Founding member offer50% off your first 3 months · Only 100 founding spotsOffer ends indhmsClaim founding offer →
All articles GDPR

WhatsApp opt-in under the GDPR

What a valid WhatsApp opt-in looks like, what you have to store to prove it, and the five wordings that quietly make consent worthless.

Checklist of the six fields a WhatsApp consent record has to contain, from phone number to method

A valid WhatsApp opt-in is a checkbox nobody ticked for the person, wording that says who is writing and about what, and a stored record of both. That is the whole standard. Most opt-ins fail it for reasons that look small on a form and large in a complaint.

The rules come from two places. The GDPR defines consent in Article 4(11) and sets the conditions in Article 7. The ePrivacy Directive is what makes consent the relevant basis for marketing messages in the first place. Its Art. 13(1) speaks of “electronic mail”; the prevailing reading — and the one German courts apply under § 7 UWG — treats a messenger message the same way. No CJEU ruling has settled the point.

The four conditions, translated

Freely given. The person must be able to say no without losing anything they were promised. A checkout that will not complete unless you accept WhatsApp updates is not free. A prize draw that requires the tick is not free either — the consent is the price of entry, which is the definition of bundling.

Specific. One purpose, one consent. “Marketing and partner offers and service updates” is three things wearing one checkbox. If you want to send both appointment reminders and promotions, either name both explicitly in one clear sentence or collect them separately.

Informed. Before ticking, the person should know who is writing, on which channel, roughly what about, and how to stop. Your privacy notice should be one click away, not required reading.

Unambiguous. A clear affirmative action. Not a pre-ticked box, not silence, not “by continuing you agree”. The tick, the tap, or the message the person sends you.

What you have to be able to prove

Article 7(1): “the controller shall be able to demonstrate that the data subject has consented.” Not that your form was well designed. That this person consented.

So the record has to be per contact, and it has to contain:

FieldWhy it matters
Phone number in E.164Identifies the record you will need to produce
The consent text as displayedProves what they actually agreed to, not what your form says today
Timestamp (UTC)Establishes when, and whether it predates the messages you sent
SourceWhich form, which page, which campaign — shows the context
IP address, where availableCorroborates the timestamp for web forms
MethodWeb form, WhatsApp keyword, QR code, imported, offline

The second row is the one people get wrong. If you store a reference to your current consent wording rather than a copy of the wording that was on screen, then every time marketing edits the form, your entire consent history quietly changes to something nobody agreed to. Store the text.

Five wordings that fail

These are common, and each one is defective for a specific reason.

  1. “I agree to the terms and conditions and to receiving WhatsApp updates.” Bundled. Under Art. 7(4), making a contract conditional on consent that is not necessary for it weighs heavily against that consent being freely given — which is why bundled ticks rarely survive scrutiny.
  2. “Sign up for our newsletter” — with a phone field on the same form. Not specific to the channel. A newsletter is email.
  3. “We may contact you about offers from us and selected partners.” Who are the partners? Unnamed third parties cannot be consented to.
  4. A pre-ticked box. Explicitly ruled out; the CJEU settled this in Planet49 in 2019 and the reasoning applies to any consent, not just cookies.
  5. “By submitting this form you consent to…” with the submit button as the only action. Not unambiguous — the person acted to submit a form, not to accept marketing.

The fix for all five is the same shape: a separate, unticked box, with one sentence that names you, names WhatsApp, names the message type, and mentions the way out.

Yes, send me appointment reminders and offers from Muster GmbH on WhatsApp. Reply STOP any time to unsubscribe. [Privacy notice]

Boring. Defensible.

Where the opt-in comes from changes what you should store

Web form. The strongest common case, because you control the page and can capture the wording, timestamp and IP together. Make sure the phone field is typed by the person, not prefilled from a purchased list.

QR code or link on a physical touchpoint. The person scans, WhatsApp opens with a prefilled message, they hit send. The inbound message is the affirmative action, and it comes from the number itself — which quietly solves the mistyped-number problem. Store the message and its timestamp as the record, and reply immediately with what they just signed up for.

Click-to-WhatsApp ads. Same mechanic: the person starts the conversation. Meta’s own Business Messaging Policy requires opt-in before you message someone, and an inbound message satisfies it — but the scope is the conversation they started. Worth knowing: Meta’s bar is lower than the GDPR’s. Its policy accepts a general opt-in that does not name WhatsApp, as long as local law is met. For EU contacts local law is the GDPR, so the channel-specific wording is on you, not on Meta. It is not blanket permission for a promotional broadcast three months later. Ask for that separately, in the chat, and store the answer.

