WhatsApp marketing compliance: consent, spam fines, and what counts as advertising
AndySendy academy
← All posts

⚖️ WhatsApp outreach without consent: one pre-checked box can cost you dearly

A company collected numbers via a website form with the marketing consent checkbox pre-ticked - users just had to leave it checked. After a regulator complaint, pre-set consent didn't count as consent. The fine: roughly $1,000+ equivalent per message in a comparable enforcement case. WhatsApp was only the delivery channel; missing provable opt-in decided the case. What counts as advertising in messengers, what consent actually protects you, and what penalties show up in practice.

WhatsApp outreach is legally the same class of promotional communication as SMS or email - different channel, same rules in most jurisdictions. Regulators in multiple markets treat messengers as electronic communication networks and apply advertising law fully: the myth "WhatsApp is just chat, ad law doesn't apply" doesn't hold in enforcement practice. Real risk isn't the channel - it's list origin and whether you can prove each recipient's consent - see cold vs warm contacts. Below: what's advertising, what consent survives audit, and what penalties look like.


What's advertising in WhatsApp - and what isn't

If a message targets an undefined audience - even with a name merge tag - to promote a product or service, regulators typically classify it as advertising. Transactional messages - order status, receipt, appointment reminder - usually aren't advertising and face lighter rules.

Personalization doesn't change the legal nature. A name tag doesn't make a promo "personal" - classification depends on purpose (market promotion), not greeting form. Hiding ads behind {{name}} doesn't work legally - see first cold message.


Data consent ≠ marketing consent

Where businesses lose money most often. Data-protection law governs storing and processing personal data - numbers, names, order history. Advertising law requires separate, advance, explicit, provable consent specifically for promotional messages. Two different legal bases - one doesn't replace the other.

A phone number in CRM or a past purchase alone isn't marketing consent - even if the client volunteered data once. Burden of proof lies on the sender, not the complainant - same logic as migrating lists from other messengers: Telegram/Viber opt-in doesn't carry over.


Consent that survives regulatory review

Pre-ticked website checkbox - common and expensive mistake: regulators regularly invalidate it because the user didn't actively give consent. Checkbox must be unchecked by default; wording explicit: "I consent to receive promotional messages, including via WhatsApp."

Stronger model - double opt-in: client leaves number, WhatsApp confirmation request arrives, only affirmative reply (e.g. digit "1") counts as consent. CRM must store inbound reply log and dialogue screenshot - evidence that actually helps in disputes - see inbound lead collection and CRM segmentation.

No single officially approved electronic-consent verification protocol exists everywhere. Double opt-in with logs improves odds - doesn't guarantee automatic win.

Opt-out mechanics: if someone writes "Stop" or "Remove my number," promotional sends must stop immediately - see handling rejection. CRM should block that contact instantly - WABA also has opt-out button requirements, see WABA overview.


Failure → Success: similar starts, different outcomes

Failed Working
Consent source Pre-ticked website checkbox Client enters number, WhatsApp confirmation request
Confirmation Form submission only Client replies "1" in WhatsApp
CRM proof Not stored separately Inbound log + dialogue screenshot
Regulator outcome Fine - consent invalid Case closed - consent proven by logs

Difference isn't collecting consent - it's whether the user acted consciously and whether that's provably recorded.


What regulators accept as spam evidence

Complaints can be filed electronically with low barrier: screenshot of open WhatsApp dialogue showing sender number, date, text, plus carrier detail confirming traffic at that time. Filing is technically easy - don't assume recipients won't bother.


Gray numbers don't shield legal liability

Promo text almost always includes site link, brand name, or order phone - otherwise it's pointless commercially. Investigators trace domain admin or trademark owner to find the actual advertiser - regardless of which number or account physically sent - see ban mechanics (platform ban ≠ legal protection).


Penalties: ranges from enforcement practice

Figures vary by jurisdiction and entity type. Illustrative ranges from markets with active messenger enforcement (converted for readability):

Violator type Typical range (illustrative)
Individuals Low hundreds USD equivalent
Sole traders / managers Mid hundreds to low thousands
Companies Low thousands to tens of thousands per message in strict regimes

Separate data-protection violations (processing without legal basis) can add another fine tier - often lower on first offense, higher on repeat. Statute of limitations commonly ~1 year from send date in comparable systems.

Caution: headline figures like "up to $millions" in data-law overviews often refer to breach/leak scenarios - don't automatically apply to routine WhatsApp promo without checking the specific violation type in your jurisdiction.


Ad labeling / disclosure tokens: unsettled in many markets

Most disputed area - no universal final answer yet. One view: messenger promo is internet distribution requiring ad registry/disclosure like other digital channels. Another: private WhatsApp DMs lack public distribution character (unlike public channels) and may not require token labeling - but consent requirement still applies either way.

No single official cross-market position - safer to model both scenarios until local guidance clarifies. Missing required labeling where mandated can trigger additional penalty tiers.


Cascade risk: advertising case → data authority follow-up

Practice observation: after losing an advertising case, a data-protection authority may open separate review on storing numbers and names in outreach software - second cascading fine on the same episode. Not automatic statutory chain everywhere - but worth modeling as risk scenario.


"Professional complainants" - not conspiracy theory

Legal forums report a trend: people deliberately leave numbers in open sources, wait for WhatsApp promos, then assemble evidence packages - carrier detail, certified screenshots - for mass regulator complaints, sometimes pursuing civil compensation afterward. No confirmed scale statistics - but risk factor for cold and purchased lists.


Multi-account and agencies: what changes, what doesn't

Splitting sends across accounts lowers WhatsApp platform ban risk - doesn't lower advertising or data-law risk. Liability attaches to advertiser and list origin, not sender number. Agencies should verify lead-source legality before launch and contractually require consent-proof retention from clients.


WhatsApp-specific penalty stats for 2025–2026?

Honestly: no separate public statistics counting complaints and fines specifically for WhatsApp - distinct from advertising overall or SMS spam - in open sources globally. That doesn't mean enforcement is inactive: advertising law applies to messengers in active jurisdictions, and cases like above are real. But a dedicated public "WhatsApp cases 2025–2026" registry isn't available - many matters never enter public analytics.

This article's detailed statutory references (152-FZ, 38-FZ, FAS) are Russia-specific. Check local advertising law, data protection, and telecom rules in your jurisdiction before launching outreach.


🎯 Next step

Audit CRM: what legal basis supports each active contact - marketing consent specifically, not just data processing? Confirm "Stop" opt-out blocks sends instantly, not "on next sync."

Conclusion

Practical rule:

The most expensive gap in WhatsApp outreach isn't missing a WhatsApp account - it's missing a log proving the client actively agreed to receive ads.