Skip to content

September 14, 2026

WhatsApp Consent Messages

Coordinator reviewing WhatsApp consent record

To message a customer proactively on WhatsApp, you need explicit opt-in that names your business and shows the contact agreed to receive messages. That consent can be collected off the app entirely, through a form, QR code, or checkout box, but it has to be logged with a timestamp, source, and the exact wording shown, and it has to stay revocable. The fastest fix for most teams: add an unticked checkbox at every signup point that names your business by its registered name, then start recording who saw it and when.


TL;DR:

  • Collect explicit opt-in through a verified channel with logged timestamp, source, consent wording, and revocability, avoiding pre-checked boxes or purchased lists.
  • Use clear, lawful wording for consent checkboxes that include your registered business name and message description, in the language the contact used.
  • Record detailed consent metadata, including the contact’s number, consent source, wording, language, timestamp, and opt-out status, with automatic updates for opt-outs.
  • Treat WhatsApp consent with the same rigor as SMS by maintaining clear records, monitoring spam reports, and reviewing templates before broadcasting marketing messages.
  • Deploy a fully bilingual system with a consent process, welcome templates, and CRM integration to prevent language barriers from causing compliance issues or opt-in confusion.

Table of Contents

Meta’s rule breaks into two parts. First, the contact has to hand over a phone number through some legitimate channel. Second, they need to give explicit opt-in that either names your business or clearly agrees to receive messages from you. The WhatsApp Business Messaging Policy requires this opt-in before you send the first proactive message, and it explicitly allows collecting it outside the app.

A lot of older guidance overstates the bar. Naming “WhatsApp” specifically in your consent text used to be treated as mandatory; it’s now a recommendation, not a requirement, according to current opt-in documentation. What still matters:

Get the category wrong and Meta will reject your template during approval, not after you’ve already annoyed a customer.

How to Collect WhatsApp Opt-In Across Different Channels

Every collection method needs the same three data points attached: the phone number in international format, a timestamp, and the exact consent wording the person saw. Here’s how that plays out channel by channel:

  1. Website and checkout forms. Add an unticked checkbox next to the phone field at checkout or account creation. Store the form version alongside the consent record, since wording changes over time.
  2. QR codes. A code that opens a pre-filled WhatsApp message works well at front desks, waiting rooms, or print materials. The scan itself isn’t consent; the message the person sends and the reply they receive confirming enrollment is what you log.
  3. Click-to-WhatsApp ads. Meta ads that open a chat thread create session permission, but that’s not automatic marketing consent. Confirm it explicitly in the first exchange before adding the contact to a broadcast list.
  4. Keyword replies (SMS or WhatsApp). “Text JOIN to opt in” flows are clean and auditable, since the reply itself is timestamped proof.
  5. IVR and phone consent. Record the script read to the caller and log their verbal agreement the same way a call center would for a recorded line.
  6. In-person sign-up. Paper forms or tablet kiosks at a front desk still count, provided you digitize the exact wording shown and the date signed.

Never use pre-checked boxes, and never buy or import a purchased list. Treat any inherited or purchased list as cold. It needs a fresh, documented opt-in before you send anything.

Pro Tip: Run a double opt-in (a confirmation reply required after the initial signup) for higher-risk situations: cross-border contacts, EU data subjects, or any list you didn’t collect directly. Single opt-in is fine for your own website forms and checkout flows.

The minimum a compliant opt-in checkbox needs: your business name, a plain description of what messages the person will get, and clear opt-out instructions. Frequency and data-rate disclosures are good practice but not strictly required by the platform.

A few adaptable lines:

Your checkbox text should use the exact legal name registered on your WhatsApp Business Account; a mismatch between what the customer sees and what’s on file causes confusion and audit headaches later.

If you serve bilingual customers, present the consent text in whichever language the person is already using, in a form or on a page, and record which version they saw. A library of ready-made bilingual WhatsApp templates makes this much faster to standardize across booking, checkout, and support flows.

