satisfies those properties. A checkbox that starts unticked and gets ticked. A form field where someone enters their number knowing what will be sent to it. A message the customer sends to the business. A reply of a keyword. An option chosen in a phone menu. A signature on a paper form in a shop. The channel used to collect consent does not have to be WhatsApp; what matters is that the person knowingly agreed to receive WhatsApp messages from this business.
Critically, consent is category-specific. Agreeing to order updates is not agreeing to promotions. Using a transactional consent record to justify a marketing send is a policy violation even though the number is genuinely theirs and was collected legitimately.
Why a pre-checked box fails even where it is legal
A pre-ticked consent box is the clearest example of the gap between what local law permits and what platform policy requires. In some jurisdictions, opt-out consent — where the box is ticked by default and the user must untick it — is lawful for certain kinds of marketing. WhatsApp's policy asks for an affirmative action from the user, and a box the user never touched records an absence of objection rather than a decision.
This distinction is not pedantry, because the two produce measurably different lists. People who actively opted in are, by construction, people who wanted the messages. People who simply did not notice a pre-ticked box include a substantial number who did not want them and will discover that when the first message arrives. That is a list with blocks and reports built into it, and the quality system will price that in.
The same reasoning rules out other patterns that can pass a legal review: consent bundled into terms and conditions nobody reads, a number collected for delivery coordination and later used for campaigns, and a scanned business card treated as a subscription. Each obtains a number without obtaining a decision, and it is the decision that predicts how the message will land.
"We have their number" is not consent
The most expensive misconception on this channel is that possession of a phone number implies permission to use it. A number from a directory listing, a purchased list, an old export from another tool, a trade-show scan or a transaction unrelated to messaging carries no WhatsApp consent with it.
Having a number is a fact about how the business acquired contact information. Consent is a fact about whether that person agreed to receive this kind of message on this channel. The two are independent, and conflating them is how a well-intentioned campaign — a business genuinely trying to reach real prospects rather than spam anyone — produces exactly the pattern the platform's abuse detection is designed to catch: high volume to people with no prior relationship to the message.
Purchased lists deserve a specific mention because they are still sold as a growth tactic. A bought list is, definitionally, a set of people who did not agree to hear from you, because they agreed with somebody else if they agreed at all. Messaging one is not a shortcut to scale; it is the fastest available route to a restricted number, and the restriction applies to the business's whole relationship with the channel rather than to that campaign.
The record that holds up when a complaint arrives
For every contact on a list, three things should be answerable rather than assumed: how consent was captured, when it was captured, and which category of message it covers. Method, timestamp, category. If any of the three is missing or vague for a contact, that contact is a liability in a send rather than a target for it, and removing them is the cautious default rather than an overcautious one.
Method means the specific mechanism, recorded precisely enough to reconstruct: which form, which keyword reply, which in-store sheet. "Website" is not a method if the site has four forms with different wording. Timestamp matters because consent ages — a permission given years ago to a business the person has not dealt with since is weaker in substance even where it remains technically valid. Category matters because of the specificity rule: a record that does not say what it covers cannot be used to justify anything in particular.
The reason to keep this as a structured record rather than an intention is that it needs to work as a filter before a send, not as a defence afterwards. A list assembled over two years from a website form, a trade-show scan and an export from a previous tool is exactly where the gaps hide, and it is much cheaper to audit a list while it is small than to reconstruct provenance for thousands of contacts after the complaints start.
Making it easy to leave, and honouring it quickly
Consent is not permanent, and the second half of a compliant programme is making withdrawal easy. Meta's policy requires businesses to honour opt-out requests, and the practical reality is stronger than the policy: a person who cannot find a way to stop your messages will use the block button, which harms the account in a way that an unsubscribe does not.
So an obvious way to stop is in the business's own interest. Marketing messages should carry a plain instruction, in the language the message is written in, and stop requests should be processed promptly and across categories where that is what the person meant. A customer who says stop and then receives another promotion has been given a reason to escalate from opting out to reporting.
It is also worth treating silence as information. Someone who has not opened or responded to anything for a long stretch has arguably withdrawn consent in practice even if never formally. Continuing to message them adds volume without adding engagement, which is exactly the ratio the quality system reads unfavourably. Trimming a list on that basis feels like giving up reach, and mostly it is giving up the portion of reach that was already working against the account.
Common questions
A customer gave us their number when they bought something. Can we send them a promotion?
Not on that basis alone. Consent is specific to the category of message. A number provided to complete a purchase supports transactional messages about that purchase; it is not marketing opt-in. You need consent for marketing specifically, with a record of how and when it was given and what it covered.
Our consent checkbox is pre-ticked, which is legal where we operate. Is that a problem?
Yes, on two counts. Platform policy asks for an affirmative action by the user, and a box they never touched records an absence of objection rather than a decision. Separately, such lists contain people who did not want the messages and will block or report them, which feeds the quality signals that cap your reach. Local legality does not protect the account.
Does opt-in have to be collected on WhatsApp itself?
No. Consent can be collected on a website form, in a shop, by SMS reply, through a phone menu or on paper. What matters is that the person took an affirmative action, understood they were agreeing to receive WhatsApp messages from your business, understood what kind, and that you recorded it. The collection channel is flexible; the clarity and the record are not.
What is the minimum record I need before treating a contact as safe to message?
Three things: the method by which consent was captured, specific enough to reconstruct; the date it was captured; and the message category it covers. If any one is missing or unclear, treat that contact as not cleared for the send. It is far cheaper to audit a list while it is small than to reconstruct provenance for thousands of contacts after complaints begin.