A valid WhatsApp opt-in is a checkbox nobody ticked for the person, wording that says who is writing and about what, and a stored record of both. That is the whole standard. Most opt-ins fail it for reasons that look small on a form and large in a complaint.
The rules come from two places. The GDPR defines consent in Article 4(11) and sets the conditions in Article 7. The ePrivacy Directive is what makes consent the relevant basis for marketing messages in the first place. Its Art. 13(1) speaks of “electronic mail”; the prevailing reading — and the one German courts apply under § 7 UWG — treats a messenger message the same way. No CJEU ruling has settled the point.
The four conditions, translated
Freely given. The person must be able to say no without losing anything they were promised. A checkout that will not complete unless you accept WhatsApp updates is not free. A prize draw that requires the tick is not free either — the consent is the price of entry, which is the definition of bundling.
Specific. One purpose, one consent. “Marketing and partner offers and service updates” is three things wearing one checkbox. If you want to send both appointment reminders and promotions, either name both explicitly in one clear sentence or collect them separately.
Informed. Before ticking, the person should know who is writing, on which channel, roughly what about, and how to stop. Your privacy notice should be one click away, not required reading.
Unambiguous. A clear affirmative action. Not a pre-ticked box, not silence, not “by continuing you agree”. The tick, the tap, or the message the person sends you.
What you have to be able to prove
Article 7(1): “the controller shall be able to demonstrate that the data subject has consented.” Not that your form was well designed. That this person consented.
So the record has to be per contact, and it has to contain:
| Field | Why it matters |
|---|---|
| Phone number in E.164 | Identifies the record you will need to produce |
| The consent text as displayed | Proves what they actually agreed to, not what your form says today |
| Timestamp (UTC) | Establishes when, and whether it predates the messages you sent |
| Source | Which form, which page, which campaign — shows the context |
| IP address, where available | Corroborates the timestamp for web forms |
| Method | Web form, WhatsApp keyword, QR code, imported, offline |
The second row is the one people get wrong. If you store a reference to your current consent wording rather than a copy of the wording that was on screen, then every time marketing edits the form, your entire consent history quietly changes to something nobody agreed to. Store the text.
Five wordings that fail
These are common, and each one is defective for a specific reason.
- “I agree to the terms and conditions and to receiving WhatsApp updates.” Bundled. Under Art. 7(4), making a contract conditional on consent that is not necessary for it weighs heavily against that consent being freely given — which is why bundled ticks rarely survive scrutiny.
- “Sign up for our newsletter” — with a phone field on the same form. Not specific to the channel. A newsletter is email.
- “We may contact you about offers from us and selected partners.” Who are the partners? Unnamed third parties cannot be consented to.
- A pre-ticked box. Explicitly ruled out; the CJEU settled this in Planet49 in 2019 and the reasoning applies to any consent, not just cookies.
- “By submitting this form you consent to…” with the submit button as the only action. Not unambiguous — the person acted to submit a form, not to accept marketing.
The fix for all five is the same shape: a separate, unticked box, with one sentence that names you, names WhatsApp, names the message type, and mentions the way out.
Yes, send me appointment reminders and offers from Muster GmbH on WhatsApp. Reply STOP any time to unsubscribe. [Privacy notice]
Boring. Defensible.
Where the opt-in comes from changes what you should store
Web form. The strongest common case, because you control the page and can capture the wording, timestamp and IP together. Make sure the phone field is typed by the person, not prefilled from a purchased list.
QR code or link on a physical touchpoint. The person scans, WhatsApp opens with a prefilled message, they hit send. The inbound message is the affirmative action, and it comes from the number itself — which quietly solves the mistyped-number problem. Store the message and its timestamp as the record, and reply immediately with what they just signed up for.
Click-to-WhatsApp ads. Same mechanic: the person starts the conversation. Meta’s own Business Messaging Policy requires opt-in before you message someone, and an inbound message satisfies it — but the scope is the conversation they started. Worth knowing: Meta’s bar is lower than the GDPR’s. Its policy accepts a general opt-in that does not name WhatsApp, as long as local law is met. For EU contacts local law is the GDPR, so the channel-specific wording is on you, not on Meta. It is not blanket permission for a promotional broadcast three months later. Ask for that separately, in the chat, and store the answer.
Offline, on paper or verbally. Legitimate, and the hardest to evidence. Keep the signed form or log the interaction with the staff member, the date and the wording used, then send a confirmation message so there is a digital trace.
Imported from another system. Only defensible if the original consent covered WhatsApp specifically and you can produce that original record. Usually it does not, which is its own article.
The confirmation step is worth it
The GDPR does not require double opt-in. It is simply the strongest evidence available under Art. 7(1), and German courts have long treated the confirmed double opt-in as the practical way to prove an email consent. On WhatsApp it costs one message.
The mechanic: the person opts in on your form, you send a single utility template asking them to confirm, they reply. Now you have a record that ties the consent to the device holding the number. Someone who typo’d a digit never confirms, so you never message a stranger; someone who entered a colleague’s number as a joke never confirms either.
Their reply also opens the 24-hour customer service window, so you can answer in free-form text instead of a pre-approved template. Note the change of economics: from 1 October 2026 Meta bills service and utility messages inside that window per message, so “inside the window” no longer means “free” (Meta, upcoming pricing updates, retrieved 1 August 2026).
The one exception, and why it rarely helps here
There is a statutory alternative to consent, and it is narrower than people hope. Art. 13(2) of the ePrivacy Directive lets you market your own similar products to someone whose details you obtained in the course of a sale, provided they were offered a way to object at collection and in every message. Germany implements it in § 7(3) UWG.
Two problems on WhatsApp. The provision is written around electronic mail, and whether it stretches to a messenger channel is contested rather than settled. And “similar products” is read narrowly. If your case looks like it fits, that is a question for a lawyer who knows your jurisdiction — in practice, asking for consent is faster than arguing the exception.
Opt-out has to be as easy as opt-in
Article 7(3): withdrawing consent must be as easy as giving it. On WhatsApp that means a keyword, honoured automatically.
Three things make it work. Every marketing message mentions the way out, once, at the end. The system acts on the keyword itself rather than waiting for a human to read the inbox. And the opt-out is recorded with a timestamp, because “we stopped messaging them” is a claim and “we stopped at 14:03 on 4 March” is evidence.
One more, easy to forget: an opt-out has to survive a re-import. If someone opts out and then arrives again in next month’s CSV, your system must keep them suppressed. A suppression list that only lives in the current contact record is not a suppression list.
What this means for you
Go and look at your own form. If the consent shares a checkbox with anything else, split it. If you store a pointer to the wording rather than the wording, start storing the text. If your opt-outs depend on someone reading the inbox, automate them today — that is the one failure that turns an annoyed customer into a complainant.
In Nybero, the consent record is append-only per contact and carries the timestamp, the source and — for WhatsApp form opt-ins and consent supplied through the API — the wording as displayed. STOP is handled by the platform rather than by a person, and the suppression survives a later import. Not because it is a clever feature, but because reconstructing consent afterwards is impossible and everyone eventually needs it.
Updated 1 August 2026. National implementations of the ePrivacy Directive differ, particularly on the existing-customer exception. An earlier version described replies inside the 24-hour window as unpaid, which stops being true on 1 October 2026. Orientation, not legal advice.