WhatsApp opt-in is the recorded permission a person gives to receive messages from a business, and it is a requirement for using the official WhatsApp Business API. Meta requires that the person provided their number and agreed to receive messages from a named business; Brazil’s data protection law (LGPD) requires a legal basis for each send and, when consent is that basis, an agreement that is free, informed and provable.
In WhatsApp customer service, this becomes a routine: Meta’s requirements, legal bases, collection channels, proof of consent, opt-out and rollout. Similar rules apply under the GDPR in the EU, so the same discipline serves businesses outside Brazil as well.
Key Takeaways
- Ask for consent with the business name and keep proof of it: Meta requires the opt-in, and the LGPD requires the proof.
- Use a dedicated, unchecked box that states the channel and purpose: a generic authorization is void.
- Offer a free and easy way out (LGPD, art. 8, §5), by message category, and honor requests made outside WhatsApp.
WhatsApp Opt-In: What It Is and What Meta Requires
The term was born in email marketing, but on WhatsApp the consequences are more immediate. The message lands in the same app where the customer talks to family and friends, and an unrequested message tends to annoy people more.
Definition of Opt-In and Opt-Out
Opt-in is prior permission to receive messages from a business, and opt-out is the request to stop receiving them. WhatsApp’s policy only allows businesses to contact people who provided their number and confirmed their agreement to receive messages from that business.
Having a number saved in a contact list or a customer database is not the same as permission. This “implied opt-in” is a common interpretation, but it lacks explicit confirmation. Anyone who sells through WhatsApp Business needs to be clear on this before building any list.
WhatsApp Business Messaging Policy Rules
The WhatsApp Business Messaging Policy sums up the requirements in three points, which must all be met at the same time:
- Number provided: the person gave their number to the business itself, not to a third party.
- Opt-in confirmed: there was a clear agreement to receive messages from that business.
- Opt-out honored: block and unsubscribe requests are respected, whether made inside or outside WhatsApp.
The policy also states that the business is solely responsible for its collection method and for legal compliance, which gives it the freedom to adapt the process to each channel. Repeatedly breaking these rules increases the risk of a banned WhatsApp number, with restrictions that affect sales and support.
Clear Wording and the Business Name
According to Meta’s opt-in guidance, the text must make it clear that the person agrees to receive communications and must include the business name. Meta also recommends opt-in by category, a clear way to opt out and an explanation of the value of the messages.
Precise wording also simplifies customer service automation: what was promised in the opt-in defines which flows can use that contact.
LGPD and Legal Bases for WhatsApp Messages
The LGPD does not mention WhatsApp, but every message uses a piece of personal data: the phone number. That is why each send needs a legal basis, and consent is only one of the options the law provides.
Meta Opt-In vs. LGPD Consent
These are two different layers. Meta sets a condition for using the platform, valid for any business that sends messages. The LGPD, in turn, defines how any personal data can be processed in Brazil.
As a result, an opt-in can meet Meta’s policy and still be weak under the law, such as an agreement with no clear purpose, no record or hidden in a long text. The reverse is also true: in customer retention campaigns, Meta requires an opt-in even when the LGPD legal basis is a different one.
Treating opt-in as part of good customer service practices, and not just as a technical requirement, helps align both layers.
Free, Informed and Unambiguous Consent
Law 13,709/2018 (in Portuguese) defines consent, in art. 5, item XII, as the free, informed and unambiguous expression by which the data subject agrees to the processing of their data for a specific purpose.
Art. 8 accepts consent in writing or by other means that demonstrate the data subject’s will. In a contract, the clause must stand out, and generic authorizations are void. In practice, a pre-checked box and consent buried in the general terms are unlikely to meet these requirements.
Art. 9 requires informing the purpose, the controller, contact details and rights, and misleading or late information voids consent. In a sales funnel, the natural moment to ask for consent is the sign-up or the proposal, with the full text visible.
Contract Performance and Legitimate Interest
Art. 7 lists other legal bases. One of them is the performance of a contract at the data subject’s request (item V), useful for order and delivery notices sent by AI assistants on WhatsApp.
Another is legitimate interest (item IX), which art. 10 links to promoting the controller’s activities. It requires respecting the data subject’s expectations, using only strictly necessary data and acting transparently.
The Legitimate Interest Guidance from Brazil’s data protection authority (ANPD) (in Portuguese) describes a balancing test to assess this use. There is no official rule on which basis to use for WhatsApp marketing, and the choice belongs to the legal team or the DPO.
Channels and Entry Points for Opt-In
Meta’s opt-in documentation lists SMS, website, phone (with an agent or IVR), in-person collection and signed paper forms as accepted channels. QR codes and ads, a frequent point of confusion, are not on that list.
Website, Forms and Checkout
Digital channels are the easiest to record, because the system logs the date, page URL and text version. Forms and checkout are not named in Meta’s documentation, but they work as variations of website collection.
