WhatsApp opt-in: what counts, and how to collect it properly
What WhatsApp's opt-in policy requires since the November 2024 update, which methods count, and how to build a consent record that survives a dispute.
· 7 min read
The rule that changed, and why it changed the burden of proof
As part of a November 2024 update to WhatsApp's Business Messaging Policy, Meta made explicit what had been more loosely understood before: a business must obtain opt-in permission before messaging someone on WhatsApp, and if that permission is ever disputed, the business — not Meta — is the one that has to produce evidence it was actually given. This is a meaningful shift in where the burden sits. A wellness clinic that messages a patient using a number collected years ago for appointment bookings cannot simply assert that consent existed; if the patient disputes it, the clinic needs a specific, checkable record: what was agreed to, through what channel, and when.
The policy states that a person can be contacted on WhatsApp if they have given their mobile number and separately confirmed they wish to receive subsequent messages or calls from that specific business. Critically, Meta's own documentation notes this opt-in permission can be general — it does not have to explicitly say 'WhatsApp' by name — as long as the business complies with all locally applicable law in how it was obtained. This is a narrower requirement than some businesses assume, but the compliance obligation underneath it is not narrow at all: getting it wrong risks the business's own WhatsApp number, not just a warning about one message.
For a small business without a legal team, the safest posture is treating every method of collecting a phone number as an opportunity to also, explicitly, capture agreement to be messaged — not assuming that handing over a number for one purpose (a delivery address, a warranty registration) silently implies consent to be messaged for every purpose thereafter.
What Meta's own documentation says a compliant opt-in must include
Meta's guidance sets out specific, minimum requirements rather than leaving the method entirely open-ended. The opt-in process must clearly state that the person is opting in to receive communication from the business, and it must clearly state the business's actual name — not a vague description, not a shortened or unofficial version, but the name the customer would recognise the business by. Beyond these two requirements, the business must comply with whatever local law applies to how consent is captured and communicated.
Meta explicitly lists several methods it considers capable of meeting these requirements when implemented correctly: an SMS-based opt-in, a website form, an interactive voice response (IVR) phone flow, and an in-person or paper-based method where a customer physically signs a document. None of these methods is inherently more or less valid than another — what makes any of them compliant is whether the specific implementation actually states the two required elements clearly, not which channel was used to capture it.
This means a real estate agency collecting a lead's number through a printed sign-up sheet at a property fair is on solid ground if the sheet itself states, in writing, that signing means agreeing to receive WhatsApp messages from that named agency — and is on much shakier ground if the sheet only asks for 'name and number for follow-up' with no such statement anywhere on the page, even though a number was still physically written down by the customer's own hand.
The mistake that catches even careful businesses: category-specific consent
The requirement to name the business and state that messaging is being consented to is only the first layer. A second, separate discipline that WhatsApp's broader policy framework depends on is that consent is tied to what a customer agreed to receive, not a blanket permission covering every future message type a business might later want to send. A patient who provides their number specifically so a physiotherapy clinic can confirm appointment slots has agreed to utility-category communication about that relationship — nothing about that agreement extends to a seasonal promotional offer the clinic later wants to send about a new treatment package.
This distinction is exactly where a wellness or beauty business commonly runs into trouble: a number collected at checkout for order confirmations gets reused months later for a festive marketing broadcast, on the reasoning that the customer already 'opted in' once. From WhatsApp's policy perspective, that reasoning does not hold — the original consent covered a specific purpose, and marketing is a different purpose requiring its own, separately captured agreement. A business genuinely wanting to send both order updates and promotional offers to the same customer needs to ask for both, ideally at the point of collection, rather than assuming one covers the other.
The practical fix is building the consent-capture moment to ask specifically: is this customer agreeing to transactional messages about their own order or appointment, promotional messages about offers and new products, or both? A checkout page with two separate checkboxes — one for order updates, one for marketing — rather than a single blanket tick-box, captures this distinction cleanly and gives the business a defensible, category-matched record for each type of message it might later want to send.
Building a consent record that actually holds up
A consent record worth keeping needs to answer three questions on demand, for any given contact: how was consent captured (which specific form, checkbox, or physical document), when was it captured (a timestamp, not a vague 'a while back'), and what category of message did it cover. A record missing any one of these three is a much weaker defence than a complete one — 'we have their number and they never complained' is not the same as a documented, timestamped, category-specific consent event.
