Quick Answer
What are WhatsApp's opt-in requirements for businesses?
Meta requires that before you message someone on WhatsApp you have their explicit opt-in, collected in a place where it is clear they are agreeing to receive WhatsApp messages from your business by name. The opt-in can be gathered anywhere - website form, in person, another channel - but it must be unambiguous, it must name your business, and you must be able to show when and how it was given. Meta does not inspect your records up front; it enforces indirectly, through blocks and reports that damage your quality rating. In India the DPDP Act adds a separate legal duty on top, including the right to withdraw consent as easily as it was given.
Last updated:
WhatsApp Opt-In Rules, Explained

Opt-in is the least glamorous topic on this platform and the one that quietly determines whether anything else you build works. Every restriction, every collapsed quality rating, every number that mysteriously stops reaching people traces back to it.
It is also the area where businesses most confidently believe they are fine. The gap is usually not between compliant and non-compliant. It is between legally defensible and actually remembered by the recipient — and only the second one protects your number.
What Meta requires
Meta’s requirement is short: get explicit opt-in before messaging, make it clear the person is agreeing to WhatsApp messages, and make it clear which business is sending them. You may collect it anywhere — a website form, a checkout flow, in person, over another channel — because Meta cares about the clarity of the agreement rather than the medium.

Record three things at the moment of collection: when, where, and what exactly the person agreed to. Not because Meta will ask — it almost certainly will not — but because the day you need it is the day you are trying to work out which list poisoned your number, and without those fields the answer is unknowable.
Enforcement is indirect, which fools people
There is no consent audit. Nobody reviews your database. This is why weak opt-in persists for so long in so many businesses: nothing bad happens for months.
Then it does, all at once. The people who did not remember agreeing start blocking. Blocks move the quality rating. The rating gates the messaging limit. Your reach shrinks, and the cause is six weeks upstream of the symptom.
The useful reframe: opt-in is not a compliance checkbox on this platform. It is the input to a reputation system that decides how many people you are allowed to talk to.
Opt-out is the half that gets neglected
Collecting consent gets attention. Handling withdrawal usually does not, and it is where the expensive failures live.
Three properties matter. It must be automatic — recognising STOP and its variants in code, not relying on someone reading the inbox. It must be global — applying across every list, campaign and event you run, not just the one that prompted it. And it must fail closed — if the suppression lookup errors, the correct behaviour is to skip the send, not to send anyway and log a warning.
That last one is a genuine engineering decision with a tempting wrong answer. An opt-out check that silently degrades to “send it” during an outage will, on exactly the worst day, message every person who ever asked you to stop.
India: the DPDP Act sits on top
For anyone messaging Indian recipients, Meta’s policy is the floor, not the ceiling. The Digital Personal Data Protection Act adds a separate legal obligation, enforced by a different body, with consequences that are not measured in quality ratings.

The requirement most likely to catch an existing system out is the symmetry rule: withdrawing consent must be as easy as giving it. If someone can opt in with one tap on a form but has to email a support address to get out, that asymmetry is the problem, and it is extremely common.
A practical standard
If you want one test that keeps you clear of both Meta and the regulator, it is this: could the recipient reconstruct, unprompted, why they are hearing from you?
Not whether a lawyer could defend it. Whether the person holding the phone recognises the sender and remembers the moment they said yes. Every list that fails that test will eventually cost you a number, and no amount of template polish will save it.
Tools referenced in this post
Try Weddingkart for your wedding
Guest lists, WhatsApp invites, RSVPs, countdowns and more - the AI layer for Indian weddings.
Related reading
Frequently Asked Questions
Does WhatsApp check my opt-in records?
Not proactively, and this is the thing businesses most often misread. Meta does not ask to see your consent database before letting you send. It enforces after the fact and indirectly: people who did not expect your message block or report it, that damages your quality rating, and the rating gates your reach. So the practical penalty for weak opt-in is not a compliance letter - it is a number that quietly stops reaching people.
What counts as valid opt-in for WhatsApp?
The person must have taken an affirmative action indicating they want WhatsApp messages from your business specifically. A ticked box that names your business next to a clear statement about WhatsApp messages counts. A phone number typed into a form for a different purpose does not. Neither does a pre-ticked box, a number scraped from a directory, or consent given to a partner company. The test worth applying: if this person received your message, would they remember agreeing to it?
Do I need opt-in if the customer messaged me first?
If a person messages you, that opens a 24-hour window in which you can reply freely, and no separate opt-in is needed for that conversation. What it does not do is give you permanent permission to send them campaigns later. Treating an inbound support question as consent for future marketing is one of the most common ways businesses accumulate recipients who block them months down the line.
How must WhatsApp opt-out work?
It must be easy, it must be honoured immediately, and it must be permanent. In practice that means recognising STOP and similar replies automatically rather than relying on a human to notice, applying the suppression across every list and campaign you run rather than just the one they replied to, and making it fail closed - if your suppression check errors, the safe behaviour is to not send. A person who opts out and is messaged anyway does not block you, they report you, which is the more damaging signal.
How does India’s DPDP Act change WhatsApp opt-in?
It adds a legal layer on top of Meta’s platform policy. The DPDP Act requires consent that is free, specific, informed and unambiguous, given for a stated purpose, with a plain-language notice - and crucially it requires that withdrawing consent be as easy as giving it. It also gives people rights of access and erasure. Meta’s policy and Indian law overlap heavily here, but they are enforced by different parties with very different consequences, and satisfying one does not automatically satisfy the other.
Was this article helpful?
Share
By Weddingkart TeamLast updated