The recommendation is to use a dedicated WhatsApp checkbox, unchecked and separate from the general terms, in line with the highlighted clause required by art. 8. A WhatsApp chatbot on the website can also capture consent, as long as it shows the full text first.
Phone, SMS, In Person and Paper
On the phone, whether through IVR or an agent, consent needs a fixed script and a record, such as the key pressed or the call recording. By SMS, a reply to a clear question that names the business and the type of message works.
In a store or at an event, a tablet with the same text as the website or a signed form handles collection. In a multi-agent inbox, no one should mark consent on their own, and the script must be single and auditable.
QR Codes, Links and Ads
WhatsApp QR codes and short links open the app with a pre-filled message of up to 140 characters, which the customer sends. Click-to-WhatsApp ads also open a conversation started by the customer.
The business can reply, but the official documentation does not say these entry points count as opt-in. Meta also does not confirm that consent given inside the conversation counts as marketing opt-in.
The most prudent option is to record that consent with the full text displayed and, if possible, confirm it at another collection point, such as sign-up or checkout. A WhatsApp service bot can make the request, with this caveat, and the legal team should validate the use.
Sales follow-up follows the same logic: picking up a quote requested in the conversation is different from adding the contact to weekly promotions, and the customer record needs to show that difference.
Opt-In Wording Templates
Good wording solves much of the compliance work. The examples below are editorial, not official, and should be validated by the legal team, but they show the elements that must be present.
Consent Checkbox at Checkout and Sign-Up
Two examples cover most sign-up forms and checkouts. The first covers purchase-related notices, and the second covers offers, with opt-out instructions included in the text itself:
- Order notices: “[ ] I want to receive order updates from [Business] on WhatsApp.”
- Offers: “[ ] I want to receive offers from [Business] on WhatsApp. I can opt out at any time by replying STOP.”
Each part has a reason. The business name meets Meta’s requirement; the channel and purpose meet arts. 5 and 8 of the LGPD; and the opt-out method anticipates the easy withdrawal required by art. 8, §5. The boxes stay unchecked and outside the terms.
In a WhatsApp delivery service, for example, the customer can accept preparation and delivery notices without accepting promotions. The offers list includes only people who actually want it.
Opt-In by Message Category
Separating permissions according to Meta’s template categories makes control more precise. People who only want order notices do not receive promotions, which tends to prevent full opt-outs. An example of consent for each category:
- Marketing: “I want to receive offers and news from [Business] on WhatsApp.”
- Utility: “I want to receive notices about my orders and appointments with [Business] on WhatsApp.”
- Authentication: “I want to receive access codes for my [Business] account on WhatsApp.”
In customer service automation, each accepted category becomes a field in the customer record, and marketing, utility and authentication templates get their own lists. The guide to WhatsApp message templates explains each category in detail.
How to Record and Prove WhatsApp Consent
Meta does not define a format for proof, but the LGPD places the burden of proof on the business. Without a record, there is no way to show that an opt-in existed, or what the customer was told at the time of consent.
Burden of Proof and Records of Processing
Art. 8, §2 of the LGPD states that the controller bears the burden of proof, meaning it must prove that consent was obtained in accordance with the law. Art. 37 requires keeping records of processing operations.
Keeping the text version is essential, because the wording changes over time. Support automation tools help link each consent to the text in force on that day, without scattered spreadsheets.
Record Fields and CRM Integration
The LGPD does not define mandatory fields. The table below is an editorial suggestion with the information that makes a record easier to defend:
| Field | What to store | Why |
|---|---|---|
| Date and time | Exact moment of consent | Proof that consent came before the send |
| Channel and URL | Source: website, store, IVR or conversation (with the Meta caveat) | Traceability of the collection point |
| Exact text and version | Sentence shown to the customer | Proof of what was disclosed (art. 9) |
| Number | Phone number with country code | Link to the data subject |
| Accepted categories | Marketing, utility, authentication | Specific purpose |
| IP, form ID or signature | Technical identifier | Authenticity of consent |
| Withdrawal | Date and channel of the opt-out | Compliance with art. 8, §5 |
Ideally, everything lives in the contact profile. A CRM integration makes this possible: consent, categories and withdrawal are visible to sales, support and marketing, and every send can check these fields before it goes out.
Opt-Out and Withdrawal of Consent

Opt-out closes the consent cycle. The opt-out must work on any channel and reach every sending list, not just the conversation where it was requested.
Free, Easy Withdrawal by Category
Under the LGPD, withdrawal can happen at any time, through a free and easy procedure (art. 8, §5), and it is a data subject right listed in art. 18, item IX. Requiring a login, a long form or a justification goes against this principle.
Offering opt-out by category, such as “stop offers and keep order notices,” keeps the customer on the lists they still want. Recognizing STOP or similar keywords in free text is a good practice, not an official rule, and the confirmation should come in a single message.
AI agents for WhatsApp understand variations such as “I don’t want promotions anymore” and trigger the opt-out in the right category, which reduces the risk of ignored requests.
