Back to the blog
WhatsApp outreach compliance checklist: what to have in place before you send

WhatsApp outreach compliance checklist: what to have in place before you send

A practical checklist for opt-in, template categories, and data handling before running WhatsApp outreach. Not legal advice, an operational one.

September 2, 2026 · 7 min read

Getting opt-in right and still landing in spam jail is a common combination: the messaging side was compliant, but the list underneath it wasn't checked, or the retention story wasn't documented. This is a working checklist for the operational side of WhatsApp outreach, not a legal opinion. Treat it as a starting point for your own review, not a substitute for one.

Messaging rules come from Meta's platform policy. Data-protection rules come from the law in whatever countries your recipients live in. Those are two different sources, they don't always move together, and neither is static. What follows is drawn from Meta's public WhatsApp Business Messaging Policy documentation and general GDPR principles, organized as an operational checklist. It is not a substitute for advice from someone who knows the specific laws that apply to your business and your recipients.

Opt-in: the baseline Meta actually enforces

Under Meta's WhatsApp Business Messaging Policy, updated November 2024, a business needs opt-in permission before sending someone a message. The opt-in has to clearly name the business and state that the person is agreeing to receive messages from it, and it doesn't have to happen inside WhatsApp itself: a checkout page, a signup form, or an SMS reply can all establish it, as long as it's explicit (Meta for Developers).

Checklist items:

  • Every number on the send list has a documented opt-in event, not an inherited one from a different part of the relationship (a past purchase, a saved contact, a support ticket).
  • The opt-in flow names your business and states what the person is agreeing to.
  • You've decided whether opt-in is blanket (covers all message categories) or scoped per category, and your list reflects that choice.
  • The one exception, replying inside the 24-hour customer service window after someone messages you first, is not being used as a substitute for marketing opt-in outside that window.

For the mechanics of what a real opt-in flow needs to capture and why a saved contact doesn't qualify, see how to reduce WhatsApp broadcast blocks.

Template categories: use the right one

Meta sorts every business-initiated WhatsApp message into a template category, and using the wrong one is a policy violation even if the opt-in was fine. The three that matter for outreach:

  • Marketing: promotions, offers, announcements, re-engagement. Requires explicit opt-in and the strictest approval review.
  • Utility: order confirmations, shipping updates, account alerts. Requires opt-in too, but review criteria are more lenient since these are transactional in nature.
  • Authentication: one-time passwords and login codes. Not relevant to outreach, but easy to confuse with utility if you're categorizing templates by hand.

Checklist items:

  • Every outreach template is submitted under Marketing, not Utility, even if it's dressed up as an update.
  • Template copy matches the category it's submitted under; Meta's review checks for this and rejects mismatches.
  • You're not routing marketing content through a transactional-looking template to dodge marketing-tier restrictions. This gets flagged and it damages the account, not just the one template.

Spam reports and quality rating: what actually gets tracked

WhatsApp tracks a rolling quality rating per business phone number, shown as Green, Yellow, or Red, built primarily from recipient blocks and spam reports over the trailing window (Meta Business Help Center). A high block rate throttles your sending tier before Meta suspends a number outright.

This is the part where messaging policy and list quality intersect directly, and it's the piece most compliance checklists skip. A failed send to a number that was never on WhatsApp reads as noise in the same system that tracks blocks and reports. It doesn't help your rating, and at volume it's one more signal working against you.

Checklist items:

  • You know your current quality rating and check it before scaling send volume, not after a drop.
  • You have a documented unsubscribe path (a STOP keyword or equivalent) checked automatically before every send.
  • Your list is validated against WhatsApp before a campaign goes out, so failed sends to dead or unregistered numbers aren't adding to the same negative signal as an actual block.

The full mechanics of quality tiers, throttling, and recovery are covered in how to reduce WhatsApp broadcast blocks, and what a typical unvalidated list costs you in failed sends is in why WhatsApp outreach bounce rates run higher than expected.

Data protection: storing numbers is processing personal data

A phone number is personal data under GDPR the moment it identifies someone, and that's true whether it's sitting in a CRM export or passing through a validation check. If any part of your audience is in the EU or UK, this applies regardless of where your business is based.

We've written a full breakdown of this specific to WhatsApp validation, covering legal basis, Data Processing Agreements with third-party tools, and retention: see GDPR and WhatsApp number validation: what actually applies. The short version, as an outreach-specific checklist:

  • You have a documented lawful basis (consent or legitimate interest) for holding each number, not just for messaging it.
  • Any third-party tool that touches your numbers, a validator, a CRM, a messaging platform, has a Data Processing Agreement in place under GDPR Article 28.
  • You have a retention rule for validated results, not an indefinite archive. GDPR's storage limitation principle means you keep data only as long as you have a purpose for it (Article 5(1)(e)).
  • Consent records are logged with timestamp, method, and what the person was told, not just a checkbox that flipped to true somewhere. Regulators expect organizations to demonstrate how and when consent was obtained, not just assert that it was (Data Protection Network).

Record-keeping: what to actually have on file

Beyond GDPR specifically, three records are worth keeping regardless of jurisdiction, because they're what you'd need to produce if a platform or a regulator asked:

  • Where each number came from (signup form, purchase, import) and when.
  • How and when opt-in was captured for that specific number.
  • When the number was last validated against WhatsApp, and the result.

None of this needs to be elaborate. A timestamped log tied to each contact record, even a few columns in the same place you already store the number, covers most of it. What doesn't work is reconstructing consent after the fact from an assumption that "they bought something, so they must be fine with this."

Regional rules to be aware of, not a complete list

Messaging and data-protection law varies by country, and this checklist deliberately doesn't try to summarize all of it, because getting a specific jurisdiction's rule wrong is worse than not stating it. A few examples of the kind of thing to check before you scale into a new region, not because we've verified the current state of each: the EU and UK apply GDPR (covered above); the US has state-level rules like the TCPA that govern automated messaging and calls, separate from WhatsApp's own policy; several countries (India, Brazil, and others) have their own data-protection statutes with their own consent and storage rules. If your recipient base spans regions, treat "is this compliant" as a per-region question, not a single global answer, and confirm with counsel familiar with each one.

Before you send: the short version

  1. Every number has documented, explicit opt-in naming your business.
  2. Every template is categorized correctly, marketing content under Marketing.
  3. Your quality rating is checked and an unsubscribe path exists.
  4. Your list is validated against WhatsApp before the send, not after.
  5. Every third-party tool touching the data has a DPA, and you have a retention rule, not an archive.
  6. Consent and validation history are logged, not assumed.
  7. You've flagged which regions need a closer legal look before scaling.

If you're setting this up as a recurring process rather than a one-off, the WhatsApp validation API and the cold outreach use case cover how the validation step fits into an automated send pipeline.

A compliant opt-in process and a validated list solve two different problems, and skipping either one still gets you blocked. wavalid handles the second half: checking every number against WhatsApp before it goes into a send, so your carefully opted-in list isn't quietly wasted on numbers that were never reachable to begin with. Validated, real numbers keep failed sends out of the same signal Meta uses to judge spam, which is one less thing working against a rating you've otherwise done everything right to protect.

Frequently asked questions

Send to numbers that are actually there

wavalid validates every number against WhatsApp in real time, in bulk or one at a time, so your compliant, opted-in list isn't wasted sending to numbers that were never registered.