Offline, on paper or verbally. Legitimate, and the hardest to evidence. Keep the signed form or log the interaction with the staff member, the date and the wording used, then send a confirmation message so there is a digital trace.

Imported from another system. Only defensible if the original consent covered WhatsApp specifically and you can produce that original record. Usually it does not, which is its own article.

The confirmation step is worth it

The GDPR does not require double opt-in. It is simply the strongest evidence available under Art. 7(1), and German courts have long treated the confirmed double opt-in as the practical way to prove an email consent. On WhatsApp it costs one message.

The mechanic: the person opts in on your form, you send a single utility template asking them to confirm, they reply. Now you have a record that ties the consent to the device holding the number. Someone who typo’d a digit never confirms, so you never message a stranger; someone who entered a colleague’s number as a joke never confirms either.

Their reply also opens the 24-hour customer service window, so you can answer in free-form text instead of a pre-approved template. Note the change of economics: from 1 October 2026 Meta bills service and utility messages inside that window per message, so “inside the window” no longer means “free” (Meta, upcoming pricing updates, retrieved 1 August 2026).

The one exception, and why it rarely helps here

There is a statutory alternative to consent, and it is narrower than people hope. Art. 13(2) of the ePrivacy Directive lets you market your own similar products to someone whose details you obtained in the course of a sale, provided they were offered a way to object at collection and in every message. Germany implements it in § 7(3) UWG.

Two problems on WhatsApp. The provision is written around electronic mail, and whether it stretches to a messenger channel is contested rather than settled. And “similar products” is read narrowly. If your case looks like it fits, that is a question for a lawyer who knows your jurisdiction — in practice, asking for consent is faster than arguing the exception.

Opt-out has to be as easy as opt-in

Article 7(3): withdrawing consent must be as easy as giving it. On WhatsApp that means a keyword, honoured automatically.

Three things make it work. Every marketing message mentions the way out, once, at the end. The system acts on the keyword itself rather than waiting for a human to read the inbox. And the opt-out is recorded with a timestamp, because “we stopped messaging them” is a claim and “we stopped at 14:03 on 4 March” is evidence.

One more, easy to forget: an opt-out has to survive a re-import. If someone opts out and then arrives again in next month’s CSV, your system must keep them suppressed. A suppression list that only lives in the current contact record is not a suppression list.

What this means for you

Go and look at your own form. If the consent shares a checkbox with anything else, split it. If you store a pointer to the wording rather than the wording, start storing the text. If your opt-outs depend on someone reading the inbox, automate them today — that is the one failure that turns an annoyed customer into a complainant.

In Nybero, the consent record is append-only per contact and carries the timestamp, the source and — for WhatsApp form opt-ins and consent supplied through the API — the wording as displayed. STOP is handled by the platform rather than by a person, and the suppression survives a later import. Not because it is a clever feature, but because reconstructing consent afterwards is impossible and everyone eventually needs it.

Updated 1 August 2026. National implementations of the ePrivacy Directive differ, particularly on the existing-customer exception. An earlier version described replies inside the 24-hour window as unpaid, which stops being true on 1 October 2026. Orientation, not legal advice.

FAQ

Frequently asked questions

What makes a WhatsApp opt-in valid under the GDPR?

Four things, from Article 4(11) and Article 7: it must be freely given, specific, informed and unambiguous. In practice that means a separate unticked checkbox, wording that names the sender and the type of message, no bundling with terms or a prize draw, and a stored record of exactly what the person saw and when.

Do I need double opt-in for WhatsApp?

The GDPR does not require it. It is still the strongest evidence you can get, because the confirmation comes from the device that owns the number and proves the number was not mistyped or entered by someone else. On WhatsApp the confirmation step is cheap: one template message the person answers with yes.

How long is a WhatsApp opt-in valid?

The GDPR sets no expiry date. What matters is whether the consent is still current in context — someone who opted in four years ago and never engaged since is a weak case. A common practice is to re-confirm consent after 24 months of no interaction and to stop messaging people who never respond.

Can I use an opt-in collected for email to send WhatsApp messages?

No. Consent has to be specific to the processing, and the channel is part of that. Someone who agreed to a newsletter did not agree to a message on their personal phone. You need a fresh opt-in that names WhatsApp.

Ready to turn leads into conversations?

Start with your own WhatsApp number. 7-day free trial, cancel anytime.

Get started free

Get in touch

Start free