A driving school collecting numbers through both a website enquiry form and an in-person walk-in register needs the record to distinguish between the two sources, because a dispute about consent will ask specifically how that particular customer's number was obtained — an answer that conflates two different collection methods into one vague 'we have a list' response is far less convincing than pointing to the specific form submission with its own timestamp.
This record-keeping habit matters even more once a business starts running any kind of automated messaging — a broadcast, a reminder sequence, a cart-recovery flow — because automation removes the human judgment that might have otherwise caught an obviously unconsented contact before a message went out. A system that checks a category-matched consent record before every send, and excludes anyone without one rather than assuming they're fine to include, is what keeps automation from quietly amplifying a consent gap across thousands of messages instead of just one.
Honouring opt-outs, and why this is treated as seriously as consent itself
Obtaining consent correctly is only half of the compliance picture — failing to honour a withdrawal of that consent is treated by WhatsApp's policy framework with equal or greater seriousness, because a customer who has explicitly asked to stop and keeps receiving messages anyway is a stronger signal of disregard for the platform's rules than a business that made a genuine one-time mistake collecting consent. WhatsApp includes its own built-in mechanisms for a customer to signal they want to stop — a reply along the lines of 'stop' or 'unsubscribe' — and a business's systems need to detect and act on these immediately, not on the next scheduled campaign review.
The practical requirement here is that an opt-out needs to propagate across every pending send for that contact, not just the specific campaign or sequence the person happened to reply to. A customer who opts out of a cart-recovery reminder but is also sitting in an unrelated festive-broadcast segment needs to be removed from both — a business whose opt-out handling only touches the sequence it arrived through, while leaving the same contact live in every other list, has not actually honoured the request in any meaningful sense, even if it feels like a narrow technical compliance gap rather than a deliberate one.
Getting this wrong is not a minor infraction with a warning attached — failing to honour opt-outs is treated as a genuine policy violation that can result in restrictions on or suspension of the business's WhatsApp Business Account itself, which is a considerably larger cost than whatever the one additional message being sent was worth.
A practical starting checklist
For a small business setting this up for the first time, a workable starting point is: identify every place a customer's phone number currently gets collected (website forms, checkout flows, in-store registers, event sign-up sheets), add an explicit, business-named consent statement to each one that specifies exactly what kind of messages the customer is agreeing to, and record the timestamp and source alongside every number collected going forward, not just for new forms built after reading this.
For numbers already on file from before this discipline existed, the honest answer is that many of them may not have a clean, checkable consent record attached — and the safer approach is treating those as unconsented for marketing purposes until a fresh, category-specific opt-in is captured, rather than assuming historical goodwill covers a gap the record itself cannot fill. This is a real cost in terms of list size, but it is a considerably smaller cost than a suspended WhatsApp Business Account discovered mid-campaign. A platform like Wavy can help structure this by storing a category-matched consent record against every contact and checking it before any send goes out — but the actual capturing of that consent, correctly and honestly, at the point a number is collected, is work only the business itself can do.
Common questions
Does opt-in have to specifically mention WhatsApp by name?
No. Meta's guidance states that opt-in permission can be general rather than WhatsApp-specific, as long as it clearly states the business's name and that the person is agreeing to receive communication from it, and as long as the method used complies with applicable local law. It does not need to say the word 'WhatsApp' explicitly anywhere to be considered a fully compliant method of collecting that consent.
Can I message a customer about a sale if they only agreed to order updates?
No. Consent is category-specific under WhatsApp's policy — agreement to receive order-status or appointment-related utility messages does not extend to marketing content. Sending a promotional message on the strength of a different category's consent is a policy violation even though a consent record technically exists for that contact, and it requires a separate, category-matched opt-in before any marketing message can be sent.
What counts as a valid method for collecting opt-in?
Meta's documentation lists SMS, website forms, interactive voice response (IVR) phone flows, and in-person or paper-based consent (a signed physical document) as examples of methods that can be compliant. What actually makes any of them valid is whether the specific implementation clearly states the business's name and that the person is agreeing to receive messages — the channel itself is not what determines compliance.
What happens if we can't produce a consent record for a contact someone disputes?
Without a documented, checkable consent record — source, timestamp, and category — the business has little defence beyond its own word against the customer's dispute. Since the November 2024 policy update places the burden of proof on the business, this can lead to restrictions on, or suspension of, the WhatsApp Business Account, which is why building the record at the point of collection matters more than trying to reconstruct one later.