Resources

WhatsApp API Opt-in Requirements

How businesses should capture, record and respect customer consent for WhatsApp Business API messaging.

Opt-in requirements are set by Meta and applicable data protection law. This guide reflects general practice. Verify current Meta requirements and seek legal advice for your specific situation.

Why opt-in is required

The WhatsApp Business API is designed for businesses messaging customers who have agreed to receive messages. Sending to contacts who have not opted in violates Meta's policy and risks account restriction.

What counts as valid opt-in

The consent must clearly identify the business and the type of messages the customer agrees to receive.

  • Website form with explicit WhatsApp messaging consent checkbox.
  • In-app consent during registration.
  • WhatsApp-initiated conversation (customer messages you first within the service window).
  • Physical form or verbal consent with a documented digital record.

What does not count

  • Purchasing a contact list.
  • Scraping numbers from directories or websites.
  • Assuming consent because a customer has previously bought from you.
  • Pre-ticked checkboxes.

Recording and managing consent

Store the opt-in source, timestamp, wording version and channel for every contact. Ommly maintains consent records linked to each contact profile. Opt-out requests must be honoured immediately and the contact suppressed from future campaigns.

FAQ

Frequently asked questions

Clicking a WhatsApp link to start a conversation is a service initiation. It does not automatically constitute consent for future marketing messages.
Honour them immediately. Remove the contact from active campaign lists and record the opt-out with a timestamp. Do not re-add opted-out contacts without a new explicit opt-in.
Yes. Data protection laws (including GDPR in Europe and DPDP in India) add additional requirements on top of Meta's baseline. Seek legal advice for your specific markets.
Get started

Questions about WhatsApp setup?

We can walk through templates, opt-in and API onboarding for your team.