Requests Outside WhatsApp and Data Deletion
Opt-out requests also arrive by email, the customer service line or in store. It is worth defining who receives these requests on each channel and a short internal deadline for forwarding them to the central opt-out list. The LGPD also provides for the right to request data deletion (art. 18, item VI).
The solution is to centralize every request in one place, synced with all lists. Ignoring opt-outs leads to blocks and reports, which lower the quality rating and can lead to template pausing, according to Meta.
With AI in customer service, a request recorded on any channel can update the customer record automatically, and the next campaign goes out without that contact.
Common Mistakes and Risks of Sending Without Permission
Shortcuts to grow a list create consequences on two fronts: on the platform, which limits or blocks sending, and under the law, which provides for sanctions.
Most Common WhatsApp Opt-In Mistakes
Four mistakes show up often in collection, each with a direct fix:
- Pre-checked box or consent inside the general terms: use a dedicated, unchecked box.
- Generic authorization “for various communications”: name the business, the channel and the purpose.
- Treating an ad click or an open conversation as marketing opt-in: ask for explicit consent and record it.
- Not keeping proof of consent: record the date, channel and text, because the LGPD requires proof.
Tracking unsubscribes, blocks and reports alongside customer service metrics shows early when something is off. A spike in opt-outs after a campaign can signal vague opt-in wording or sends outside the accepted category.
Meta Penalties and LGPD Sanctions
On the platform, prolonged low quality leads to messaging limits, according to Meta’s opt-in guidance. Under Meta’s policy enforcement rules, spam and miscategorization lead to warnings, messaging blocks of 1 to 30 days, account locks and account disabling.
Appeals are filed through Business Support Home, with a decision in 24 to 48 hours. The official API reduces the risk of a banned number, but it does not prevent blocks when a business messages people who never gave permission.
On the LGPD side, art. 52 provides for warnings, publicizing the violation, blocking and deleting the data, and fines of up to 2% of revenue in Brazil, capped at R$ 50 million per violation.
How to Implement WhatsApp Opt-In in Your Business
The roadmap below turns the rules into routine. It works both for businesses starting on the official API and for those that need to clean up an old contact list.
Step-by-Step Rollout
Six steps organize the rollout, from mapping purposes to auditing. The order matters, because each stage depends on decisions made in the previous one:
- Map the purposes (notices, marketing, collections) and define the legal basis for each with the legal team or DPO.
- Write the text for each category, with the business name, the channel and the way to opt out.
- Place collection points on the website, at checkout, in store, on the IVR and, with the caveat above, in the conversation.
- Set up the record in the CRM with the fields from the proof table.
- Create the central opt-out list, connected to every sending list.
- Periodically audit the text version, opt-outs and reports.
In step 1, in regulated industries such as healthcare, vertical AI agents can apply the wording and legal basis defined by the legal team. For older contact lists, guidance is in the FAQ.
Automation with AI Agents and ConverZap
AI agents keep the rules in place day to day: they ask for consent, understand opt-out requests and respect categories when sending. When evaluating WhatsApp AI tools, check whether the agent saves consent in the CRM and blocks sends outside the authorized category.
ConverZap is an AI agent platform for WhatsApp connected to the official API with coexistence, with template sends and unsubscribe options, database and CRM integration, and dashboards. The platform automates the process, but decisions about wording and legal basis remain with the business.
Frequently Asked Questions About Opt-In
The answers below are general guidance on WhatsApp opt-in and do not replace the analysis of each company’s legal team or DPO, especially when choosing the legal basis.
The LGPD does not set a deadline in days: processing ends when the purpose is achieved or when the data subject withdraws consent (art. 8, §5). If the purpose changes, the right move is to ask for new consent. Periodic reviews should be aligned with the legal team or DPO.
It is not recommended. Meta’s policy requires that the person provided their number and agreed to receive messages from the business that is sending, with its name in the text. An opt-in given to another company does not meet this condition.
Consent can be collected on another channel, but the text must make it clear that the person will receive messages from the business on WhatsApp. Under the LGPD, generic authorizations are void, so it is safer for the text to mention WhatsApp explicitly. When in doubt, ask for specific consent at the next contact.
The safest path is to use a channel where the business already has permission, such as email, SMS, a logged-in area or the next purchase, to invite the customer to turn on WhatsApp, with the full text and a record. Contacts without proof of consent should be treated as not authorized.
The WhatsApp Business Messaging Policy refers to opt-in for receiving messages or calls from the business. The consent text can therefore mention calls when the business plans to use them, making it clear to the customer what type of contact they are authorizing.
Conclusion
A well-executed WhatsApp opt-in answers three questions for each contact: who gave permission, for which type of message and in response to which text. With these answers in the customer record, the business meets Meta’s requirements, supports its legal basis under the LGPD and stops sending as soon as the customer asks.
To automate this cycle with AI agents on the official API, talk to the ConverZap team.