Bilingual consent workflow with recorded language version

Recordkeeping: What to Log and How to Honor Opt-Outs

An audit-ready consent record needs six fields attached to the contact: the full phone number, the source of consent (form, QR, keyword, in-person), the exact wording shown, the language tag, the timestamp, and the current opt-out status.

Operationally, that means:

A CRM integration that ties consent metadata directly to the contact record removes most of the manual tracking that causes gaps.

Whether the TCPA applies directly to WhatsApp messages the way it does to SMS is genuinely unsettled, and no business should bet its compliance posture on that ambiguity resolving in its favor. The safer default is to collect consent to the same standard carriers already expect for SMS: an explicit opt-in, a clear record of how and when it was given, and easy opt-out.

Carrier and industry guidance backs this up directly. SMS consent standards require recording the method of consent, the exact wording, opt-out instructions, and retained proof, and they flatly prohibit sharing or buying consent lists.

A short governance checklist covers most of the risk:

For contacts covered by GDPR, consent needs to be explicit, unbundled from other agreements, and easy to withdraw, and double opt-in is the stronger proof when that standard applies.

Storing which language version of your consent text a contact saw isn’t a nice-to-have. It’s what lets you defend the record later and what determines which welcome message the person actually receives.

A short bilingual welcome flow cuts down “who is this?” replies, which is one of the fastest ways a business account racks up spam reports. A simple pairing works:

Route language-specific STOP or HELP replies to the matching support queue instead of a single generic inbox, so a Spanish-speaking contact isn’t waiting on an English-only agent to process an opt-out. Practices booking through WhatsApp QR codes at the front desk see this pay off immediately, since the language choice gets locked in at the very first scan.

Compliance Without Killing Conversion

Favor the boring, auditable opt-in over the clever acquisition trick every time. A checkbox that clearly names your business and logs a timestamp will outlast any growth hack that skips the paperwork, because the growth hack is the thing that gets your account suspended.

Prioritize the high-value touchpoints first: checkout, booking, and account settings, not a scattershot pop-up on every page. And don’t treat the bilingual welcome message as an afterthought. It’s often the cheapest fix for the complaint volume that gets accounts flagged in the first place.

— Francisco

Many practices juggling English and Spanish speakers end up stitching together a website, a call service, and a WhatsApp number that nobody quite manages consistently. This can be replaced by one bilingual system: a fully optimized website, a 24/7 AI receptionist fluent in both languages, and WhatsApp integration that captures opt-in at the moment a client books, calls, or messages, so nothing falls through a language gap.

Diazluna

Setup typically covers the pieces this article just walked through: a compliant consent checkbox on your booking and contact forms, a bilingual welcome template that logs which language version a client saw, CRM syncing so opt-outs update everywhere at once, and an audit trail you can pull if a client or platform ever asks how consent was collected. If you’re already tightening up your marketing automation and lead capture, a resource like this automation checklist for small businesses pairs well with the workflow.

If your practice serves Hispanic clients and you’re still managing consent by hand, start with a Diazluna demo to see the bilingual front desk and consent logging running on your own booking flow.

Sources

FAQ

It’s the notice or checkbox text that names your business and confirms a contact agreed to receive messages from you before you send anything proactively.

Can someone read my WhatsApp messages without my permission?

WhatsApp messages are end-to-end encrypted by default, so no outside party, including WhatsApp itself, can read message content without access to the device; this is separate from business messaging consent rules.

What happens if I don’t agree to WhatsApp’s terms?

You won’t be able to use the app or send and receive messages through it, since accepting the terms of service is required to create or keep an active account.

Can WhatsApp texts be used in court?

Courts have accepted WhatsApp messages as evidence in various cases, though admissibility depends on authentication and the specific jurisdiction’s rules of evidence, so treat this as a general pattern, not a guarantee for any particular case.

No. Naming your business and describing the messages a contact will receive satisfies Meta’s current requirement; naming the WhatsApp platform itself is a nice-to-have, not a mandate.