💚 WhatsApp

WhatsApp Marketing Compliance: Meta's Rules and UK GDPR/PECR

Havari Team·19 February 2026·9 min read

WhatsApp marketing compliance isn't one rulebook — it's two, layered on top of each other. Meta sets the platform-level rules for what you can send and to whom, and UK businesses also have to satisfy GDPR and PECR consent requirements underneath that. Get either layer wrong and you risk anything from a blocked number to a regulatory complaint, so it's worth understanding both properly before you send your first campaign.

Two layers of rules, not one

It's easy to assume that following Meta's policy is enough on its own. It isn't, and the reverse is also true — following UK data protection law doesn't automatically satisfy Meta's platform rules either. A compliant WhatsApp marketing programme for a UK business needs to clear both bars at once.

The two layers at a glance

Meta's WhatsApp Business Messaging Policy — governs what content and message types are allowed on the platform, and enforces the opt-in and 24-hour session rules
UK GDPR and PECR — govern whether you were legally allowed to collect someone's number and message them for marketing purposes in the first place

Meta's WhatsApp Business Messaging Policy

Meta requires that every business obtain opt-in before sending a WhatsApp message, and that opt-in has to happen somewhere other than WhatsApp itself — a checkout page, a sign-up form, an in-store sign, or a previous conversation on another channel. You can't simply message a number you've never had contact from and call that compliant just because the number is technically a customer's.

What Meta expects from a compliant opt-in

1

Clear opt-in, collected off-platform

Consent has to be captured somewhere the customer can see exactly what they're agreeing to — a web form, a paper form, a checkbox at checkout — not implied from having a phone number on file.

2

Message content matches what was described

If someone opted in for order updates, sending unrelated promotional broadcasts through the same opt-in is against policy, even if they technically agreed to receive WhatsApp messages at some point.

3

Templates for anything outside the 24-hour window

Business-initiated messages sent more than 24 hours after the customer's last message must use a Meta-approved template. Free-form marketing copy outside that window will be rejected.

4

A working opt-out

Customers need a straightforward way to stop receiving messages, and that request has to be honoured promptly, not buried behind a support ticket.

⚠️

Enforcement is on Meta's terms

Meta reviews accounts against its own policy independently, and repeated complaints or policy violations can lead to restrictions on your WhatsApp Business account regardless of how carefully you've handled UK consent law. Platform compliance and legal compliance are both necessary, and neither substitutes for the other.

UK GDPR and PECR: the layer underneath

For UK businesses, the Privacy and Electronic Communications Regulations (PECR) sit alongside GDPR and specifically cover electronic marketing messages, which includes WhatsApp. The core requirement is the same one that applies to SMS and email marketing: for most consumer marketing, you need clear, specific, opt-in consent before sending — pre-ticked boxes and consent bundled into general terms and conditions don't meet the bar.

What UK consent needs to look like

Consent must be freely given, specific, informed and unambiguous — a genuine opt-in, not an assumption
The request to opt in should be separate from other terms and conditions, not buried in them
Records of when and how consent was given should be kept, in case it's ever questioned
Consent should be easy to withdraw, and withdrawal should be actioned quickly
B2B marketing to individual sole traders and unincorporated partnerships still generally needs the same consent standard as consumer marketing

There is a limited 'soft opt-in' exception under PECR for existing customers being marketed similar products they've bought before, provided they were given a clear chance to opt out at the point of collection and in every message since. It's a narrow exception, not a general licence to message anyone who's ever bought from you, so most businesses are better off treating it cautiously rather than relying on it as their main consent basis.

💡

Keep one clean record of consent

Rather than tracking consent across spreadsheets or separate tools per channel, keep it attached to the contact record itself. Havari records opt-in status and message history against each contact, so if a customer's consent is ever questioned, you can see exactly when and how they opted in without digging through old exports.

Practical steps for a compliant WhatsApp programme

Getting the basics right

1

Collect opt-in away from WhatsApp itself

Use a website form, checkout step, or in-store sign-up that clearly states what someone is agreeing to receive and how often.

2

Match your templates to what people opted in for

If a template was approved for delivery updates, don't repurpose the same opt-in list for unrelated promotions.

3

Keep an accessible opt-out

Make it obvious how to stop messages, and action opt-outs immediately rather than on a delay.

4

Keep records tied to each contact

Store when and how consent was captured against the contact itself, so you can answer a consent question in seconds rather than searching for it.

24hr
Window for free-form replies before a template is required
2
Rulebooks that apply at once: Meta's policy and UK GDPR/PECR

Meta's policy tells you what you're allowed to send. UK law tells you whether you were allowed to collect the number in the first place. You need both answers to be yes.

Is following Meta's WhatsApp policy enough for UK compliance?

No. Meta's Business Messaging Policy governs the platform, but UK businesses also need to satisfy GDPR and PECR consent requirements, which are a separate legal obligation.

Can I message existing customers on WhatsApp without a fresh opt-in?

Only within narrow limits, such as the PECR soft opt-in for similar products to something they've already bought, and even then they must have been given a clear chance to opt out at collection and in every message.

What happens if a customer complains about unwanted WhatsApp messages?

Meta may restrict the sending account for a policy breach, and separately the business may face a complaint or enforcement action under UK data protection law. It's worth treating every opt-out request as final and immediate.

None of this needs to be complicated in practice — it just needs to be deliberate. Capture clear, specific opt-in, keep your templates matched to what customers agreed to, make opt-out effortless, and keep a record you can point to. A platform like Havari that ties consent and message history to each contact makes that far easier to maintain as your WhatsApp list grows.

Ready to see it in action?

Join UK businesses using Havari to reach customers across SMS, WhatsApp, Email, Instagram and Messenger — all from one shared inbox.

Get 25 Free Messages

25 free messages · No credit card required · Cancel anytime