WhatsApp marketing and the GDPR
What European law actually requires before you message someone on WhatsApp — lawful basis, opt-in, opt-out, retention, transfers and the DPA your customers will ask you for.
September 24, 2026 · 5 min read
WhatsApp is the default messenger across most of Europe, which makes it the obvious channel — and the one most likely to get a complaint if you treat it like an email list. The rules aren't complicated, but they are strict, and Meta enforces its own version of them independently of the regulators.
This guide covers what you need in place before your first campaign to an EU or UK number.
The short version
- Get consent before the first message. Not a legitimate-interest argument — actual opt-in.
- Record when and how you got it, for each person.
- Make opting out one word, and honour it immediately.
- Say in your privacy notice that you message people on WhatsApp and who processes it.
- Have a DPA with whoever sends on your behalf, ours included.
If all five are true, you're in a good position. Most problems come from the first two.
Why opt-in isn't optional here
Two separate rules land on the same answer.
The ePrivacy Directive treats a WhatsApp message as an electronic communication for direct marketing, which in most member states means prior consent. The narrow "soft opt-in" some countries allow for email — existing customers, similar products, an opt-out offered each time — is applied inconsistently to messaging apps, and regulators have been unsympathetic to businesses that stretched it.
Meta's own Business Messaging Policy requires opt-in regardless of your jurisdiction. Break it and you don't get a fine, you get something faster: your number's quality rating drops, your messaging limit falls, and the number can be restricted. Meta doesn't wait for a regulator.
So the practical standard is the stricter of the two: ask first, in a way you can prove.
What good consent looks like
- A tick box that isn't pre-ticked, next to plain words: "Send me order updates and offers on WhatsApp."
- A click-to-WhatsApp ad or a QR code where the person starts the conversation themselves.
- A keyword opt-in — "text JOIN to this number" — where the inbound message is the consent.
- Separate consent for marketing and for transactional messages, because someone who wants a delivery notification hasn't agreed to a promotion.
Keep the timestamp, the source and the exact wording shown. That record is the whole defence if someone complains, and it's worth storing as a column on the contact so it travels with them.
Lawful basis in one paragraph
For marketing messages, use consent (Article 6(1)(a)). For genuinely transactional messages to an existing customer — order confirmations, delivery updates, appointment reminders — contract (Article 6(1)(b)) usually fits, because you're doing what they bought. Don't stretch legitimate interest to cover promotions on a messaging app; that argument is weak and gets tested exactly when you least want it to.
Opt-out has to be trivial
Under the GDPR, withdrawing consent must be as easy as giving it. In practice:
- Accept STOP and the local-language equivalents your audience actually uses.
- Honour it immediately, across every campaign, sequence and flow — not just the one they replied to.
- Don't require them to log in, email you, or explain themselves.
SendFromChat marks anyone who replies STOP as opted out automatically and excludes them from every future send, including drip sequences already in progress. You can also mark someone opted out by hand from the inbox.
Retention: delete what you're not using
The GDPR's storage limitation principle means "we keep everything forever" isn't a policy. Decide how long a contact stays after their last interaction — 12 or 24 months is a common choice for marketing lists — and actually delete after it. Message history is personal data too.
A contact and their full message history can be deleted from the dashboard in one action, which is what makes most erasure requests a thirty-second job rather than a ticket.
Data subject requests
People can ask what you hold, ask for a copy, ask you to correct it, or ask you to erase it. You have one month to respond. Because you're the controller, the request comes to you, not to us. Everything about a contact — profile, consent record, full message history — is exportable and deletable from the dashboard, so you can answer without involving anyone else.
Transfers outside Europe
If your messaging provider stores data outside the EEA, you need a transfer mechanism — normally the Standard Contractual Clauses. This is the question European buyers ask that most vendors dodge, so check it for any tool you evaluate:
- Where is the database, specifically? Which region?
- Is there a published sub-processor list?
- Are the SCCs already incorporated, or do you have to negotiate them?
Be aware that Meta delivers the messages themselves whichever platform you use, under Meta's own terms — so no WhatsApp tool can promise your message content never leaves Europe.
For our part: our database is in Mumbai, our sub-processors are published, and our DPA incorporates the SCCs and the UK addendum by reference, so there's nothing to negotiate. If strict EU data residency is a hard requirement for you, ask us before subscribing and we'll tell you plainly whether we can meet it.
The DPA
Any time someone sends messages on your behalf, they're a processor and you need a Data Processing Agreement with them (Article 28). Your buyers will ask you for one too, once you're the provider in someone else's chain.
A DPA you can actually use should already state: the roles, what's processed and for how long, the security measures, the sub-processors and how you're told about changes, the transfer mechanism, breach notification timing, audit rights, and what happens to the data at the end. Ours states all of it and applies automatically when you accept the Terms — read it here. No sales call, no redlines, unless your own procurement needs a signed copy.
A pre-launch checklist
- Consent captured, with timestamp and source, for every number on the list
- Marketing and transactional consent recorded separately
- Privacy notice mentions WhatsApp messaging and names the processor
- STOP handling tested in the languages your audience uses
- Retention period decided and written down
- DPA in place with your messaging provider
- Templates match what people agreed to receive
What this has to do with getting banned
Consent, opt-outs and relevance are also exactly what keeps Meta's quality rating high. A list that's compliant is a list that doesn't get blocked — the legal work and the deliverability work are the same work. See sending in bulk without getting banned and messaging limits for the Meta side of it.
This is a practical summary, not legal advice. If you're processing sensitive data or operating at scale, have a data protection lawyer review your setup.
Do this from your AI assistant
SendFromChat connects Claude, ChatGPT, Cursor or any MCP client to the WhatsApp Business API — templates, bulk sends, inbox, chatbots and sequences, just by asking. 30 days free, no card.
Start freeMore guides
WhatsApp Business API in Europe — a country-by-country guide
Where WhatsApp actually dominates in Europe, what it costs to send in each market, and the rules that differ by country before you launch a campaign.
How to set up the WhatsApp Cloud API (2026 step-by-step guide)
Create a Meta app, get a WhatsApp Business Account, send your first message from the free test number, then make it permanent with a system-user token — every step, with the parts Meta's docs skip.
How to send WhatsApp messages from Claude or ChatGPT
Connect Claude or ChatGPT to the WhatsApp Business API with a custom connector, then draft templates, message customers and run broadcasts by just asking.
The WhatsApp 24-hour customer service window, explained
When you can send free-form WhatsApp messages, when you need an approved template, what each costs, and why a "sent" message sometimes never arrives.